BRIEFLeaklowP37
Data leak of roughly 697,000 Substack users
Substack
Detected20 September 2026 · 13:37 UTC
A dataset of approximately 697,000 Substack accounts (2025) is circulating on a leak forum, most likely credential-style records (email/password) that fuel account takeover and credential stuffing. Substack is a US platform, so the direct impact is outside Argentina and Latin America. The February 2026 posting is not a fresh alert, but it is worth logging for credential-exposure tracking.
CategoryLeak
Severitylow
Priority score37
Detected20 September 2026 · 13:37 UTC
Leak● 28
Filtración de la base de datos del Ministerio de Justicia de FranciaA CSV export of personal data from the French Ministry of Justice (justice.fr) was posted on a leak forum, exposing names and other identifiers of individuals linked to the judicial system. It is a genuine government data exposure, but the post is from April 2023 and is therefore a stale item, not a fresh alert. It does not involve any Argentine or Latin American entity.Leak● 56
Filtración masiva de datos del parlamento de Sulawesi CentralA threat actor is distributing a 366K-record database allegedly belonging to the DPRD (regional legislature) of Central Sulawesi, Indonesia. Government records of this type typically include citizen PII, official communications and internal identifiers enabling follow-on fraud, phishing or intelligence gathering. Public-sector defenders should monitor for downstream abuse of the exposed data.Leak● 71
Filtración HATICA expone datos de JPMorgan, BrowserStack y GE HealthcareA claimed fresh breach dubbed HATICA reportedly bundles data from JPMorgan, BrowserStack and GE Healthcare, exposing records tied to major financial and healthcare targets. Third-party or vendor leaks like this enable downstream fraud, credential abuse and supply-chain targeting against connected organizations. Defenders at these firms and their partners should verify exposure and watch for credential-stuffing and phishing activity.Leak● 46
Filtración de datos de empleados de McDonald's IndonesiaA dataset described as McDonald's Indonesia worker records has been leaked for download. Employee PII such as names, identifiers and contact details can fuel phishing, payroll fraud and credential-based account takeover. The workforce data of a global brand is worth flagging even though the victim is outside Latin America.Leak● 52
Filtración de base de datos gubernamental de la regencia Kabupaten BeluA database belonging to the Belu Regency (Kabupaten Belu) local government in Indonesia has been published for download. Public-sector records can include citizen identity, civil-registry and administrative data, raising risks of identity theft and targeted fraud. Although outside Latin America, a government data leak is notable for regional watchlists.Leak● 22
Filtración de 1,2 millones de registros de la minorista rusa DetmirA 1.2 million-row database attributed to Russian retailer Detmir has been posted on DarkForums, though the underlying data dates from 2024. It likely includes customer names, emails and phone numbers usable for spam and credential attacks. Because the data is old and the victim is outside Latin America, it is only marginally relevant.