Cybercrime forum reports multiple data breaches

Between 5–7 September 2026, infosec researchers reported multiple alleged data leaks on cybercrime forums: French social housing cooperative La Maison Pour Tous (8,000 records), Atout France tourism agency (10,000 records), Argentine hospitals Hospital Alemán and OSDEPYM, Brazilian municipality Rincão, plus sales of Ledger/Trezor cryptocurrency theft toolkits and ExEngine AV/EDR malware. As of 7 September, these remained unconfirmed allegations.

18 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

🚨🇫🇷 La Maison Pour Tous tenant dataset allegedly leaked on a cybercrime forum, 8K records claimed ⠀ La Maison Pour Tous, a French social housing cooperative, is named in a cybercrime forum post whe

mastodon:infosec-exchangeother24d ago kagi ↗

🚨🇫🇷 La Maison Pour Tous tenant dataset allegedly leaked on a cybercrime forum, 8K records claimed ⠀ La Maison Pour Tous, a French social housing cooperative, is named in a cybercrime forum post where a threat actor claims to have leaked a dataset containing information tied to approximately 8,000 tenants. ⠀ The advertised data includes: ⠀ • Tenant names • Associated record identifiers ⠀ The act

🚨🇫🇷 Atout France user dataset allegedly leaked on a cybercrime forum, 10K records claimed ⠀ Atout France, France’s national tourism development agency, is named in a cybercrime forum post where a t

mastodon:infosec-exchangeother24d ago kagi ↗

🚨🇫🇷 Atout France user dataset allegedly leaked on a cybercrime forum, 10K records claimed ⠀ Atout France, France’s national tourism development agency, is named in a cybercrime forum post where a threat actor claims to have exploited a vulnerability and scraped approximately 10,000 user records. ⠀ The advertised data includes: ⠀ • Full names • Email addresses and login information • Phone numbe

🚨 Ledger + Trezor cryptocurrency theft toolkit allegedly offered for sale on a cybercrime forum ⠀ A threat actor is advertising what they describe as an “unleaked” Ledger and Trezor exploit toolkit,

mastodon:infosec-exchangeother24d ago kagi ↗

🚨 Ledger + Trezor cryptocurrency theft toolkit allegedly offered for sale on a cybercrime forum ⠀ A threat actor is advertising what they describe as an “unleaked” Ledger and Trezor exploit toolkit, claiming it can be used to trick cryptocurrency wallet users into authorizing malicious transactions. ⠀ The advertised capabilities include: ⠀ • Support for Ledger and Trezor devices • Custom cryptocu

🚨🇺🇸 Spirit Cultural Exchange allegedly breached, 170 GB of data claimed Spirit Cultural Exchange, a U.S.-based provider of international cultural exchange and J-1 visa programs, has been named in a

mastodon:infosec-exchangeother24d ago kagi ↗

🚨🇺🇸 Spirit Cultural Exchange allegedly breached, 170 GB of data claimed Spirit Cultural Exchange, a U.S.-based provider of international cultural exchange and J-1 visa programs, has been named in an extortion post on a cybercrime forum. Claimed exposure • 170 GB of data • 136,817 files • Passport files and face images • Employment verification documents • Degree diplomas • Host school offers •

🚨🇮🇱 Yehud-Monosson Municipality allegedly breached, 836K+ rows of data claimed Yehud-Monosson Municipality, a local government authority in Israel, is named in a cybercrime forum post where a threa

mastodon:infosec-exchangeother24d ago kagi ↗

🚨🇮🇱 Yehud-Monosson Municipality allegedly breached, 836K+ rows of data claimed Yehud-Monosson Municipality, a local government authority in Israel, is named in a cybercrime forum post where a threat actor claims to have obtained a full MariaDB dump from the municipality’s Social Welfare Office systems. Claimed exposure • 135 MB of data • 114 database tables • 836,672 rows • 16 staff accounts wi

🚨🇪🇸 Spain SIPS energy supply dataset allegedly leaked, 40M+ CUPS records claimed ⠀ SIPS (Sistema de Información de Puntos de Suministro), Spain’s electricity and gas supply-point information system

mastodon:infosec-exchangeother23d ago kagi ↗

🚨🇪🇸 Spain SIPS energy supply dataset allegedly leaked, 40M+ CUPS records claimed ⠀ SIPS (Sistema de Información de Puntos de Suministro), Spain’s electricity and gas supply-point information system, is named in a cybercrime forum post where a threat actor claims to have obtained a full dataset covering more than 40 million CUPS records. ⠀ Claimed exposure ⠀ • Customer names and NIF/CIF identifi

