Underground · what matters today
The underground stories that broke through this window. Gov/mil, access sales, ransomware, leaks, stealers. Screenshots and context on each.
Distribution by category · window
- Gov / Military5
- Access sale11
- Ransomware33
- Leak88
- Stealer0
- Other1
Window
Category
Severity
Combolist de más de 120.000 correos corporativos de empresas a la venta
Corporate organizations
This is a 120,000-line combolist of corporate business email addresses and passwords, likely harvested from breaches. It could be used for business email compromise (BEC), phishing, or credential stuffing against companies. The geographic scope is not specified, but corporate credentials are valuable regardless of location; no clear posting date limits the immediate alert value.
Venta de datos personales de un millón de personas de EE. UU.
US residents
A database containing personal information of one million US individuals is being sold, which can fuel identity theft and financial fraud. The thread appears to be older (no recent date), so the urgency is limited, but the volume makes it a notable data exposure. Even if stale, it may still be used for credential stuffing or phishing campaigns.
Venta de 1 millón de fullz con datos bancarios de EE. UU.
A thread advertises one million US fullz with banking details, a substantial volume of identity and financial data. The lack of a named victim and the typical staleness of such listings reduce its immediate value, but it still warrants monitoring for credential and fraud campaigns.
Venta de base de datos de Binance con 1,5 millones de registros
Binance
A seller on a carding forum advertises a 2026 Binance database containing 1.5 million records. If valid, this is a large leak of a major cryptocurrency exchange's user data, with potential for account takeover and fraud. The freshness and scale make it worth validating urgently.
Filtración de base de datos de control vehicular de la Fiscalía de Coahuila
Fiscalía de Coahuila
The Coahuila Prosecutor's Office vehicle control database has been leaked on a dark web forum. The dataset likely contains vehicle registration and ownership records from a Mexican state government, useful for identity fraud and extortion. This is a fresh, government-related data exposure relevant to Latin American defenders.
Divulgación de más de 10 millones de credenciales URL:LOGIN:PASSWORD de StarLinkClouds
Secretline.top / StarLinkClouds
A large dump containing more than 10 million URL:LOGIN:PASSWORD lines attributed to Secretline.top and StarLinkClouds has been posted on a breach forum. The data likely originates from stealer malware and could facilitate account takeovers across many platforms. Organizations should check these credentials for exposure and implement phishing-resistant MFA.
Filtración masiva de 250 millones de credenciales de registros stealer
A private dump of 250 million URL:LOGIN:PASSWORD entries from stealer logs was published on August 30, 2026. This represents a massive trove of credentials that could be used to access diverse online services, including potentially corporate and personal accounts. Defenders should treat any credentials from stealer logs as compromised and enforce password resets, MFA, and dark web monitoring.
Filtración de datos de la CAF francesa con 22,4 millones de registros
CAF.FR
A database of CAF.FR, the French family allowance agency, containing 22.4 million records from December 2025 is being shared. The data was likely obtained in a breach of a government agency and includes sensitive personal information. Although the breach is several months old, the volume makes it relevant for monitoring and fraud prevention.
Venta de base de datos de telecomunicaciones china con 650 millones de registros
A database allegedly from a Chinese telecom operator containing 650 million records is being offered. This is one of the largest data sets seen, likely including names, phone numbers, addresses, and possibly more. Even if the breach is not fresh, the scale makes it a critical credential and privacy risk for affected users.
Filtración de base de datos de la empresa de IA mercor.com
mercor.com
A seller is offering the source code, user database, and contractor database of mercor.com, an AI training company based in the USA. The leak likely contains source code and personal data of users and contractors, which could facilitate further attacks. This is a significant breach of a real organization and warrants immediate monitoring.
Venta de base de datos de 4 TB con selfies, pasaportes y documentos de identidad
A forum thread offers a 4-terabyte database of identity documents, including selfies and video selfies, passports, national IDs and driver's licenses. If genuine, this scale of biometric and PII data enables KYC bypass, account takeover and identity fraud at scale. Defenders should check whether their users' documents are exposed and watch for resale of this dataset.
Venta de lista de credenciales de 3.1 millones de URL:LOG:PASS
This post advertises a private 3.1 million URL:LOG:PASS dataset, similar to other infostealer credential dumps. Such lists are used for unauthorized access to web applications, email accounts, and remote access portals, posing a risk to any organization whose users are included. No date is provided, so recency cannot be confirmed, but the size makes it relevant for credential monitoring.
