Underground · what matters today
The underground stories that broke through this window. Gov/mil, access sales, ransomware, leaks, stealers. Screenshots and context on each.
Distribution by category · window
- Gov / Military5
- Access sale11
- Ransomware33
- Leak88
- Stealer0
- Other1
Window
Category
Severity
Filtración de 263 GB de datos de ciudadanos de EE. UU.
US citizens
A dataset of 263 GB containing US citizen PII (names, addresses, income, family details) is circulating. The scale is massive and could fuel identity theft and fraud. Although no specific organization is named, this is a major data exposure relevant for global breach monitoring.
Filtran la base de datos del foro BreachForums
BreachForums
A user on DarkNetArmy claims that the BreachForums database has been leaked, which could contain usernames, emails, hashed passwords, and private messages of forum members. This is relevant for threat intelligence as BreachForums is a major cybercrime forum. The leak appears fresh and may expose identities of underground actors.
Filtración masiva de credenciales de acceso de Secretline.top
Secretline.top / StarLinkClouds
A free dump of nearly 9.7 million URL/login/password rows attributed to Secretline.top was posted on carding forums. These credentials likely come from stealer logs and can be used for credential stuffing against banking, government, and corporate portals. Defenders should check exposure of their users and enforce password resets and MFA.
Base de datos de ekiba.de (200K registros con teléfonos y correos) en venta
ekiba.de
A 200,000-record database from German site ekiba.de is being sold, containing phone numbers and email addresses. While not as sensitive as financial data, the volume enables phishing and spam campaigns. This leak should be reported to German data protection authorities, and affected users should be alerted to potential social engineering.
Base de datos de juandediego.es (80K registros con NIF/IBAN) en venta
juandediego.es
An 80,000-record database from Spanish site juandediego.es is offered for sale, including CIF/NIF and IBAN lines. The presence of tax identifiers and bank account numbers elevates the risk of financial fraud and impersonation. This is a significant data breach disclosure that should be investigated by the affected company and relevant authorities.
Base de datos de tellmebye.com (1.5M registros con IBAN y DNI) en venta
tellmebye.com
A 1.5 million-line database from tellmebye.com, a Spanish service, is for sale, reportedly including IBAN, date of birth, DNI, and phone numbers. This is highly sensitive PII plus financial data, posing a serious risk of fraud and identity theft. The combination of financial and identity fields makes this a high-priority alert for Spanish-speaking regions.
Gran base de datos de helity.es (2M registros) en venta
helity.es
A database containing 2 million lines from Spanish site helity.es is being sold on a darkweb marketplace. The exact data fields are not specified, but the volume indicates a large-scale exposure. Organizations should assess their exposure if they have accounts on the platform and monitor for fraud.
Filtración de datos de 70.000 agentes de inteligencia marroquíes
Dirección General de Vigilancia del Territorio (Marruecos)
A massive leak reportedly exposes the personal data of around 70,000 Moroccan intelligence agents from the DGST. The information, published by the group Jabaroot, may include identities, addresses, and other sensitive records. This is a significant government intelligence breach that merits close monitoring because it demonstrates the scale of data adversaries can obtain and publish.
Filtración de la base de datos SQL completa de Cornerstone Residential Property
Cornerstone Residential Property
A complete SQL dump of Cornerstone Residential Property was posted on Spear, likely exposing customer and property records. The database could enable phishing, fraud, and credential stuffing against the company and its clients. The leak is fresh and should be monitored.
Fuga de datos de ciudadanía rusa de 20 GB publicada en foro ilegal
Ciudadanos de Rusia
A 20 GB uncompressed database of Russian citizenship data was posted on the Spear leak forum. It contains personal records of Russian citizens and is freely available for download. Although outside Latin America, this is a significant government-related data breach that could drive identity fraud and targeted operations.
Base de datos DEAD HAND de 5 TB con claves API en venta
An unverified ad offers a 5 TB database containing API keys and other sensitive data, with free ULP access. If real, it could be one of the largest leaks available, enabling credential abuse and supply-chain attacks. The lack of details makes it hard to assess current impact, but the scale deserves monitoring.
Filtración de base de datos de Chile con 10 millones de registros
Chile
A database with ~10 million records from Chile is being shared on an underground forum. This scale indicates a significant exposure of personal data, likely enabling identity theft and fraud. Latin American defenders should check if their data is affected and monitor for misuse.
Acceso de administrador filtrado al TeamCity de SteelSeries
SteelSeries
A freshly leaked admin access to SteelSeries' TeamCity CI/CD server was posted on a darkweb forum. The breach could expose source code, build pipelines, secrets and internal credentials, allowing further compromise. Although not in Latin America, it is a real high-value corporate target and the post is recent, so it warrants immediate attention.
Filtración de datos de 820 millones de usuarios de Alipay
Alipay
A database reportedly containing 820 million Alipay user records has been leaked on a hacking forum, with names and phone numbers. The 5GB archive represents one of the largest consumer data exposures. Organizations should prepare for credential stuffing and phishing campaigns targeting affected users.
Filtración de 7,6 millones de credenciales URL:Login:Pass en foro darkweb
Secretline.top / StarLinkClouds
A dataset containing 7.6 million URL:Login:Pass lines has been released on a darkweb leaks forum. These stealer logs can be used to compromise accounts across many services, including webmail, corporate portals, and e-commerce platforms. Defenders should monitor for credential stuffing and validate whether any of their users are exposed.
Venta de base de datos de 1M de empresas e inversores de EE. UU.
USA Business & Investor Database
A carding forum advertises the sale of a 1M-record subset of an 8M-record USA business and investor database. The data likely includes contacts of U.S. companies/investors, enabling phishing or fraud. No posting date or victim organization is shown, so urgency is limited, but it is a sizable database for sale.