BRIEFLeakhighP50
2M+ records from Iranian chat platform Chatzi.ir leaked
Chatzi.ir
Detected26 September 2026 · 10:16 UTC
A threat actor is offering 2M+ records from Chatzi.ir, an Iranian chat platform, with a sample attached. The scale suggests a full-user database compromise affecting a large user base. Though outside LATAM, it is a sizable real-organization leak worth tracking for credential-reuse and regional spillover.
CategoryLeak
Severityhigh
Priority score50
Detected26 September 2026 · 10:16 UTC
Leak● 42
Filtración de base de datos de la casa de empeños indonesia Budi GadaiA threat actor advertised a database from PT Budi Gadai Indonesia (budigadai.com), an Indonesian pawnshop and consumer-lender, in September 2026. Those records typically include customer identities, contacts and loan/financial data. It is outside Latin America, so it matters mainly for actor tracking and as identity data that can be reused in regional fraud.Leak● 56
Filtración de 5,5 millones de datos de empresas italianas y europeasA 5.5 million-record dataset of Italian businesses, mostly European companies, is being offered for sale. It likely contains corporate contact and registration data usable for targeted phishing and BEC. Large business datasets fuel downstream fraud, so defenders should flag exposure of named companies.Leak● 58
Base de datos robada de Ledger (309.000 registros) a la ventaA threat actor (Gogi_data) is circulating a claimed 2026 Ledger customer database of about 309,000 records, cross-posted on DarkNetArmy, BlackBones, SpyHackerz and LEET. Ledger sells crypto hardware wallets, so leaked customer PII (names, emails, addresses, phones) directly fuels targeted phishing, SIM-swap and even physical-threat campaigns against high-value crypto holders. Defenders should treat affected users as at elevated risk and watch for credential reuse.Leak● 40
Publicadas 21 millones de credenciales en un volcado ULPA fresh dump of about 21 million URL:login:password (ULP) stealer-log entries was posted today. Such large credential sets fuel credential stuffing against corporate VPNs, webmail and SaaS. No specific victim is named, but the scale makes it a high-volume source for account-takeover attempts.Leak● 48
Filtrada la base de datos del sitio de salud húngaro diagnozis.huA Hungarian health/medicine website, diagnozis.hu, has been breached and its full database leaked by the actor 'Sophia'. Health-sector data is sensitive personal information subject to strict regulation and can be abused for medical fraud and targeted phishing. The fresh leak warrants monitoring of reused credentials and downstream exposure.Leak● 60
Base de datos de 7 GB de etestify.com (España) a la ventaA seller is offering a 7 GB SQL database of Spain's etestify.com containing roughly 84,000 member records, posted within the last hour. It includes customer/member personal data that can fuel phishing and account takeover against Spanish users. Because it is fresh and tied to a real Spanish company, credential-stuffing and fraud campaigns are likely.