BRIEFLeaklowP33
Leaked databases of three Turkish tourism companies
luksartvin.com.tr, fatihturizm.com.tr, ustundagturizm.com.tr
Detected27 September 2026 · 17:48 UTC
Leaked databases from three Turkish travel/tourism websites are being advertised on a leak forum, exposing customer and booking data from small regional operators. The scale is limited and the victims are outside Latin America, so direct impact for AR-LATAM defenders is low. It is still relevant as a reminder that sector vendors and booking platforms can leak PII used for targeted fraud.
CategoryLeak
Severitylow
Priority score33
Detected27 September 2026 · 17:48 UTC
Leak● 42
Publicación de un millón de registros URL:LOG:PASS de stealer logsA dump of roughly one million URL:LOG:PASS credential records harvested by infostealers is being freely shared across multiple leak forums. This is unstructured but very large and fresh, exposing live session URLs and plaintext logins that feed account takeover and VPN/SSO abuse. Defenders should treat it as a broad credential hygiene alert, especially for any reused corporate or government emails.Leak● 62
Filtración de la base de datos del Ministerio de Educación de MarruecosA database belonging to Morocco's Ministry of Education is being distributed on BreachForums, exposing government records tied to a national education authority. If confirmed, this is a public-sector breach affecting student and citizen data, useful for identity theft and targeting public employees. Government and education defenders should watch for credential reuse and phishing built on this data.Leak● 42
Filtración de datos de Banc Certified (banccertified.com)A database belonging to Banc Certified Merchant Services (banccertified.com), a payment/merchant-services provider, has been leaked and is offered for download. Breach of a financial-services firm can expose customer and transaction data usable for card fraud. Merchant-services defenders should monitor for downstream phishing, card fraud and credential stuffing.Leak● 46
Colección de 480 volcados SQL (9 GB) filtradaA 9 GB archive containing 480 SQL dumps reportedly taken from multiple organizations (e.g., esac.sk, osme.es, aba.ae, aepaa.pt) has been published. The volume and mixing of sources indicate broad database exfiltration or aggregation, exposing user records and credentials. Defenders whose domains appear should assume compromise, rotate credentials and audit for reuse.Leak● 54
Base de datos del Federal Bank a la venta (2026)A seller is advertising a 'Federal Bank' customer database dated 2026 on an unverified darkweb marketplace, posted minutes ago. If genuine, the record set would expose account holders' personal and banking data, enabling fraud and account takeover. Financial-sector defenders should watch for credential reuse and targeted phishing built on this data.Leak● 30
Filtración de la base de datos de usuarios de HomePad.comA moderator posted the HomePad.com user database on a leak forum in June 2026, exposing account and personal data of the site's users. Although the post is a few months old, the data remains usable for credential stuffing and phishing. Affected users should rotate passwords and defenders should watch for reuse.