BRIEFLeakhighP48
Leak of 6.95 million URL:LOG:PASS credentials
Detected13 September 2026 · 03:12 UTC
A 6.95 million-line URL:log:pass credential list of stealer logs is being resold and mirrored across multiple forums. Its scale and cross-forum distribution make it valuable for credential stuffing against web and VPN portals. Organizations should screen exposed credentials for corporate and government domains.
CategoryLeak
Severityhigh
Priority score48
Detected13 September 2026 · 03:12 UTC
Leak● 55
Base de datos siria publicada en BreachForumsA freshly posted database labeled 'Syrian' appeared on BreachForums today. Large regional population datasets typically contain PII that supports identity fraud and targeted phishing campaigns. Though outside LATAM, it is worth tracking as part of broader breach-monitoring activity.Leak● 58
Base de datos de usuarios de Bitcoin a la venta en DarkNetArmyA vendor on DarkNetArmy is advertising a large 'Bitcoin user database vault 2026' targeting crypto account holders. If genuine, such data fuels account takeover, phishing and theft of funds, and is commonly reused for credential stuffing across exchanges. Authenticity is unverified, so treat it as a lead for monitoring rather than a confirmed breach.Leak● 28
Volcado de credenciales ULP de 27 millones de líneas (1,5 GB)A 1.5 GB credential dump labelled 'ULP' containing roughly 27 million URL:LOG:PASS lines was posted to DarkForums in March 2026. These email/password pairs feed credential-stuffing and account-takeover attacks across many services. Defenders should check exposure of corporate and government accounts, though the dump is months old and not directed at a specific entity.Leak● 40
Filtración de 6,95 millones de logs URL:LOG:PASS (DAXUS)A 6.95 million-line URL:LOG:PASS stealer-log dump was uploaded to DarkForums and advertised by the handle DAXUS. Such logs hold live credentials harvested by infostealers and are used for account takeover and VPN/SSO intrusion. No single victim is named, so it is a broad credential-exposure alert rather than a targeted access sale.Leak● 48
Filtración de base de datos de prisioneros iraquíesA DarkForums thread shares an alleged database of Iraqi prisoners containing identifying and detention data. If genuine, it is a sensitive government and national-security leak affecting detainees and officials. The post is undated so freshness is unconfirmed, but the subject matter warrants monitoring.Leak● 65
Filtración expone a 70.000 agentes de inteligencia de MarruecosA leak dubbed 'Jabaroot' exposes roughly 70,000 personnel of Morocco's Directorate General for Territorial Surveillance (DGST), including identities and contact data. It is a serious counter-intelligence breach against a foreign state service, published around 24 Aug 2026 and still circulating. Though outside Latin America, it is a high-value state dataset that enables targeting and should be tracked.