BRIEFLeakhighP60
Salt.ch database with 1.09 million records for sale
Salt.ch
Detected21 September 2026 · 14:37 UTC
A seller is offering a Salt.ch database with more than 1,090,000 records, likely containing customer names, emails and related personal data. Such a dump feeds credential-stuffing, phishing and account-takeover campaigns against the provider and its users. A million-record leak of a named company is a substantial, actionable exposure for defenders.
CategoryLeak
Severityhigh
Priority score60
Detected21 September 2026 · 14:37 UTC
Leak● 44
Base de datos del sitio ruso ibiw.ru (726K registros) filtradaThe 'AnkaTeam' group published a 726,000-record database allegedly belonging to the Russian site ibiw.ru. The dump contains personal and account data that can fuel credential-stuffing and targeted phishing against the company's users. It is a mid-sized but genuine breach of a named organization, notable mainly for the volume and the actor behind it.Leak● 38
Venta de datos de traders de Forex de EspañaA marketplace seller is offering a fresh lead list of Spanish forex traders dated 2025-2026. It likely contains names, emails and phone numbers of retail investors, enabling targeted phishing and financial fraud. It is regionally relevant but is a lead list rather than a breach of critical infrastructure.Leak● 72
Filtración de base de datos de Bureau Van Dijk (Moody's)A threat actor claims to have leaked a large database belonging to Bureau Van Dijk, a Moody's subsidiary that aggregates private-company and financial data (e.g. Orbis). If genuine, this exposes extensive corporate records used for due diligence, KYC and credit decisions. Defenders should track downstream credential abuse and business-intelligence targeting.Leak● 33
Venta de base de datos del internado Darussalam GontorA seller is offering the database of Darussalam Gontor, a large Indonesian Islamic boarding school, on a hacking forum posted minutes ago. If genuine, it exposes student, staff and possibly parent records. It is a real but low-impact education-sector leak outside Latin America, worth noting only as a data-sale trend indicator.Leak● 60
Base de datos de PII mexicanos de Cosmotienda publicada gratisA threat actor released a database of Mexican citizens' personal information (PII) tied to cosmetics retailer Cosmotienda, posted for free on a carding forum. The dataset exposes customer names and contact details usable for fraud, phishing and identity theft in Mexico. For LATAM defenders it signals fresh regional PII exposure and likely downstream credential-stuffing and scam campaigns.Leak● 40
Comparten volcado masivo de 13,5 millones de credenciales URL:usuario:contraseñaA dump advertised as 13.5M URL:login:password records is circulating through the 'vulta.pw' shop, a large fresh credential corpus that can fuel credential stuffing and account takeover. Aggregated logs of this size frequently include government and corporate email access. Defenders should assume their users' credentials are exposed and enforce resets and MFA.