BRIEFLeaklowP42
180,000 Colombian credential combolist for sale
Colombia
Detected21 September 2026 · 15:37 UTC
A bulk combolist of roughly 180,000 Colombian credentials dated 11 August 2026 is being circulated. Such lists fuel credential-stuffing and account takeover against Colombian services and users, indicating fresh regional credential theft. Defenders in Colombia should force resets and monitor for credential reuse.
CategoryLeak
Severitylow
Priority score42
Detected21 September 2026 · 15:37 UTC
Leak● 45
Venta de datos personales de CentraCare, sanidad de EE. UU.A seller is offering personal-data leads for CentraCare, a large US healthcare system in Minnesota, advertised as 2026 data. Leaked patient or contact data enables targeted phishing and fraud against a healthcare provider. Healthcare security teams should verify the dataset's authenticity and scope.Leak● 72
Filtración de base de datos de las telecos iraquíes Asiacell y ZainA database of subscribers of Asiacell and Zain, two of Iraq's largest mobile operators, is offered on a leak forum dated 21 September 2026. The exposed phone numbers and subscriber details enable SIM-swap, phishing and targeted attacks against critical telecommunications infrastructure. Regional telecoms and CERTs should verify the scope and warn affected users.Leak● 60
Base de datos de Salt.ch con 1,09 millones de registros a la ventaA seller is offering a Salt.ch database with more than 1,090,000 records, likely containing customer names, emails and related personal data. Such a dump feeds credential-stuffing, phishing and account-takeover campaigns against the provider and its users. A million-record leak of a named company is a substantial, actionable exposure for defenders.Leak● 44
Base de datos del sitio ruso ibiw.ru (726K registros) filtradaThe 'AnkaTeam' group published a 726,000-record database allegedly belonging to the Russian site ibiw.ru. The dump contains personal and account data that can fuel credential-stuffing and targeted phishing against the company's users. It is a mid-sized but genuine breach of a named organization, notable mainly for the volume and the actor behind it.Leak● 38
Venta de datos de traders de Forex de EspañaA marketplace seller is offering a fresh lead list of Spanish forex traders dated 2025-2026. It likely contains names, emails and phone numbers of retail investors, enabling targeted phishing and financial fraud. It is regionally relevant but is a lead list rather than a breach of critical infrastructure.Leak● 72
Filtración de base de datos de Bureau Van Dijk (Moody's)A threat actor claims to have leaked a large database belonging to Bureau Van Dijk, a Moody's subsidiary that aggregates private-company and financial data (e.g. Orbis). If genuine, this exposes extensive corporate records used for due diligence, KYC and credit decisions. Defenders should track downstream credential abuse and business-intelligence targeting.