BRIEFLeakhighP58
1.4M-user Propertyfinder.ae database for sale
Propertyfinder.ae
Detected8 October 2026 · 15:22 UTC
A seller is offering a 1.4 million-record database of Propertyfinder.ae, a major UAE real-estate platform. The dump likely contains names, emails and phone numbers, enabling phishing, real-estate fraud and account takeover. Large regional PII leaks like this get reused fast by fraud and spam campaigns.
CategoryLeak
Severityhigh
Priority score58
Detected8 October 2026 · 15:22 UTC
Leak● 22
Base de datos de 23,5 millones de ciudadanos de Taiwán (2022) recirculadaA 23.5M-row Taiwan citizens database originally leaked in October 2022 is being recirculated. It is old, so not a fresh incident, but the scale and government-linked PII keep it valuable for identity fraud and social engineering. Treat it as historical context, not an active alert.Leak● 38
Combolist de 2,8 millones de credenciales filtradasA large 2.8 million-line ULP (email/password) combolist has been posted. While generic and undated, its size makes it useful for credential-stuffing campaigns against services with password reuse. Defenders should enforce MFA and monitor for reuse of these credentials on exposed logins.Leak● 40
Base de datos de 417.000 contactos de empresarios de EAU a la ventaA vendor is selling a 417k-contact database of UAE business owners, likely harvested from directories or registries. Business-contact lists fuel BEC, investment and phishing scams targeting executives. Low-technical but monetizable, it is worth noting for regional fraud monitoring.Leak● 48
100.000 registros de transacciones de PayPal de EE. UU. a la ventaA poster is selling 100,000 US PayPal transaction records dated 2026. If genuine, the dataset exposes account, transaction and possibly identity data used for fraud and account takeover. Fraud teams should treat it as a potential privacy/fraud incident pending validation of the sample.Leak● 50
Filtración de SCADA/HMI de una línea de embotellado en FranciaA collection labeled as a SCADA/HMI system for a beer bottling and automated packaging line in France is being shared. Industrial control dumps reveal PLC/HMI details, credentials and network layouts that enable disruptive attacks. Asset owners should audit exposed interfaces and rotate PLC/HMI credentials.Leak● 60
Filtración de sistemas SCADA de una estación de servicio en EE. UU.A leak labeled TRK25 exposes SCADA/industrial systems of a US gas station, including HMI or control-logic data. Exposed OT details can reveal network topology, default credentials and process controls useful for sabotage. OT defenders should review remote access and segment control networks immediately.