PULSE
FEED
ransomdeadlock reclama a Saber1 · US · Not Foundransomdeadlock reclama a idi pharma · ES · Healthcareransomsafepay reclama a hoteldelfinolugano.ch · CH · Hospitalityransomsafepay reclama a dwi-bau.de · DE · Otherransompanzer reclama a Supreme Energy · SG · Energy & Utilitiesransompanzer reclama a solutend · Technologyransomqilin reclama a Vadeto Group · SE · Not Foundransomrhysida reclama a Anne Arundel County · US · Government & Defenseransomthreeam reclama a fleetworksinc.com · US · Transportationransomthegentlemen reclama a TGN · AR · Not Foundransomthegentlemen reclama a Galil Engineering · IL · Manufacturingransomthegentlemen reclama a Smart Value · BZ · Retail & E-Commerceransomthegentlemen reclama a Kooltronic · US · Manufacturingransomthegentlemen reclama a Skyplan Services · Professional Servicesransomdeadlock reclama a Saber1 · US · Not Foundransomdeadlock reclama a idi pharma · ES · Healthcareransomsafepay reclama a hoteldelfinolugano.ch · CH · Hospitalityransomsafepay reclama a dwi-bau.de · DE · Otherransompanzer reclama a Supreme Energy · SG · Energy & Utilitiesransompanzer reclama a solutend · Technologyransomqilin reclama a Vadeto Group · SE · Not Foundransomrhysida reclama a Anne Arundel County · US · Government & Defenseransomthreeam reclama a fleetworksinc.com · US · Transportationransomthegentlemen reclama a TGN · AR · Not Foundransomthegentlemen reclama a Galil Engineering · IL · Manufacturingransomthegentlemen reclama a Smart Value · BZ · Retail & E-Commerceransomthegentlemen reclama a Kooltronic · US · Manufacturingransomthegentlemen reclama a Skyplan Services · Professional Services
Kalir Brief · Item10 October 2026 · 13:21 UTC
BRIEFLeakhighP70

Mecourier (UAE) database of 31M records for sale

Mecourier (mecourier.ae)

Detected10 October 2026 · 13:21 UTC
Why it matters

A seller is offering a database of roughly 31 million records allegedly taken from Mecourier, a UAE courier and logistics company. If authentic, it exposes customer names, contact details and delivery data, fueling phishing, SIM-swap and fraud campaigns. Large logistics datasets also help attackers map operational and vendor relationships.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score70
Detected10 October 2026 · 13:21 UTC
Related items6
Leak● 30
Combolist de 52.179 credenciales de Chile publicado en foroA freshly posted combolist contains roughly 52,179 email/password pairs attributed to Chile. The volume is modest, but the set can fuel credential-stuffing and account-takeover against Chilean online services and public portals. Defenders should screen for password reuse and force resets on affected accounts.
14m
Leak● 66
Venta de base de datos de la plataforma educativa española Fiction Express (725 GB)A seller is offering a 725 GB database allegedly belonging to Fiction Express, a Spanish digital reading and education platform used by schools. Such a volume could expose student, parent and teacher accounts plus internal data across many institutions. Education-sector defenders in Spain should watch for credential reuse, phishing against schools, and account-takeover attempts.
14m
Leak● 48
Base de datos de Standard Gas con 4M de registros a la ventaA threat actor is selling a database of about 4 million records attributed to Standard Gas. The data fields are unverified, but if it holds customer or operational information it enables targeted phishing and fraud. Any energy-sector victim also raises the possibility of critical-infrastructure exposure.
1h
Leak● 55
Divulgación de brecha de datos de Pathao LimitedAn actor is publishing an ongoing breach disclosure against Pathao, a major Bangladeshi ride-hailing, delivery and payments platform. The continuing nature suggests active access and further exfiltration, affecting a large base of users and drivers. Exposed PII and payment data could drive fraud and account takeover.
1h
Leak● 33
Base de datos de OpenCorporates republicada en un foroThe full OpenCorporates corporate registry dataset has been reposted, a large aggregation of company and officer records useful for identity fraud and B2B targeting. The post is dated August 2025, so it is a stale re-post rather than a fresh breach. Still relevant for data-exposure and third-party risk tracking.
2h
Leak● 38
Volcado de 2,8 millones de credenciales de stealer logs (URL:LOGIN:PASS)A dump of about 2.8 million URL:LOGIN:PASSWORD records, likely harvested by infostealers, was posted. Such credentials enable credential stuffing and initial access against corporate email and VPN portals. Organisations should check exposure and force resets on affected accounts.
2h