BRIEFLeakcriticalP84
EDUSAL leak exposes 331K teacher and admin credentials
EDUSAL (plataforma educativa, El Salvador)
Detected23 September 2026 · 16:51 UTC
A dump labelled EDUSAL exposes roughly 331,000 teacher and administrator credentials in plaintext, attributed to an education platform in El Salvador. Because passwords are cleartext, attackers can log in directly rather than crack hashes. This affects a Latin American public education system and enables credential reuse and lateral access to government-linked accounts.
CategoryLeak
Severitycritical
Priority score84
Detected23 September 2026 · 16:51 UTC
Leak● 42
Venta de 100.000 IBAN de La Banque Postale (Francia)A seller offers 100,000 records of French postal bank La Banque Postale, including first and last name, IBAN and BIC. Such data enables direct-debit fraud and identity theft against account holders. The post is dated June 2026 and targets a European bank, so it is relevant but not regionally urgent.Leak● 46
Volcado de 9,8 millones de credenciales URL:Login:Pass publicadoA 9.8 million-line URL:Login:Password dataset was posted as fresh on 21-Sep-2026. It aggregates stealer logs that can be used for credential stuffing and account takeover across many services. No specific organization is named, but the volume makes it valuable for mass authentication attacks.Leak● 50
Base de datos de la teleco australiana Optus a la ventaA database attributed to Australian telecom Optus is being circulated on a forum. If the data is current, it relates to a major carrier and critical telecommunications infrastructure. Even as a repost of the known 2022 Optus breach, it remains a large telecom dataset worth verifying against new indicators.Leak● 47
Base de datos de 31 GB de la casa de apuestas turca CenabetA 31 GB database attributed to Cenabet, a Turkish betting platform, is being redistributed on a hacking forum. Betting databases typically hold user accounts, credentials and payment data at scale. Large, but Turkey-focused, so mainly relevant for credential-reuse and KYC/AML monitoring.Leak● 26
Breach antiguo con 150.000 registros del seguro de salud AILifeA 150,000-record dump from ailife.com, a US health-insurance provider, is offered free, including fullz (identity plus policy data). The post is dated 22 September 2025, so it is roughly a year old and likely widely circulated already. Sensitive health PII, but not a fresh alert.Leak● 50
Filtración de documentos KYC de ciudadanos indonesiosA RaidForums thread offers Indonesian KYC identity documents (KTP, SIM, KIS, DJP, KP, KK) — national IDs, driver licences and tax/family records. If genuine, this is bulk PII enabling identity theft, loan fraud and account takeover of Indonesian citizens. Valuable for fraud and identity-monitoring teams.