
BRIEFLeakhighP55
Leak of 90 million URL:login:password credentials
Detected7 October 2026 · 23:07 UTC
A freshly posted 90-million-line URL:login:password combolist (stealer logs) is being distributed as a private UHQ dump dated 07/10/2026. The set is global and not tied to a single named org, but its sheer scale makes it a high-value resource for credential-stuffing and account-takeover campaigns. Defenders should treat it as a fresh corpus of valid-looking domain credentials for password-reuse monitoring.
CategoryLeak
Severityhigh
Priority score55
Detected7 October 2026 · 23:07 UTC
Leak● 35
Filtración de la base de datos SQL de helpachildofindia.orgA BreachForums user posted a full SQL database dump of helpachildofindia.org, an Indian children's charity, dated October 7, 2026. The dump likely exposes donor and contact records for a small NGO, which matters for the affected organization and for downstream phishing. Impact is limited and the entity is outside the Latin America region, so priority is low.Leak● 44
Filtración de identidades de 120.000 residentes de CirebonA threat actor is publishing a database reportedly containing the personal identities of roughly 120,000 residents of Cirebon, Indonesia, likely sourced from a local government population registry. The scale and citizen-PII nature make it useful for identity theft and downstream fraud. It matters to defenders outside the region only as a signal of an exposed civic data source, not as a direct AR-LATAM target.Leak● 45
Base de datos con 3 millones de PII de la financiera india EmergencyPaisa a la ventaA seller on the Spear forum is offering a 3-million-record PII database from EmergencyPaisa, an Indian consumer-finance website. The data likely includes names, contact details and financial identifiers that enable fraud and targeted phishing. Even outside our region, it shows mid-size fintechs remain prime leak targets.Leak● 52
Filtración de documentos del banco de inversión Goldman SachsA DarkForums thread advertises leaked documents tied to Goldman Sachs, a top-tier US investment bank. If authentic, the dump could expose employee or client data usable for fraud, phishing and business email compromise. Defenders should verify scope and watch for credential reuse against the bank and its partners.Leak● 25
Filtración de base de datos de la brasileña Grupo FortaA database tied to grupoforta.com.br, a Brazilian company, was posted for download on DarkForums, potentially exposing customer or internal records. Brazilian corporate breaches are relevant to LATAM defenders because leaked identities often resurface in regional fraud. The post dates to late 2023, so it is old and should be treated as background, not a fresh incident.Leak● 28
Filtración de base de datos de Opendatacenter.com.brA leaked database from Opendatacenter.com.br, a Brazilian hosting/data-center provider, was shared on DarkForums. As a hosting/infrastructure supplier, exposed customer and access data could cascade to many downstream organizations. However the post is dated 2023, so it is stale context rather than a fresh alert.