BRIEFLeakhighP80
Citizen data leak from Uruguay's UTU and UDELAR
UTU / UDELAR (Uruguay)
Detected12 September 2026 · 11:12 UTC
Reposts collapsed2
A 267,000-record database containing citizen data from Uruguay's UTU (technical education) and UDELAR (national university) is being released for free, likely by a regional actor (LaPampaLeaks). The public-sector origin means real personal data of students and staff is exposed, enabling identity theft and targeted phishing. Uruguayan defenders should validate the exposure, scope the records and notify affected individuals.
CategoryLeak
Severityhigh
Priority score80
Detected12 September 2026 · 11:12 UTC
Leak● 28
Filtración de código fuente de HD HyundaiA post shares a leaked data set from HD Hyundai, including source code, dated November 2025. Source-code exposure of a large industrial group can reveal credentials, internal systems and supply-chain details. It is included at low priority because it is months old and the affected entity is outside the LATAM region, so it is background rather than a live alert.Leak● 38
Base de datos de la criptoexchange Nexo (1,7M) republicadaA 1.7M-record Nexo database is being re-shared on BreachForums, dated May 2026 but tied to an earlier 2024 leak. It contains customer identity and KYC-type data valuable for account takeover and crypto-targeted fraud. The impact is real but reduced because the material is recycled rather than a new intrusion, so treat it as context, not a fresh alert.Leak● 45
Base de datos de 4,2M de registros personales de daryn.online a la ventaA 4.2 million-record personal database allegedly belonging to the Kazakh digital-services platform daryn.online is being circulated for sale. Dumps of citizen personal data of this size feed identity theft, fraud and targeted phishing against a broad user population. Organizations that integrate or federate with the platform should review exposure and monitor for downstream abuse.Leak● 52
Base de datos de 9,5M de usuarios del marketplace Lalafo a la ventaA threat actor is advertising a database of the Kyrgyz classifieds marketplace Lalafo containing more than 9.5 million fresh user records. Leaked marketplace data typically exposes names, phone numbers, emails and hashed or cleartext passwords, enabling credential stuffing, phishing and large-scale account takeover. Defenders should treat the Lalafo credentials as compromised and watch for reuse across other services.Leak● 34
Filtración de base de datos de la Autoridad Hospitalaria de Hong KongA forum user posted a downloadable dump allegedly taken from www.ha.org.hk, the Hong Kong Hospital Authority, a public healthcare body serving millions. If authentic it exposes patient and staff records useful for fraud, phishing and extortion. The post is dated 02-04-26, so it is not a fresh alert, but healthcare defenders outside the region should still verify exposure.Leak● 42
Filtración de la base de datos de la tienda de moda RomweThe Romwe database, belonging to a global fast-fashion e-commerce brand, has been reposted for download, potentially exposing customer emails, hashed passwords and order details. For defenders it is mainly useful for gauging credential-stuffing exposure affecting end users, not a regional target. Treat as corroborating material unless evidence of a genuinely new breach appears.