BRIEFAccess salehighP80
Pakistan airport live access and 5.6TB data dump for sale
Pakistani airport / aviation authority
Detected3 October 2026 · 12:03 UTC
An actor advertises live access to Pakistan's airport infrastructure alongside a 5.6TB data dump, signaling an ongoing intrusion with hands-on capability. The volume covers operational and passenger data at a national aviation target. Aviation and border-control defenders should treat it as a high-impact active breach.
CategoryAccess sale
Severityhigh
Priority score80
Detected3 October 2026 · 12:03 UTC
Access sale● 45
Venta de acceso y base de datos de la Universidad Federal de AkureA seller advertises both access and a database from the Federal University of Technology, Akure (Nigeria). Combining entry access with a student/staff database enables account takeover, credential abuse and further intrusions across the institution's systems. It matters as a live access-sale listing against a named educational target.Access sale● 78
Acceso completo a red del MSP Kirey Group a la ventaA seller is offering full Active Directory 'golden ticket' access to Kirey Group, an IT managed service provider with roughly 1,600 employees. Golden-ticket access implies a complete domain compromise, letting an attacker impersonate any user or service and move laterally into the MSP's downstream clients. For defenders, an MSP compromise is a supply-chain risk that can cascade into every organization it manages.Access sale● 72
Venta de acceso a empresa LATAM de cobranza: webshell y SSH rootA seller is offering a webshell plus SSH root access to a Latin American debt-collection/robocall company, indicating full server compromise. This matters because it grants persistent privileged access to a region-relevant organization that handles large volumes of consumer PII, enabling fraud, spam, or lateral movement. Web shell + root is high-value initial access worth monitoring.Access sale● 35
Venta de acceso a correos y archivos de NASA.govA threat actor claims to have email and file-drop access to the NASA.gov domain and is offering it to buyers. Genuine access to a US federal agency would enable mailbox compromise, data theft and follow-on attacks on contractors. However, the post dates to March 2026, so it is likely stale and should be treated as context rather than a fresh alert.Access sale● 52
Venta de acceso a la eléctrica española FENIE EnergíaA seller lists access to FENIE Energía, a Spanish electricity-sector company in one of the most sensitive critical-infrastructure sectors. If legitimate, it gives an attacker a foothold in energy operations, but the listing dates from March 2026 so credentials may already be rotated. It is worth verifying whether the access is still valid.Access sale● 68
Acceso obtenido a un sistema industrial de Siemens EnergyA threat actor claims to have obtained access to an industrial/OT system belonging to Siemens Energy, a global energy and critical-infrastructure supplier. Compromise of industrial systems can enable sabotage, lateral movement into operational networks and disruption of energy services. Defenders in energy and OT environments should treat this as a potential initial-access claim and hunt for related indicators.