BRIEFLeaklowP40
Spain combolist of 3.35 million email and password pairs
Detected5 October 2026 · 17:53 UTC
A 3.35 million-line email:password combolist targeting Spain is circulating on cracking forums. Large regional combolists drive credential stuffing against Spanish services and corporate accounts, even if the data is commodity. It is worth flagging for Spanish-speaking defenders to force resets and monitor login abuse.
CategoryLeak
Severitylow
Priority score40
Detected5 October 2026 · 17:53 UTC
Leak● 40
Filtración de datos de clientes de la financiera estadounidense New American FundingA leaked database attributed to US mortgage lender New American Funding contains client personal documents and ID numbers. Mortgage PII of this type supports loan fraud, account takeover and synthetic-identity creation, making it valuable despite being US-focused. Defenders should watch for re-use of these identities in credit and onboarding fraud.Leak● 60
Filtración de base de datos de PII de clientes mexicanos de CosmotiendaA 2026 database containing Mexican personally identifiable information tied to Cosmotienda has been published, exposing customer names, contact details and related records. Mexican PII is a high-demand commodity that fuels identity theft, loan fraud and targeted phishing against local consumers and businesses. Defenders in Mexico should monitor for downstream credential-stuffing and impersonation abuse.Leak● 58
Filtración completa del ERP Odoo de Tera.ma (Marruecos): 2,3 GB y 19.000 clientesA 2.3 GB Odoo ERP dump from the Moroccan company Tera.ma was leaked, containing roughly 19,000 customers and 124,000 invoices. ERP data of this scale exposes billing, contact and financial details, enabling fraud, extortion and competitive-intelligence gathering. It underscores the risk of unsecured or internet-exposed Odoo deployments, relevant to any organization running similar ERP systems.Leak● 66
Filtración de la base de datos de clientes de CTT (Correos de Portugal) 2026A customer database belonging to CTT, the Portuguese national postal operator, was posted for leak on October 5, 2026. Exposure of customer records affects a national logistics and financial-services provider, enabling phishing, fraud and account takeover against CTT customers. Because CTT handles mail, parcels and payments, defenders should treat it as a high-value regional data incident.Leak● 70
Puesta en venta de datos de SK Telecom (Corea del Sur)A seller is offering data or access tied to SK Telecom, South Korea's largest mobile operator and a piece of critical communications infrastructure. Any sale of subscriber data or internal access poses risks of network intrusion, SIM-related fraud and mass customer phishing. Defenders should verify whether the claimed material is authentic and monitor for resale or weaponization.Leak● 72
Filtración gratuita de base de datos del banco HSBC con 175.000 registrosA 175,000-record HSBC customer dataset has been released for free, indicating the data may already be widely redistributed among criminals. Exposure of banking customer records fuels fraud, phishing and account takeover, and the zero-cost release sharply increases downstream abuse. Financial-sector defenders should watch for credential-stuffing and impersonation campaigns referencing the leaked data.