BRIEFAccess salelowP30
Leaked VM from Spanish crypto exchange Criptan
Criptan
Detected3 October 2026 · 19:03 UTC
A leaked virtual machine associated with Criptan, a Spanish cryptocurrency exchange, was posted in a leaked-tools section. Such environments can contain credentials, API keys or customer data. The post dates from January 2026, so it is stale but still relevant for Spanish fintech risk review.
CategoryAccess sale
Severitylow
Priority score30
Detected3 October 2026 · 19:03 UTC
Access sale● 35
Venta de acceso a máquina virtual de la exchange DigiFinexA listing offers a virtual machine allegedly belonging to DigiFinex, a global cryptocurrency exchange, dated early 2026. Such a leak could expose exchange infrastructure, API credentials or user data if verified. The post is several months old, so it is not a fresh access sale but may still be useful for tracking reused credentials and crypto-sector targeting.Access sale● 38
Venta de acceso a máquina virtual de la exchange CriptanA forum user is offering a virtual machine reportedly taken from Criptan, a Spanish-regulated cryptocurrency exchange, with a post date in early 2026. If genuine, the image could expose API keys, wallet access or customer data of a financial entity. However the post is months old, so it is not a fresh alert and should be treated as background intelligence for Spanish financial-sector defenders.Access sale● 45
Venta de acceso y base de datos de la Universidad Federal de AkureA seller advertises both access and a database from the Federal University of Technology, Akure (Nigeria). Combining entry access with a student/staff database enables account takeover, credential abuse and further intrusions across the institution's systems. It matters as a live access-sale listing against a named educational target.Access sale● 78
Acceso completo a red del MSP Kirey Group a la ventaA seller is offering full Active Directory 'golden ticket' access to Kirey Group, an IT managed service provider with roughly 1,600 employees. Golden-ticket access implies a complete domain compromise, letting an attacker impersonate any user or service and move laterally into the MSP's downstream clients. For defenders, an MSP compromise is a supply-chain risk that can cascade into every organization it manages.Access sale● 80
Venta de acceso en vivo y 5,6 TB de datos del aeropuerto de PakistánAn actor advertises live access to Pakistan's airport infrastructure alongside a 5.6TB data dump, signaling an ongoing intrusion with hands-on capability. The volume covers operational and passenger data at a national aviation target. Aviation and border-control defenders should treat it as a high-impact active breach.Access sale● 72
Venta de acceso a empresa LATAM de cobranza: webshell y SSH rootA seller is offering a webshell plus SSH root access to a Latin American debt-collection/robocall company, indicating full server compromise. This matters because it grants persistent privileged access to a region-relevant organization that handles large volumes of consumer PII, enabling fraud, spam, or lateral movement. Web shell + root is high-value initial access worth monitoring.