BRIEFLeaklowP42
Drupal.org database leak with 1.75 million lines
Drupal.org (Drupal Association)
Detected3 October 2026 · 23:55 UTC
A dataset attributed to Drupal.org (~1,752,873 lines) with full names, emails and phone numbers is being circulated on xReactor. Drupal is the upstream CMS behind many government and enterprise portals, so leaked credentials could enable follow-on access attempts. It is likely a repackaged older leak, so treat it as low-urgency but check for password reuse.
CategoryLeak
Severitylow
Priority score42
Detected3 October 2026 · 23:55 UTC
Leak● 45
Dump de 18 millones de URL:LOG:PASS (VULTA.PW) compartidoAn 18-million-record URL:LOG:PASS dump is being shared and marketed as fresh under 'VULTA.PW'. This volume of stolen credentials can drive automated account-takeover campaigns, so regional SOCs should watch for reuse of these logins. It is commodity data but of significant scale.Leak● 48
Dump de 19,6 millones de credenciales (LUPIN ULP) en circulaciónA bulk credential dump of roughly 19.6 million url:login:password records ('LUPIN ULP') is being circulated from a VIP forum section, dated 10/04/2026. Large stealer-log sets like this enable large-scale credential stuffing and account takeover across many services, including exposed Latin American accounts. Though commodity, its scale warrants monitoring for ATO against regional assets.Leak● 58
Dump de credenciales argentinas (13.008 registros) publicadoA mail:password dump of 13,008 credentials labeled specifically for Argentina was posted by 'EvenRoad' on Niflheim. Although small, it is region-targeted and can fuel credential-stuffing against Argentine corporate and public services. Defenders should check for reuse of these credentials in AR-facing systems.Leak● 60
Venta de base de datos de reservas de GuruHotel (528K filas)A seller offers the full GuruHotel reservations database: 528K rows with roughly 6,300 guest PII leads. Booking data typically includes names, contact details, stay dates and payment hints, enabling targeted phishing and fraud against travelers and corporate clients. The organization should confirm the breach and notify affected guests.Leak● 58
Base de datos de Coinbase, de hasta 6 meses, a la ventaA seller on DarkForums is offering a 'high quality' Coinbase database, claimed to be one to six months old. If genuine, it exposes crypto-exchange account data valuable for account takeover and financial fraud. Worth verifying and monitoring for reuse of leaked customer identities.Leak● 45
Base de datos de 12 millones de Paradox Interactive a la ventaA 12M+ record database attributed to game publisher Paradox Interactive is circulating for sale or download. It is a real, large corporate dataset but tied to gaming accounts rather than critical infrastructure. It remains useful for credential-stuffing intelligence and account-takeover campaigns.