BRIEFLeakhighP52
Binance database of 1.5 million users for sale
Binance
Detected24 September 2026 · 07:51 UTC
A carding-forum seller claims to hold a 1.5-million-record Binance user database, likely assembled from credential stuffing or an older breach. If genuine it exposes crypto customers to account takeover and targeted phishing. Binance's large Latin American user base makes it relevant, though the recycled '2026' framing suggests limited freshness.
CategoryLeak
Severityhigh
Priority score52
Detected24 September 2026 · 07:51 UTC
Leak● 38
Stealer log de 357.000 credenciales URL:login:pass publicadoA stealer log containing roughly 357,000 URL:login:password entries was released by 'Napoleon' and mirrored across several forums. Stealer logs pair credentials with the exact site and often session data, making them directly usable for credential stuffing and account takeover. Although not region-specific, the volume and freshness justify checking for your users' corporate credentials.Leak● 40
Dump de 960.000 credenciales URL:login:pass publicadoA forum user published a 960,000-line URL:login:password credential dump labelled 'UHQ FRESH SEP', indicating recently harvested stealer/combolist data. The scale and 'fresh' label mean many entries are likely still valid, feeding credential stuffing, account takeover and initial-access attempts across many services. Defenders should enforce credential-stuffing detection and MFA on any exposed accounts.Leak● 45
Cookies de sesión activas de Walmart, LinkedIn y redes sociales a la ventaA threat actor is trading '2f' accounts for Walmart, LinkedIn, Nextdoor, Instagram, Facebook and Twitter bundled with active email session cookies, i.e. takeover-ready access rather than plain credentials. Active cookies let buyers bypass passwords and often 2FA, enabling immediate account takeover and lateral phishing. Organizations on these platforms should force re-authentication and hunt for anomalous session activity.Leak● 72
Filtración de la base de datos de Bureau van Dijk (Orbis) a la ventaA DarkForums seller is offering a 2025-2026 leak of Bureau van Dijk's corporate data, the Moody's-owned Orbis business-intelligence platform (posted 21 Sep 2026). It holds financial, ownership and executive records on millions of companies worldwide. If genuine, this is high-value corporate/KYC intelligence for BEC, fraud and supply-chain mapping, so defenders should watch for downstream abuse of leaked business records.Leak● 74
Filtración de 42 GB de datos de McDonald's EcuadorA threat actor is distributing a 42 GB dataset allegedly exfiltrated from mcdonalds.com.ec, the Ecuadorian McDonald's operator. A volume that large usually contains customer, HR, supplier and internal business records, enabling fraud, phishing and follow-on intrusion. It signals an active breach of a major consumer brand in Latin America, worth alerting regional defenders.Leak● 33
Filtración de datos de 34.500 clientes de Ronis AustraliaA threat actor posted a database containing 34,500+ customer records belonging to the Australian company Ronis on a leak forum in mid-June 2026. The dataset likely holds customer PII usable for phishing, fraud, and credential abuse. It is a genuine named-org leak, but it is outside the AR/LATAM region and already weeks old, so it is not a fresh alert.