Underground · what matters today
The underground stories that broke through this window. Gov/mil, access sales, ransomware, leaks, stealers. Screenshots and context on each.
Distribution by category · window
- Gov / Military5
- Access sale11
- Ransomware36
- Leak93
- Stealer0
- Other1
Window
Category
Severity
Combolist de más de 120.000 correos corporativos de empresas a la venta
Corporate organizations
This is a 120,000-line combolist of corporate business email addresses and passwords, likely harvested from breaches. It could be used for business email compromise (BEC), phishing, or credential stuffing against companies. The geographic scope is not specified, but corporate credentials are valuable regardless of location; no clear posting date limits the immediate alert value.
Venta de datos personales de un millón de personas de EE. UU.
US residents
A database containing personal information of one million US individuals is being sold, which can fuel identity theft and financial fraud. The thread appears to be older (no recent date), so the urgency is limited, but the volume makes it a notable data exposure. Even if stale, it may still be used for credential stuffing or phishing campaigns.
Servicio de búsqueda de credenciales filtradas LeakZero ofrece acceso masivo a cuentas
Global
This service aggregates URL:LOG:PASS (ULP) data from multiple breaches and lets subscribers search by domain, making credential stuffing and account takeover trivially easy. It affects organizations worldwide, and the scale (15KKK rows) means many corporate and personal accounts are exposed. Defenders should treat any leaked credential as compromised, enforce MFA, and monitor for anomalous logins.
Venta de 1 millón de fullz con datos bancarios de EE. UU.
A thread advertises one million US fullz with banking details, a substantial volume of identity and financial data. The lack of a named victim and the typical staleness of such listings reduce its immediate value, but it still warrants monitoring for credential and fraud campaigns.
Venta de base de datos de Binance con 1,5 millones de registros
Binance
A seller on a carding forum advertises a 2026 Binance database containing 1.5 million records. If valid, this is a large leak of a major cryptocurrency exchange's user data, with potential for account takeover and fraud. The freshness and scale make it worth validating urgently.
Filtración de base de datos de control vehicular de la Fiscalía de Coahuila
Fiscalía de Coahuila
The Coahuila Prosecutor's Office vehicle control database has been leaked on a dark web forum. The dataset likely contains vehicle registration and ownership records from a Mexican state government, useful for identity fraud and extortion. This is a fresh, government-related data exposure relevant to Latin American defenders.
Divulgación de más de 10 millones de credenciales URL:LOGIN:PASSWORD de StarLinkClouds
Secretline.top / StarLinkClouds
A large dump containing more than 10 million URL:LOGIN:PASSWORD lines attributed to Secretline.top and StarLinkClouds has been posted on a breach forum. The data likely originates from stealer malware and could facilitate account takeovers across many platforms. Organizations should check these credentials for exposure and implement phishing-resistant MFA.
Filtración masiva de 250 millones de credenciales de registros stealer
A private dump of 250 million URL:LOGIN:PASSWORD entries from stealer logs was published on August 30, 2026. This represents a massive trove of credentials that could be used to access diverse online services, including potentially corporate and personal accounts. Defenders should treat any credentials from stealer logs as compromised and enforce password resets, MFA, and dark web monitoring.
Ransomware Wallstreet publica datos del municipio de Andover, Massachusetts
Town of Andover, Massachusetts (USA)
The Wallstreet ransomware group listed the Town of Andover, Massachusetts, a U.S. municipal government, as a victim. Municipal data, including citizen records and infrastructure details, may be exposed. Although outside Latin America, this fresh ransomware victim is relevant for tracking current ransomware activity.
Ransomware Falcon publica a DistributionNOW (distribuidor de energía de EE. UU.)
DistributionNOW
Falcon ransomware claims 344 GB exfiltrated from energy distributor DistributionNOW, including financial records, SCADA gateway backups, and PLC logic. Loss of OT-related data indicates potential impact on industrial operations. This case is relevant to Latin American energy and critical infrastructure sectors as a warning of similar attack patterns.
Ransomware Falcon publica a Globus Medical (fabricante de dispositivos médicos de EE. UU.)
Globus Medical
Falcon ransomware claims to have exfiltrated 2.96 TB from medical device maker Globus Medical, including customer records, FDA submissions, and product complaint logs. The incident exposes sensitive healthcare and regulatory data, raising supply-chain concerns. Even though the victim is in the US, this type of attack highlights TTPs relevant for Latin American healthcare and critical infrastructure defenders.
