BRIEFLeakhighP45
4.2M-record personal database of Kazakhstan's daryn.online for sale
Daryn.online (Kazajistán)
Detected12 September 2026 · 10:12 UTC
A 4.2 million-record personal database allegedly belonging to the Kazakh digital-services platform daryn.online is being circulated for sale. Dumps of citizen personal data of this size feed identity theft, fraud and targeted phishing against a broad user population. Organizations that integrate or federate with the platform should review exposure and monitor for downstream abuse.
CategoryLeak
Severityhigh
Priority score45
Detected12 September 2026 · 10:12 UTC
Leak● 52
Base de datos de 9,5M de usuarios del marketplace Lalafo a la ventaA threat actor is advertising a database of the Kyrgyz classifieds marketplace Lalafo containing more than 9.5 million fresh user records. Leaked marketplace data typically exposes names, phone numbers, emails and hashed or cleartext passwords, enabling credential stuffing, phishing and large-scale account takeover. Defenders should treat the Lalafo credentials as compromised and watch for reuse across other services.Leak● 34
Filtración de base de datos de la Autoridad Hospitalaria de Hong KongA forum user posted a downloadable dump allegedly taken from www.ha.org.hk, the Hong Kong Hospital Authority, a public healthcare body serving millions. If authentic it exposes patient and staff records useful for fraud, phishing and extortion. The post is dated 02-04-26, so it is not a fresh alert, but healthcare defenders outside the region should still verify exposure.Leak● 42
Filtración de la base de datos de la tienda de moda RomweThe Romwe database, belonging to a global fast-fashion e-commerce brand, has been reposted for download, potentially exposing customer emails, hashed passwords and order details. For defenders it is mainly useful for gauging credential-stuffing exposure affecting end users, not a regional target. Treat as corroborating material unless evidence of a genuinely new breach appears.Leak● 47
Filtración de base de datos de 52 millones de registros de UcraniaA thread advertises a 52-million-record Ukrainian database in a 'fresh leaks' section, reportedly containing citizen or service data. Even though it is outside the LATAM scope, its scale makes it relevant for identity-theft and credential-reuse monitoring across downstream services. Verify freshness and actual record contents before acting on it.Leak● 62
Filtración de documentos de Yucatán, MéxicoA freshly posted thread (about 1 hour old) shares a pack of documents attributed to Yucatán, Mexico, promoted alongside Telegram channels whose names reference attacking governments. The exact record count and whether the files come from state/municipal entities are not yet confirmed, but the targeting pattern points to a government or public-sector source. Defenders in Mexican government and critical-infrastructure entities should treat this as a possible breach lead and monitor for reuse of the data.Leak● 42
Base de datos de médicos del hospital Hermina Palembang (Indonesia) filtradaA fresh forum post advertises a database attributed to Doctors/Hermina Palembang, a hospital network in Indonesia, reportedly containing doctor/medical records. Healthcare data is highly sensitive and enables targeted fraud, phishing and extortion against staff and patients. Though outside the LATAM region, it reflects ongoing hospital-sector exposure worth tracking for regional analogues.