BRIEFLeakhighP47
Database 'PdiHealt' posted on underground forum
PdiHealt (entidad no confirmada)
Detected10 September 2026 · 16:12 UTC
A newly registered member posted a database file labelled 'PdiHealt_AS_Data' to a darkweb forum, pointing to an exposed health- or PDI-linked dataset. The volume and contents are not yet confirmed, but any medical or police-related records are highly sensitive for credential stuffing, identity theft and downstream fraud. Defenders in the health and public-security sectors should verify whether the data belongs to their organization.
CategoryLeak
Severityhigh
Priority score47
Detected10 September 2026 · 16:12 UTC
Leak● 32
Volcado de 5 millones de credenciales de stealer (url:log:pass)Actor 'Napoleon' posted a fresh dump of roughly 5 million url:log:pass stealer-log entries, part of an ongoing series of high-volume credential leaks. The volume makes it a sizable corpus for credential stuffing and account takeover, though no specific organization or region is identified. It carries no evident government or LATAM critical-infrastructure relevance.Leak● 40
Filtración de la base de datos de la tienda online de SFR (583k)A ~583,000-record dump of boutique.sfr.fr, the e-commerce site of French telecom operator SFR, is circulating on a breach forum. Telecom is critical national infrastructure, so customer PII and order data can power phishing, account takeover and SIM-swap fraud. The thread dates to January 2026, so it is a stale leak, not a fresh breach.Leak● 45
Filtración de base de datos de Brasil con 85 millones de registrosA database of 85 million records attributed to Brazil is offered on a dark web forum, one of the largest Latin American exposures seen. A leak this size can expose national IDs, addresses and credentials used for fraud and account takeover across the region. The thread dates to June 2024, so it is an old leak and not a fresh alert.Leak● 18
Base de datos del parlamento de Indonesia DPR.GO.ID (730K) filtradaA thread advertises the leaked database of Indonesia's parliament (dpr.go.id) with roughly 730,000 entries. The content is sensitive given the legislative target, but the dump is dated December 2024, so it is not a new incident. Its value now is contextual rather than actionable for an immediate response.Leak● 52
Filtración masiva expone a 70.000 agentes de inteligencia de MarruecosA mass leak reportedly exposes roughly 70,000 personnel of Morocco's DGST territorial-surveillance directorate, including identities and contact details. Although it is outside Latin America, it is a landmark breach of a state intelligence body and a strong reminder that security services are targeted. CTI teams should track it for tradecraft and for the risk that the exposed identities are reused for impersonation or extortion.Leak● 42
Brecha de datos de la University of Southeastern PhilippinesA data set described as a breach of all faculties of the University of Southeastern Philippines was freshly posted on DarkNetArmy. It appears to include faculty and staff records, exposing personal data of university personnel. Educational institutions are frequent targets and such leaks fuel phishing and credential abuse.