BRIEFLeakhighP62
Stolen Ledger database with 309,000 records for sale
Ledger
Detected23 September 2026 · 01:29 UTC
A seller is offering a claimed database of 309,000 records allegedly stolen from Ledger, the crypto hardware-wallet vendor, in 2026. If genuine it exposes user PII and contact data, enabling phishing and account-takeover against crypto holders. Its freshness and named real target make it worth verifying with Ledger and monitoring for resale.
CategoryLeak
Severityhigh
Priority score62
Detected23 September 2026 · 01:29 UTC
Leak● 42
Actualización OSINT sobre España publicada en un foro clandestinoA user posted a fresh 'osint spain update' to a leak forum minutes ago, suggesting newly compiled data or dorking material on Spanish targets. The content is vague, but recency and an EU country focus make it worth checking whether it contains Spanish PII or access enablers. Relevance to AR-LATAM is indirect and impact is currently unclear.Leak● 45
Combolista de 723.000 credenciales de Brasil filtradoA credential combolist of roughly 723,000 lines targeting Brazilian accounts was published, likely aggregated from prior breaches and infostealer logs. Though not tied to a single organization, its scale and Brazil focus make it useful for credential-stuffing against regional services and for spotting exposed corporate accounts. Defenders in Brazil should treat affected credentials as compromised.Leak● 38
Filtración de base de datos con email y CUIL/CUIT de ArgentinaA threat actor posted a database containing Argentine email addresses plus CUIL/CUIT national tax identifiers, unique to each citizen. Though dated October 2025 and thus not fresh, such data enables identity fraud, SIM-swap and account takeover. Argentine defenders should check exposure of their user base.Leak● 34
Filtración de base de datos de The Post MillennialA BreachForums thread posted September 22, 2026 names the Canadian outlet The Post Millennial as a database leak. If authentic, subscriber, contact and internal data could be exposed and reused for phishing and influence operations. The poster is known for re-posting older BreachForums content, so the data may be recycled rather than a new breach.Leak● 46
Filtración de base de datos de Carnival CorporationCarnival Corporation & plc, the global cruise operator, appears in a database-leak thread on DarkForums dated April 2026. Carnival holds massive volumes of customer, booking and employee PII, so a genuine dump would fuel credential stuffing, phishing and fraud. The post is months old, so it is not a fresh alert, but defenders should still watch for re-exposed credentials and account abuse tied to Carnival brands.Leak● 33
Filtración de la base de datos de la plataforma cripto Remote3.coA thread offers a leaked database from Remote3.co, a crypto-related service, for free download. If genuine, it exposes user account data that could fuel credential stuffing and phishing against the platform's customers. The post carries no clear date, so its freshness cannot be confirmed.