BRIEFLeaklowP48
Indonesian Ministry of Labor hit by 347 GB data leak
kemnaker.go.id (Ministerio de Trabajo de Indonesia)
Detected18 September 2026 · 08:12 UTC
A verified seller claims a 347 GB dump (~1.2 billion records) from Indonesia's Ministry of Labor, kemnaker.go.id, said to date from December 2025. A government dataset of this size can fuel identity theft, phishing and fraud against citizens and workers at scale. Although not fresh, regional CTI teams should track its reuse and downstream misuse.
CategoryLeak
Severitylow
Priority score48
Detected18 September 2026 · 08:12 UTC
Leak● 33
Combolist de correos de Telefonica.net filtrado en un foroA credential combolist of Telefonica.net email accounts was posted to a cracking forum as mail:pass pairs. Although stale (August 2025) and credential-stuffing style, Telefonica is critical telecom infrastructure across Spain and Latin America. Defenders should check for password reuse against corporate accounts and enforce MFA.Leak● 38
Base de datos de 199K pólizas de FUSE.CO.ID a la ventaA seller is offering a database of about 199K Indonesian insurance records from FUSE.CO.ID, including full policy data and KTP national IDs, emails and phone numbers. This PII is well suited for identity fraud and targeted phishing against policyholders. Regional defenders should watch for credential and data reuse, though the volume is moderate and the post is months old.Leak● 52
Base de datos CRM de 627.000 clientes de mihnati.com a la ventaA marketplace seller is offering a 627,000-record CRM PII dataset from the Saudi recruitment site mihnati.com, including emails, names and dates of birth. The volume and PII depth make it valuable for phishing and identity fraud targeting job seekers in Saudi Arabia. Though outside Latin America, it is a sizable fresh leak worth tracking.Leak● 25
Base de datos de 28 millones de consumidores de EE.UU. a la ventaA seller offers a 28-million-record US consumer opt-in database for $200, likely containing names, emails, phones and addresses. Although the post dates from mid-2023 and the data has probably circulated already, its scale makes it valuable for phishing, fraud and account-takeover campaigns. Defenders should watch for reuse of these records in credential-stuffing and social-engineering against US consumers.Leak● 40
Volcado de 740 GB de registros stealer y ULP publicadoA 740 GB archive of stealer logs and URL:login:password (ULP) data has been posted on RaidForums. Though published in January 2026, the sheer volume makes it a long-lived credential source for account takeover. Defenders should assume broad credential exposure and enforce resets and MFA.Leak● 60
Base de datos de la exchange de criptomonedas CoinSwitch a la ventaA partial database of crypto exchange CoinSwitch containing over 1 million lines with KYC data and account balances is being offered on RaidForums. KYC records are highly sensitive and fuel identity fraud and targeted phishing. Financial-sector defenders should monitor for downstream abuse of the leaked customer data.