BRIEFLeakhighP71
HATICA breach exposes data from JPMorgan, BrowserStack and GE Healthcare
HATICA (JPMorgan, BrowserStack, GE Healthcare)
Detected20 September 2026 · 11:37 UTC
A claimed fresh breach dubbed HATICA reportedly bundles data from JPMorgan, BrowserStack and GE Healthcare, exposing records tied to major financial and healthcare targets. Third-party or vendor leaks like this enable downstream fraud, credential abuse and supply-chain targeting against connected organizations. Defenders at these firms and their partners should verify exposure and watch for credential-stuffing and phishing activity.
CategoryLeak
Severityhigh
Priority score71
Detected20 September 2026 · 11:37 UTC
Leak● 46
Filtración de datos de empleados de McDonald's IndonesiaA dataset described as McDonald's Indonesia worker records has been leaked for download. Employee PII such as names, identifiers and contact details can fuel phishing, payroll fraud and credential-based account takeover. The workforce data of a global brand is worth flagging even though the victim is outside Latin America.Leak● 52
Filtración de base de datos gubernamental de la regencia Kabupaten BeluA database belonging to the Belu Regency (Kabupaten Belu) local government in Indonesia has been published for download. Public-sector records can include citizen identity, civil-registry and administrative data, raising risks of identity theft and targeted fraud. Although outside Latin America, a government data leak is notable for regional watchlists.Leak● 22
Filtración de 1,2 millones de registros de la minorista rusa DetmirA 1.2 million-row database attributed to Russian retailer Detmir has been posted on DarkForums, though the underlying data dates from 2024. It likely includes customer names, emails and phone numbers usable for spam and credential attacks. Because the data is old and the victim is outside Latin America, it is only marginally relevant.Leak● 58
Filtración de base de datos de la empresa logística InPostA database attributed to InPost, one of Europe's largest parcel-locker and logistics operators, has been posted for download on a darkweb forum. Such a leak could expose customer, delivery and employee records, enabling phishing, account takeover and parcel fraud. InPost's scale in Poland and across Europe makes any confirmed breach operationally significant.Leak● 34
Filtración de base de datos de la Universidad de HarvardA database purportedly belonging to Harvard University has been shared on DarkForums. University breaches typically expose student and staff PII, credentials and internal directories, useful for credential stuffing and targeted phishing. However, the post dates from April 2026 and the victim is outside the region, so it is low priority here.Leak● 42
Filtración de la base de datos completa de Sctour.ruAn actor claims to hold the full database of Russian travel site Sctour.ru and is distributing it on DarkForums. Full customer databases typically contain names, contacts and booking/payment data, enabling fraud against the site's customers. Low regional priority but relevant if Sctour has Latin American partners or clients.