BRIEFLeaklowP45
Admin VM leak of crypto exchange KuCoin
KuCoin
Detected26 September 2026 · 00:33 UTC
A forum post claims to offer a leaked administrator virtual machine for KuCoin, a major crypto exchange. Admin-level access to an exchange could let attackers drain funds, tamper with internal systems or pivot to user data, making it high-impact if genuine. The post is dated January 2026, so it is stale and should be treated as background rather than a fresh alert.
CategoryLeak
Severitylow
Priority score45
Detected26 September 2026 · 00:33 UTC
Leak● 35
Filtración de la base de datos de Serasa Experian (Brasil)A large dump attributed to Serasa Experian, Brazil's biggest credit bureau, is circulating for download. Such records typically contain personal and financial data of millions of Brazilian consumers, enabling identity theft and fraud. The thread appears tied to older RaidForums activity, so it is context rather than a fresh alert.Leak● 40
Datos 'Top Secret' del Ministerio de Defensa de la India a la ventaA 'Top Secret' Indian Ministry of Defence dataset is advertised for sale, mirroring posts dated May 2025 across several forums. If authentic, leaked defense technology or procurement data could aid espionage against a foreign government. However the posting is stale and outside the AR-LATAM region, so it ranks well below fresh regional alerts.Leak● 85
Venta de 15 millones de filas de datos de bancos brasileñosA seller on DarkForums is offering 15 million rows of Brazilian bank data, posted in late September 2026. Financial records enable account takeover, fraud and identity theft, and typically include PII and account details. Brazilian banking is critical infrastructure, so this warrants urgent validation and customer-notification planning.Leak● 55
Filtración de base de datos de la app china 'AnGeMo' con 1,8 millones de usuariosAn actor posted a database said to contain 7.5 million orders and 1.8 million user records from the Chinese massage-booking app 'AnGeMo'. The volume and PII/financial fields make it a strong credential-stuffing and fraud source. It is outside the LATAM region, but the scale warrants tracking for downstream resale.Leak● 60
Datos y código fuente de la plataforma Kayako puestos a la ventaA seller is offering both customer data and the proprietary source code of Kayako, a helpdesk/CRM platform used by many enterprises. Source-code disclosure is high-value because it lets attackers locate auth, file-upload and deserialization flaws and pivot into any organization running the product. No date or sample is shown, so the claim needs verification before acting.Leak● 42
Filtración de base de datos de sdmtponorogo.com (250K registros)TurkHackTeam's AnkaTeam is publishing a 250K-record database allegedly taken from sdmtponorogo.com, an Indonesian website. While not a high-value government target, it is a named organisational breach with real user records that fuels credential stuffing and phishing. Useful mainly as a signal of ongoing regional hacktivist leak activity.