BRIEFLeakhighP48
Database of 450,000 hardware wallet users offered for sale
Ledger/Trezor/SafePal/OneKey users
Detected2 October 2026 · 12:45 UTC
A seller advertises a 450,000-record database of personally identifiable data on users of hardware wallets (Ledger, Trezor, SafePal, OneKey) as fresh 2026 private leads. Such data drives highly targeted phishing and crypto-theft against high-value victims. Crypto and financial defenders should warn affected customers and watch for follow-on social engineering.
CategoryLeak
Severityhigh
Priority score48
Detected2 October 2026 · 12:45 UTC
Leak● 45
Venta de más de 6.000 documentos de identidad españoles y de la UEA DarkForums seller offers 6,000+ Spanish and EU identity documents (passports, national IDs and similar) intended for fraud and KYC bypass. Such material enables impersonation, account takeover and loan or benefit fraud against Spanish-speaking victims. The batch is not recent, but it remains usable and is relevant to Spanish/LATAM fraud defenders.Leak● 62
Filtración de 579 GB de datos de hardware y dispositivos de SamsungA forum user posted a 579 GB archive claiming to contain Samsung hardware and device source code and internal data, shared minutes before collection. If authentic it exposes proprietary firmware and design material for a major global manufacturer, enabling IP theft and supply-chain attacks. Hardware, telecom and electronics defenders should verify the claim and monitor for downstream abuse.Leak● 44
Volcado de 1,8 millones de credenciales ULP publicado en DarkForumsA fresh stealer-log dump labeled '1800000_ULP' (~1.8 million URL:login:password entries) was posted on DarkForums minutes before collection, with mirrors already appearing on Niflheim and xReactor. It is aggregated malware-harvested credentials rather than a breach of a single named organization, so it mainly fuels credential-stuffing and account takeover. Defenders should ingest the domains/emails for exposure checks and force resets on any matching corporate accounts.Leak● 40
Base de datos de John Hay Management Corp. (Filipinas) filtradaA Spear Leaks post from March 2026 offers a database belonging to John Hay Management Corporation, a Philippine government-owned firm. The data is already some months old, so it is not a fresh alert, but the target is a public-sector entity and the leak still aids fraud and further intrusion. Worth noting for regional context rather than urgent response.Leak● 46
Filtración de base de datos de Youplanet.app con 40.000 usuariosA DarkForums post shares a 40,000-record database from Youplanet.app containing usernames, names, IDs and emails, allegedly exfiltrated by a user named @zimablue. The scale is moderate but the records are personal data that enable phishing and account takeover. It matters mainly for affected users and for tracking the actor's activity.Leak● 42
Filtración de copias de seguridad y base de datos SQL de mrlenorman.gr (Grecia)Full website backup files plus the SQL database of the Greek site mrlenorman.gr are being shared, exposing the site's content, user and order data. A complete backup can reveal configuration secrets and credentials, enabling further compromise of the site and its customers. Defenders should assume source and database exposure and rotate secrets.