Underground · what matters today
The underground stories that broke through this window. Gov/mil, access sales, ransomware, leaks, stealers. Screenshots and context on each.
Distribution by category · window
- Gov / Military5
- Access sale11
- Ransomware33
- Leak88
- Stealer0
- Other1
Window
Category
Severity
Venta de base de datos de 1 millón de fullz y datos bancarios de EE. UU.
unknown (US consumers)
A database of about 1 million US fullz records with personal and banking details is being offered for sale. This is a large-scale identity theft and financial fraud risk, though the source and freshness are unclear. Defenders should monitor for exposed credentials and advise users of potential phishing and fraud.
Filtración de datos personales y SSN de generales de EE.UU.
United States military (general officers)
A free leak on Spear Leaks claims to expose full personal details and Social Security numbers of high-ranking U.S. generals. If authentic, this PII could enable identity theft, financial fraud, and targeted spear-phishing against senior military leaders. The post is fresh (1 hour old) and warrants immediate verification and protective monitoring.
Filtración de pasaportes e identificaciones de EAU (3,5 GB)
UAE (Emiratos Árabes Unidos)
A 3.5 GB archive containing UAE passports and national IDs is being distributed on an underground forum. This volume of government-issued identity documents creates a serious risk of identity theft and document forgery. The post has no clear date and seems to be an older leak, so it is not time-sensitive.
Filtración de datos KYC de Alphaex.net: 15.000 pasaportes y licencias
Alphaex.net
A database with 15,000 KYC records (passports and driving licenses) linked to Alphaex.net is circulating on the xReactor leak forum. The exposed identity documents can be used for fraud, account takeovers, and KYC bypass. The thread appears old, so this is not a fresh alert, but the data remains sensitive.
Filtración masiva de datos de 70.000 agentes de inteligencia marroquíes
DGST - Dirección General de Vigilancia del Territorio, Marruecos
A forum reports a massive leak attributed to Jabaroot exposing 70,000 agents of Morocco's intelligence directorate (DGST). The data reportedly includes detailed personal and operational information of state security personnel. This is a high-impact government data breach that could enable targeted attacks against intelligence agents and serves as a warning for similar leaks in Latin America.
Base de datos de contactos de Polonia (16 millones) a la venta
Poland residents
An unverified seller on a dark web forum is offering a 16-million-record contact database of Polish residents. The data likely includes personal information such as names, addresses, and phone numbers, posing a risk of phishing and identity fraud. Although not from Latin America, the scale and freshness make it relevant for global cyber threat intelligence.
Publicados 613 MB de logs frescos de infostealers
A 613 MB archive of fresh infostealer logs dated 28 August 2026 was shared publicly. These logs likely contain credentials, cookies, and session tokens from many users. The volume and freshness make it a useful source for validating compromised accounts and identifying new breaches.
Venta de base de datos china de telecomunicaciones con 650 millones de registros
Telecomunicaciones de China (sin confirmar)
A seller is offering a 650-million-record database allegedly from a Chinese telecom operator. The dataset likely contains PII and could enable fraud or targeted attacks at scale. The seller is unverified and the source is not fully confirmed, but the size warrants monitoring.
Filtración de 25 millones de credenciales ULP
A fresh dump of 25 million URL:LOGIN:PASSWORD lines was posted on a hidden forum, indicating a large stealer-log compilation. Such credentials can be used for account takeover, VPN/RDP access, and further intrusions. The sheer volume and recent date make it relevant for credential monitoring and dark web watch.
Mega paquete de datos brasileños de 1.500+ GB a la venta
Brazilian data (multiple sources)
An attacker is selling more than 1.5 TB of Brazilian consumer data spanning 2020 to 2026. The pack likely includes PII, credentials and financial records on a massive scale. This poses a severe fraud and identity-theft risk for Brazilian residents and demands analysis to identify sources.
Base de datos de Banco Inter a la venta
Banco Inter
A seller is offering data from Banco Inter, one of Brazil's largest digital banks. This could expose customer account details and financial information. The breach of a financial institution demands urgent impact assessment and customer notification.
Filtración de Serasa: respaldo de 500 GB a la venta
Serasa
A 500 GB backup from Serasa, Brazil's largest credit bureau, is being sold on a darknet forum. The archive likely contains personal, financial and credit data of millions of Brazilian consumers. This is a critical exposure that requires immediate verification and fraud monitoring.
