BRIEFLeaklowP38
40 million URL:LOGIN:PASSWORD credential dump
Detected16 September 2026 · 23:12 UTC
A private 40 million line URL:LOGIN:PASSWORD stealer log was published on 16/09/2026, indicating freshly harvested infostealer credentials. It is a generic aggregated dump without a named victim, so its direct relevance to AR-LATAM is limited. It still matters as a source of valid credentials that may enable account takeover if re-used broadly.
CategoryLeak
Severitylow
Priority score38
Detected16 September 2026 · 23:12 UTC
Leak● 32
Base de datos de una repartidora marroquí con 500.000 registrosA full database belonging to a large Moroccan delivery company, roughly 500,000 records, was posted for sale on DarkNetArmy. It is a mid-sized corporate leak outside the AR-LATAM region, more relevant to the affected company than to regional defenders. It is notable only as another logistics-sector data exposure.Leak● 40
Base de datos de 53 millones de correos de EE. UU. en ventaA freshly posted listing advertises a 53 million record email database labeled 'USA 2026' on DarkForums. The dataset is large but appears to be a generic bulk email list of unclear provenance, with limited direct impact on AR-LATAM defenders. It is worth tracking only as a source of credential-stuffing and phishing input.Leak● 55
Filtración de base de datos de 602 millones de ciudadanos paquistaníesA threat actor is circulating what is claimed to be a 602 million record database of Pakistani citizens on DarkForums, a nation-scale exposure of identity data. Although outside the AR-LATAM region, the sheer scale makes it a major PII and credential source that could be reused for fraud and targeting worldwide. Defenders should watch for re-use of these records against regional accounts and services.Leak● 42
Base de datos de juandediego.es (España, 80K registros con CIF/NIF e IBAN) a la ventaA database of roughly 80,000 records from the Spanish site juandediego.es is for sale, including CIF/NIF tax identifiers and IBAN bank lines. Combining tax identity with banking data facilitates invoice fraud and direct-debit abuse. Smaller in scope than other listings, so it ranks lower but is still worth tracking.Leak● 62
Base de datos de tellmebye.com (España, 1,5M líneas con IBAN, DNI y teléfono) a la ventaA seller is offering a 1.5 million-line database from the Spanish service tellmebye.com containing IBAN, date of birth, DNI and phone numbers. This is high-grade PII plus banking data that directly enables fraud, phishing and account takeover. Spanish-speaking banks and customers should monitor for downstream abuse even though the entity is in Spain, not LatAm.Leak● 78
Filtración de base de datos de la Facultad de Veterinaria de la UBA (31.000 registros)A threat actor is offering a database of over 31,000 records belonging to the Veterinary Sciences Faculty of the University of Buenos Aires (Argentina). The dataset likely holds student and staff personal data (names, emails, ID numbers) usable for credential stuffing, phishing and identity fraud. As an Argentine public higher-education institution this is sensitive, and affected people should be notified.