BRIEFLeakhighP48
Customer database of 65,000 from Zimbabwe SPAR store for sale
spar.co.zw
Detected26 September 2026 · 16:16 UTC
A vendor is selling a customer database of about 65,000 records from the Zimbabwean online store spar.co.zw, a real retail organization. The data reportedly includes customer PII that can feed phishing, fraud and credential-stuffing attacks against those individuals. It is a confirmed breach of a named company but outside the LATAM region, lowering its priority for a regional operator.
CategoryLeak
Severityhigh
Priority score48
Detected26 September 2026 · 16:16 UTC
Leak● 32
Filtración del sitio web de la contratista Cleveland Bridge (Arabia Saudí)A moderator posted a leak affecting the website www.clevelandbridge.sa, a contracting company based in Saudi Arabia. The scope and data types are unclear from the thread, and the target is a single mid-size firm outside Latin America. It is worth noting for completeness but carries low defensive urgency for a regional CTI operator.Leak● 49
Base de datos de 65.000 clientes de la tienda SPAR de Zimbabue a la ventaA seller is offering a customer database of roughly 65,000 records belonging to the Zimbabwean online store spar.co.zw. The dataset likely includes names, contact details and purchase history of real customers. Although outside LATAM, it is a genuine real-organization data exposure worth tracking for credential-stuffing and fraud follow-on.Leak● 62
Filtración de base de datos de pasaportes e identidades de IsraelA hacking forum is circulating what is claimed to be a full database of Israeli passport and identity records. If authentic, this is a mass PII exposure enabling identity theft and fraud at national scale. It warrants verification and victim-notification preparedness even though it falls outside the LATAM region.Leak● 38
Filtración de base de datos de 2,2 millones de usuarios de DUPR (pickleball)A database containing 2.2 million DUPR pickleball accounts is being circulated, with full name, home address, email and phone number. The data enables identity theft, phishing and SMS-based attacks against a large consumer base. Defenders whose users reuse credentials should flag the exposure and watch for targeted phishing.Leak● 45
Filtración de más de 10 millones de registros de la base de datos de JKT48.comA full database from the Indonesian site JKT48.com is offered, claiming over 10 million records including Gmail addresses, NIK national ID numbers and phone numbers. The inclusion of national identifiers significantly raises the risk of fraud and impersonation. Leaks of this scale deserve monitoring even outside the region because of credential reuse.Leak● 44
Base de datos con PII de 450.000 usuarios de monederos hardware a la ventaA private 450,000-record PII dataset of users of hardware wallets (Ledger, Trezor, SafePal, OneKey) is being marketed across multiple carding forums as '2026 private leads'. Although it is fraud-focused rather than government-related, it is a large, fresh personal-data set that enables targeted phishing, SIM-swap and crypto-theft campaigns against high-value holders. Its mass cross-forum promotion lowers urgency somewhat.