BRIEFLeakhighP45
Massive leak of 16 million stealer credentials (Secretline.top)
Secretline.top
Detected18 September 2026 · 12:12 UTC
A 16 million-line URL:login:password dump attributed to Secretline.top stealer logs was reposted across several underground forums. Bulk stealer logs routinely contain corporate and government credentials that fuel account takeover and VPN/RDP intrusions. Volume is high but provenance and freshness are unverified, so treat it as context rather than a targeted alert.
CategoryLeak
Severityhigh
Priority score45
Detected18 September 2026 · 12:12 UTC
Leak● 60
Base de datos de clientes de ADT USA con SSN a la ventaA database attributed to ADT, the US home-security provider, is being offered with what are described as customer Social Security Numbers. SSN exposure enables identity theft, credit fraud and account takeover at scale. Defenders should watch for credential-stuffing and social-engineering campaigns targeting ADT customers and staff.Leak● 35
Base de datos de Allianz Alemania (2,8 M registros) filtradaA carding forum is circulating a file claimed to contain 2.8M Allianz customer records from Germany. The thread appears old and heavily bumped, so it is likely a repost rather than a fresh breach, but the scale and the reputation of the insurer make it worth noting for fraud and phishing exposure.Leak● 62
Base de datos con PII de ciudadanos y residentes de EAU a la ventaA user is selling a database described as the full PII of UAE citizens and residents, i.e. names and national identifiers for an entire population. Even though the region is not Latin America, a dump of this scale is a serious identity-theft and state-security problem and should be tracked for downstream credential and fraud abuse.Leak● 52
Base de datos de Pegadaian, empresa estatal indonesia, filtradaA thread offers a leaked database from Pegadaian, the Indonesian state-owned pawn and financial services company. If genuine, it exposes customer and financial data of a government-linked institution; the post is undated and possibly stale, so it is logged at moderate confidence.Leak● 33
Combolist de correos de Telefonica.net filtrado en un foroA credential combolist of Telefonica.net email accounts was posted to a cracking forum as mail:pass pairs. Although stale (August 2025) and credential-stuffing style, Telefonica is critical telecom infrastructure across Spain and Latin America. Defenders should check for password reuse against corporate accounts and enforce MFA.Leak● 38
Base de datos de 199K pólizas de FUSE.CO.ID a la ventaA seller is offering a database of about 199K Indonesian insurance records from FUSE.CO.ID, including full policy data and KTP national IDs, emails and phone numbers. This PII is well suited for identity fraud and targeted phishing against policyholders. Regional defenders should watch for credential and data reuse, though the volume is moderate and the post is months old.