BRIEFAccess salehighP72
LATAM debt collection firm access for sale: webshell and SSH root
Empresa de cobranza/robocaller LATAM
Detected3 October 2026 · 08:02 UTC
A seller is offering a webshell plus SSH root access to a Latin American debt-collection/robocall company, indicating full server compromise. This matters because it grants persistent privileged access to a region-relevant organization that handles large volumes of consumer PII, enabling fraud, spam, or lateral movement. Web shell + root is high-value initial access worth monitoring.
CategoryAccess sale
Severityhigh
Priority score72
Detected3 October 2026 · 08:02 UTC
Access sale● 35
Venta de acceso a correos y archivos de NASA.govA threat actor claims to have email and file-drop access to the NASA.gov domain and is offering it to buyers. Genuine access to a US federal agency would enable mailbox compromise, data theft and follow-on attacks on contractors. However, the post dates to March 2026, so it is likely stale and should be treated as context rather than a fresh alert.Access sale● 52
Venta de acceso a la eléctrica española FENIE EnergíaA seller lists access to FENIE Energía, a Spanish electricity-sector company in one of the most sensitive critical-infrastructure sectors. If legitimate, it gives an attacker a foothold in energy operations, but the listing dates from March 2026 so credentials may already be rotated. It is worth verifying whether the access is still valid.Access sale● 68
Acceso obtenido a un sistema industrial de Siemens EnergyA threat actor claims to have obtained access to an industrial/OT system belonging to Siemens Energy, a global energy and critical-infrastructure supplier. Compromise of industrial systems can enable sabotage, lateral movement into operational networks and disruption of energy services. Defenders in energy and OT environments should treat this as a potential initial-access claim and hunt for related indicators.Access sale● 35
Servicio de reseteo de correo de ISP ofrecido en ventaA fresh BreachForums post advertises 'ISP MAIL RESETS', described as a service to take over or reset customer mailboxes at internet service providers. If real, this capability targets telecom subscriber email and can enable account takeover and downstream access. Telecom/ISP operators should watch for anomalous mailbox resets and harden reset verification.Access sale● 52
Acceso de administrador a bizlistings.ca a la ventaA seller on BreachForums is offering full administrative backend access to bizlistings.ca, a business-listing platform. Full backend control lets a buyer alter listings, dump the full user database and pivot into any connected infrastructure. Access sales to a named web property are directly actionable for defenders and downstream abuse.Access sale● 78
Venta de acceso a call center de Claro Colombia (GNP BPO)A seller is offering access or data from GNP BPO, a call center operating for Claro Colombia, a major national telecom operator. The listing was posted on 2026-09-29, so the exposure is fresh and time-sensitive. This matters because Claro is critical telecom infrastructure, and call-center access often yields customer records, SIM-related data and internal tooling that can be abused for fraud or further intrusion.