Underground · what matters today
The underground stories that broke through this window. Gov/mil, access sales, ransomware, leaks, stealers. Screenshots and context on each.
Distribution by category · window
- Gov / Military5
- Access sale11
- Ransomware35
- Leak93
- Stealer0
- Other1
Window
Category
Severity
Fuga de datos de ciudadanía rusa de 20 GB publicada en foro ilegal
Ciudadanos de Rusia
A 20 GB uncompressed database of Russian citizenship data was posted on the Spear leak forum. It contains personal records of Russian citizens and is freely available for download. Although outside Latin America, this is a significant government-related data breach that could drive identity fraud and targeted operations.
Base de datos DEAD HAND de 5 TB con claves API en venta
An unverified ad offers a 5 TB database containing API keys and other sensitive data, with free ULP access. If real, it could be one of the largest leaks available, enabling credential abuse and supply-chain attacks. The lack of details makes it hard to assess current impact, but the scale deserves monitoring.
Filtración de base de datos de Chile con 10 millones de registros
Chile
A database with ~10 million records from Chile is being shared on an underground forum. This scale indicates a significant exposure of personal data, likely enabling identity theft and fraud. Latin American defenders should check if their data is affected and monitor for misuse.
Ransomware Qilin publica a Consultores de Seguros
Consultores de Seguros
The Qilin ransomware group has posted 'Consultores de Seguros' on its leak site, claiming the theft of corporate data. The company appears to operate in the insurance/financial services sector and the Spanish-language name suggests it may be based in Latin America or Spain. This is a fresh ransomware victim and should be monitored for potential data leak, as financial services is a high-risk sector.
Filtración de 100 GB de Jones, Little & Co., despacho contable
Jones, Little & Co., CPAs, LLP
The Dark Project ransomware group published over 100GB of data allegedly from Jones, Little & Co., a US accounting firm, including financial records. Accounting firms hold highly sensitive client financial data, making this leak a serious risk for identity theft and fraud. This incident is significant despite being outside the region due to the sensitive nature of the data.
Ransomware Dark Project publica a la empresa Liberty Group
The Liberty Group
The Dark Project ransomware group has publicly listed The Liberty Group, a US moving and logistics company, as a victim. The group typically leaks stolen data on their darknet blog. While the company is not in Latin America, the leak of corporate data can expose employee PII and client information, and indicates the threat group's ongoing activity.
Venta de acceso admin a TeamCity de Steelseries
Steelseries
A threat actor is selling admin access to Steelseries' TeamCity server, a build and release management system. Such access can lead to source code theft, supply chain attacks, or further lateral movement into corporate networks. Defenders should treat this as a critical initial access risk and check for any related IOCs.
Acceso de administrador filtrado al TeamCity de SteelSeries
SteelSeries
A freshly leaked admin access to SteelSeries' TeamCity CI/CD server was posted on a darkweb forum. The breach could expose source code, build pipelines, secrets and internal credentials, allowing further compromise. Although not in Latin America, it is a real high-value corporate target and the post is recent, so it warrants immediate attention.
Ransomware DragonForce publica datos de la empresa brasileña Frato
Frato
DragonForce listed Brazilian company Frato on its ransomware leak site, exposing financial documentation, shareholder information, and employee/client personal data across the group. This is a recent Latin American ransomware victim that could impact business partners and customers. Defenders should watch for leaked data and ensure response plans are ready.
Ransomware DragonForce publica datos de la constructora argentina Criba
Criba
DragonForce published data allegedly from Argentine construction firm Criba, including financial documents and client files covering Argentina and Uruguay. The leak may expose sensitive personal and corporate data of employees and partners. Organizations in the Argentine construction sector should verify potential exposure and increase monitoring.
Ransomware Booba publica datos de la firma legal Federis Abogados
Federis Abogados
The ransomware group 'booba project' has published 61 GB of data stolen from Federis Abogados, a Mexican law firm. The leak may include sensitive legal documents and client information, creating legal and reputational risks. This fresh ransomware incident in Latin America warrants immediate monitoring and response.
Filtración de datos de 820 millones de usuarios de Alipay
Alipay
A database reportedly containing 820 million Alipay user records has been leaked on a hacking forum, with names and phone numbers. The 5GB archive represents one of the largest consumer data exposures. Organizations should prepare for credential stuffing and phishing campaigns targeting affected users.
