BRIEFLeakhighP70
1.1M-record leak from commercial real estate firm Cushman & Wakefield
cushmanwakefield.com
Detected10 October 2026 · 10:21 UTC
A new listing advertises a 1.1 million-record dataset from Cushman & Wakefield, a global commercial real estate firm, attributed to Salesforce and dated 2026. Datasets of this size typically contain business contacts, emails and client records valuable for targeted phishing and account takeover. The firm and its partners should assess exposure and monitor for credential misuse.
CategoryLeak
Severityhigh
Priority score70
Detected10 October 2026 · 10:21 UTC
Leak● 38
Base de datos de social-formula.com (200K) a la ventaA seller is listing a roughly 200K-record database belonging to social-formula.com, a US-targeted property, on a darkweb marketplace. The scale is moderate and the entity is a commercial site rather than a critical-infrastructure or government target. It is worth tracking as a real-organization leak but is low priority outside its user base.Leak● 66
Base de datos de 687.000 registros de BCD Travel a la ventaA freshly posted listing offers a 687,000-record database attributed to BCD Travel, describing corporate travel management data pulled via Salesforce. Corporate travel and employee contact data at this scale fuels phishing, BEC and credential-stuffing against the travel and corporate sector. BCD Travel and its corporate clients should treat affected credentials as compromised and hunt for downstream login abuse.Leak● 63
Filtración de logs del sistema HRMS del Metro de NoidaA threat actor posted logs from the HRMS (Human Resource Management System) of the Noida Metro Rail Corporation, a critical urban transport operator. Exposure of HR/identity records and internal system logs enables credential reuse, phishing and lateral movement against a government-owned infrastructure entity. The post is fresh (minutes old), so defenders should treat it as an active alert and rotate any implicated credentials.Leak● 44
Filtración de 16 millones de credenciales en registros de stealerA 16-million-line URL:login:password stealer-log dump is posted for free, aggregating credentials harvested by infostealers. Although no single organization is named, the scale makes credential-stuffing and account takeover against any exposed user highly likely. Defenders should search for their domains and force resets of affected sessions.Leak● 85
Filtración de base de datos del banco mexicano BanorteA Banorte database is being distributed for free on BreachForums with a direct download link. Banorte is one of Mexico's largest banks, so exposed customer records create serious fraud, identity-theft and follow-on account-takeover risk. LatAm financial defenders should treat any credentials and PII in this dump as compromised.Leak● 50
Filtración de 16 millones de credenciales de Secretline.topA free dump labelled Secretline.top claims over 16 million URL:login:password credential lines, a classic stealer/credential-log set. While such mass dumps are often recycled, exposed combinations fuel credential stuffing against corporate webmail, portals and cloud services.