Ransomware Qilin publica a la constructora qatarí Black Cat Engineering
Black Cat Engineering Construction Wll
Qilin ransomware has added Black Cat Engineering Construction Wll, a Qatari manufacturing/construction company, to its leak site. The publication may expose project documents and corporate data. This fresh ransomware incident highlights the group's ongoing activity in the Gulf region.
Ransomware Qilin publica a la consultora británica Absolute Consultancy Services
Absolute Consultancy Services
Qilin ransomware has published Absolute Consultancy Services, a UK-based professional services firm. The leak may include client data and corporate documents. This is a fresh victim post, indicating active ransomware operations targeting the professional services sector.
Ransomware Qilin publica a la farmacéutica Crystalpharmatech
Crystalpharmatech
The Qilin ransomware group has added Crystalpharmatech to its leak site. The company is in the healthcare sector, and the publication likely includes sensitive corporate and possibly patient-related data. This is a fresh ransomware incident that requires immediate attention.
Filtración de datos de la CAF francesa con 22,4 millones de registros
CAF.FR
A database of CAF.FR, the French family allowance agency, containing 22.4 million records from December 2025 is being shared. The data was likely obtained in a breach of a government agency and includes sensitive personal information. Although the breach is several months old, the volume makes it relevant for monitoring and fraud prevention.
Venta de base de datos de telecomunicaciones china con 650 millones de registros
A database allegedly from a Chinese telecom operator containing 650 million records is being offered. This is one of the largest data sets seen, likely including names, phone numbers, addresses, and possibly more. Even if the breach is not fresh, the scale makes it a critical credential and privacy risk for affected users.
Filtración de base de datos de la empresa de IA mercor.com
mercor.com
A seller is offering the source code, user database, and contractor database of mercor.com, an AI training company based in the USA. The leak likely contains source code and personal data of users and contractors, which could facilitate further attacks. This is a significant breach of a real organization and warrants immediate monitoring.
Venta de base de datos de 4 TB con selfies, pasaportes y documentos de identidad
A forum thread offers a 4-terabyte database of identity documents, including selfies and video selfies, passports, national IDs and driver's licenses. If genuine, this scale of biometric and PII data enables KYC bypass, account takeover and identity fraud at scale. Defenders should check whether their users' documents are exposed and watch for resale of this dataset.
Venta de lista de credenciales de 3.1 millones de URL:LOG:PASS
This post advertises a private 3.1 million URL:LOG:PASS dataset, similar to other infostealer credential dumps. Such lists are used for unauthorized access to web applications, email accounts, and remote access portals, posing a risk to any organization whose users are included. No date is provided, so recency cannot be confirmed, but the size makes it relevant for credential monitoring.
Venta de lista de credenciales de 3.6 millones de URL:LOG:PASS
This thread offers a private list of 3.6 million URL:LOG:PASS credentials, likely harvested from infostealer malware. The scale is significant and could enable credential stuffing against a wide range of online services, including corporate portals and VPNs. The lack of a clear post date makes it difficult to confirm freshness, but the volume alone justifies monitoring.
Filtración de 1 TB de datos técnicos de i-one (Corea del Sur)
i-one
The South Korean auto parts maker i-one was listed by the Black X ransomware group, which claims to have exfiltrated 1 TB of technical data, including drawings and supply chain information. The exposure of industrial intellectual property is critical for the company and its customers. Organizations should verify if this campaign affects their supply chain.
Filtración de datos de millones de clientes de FE Credit (Vietnam)
FE Credit
FE Credit, a Vietnamese financial institution, was published by the Black X ransomware group, which claims to hold personal data of millions of customers. The exposure of a financial database at this scale could enable large-scale fraud and targeted phishing. This warrants monitoring and CERT coordination.
Fábrica de Rodamientos FRM (Brasil) listada por ransomware zawoo
FRM - Fábrica de Rolamentos e Mancais Ltda
The Brazilian bearing manufacturer FRM was listed as a victim of the zawoo ransomware group, indicating a recent compromise and possible data theft. This is a fresh ransomware victim in Latin America, and industrial organizations in the region should check for exposure to this campaign.
Venta de base de datos de 4 TB con documentos de identidad y selfies
A 4 TB database of identity documents, including passports, IDs, and selfies, is being offered for sale. The scale is massive and likely enables identity fraud and account takeover. Defenders should monitor for any of their users' documents appearing in these collections and alert affected individuals.