BRIEFLeakhighP78
India's Aadhaar national ID database offered for sale on BreachForums
India – Aadhaar (UIDAI)
Detected15 September 2026 · 04:12 UTC
A database tied to India's Aadhaar national biometric ID programme, which covers over a billion citizens, is being advertised on BreachForums in early September 2026. Aadhaar data underpins banking, telecom SIM issuance and government welfare, so exposure enables mass identity fraud, SIM-swap and targeted phishing. Defenders should treat this as a national-identity exposure event and watch for downstream abuse.
CategoryLeak
Severityhigh
Priority score78
Detected15 September 2026 · 04:12 UTC
Leak● 40
10 millones de registros URL:login:password de stealer a la ventaA DarkForums listing from 28 May 2026 offers a private 10-million-line URL:login:password stealer log collection marked as HQ. Credential dumps of this size fuel credential stuffing and account takeover across many services. However the post is several months old, so it is background material rather than a fresh alert.Leak● 50
Base de datos KYC de Indonesia con más de un millón de registros a la ventaA BreachForums thread dated 4 July 2026 offers an Indonesian KYC dataset of over one million records for sale. KYC data typically includes government IDs, selfies and proof-of-address, ideal for account opening fraud and money laundering. It is significant in scale but roughly two months old, so it is no longer a fresh alert.Leak● 55
Filtración gratuita de 774.000 registros escolares de EE. UU.A freshly posted DarkForums thread on 15 September 2026 is giving away a database of 774,000 US school-related records for free. Free distribution maximises spread and enables downstream phishing, account takeover and targeting of minors or staff. It matters for defenders tracking education-sector exposure, though it is outside the LATAM region.
Leak● 32
Base de datos B2B de EE.UU. con 54M de contactos a la ventaA seller advertises a US B2B database with over 54 million contact records on DarkForums. This is marketing/lead data rather than credentials, so direct compromise risk is limited, but it enables large-scale business phishing and spam. No regional or critical-infrastructure impact.Leak● 45
Base de datos de Ingram Content Group publicada en un foroA DarkForums user is offering a database attributed to Ingram Content Group, a large US book distributor. If genuine, the dump could hold business, customer or partner data useful for fraud and targeted intrusion. It is not a LATAM target and the post is not fresh, so priority is moderate.Leak● 34
Combolista de 126.000 credenciales de correo de PerúA 126K-line Peru-tagged email:password combolist was posted as 'FRESH', exposing credentials that feed credential-stuffing and account takeover. It is regionally relevant for LATAM defenders as recycled access material. Value is moderate since it is a combolist rather than a confirmed compromise of a specific organization.