BRIEFLeakhighP82
Bolivian state airline BoA customer CRM data leak
Boliviana de Aviación (BoA)
Detected2 October 2026 · 22:03 UTC
A 437,000-record CRM database from boa.bo, the Bolivian state-owned airline Boliviana de Aviación, is offered for sale with customer personal and contact data. Exposing a state entity's customer CRM enables phishing and fraud against travellers. State-linked aviation data also raises operational and national-interest concerns.
CategoryLeak
Severityhigh
Priority score82
Detected2 October 2026 · 22:03 UTC
Leak● 45
Filtración de base de datos de la empresa médica italiana Alfamedic.itA database belonging to Italian healthcare provider Alfamedic.it has been posted on DarkForums for download. Leaked patient and client data from a medical entity enables targeted phishing and identity fraud. Although outside Latin America, it is a fresh breach of a real healthcare organisation worth tracking.Leak● 82
Base de datos de la aerolínea estatal Boliviana de Aviación a la venta en BreachForumsThe same Boliviana de Aviación dump is being reposted on BreachForums, confirming the leak is circulating across multiple forums. This amplifies exposure of a Latin American critical-infrastructure operator and increases the chance of the data being weaponised. Rapid verification of the affected records and customer notification is warranted.Leak● 85
Filtración de base de datos de la aerolínea estatal Boliviana de Aviación (BoA)A threat actor is distributing a database allegedly belonging to Boliviana de Aviación, Bolivia's state-owned flag carrier, on an underground leak forum. Aviation is critical infrastructure and a state operator, so any exposure of customer and operational records carries regulatory and national-security weight. Defenders in the region should treat it as a fresh breach and check for credential reuse and downstream phishing.Leak● 44
Filtración de datos de pacientes de HealthEngine (Australia)A 428,000-record database of Australia's HealthEngine is offered, containing patient contact data including emails. Health data exposure is sensitive and enables phishing and medical-related fraud. It is a notable large leak, though outside the LATAM region.Leak● 48
Filtración de 742.000 registros de mpac.ca (Canadá)A 742,000-record database from Canada's mpac.ca (Municipal Property Assessment Corporation) is for sale, containing residential property records and contact details. Property and owner data enables fraud and targeted campaigns. It is a large named-organization leak, though outside the LATAM region.Leak● 55
Filtración de 26 millones de ciudadanos venezolanosA leaked database of 26,375,483 Venezuelan citizens' records (names, IDs and personal data) is circulating, though the post dates to May 2025. Its scale makes it a lasting resource for identity fraud and targeting of Venezuelan nationals. Still relevant for regional defenders despite its age.