BRIEFLeaklowP31
Indonesian user database 'Surxrat' offered for sale
Surxrat (Indonesia)
Detected17 September 2026 · 09:12 UTC
A seller is offering a user database from 'Surxrat' (Indonesia) on a dark-web forum, dated 2026-04-27. The data appears tied to victims of the Surxrat remote-access trojan, exposing accounts and possibly device details. It is outside Latin America and several months old, so alert value is limited but still worth tracking.
CategoryLeak
Severitylow
Priority score31
Detected17 September 2026 · 09:12 UTC
Leak● 46
Filtración de datos de la plataforma de influencers Alist.ae (EAU), 63.000 registrosA threat actor posted a 63,000-record dataset from Alist.ae, a UAE influencer-marketing platform, on a dark-web forum with a fresh date of 2026. The dump likely contains contact and account details of influencers and brands. While outside Latin America, it is a fresh leak of a real organization, useful for credential-reuse and phishing exposure checks.Leak● 51
Filtración de datos de vigilancia del aeropuerto de Shanghái (Suishenma)A .csv file allegedly containing Shanghai Suishenma airport surveillance data has been posted for leak, suggesting exposure of health and surveillance records tied to travelers. Such data is highly sensitive and can enable tracking and targeting of individuals. It matters for defenders monitoring surveillance-data leaks, though it falls outside the AR-LATAM region.Leak● 25
Base de datos israelí publicada en foro de brechasA thread on BreachForums offers an 'Israel database' for download, though the exact size and source are not clearly stated. If genuine it could hold citizen or organizational records of Israeli entities. Relevance to an AR-LATAM operator is limited and the post dates from May 2026, making it stale.Leak● 35
Base de datos de 2,3 millones de cuentas de Wired a la ventaA 2.3M-record database tied to wired.com is offered on DarkForums. These account/subscriber records are useful for credential stuffing against a media audience. The post is dated December 2025 and targets a US outlet, so it is neither fresh nor regionally relevant.Leak● 50
Base de datos indonesia de 50 millones de registros publicadaA 50-million-record Indonesian database attributed to 'JakartaGhostDigital' is being shared on a forum. At this scale it likely contains citizen PII usable for fraud and account takeover. The target is outside the region and there is no reliable timestamp, so it is recorded but not treated as a fresh alert.Leak● 50
Base de datos de suscriptores de ISP de Indonesia a la ventaA collection claiming to be an Indonesian internet service provider subscriber database is circulating for download on RaidForums. Telecom subscriber records enable SIM-swap, phishing and account-takeover campaigns against consumers. The target lies outside Latin America and the post carries no clear date, so it is logged at moderate priority.