Ransomware Qilin publica a A&E + SMA Design (Emiratos Árabes)
A&E + SMA Design
The Qilin ransomware group has added A&E + SMA Design, a professional services firm in the United Arab Emirates, to its leak site. This confirms the victim did not pay the ransom and internal data has been exfiltrated. While outside Latin America, it is a fresh ransomware case that could impact regional partners or supply chains.
Filtración de 7,6 millones de credenciales URL:Login:Pass en foro darkweb
Secretline.top / StarLinkClouds
A dataset containing 7.6 million URL:Login:Pass lines has been released on a darkweb leaks forum. These stealer logs can be used to compromise accounts across many services, including webmail, corporate portals, and e-commerce platforms. Defenders should monitor for credential stuffing and validate whether any of their users are exposed.
Venta de base de datos de 1M de empresas e inversores de EE. UU.
USA Business & Investor Database
A carding forum advertises the sale of a 1M-record subset of an 8M-record USA business and investor database. The data likely includes contacts of U.S. companies/investors, enabling phishing or fraud. No posting date or victim organization is shown, so urgency is limited, but it is a sizable database for sale.
Venta de base de datos con 7,6 millones de credenciales URL:Login:Pass
A credential database with 7.6 million URL:Login:Pass entries is being offered, similar to other large-scale credential dumps on the same forum. These credentials can be exploited for credential stuffing or unauthorized access to various online systems. The volume and potential reach mean organizations should check for exposure and enforce credential resets.
Base de datos con 21,6 millones de credenciales URL:Login:Pass a la venta
A fresh database of over 21.6 million URL:Login:Pass credentials dated 08/23/2026 is being sold. The list likely contains credentials for multiple web services, useful for credential stuffing or initial access to corporate systems. Its scale and freshness make it a direct threat to any organization, including those in LATAM.
Venta de base de datos con 7,4 millones de credenciales URL:Login:Pass
A large credential database containing 7.4 million URL:Login:Pass entries is being marketed on a carding forum. These credentials could grant access to various online platforms and corporate portals, enabling account takeover or network intrusion. The absence of a clear date affects urgency, but the volume alone warrants monitoring and credential-reset recommendations for potentially affected entities.
Filtración de datos de 11.5 millones de ciudadanos mexicanos
México (ciudadanos)
A dataset reportedly containing records of 11.5 million Mexican citizens is being shared on a carding forum. The 1.36 GB leak likely includes personal information and could be used for identity theft, fraud, and phishing campaigns. Defenders in Latin America should monitor for exposure of their constituents and validate if the data overlaps with local databases.
Venta de base de datos de rezcomm.com con 17 millones de registros
rezcomm.com
A seller is offering the full database of rezcomm.com, a UK-based booking platform, with approximately 17 million users. The data likely includes personal and contact details of European customers and can be used for credential stuffing, phishing, and fraud. Defenders should check if their organizations rely on Rezcomm and monitor for related incidents.
Venta de base de datos de rezcomm.com con 17 millones de registros
rezcomm.com
A darknet seller is offering a database from rezcomm.com containing personal data of 17 million people, likely including names, emails, and phone numbers. The scale and freshness make it a significant data breach that could enable phishing, identity theft, and credential stuffing. Organizations in Europe should check if their users are affected.
Venta de 6.1 TB de datos personales de Gruppo Spaggiari Parma por $50k
Gruppo Spaggiari Parma
A seller is offering 6.1 TB of personal information allegedly from Gruppo Spaggiari Parma, an Italian IT provider for the education sector, for $50,000. The scale of the leak is enormous and could affect millions of individuals. Even though it is not in Latin America, this is a major incident worth monitoring.
Ransomware Coinbasecartel publica a Westwing Group SE
Westwing Group SE
The Coinbasecartel ransomware group has claimed responsibility for an attack on Westwing Group SE, a major European e-commerce company for home and living products. The incident affects a large online retail operation and may involve customer data. It is relevant as a recent ransomware victim outside the region.
Ransomware Genesis publica a Hospitality Health ER
Hospitality Health ER
The Genesis ransomware group has publicly listed Hospitality Health ER, a U.S. healthcare provider, on its leak site. This compromises critical medical infrastructure and could expose sensitive patient health information. Although outside Latin America, it signals an active ransomware campaign that could expand regionally.