BRIEFLeaklowP52
6.5M stealer logs (URL:login:pass) published for free
Detected25 September 2026 · 19:54 UTC
A 6.5 million stealer-log set in URL:login:password format was posted for free roughly an hour before capture. These logs originate from infostealer malware and contain live corporate and consumer credentials usable for account takeover and session hijacking. Defenders should feed it into credential-monitoring to detect exposed employee or customer logins.
CategoryLeak
Severitylow
Priority score52
Detected25 September 2026 · 19:54 UTC
Leak● 66
Base de datos del seguro de salud de Corea del Sur a la ventaA seller is offering a 39-million-line database allegedly from South Korea's national health insurance system, exposing subscriber identity and medical data. Such records enable identity theft, phishing, and medical fraud at national scale. Healthcare and identity-protection defenders should watch for downstream credential-stuffing and fraud campaigns.Leak● 82
Filtración de 10 millones de casos del FBI en un foroA forum post claims a leak of roughly 10 million FBI case files, a volume that would be extraordinary if authentic and remains unverified. If real, it would expose investigative data, informants, and techniques with serious operational-security implications. Treat with skepticism but monitor closely for sample releases.Leak● 48
Base de datos MySQL expuesta en GCP con datos personalesA freshly found MySQL database on Google Cloud Platform was left without authentication, exposing PII from a Korean exam dataset and a Saudi loan dataset, with signs of ransomware involvement. Open cloud databases let attackers bulk-scrape personal and financial records. Affected teams should force credential rotation and confirm the exposure is closed.Leak● 60
Filtración de datos del Centro Nacional de Bomberos de EE.UU.A threat actor published a downloadable dump of data allegedly taken from the US National Interagency Fire Center (NIFC), a federal wildfire-response agency. Though outside Latin America, a government breach can fuel phishing, credential reuse and follow-on intrusion. Defenders should verify scope and watch for reuse of the data.Leak● 48
Venta de 82,9 millones de credenciales francesasA seller offers an 82.9 million record email:password dump, allegedly extracted from a large credential-stealer collection, for 500 USDT. Even if recycled from older stealer logs, the sheer volume enables credential-stuffing and targeted phishing against French users and organizations. Defenders should monitor for reuse of these credentials and enforce MFA.Leak● 68
Base de datos de 13M de business.adobe.com a la ventaA seller is offering a business.adobe.com dataset of roughly 13 million records and 832 GB, posted on DarkForums very recently. Adobe is a major SaaS and identity provider, so leaked corporate data could fuel targeted phishing and account abuse. The data may be recycled from older Adobe breaches, so verify freshness before alerting.