BRIEFLeakhighP48
Database leak of the University of the Philippines Mindanao
University of the Philippines Mindanao
Detected15 September 2026 · 02:12 UTC
A threat actor published a 4GB+ database allegedly belonging to the University of the Philippines Mindanao (upmin.edu.ph), a public university. It can expose student and staff personal data, credentials and internal documents usable in further attacks. Relevant as a real, high-volume education-sector breach impacting a public institution, though outside AR-LATAM.
CategoryLeak
Severityhigh
Priority score48
Detected15 September 2026 · 02:12 UTC
Leak● 34
Combolista de 126.000 credenciales de correo de PerúA 126K-line Peru-tagged email:password combolist was posted as 'FRESH', exposing credentials that feed credential-stuffing and account takeover. It is regionally relevant for LATAM defenders as recycled access material. Value is moderate since it is a combolist rather than a confirmed compromise of a specific organization.Leak● 64
Filtración masiva de datos de Hargreaves Lansdown (hl.co.uk)A forum post advertises 5,924,335 lines attributed to hl.co.uk, the domain of Hargreaves Lansdown, a major UK investment platform. Such a volume points to a large-scale exposure of customer PII and possibly financial/KYC data that could drive fraud and account takeover. It matters for defenders as a benchmark high-impact financial-sector leak, even though it falls outside the AR-LATAM region.Leak● 40
Base de datos de Rockstar Games publicada en foroA compressed ZIP allegedly containing a Rockstar Games database, described as roughly one month old, was posted on a leak forum. Rockstar is a high-profile games publisher, so a real leak could enable account takeover and credential-stuffing against players. The post dates to May 2026, making it stale rather than a fresh alert.Leak● 55
Filtración de base de datos de Stripe.com publicada en foroA lengthy carding-forum thread claims Stripe.com's database has been leaked and is being reposted across several pages. If genuine, exposure tied to a major payment processor could affect merchant and transaction data and fuel large-scale fraud. Defenders should treat it as an unverified claim and watch for card or credential reuse.Leak● 42
Filtración de base de datos de la colombiana Centrito.co (23K registros)A leaked database of roughly 22,948 records from the Colombian site Centrito.co is being shared, containing user accounts, emails and phone numbers. The scale is modest, but it gives attackers valid credentials and contact data useful for credential-stuffing and targeted phishing against Colombian users. Affected accounts should be force-reset.Leak● 22
Combolist de 180.000 credenciales de ColombiaA NulledBB post advertises a roughly 180K-line combo list targeting Colombian accounts, dated 11 August 2026. It is a regional credential dump rather than a named-org breach or access sale, and combolists are largely commodity noise. Minimal defensive value beyond credential-stuffing awareness.