PULSE
FEED
ransomaurora reclama a Laboratorios Roemmers SAICF · AR · Healthcareransomn0n reclama a Houston Thyroid & Endocrine Specialists · US · Healthcareransomeclipse reclama a The Japan Times · JP · Otherransomvexy ransomware reclama a Summit Electric Supply · US · Energy & Utilitiesransomsafepay reclama a wolfusofsky.de · DE · Not Foundransomkairos reclama a Le Centre National de l'Expertise Hospitalière (CNEH) · FR · Healthcareransomplay reclama a Titus · DE · Technologyransomplay reclama a Airtech Mechanical Services · US · Professional Servicesransomplay reclama a Orth Automobile · DE · Manufacturingransominterlock reclama a Blaise C. Bender, PC · US · Professional Servicesransomaurora reclama a Buford-Thompson Company, LTD · US · Manufacturingransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomaurora reclama a Laboratorios Roemmers SAICF · AR · Healthcareransomn0n reclama a Houston Thyroid & Endocrine Specialists · US · Healthcareransomeclipse reclama a The Japan Times · JP · Otherransomvexy ransomware reclama a Summit Electric Supply · US · Energy & Utilitiesransomsafepay reclama a wolfusofsky.de · DE · Not Foundransomkairos reclama a Le Centre National de l'Expertise Hospitalière (CNEH) · FR · Healthcareransomplay reclama a Titus · DE · Technologyransomplay reclama a Airtech Mechanical Services · US · Professional Servicesransomplay reclama a Orth Automobile · DE · Manufacturingransominterlock reclama a Blaise C. Bender, PC · US · Professional Servicesransomaurora reclama a Buford-Thompson Company, LTD · US · Manufacturingransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technology
Kalir Brief · Item1 October 2026 · 09:47 UTC
BRIEFLeakhighP58

543 GB stealer-log dump with 1.9 billion accounts circulating

Infostealer log aggregate (global)

Detected1 October 2026 · 09:47 UTC
Reposts collapsed2
Why it matters

A 543 GB stealer-log archive advertised as containing over 1.9 billion accounts is being circulated on the SpyHackerz underground forum. It is an aggregate of infostealer data rather than a single organization's database, so the impact is broad instead of targeted at one victim. It is useful for credential-exposure monitoring and password-reuse checks for your users, but offers low specificity for any named entity.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score58
Detected1 October 2026 · 09:47 UTC
Related items6
Leak● 48
Base de datos de empresas francesas de 5,3 millones de registros a la ventaA threat actor is selling a French business database advertised as 5.3 million records from 2026 on BreachForums. Business contact data at this scale fuels targeted B2B phishing, invoice fraud and social engineering. It sits outside the LATAM priority region but is a large, fresh commercial leak worth tracking.
53m
Leak● 58
Base de datos de clientes de Digitec Galaxus (Suiza) a la ventaA seller is offering customer data of Digitec Galaxus, one of Switzerland's largest online retailers, in a post dated 27-09-26. Although outside Latin America, it is a fresh, named-organization leak that can enable phishing and account takeover against the retailer's customers and partners. Defenders with Swiss exposure should monitor and validate it.
53m
Leak● 28
Presunta filtración de 200 millones de cuentas de X/Twitter ofrecida a la ventaA forum post dated 31 October 2025 advertises a 200-million-record X/Twitter email:password dataset. The claim is nearly a year old and closely matches previously recycled Twitter leaks, so it is unlikely to be a fresh breach. Treat it as low priority unless credential-stuffing against X accounts tied to your organization is actually observed.
2h
Leak● 45
Filtración de 17 millones de credenciales URL:login:pass de stealer logsA 17-million-line URL:login:password combolist attributed to 'Secretline.top' stealer logs is being shared freely across several underground forums. It aggregates credentials harvested by infostealers rather than a single organization's data, so the impact is diffuse. Worth monitoring so your users' leaked credentials can be reset, but it is not a targeted breach of a named entity.
2h
Leak● 28
Filtración de combolist con 275.000 credenciales de PerúA 275,000-entry Peru-oriented credential combolist is circulating on DarkForums, originally posted in June 2025. Although now stale, it remains a usable source for credential stuffing against Peruvian online services and user accounts. It is regionally relevant for awareness but too old and generic to be a fresh alert.
3h
Leak● 34
Filtración de 17 millones de credenciales en stealer logs de Secretline.topA 17-million-line set of URL:login:password stealer logs sourced from Secretline.top was posted for free on a Tor leak forum. These are aggregated infostealer credentials rather than a single-victim breach, and they fuel account-takeover and fraud campaigns. Organizations should check whether corporate emails and employees appear in the set and force password resets where needed.
3h