Between 2026-08-25 and 2026-08-27, reports emerged of at least six major data breaches—affecting Cornerstone Residential, Toledo Zoo, KodexGlobal, Mercor, Complexpress Logisztika, and others—with millions of records offered for sale on cybercrime forums. On 2026-08-27, Australian authorities arrested alleged TeamPCP members following a joint AFP, WAPOL, and FBI investigation into large-scale cybercrime offending.
15 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
🚨🇺🇸 Cornerstone Residential allegedly breached, SQL dump advertised on cybercrime forum ⠀ Cornerstone Residential, a Texas-based property management company, is allegedly the target of a claimed breach after a threat actor advertised what they describe as a full SQL database dump from the company. ⠀ The threat actor claims the leaked data includes: ⠀ • User preferences • User roles • Elementor
🚨🇺🇸 Toledo Zoo database allegedly leaked on a cybercrime forum, 1.9M+ records claimed ⠀ Toledo Zoo & Aquarium, an Ohio-based zoo and aquarium housing thousands of animals across hundreds of species, is allegedly the target of a claimed data breach after a threat actor advertised a database dump containing approximately 1.9 million records. ⠀ The threat actor claims the database was obtained thr
🚨 KodexGlobal database allegedly offered for sale on a cybercrime forum, 251K+ user accounts claimed ⠀ KodexGlobal, a platform used by law enforcement agencies to submit and manage legal data requests, is allegedly the target of a breach after a threat actor claimed to have accessed its backend through an exposed administrative API and obtained a full database dump. ⠀ The advertised data includes
🚨🇫🇷 MsSanté database allegedly offered for sale on a cybercrime forum, 535K+ records claimed ⠀ MsSanté, France's secure healthcare messaging ecosystem, is allegedly affected by a data exposure after a threat actor advertised a database containing 535,358 records. ⠀ The sample published with the listing appears to contain information associated with healthcare professionals and organizations. ⠀
🚨🇵🇸 Palestinian Ministry of Interior citizen database allegedly leaked on a cybercrime forum, 3.56M records claimed ⠀ A threat actor claims to have obtained a database attributed to the Palestinian Ministry of Interior containing information on 3,559,378 Palestinian citizens. ⠀ The advertised data appears to include: ⠀ • Citizen identification numbers • Full names • Dates of birth • Arabic-lang
🚨🇶🇦 Access to Qatar-based pharmacy chain infrastructure allegedly offered for sale on a cybercrime forum ⠀ An unnamed pharmacy chain in Qatar operating in the healthcare and pharmaceutical sector is allegedly compromised, with a threat actor advertising access to multiple parts of the company's cloud and communications infrastructure. ⠀ The advertised access includes: ⠀ • MongoDB • Google Cloud
🚨🇲🇽 Universidad Autónoma de Sinaloa employee documents allegedly leaked on a cybercrime forum ⠀ Universidad Autónoma de Sinaloa (UAS), a public university in Sinaloa, Mexico, is allegedly affected by a data exposure after a threat actor claimed to have extracted employee information and documents from a university personnel system. ⠀ The actor claims the files were organized using employees' RF
🚨🇨🇦 Chatr Wireless exploit allegedly exposes subscriber data through phone-number lookups ⠀ Chatr Wireless, a Canadian mobile service provider, is the subject of a cybercrime forum listing where a threat actor is selling what they claim is a vulnerability capable of retrieving extensive account information tied to a subscriber's real phone number. ⠀ The allegedly exposed data includes: ⠀ • Full
🚨 Hinge database allegedly offered for sale on a cybercrime forum, 34M+ unique user records claimed ⠀ Hinge, a dating application operated by Match Group, is allegedly affected by a data exposure after a threat actor advertised what they claim is the platform's complete database containing more than 34 million unique user records. ⠀ The advertised data includes: ⠀ • Full names • Email addresses •
🚨🇫🇷 I-RUN customer database allegedly leaked on a cybercrime forum, 1M+ records claimed ⠀ I-RUN, a French online retailer specializing in running and trail-running footwear, apparel and sports equipment, is allegedly affected by a data exposure after a threat actor advertised a 2026 database containing more than 1 million records. ⠀ The advertised data includes: ⠀ • First names • Last names • E
🚨🇨🇳 Chinese booking website database allegedly leaked on a cybercrime forum, 1.94M records claimed ⠀ An unnamed booking website operating in China is allegedly affected by a data exposure after a threat actor published what they claim is a database containing approximately 1.94 million records. ⠀ The sample published with the listing appears to include: ⠀ • Full names • Email addresses • Userna
🚨🇺🇸 Vercel employee dataset allegedly offered for sale on a cybercrime forum, 800+ records claimed ⠀ Vercel, a US-based cloud platform used to build and deploy web applications, is allegedly affected by a data exposure after a threat actor advertised what they claim is an updated employee database containing more than 800 records. ⠀ The advertised data includes: ⠀ • Employee email addresses • D
🚨🇺🇸 Mercor dataset and source code allegedly offered for sale on a cybercrime forum by LAPSUS$ Group, 4TB claimed ⠀ Mercor, an AI-powered recruiting and hiring platform, is allegedly affected by a breach after a threat actor operating under the LAPSUS$ Group name advertised what they claim is approximately 4 TB of company data and source code. ⠀ The advertised material includes: ⠀ • Company dat
🚨🇭🇺 Complexpress Logisztika dataset allegedly offered for sale on a cybercrime forum, 1M+ records claimed X: Sorbinfo ⠀ Complexpress Logisztika Kft., a Hungarian logistics and e-commerce fulfillment provider, is allegedly affected by a data exposure after a threat actor advertised a 3.8 GB CSV dataset containing shipment and customer information. ⠀ The actor claims the dataset contains approxim
Alleged Australian TeamPCP members nabbed following joint probe by the AFP, WAPOL and FBI: '... large-scale cybercrime offending, including data intrusion, identity crime, and cryptocurrency-based money laundering. '... allegedly inserted malicious code into software available on an open-source repository ... '... distributed into computer systems at other organisations across government, academia