BRIEFLeakcriticalP85
SQL database leak of Mexico's Universidad Pedagógica Nacional
Universidad Pedagógica Nacional (México)
Detected4 October 2026 · 02:55 UTC
A leaked SQL dump of Mexico's Universidad Pedagógica Nacional (UPN), a federal public education institution, is being posted on a dark-web forum within minutes of discovery. The dump likely exposes student, staff and internal records, giving attackers a working map of the institution's database. Defenders should identify the source of the leak, patch exposed services and prepare notification for affected individuals.
CategoryLeak
Severitycritical
Priority score85
Detected4 October 2026 · 02:55 UTC
Leak● 72
Base de datos de GameStop con 27 millones de registros a la ventaA threat actor is offering a 27-million-record GameStop database containing email:password combinations, claiming a value around $800M. Dumps of this size directly fuel credential stuffing and account takeover against the retailer and its customers. Defenders should force credential resets, watch for reused passwords and monitor for downstream fraud.Leak● 44
Filtración de 426.000 credenciales de EspañaA large combolist of roughly 426,000 email and password pairs targeting Spanish users was posted, dated late June 2026. Though aggregated credential lists are common, the volume and Spain focus make it usable for credential-stuffing against Spanish accounts. Organizations and users in Spain should reset exposed passwords and monitor for account takeover.Leak● 68
Base de datos de 8.045 colegios de Chile a la ventaA threat actor is selling a database covering 8,045 schools in Chile, likely including institutional and contact details. Education-sector data in Latin America is valuable for phishing and fraud and may include student or staff records. Defenders in the Chilean education sector should verify exposure and warn affected institutions.Leak● 45
Dump de 18 millones de URL:LOG:PASS (VULTA.PW) compartidoAn 18-million-record URL:LOG:PASS dump is being shared and marketed as fresh under 'VULTA.PW'. This volume of stolen credentials can drive automated account-takeover campaigns, so regional SOCs should watch for reuse of these logins. It is commodity data but of significant scale.Leak● 48
Dump de 19,6 millones de credenciales (LUPIN ULP) en circulaciónA bulk credential dump of roughly 19.6 million url:login:password records ('LUPIN ULP') is being circulated from a VIP forum section, dated 10/04/2026. Large stealer-log sets like this enable large-scale credential stuffing and account takeover across many services, including exposed Latin American accounts. Though commodity, its scale warrants monitoring for ATO against regional assets.Leak● 58
Dump de credenciales argentinas (13.008 registros) publicadoA mail:password dump of 13,008 credentials labeled specifically for Argentina was posted by 'EvenRoad' on Niflheim. Although small, it is region-targeted and can fuel credential-stuffing against Argentine corporate and public services. Defenders should check for reuse of these credentials in AR-facing systems.