BRIEFLeaklowP46
Turkish betting-site database leak exposing 500,000 users
Turkish betting platform
Detected1 October 2026 · 09:47 UTC
A seller on DarkForums is offering a leaked database of a Turkish betting platform containing roughly 500,000 user records (posted July 2026). Such dumps typically include PII and hashed or plaintext credentials usable for fraud and account takeover. It matters less for LATAM-critical targets but indicates ongoing regional leak activity worth tracking.
CategoryLeak
Severitylow
Priority score46
Detected1 October 2026 · 09:47 UTC
Leak● 48
Base de datos de empresas francesas de 5,3 millones de registros a la ventaA threat actor is selling a French business database advertised as 5.3 million records from 2026 on BreachForums. Business contact data at this scale fuels targeted B2B phishing, invoice fraud and social engineering. It sits outside the LATAM priority region but is a large, fresh commercial leak worth tracking.Leak● 58
Base de datos de clientes de Digitec Galaxus (Suiza) a la ventaA seller is offering customer data of Digitec Galaxus, one of Switzerland's largest online retailers, in a post dated 27-09-26. Although outside Latin America, it is a fresh, named-organization leak that can enable phishing and account takeover against the retailer's customers and partners. Defenders with Swiss exposure should monitor and validate it.Leak● 28
Presunta filtración de 200 millones de cuentas de X/Twitter ofrecida a la ventaA forum post dated 31 October 2025 advertises a 200-million-record X/Twitter email:password dataset. The claim is nearly a year old and closely matches previously recycled Twitter leaks, so it is unlikely to be a fresh breach. Treat it as low priority unless credential-stuffing against X accounts tied to your organization is actually observed.Leak● 45
Filtración de 17 millones de credenciales URL:login:pass de stealer logsA 17-million-line URL:login:password combolist attributed to 'Secretline.top' stealer logs is being shared freely across several underground forums. It aggregates credentials harvested by infostealers rather than a single organization's data, so the impact is diffuse. Worth monitoring so your users' leaked credentials can be reset, but it is not a targeted breach of a named entity.Leak● 28
Filtración de combolist con 275.000 credenciales de PerúA 275,000-entry Peru-oriented credential combolist is circulating on DarkForums, originally posted in June 2025. Although now stale, it remains a usable source for credential stuffing against Peruvian online services and user accounts. It is regionally relevant for awareness but too old and generic to be a fresh alert.Leak● 34
Filtración de 17 millones de credenciales en stealer logs de Secretline.topA 17-million-line set of URL:login:password stealer logs sourced from Secretline.top was posted for free on a Tor leak forum. These are aggregated infostealer credentials rather than a single-victim breach, and they fuel account-takeover and fraud campaigns. Organizations should check whether corporate emails and employees appear in the set and force password resets where needed.