BRIEFLeakhighP78
Brazil citizens database offered for sale
Brasil (ciudadanos)
Detected16 September 2026 · 07:12 UTC
A threat actor is selling a database of Brazilian citizens' records, posted just minutes before collection on a dark web marketplace. The scale and personal nature of citizen data make it valuable for identity theft, fraud, and targeted phishing against Brazilian residents. Defenders in Brazil should watch for credential-stuffing and social-engineering campaigns reusing this data.
CategoryLeak
Severityhigh
Priority score78
Detected16 September 2026 · 07:12 UTC
Leak● 45
Filtración de base de datos de la Escuela Nacional de Seguridad de FranciaA database tied to ecolenationalesecurite.fr, a French security education institution, has been leaked for free on a hacking forum. Free public release lowers the barrier to abuse and may expose sensitive staff, student, or affiliated personal data. It matters for defenders tracking exposure of government and defense-adjacent organizations.Leak● 40
Publicación de datos OSINT de España en foro de filtracionesA freshly posted 'osint spain' thread in a leak forum appears to share OSINT or leaked data on Spanish individuals or entities. Spain is a Spanish-speaking region in scope, and fresh doxx/OSINT dumps can feed targeting, fraud or extortion. Impact looks limited so far but it is region-relevant and warrants monitoring.Leak● 48
Filtración de más de 15 millones de registros de credencialesA 15-million-line credential dump (URL:login:password) linked to Secretline.top and StarLinkClouds stealer logs is circulating across several forums. Volumes this large fuel credential stuffing and account takeover against corporate VPNs, email and cloud services. It is worth screening for reused government, banking or telecom credentials.Leak● 40
Base de datos alemana de 5 millones de líneas filtrada en siete partesA 5 million-line German credential database was shared in seven parts on BreachForums, gated to registered users. The volume suggests a sizable credential set potentially usable for account takeover and fraud. It sits outside the region with uncertain provenance, so it is a lower priority for AR-LATAM defenders.Leak● 30
Filtración de base de datos de la constructora francesa EiffageA database allegedly belonging to French infrastructure and construction giant Eiffage was posted for leak in early 2026. Eiffage runs major public-works and concession infrastructure, so any exposed customer, employee or project data is relevant to critical-infrastructure risk. The content is months old, so it is background context rather than an actionable fresh alert.Leak● 34
Filtración del correo del director del FBI Kash Patel por HandalaAn email leak attributed to the Iran-linked group Handala claims to expose data tied to US FBI Director Kash Patel. Handala has repeatedly targeted high-profile government figures, so it fits a broader influence and hack-and-leak campaign. The material dates to March 2026, making it useful context rather than a fresh alert.