BRIEFLeakhighP50
Database of Ledger, Trezor and other hardware wallet user PII for sale
Usuarios de carteras hardware (Ledger, Trezor, SafePal, OneKey)
Detected26 September 2026 · 12:16 UTC
A private dataset of PII tied to hardware-wallet owners (Ledger, Trezor, SafePal, OneKey) is circulating across multiple forums as '2026 private leads'. Such data maps crypto holders by name, email and address, fueling targeted phishing and physical/extortion attacks against high-value individuals. Defenders and exchanges should flag these users for heightened social-engineering and SIM-swap monitoring.
CategoryLeak
Severityhigh
Priority score50
Detected26 September 2026 · 12:16 UTC
Leak● 38
Filtración de base de datos de 2,2 millones de usuarios de DUPR (pickleball)A database containing 2.2 million DUPR pickleball accounts is being circulated, with full name, home address, email and phone number. The data enables identity theft, phishing and SMS-based attacks against a large consumer base. Defenders whose users reuse credentials should flag the exposure and watch for targeted phishing.Leak● 45
Filtración de más de 10 millones de registros de la base de datos de JKT48.comA full database from the Indonesian site JKT48.com is offered, claiming over 10 million records including Gmail addresses, NIK national ID numbers and phone numbers. The inclusion of national identifiers significantly raises the risk of fraud and impersonation. Leaks of this scale deserve monitoring even outside the region because of credential reuse.Leak● 44
Base de datos con PII de 450.000 usuarios de monederos hardware a la ventaA private 450,000-record PII dataset of users of hardware wallets (Ledger, Trezor, SafePal, OneKey) is being marketed across multiple carding forums as '2026 private leads'. Although it is fraud-focused rather than government-related, it is a large, fresh personal-data set that enables targeted phishing, SIM-swap and crypto-theft campaigns against high-value holders. Its mass cross-forum promotion lowers urgency somewhat.Leak● 70
Venta de 125.000 archivos de I+D gubernamental y componentes militares rusosA seller on DarkForums is advertising a 125,000-file trove covering Russian government and semiconductor R&D as well as military components. Such material can expose supply-chain designs, procurement details and dual-use technical data valuable to state and defense analysis. It matters for tracking strategic technology theft and for cross-referencing related campaigns.Leak● 78
Filtración de base de datos de 1,2 millones de usuarios de military.comA 1.2M-record database from the US military community site military.com (Buddy Finder/peer-finder feature) is being offered on BreachForums today. It likely contains names, emails, service details and location data of military personnel and veterans, forming a ready-made targeting list for phishing and identity theft. Defenders tied to military-linked individuals should treat this as a live credential/PII exposure.Leak● 72
Filtración de base de datos de Under Armour con 72 millones de líneasA 72-million-line dataset attributed to underarmour.com is being published, likely credentials and customer PII in bulk. For a global retail brand this volume enables mass credential stuffing, account takeover and downstream fraud against the brand's customers. Defenders should treat Under Armour credentials as compromised and force resets plus monitor reuse across other services.