BRIEFLeaklowP45
Active session cookies for Walmart, LinkedIn and social accounts for sale
Walmart, LinkedIn, Nextdoor, Instagram, Facebook, Twitter
Detected24 September 2026 · 08:51 UTC
A threat actor is trading '2f' accounts for Walmart, LinkedIn, Nextdoor, Instagram, Facebook and Twitter bundled with active email session cookies, i.e. takeover-ready access rather than plain credentials. Active cookies let buyers bypass passwords and often 2FA, enabling immediate account takeover and lateral phishing. Organizations on these platforms should force re-authentication and hunt for anomalous session activity.
CategoryLeak
Severitylow
Priority score45
Detected24 September 2026 · 08:51 UTC
Leak● 35
Filtración de datos de Grupo Hasar publicada en foroA dumped database tied to Grupo Hasar, a Latin American electronics group, is being shared on DarkForums. The post dates to August 2025, so it is stale and likely already traded, but exposed customer or employee PII could still fuel fraud. Worth tracking for credential reuse.Leak● 55
Base de datos de plataforma china de masajes a la ventaA threat actor is selling a Chinese on-demand massage platform database with roughly 7.5 million orders and 1.8 million users, including names, phone numbers and payment data. Although the victim is outside Latin America, the scale makes it a notable bulk-data sale. Buyers could enable large-scale fraud and downstream phishing.Leak● 38
Stealer log de 357.000 credenciales URL:login:pass publicadoA stealer log containing roughly 357,000 URL:login:password entries was released by 'Napoleon' and mirrored across several forums. Stealer logs pair credentials with the exact site and often session data, making them directly usable for credential stuffing and account takeover. Although not region-specific, the volume and freshness justify checking for your users' corporate credentials.Leak● 40
Dump de 960.000 credenciales URL:login:pass publicadoA forum user published a 960,000-line URL:login:password credential dump labelled 'UHQ FRESH SEP', indicating recently harvested stealer/combolist data. The scale and 'fresh' label mean many entries are likely still valid, feeding credential stuffing, account takeover and initial-access attempts across many services. Defenders should enforce credential-stuffing detection and MFA on any exposed accounts.Leak● 72
Filtración de la base de datos de Bureau van Dijk (Orbis) a la ventaA DarkForums seller is offering a 2025-2026 leak of Bureau van Dijk's corporate data, the Moody's-owned Orbis business-intelligence platform (posted 21 Sep 2026). It holds financial, ownership and executive records on millions of companies worldwide. If genuine, this is high-value corporate/KYC intelligence for BEC, fraud and supply-chain mapping, so defenders should watch for downstream abuse of leaked business records.Leak● 52
Base de datos de 1,5 millones de usuarios de Binance a la ventaA carding-forum seller claims to hold a 1.5-million-record Binance user database, likely assembled from credential stuffing or an older breach. If genuine it exposes crypto customers to account takeover and targeted phishing. Binance's large Latin American user base makes it relevant, though the recycled '2026' framing suggests limited freshness.