BRIEFLeakhighP58
Ledger database leak of 309,000 customer records
Ledger
Detected20 September 2026 · 14:37 UTC
A threat actor is circulating a leaked Ledger customer database of roughly 309,000 records dated 2026. Ledger is a leading crypto hardware-wallet vendor, so the exposed names, emails and addresses fuel phishing, wallet-drainer and SIM-swap attacks against crypto holders. Defenders should alert users and watch for credential abuse.
CategoryLeak
Severityhigh
Priority score58
Detected20 September 2026 · 14:37 UTC
Leak● 28
Base de datos KYC de 6 GB de AlphaEX a la ventaA 6 GB dataset described as KYC data from 'AlphaEX' has been offered on a DarkNetArmy forum since December 2025. KYC records contain identity documents and personal details that fuel identity fraud and account takeover on financial platforms. It is an older post and not a fresh alert, but the dataset may still circulate and be resold.Leak● 55
Base de datos de cargasectorial.info publicada en foroA full database for the domain cargasectorial.info was posted on a RAIDFORUMS mirror on 20 September 2026. The Spanish name suggests a Latin American operation, and the dump likely contains user accounts and possibly customer records. If it belongs to a logistics or industrial firm, leaked credentials could enable lateral movement into connected systems.Leak● 62
Filtración de base de datos con 153.136 personas de Celaya, MéxicoA free dump of a database containing roughly 153,136 individuals linked to Celaya, Guanajuato (Mexico) was posted on DarkForums minutes ago. If it holds national ID, address, or phone data it directly enables identity theft and targeted fraud against residents. Given Celaya's profile, resident-data exposure also carries physical-safety implications; defenders should verify scope and warn affected people.Leak● 31
Filtración de la base de datos de LearnCrypto.comA database for the crypto-education site LearnCrypto.com was posted to a leak forum in early 2026. If confirmed, exposed user credentials and emails enable account takeover and phishing against crypto-interested users. Relatively low scale, but a named-organization leak worth noting.Leak● 44
Filtración de la base de datos de la Universidad de PensilvaniaA database belonging to the University of Pennsylvania is being offered for download on a hacking forum. University breaches typically expose student and staff PII, credentials and research data, enabling account takeover and downstream targeting of affiliates. It highlights continued education-sector exposure.Leak● 50
Venta de 700.000 leads de usuarios de CoinbaseA vendor is selling roughly 700,000 Coinbase leads covering multiple countries. Crypto-exchange customer lists are prime material for phishing, account-takeover and social-engineering campaigns against account holders. The scale makes it worth tracking even though it is not a region-specific incident.