BRIEFLeakhighP56
Massive data leak of Central Sulawesi regional parliament
DPRD Sulawesi Tengah (Indonesia)
Detected20 September 2026 · 12:37 UTC
A threat actor is distributing a 366K-record database allegedly belonging to the DPRD (regional legislature) of Central Sulawesi, Indonesia. Government records of this type typically include citizen PII, official communications and internal identifiers enabling follow-on fraud, phishing or intelligence gathering. Public-sector defenders should monitor for downstream abuse of the exposed data.
CategoryLeak
Severityhigh
Priority score56
Detected20 September 2026 · 12:37 UTC
Leak● 71
Filtración HATICA expone datos de JPMorgan, BrowserStack y GE HealthcareA claimed fresh breach dubbed HATICA reportedly bundles data from JPMorgan, BrowserStack and GE Healthcare, exposing records tied to major financial and healthcare targets. Third-party or vendor leaks like this enable downstream fraud, credential abuse and supply-chain targeting against connected organizations. Defenders at these firms and their partners should verify exposure and watch for credential-stuffing and phishing activity.Leak● 46
Filtración de datos de empleados de McDonald's IndonesiaA dataset described as McDonald's Indonesia worker records has been leaked for download. Employee PII such as names, identifiers and contact details can fuel phishing, payroll fraud and credential-based account takeover. The workforce data of a global brand is worth flagging even though the victim is outside Latin America.Leak● 52
Filtración de base de datos gubernamental de la regencia Kabupaten BeluA database belonging to the Belu Regency (Kabupaten Belu) local government in Indonesia has been published for download. Public-sector records can include citizen identity, civil-registry and administrative data, raising risks of identity theft and targeted fraud. Although outside Latin America, a government data leak is notable for regional watchlists.Leak● 22
Filtración de 1,2 millones de registros de la minorista rusa DetmirA 1.2 million-row database attributed to Russian retailer Detmir has been posted on DarkForums, though the underlying data dates from 2024. It likely includes customer names, emails and phone numbers usable for spam and credential attacks. Because the data is old and the victim is outside Latin America, it is only marginally relevant.Leak● 58
Filtración de base de datos de la empresa logística InPostA database attributed to InPost, one of Europe's largest parcel-locker and logistics operators, has been posted for download on a darkweb forum. Such a leak could expose customer, delivery and employee records, enabling phishing, account takeover and parcel fraud. InPost's scale in Poland and across Europe makes any confirmed breach operationally significant.Leak● 34
Filtración de base de datos de la Universidad de HarvardA database purportedly belonging to Harvard University has been shared on DarkForums. University breaches typically expose student and staff PII, credentials and internal directories, useful for credential stuffing and targeted phishing. However, the post dates from April 2026 and the victim is outside the region, so it is low priority here.