
BRIEFLeakhighP68
Leak of 92 million URL:login:password credentials
Detected9 October 2026 · 18:21 UTC
A freshly posted dump of roughly 92 million URL:login:password (ULP) records, harvested from infostealer logs, was released privately and marked as high quality. A set this large and recent fuels credential-stuffing, account takeover and session hijacking across web services worldwide. Defenders should hunt for reuse of these credentials and force resets on any exposed corporate accounts.
CategoryLeak
Severityhigh
Priority score68
Detected9 October 2026 · 18:21 UTC
Leak● 52
Base de datos francesa UNSS con más de 7 millones filtradaA database labeled 'UNSS' with over 7 million records is being shared, likely tied to French school/university sport. Millions of records can include names, addresses, dates of birth and contact data of students and staff. Its scale makes it a valuable asset for identity fraud and phishing even if posted months ago.Leak● 48
Colección de filtraciones de federaciones deportivas francesasA collection of leaked databases from multiple official French sports federations has been posted for download. These federations hold member, licensing, medical and staff records, so aggregating them amplifies exposure across several organizations at once. It matters for tracking a coordinated leak campaign against French sporting bodies.Leak● 45
Base de datos del bufete Prater & Ridley filtradaA database belonging to the US law firm Prater & Ridley Attorneys at Law has been posted for download on a RaidForums mirror. Law-firm data typically contains client identities, matter details and contact records, exposing legal-sensitive information. It matters for defenders tracking law-firm targeting, a common ransomware and BEC precursor.Leak● 30
Filtración de datos KYC del casino LeoVegas (2025)An actor is sharing 1,300+ files from LeoVegas containing KYC documents, account balances, emails and source code. KYC and balance data are high-sensitivity and feed identity theft and account takeover against a regulated gambling operator. Dated 2025, it is a stale leak for alerting but still useful as background on the operator's exposure.Leak● 42
Filtración de base de datos de Vodafone 2026A forum thread offers a Vodafone database leak dated mid-2026, a major global telecom operator. While the content could be significant, the post is roughly four months old, so it is not a fresh alert. It still matters for defenders tracking subscriber-data exposure across telecom providers.Leak● 70
Brecha de datos sanitarios de la empresa WoundtechA raid forum thread advertises a fresh healthcare data breach at Woundtech, a US wound-care provider. Healthcare data is among the most sensitive, including patient identities and possibly medical records. Fresh medical leaks enable medical identity theft and targeted extortion, warranting immediate triage for defenders.