Paquete de bases de datos brasileñas a la venta
Brazil (multiple sources)
A seller is advertising a pack of Brazilian databases on a darknet forum. The pack likely combines data from multiple Brazilian companies, increasing the risk of identity theft and fraud. The lack of detail about sources makes it essential to monitor for follow-up leaks.
Venta de base de datos de Coupang con 33 millones de registros
Coupang
A seller is offering a 2025 database of Coupang, a major South Korean e-commerce platform, containing 33 million records. The data likely includes customer PII and may enable credential stuffing and fraud. Although outside LATAM, this is a significant corporate data breach worth tracking.
Venta de base de datos masiva de 35 mil millones de registros (1.1 TB)
Múltiples organizaciones a nivel global
A vendor is selling a 1.1 TB database with ~35 billion email:password pairs, likely aggregated from multiple breaches. This massive credential compilation enables large-scale credential-stuffing and account takeover. Defenders should validate any exposed credentials against known breach data.
Venta de mega paquete de datos de Brasil actualizado 2022-2026
Ciudadanos de Brasil
A seller is offering an updated Brazilian mega data pack (2022-2026), likely with CPFs, names, addresses, and phones of millions of citizens. This is a major source for identity fraud and social engineering across Latin America. Defenders should assume Brazilian personal data is exposed and monitor for fraudulent activity.
Publican muestra de 900K credenciales robadas por stealer
A free sample of 900,000 URL:LOG:PASS lines from the Plutonium stealer was posted on a darknet forum. These credentials were likely harvested from infected devices and can be used for account takeover or further intrusions. Organizations should check the sample against their exposed domains and enforce credential reset and remediation.
Fuga de datos PII de aerolíneas con acceso a bookntravel
bookntravel
An exposed airline PII database associated with bookntravel is being circulated on underground forums, reportedly including passenger personal information and access credentials. The leak can affect travelers' privacy and enable fraud, phishing, or account takeover if credentials are reused. Organizations in the travel sector should immediately check if their data is impacted and force credential resets.
Venta de bases de datos frescas de Brasil 2026
Brazil (multiple organizations)
A DarkNetArmy seller is advertising fresh databases from Brazil dated 2026, likely containing personal data from multiple Brazilian organizations. This is directly relevant to Latin America and could include sensitive records from companies or institutions in the region. The sale of fresh regional databases suggests active collection, so Brazilian and neighboring-country SOCs should watch for related fraud or credential abuse.
Filtración de datos PII de aerolíneas con acceso a base de datos (bookntravel)
bookntravel
A fresh leak advertises airline passenger PII, possibly including names, contact details and booking information, along with database access. The scope is not disclosed, but exposure of travel data at scale can fuel fraud and targeted phishing. Defenders in the airline and travel sector should monitor for this dataset and validate any exposed credentials.
Filtran 9,5 millones de credenciales de Secretline.top
Secretline.top / StarLinkClouds
A dataset with over 9.5 million URL:login:password lines labeled Secretline.top/@StarLinkClouds has been posted on Spear Leaks. This is a large stealer-log/credential dump that enables widespread account takeover and further intrusion. Organizations in Latin America should check password reuse against this data and force resets for affected users.
Filtración de datos de 70.000 agentes de inteligencia marroquíes
Moroccan intelligence agency (DGST)
The leak exposes personal and operational data of 70,000 Moroccan intelligence agents, a massive breach. It jeopardizes national security and agent safety. Defenders should watch for similar leaks affecting regional agencies.
Filtración masiva de credenciales de Secretline.top (9,5 millones de líneas)
Secretline.top
A free dump on a leak forum contains 9,563,322 URL:login:password lines attributed to Secretline.top, likely collected by info-stealer malware. This credential volume poses significant account-takeover risk for users of the service. Organizations should scan the dump for corporate credentials and force password resets if impacted.
Filtración de base de datos de la italiana UnicaSpa
UnicaSpa.it
A database from UnicaSpa, an Italian back-office and reporting services firm, was leaked on a cybercrime forum. The thread does not disclose the number of records, but the leak is fresh and exposes internal operational data. Defenders should check whether UnicaSpa appears in their supply chain or client portfolios.