BRIEFLeakhighP45
18M URL:LOG:PASS dump (VULTA.PW) shared
Detected4 October 2026 · 00:55 UTC
An 18-million-record URL:LOG:PASS dump is being shared and marketed as fresh under 'VULTA.PW'. This volume of stolen credentials can drive automated account-takeover campaigns, so regional SOCs should watch for reuse of these logins. It is commodity data but of significant scale.
CategoryLeak
Severityhigh
Priority score45
Detected4 October 2026 · 00:55 UTC
Leak● 44
Filtración de 426.000 credenciales de EspañaA large combolist of roughly 426,000 email and password pairs targeting Spanish users was posted, dated late June 2026. Though aggregated credential lists are common, the volume and Spain focus make it usable for credential-stuffing against Spanish accounts. Organizations and users in Spain should reset exposed passwords and monitor for account takeover.Leak● 68
Base de datos de 8.045 colegios de Chile a la ventaA threat actor is selling a database covering 8,045 schools in Chile, likely including institutional and contact details. Education-sector data in Latin America is valuable for phishing and fraud and may include student or staff records. Defenders in the Chilean education sector should verify exposure and warn affected institutions.Leak● 48
Dump de 19,6 millones de credenciales (LUPIN ULP) en circulaciónA bulk credential dump of roughly 19.6 million url:login:password records ('LUPIN ULP') is being circulated from a VIP forum section, dated 10/04/2026. Large stealer-log sets like this enable large-scale credential stuffing and account takeover across many services, including exposed Latin American accounts. Though commodity, its scale warrants monitoring for ATO against regional assets.Leak● 58
Dump de credenciales argentinas (13.008 registros) publicadoA mail:password dump of 13,008 credentials labeled specifically for Argentina was posted by 'EvenRoad' on Niflheim. Although small, it is region-targeted and can fuel credential-stuffing against Argentine corporate and public services. Defenders should check for reuse of these credentials in AR-facing systems.Leak● 60
Venta de base de datos de reservas de GuruHotel (528K filas)A seller offers the full GuruHotel reservations database: 528K rows with roughly 6,300 guest PII leads. Booking data typically includes names, contact details, stay dates and payment hints, enabling targeted phishing and fraud against travelers and corporate clients. The organization should confirm the breach and notify affected guests.Leak● 42
Filtración de base de datos de Drupal.org con 1,75M de líneasA dataset attributed to Drupal.org (~1,752,873 lines) with full names, emails and phone numbers is being circulated on xReactor. Drupal is the upstream CMS behind many government and enterprise portals, so leaked credentials could enable follow-on access attempts. It is likely a repackaged older leak, so treat it as low-urgency but check for password reuse.