Venta de lista de credenciales de 3.6 millones de URL:LOG:PASS
This thread offers a private list of 3.6 million URL:LOG:PASS credentials, likely harvested from infostealer malware. The scale is significant and could enable credential stuffing against a wide range of online services, including corporate portals and VPNs. The lack of a clear post date makes it difficult to confirm freshness, but the volume alone justifies monitoring.
Venta de base de datos de 4 TB con documentos de identidad y selfies
A 4 TB database of identity documents, including passports, IDs, and selfies, is being offered for sale. The scale is massive and likely enables identity fraud and account takeover. Defenders should monitor for any of their users' documents appearing in these collections and alert affected individuals.
Base de datos de info personal de EE. UU. y leads de Bank of America a la venta
Bank of America
A seller is advertising a database of USA personal information and Bank of America leads on a carding forum. While the size and source are not specified, such data can enable account takeover, phishing, and financial fraud. Defenders should watch for increased fraud attempts against US-based financial customers and monitor for related exposures.
Venta de datos de 148.000 ciudadanos belgas con IBANs y correos
Ciudadanos belgas
A database containing 148,000 Belgian citizens' records with 40,000 IBANs and 52,000 emails is being offered for sale. This is a substantial leak of personal and financial data that could enable identity theft, fraud, and targeted phishing against Belgian residents. Financial institutions and authorities should treat this as an active data breach.
Filtración de 30 millones de credenciales de acceso web
A free dump of 30 million URL:login:password lines was posted, likely harvested by infostealers. It spans many online services and enables credential stuffing against email, banking, government, and VPN portals. Organizations should immediately check exposed credentials and enforce MFA.
Base de datos de 200 millones de cuentas de Twitter (X) a la venta
Twitter / X
The post offers a 200 million-record Twitter/X email:password database, allegedly from a 2025 breach. While the scale is significant, the data appears to be at least a year old, reducing its urgency as a fresh alert. Organizations should still use it to check for compromised employee credentials.
Venta de base de datos masiva de credenciales (35 mil millones) en foros underground
Stradu DB Market Cloud
A seller is advertising a credential database containing approximately 35 billion unique mail:pass rows (1.1 TB), aggregated from multiple breaches. While not attributed to a specific organization, this corpus is large enough to enable widespread credential stuffing and account takeover across global services. Defenders should monitor it for exposed corporate and personal credentials.
Base de datos masiva de credenciales (35B registros) a la venta
DB Market Cloud is a paid service offering a searchable database of approximately 35 billion unique mail:pass and combolist records. Such credential collections enable widespread credential stuffing, account takeover, and targeted phishing campaigns. Since it includes data from numerous breaches, organizations should check for exposed corporate credentials.
Filtración de la base de datos del gobierno de Irak rss.gov.iq (100 GB)
rss.gov.iq
A 100 GB database from the Iraqi government domain rss.gov.iq has been leaked and published in August 2026. The scale suggests it may contain sensitive government records, potentially affecting national security. This is a significant data breach that warrants immediate monitoring for misuse of the exposed data.
Filtración de base de datos del gobierno de Irak (rss.gov.iq)
Government of Iraq (rss.gov.iq)
A 100 GB database allegedly from the Iraqi government domain rss.gov.iq was leaked on a cybercrime forum. The leak appears fresh (August 2026) and could include sensitive official data, accounts, or internal records. While the entity is outside Latin America, this is a substantial government breach that warrants immediate validation and monitoring.
Filtración de la base de datos de USAGummies
USAGummies
The customer database of USAGummies, a US-based company, is being offered as exclusive and fresh. The leak likely contains personal data of customers, which could lead to identity theft, fraud, and targeted phishing. Even though the company is not in the Latin American region, the incident is relevant for global threat monitoring and demonstrates active database trading.
Filtración de 433.000 registros de acceso privados
A dataset of 433,000 private logs allegedly obtained from info-stealer malware is being offered. These logs contain credentials (usernames, passwords) and possibly sessions for a wide range of online services. The sheer volume and freshness make it a valuable resource for credential stuffing and account takeover attacks.