BRIEFLeaklowP34
University of Pennsylvania database leak
University of Pennsylvania
Detected14 September 2026 · 18:12 UTC
A DarkForums thread markets a database attributed to the University of Pennsylvania, a well-known US institution. It is a real named-org leak but sits outside the Argentina/LATAM remit and is dated April 2026, so it is stale rather than a fresh alert. Worth logging for context only.
CategoryLeak
Severitylow
Priority score34
Detected14 September 2026 · 18:12 UTC
Leak● 22
Combolist de 180.000 credenciales de ColombiaA NulledBB post advertises a roughly 180K-line combo list targeting Colombian accounts, dated 11 August 2026. It is a regional credential dump rather than a named-org breach or access sale, and combolists are largely commodity noise. Minimal defensive value beyond credential-stuffing awareness.Leak● 32
Filtración de 1M de registros de un salón de belleza de CanadáA 1M-record database belonging to a Canadian beauty salon is being shared free on BreachForums, likely containing customer PII and credentials. The volume is large enough to feed credential-stuffing and phishing campaigns, though the victim is a small private business outside the LATAM region.Leak● 72
Filtración de base de datos de la Universidad Corporativa FP PerúA database of about 1M user records from Universidad Corporativa FP Peru has been posted for download on DarkForums, exposing student and staff identities. As a Latin American education target, the leaked credentials and personal data can fuel phishing, account takeover and credential stuffing against related regional institutions.Leak● 38
Filtración de pasaportes y documentos de identidad de EAU (3,5 GB)A 3.5 GB archive of UAE passports and national ID documents is being traded, exposing sensitive identity data usable for fraud and account takeover. The thread sits at page 29, indicating it has circulated for a long time rather than being fresh. Impact is real but outside the AR-LATAM region.Leak● 25
Filtración de base de datos del JPJ, transporte de MalasiaA database allegedly tied to Malaysia's Road Transport Department (jpj.gov.my) is circulating on BreachForums, a genuine government source. However, the post dates to November 2024 and is a repost, and the victim is outside Latin America, so it carries little current alerting value.Leak● 48
Filtración de 1,49M de registros de empresas estatales indiasA dataset with roughly 1.49 million records tied to India's Central Public Sector Enterprises (CPSE) is being circulated on DarkForums. It reportedly includes employee and contact details of state-owned companies. Such government-linked data fuels phishing, impersonation and credential-stuffing campaigns against public-sector and supplier targets.