BRIEFLeakhighP50
Stolen-log base with 6.11 million credentials offered
Detected17 September 2026 · 02:12 UTC
A 6.11 million-entry URL:LOG:PASS stealer log (DAXUS.PRO) is advertised as a private, high-quality base. It holds credentials stolen from infected machines and is useful for account-takeover and credential-stuffing. Monitor for reuse of leaked corporate credentials.
CategoryLeak
Severityhigh
Priority score50
Detected17 September 2026 · 02:12 UTC
Leak● 66
Base de datos de 7,6 millones de clientes de Coinbase en ventaA 7.6 million-record Coinbase customer dataset tied to a 2025 breach is being reposted for download. It likely includes names, emails, phone numbers and account data usable for phishing and SIM-swap fraud. Crypto holders and exchanges face targeted social engineering.Leak● 58
Base de 29,29 millones de credenciales URL:LOG:PASS publicadaA 29.29 million-line URL:LOG:PASS stealer log is being shared privately as a supposedly fresh base. It contains credentials harvested from infected devices, enabling credential-stuffing, account takeover and fraud at scale. Organizations should assume corporate credentials are exposed and enforce MFA and password resets.Leak● 47
Filtración de la base de datos de Younow.comA full database attributed to Younow.com is being shared on the DarkNetArmy forum, posted today. While the exact record count is not yet detailed, leaked user records of a live-streaming/social platform feed credential stuffing, phishing and account-takeover campaigns. Platform operators and defenders of downstream identity providers should verify the exposure and force resets if valid credentials are confirmed.Leak● 54
Filtración de la base de datos de la empresa colombiana sosltda.comA database belonging to the Colombian firm sosltda.com is being distributed on a dark web forum as a 2026 leak. It exposes the organization's internal/customer records to anyone who downloads it, enabling fraud and targeted attacks. Colombian and regional defenders should verify scope and notify affected parties.Leak● 32
Base de datos de una repartidora marroquí con 500.000 registrosA full database belonging to a large Moroccan delivery company, roughly 500,000 records, was posted for sale on DarkNetArmy. It is a mid-sized corporate leak outside the AR-LATAM region, more relevant to the affected company than to regional defenders. It is notable only as another logistics-sector data exposure.Leak● 38
Volcado de 40 millones de credenciales URL:LOGIN:PASSWORDA private 40 million line URL:LOGIN:PASSWORD stealer log was published on 16/09/2026, indicating freshly harvested infostealer credentials. It is a generic aggregated dump without a named victim, so its direct relevance to AR-LATAM is limited. It still matters as a source of valid credentials that may enable account takeover if re-used broadly.