BRIEFLeakhighP66
Data leak of 940 UASLP students including photos
UASLP (Universidad Autónoma de San Luis Potosí)
Detected13 September 2026 · 05:12 UTC
A threat actor published a database of roughly 940 students from the Universidad Autónoma de San Luis Potosí (Mexico), bundling personal data with facial photographs. The combination of identity data and biometric images enables identity theft, harassment and social-engineering attacks against the institution. It is a fresh, regionally relevant education-sector leak that defenders in Latin America should track.
CategoryLeak
Severityhigh
Priority score66
Detected13 September 2026 · 05:12 UTC
Leak● 44
Publicación de 2,7 GB de logs de stealer frescos (12-09-2026)A 2.7GB archive of freshly captured infostealer logs dated 12-09-2026 was posted, containing stolen credential and session data. Such logs commonly feed credential stuffing and initial-access attempts against corporate and consumer accounts. It is broad and untargeted, but its freshness makes it worth monitoring for any exposed organizational credentials.Leak● 56
Filtración de un millón de datos personales de usuarios de IKEAAn actor claims to be leaking roughly one million pieces of IKEA customer personal information on a criminal forum. At this scale the records can fuel phishing, account takeover and fraud against a major global retailer and its customers. The claim should be validated and cross-checked against known IKEA breach data.Leak● 75
Venta de 23 bases de datos de Grupo ATC (México y EE.UU.): 340 GB y 2.000 millones de filasA threat actor is selling 23 databases belonging to Grupo ATC across Mexico and the USA, totaling over 340 GB and roughly 2 billion unique rows. The scale implies large volumes of customer or identity data, directly relevant to Latin American breach monitoring. A leak this size can fuel fraud and credential-stuffing against Mexican users and partner organizations.Leak● 48
Filtración de 6,95 millones de credenciales URL:LOG:PASSA 6.95 million-line URL:log:pass credential list of stealer logs is being resold and mirrored across multiple forums. Its scale and cross-forum distribution make it valuable for credential stuffing against web and VPN portals. Organizations should screen exposed credentials for corporate and government domains.Leak● 55
Base de datos siria publicada en BreachForumsA freshly posted database labeled 'Syrian' appeared on BreachForums today. Large regional population datasets typically contain PII that supports identity fraud and targeted phishing campaigns. Though outside LATAM, it is worth tracking as part of broader breach-monitoring activity.Leak● 58
Base de datos de usuarios de Bitcoin a la venta en DarkNetArmyA vendor on DarkNetArmy is advertising a large 'Bitcoin user database vault 2026' targeting crypto account holders. If genuine, such data fuels account takeover, phishing and theft of funds, and is commonly reused for credential stuffing across exchanges. Authenticity is unverified, so treat it as a lead for monitoring rather than a confirmed breach.