BRIEFLeakhighP57
Leak of 129,000 Argentine citizen phone numbers
Argentina (PERSONAL)
Detected19 September 2026 · 11:12 UTC
A dataset labeled 'Argentina: PERSONAL' with roughly 129,000 records of Argentine citizens' phone numbers is circulating on DarkForums. The exact source and date are unconfirmed, but exposed citizen PII at this scale matters to telecom, banking and public-sector defenders in Argentina. Such data fuels SIM-swap, smishing and identity-theft campaigns, so it should be triaged for downstream account risk.
CategoryLeak
Severityhigh
Priority score57
Detected19 September 2026 · 11:12 UTC
Leak● 40
Base de datos de inteligencia empresarial de Zhuohi (China) publicadaA fresh DarkForums post advertises a database of Chinese business-intelligence data from the firm referenced as Zhuohi. Business-intelligence databases typically hold corporate contacts, financials and internal documents useful for fraud and espionage. Flag it for monitoring even though it concerns China rather than Latin America.Leak● 45
Base de datos OSINT francesa de 214 GB publicadaA 214 GB 'French OSINT' mixed database is being shared on RaidForums, aggregating personal and organizational data into a searchable corpus. Such aggregated leaks fuel doxing, social engineering and targeted intrusion against French entities. Its sheer size makes it useful to attackers even without a single clear victim.Leak● 45
Base de datos de jugadores de apuestas alemanes a la ventaA seller is offering a database of German online-gambling users, a high-value target list for phishing and account takeover because gambling platforms handle KYC and payment data. The post is fresh (17 Sep 2026) and traded directly through a marketplace thread. European gambling operators and regulators should expect credential-stuffing and fraud waves.Leak● 55
Filtración de datos de la firma de ciberseguridad RadwareA forum user ('OpCyberToufan') is publishing what they claim are parts one and two of leaked Radware files on the Spear leak forum. Radware is a major DDoS-protection and application-security vendor, so internal data could expose customer lists, configs or credentials, creating supply-chain risk. Treat as unverified but worth monitoring for downstream credential abuse.Leak● 62
Filtración de datos de Radware publicada por OpCyberToufanA user posting as OpCyberToufan released what is described as 'parts one and two' of data allegedly leaked from Radware, a major cybersecurity and application-delivery vendor. If authentic, internal data from a security provider could expose customer records, product internals or credentials reusable in follow-on intrusions. Defenders should treat this as a supply-chain-adjacent exposure and hunt for leaked Radware customer credentials.Leak● 42
Filtración masiva de 20 millones de credenciales robadasA forum post advertises roughly 20 million stolen URL:login:password lines originating from stealer logs. The dump is generic and not tied to a named victim, but its volume makes it valuable for credential-stuffing and password-reuse attacks across many organizations. Defenders should ingest it for exposure monitoring rather than treat it as a targeted intrusion.