BRIEFLeaklowP30
89 million URL:LOGIN:PASS credentials offered for sale
Detected9 October 2026 · 01:21 UTC
A seller is dumping a roughly 89-million-entry URL:LOGIN:PASS combo of stealer-log style credentials sourced from infected hosts. It is a large commodity credential set rather than a breach of a specific named organization, so it mainly fuels credential-stuffing. Value is limited unless defenders cross-reference their own domains against it.
CategoryLeak
Severitylow
Priority score30
Detected9 October 2026 · 01:21 UTC
Leak● 40
Filtración de 89 millones de credenciales URL:login:contraseñaA member is publishing a very large stealer-log compilation of URL:login:password entries, claimed at 89 million lines. Credential dumps this size fuel credential-stuffing and account-takeover campaigns across many services. Defenders should enforce MFA and monitor for spikes in failed logins against their user base.Leak● 42
Venta de datos de 43.000 residentes de Probolinggo, IndonesiaA seller is advertising 43,000 identity records belonging to residents of Probolinggo, Indonesia, likely including national ID and personal data. Bulk PII of this kind enables identity fraud and targeted phishing against the affected population. It also suggests a possible compromise of a regional government or service-provider database.Leak● 62
Filtración de datos de operaciones de vuelo de aerolíneas de EE. UU.A forum user posted what is described as US airline flight operations data, a dataset touching aviation logistics and scheduling. If genuine, exposure could reveal routes, schedules and operational details useful for disruption or fraud. Aviation operators and their suppliers should verify exposure and monitor for downstream abuse.Leak● 44
Volcado fresco de registros stealer de 743 MB publicado en foroA 743 MB dump of infostealer logs was posted today on DarkForums, likely containing credentials, cookies and session data harvested from infected machines. Fresh stealer logs of this size often feed account-takeover and initial-access campaigns against corporate and government targets. Defenders should hunt their users' and organizations' credentials in the dump before it is weaponized.Leak● 71
Filtración de datos de empleados de TI de StarMedica MéxicoStarMedica, a Mexican private hospital chain, is reportedly leaking data tied to its IT department employees. If valid, threat actors could reuse credentials and internal details for phishing or lateral access into healthcare infrastructure. Health-sector targets in Latin America are prime for ransomware, so this warrants validation and credential-reset advice.Leak● 28
Base de datos filtrada de Phone House EspañaThe Phone House España customer database is circulating for download on a RaidForums clone. Spanish retailer data (names, contact and potentially payment details) can fuel fraud and phishing against Spanish-speaking victims. However the sample appears to be an older leak, so it is not a fresh alert for LATAM defenders.