BRIEFLeakhighP58
Leak of 6.2M customer records of airline TAP (flytap.com)
TAP Air Portugal / flytap.com
Detected10 October 2026 · 12:21 UTC
A database of roughly 6.2 million customers of Portuguese flag carrier TAP (flytap.com) is being shared, exposing passenger names, contacts and likely booking details. Large airline leaks fuel targeted phishing, fraud and account takeover. Affected travellers and the airline's partners should be warned.
CategoryLeak
Severityhigh
Priority score58
Detected10 October 2026 · 12:21 UTC
Leak● 30
Combolist de 52.179 credenciales de Chile publicado en foroA freshly posted combolist contains roughly 52,179 email/password pairs attributed to Chile. The volume is modest, but the set can fuel credential-stuffing and account-takeover against Chilean online services and public portals. Defenders should screen for password reuse and force resets on affected accounts.Leak● 66
Venta de base de datos de la plataforma educativa española Fiction Express (725 GB)A seller is offering a 725 GB database allegedly belonging to Fiction Express, a Spanish digital reading and education platform used by schools. Such a volume could expose student, parent and teacher accounts plus internal data across many institutions. Education-sector defenders in Spain should watch for credential reuse, phishing against schools, and account-takeover attempts.Leak● 48
Base de datos de Standard Gas con 4M de registros a la ventaA threat actor is selling a database of about 4 million records attributed to Standard Gas. The data fields are unverified, but if it holds customer or operational information it enables targeted phishing and fraud. Any energy-sector victim also raises the possibility of critical-infrastructure exposure.Leak● 55
Divulgación de brecha de datos de Pathao LimitedAn actor is publishing an ongoing breach disclosure against Pathao, a major Bangladeshi ride-hailing, delivery and payments platform. The continuing nature suggests active access and further exfiltration, affecting a large base of users and drivers. Exposed PII and payment data could drive fraud and account takeover.Leak● 70
Base de datos de Mecourier (EAU) con 31M de registros a la ventaA seller is offering a database of roughly 31 million records allegedly taken from Mecourier, a UAE courier and logistics company. If authentic, it exposes customer names, contact details and delivery data, fueling phishing, SIM-swap and fraud campaigns. Large logistics datasets also help attackers map operational and vendor relationships.Leak● 33
Base de datos de OpenCorporates republicada en un foroThe full OpenCorporates corporate registry dataset has been reposted, a large aggregation of company and officer records useful for identity fraud and B2B targeting. The post is dated August 2025, so it is a stale re-post rather than a fresh breach. Still relevant for data-exposure and third-party risk tracking.