BRIEFLeakhighP46
400k institutional emails from UK/Ireland government and education bodies for sale
Detected4 October 2026 · 11:56 UTC
A seller on spear.cx is offering 400K+ institutional email addresses harvested from UK and Ireland government and education organisations, posted around 2026-10-01. These lists enable credential-stuffing, phishing and business-email-compromise campaigns against public bodies. Public-sector and education security teams should treat it as an active threat.
CategoryLeak
Severityhigh
Priority score46
Detected4 October 2026 · 11:56 UTC
Leak● 38
Base de datos de la CAF de Francia con 22,37M de registrosA 22.37M-record database tied to France's CAF family-benefit and student-grant service is circulating, containing sensitive government benefit and personal data. However the post is dated 2025 and looks like repackaged older data, so it is not a fresh alert. It remains useful background on re-circulated European government data rather than an urgent item.Leak● 55
Base de datos del aeropuerto de Mascate con 17M de registrosA seller is offering a 17M-record database allegedly from Muscat Airport in Oman, dated 30 Sep 2026. Airports are critical infrastructure, and leaked traveler and operational data can fuel phishing, targeting and follow-on intrusions. The post is only days old, making it time-sensitive for aviation and government defenders.Leak● 60
Base de datos de España con IBAN a la ventaA fresh database of Spanish IBAN banking details is being sold on a dark-web forum (posted 4 Oct 2026). IBAN plus account-holder data enables fraudulent direct debits, invoice fraud and identity theft against Spanish account holders. Financial institutions in Spain should expect downstream fraud and watch for abuse of listed accounts.Leak● 88
Filtración de base de datos de Izipay Perú con 3,64M de registrosA threat actor is offering a database of Izipay, a major Peruvian payment gateway, containing 3.64M+ merchant and payment records tied to Peru's card ecosystem. This is a confirmed high-impact leak of a named LATAM payment entity, enabling card fraud, merchant targeting and account takeover. Regional defenders should treat it as a live financial-sector exposure and watch for downstream abuse.Leak● 44
Filtración de 374K registros de usuarios del instituto sanitario italiano IZSLTRoughly 374K user registration and contact records from Italy's public health research institute IZSLT (izslt.it) are being offered. The institute is a government-linked veterinary/public-health body, so the leak can support phishing against public-health staff. Lower impact, but a legitimate critical-sector exposure.Leak● 53
Filtración de datos de clientes de Hrvatski Telekom (Croacia)A database of roughly 237K customer records from Croatian telecom Hrvatski Telekom (hrvatskitelekom.hr) is being offered, including emails and phone numbers. Telecom operators are critical infrastructure, so this data enables phishing, SIM-swap and account-takeover attacks. Croatian subscribers and the operator's security team should treat it as an active exposure.