BRIEFLeakhighP68
Spanish citizen database with 20M records and financial data for sale
Detected8 October 2026 · 10:07 UTC
A seller on DarkForums is advertising a 20-million-record database of Spanish citizens that reportedly includes financial data. Such a dataset fuels identity theft, targeted phishing with accurate personal details, and fraud against banking customers. Spanish banks and public bodies should treat it as a fresh PII and financial-exposure risk and prepare customer notifications.
CategoryLeak
Severityhigh
Priority score68
Detected8 October 2026 · 10:07 UTC
Leak● 40
ShinyHunters publica base de datos ANTS de 13,1 millonesShinyHunters posted a 13.1M-record database named 'ANTS' to BreachForums, a large dump from a known prolific group. The post dates from June 2026 and is not fresh, so it is not a new alert, but its scale makes credential reuse and follow-on attacks likely. Useful for tracking past exposure and credential hygiene.Leak● 62
Base de datos B2B de EE.UU. con 31M de registros a la ventaA seller is offering a US-focused B2B database of 31M+ business records labelled 'fresh 2026', likely containing company contacts and firmographic data. Such datasets directly fuel targeted BEC, phishing and lead-generation fraud. Organizations in the dataset should anticipate a rise in social-engineering attempts.Leak● 70
Filtración de base de datos y código fuente de smpw.netA threat actor is publishing a full database dump plus the underlying source code of smpw.net, a Jehovah's Witnesses platform, in a very recent post. Exposed data likely includes member accounts and personal details, enabling credential stuffing and phishing against a large, identifiable user base. Defenders should treat any reused credentials as compromised.Leak● 42
Base de datos de COVID de Brasil (2021-2023) republicada en un foroA database labelled as Brazilian COVID data covering 2021-2023 is being re-posted in a darkweb marketplace. It concerns health-related personal data, a sensitive category under Brazil's LGPD, although the underlying records are several years old. Brazilian health authorities and partners should verify exposure and assess notification duties.Leak● 46
Filtración de 2.500 registros de infostealer de equipos Windows en MéxicoAn Aurora infostealer log pack covering roughly 2,500 compromised Windows 10 Enterprise machines in Mexico is being shared for free. Such logs typically contain browser credentials, cookies and session tokens that enable account takeover and lateral movement. Mexican organizations should hunt for exposed corporate credentials and reset affected accounts.Leak● 56
Venta de archivos sensibles de KPMG con muestra gratuitaA threat actor is posting a free sample of allegedly sensitive internal KPMG documents to advertise a larger paid sale. KPMG is a global audit and consulting firm whose internal files can include confidential client and public-sector engagements. Client organizations and KPMG itself should watch for follow-on phishing, extortion or data-driven attacks.