BRIEFLeakhighP55
Alleged attacker exposes Pathao data breach (Bangladesh)
Pathao
Detected9 October 2026 · 10:21 UTC
An actor published a message addressed directly to Pathao management about what they call a "partial data breach", implying a database dump, extortion or a follow-up leak of the Bangladeshi super-app. Pathao runs ride-hailing, food delivery and payments for millions of users, so any customer data exposure can fuel fraud and credential-stuffing across the region. Even though the scale is unconfirmed, defenders should verify exposure and watch for the data being published or sold on the same forum.
CategoryLeak
Severityhigh
Priority score55
Detected9 October 2026 · 10:21 UTC
Leak● 40
Filtración de la base de datos de ArtsyA database described as the Artsy online art marketplace has been posted in a forum leaks section. The scale and date are unclear, but a real company database leak can expose customer and account data used for credential stuffing. Worth verifying and adding to monitoring if confirmed.Leak● 52
Filtración de 21.145 cuentas de BinanceA database of roughly 21,145 Binance accounts is being circulated on a breach forum under a 2026 label. While the volume is modest, crypto-exchange credentials fuel account takeover, wallet draining and follow-on phishing. Exposed users should be flagged for credential rotation and monitoring.Leak● 56
Filtración de SCADA/BMS del hospital Thye Hua Kwan de Ang Mo KioA collection labeled as the Building Management System (BMS) and SCADA system of Ang Mo Kio–Thye Hua Kwan Hospital in Singapore has been posted on a breach forum. If authentic, it exposes operational-technology data controlling building systems in a healthcare facility, a critical-infrastructure setting. Defenders should treat it as a possible OT-access vector and verify whether the data is genuine and current.Leak● 28
Filtración de datos de empleados de McDonald's IndiaA database of McDonald's India workers was leaked and made available for download, exposing staff personal data. Such records enable identity fraud and targeted phishing against employees. The post dates to 2025, so it is not a fresh alert, but the data may still be reused against affected individuals.Leak● 40
Filtración de datos de Systech USA publicada en DarkForumsA dataset from Systech USA was published on DarkForums for free download, exposing internal company data. Although the exact scale is unclear, leaked corporate data fuels fraud and follow-on intrusions. It is worth tracking for credential reuse and possible supply-chain exposure.Leak● 45
Filtración de 327.000 contactos del portal jordano AkhtabootA 327k-record database from the Jordanian job portal Akhtaboot is circulating, exposing professional contacts and likely account data. Recruitment portals are prime targets for targeted phishing and BEC. Affected organizations and users should be warned and credentials reset.