BRIEFLeakhighP62
Billing database with 6 million records for sale
Detected17 September 2026 · 20:12 UTC
A DarkForums seller is offering a billing dataset of roughly 6 million records, posted 15-Sep-2026 and therefore fresh. Billing data typically carries names, addresses and payment details, fueling fraud and account takeover. A set this large also feeds credential-stuffing against the underlying merchants.
CategoryLeak
Severityhigh
Priority score62
Detected17 September 2026 · 20:12 UTC
Leak● 48
Filtración de datos de Bijak.in con muestra de la aerolínea VolarisA ~308K-record database tied to Bijak.in was shared, including phone numbers, IPs and names, with a free sample referencing Volaris.com. Volaris is a major Mexican airline, so the sample points to a LATAM transport entity being affected. Such contact data enables targeted phishing and SIM-swap fraud against customers and staff.Leak● 45
Filtración de 56.000 clientes de Energynet SerbiaA database of 56,000+ customers of Serbia's Energynet (HVAC services) was shared on DarkForums, exposing names, contact and address details. Though outside Latin America, it is a concrete company leak useful for phishing and fraud campaigns. Lower regional priority, but it confirms an active seller of real corporate data.Leak● 65
Base de datos robada de Ledger (309.000 registros) a la ventaA listing claims to offer a stolen Ledger database containing 309,000 records dated 2026. Ledger is a major crypto-hardware wallet vendor, and customer-data leaks erode trust and feed targeted phishing and extortion against high-value crypto holders. It is unverified, but given the brand's breach history it merits monitoring.Leak● 55
Volcado masivo de 1.200 millones de credenciales (44 GB)A 44 GB dump containing roughly 1.2 billion URL:login:password lines was posted on 15 September 2026. This is a very large stealer-log aggregation, implying massive credential-reuse risk across corporate and consumer accounts. Defenders should enable credential-leak detection and force resets for exposed users.Leak● 62
Filtración de la base de datos central de VodafoneA threat actor claims to have compromised Vodafone's core database and posted an encrypted drop on a cloned forum. Vodafone is a major global telecom, so a core database leak could expose subscriber and infrastructure data at scale. Defenders in telecom should treat this as a possible exposure pending verification.Leak● 42
Filtración de datos de John Lewis, Currys y American AirlinesA leak thread offers data linked to UK retailers John Lewis, Currys and PC World plus US airlines American Airlines and Southwest. Collections like this usually contain customer accounts and credentials that feed fraud and account takeover. It is outside LatAm, but the airlines' reach makes it worth tracking.