BRIEFLeakhighP72
Leak of Colombia employee device registration database
Detected5 October 2026 · 11:55 UTC
Reposts collapsed2
An actor posted on DarkForums a database labeled 'Colombia_Employee_Device_Registration' with employee and device records from a Colombian entity. The posting is fresh (minutes before detection), raising the risk of immediate abuse. For a regional defender it exposes internal data that enables targeted phishing and corporate network access.
CategoryLeak
Severityhigh
Priority score72
Detected5 October 2026 · 11:55 UTC
Leak● 50
Base de datos de 430.000 usuarios de Dubizzle (EAU) a la ventaA seller on BreachForums offers a 430,000-user profile database from Dubizzle (UAE), including emails, phones, and transactions. It is a large leak of a real e-commerce platform, though outside Latin America. Regionally it mainly serves as a reference for resold e-commerce data, with limited direct impact.Leak● 58
Filtración de base de datos del centro médico CEMADOJA (Rep. Dominicana)DarkForums lists a leak attributed to the Centro de Educación Médica de Amistad Dominico-Japonesa (CEMADOJA), a Dominican Republic medical and education entity. The exact date is not visible, but it is a real regional organization's database. Exposure of medical and personal data is sensitive under health rules and enables fraud and social engineering.Leak● 35
Datos privados de México, EE.UU. y Canadá a la ventaA bundle advertised as private data from Canada, Mexico and the USA is being shared as a checked set of personal records. The Mexican portion is relevant for the region and could enable fraud or account takeover. The post is undated, unverified and its true scale is unclear, so treat it as low confidence.Leak● 64
Base de datos de salud de Türkiye Sigorta a la ventaA seller is offering a 13-million-row database of Türkiye Sigorta health and treatment records, exposing sensitive medical data of Turkish policyholders. A leak of this scale enables identity fraud, insurance scams and targeted phishing. It concerns a real insurer, but lies outside AR-LATAM and the post is undated.Leak● 28
Filtración de comunicaciones internas de RyanairA leak of Ryanair's internal communications is being shared, dated November 2025 and thus almost a year old. It may expose internal email, operational or employee details. Because it is dated and outside the AR-LATAM region, it is not a fresh alert but is worth noting for context.Leak● 78
Base de datos de oficiales de inteligencia saudíes a la ventaA threat actor is offering a claimed database of Saudi intelligence officers on RaidForums/BreachForums, listing names and identifying details of government personnel. If genuine, this is a high-impact leak of sensitive state-intelligence data of interest to both criminal and state-sponsored actors. Although outside the AR-LATAM scope, it flags an active government-data leak worth tracking for actor and tooling overlaps.