BRIEFLeakhighP55
PII leak of 450,000 hardware wallet users (Ledger, Trezor)
Detected1 October 2026 · 07:47 UTC
A forum post offers a database of roughly 450,000 PII records belonging to users of hardware wallets such as Ledger, Trezor, SafePal and OneKey, with contact and account-related details. Such data enables highly targeted phishing, SIM-swap and physical/extortion campaigns against crypto holders who control significant funds. Defenders should treat exposed hardware-wallet PII as a priority for customer alerting and fraud monitoring.
CategoryLeak
Severityhigh
Priority score55
Detected1 October 2026 · 07:47 UTC
Leak● 42
Filtración de base de datos de FiestasMix (131K registros)A 131K-record database of FiestasMix, a Spanish event and ticketing platform, is being offered for sale, exposing customer PII. Spanish-speaking users are the affected population. The post dates to August 2026, so it is adjacent to but outside Argentina and not a fresh alert.Leak● 50
Venta de datos personales de usuarios de monederos hardware (Ledger, Trezor, SafePal, OneKey)A dataset of PII belonging to users of hardware crypto wallets (Ledger, Trezor, SafePal, OneKey) is being sold, likely aggregated from prior breaches and data-broker leaks. These records expose names, addresses and contact details that fuel phishing, SIM-swap and physical/extortion targeting of crypto holders. Aggregated wallet-user data is a recurring high-value lure for social engineering.Leak● 62
Base de datos de la agencia india NTA (nta.ac.in) a la ventaA seller is offering a database belonging to nta.ac.in, the Indian National Testing Agency, a government body that holds candidate and student exam records. Government-held PII of this kind enables identity fraud, scholarship/loan fraud and targeted phishing. The sale of a state agency database is a high-impact supply of personal data for downstream abuse.Leak● 55
Filtración de base de datos de Mint Mobile con 50 millones de usuariosA threat actor is selling a database claimed to hold 50 million Mint Mobile records, exposing customer PII (names, phone numbers, likely SIM/identity data) of a major US mobile carrier. Such data directly fuels SIM-swap and account-takeover attacks. The post dates to June 2026, so it is not a fresh alert, but it remains a large telecom breach worth tracking.Leak● 45
Filtración de base de datos de Instagram con 17 millones de cuentasA forum thread circulates an alleged Instagram database of about 17 million accounts, likely credentials or profile data. Even if partly recycled from older breaches, such volume fuels credential stuffing, phishing and account takeover across services that reuse the same credentials. Confirming recency and uniqueness is essential before treating it as a new incident.Leak● 50
Filtración de base de datos del portal educativo San Patricio de ParaguayA threat actor is leaking a database belonging to the Paraguayan educational portal spiapp.sanpatricio.edu.py, exposing student, parent and staff data. School portals routinely hold personal details and credentials that enable phishing and account takeover. It matters as a real LATAM-entity breach, even though the blast radius is limited to one institution.