BRIEFLeaklowP40
Morgan Stanley employee data posted on leak forum
Morgan Stanley
Detected27 September 2026 · 15:48 UTC
A leak-forum thread titled 'Morgan Stanley employees' shares a dataset of the bank's staff, posted in June 2025. Employee lists are valuable for spear-phishing, vishing and social engineering against a major financial institution. Defenders should treat this as a targeting aid even though the post is not fresh.
CategoryLeak
Severitylow
Priority score40
Detected27 September 2026 · 15:48 UTC
Leak● 42
Filtración de datos de Banc Certified (banccertified.com)A database belonging to Banc Certified Merchant Services (banccertified.com), a payment/merchant-services provider, has been leaked and is offered for download. Breach of a financial-services firm can expose customer and transaction data usable for card fraud. Merchant-services defenders should monitor for downstream phishing, card fraud and credential stuffing.Leak● 46
Colección de 480 volcados SQL (9 GB) filtradaA 9 GB archive containing 480 SQL dumps reportedly taken from multiple organizations (e.g., esac.sk, osme.es, aba.ae, aepaa.pt) has been published. The volume and mixing of sources indicate broad database exfiltration or aggregation, exposing user records and credentials. Defenders whose domains appear should assume compromise, rotate credentials and audit for reuse.Leak● 54
Base de datos del Federal Bank a la venta (2026)A seller is advertising a 'Federal Bank' customer database dated 2026 on an unverified darkweb marketplace, posted minutes ago. If genuine, the record set would expose account holders' personal and banking data, enabling fraud and account takeover. Financial-sector defenders should watch for credential reuse and targeted phishing built on this data.Leak● 30
Filtración de la base de datos de usuarios de HomePad.comA moderator posted the HomePad.com user database on a leak forum in June 2026, exposing account and personal data of the site's users. Although the post is a few months old, the data remains usable for credential stuffing and phishing. Affected users should rotate passwords and defenders should watch for reuse.Leak● 45
Filtración de base de datos del medio ecuatoriano Studio FútbolA breach dump of studiofutbol.com.ec, an Ecuadorian football news site, was shared on a leak forum, exposing subscriber and account data. Although dated 2025, leaked regional media databases fuel phishing and account takeover across LATAM. Defenders should check for reuse of these credentials against other services.Leak● 50
Filtración de base de datos de Pares.AI (sector inmobiliario)A free download of the Pares.AI real-estate database has been posted on a leak forum, exposing customer and property records of the platform. Such dumps enable phishing, account takeover and targeted fraud against clients and agents. Teams should verify whether their data is included and monitor for credential reuse.