Underground · what matters today
The underground stories that broke through this window. Gov/mil, access sales, ransomware, leaks, stealers. Screenshots and context on each.
Distribution by category · window
- Gov / Military5
- Access sale11
- Ransomware33
- Leak88
- Stealer0
- Other1
Window
Category
Severity
Filtración de datos de pacientes del portal australiano Healthengine (428k registros)
Healthengine (healthengine.com.au)
Australia's health booking platform Healthengine had 428,000 patient contact records leaked, including emails and personal details. Although not in Latin America, the health data is highly sensitive and may be used for targeted scams. The database was posted on the same leak forum and appears recent.
Muestra de 180.000 credenciales robadas (URL:LOG:PASS) publicada en Plutonium
Plutonium / unknown victims
A sample of 180,000 URL:LOG:PASS stealer log lines was released for free on the Plutonium channel. These credentials likely came from infostealer infections and can be used for account takeover and network intrusion. The post is extremely recent, making the data a priority for credential monitoring.
Filtración de base de datos de Pensamiento Digital Argentina (478k contactos)
Pensamiento Digital Argentina (pensamientodigital.com.ar)
A database with 478,000 email contacts and job titles from the Argentine domain pensamientodigital.com.ar has been leaked on a cybercrime forum. The data enables targeted phishing and social engineering against Argentine professionals and organizations. The leak appears recent and is directly relevant to Spanish-speaking LATAM defenders.
Filtración de base de datos de Fortalezas.org en Brasil (742k perfiles)
Fortalezas.org
The Brazilian portal fortalezas.org suffered a data leak involving 742,000 personal contacts and professional profiles. This is a large exposure of Brazilian personal data that could be used for fraud, phishing, and credential stuffing. The database was published on a specialized leak forum and appears fresh.
Filtración de datos de clientes de la aerolínea estatal boliviana BOA (437k registros)
BOA - Boliviana de Aviación
Customer contact data from Bolivia's state-owned airline BOA (boa.bo) was leaked, with 437,000 CRM records including personal and contact information. The breach of a state-linked carrier is significant for Bolivian critical infrastructure and national security. The dump is recent and posted on a known leak forum.
Venta de 1.3TB de datos de Eurail/Interrail
Eurail/Interrail
A seller offers 1.3TB of data allegedly from Eurail/Interrail, citing a SecurityWeek article. This fresh, large-scale leak likely contains personal and payment data of European rail passengers. Defenders should watch for related credential dumps and phishing, and EU DPAs may need to be alerted.
Venta de base de datos de 4TB con documentos de identidad y selfies
The ad offers a 4TB database of identity documents including selfies, passports, and driver's licenses. This massive scale could enable large-scale identity fraud and KYC bypass. Defenders should check if their customers' PII appears in such datasets, though the unknown origin and date reduce immediate actionability.
Venta de datos robados de Eurail/Interrail (1,3 TB)
Eurail/Interrail
A seller is offering 1.3 TB of data from Eurail/Interrail, referencing a SecurityWeek report about hackers stealing customer records. This is a large, fresh breach dataset from a known travel company that could contain personal and payment information. Organisations should check for related exposure and reset any affected credentials.
Filtración masiva de credenciales de Secretline.top (9,8 millones de líneas)
Secretline.top
A free dump of nearly 10 million URL:login:password lines linked to Secretline.top and StarLinkClouds was posted on a stealer-log forum. This scale of credential exposure can fuel account takeover, credential stuffing, and further intrusions. Defenders should treat any reused credentials as compromised and monitor for abuse.
Venta masiva de 239 TB con más de 100.000 bases de datos privadas
A user is selling an aggregated collection of 239 TB of data, advertised as including more than 100,000 private databases. The contents appear to be a compilation of numerous past breaches rather than a single fresh incident, and the post date is unclear. It still represents a major credential-stuffing risk and should be flagged for exposure monitoring.
Venta de base de datos de SK Telecom (Corea del Sur)
SK Telecom
A threat actor is selling a database from SK Telecom, one of South Korea's largest telecommunications providers, with organizational and possibly customer data. The freshness of the post (August 2026) and the size of the operator make it a high-value leak that could affect millions of users. Organizations should check for exposed credentials and monitor for targeted phishing.
