BRIEFLeaklowP40
Partial database leak of French real estate firm Capifrance
Capifrance
Detected20 September 2026 · 07:37 UTC
A partial database of the French real-estate network Capifrance is circulating, likely containing client/agent contact data and possibly credentials. Partial leaks still fuel phishing and account takeover against the company and its clients. Impact is limited because only part of the dataset is exposed.
CategoryLeak
Severitylow
Priority score40
Detected20 September 2026 · 07:37 UTC
Leak● 52
Filtrada base de datos del Ministerio de Asuntos Religiosos de IndonesiaA database attributed to Indonesia's Ministry of Religious Affairs is being shared, exposing government records and likely citizen data. Government ministry data is high-value for fraud, espionage and identity theft. Though outside the AR-LATAM region, it shows active targeting of public-sector entities.Leak● 42
Base de datos del registro civil Dukcapil de Indonesia reeditadaThe Indonesian Dukcapil civil registry, holding national ID, family and address data of hundreds of millions of citizens, was reposted on a RaidForums clone dated August. Such data enables identity fraud, SIM-swap and account takeover at national scale. Given the leak's known 2022 origin, this appears to be a stale repost rather than a new breach.Leak● 38
Base de datos de 527.000 correos cripto a la ventaA 527,000-record database of cryptocurrency-related email addresses is being offered for sale on a leak forum, aggregating holders worldwide rather than a single named Latin American target. It is not a fresh regional compromise, but crypto users face targeted phishing and wallet-drainer lures built from these lists. Worth monitoring for downstream campaigns, though immediate regional impact is limited.Leak● 46
Filtración de base de datos de Fasul Educacional en BrasilA database reportedly containing email addresses and phone numbers tied to Brazil's Fasul Educacional (fasuleducacional.edu.br) is being redistributed on a breach forum as a repost of a 2025 incident. Even though it is not fresh, the data can fuel phishing, credential stuffing and social engineering against a Latin American education institution. Regional defenders should treat the exposed emails and phones as compromised identifiers and monitor for downstream abuse.Leak● 60
Se ofrecen 723.000 registros de clientes de DoorDash y otras marcasA 723K-record dataset claimed to include DoorDash, BWW and other customer data is marketed as fresh 2026 private data with many 'hits'. Large PII/credential dumps fuel account takeover and card fraud across food-delivery and retail users. Fraud and identity teams should monitor for reuse of these credentials on other services.Leak● 55
Filtración de datos de residentes de Hong Kong: 2,8M filas con nombres, teléfonos y HKIDAn actor is selling a 2.8M-row dataset of Hong Kong residents containing names, phone numbers and HKID numbers. Government-issued identity numbers enable impersonation, account takeover and fraud at scale. Although outside AR-LATAM, large national PII sets like this feed downstream attacks and are worth tracking for fraud and identity-abuse detection.