BRIEFAccess salehighP58
RDWeb access to a Swiss university for sale
Swiss university (~$5B revenue)
Detected1 October 2026 · 22:45 UTC
A threat actor is selling RDWeb access to a Swiss university reported to generate over $5B in revenue, making it a large, well-resourced education target. RDWeb access often provides a foothold into internal systems and lateral movement toward sensitive research or administrative data. It is a live initial-access offer rather than a reused leak.
CategoryAccess sale
Severityhigh
Priority score58
Detected1 October 2026 · 22:45 UTC
Access sale● 35
Venta de acceso al sitio surcoreano newyjh.comA seller is offering control of or access to the website www.newyjh.com, a South Korean target, in a marketplace listing dated 29 September 2026. If genuine, such access could be used for defacement, phishing or as a foothold. Impact is limited to a single non-Latin-American site, so it ranks low for a DRP in the region.Access sale● 52
Venta de credenciales bancarias de HSBC, Barclays y otros bancosA seller advertises working bank account logins for HSBC, Barclays, Wells Fargo, Bank of America and Chase. These credentials enable account takeover and money-mule fraud. Generic but fresh, it is worth feeding into fraud and ATO detection.Access sale● 40
Venta de credenciales bancarias de HSBC, Barclays y Wells FargoA forum user is offering bank logins/accounts for major institutions including HSBC, Barclays, Wells Fargo and Bank of America. Such posts are frequently scam or recycled combolist material, but if genuine they fuel account takeover and fraud against retail and business banking customers. No specific organisation or confirmed access is named, so impact and reliability are unverified.Access sale● 38
Venta de accesos RMM (ScreenConnect/SimpleHelp) para acceso inicialA seller is advertising paid access to ScreenConnect, SimpleHelp and other RMM platforms, which ransomware affiliates commonly abuse for initial access and lateral movement. No specific victim is named, so this is a capability/service rather than a confirmed intrusion. Defenders should hunt for unauthorized RMM sessions and enforce MFA on remote-management tools.Access sale● 55
Venta de acceso a sitio gubernamental indio (mgovcloud.in)A seller is offering access to accounts.mgovcloud.in, an Indian government portal, claiming to reveal classified documents. Sales of government access enable espionage, data theft and further intrusion into state systems. Defenders should monitor for credential abuse and unauthorized logins to that domain and treat the claim as an active access offer.Access sale● 78
Venta de acceso inicial a la india Bharti AirtelA threat actor is advertising initial access to Bharti Airtel, one of India's largest telecom operators, in a freshly posted forum thread. Telecom access is high-impact, enabling subscriber-data theft, interception and lateral movement into critical infrastructure. Although outside LATAM, a named telecom access sale warrants tracking and notification.