BRIEFLeakhighP52
976K FedEx/UPS USA customer records offered for sale
FedEx / UPS (clientes)
Detected30 September 2026 · 04:18 UTC
A 976K 'new 2026' private database of FedEx/UPS USA account data is being sold on DarkForums, the largest of a series of logistics combos. Such data feeds parcel-rerouting fraud, account takeover and credential stuffing against corporate shipping portals. Carriers and their business customers should review access controls and monitor for fraudulent delivery changes.
CategoryLeak
Severityhigh
Priority score52
Detected30 September 2026 · 04:18 UTC
Leak● 48
Filtración de base de datos de la app china de masajes AngemoA Chinese on-demand massage platform (angemo.com) was compromised, exposing roughly 7.5 million orders and 1.8 million user records including therapists and merchants. The dataset contains PII and transactional data usable for fraud, account takeover and customer targeting. It is a sizable real-organization leak worth tracking, though it has no direct AR-LATAM nexus.Leak● 38
Filtración de 337.000 credenciales alemanas (D4RKNETHUB Cloud)A 337.3K mail:pass combo targeting German users was published via the D4RKNETHUB cloud, dated 29 September 2026. It is credential-stuffing fuel rather than a breach of a single named victim, so impact is diffuse. Defenders in Germany and adjacent EU sectors should check exposure of corporate mail accounts and enforce MFA.Leak● 46
Base de datos de clientes de FedEx y UPS (688.000 registros) a la ventaA 688K database of FedEx/UPS delivery accounts is being sold as 'fresh and private' on DarkForums. It appears to bundle customer and shipping-login records used for parcel fraud and account takeover. Logistics, e-commerce and anyone relying on these carriers should watch for fraudulent rerouting and business-email-compromise abuse.Leak● 60
Venta de dump de 5,56 millones de credenciales URL:LOG:PASS en DAXUS.PROA dump of roughly 5.56 million URL:LOG:PASS stealer records is being advertised on the DAXUS.PRO marketplace. The volume and log format mean many corporate web logins, session cookies and internal portals are likely included. Any organization with exposed web authentication should treat this as an active credential leak and force resets where relevant.Leak● 74
Filtración de fotos y nombres de pacientes de San Juan Andes HealthA threat actor is publishing patient photos alongside the full names of individuals identified as patients of San Juan Andes Health, exposing highly sensitive medical PII/PHI. The leak enables targeted fraud, extortion and doxxing of patients, and points to a probable breach of a regional healthcare provider in the Andes/San Juan area. Health entities are critical infrastructure, so the affected organisation should urgently verify exposure, contain the source and notify regulators.Leak● 55
Filtración de base de datos del Ministerio de Servicio Civil de TaiwánA leaked database belonging to Taiwan's Ministry of Civil Service is being shared for download, exposing sensitive records of government employees and citizens. Civil-service and HR data of this kind enables identity theft, targeted phishing and possible espionage against public-sector staff. Public-administration defenders should treat affected accounts as compromised and watch for follow-on abuse.