BRIEFLeakhighP60
Ransomware settra publishes US retailer DFI Retail Group
DFI Retail Group
Detected30 September 2026 · 14:14 UTC
Reposts collapsed2
Settra listed DFI Retail Group, claiming 27 years of email archives, 397 illegal stores and over 40,000 medical files across 160+ mail accounts. This is a large, sensitive haul from a US retailer. The mix of corporate email and medical data raises both fraud and regulatory risk for the victim and its partners.
CategoryLeak
Severityhigh
Priority score60
Detected30 September 2026 · 14:14 UTC
Leak● 45
Filtración de datos de 373.000 usuarios de HamroPay, NepalA BreachForums seller claims identity and financial data of 373,000 natural persons from HamroPay / Hamropatro, a Nepali digital payments provider. Leaked KYC and transaction data enable account takeover, loan fraud and targeted scams against payment users. Though outside LATAM, the scale and financial nature of the data make it worth tracking.Leak● 46
Filtrados contactos de la Asamblea Nacional francesaA RaidForums thread offers a database of contact information of members of the French National Assembly. Even limited to names, emails and offices, this data exposes elected officials to targeted phishing, impersonation and social engineering. As a government body, the collection carries political and espionage risk, though the post is likely not fresh.Leak● 78
Filtración de base de datos de 4,4 millones de usuarios de Grupo Lisp Promotora (Brasil)A seller on BreachForums is offering a Brazilian database of roughly 4,416,319 users tied to AlcifMais / Grupo Lisp Promotora, a financial/promotora entity. The volume implies full customer records, likely including personal identity and financial data, exposing millions of Latin American individuals to fraud and credential abuse. Brazilian finance and consumer-protection defenders should treat this as an active leak and hunt for downstream misuse.Leak● 55
Filtración gratuita de base de datos francesa con 3,6 millones de registrosA 3.6 million-record French database was published for free on RaidForums on 2026-08-28, indicating a broad set of personal records from an unspecified French source. Although the victim is outside Latin America, the size and freshness make it a candidate for credential-stuffing and identity-fraud campaigns against European users and services. Defenders should watch for reuse of these identities across authentication systems.Leak● 33
Filtración de base de datos de Orange Moldova (orange.md)A dump tied to Orange Moldova (orange.md), a national mobile and internet operator, was posted on BreachForums dated July 28, 2025. Telecom subscriber data is high value for SIM-swap, phishing and account fraud against customers. However, the post is over a year old and likely already circulated widely, so it is background context rather than a fresh alert.Leak● 43
Publicación de 1 millón de registros URL:LOG:PASS de roboA one-million-row 'URL:LOG:PASS' stealer-log dump has just been released, giving attackers ready-to-use credentials mapped to specific login pages. No single victim organization is named, but the volume makes it valuable for credential stuffing and account takeover across many services. Defenders should ingest it into exposure monitoring for their corporate email domains and high-value portals.