BRIEFLeakhighP60
GuruHotel reservations database for sale (528K rows)
GuruHotel
Detected4 October 2026 · 00:55 UTC
A seller offers the full GuruHotel reservations database: 528K rows with roughly 6,300 guest PII leads. Booking data typically includes names, contact details, stay dates and payment hints, enabling targeted phishing and fraud against travelers and corporate clients. The organization should confirm the breach and notify affected guests.
CategoryLeak
Severityhigh
Priority score60
Detected4 October 2026 · 00:55 UTC
Leak● 72
Base de datos de GameStop con 27 millones de registros a la ventaA threat actor is offering a 27-million-record GameStop database containing email:password combinations, claiming a value around $800M. Dumps of this size directly fuel credential stuffing and account takeover against the retailer and its customers. Defenders should force credential resets, watch for reused passwords and monitor for downstream fraud.Leak● 85
Filtración de base de datos SQL de la Universidad Pedagógica Nacional (México)A leaked SQL dump of Mexico's Universidad Pedagógica Nacional (UPN), a federal public education institution, is being posted on a dark-web forum within minutes of discovery. The dump likely exposes student, staff and internal records, giving attackers a working map of the institution's database. Defenders should identify the source of the leak, patch exposed services and prepare notification for affected individuals.Leak● 44
Filtración de 426.000 credenciales de EspañaA large combolist of roughly 426,000 email and password pairs targeting Spanish users was posted, dated late June 2026. Though aggregated credential lists are common, the volume and Spain focus make it usable for credential-stuffing against Spanish accounts. Organizations and users in Spain should reset exposed passwords and monitor for account takeover.Leak● 68
Base de datos de 8.045 colegios de Chile a la ventaA threat actor is selling a database covering 8,045 schools in Chile, likely including institutional and contact details. Education-sector data in Latin America is valuable for phishing and fraud and may include student or staff records. Defenders in the Chilean education sector should verify exposure and warn affected institutions.Leak● 45
Dump de 18 millones de URL:LOG:PASS (VULTA.PW) compartidoAn 18-million-record URL:LOG:PASS dump is being shared and marketed as fresh under 'VULTA.PW'. This volume of stolen credentials can drive automated account-takeover campaigns, so regional SOCs should watch for reuse of these logins. It is commodity data but of significant scale.Leak● 48
Dump de 19,6 millones de credenciales (LUPIN ULP) en circulaciónA bulk credential dump of roughly 19.6 million url:login:password records ('LUPIN ULP') is being circulated from a VIP forum section, dated 10/04/2026. Large stealer-log sets like this enable large-scale credential stuffing and account takeover across many services, including exposed Latin American accounts. Though commodity, its scale warrants monitoring for ATO against regional assets.