BRIEFLeakhighP66
India's Comptroller and Auditor General database leaked
Comptroller and Auditor General of India
Detected2 October 2026 · 02:45 UTC
Threat actors claim to have hacked and leaked a database from cag.gov.in, India's Comptroller and Auditor General, a top national audit authority. Government audit data can expose financial oversight records and citizen-linked information. Although outside LATAM, it shows active targeting of government bodies and should be tracked.
CategoryLeak
Severityhigh
Priority score66
Detected2 October 2026 · 02:45 UTC
Leak● 33
Filtración de 11 millones de credenciales URL:login:passA forum post shares a dump of roughly 11 million URL:login:password credentials. Large credential sets drive password-reuse attacks and account takeover across many services. It is not org-specific, but defenders should monitor for their own domains and users appearing in the set.Leak● 30
Filtración de datos del transporte público VayVen Yucatán (México)A dump attributed to VayVen Yucatán, a public transport operator in Mexico, was posted to a leak forum. The post dates to 15 September 2025 and is now stale, so it is not a fresh alert. It may still expose passenger or operational data useful for fraud or targeting, and is worth tracking for reuse.Leak● 78
Filtración de base de datos del Cecyte Jalisco en MéxicoA threat actor posted a database belonging to Cecyte Jalisco, a public technical-education body of the Jalisco state government, on a darkweb forum. The leak exposes student, staff and related personal data that fuels phishing and identity fraud. Regional defenders should verify scope and warn victims.Leak● 48
Filtración de base de datos completa de pasaportes e identidades de IsraelA database allegedly containing full Israeli passport and national identity records is being shared on SpyHackerz. Although outside the Argentina/LATAM scope, a national identity document leak is a high-impact event that can enable identity fraud and targeted attacks. Defenders with Israeli customers, partners or staff should treat it as a validation source for potential impersonation.Leak● 55
Volcado masivo de logs de stealer con 1.900 millones de cuentasA 543GB collection of infostealer logs (U:L:P, browser credentials) claiming over 1.9 billion accounts is being circulated as 'fresh' on SpyHackerz. This is a Credential-stuffing goldmine that can fuel account takeover against corporate and government services worldwide, including any exposed LATAM accounts. Defenders should assume corporate credentials may be present and prioritize password resets and MFA enforcement.Leak● 84
Filtración masiva de EsqueleSquad afecta datos de España, México, Argentina, Colombia y EcuadorA threat actor using the handle EsqueleSquad is advertising a large multi-country database leak covering Spain, Mexico, Argentina, Colombia and Ecuador, tagged 2026. If authentic, it bundles citizen/customer records from several Latin American countries including Argentina, which is directly relevant to regional gov and critical-infra defenders. Defenders in these countries should begin credential and PII exposure monitoring and prepare victim notification workflows.