BRIEFLeakhighP50
9,000 KYC documents with IDs, passports and selfies for sale
Detected30 September 2026 · 16:54 UTC
Threat actors are offering roughly 9,000 KYC records that combine front/back ID images, passports and matching selfies. Document plus biometric bundles allow full identity takeover and can bypass KYC/onboarding checks at banks and crypto exchanges. Even without a named victim, this style of dataset is directly usable for regional account-opening fraud.
CategoryLeak
Severityhigh
Priority score50
Detected30 September 2026 · 16:54 UTC
Leak● 42
Filtración de 235.000 registros de un centro educativo de Hong KongTurkHackTeam's ANKA TEAM published a 235,000-record database allegedly belonging to the Hong Kong educational institution mckln.edu.hk. Student and staff data of this scale fuels credential stuffing and targeted phishing. It is not a LATAM target, but it is a real organizational breach worth tracking.Leak● 45
Dump de credenciales de Sudamérica: Argentina, Brasil y ChileA 'verified' credential dump on Cracked.st claims to combine Argentine, Brazilian and Chilean data under a South America dataset. Regional combolists like this fuel account takeover against LATAM consumers and businesses, and the country tagging makes them easy to weaponise. It is generic content, but the region-specific focus justifies exposure checks.Leak● 50
Filtración de base de datos del sitio brasileño repediu.com.brA threat actor posted a database breach for the Brazilian site repediu.com.br on DarkForums. Brazilian user data is exposed, useful for phishing and credential-reuse attacks against local victims. The post dates to February 2026, so it is stale and mainly of historical and enrichment value rather than a fresh alert.Leak● 57
Filtración de 250 millones de números de Seguro Social de EE. UU.A long-running thread on xReactor resurfaces a claimed 250 million US Social Security Number dataset for download. If genuine, this is one of the largest PII troves in circulation and directly fuels identity theft, loan fraud and tax fraud. Being on page 13 it is likely an old, re-circulated dump rather than a new breach, so treat it as high-impact but not fresh.Leak● 76
Filtración masiva de 180 millones de credenciales (URL:login:password)A stealer-log dump of roughly 180 million URL:login:password entries was published today, labeled private and freshly checked (30/09/2026). Credentials at this scale fuel credential stuffing and account takeover across many sectors and regions. Defenders should hunt for matches and enforce password resets and MFA where hits occur.Leak● 72
Filtración de base de datos de la universidad mexicana UTELA database belonging to UTEL, a Mexican online university, was posted on DarkForums by the actor whoamipwn just minutes ago. Exposed student and staff records enable phishing, credential stuffing and identity fraud against Mexican users. Because the leak is fresh, affected accounts should be reset and monitored now.