BRIEFLeakhighP72
Bureau Van Dijk (Moody's) database leak
Bureau Van Dijk (Moody's)
Detected21 September 2026 · 13:37 UTC
A threat actor claims to have leaked a large database belonging to Bureau Van Dijk, a Moody's subsidiary that aggregates private-company and financial data (e.g. Orbis). If genuine, this exposes extensive corporate records used for due diligence, KYC and credit decisions. Defenders should track downstream credential abuse and business-intelligence targeting.
CategoryLeak
Severityhigh
Priority score72
Detected21 September 2026 · 13:37 UTC
Leak● 38
Venta de datos de traders de Forex de EspañaA marketplace seller is offering a fresh lead list of Spanish forex traders dated 2025-2026. It likely contains names, emails and phone numbers of retail investors, enabling targeted phishing and financial fraud. It is regionally relevant but is a lead list rather than a breach of critical infrastructure.Leak● 33
Venta de base de datos del internado Darussalam GontorA seller is offering the database of Darussalam Gontor, a large Indonesian Islamic boarding school, on a hacking forum posted minutes ago. If genuine, it exposes student, staff and possibly parent records. It is a real but low-impact education-sector leak outside Latin America, worth noting only as a data-sale trend indicator.Leak● 60
Base de datos de PII mexicanos de Cosmotienda publicada gratisA threat actor released a database of Mexican citizens' personal information (PII) tied to cosmetics retailer Cosmotienda, posted for free on a carding forum. The dataset exposes customer names and contact details usable for fraud, phishing and identity theft in Mexico. For LATAM defenders it signals fresh regional PII exposure and likely downstream credential-stuffing and scam campaigns.Leak● 40
Comparten volcado masivo de 13,5 millones de credenciales URL:usuario:contraseñaA dump advertised as 13.5M URL:login:password records is circulating through the 'vulta.pw' shop, a large fresh credential corpus that can fuel credential stuffing and account takeover. Aggregated logs of this size frequently include government and corporate email access. Defenders should assume their users' credentials are exposed and enforce resets and MFA.Leak● 42
Filtrada base de datos del servicio postal ruso Pochta.ru con 499.000 registrosA 499K-row database from the Russian postal operator Pochta.ru has been shared on DarkForums, reportedly containing names, phone numbers and physical addresses. The dataset is valuable for phishing, smishing and identity fraud against Russian citizens. Even if partly recycled, defenders should flag it for credential-stuffing and mailing-fraud campaigns.Leak● 45
Publican la filtración de la base de datos de la empresa paquistaní de IA KhaityA database belonging to the Pakistani AI company Khaity has been published for free in 2026, exposing the firm's stored data. AI vendors typically hold client datasets and model/API material that can be abused for further attacks. Defenders in the AI supply chain should treat the exposure as a lead for credential reuse and downstream targeting.