BRIEFLeaklowP32
Stealer log dump from 30,000 infected PCs (EagleCloud)
Detected21 September 2026 · 00:37 UTC
A fresh dump of stealer logs covering roughly 30,000 infected PCs was released, containing URL, login and password pairs harvested from victims. Although not tied to a named organisation, the scale lets attackers quickly pivot to corporate SSO, VPN and webmail access from reused credentials. Defenders should treat any matching credentials as compromised and force resets plus MFA.
CategoryLeak
Severitylow
Priority score32
Detected21 September 2026 · 00:37 UTC
Leak● 38
Lista de 541.000 credenciales de Booking.com, Airbnb y viajesA 541,000-line credential combolist targeting Booking.com, Airbnb and holiday-booking accounts is circulating, assembled from stealer logs. These credentials enable account takeover, fraudulent bookings and loyalty-point theft, and are frequently reused on corporate travel and mail accounts. Hospitality and travel firms should enforce MFA and watch for credential-stuffing.Leak● 45
Filtración de base de datos de 182.000 tarjetas de créditoA database of roughly 182,000 payment-card records was advertised as a 2026 leak, exposing cardholder data in bulk. Leaks like this fuel card-not-present fraud, account takeover and targeted phishing against affected issuers and merchants. Defenders should watch for card-testing bursts against payment endpoints and monitor BINs tied to the dumped cards.Leak● 45
Filtración de base de datos de telefonía de MovistarA BreachForums thread circulates what appears to be a database of Movistar mobile phone data; Movistar (Telefónica) is a major telecom across Argentina and Latin America. Subscriber records fuel SIM-swap, phishing and account-takeover attacks against millions of users and touch critical communications infrastructure. The post is dated April 2026, so it is stale rather than a fresh alert.Leak● 45
Filtración de datos del software médico Mon Logiciel MédicalA scraped dataset from Mon Logiciel Médical, a French medical-practice software, has been leaked and offered for download on a cybercrime forum. Breaches of medical software commonly expose patient records and login credentials shared across many clinics. Although the victim is outside Latin America, it matters to health-sector defenders assessing supply-chain exposure; low priority due to no clear scale or freshness.Leak● 50
ShinyHunters pone a la venta datos de CiscoThe prolific actor ShinyHunters is advertising 'Cisco Data' for sale on BreachForums. Cisco is a globally critical network-infrastructure vendor, so a genuine leak could expose customer, employee or configuration data with wide downstream risk. However the listing is dated April 2026, so it is not a fresh alert and should be treated as context rather than breaking intelligence.Leak● 78
Filtración de 120 GB de base de datos de RedClinica ChileA 120 GB database belonging to RedClinica, a Chilean clinical/health services provider, was posted for download on a cybercrime forum by user Synq1xxs less than a minute before discovery. The dump likely contains patient records, appointments and personal health data protected under Chilean law. Health-sector defenders in Chile should treat this as a confirmed breach and monitor for downstream identity theft, fraud and targeted phishing.