BRIEFLeakhighP50
Brazil documents database with 780,000 records for sale
Brasil (base de datos)
Detected18 September 2026 · 20:12 UTC
A 780,000-record document dataset from Brazil is being shared as 'part 1 of Latin America', signalling a broader regional leak campaign. It contains personal document data useful for fraud, account takeover and impersonation against Brazilian individuals. Regional defenders should anticipate follow-up parts targeting other LATAM countries.
CategoryLeak
Severityhigh
Priority score50
Detected18 September 2026 · 20:12 UTC
Leak● 45
Base de datos del exchange de criptomonedas BitMax.io a la ventaAn actor posted a database attributed to the crypto exchange BitMax.io on a dark web forum. Exchange user data drives credential-stuffing, phishing and targeted wallet theft, and the listing appears freshly posted. Crypto sector defenders should verify scope and force credential resets if the data is confirmed.Leak● 55
Base de datos de clientes de Ledger (309.000 registros) a la ventaAn actor is offering a database of about 309,000 Ledger customer records allegedly stolen in 2026, including personal and contact data of crypto wallet users. Such data feeds phishing, SIM-swap and physical-extortion campaigns against high-value crypto holders. Defenders and crypto users should treat it as a fresh, actionable exposure even if the exact provenance needs verification.Leak● 60
Filtración de 55 GB de la app Tea expone chats y documentosA 55 GB dump from the Tea app is being freely distributed, containing private chats, direct messages, verification documents, licences and selfies. The scale and the presence of government-issued ID images make it a serious privacy and identity-fraud exposure for the app's user base. Defenders monitoring leaked KYC/document troves should flag it for downstream impersonation and sextortion risk.Leak● 88
Filtración de datos médicos de 6,6 millones de pacientes de EcuadorA threat actor posted on a dark web forum a database with 6.6 million patient records from Ecuador, including medical and personal data. This hits a Latin American healthcare sector target directly and enables identity theft, insurance fraud and targeted extortion of citizens. Ecuadorian health entities and regional defenders should treat this as a high-priority exposure and check for downstream credential reuse.Leak● 42
Venta de 185 millones de leads B2B extraídos de ZoomInfoAnother seller is marketing a 185 million record B2B lead database sourced from ZoomInfo, containing corporate names, emails and phone numbers. Though it is an aggregated marketing dataset rather than a named-victim breach, its size and recency make it useful for large-scale social engineering and business email compromise campaigns.Leak● 46
Base de datos de 486 millones de contactos B2B de Apollo.io a la ventaA seller is offering a 486M+ record dataset of business contacts (names, emails, phone numbers and company data) attributed to Apollo.io. It is a scraped/aggregated B2B corpus rather than a fresh breach, but its scale makes it valuable for targeted phishing and business-email-compromise against organizations worldwide, including in Latin America.