BRIEFLeakhighP74
Data breach at a Costa Rican credit reporting agency
Agencia de reporte de crédito de Costa Rica
Detected13 September 2026 · 22:12 UTC
An actor claims to have hacked a Costa Rican credit reporting agency and obtained large volumes of consumer credit data. Credit bureaus hold complete financial PII (identities, debts, payment histories), making this a serious leak for the region. Impacted citizens face identity theft and financial fraud, and downstream lenders should expect abuse of the exposed records.
CategoryLeak
Severityhigh
Priority score74
Detected13 September 2026 · 22:12 UTC
Leak● 28
Presunta filtración y dox de datos de BCA LTDA forum post claims a data leak and dox of 'BCA LTD' exposing resident records, published under a user linked to Argentina (LaPampaLeaks). The organization, scope and record count are unclear, and the post is several months old. It is at most a low-priority lead pending verification of the entity and data.Leak● 88
Base de datos de la Clínica Nacional de Chile y RENAPER filtradaA full database tied to Chile's Nacional Clinic and Argentina's RENAPER national identity registry is being offered on a darkweb forum. RENAPER holds core citizen identity data (DNI, names, addresses, biographic records), so its exposure is extremely sensitive for both countries. Defenders should treat this as a high-impact PII/identity leak enabling impersonation, fraud and targeted social engineering.Leak● 50
Brecha de 250 millones de números de Seguro Social de EE. UU.A long-running thread offering a 250 million-record US SSN dataset keeps being bumped, indicating the data remains in circulation. Exposure at this scale enables identity theft, loan fraud and account takeover. US and global fraud teams should treat affected individuals as high risk and watch for synthetic-identity abuse.Leak● 62
Base de datos GSM de Turquía con 145 millones de registrosA 145 million-record Turkish GSM database is being circulated, a scale that points to subscriber-level data such as phone numbers and possibly identity details. Such data drives SIM-swap, smishing and account-takeover campaigns. Telcos and regional partners should assess exposure and warn affected customers.Leak● 45
Venta de 7,95M de stealer logs (URL:LOG:PASS) con credencialesA seller is dropping 7.95 million URL:login:password stealer log entries, posted minutes ago. Logs like these often carry corporate SSO, VPN and webmail credentials that feed follow-on intrusions. Even as commodity data, the volume warrants watching for credentials tied to regional organizations.Leak● 68
Base de datos de 153 millones de consumidores de EE. UU. a la ventaA seller is offering a 153 million-record US consumer database dated 2026 and posted within the last day. The scale indicates a major aggregation of personal data usable for identity theft, phishing and account takeover. This volume is worth monitoring for downstream fraud affecting US consumers and their partners.