BRIEFLeaklowP40
Philippines' John Hay Management Corporation database leaked
John Hay Management Corporation (Philippines)
Detected2 October 2026 · 10:45 UTC
A Spear Leaks post from March 2026 offers a database belonging to John Hay Management Corporation, a Philippine government-owned firm. The data is already some months old, so it is not a fresh alert, but the target is a public-sector entity and the leak still aids fraud and further intrusion. Worth noting for regional context rather than urgent response.
CategoryLeak
Severitylow
Priority score40
Detected2 October 2026 · 10:45 UTC
Leak● 44
Volcado de 1,8 millones de credenciales ULP publicado en DarkForumsA fresh stealer-log dump labeled '1800000_ULP' (~1.8 million URL:login:password entries) was posted on DarkForums minutes before collection, with mirrors already appearing on Niflheim and xReactor. It is aggregated malware-harvested credentials rather than a breach of a single named organization, so it mainly fuels credential-stuffing and account takeover. Defenders should ingest the domains/emails for exposure checks and force resets on any matching corporate accounts.Leak● 46
Filtración de base de datos de Youplanet.app con 40.000 usuariosA DarkForums post shares a 40,000-record database from Youplanet.app containing usernames, names, IDs and emails, allegedly exfiltrated by a user named @zimablue. The scale is moderate but the records are personal data that enable phishing and account takeover. It matters mainly for affected users and for tracking the actor's activity.Leak● 42
Filtración de copias de seguridad y base de datos SQL de mrlenorman.gr (Grecia)Full website backup files plus the SQL database of the Greek site mrlenorman.gr are being shared, exposing the site's content, user and order data. A complete backup can reveal configuration secrets and credentials, enabling further compromise of the site and its customers. Defenders should assume source and database exposure and rotate secrets.Leak● 45
Filtración de 150K cuentas de criptomonedas (Binance, Coinbase, TrustWallet)A 150K-line credential set specifically targeting crypto users of Binance, Coinbase and TrustWallet is circulating, indicating a focused campaign against exchange and wallet accounts. Credentials of this kind feed account takeover and wallet draining, with direct financial loss. Exchange and wallet operators should monitor for stuffing and force re-authentication.Leak● 55
Base de datos SQL de 4GB de aesdistribution.com a la ventaA DarkForums listing offers a 4GB SQL/CSV database from aesdistribution.com, a commercial distributor. A multi-gigabyte database usually means customer, order and business records, exposing both the company and its clients. Such leaks fuel credential stuffing, fraud and B2B targeting and deserve monitoring.Leak● 42
Colección de datos de China: educación, telecomunicaciones, banca y logísticaA collection claiming Chinese data from education, telecom, banking and logistics sectors is posted for distribution. If authentic, it aggregates multiple industry datasets that can fuel credential stuffing, fraud and targeting of Chinese organizations. The date and provenance are unclear, lowering its immediate alerting value for regional defenders.