BRIEFLeaklowP45
Dutch retailer time4toys.nl 140K customer database for sale
time4toys.nl
Detected12 September 2026 · 21:12 UTC
A seller is offering a 140,000-record database belonging to the Dutch retailer time4toys.nl in a DarkForums marketplace thread. The dataset likely contains customer personal and order data, enabling phishing and fraud against the shop's clients. It is a real named-company leak posted within the last month, though outside the AR-LATAM region.
CategoryLeak
Severitylow
Priority score45
Detected12 September 2026 · 21:12 UTC
Leak● 90
Filtración completa de base de datos de Clínica Nacional de ChileA full database from Chile's Nacional Clinic is being offered on DarkForums, apparently cross-referenced with RENAPER, Argentina's national identity registry, exposing patient and identity records. Chile is LATAM critical health infrastructure and RENAPER data would implicate Argentine government identity records. The post is brand-new, so defenders in health and national identity services should treat this as a live exposure.Leak● 44
Filtración de base de datos de la Universidad Helenística (800.000 registros)A threat actor claims to have hacked a subdomain and leaked an 800,000-record database from Helenistik University. If genuine, the dump exposes student and staff PII usable for fraud, doxing and credential-stuffing attacks. The claim comes from the TurkHackTeam/AnkaTeam collective and should be verified before use.Leak● 58
Filtración de base de datos de la Policía de Filipinas (393.000 registros)A database of 393,000 records attributed to the Philippines national police is being offered for sale, exposing officer names, ranks and contact details. Law-enforcement personnel data is high-value for targeted phishing, credential abuse and physical threats against officers. Though outside Latin America, it is a live government-sector leak a regional CTI desk should track.Leak● 60
Supuesta filtración de 33GB con bases de datos y claves API de StripeA forum listing claims 33GB of data from Stripe, covering 662 databases and 1033 API keys, is compromised. Stripe is a global payment processor whose leaked keys could enable fraudulent charges and downstream data access for merchants. Defenders should rotate keys and audit for anomalies, though the claim is unverified and may be repackaged marketing.Leak● 28
Filtración de datos CURP y RFC de ciudadanos mexicanosPersonal CURP and RFC records belonging to Mexican citizens were posted, apparently scraped from a scam site. These identifiers are used across Mexican government and tax services, so exposure enables identity theft and fraudulent procedures. Even a partial set is worth flagging for Mexican fraud-watch and KYC teams.Leak● 35
Base de datos del banco central de Indonesia (BI.GO.ID) filtradaA 5,000-record sample attributed to Bank Indonesia (BI.GO.ID) is circulating, presenting the country's central bank as a target. Although small and dated early 2025, even partial data from a central bank threatens customer and staff privacy and enables targeted social engineering. Monitor for a fuller dump or reuse of these identifiers.