BRIEFLeakhighP72
Database leak of Iraqi telecom operators Asiacell and Zain
Asiacell / Zain Iraq
Detected21 September 2026 · 15:37 UTC
A database of subscribers of Asiacell and Zain, two of Iraq's largest mobile operators, is offered on a leak forum dated 21 September 2026. The exposed phone numbers and subscriber details enable SIM-swap, phishing and targeted attacks against critical telecommunications infrastructure. Regional telecoms and CERTs should verify the scope and warn affected users.
CategoryLeak
Severityhigh
Priority score72
Detected21 September 2026 · 15:37 UTC
Leak● 42
Combolist de 180.000 credenciales de Colombia a la ventaA bulk combolist of roughly 180,000 Colombian credentials dated 11 August 2026 is being circulated. Such lists fuel credential-stuffing and account takeover against Colombian services and users, indicating fresh regional credential theft. Defenders in Colombia should force resets and monitor for credential reuse.Leak● 45
Venta de datos personales de CentraCare, sanidad de EE. UU.A seller is offering personal-data leads for CentraCare, a large US healthcare system in Minnesota, advertised as 2026 data. Leaked patient or contact data enables targeted phishing and fraud against a healthcare provider. Healthcare security teams should verify the dataset's authenticity and scope.Leak● 60
Base de datos de Salt.ch con 1,09 millones de registros a la ventaA seller is offering a Salt.ch database with more than 1,090,000 records, likely containing customer names, emails and related personal data. Such a dump feeds credential-stuffing, phishing and account-takeover campaigns against the provider and its users. A million-record leak of a named company is a substantial, actionable exposure for defenders.Leak● 44
Base de datos del sitio ruso ibiw.ru (726K registros) filtradaThe 'AnkaTeam' group published a 726,000-record database allegedly belonging to the Russian site ibiw.ru. The dump contains personal and account data that can fuel credential-stuffing and targeted phishing against the company's users. It is a mid-sized but genuine breach of a named organization, notable mainly for the volume and the actor behind it.Leak● 38
Venta de datos de traders de Forex de EspañaA marketplace seller is offering a fresh lead list of Spanish forex traders dated 2025-2026. It likely contains names, emails and phone numbers of retail investors, enabling targeted phishing and financial fraud. It is regionally relevant but is a lead list rather than a breach of critical infrastructure.Leak● 72
Filtración de base de datos de Bureau Van Dijk (Moody's)A threat actor claims to have leaked a large database belonging to Bureau Van Dijk, a Moody's subsidiary that aggregates private-company and financial data (e.g. Orbis). If genuine, this exposes extensive corporate records used for due diligence, KYC and credit decisions. Defenders should track downstream credential abuse and business-intelligence targeting.