BRIEFLeakhighP42
Salesforce / Data.com B2B leads database (231K records) for sale
Data.com / Salesforce B2B leads
Detected7 October 2026 · 00:07 UTC
A 231K+ record B2B leads database attributed to Data.com/Salesforce is offered for sale. It contains business contact and firmographic data useful for targeted phishing and account takeover. Direct impact is lower, but it is valuable for social-engineering campaigns against enterprises.
CategoryLeak
Severityhigh
Priority score42
Detected7 October 2026 · 00:07 UTC
Leak● 45
Volcado privado de 120 millones de credenciales URL:login:contraseñaA seller is offering a private dump advertised as 120 million URL:login:password (ULP) credentials, posted only minutes before collection. Stealer-log datasets of this size fuel credential stuffing, account takeover and initial access across many sectors. It is not tied to a specific named victim, so priority is lower, but the scale warrants monitoring.Leak● 70
Filtración de la base de datos de clientes de CTT (Correos de Portugal)A customer database belonging to CTT, Portugal's national postal operator, is listed on DarkForums as a 2026 leak. Postal services hold millions of names, addresses, phone numbers and often payment and tracking data, and CTT is core national infrastructure. A fresh dump exposes citizens to phishing and parcel-fraud scams and can enable account takeover of CTT services.Leak● 46
Base de datos de usuarios de Nexus Mods filtrada y compartidaAttackers are circulating a leaked database tied to Nexus Mods, a popular game-modding platform with millions of accounts, in a post dated October 6. Emails and credentials from the dump feed credential-stuffing against other services. Though not government or LATAM, the scale and recency warrant monitoring for password reuse.Leak● 56
Filtración de bases de datos del centro de servicios al ciudadano de Libia (csc.gov.ly)Sensitive databases and files belonging to Libya's Citizen Service Center (csc.gov.ly) are being shared on a leak forum. This national government portal exposure likely includes citizen personal data and internal documents, enabling identity fraud and follow-on intrusion. Regional CTI teams should track the dump and its reused infrastructure.Leak● 60
Base de datos de 36 sitios web gubernamentales de EE. UU. a la ventaA BreachForums thread advertises a 2026 database said to cover 36 U.S. government, federal and state websites. If genuine, it could expose citizen records, employee accounts or site credentials for public bodies. Government data leaks of this kind enable phishing, impersonation and account takeover against public services.Leak● 30
Base de datos de France Travail (44,3M) recompilada, filtración de 2024The France Travail database, from France's national employment agency, with 44.3 million records is being re-shared, but it corresponds to the 2024 breach and the post itself is from 2025. It contains names, social security numbers and contact details. It is stale and already known, so it only merits a low-priority mention.