PULSE
FEED
ransomn0n reclama a Company #5 · Not Foundransomn0n reclama a Company #4 · Not Foundransomrhysida reclama a Charles E. Tabor AAL LLC · US · Otherransomdragonforce reclama a TQC S.A. · PE · Manufacturingransomqilin reclama a Confipetrol · CO · Energy & Utilitiesransomdragonforce reclama a TEXMA International Co., Ltd · TW · Manufacturingransomthegentlemen reclama a Royal Thai Air Force · TH · Government & Defenseransomumbra reclama a Helwan University (HITU) · EG · Educationransomredact reclama a DexCom · US · Healthcareransomqilin reclama a ACI Proyectos SAS · CO · Otherransomexitium reclama a KOIKE Sanso Kogoyo Co. Ltd. · JP · Manufacturingransomrhysida reclama a Gress Clark Young & Schoepper · US · Professional Servicesransomqilin reclama a Glenhardie Country Club · US · Hospitalityransomqilin reclama a LD Constructora · CL · Manufacturingransomn0n reclama a Company #5 · Not Foundransomn0n reclama a Company #4 · Not Foundransomrhysida reclama a Charles E. Tabor AAL LLC · US · Otherransomdragonforce reclama a TQC S.A. · PE · Manufacturingransomqilin reclama a Confipetrol · CO · Energy & Utilitiesransomdragonforce reclama a TEXMA International Co., Ltd · TW · Manufacturingransomthegentlemen reclama a Royal Thai Air Force · TH · Government & Defenseransomumbra reclama a Helwan University (HITU) · EG · Educationransomredact reclama a DexCom · US · Healthcareransomqilin reclama a ACI Proyectos SAS · CO · Otherransomexitium reclama a KOIKE Sanso Kogoyo Co. Ltd. · JP · Manufacturingransomrhysida reclama a Gress Clark Young & Schoepper · US · Professional Servicesransomqilin reclama a Glenhardie Country Club · US · Hospitalityransomqilin reclama a LD Constructora · CL · Manufacturing
Kalir Brief · Item11 October 2026 · 11:32 UTC
BRIEFLeakhighP48

SCADA data leak of the Qingyuan control system (China)

Qingyuan Tracking System

Detected11 October 2026 · 11:32 UTC
Why it matters

A collection reportedly containing SCADA/tracking control-system data from Qingyuan, China, is being shared on BreachForums. SCADA exposures can reveal ICS network topology, credentials and device configuration, enabling downstream attacks on critical infrastructure. Though outside Argentina/LATAM, it is relevant as an ICS/OT data exposure and for tracking actors who resell such industrial data.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score48
Detected11 October 2026 · 11:32 UTC
Related items6
Leak● 47
Base de datos de una aseguradora japonesa publicadaA freshly posted DarkForums thread dated within minutes of discovery offers a database labeled 'Japan_insurance', pointing to records from a Japanese insurer. Insurance data is high-value for fraud because it links identity, policy and financial details. The victim is not named and the size is unstated, so it needs verification, but the recency makes it worth tracking.
1h
Leak● 42
Filtración de la base de datos de la plataforma PaidworkA DarkForums post dated 14 August 2026 shares a 'cleaned' database from Paidwork.com, a freelancing/payout platform, likely containing user account and contact data. Freelance and payout platforms are attractive for follow-on account-takeover and financial fraud against workers. It is a mid-sized, roughly two-month-old leak, so it is worth surfacing but not a fresh emergency.
1h
Leak● 38
Filtración de historiales de pacientes de LabQuest, RusiaA forum post offers a 466,000-row database from LabQuest, a Russian medical lab, reportedly containing patient records plus PST email archives belonging to top managers. The executive mailboxes are the notable part, since they can enable business-email-compromise and lateral phishing. Scale is modest, so it ranks below the larger regional leaks but still exposes healthcare PII.
1h
Leak● 56
Filtración de 554M de líneas de la base de datos de GemotestA BreachForums thread discusses a claimed 554-million-line database from Gemotest, a large Russian medical-testing lab, reportedly covering customer orders and patient records. Such a volume implies massive exposure of sensitive health and identity data for a real healthcare provider. Defenders in healthcare should note the pattern of medical-lab data being traded in bulk and watch for credential-stuffing against related portals.
1h
Leak● 52
Dudosa filtración de 210M de registros de Gosuslugi, RusiaA forum thread is re-examining a claim of 210 million rows allegedly taken from Gosuslugi, Russia's national state-services portal, covering citizen PII such as names, phones and IDs. If genuine it is one of the largest government data exposures, enabling mass identity fraud and targeted phishing. The claim is still being verified, so reliability remains uncertain and should be treated cautiously.
1h
Leak● 78
Base de datos de 3TB de Salesforce publicada en foro clandestinoA 3TB database labeled 'Salesforce 2026' was posted on DarkForums only minutes ago, pointing to a very large and potentially fresh exfiltration. Salesforce is widely used by enterprises and public bodies, so a leak of this size could expose customer records and business data across many victim organizations. Defenders should watch for credential reuse and customer-targeting phishing.
2h