Filtración de base de datos del Boletín Oficial argentino
Boletín Oficial de la República Argentina
A seller on a dark web leak forum is offering a database from Argentina's Official Gazette (Boletín Oficial). The dataset appears to contain records from the government's official bulletin, which may include sensitive personally identifiable information and official administrative data. This is a fresh, Argentine government-related leak that could facilitate fraud or social engineering against public institutions and citizens.
Base de datos de complexpress.hu con 1 millón de registros a la venta
complexpress.hu
A database from the Hungarian site complexpress.hu is for sale, with about one million records. It likely contains personal data of Hungarian users. This large, fresh leak could fuel phishing and identity theft, so defenders should track it and watch for follow-on attacks.
Venta de base de datos de 4 TB con selfies, pasaportes y DNIs
A seller offers a 4TB database containing selfies, passport scans and ID documents, likely aggregated from multiple breaches. This volume of identity data is a major risk for account takeover and fraud. Defenders should monitor for any inclusion of regional data and alert affected users.
Filtración de 1,7 millones de credenciales url:log:pass en Spear Leaks
A new stealer-log dump with around 1.7 million URL:log:pass entries was posted on Spear Leaks. These credentials come from infected machines and can be used for account takeover, initial access and credential stuffing. Defenders should check the dump against their assets and reset exposed passwords.
Base de datos de hdsoudage.fr (Francia) a la venta
hdsoudage.fr
The database of French company hdsoudage.fr, with 50,000 records, is being offered for sale. This fresh leak may compromise customer or operational data. It represents a real breach that could be exploited for further attacks or data abuse.
Base de datos de la red social truthbook.social a la venta
truthbook.social
A database of the social network truthbook.social with 75,000 records is being sold on a leak market. This fresh leak likely contains user personal data, useful for credential stuffing or identity theft. It is a recent breach worth monitoring for affected users.
Listado de 500 mil credenciales de Gmail publicado en foro
Gmail users
A thread on a Russian forum is sharing a combolist of 500,000 unique Gmail credentials dated 2026. Such lists are typically used for credential stuffing and can lead to account takeovers if users reuse passwords. While the exact source and freshness are unconfirmed, the volume merits a quick check for any overlaps with government or corporate domains.
Base de datos de 1 millón de usuarios de casino alemán a la venta
German casino (unidentified)
A database with one million user records from a German casino is being offered for sale. The leak appears fresh (posted on 23 August 2026) and includes personal and possibly financial data of casino customers. Even though it is not in Latin America, exposed credentials and personal data can be reused for phishing or account takeover, so it should be monitored.
Filtración masiva expone datos de 70.000 agentes de inteligencia de Marruecos
Moroccan intelligence (DGST)
A forum thread claims a massive leak (Jabaroot) exposing personal data of 70,000 Moroccan intelligence officers, including the DGST. This scale of a state intelligence breach has significant espionage and targeting implications, and the leak appears to be current. Defenders should verify the data and monitor for follow-on harassment or spear-phishing against the exposed personnel.
Fuga de datos del exchange de criptomonedas BitMax.io
BitMax.io
A database from the crypto exchange BitMax.io has been published on a dark web forum. While the full size is not confirmed, the leak may expose user personal information, including emails and financial data. This is a relevant indicator for organizations monitoring credential compromise and financial-sector data breaches.
Filtración de 15 millones de credenciales URL:LOG:PASS
A fresh underground post shares a 15 million-line list of URL:login:password combinations, likely harvested from stealer logs. This volume of credentials can enable widespread account takeover across many services. Organizations should check the list for exposed corporate accounts.
Filtración de base de datos del Ministerio de Seguridad Pública de China
Ministry of Public Security of China
An underground forum is distributing a database attributed to China's Ministry of Public Security with a 2026 date. If genuine, it could expose highly sensitive law-enforcement or citizen data. This is a major government leak that merits validation and monitoring even though it is outside Latin America.
Base de datos de 1 millón de estadounidenses con datos bancarios a la venta
US citizens
A database with fullz and banking details of 1 million US citizens is offered for sale on a carding forum. This financial PII enables credit card fraud, account takeover and identity theft. The victim is outside Latin America and the post date is unknown, so it is not a fresh regional alert.