BRIEFLeakhighP48
Database leak of US records firm Morgan Records Management
Morgan Records Management
Detected29 September 2026 · 16:07 UTC
Actor V0idix on DarkForums is offering a database belonging to Morgan Records Management, a US firm that handles medical and business records. Exposed patient and client PII can fuel identity theft and targeted phishing. Defenders tied to this vendor or its clients should treat shared credentials as compromised and monitor for reuse.
CategoryLeak
Severityhigh
Priority score48
Detected29 September 2026 · 16:07 UTC
Leak● 33
Base de datos de CoinTracker.io a la venta en un foroA seller on DarkForums is offering a database allegedly taken from crypto portfolio tracker CoinTracker.io, with the listing first posted around mid-2025. Crypto user data is high-value for phishing, wallet-drain and SIM-swap attacks against holders. The listing is stale, so it is a useful intelligence datapoint rather than a fresh alert.Leak● 42
Filtración de base de datos de Rentomojo con 500.000 registrosA leaked database containing 500,000+ records attributed to Indian furniture and appliance rental firm Rentomojo surfaced on BreachForums. Customer PII of this size feeds phishing, account takeover and identity-fraud campaigns against both the firm and its users. Though outside Latin America, it is a named-victim corporate leak worth tracking for credential-reuse risk.Leak● 60
Filtrados datos internos de la química alemana Lanxess (14k usuarios)An actor is leaking 'Lanxess Internal Data' covering roughly 14,000 users of the German specialty-chemicals group Lanxess, posted September 20, 2026. Internal employee records of a major manufacturer enable targeted social engineering and, in this sector, critical-infrastructure exposure. Treat exposed accounts as compromised.Leak● 32
Filtración de datos de 17Media (17.live) con 28 millones de registrosA forum post offers a leaked dataset from the 17Media/17.live live-streaming platform containing roughly 28 million records. While the scale is large and could fuel account-takeover and extortion, the post is dated March 2026 and is therefore roughly six months stale, not a fresh alert. It is worth tracking for contextual exposure and downstream credential abuse but is low priority right now.Leak● 72
Filtración de base de datos de Transfast/Mastercard con 11 millones de registrosA threat actor is advertising a Transfast/Mastercard data breach of roughly 11 million records, freshly posted to a dark web forum. The dataset reportedly contains payment-transfer customer data, which enables card fraud, account takeover and targeted phishing against banks and fintechs. Financial-sector defenders should verify exposure and monitor for downstream fraud.Leak● 45
Filtración de 235.000 registros de escuela de Hong Kong (mckln.edu.hk)The ANKA TEAM/TurkHackTeam actor claims a 235k-record database leak from mckln.edu.hk, a Hong Kong educational institution. Leaked student and staff PII can drive phishing, credential stuffing and downstream account takeover. It is a real organization with a sizable breach, but it is outside the Argentina/LATAM region and only moderately impactful.