BRIEFLeakhighP44
566K Payback.de customer records leaked
Payback.de
Detected30 September 2026 · 19:23 UTC
A 566K-record dataset linked to the German loyalty program Payback.de is offered as new private data for 2026. It likely contains customer identities and contact details usable for phishing and account takeover. Relevant for defenders tracking credential exposure at a major consumer platform.
CategoryLeak
Severityhigh
Priority score44
Detected30 September 2026 · 19:23 UTC
Leak● 46
Compromiso del sitio de la corredora brasileña VIPSA separate Cracked.st thread repeats claims that VIPS Corretora de Cambio SA, a Brazilian foreign-exchange firm, has a compromised website. This points to a possible financial-sector breach in Latin America exposing customer or transaction data. Detail is thin, so defenders should treat it as an unverified lead to investigate.Leak● 42
Filtración de base de datos de la telefónica SFR con 5M registrosA thread on xReactor offers a 5M-record database attributed to French telecom operator SFR. Telecom data includes subscriber PII and service details, high-value for SIM-swap and social-engineering attacks. Whether fresh or reposted, it warrants tracking given the critical-infrastructure nature of the target.Leak● 50
Compromiso del sitio de la corredora brasileña VIPSA user on Cracked.st is sharing information about a compromised site belonging to VIPS Corretora de Cambio SA, a Brazilian foreign-exchange firm. If confirmed, this is a financial-sector compromise in Latin America potentially exposing client or transaction data. The post lacks detail, so scope must be verified.Leak● 63
Base de datos de Neiman Marcus filtradaA database attributed to US retailer Neiman Marcus was posted to a leak forum within the last minute, likely a repost or fresh dump. Databases from large retailers fuel credential stuffing, phishing and payment fraud at scale. It is worth tracking for size and authenticity, though it falls outside the Latin America region.Leak● 42
Filtración de 235.000 registros de un centro educativo de Hong KongTurkHackTeam's ANKA TEAM published a 235,000-record database allegedly belonging to the Hong Kong educational institution mckln.edu.hk. Student and staff data of this scale fuels credential stuffing and targeted phishing. It is not a LATAM target, but it is a real organizational breach worth tracking.Leak● 45
Dump de credenciales de Sudamérica: Argentina, Brasil y ChileA 'verified' credential dump on Cracked.st claims to combine Argentine, Brazilian and Chilean data under a South America dataset. Regional combolists like this fuel account takeover against LATAM consumers and businesses, and the country tagging makes them easy to weaponise. It is generic content, but the region-specific focus justifies exposure checks.