BRIEFLeaklowP28
Leak of CURP and RFC ID data of Mexican citizens
Mexican citizens (CURP/RFC)
Detected12 September 2026 · 18:12 UTC
Personal CURP and RFC records belonging to Mexican citizens were posted, apparently scraped from a scam site. These identifiers are used across Mexican government and tax services, so exposure enables identity theft and fraudulent procedures. Even a partial set is worth flagging for Mexican fraud-watch and KYC teams.
CategoryLeak
Severitylow
Priority score28
Detected12 September 2026 · 18:12 UTC
Leak● 60
Supuesta filtración de 33GB con bases de datos y claves API de StripeA forum listing claims 33GB of data from Stripe, covering 662 databases and 1033 API keys, is compromised. Stripe is a global payment processor whose leaked keys could enable fraudulent charges and downstream data access for merchants. Defenders should rotate keys and audit for anomalies, though the claim is unverified and may be repackaged marketing.Leak● 35
Base de datos del banco central de Indonesia (BI.GO.ID) filtradaA 5,000-record sample attributed to Bank Indonesia (BI.GO.ID) is circulating, presenting the country's central bank as a target. Although small and dated early 2025, even partial data from a central bank threatens customer and staff privacy and enables targeted social engineering. Monitor for a fuller dump or reuse of these identifiers.Leak● 40
Filtración de 2 millones de registros de vacunación COVID-19 de TurquíaA database with roughly 2 million Turkish COVID-19 vaccination records remains available, containing personal and health data of citizens. Medical datasets like this fuel phishing, insurance fraud and discrimination, and are routinely reused in later breaches. Despite its age, the scale makes it a persistent exposure for Turkish health and privacy teams.Leak● 50
Filtración del volcado SQL de la plataforma saudí saudigames.saAn actor posted a full SQL database dump allegedly taken from saudigames.sa, Saudi Arabia's national Olympic games platform. The dump may expose participant accounts, contact data and other records tied to a state-linked sports body. It matters for regional CTI monitoring even though the target is outside Latin America.Leak● 55
Filtración de base de datos brasileña con 110.000 registrosA 110,000-record Brazilian database was released for free on the DarkNetArmy forum under the 'ROOT SYSTEM' banner as a community gift drop. The exact source organisation is not named, but the data set targets Brazilian individuals and could fuel credential stuffing, phishing and identity fraud against victims in the region. Defenders in Brazil should treat it as a fresh local leak and watch for reuse of the exposed records.Leak● 48
Equipo turco filtra base de datos de la Universidad Helenística (800.000 registros)The group AnkaTeam claims to have hacked a subdomain of Helenistik University and leaked roughly 800,000 records. University databases hold sensitive personal, academic and staff data that supports phishing and identity theft. The claim of a live subdomain compromise also points to weak perimeter controls at the institution.