BRIEFLeakhighP58
1.5 million credentials leaked in stealer logs
Detected23 September 2026 · 12:29 UTC
A freshly posted stealer log of roughly 1.5 million url:login:password entries was dumped on a Russian-speaking forum, harvested by infostealer malware. Because it aggregates real user credentials across many services, defenders should query it for corporate email/domain matches and force resets on any hits. Volume and recency make it more actionable than the surrounding combolist spam.
CategoryLeak
Severityhigh
Priority score58
Detected23 September 2026 · 12:29 UTC
Leak● 72
Filtración de la base de datos de Nexo.comA threat actor posted a claimed database of Nexo, a large global crypto lender, across multiple forums on 23 Sep 2026. If genuine, it exposes customer records (KYC, balances, contact data) of a regulated financial platform. Leaked identities and credentials can fuel account takeover and phishing against crypto users worldwide.Leak● 44
Volcado SQL de la base de datos de jamtangan.comA SQL dump of the jamtangan.com database was posted to BreachForums, exposing customer and order data of the watch e-commerce platform. Such leaks feed credential stuffing and fraud against the site's users; lower regional relevance but still a fresh breach of a real organization.Leak● 58
Documentos del Knesset israelí ofrecidos en BreachForumsA collection of Israeli Knesset documents is being shared, exposing internal material of a national legislature. Government documents fuel targeted phishing, disinformation and intelligence gathering, and this is a fresh posting worth flagging even though it falls outside the AR-LATAM scope.Leak● 62
Filtración de la base de datos de la Jamaica Police FederationA full SQL dump of the Jamaica Police Federation database was posted, likely exposing officer and staff records from a national law-enforcement body. Police-union data enables targeted phishing and harassment of officers and can support further intrusion; it is a fresh government-sector leak, though outside the LATAM region.Leak● 35
Venta de base de datos del centro de datos SIMLALA DEPHUB (Indonesia)A forum user is advertising a database tied to SIMLALA/DEPHUB, Indonesia's transport ministry data center, in a very recent post. If genuine, it indicates public-sector data being commoditised, but details are thin and the target is outside our region, so confidence and priority are low.Leak● 63
Filtración de 80 millones de registros de la empresa ApexSMSA DarkNetArmy post reports 80 million records exposed at ApexSMS, a text-messaging marketing company. That volume of phone numbers and linked personal data is a prime feed for smishing, SIM attacks and downstream fraud; defenders should verify the exposure and warn affected customers.