BRIEFLeakhighP72
Transfast/Mastercard database breach of 11 million records
Transfast / Mastercard
Detected29 September 2026 · 14:07 UTC
A threat actor is advertising a database allegedly tied to Transfast, a remittance/payments provider linked to Mastercard, claiming 11 million records. This is a large payment-sector leak that would expose customer PII, account and transaction data used for fraud and identity theft. Given Transfast serves cross-border/LatAm money-transfer corridors, defenders should treat it as a plausible high-impact leak and hunt for credential-stuffing and phishing.
CategoryLeak
Severityhigh
Priority score72
Detected29 September 2026 · 14:07 UTC
Leak● 32
Filtración de datos de 17Media (17.live) con 28 millones de registrosA forum post offers a leaked dataset from the 17Media/17.live live-streaming platform containing roughly 28 million records. While the scale is large and could fuel account-takeover and extortion, the post is dated March 2026 and is therefore roughly six months stale, not a fresh alert. It is worth tracking for contextual exposure and downstream credential abuse but is low priority right now.Leak● 45
Filtración de 235.000 registros de escuela de Hong Kong (mckln.edu.hk)The ANKA TEAM/TurkHackTeam actor claims a 235k-record database leak from mckln.edu.hk, a Hong Kong educational institution. Leaked student and staff PII can drive phishing, credential stuffing and downstream account takeover. It is a real organization with a sizable breach, but it is outside the Argentina/LATAM region and only moderately impactful.Leak● 55
Base de datos completa de la mutua francesa Solimut a la ventaA threat actor is offering the full database of SOLIMUT Mutuelle de France, a French health-insurance mutual, for sale on BreachForums. Leaked member and policyholder data fuels targeted phishing, identity fraud and account-takeover attempts against a real organization. It is a genuine corporate data sale, not generic chatter, but the victim is outside the Argentina/LATAM scope.Leak● 52
Filtración de la base de datos de Start.ru con 43,9 millones de registrosThe Start.ru (Russian streaming service) database has been leaked in CSV form, reportedly containing roughly 43.9 million user records. A credential set of this scale enables account takeover, credential stuffing and phishing at scale. Analysts should check monitored emails for exposure and treat the dump as a reusable credential source.Leak● 58
Base de datos empresarial de Canadá con 8,5 millones de registros a la ventaA seller is offering a Canadian business database of 8,588,331 records, likely containing company contacts and firmographic data. Bulk business data of this size fuels phishing, BEC fraud and targeted campaigns against Canadian organizations. Defenders should watch for credential-stuffing and social-engineering attempts leveraging these records.Leak● 48
Datos personales de personal del Ejército de Malasia a la ventaPersonnel PII of the Malaysian Army is being offered for sale on a dark web forum, flagged as a repost of previously circulated data. Military personnel records enable targeted phishing, identity fraud and physical targeting of service members. Outside LATAM, it still signals a gov/military data exposure worth tracking for reuse.