BRIEFLeakhighP50
Leak of 1.8M credential logs from stealer malware
Detected18 September 2026 · 00:12 UTC
A free dump of about 1.8 million URL:login:password credential logs from private stealer logs was posted to a leak forum. The volume makes it valuable for credential stuffing and account takeover across many services. Defenders should check exposure and force MFA and password resets for affected users.
CategoryLeak
Severityhigh
Priority score50
Detected18 September 2026 · 00:12 UTC
Leak● 38
Filtración de base de datos de clientes de German Doner KebabA customer database attributed to German Doner Kebab (GDK) is being offered on a darknet forum in what appears to be a recent post. Customer PII enables phishing, fraud and loyalty-account takeover. Retail and food-sector defenders should verify the claim and prepare customer notification.Leak● 62
Venta de 1M de datos personales de mtglobal.orgA seller is offering roughly one million PII records from mtglobal.org, a UK international money-transfer firm, in what appears to be a fresh listing. Customer identity and financial data fuels fraud, account takeover and regulatory exposure. Financial-sector defenders should watch for reused credentials and customer phishing.Leak● 46
Base de datos de ciudadanos de República Dominicana a la ventaAn actor claims to hold a citizens database of the Dominican Republic, potentially containing names, national IDs and other PII of a whole national population. It matters to LATAM defenders, but the post is dated February 2026, so it is likely a recirculated dump rather than a fresh breach.Leak● 48
Filtración de base de datos de la plataforma de apuestas 1winA database allegedly belonging to the betting platform 1win (1winbet) is being leaked on an underground forum. Gambling platforms hold account, payment and KYC data of many users, so a leak of this kind enables fraud, credential stuffing and identity theft against a broad Spanish-speaking user base.Leak● 62
Filtración de 1M de datos PII de la firma de transferencias mtglobalA seller is offering roughly 1 million PII records belonging to mtglobal.org, a UK-based international money transfer firm, likely including customer identity and KYC data. Finance-sector defenders should care because such records fuel account takeover, targeted phishing and fraud against the provider and its clients.Leak● 40
Volcado de 10 millones de URL:LOG:PASS con credenciales a la ventaA 10-million-line stealer-log set (URL:LOG:PASS) is being distributed, exposing browser-saved credentials together with the sites they belong to. Dumps like this enable credential stuffing against webmail, VPN and admin portals, so any organisation relying on password-only authentication is exposed. Posted in May 2026, it is somewhat stale yet still widely reused by attackers.