BRIEFLeakhighP55
810 million Chinese delivery addresses offered for sale
China shopping delivery address database (seller 'hulky')
Detected17 September 2026 · 03:12 UTC
A BreachForums seller is offering a dataset of roughly 810 million Chinese shopping and delivery addresses. This is a massive trove of PII including names, phone numbers and home addresses, ideal for phishing, smishing and identity theft. Its sheer scale makes it a re-usable resource for fraud campaigns well beyond China.
CategoryLeak
Severityhigh
Priority score55
Detected17 September 2026 · 03:12 UTC
Leak● 40
Base de datos de la china Integrity Technology Group filtradaA database belonging to Integrity Technology Group, a Chinese cybersecurity and threat-intelligence firm, has been posted for download on a leak forum. Breach of a security vendor can expose internal tooling, customer data and intelligence sources, which may be abused to target its clients. The post dates from May 2026, so it is not a fresh alert but remains relevant for sector awareness.Leak● 46
Filtración de base de datos de centros de salud Puskesmas de IndonesiaA dataset attributed to Indonesian Puskesmas community health centres is being offered on a dark web forum. These are government-run public health facilities, so the data likely contains patient records and personal health information. A breach of this size over health data can enable fraud, extortion and targeted attacks on public health infrastructure.Leak● 50
Logs robados con 6,11 millones de credenciales a la ventaA 6.11 million-entry URL:LOG:PASS stealer log (DAXUS.PRO) is advertised as a private, high-quality base. It holds credentials stolen from infected machines and is useful for account-takeover and credential-stuffing. Monitor for reuse of leaked corporate credentials.Leak● 66
Base de datos de 7,6 millones de clientes de Coinbase en ventaA 7.6 million-record Coinbase customer dataset tied to a 2025 breach is being reposted for download. It likely includes names, emails, phone numbers and account data usable for phishing and SIM-swap fraud. Crypto holders and exchanges face targeted social engineering.Leak● 58
Base de 29,29 millones de credenciales URL:LOG:PASS publicadaA 29.29 million-line URL:LOG:PASS stealer log is being shared privately as a supposedly fresh base. It contains credentials harvested from infected devices, enabling credential-stuffing, account takeover and fraud at scale. Organizations should assume corporate credentials are exposed and enforce MFA and password resets.Leak● 47
Filtración de la base de datos de Younow.comA full database attributed to Younow.com is being shared on the DarkNetArmy forum, posted today. While the exact record count is not yet detailed, leaked user records of a live-streaming/social platform feed credential stuffing, phishing and account-takeover campaigns. Platform operators and defenders of downstream identity providers should verify the exposure and force resets if valid credentials are confirmed.