BRIEFLeakhighP55
Chinese on-demand massage platform database for sale
Chinese on-demand massage service platform
Detected24 September 2026 · 09:51 UTC
A threat actor is selling a Chinese on-demand massage platform database with roughly 7.5 million orders and 1.8 million users, including names, phone numbers and payment data. Although the victim is outside Latin America, the scale makes it a notable bulk-data sale. Buyers could enable large-scale fraud and downstream phishing.
CategoryLeak
Severityhigh
Priority score55
Detected24 September 2026 · 09:51 UTC
Leak● 52
Venta de datos de usuarios alemanes de BinanceA seller is offering German Binance customer data described as '100% active numbers', posted 13 September 2026. Crypto-exchange user data fuels account takeover, phishing and SIM-swap fraud against high-value targets. A recent financial-sector PII leak remains actionable for fraud and CTI teams.Leak● 50
Base de datos de las elecciones de Marruecos publicada en foroA forum user posted a database allegedly tied to Morocco's elections, published today. Election data can enable disinformation, targeting of officials and foreign interference. Although outside LATAM, fresh government election leaks are high-value and should be flagged for monitoring.Leak● 58
Filtración de 50.000 registros del dominio VUCE.gov.co de ColombiaA 50,000-record database tied to Colombia's VUCE foreign-trade government portal (vuce.gov.co) is being traded on a Russian-language forum. It exposes official trade and company information useful for BEC, identity fraud and mapping Colombian state systems. Though posted back in March 2026 it remains a LATAM government data exposure worth tracking.Leak● 35
Filtración de datos de Grupo Hasar publicada en foroA dumped database tied to Grupo Hasar, a Latin American electronics group, is being shared on DarkForums. The post dates to August 2025, so it is stale and likely already traded, but exposed customer or employee PII could still fuel fraud. Worth tracking for credential reuse.Leak● 38
Stealer log de 357.000 credenciales URL:login:pass publicadoA stealer log containing roughly 357,000 URL:login:password entries was released by 'Napoleon' and mirrored across several forums. Stealer logs pair credentials with the exact site and often session data, making them directly usable for credential stuffing and account takeover. Although not region-specific, the volume and freshness justify checking for your users' corporate credentials.Leak● 40
Dump de 960.000 credenciales URL:login:pass publicadoA forum user published a 960,000-line URL:login:password credential dump labelled 'UHQ FRESH SEP', indicating recently harvested stealer/combolist data. The scale and 'fresh' label mean many entries are likely still valid, feeding credential stuffing, account takeover and initial-access attempts across many services. Defenders should enforce credential-stuffing detection and MFA on any exposed accounts.