BRIEFLeaklowP48
82.9M French email:password credentials for sale
Usuarios franceses (email:pass)
Detected25 September 2026 · 18:15 UTC
Reposts collapsed2
A seller offers an 82.9 million record email:password dump, allegedly extracted from a large credential-stealer collection, for 500 USDT. Even if recycled from older stealer logs, the sheer volume enables credential-stuffing and targeted phishing against French users and organizations. Defenders should monitor for reuse of these credentials and enforce MFA.
CategoryLeak
Severitylow
Priority score48
Detected25 September 2026 · 18:15 UTC
Leak● 68
Base de datos de 13M de business.adobe.com a la ventaA seller is offering a business.adobe.com dataset of roughly 13 million records and 832 GB, posted on DarkForums very recently. Adobe is a major SaaS and identity provider, so leaked corporate data could fuel targeted phishing and account abuse. The data may be recycled from older Adobe breaches, so verify freshness before alerting.Leak● 80
Base de datos de rto.cent.ar publicada en un foroA user posted a full database tied to the Argentine domain rto.cent.ar just minutes ago, indicating a fresh breach of an entity in Argentina. If the domain belongs to a public registry or a regional service, the dump could expose citizen records usable for identity theft and phishing. Argentine defenders should verify scope and notify affected users immediately.Leak● 48
Filtración de 3,5 GB de pasaportes y documentos de identidad de EAUA long-running thread offers a 3.5 GB dataset of UAE passports and identity documents. Government ID leaks enable identity fraud, impersonation and targeted attacks, and the volume indicates sensitive citizen data, although the thread appears long-lived and possibly stale.Leak● 58
Base de datos de MyPertamina filtrada (energética estatal de Indonesia)The MyPertamina loyalty database belonging to Indonesia's state-owned energy company Pertamina was leaked and is being distributed publicly with a long active thread. State-linked energy customer data leaks can enable phishing, fraud and reconnaissance against a critical-infrastructure operator. Notable as a large government-linked leak, though not in the LATAM region.Leak● 40
Combolist de credenciales argentinas (117.000 cuentas)A freshly posted combolist claims around 117,000 Argentine email/password pairs, most likely aggregating infostealer and past credential-stuffing data. It is not tied to a government or critical-infrastructure breach, so the impact is diffuse, but it directly feeds account-takeover attempts against Argentine users and organizations. Treat it as working material for credential-stuffing rather than a targeted government compromise.Leak● 50
Filtración de la base de datos del Banco Syariah IndonesiaA database attributed to Bank Syariah Indonesia (BSI), the country's largest Islamic bank, is posted for sale/download. Banking records include customer identity, account and contact data that fuel fraud and account takeover. The post is a few months old, so it is a standing exposure rather than a fresh alert.