BRIEFLeakhighP46
Leak of 1.8M users from Chinese massage app '按个摩'
按个摩 (Chinese massage app)
Detected2 October 2026 · 14:45 UTC
A database from the Chinese massage app '按个摩' is being offered, containing roughly 7.5 million orders and 1.8 million user records. The scale makes it a significant PII and order-data leak that could fuel fraud and phishing against affected users. Although outside Latin America, it is a sizable fresh database exposure worth tracking.
CategoryLeak
Severityhigh
Priority score46
Detected2 October 2026 · 14:45 UTC
Leak● 45
Venta de más de 6.000 documentos de identidad españoles y de la UEA DarkForums seller offers 6,000+ Spanish and EU identity documents (passports, national IDs and similar) intended for fraud and KYC bypass. Such material enables impersonation, account takeover and loan or benefit fraud against Spanish-speaking victims. The batch is not recent, but it remains usable and is relevant to Spanish/LATAM fraud defenders.Leak● 48
Base de datos de 450.000 usuarios de carteras hardware a la ventaA seller advertises a 450,000-record database of personally identifiable data on users of hardware wallets (Ledger, Trezor, SafePal, OneKey) as fresh 2026 private leads. Such data drives highly targeted phishing and crypto-theft against high-value victims. Crypto and financial defenders should warn affected customers and watch for follow-on social engineering.Leak● 62
Filtración de 579 GB de datos de hardware y dispositivos de SamsungA forum user posted a 579 GB archive claiming to contain Samsung hardware and device source code and internal data, shared minutes before collection. If authentic it exposes proprietary firmware and design material for a major global manufacturer, enabling IP theft and supply-chain attacks. Hardware, telecom and electronics defenders should verify the claim and monitor for downstream abuse.Leak● 44
Volcado de 1,8 millones de credenciales ULP publicado en DarkForumsA fresh stealer-log dump labeled '1800000_ULP' (~1.8 million URL:login:password entries) was posted on DarkForums minutes before collection, with mirrors already appearing on Niflheim and xReactor. It is aggregated malware-harvested credentials rather than a breach of a single named organization, so it mainly fuels credential-stuffing and account takeover. Defenders should ingest the domains/emails for exposure checks and force resets on any matching corporate accounts.Leak● 40
Base de datos de John Hay Management Corp. (Filipinas) filtradaA Spear Leaks post from March 2026 offers a database belonging to John Hay Management Corporation, a Philippine government-owned firm. The data is already some months old, so it is not a fresh alert, but the target is a public-sector entity and the leak still aids fraud and further intrusion. Worth noting for regional context rather than urgent response.Leak● 46
Filtración de base de datos de Youplanet.app con 40.000 usuariosA DarkForums post shares a 40,000-record database from Youplanet.app containing usernames, names, IDs and emails, allegedly exfiltrated by a user named @zimablue. The scale is moderate but the records are personal data that enable phishing and account takeover. It matters mainly for affected users and for tracking the actor's activity.