BRIEFLeaklowP24
Leak of 2.1M private URL:LOG:PASS credentials
Detected22 September 2026 · 12:01 UTC
A private 2.1-million-line URL:LOG:PASS credential dump was posted to DarkForums. Dumps this size fuel credential-stuffing across many services and can contain valid corporate logins. However, the post dates to July 2025, so the data is stale and now of mostly background value for defenders.
CategoryLeak
Severitylow
Priority score24
Detected22 September 2026 · 12:01 UTC
Leak● 40
Combolist dirigida al dominio telefonica.net (Telefónica)A forum user published a ~5,919-line credential list sorted and targeted at the telefonica.net domain (Telefonica). Although small, it is a named telecom target with extensive Latin America and Spain operations, making it useful for credential stuffing against corporate mail and VPN portals. Defenders should force credential rotation and MFA on affected accounts and watch for reused passwords.Leak● 70
Filtración de base de datos con 945.000 clientes de ChileA threat actor is distributing a database containing roughly 945,000 complete customer records from Chile via a BreachForums leak channel. The volume and per-customer detail suggest it can fuel identity theft, phishing and credential-stuffing against Chilean consumers. Defenders in Chilean finance, retail and telecom should treat it as a fresh regional exposure and monitor for downstream fraud.Leak● 40
Combolist de 253.000 credenciales de correo de BrasilA 253,000-line Mail:Pass combolist targeting Brazilian email accounts was posted in 2026 as a fresh 'unique combo'. Dumps of this size expose a large victim pool to account takeover and are frequently reused in region-focused phishing and fraud. Brazilian users, ISPs and banks should treat it as an active credential-reuse risk.Leak● 42
Filtración de base de datos de la Universidad Lambung MangkuratA database from Universitas Lambung Mangkurat, a public university in Indonesia, was published on BreachForums. Such leaks typically expose student and staff PII, academic records and contact data, enabling downstream phishing and credential reuse. Track it as a confirmed named-organization breach, although it falls outside the AR-LATAM region.Leak● 55
Filtración de 11,5 millones de registros de datos de MéxicoA 1.36 GB dataset holding roughly 11.5 million Mexican records is being circulated for free on a carding forum, likely containing personal identifiers and contact data of Mexican citizens. The source organisation and breach date are not stated, so it may be a re-post of an older incident, but the sheer volume makes it viable for credential-stuffing and identity-fraud against Mexican users and services. Defenders in Mexico should monitor for re-use of these identities and watch for linked downstream fraud.Leak● 45
Reventa del volcado de National Public Data con 2.700 millones de registrosA seller is re-posting the well-known National Public Data breach, advertising access to roughly 2.7 billion records including SSNs, names and addresses. While the underlying data is an old 2024 US leak rather than new activity, the huge scale means it fuels identity theft, account takeover and loan fraud. The thread itself is new, so defenders in US financial, telecom and identity sectors should treat it as recycled high-impact PII rather than a fresh breach.