BRIEFLeakhighP70
Database and source code leak of smpw.net (Jehovah's Witnesses)
smpw.net (Testigos de Jehová)
Detected8 October 2026 · 11:07 UTC
A threat actor is publishing a full database dump plus the underlying source code of smpw.net, a Jehovah's Witnesses platform, in a very recent post. Exposed data likely includes member accounts and personal details, enabling credential stuffing and phishing against a large, identifiable user base. Defenders should treat any reused credentials as compromised.
CategoryLeak
Severityhigh
Priority score70
Detected8 October 2026 · 11:07 UTC
Leak● 43
Base de datos de PayPal con 14 millones de registros a la ventaSeller Marx is listing a database attributed to PayPal with over 14 million records on DarkForums, dated 4 October 2026. PayPal is a very high-value target, but such posts often recycle old data, so authenticity is unconfirmed. It still warrants monitoring for financial fraud and credential re-use.Leak● 47
Filtración de la base de datos de Meetic disponible para descargaA claimed Meetic dating-platform database is being offered for free download on BreachForums. Such a leak would expose credentials, emails and personal details of millions of dating users in Europe. Defenders should validate scope and watch for credential stuffing and re-use.Leak● 62
Base de datos de MedGulf (Bahréin) con 490.000 registros a la ventaAn actor on DarkForums (Marx) is selling a database tied to medgulf.com.bh with over 490,000 records, posted on 4 October 2026. MedGulf is a health insurer operating in the Gulf, so the leak likely exposes personal and medical data of policyholders. Healthcare and insurance defenders should verify authenticity and prepare notifications.Leak● 45
Venta de 1,67 millones de credenciales URL:LOG:PASSA seller is offering a 'fresh, private, valid' dump of 1.67 million URL:LOG:PASS credentials, a format consistent with stealer or combolist output. Credential sets of this type enable credential stuffing and initial access against web portals and exposed logins. The origin and target scope are unverified, so treat it as a mass credential exposure rather than a confirmed breach.Leak● 50
Filtración de 2.500 registros de stealer de México (Windows 10)A free dump of roughly 2,500 infostealer logs harvested from machines in Mexico running Windows 10 Enterprise was posted today. Such logs typically contain browser-saved credentials, cookies and live session tokens that enable account takeover and initial network access. For LATAM defenders this is a fresh, region-specific exposure that warrants credential resets and compromise hunting.Leak● 40
ShinyHunters publica base de datos ANTS de 13,1 millonesShinyHunters posted a 13.1M-record database named 'ANTS' to BreachForums, a large dump from a known prolific group. The post dates from June 2026 and is not fresh, so it is not a new alert, but its scale makes credential reuse and follow-on attacks likely. Useful for tracking past exposure and credential hygiene.