🚨🇲🇽 Querétaro State Civil Protection Coordination allegedly breached, user dataset leaked ⠀ Coordinación Estatal de Protección Civil de Querétaro (CEPCQ), the state agency responsible for civil pro

mastodon:infosec-exchangeother23d ago kagi ↗

🚨🇲🇽 Querétaro State Civil Protection Coordination allegedly breached, user dataset leaked ⠀ Coordinación Estatal de Protección Civil de Querétaro (CEPCQ), the state agency responsible for civil protection in Querétaro, Mexico, is named in a cybercrime forum post where a threat actor claims to have obtained the full user dataset from its online procedures platform. ⠀ Claimed exposure ⠀ • Full na

🚨🇨🇦 Bitbuy super-admin support portal access allegedly offered for sale on a cybercrime forum ⠀ Bitbuy, a Canadian cryptocurrency trading platform, is named in a cybercrime forum post where a threa

mastodon:infosec-exchangeother23d ago kagi ↗

🚨🇨🇦 Bitbuy super-admin support portal access allegedly offered for sale on a cybercrime forum ⠀ Bitbuy, a Canadian cryptocurrency trading platform, is named in a cybercrime forum post where a threat actor claims to have access to an internal super-admin/support portal and is offering the access for sale. ⠀ Claimed exposure ⠀ • User IDs and email addresses • Account risk scores • Investigation s

🚨🇧🇷 Central dos Benefícios dataset allegedly offered for sale, 2.7M+ people claimed ⠀ Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named i

mastodon:infosec-exchangeother23d ago kagi ↗

🚨🇧🇷 Central dos Benefícios dataset allegedly offered for sale, 2.7M+ people claimed ⠀ Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named in a cybercrime forum post where a threat actor claims to be selling a 1 GB dataset containing millions of records. ⠀ Claimed exposure ⠀ • 2,734,282 people records • 2,086,659 payment card records • 78

🚨 Threat actor seeking to buy compromised cPanel, Plesk and WHM access on a cybercrime forum ⠀ A threat actor has posted a listing seeking to purchase cPanel, Plesk and WHM credentials obtained from

mastodon:infosec-exchangeother23d ago kagi ↗

🚨 Threat actor seeking to buy compromised cPanel, Plesk and WHM access on a cybercrime forum ⠀ A threat actor has posted a listing seeking to purchase cPanel, Plesk and WHM credentials obtained from stealer logs or other compromised sources. ⠀ Requested access ⠀ • cPanel, Plesk or WHM credentials • Valid username and password combinations • No 2FA enabled • Website must be operational • Access mu

🚨🇺🇸🇨🇦 195M identity records allegedly offered for sale on a cybercrime forum, including 153M+ driver’s license records from the recent Nexus onion DL market. ⠀ A threat actor is advertising what

mastodon:infosec-exchangeother23d ago kagi ↗

🚨🇺🇸🇨🇦 195M identity records allegedly offered for sale on a cybercrime forum, including 153M+ driver’s license records from the recent Nexus onion DL market. ⠀ A threat actor is advertising what they claim is a 195 million-record identity dataset containing information tied primarily to individuals in the United States and Canada. ⠀ Claimed exposure ⠀ • 153,347,439 driver’s license records •

🚨🇷🇺 Strezhevoy city portal allegedly breached, 54K+ user accounts exposed ⠀ The Strezhevoy city portal, serving the city of Strezhevoy in Russia’s Kemerovo Oblast (Kuzbass), is named in a cybercrim

mastodon:infosec-exchangeother23d ago kagi ↗

🚨🇷🇺 Strezhevoy city portal allegedly breached, 54K+ user accounts exposed ⠀ The Strezhevoy city portal, serving the city of Strezhevoy in Russia’s Kemerovo Oblast (Kuzbass), is named in a cybercrime forum post where a threat actor claims to have breached the site and obtained data from 13 database tables containing 450,516 rows. ⠀ Claimed exposure ⠀ • 54,404 chat accounts • 54,387 MD5 password

🚨🇫🇷 Service National Universel portal allegedly breached, 275K+ user records claimed ⠀ Service National Universel (SNU), a French government youth engagement program, is named in a cybercrime forum

mastodon:infosec-exchangeother23d ago kagi ↗

🚨🇫🇷 Service National Universel portal allegedly breached, 275K+ user records claimed ⠀ Service National Universel (SNU), a French government youth engagement program, is named in a cybercrime forum post where a threat actor claims to have exploited an IDOR vulnerability in one of its portals and scraped user information. ⠀ Claimed exposure ⠀ • 275,083 total user records • 270,021 general user I

🚨🇷🇸🇧🇬 PHOENIX Pharma Serbia & Bulgaria allegedly breached, 293 MB of internal B2B data claimed ⠀ PHOENIX Pharma Serbia & Bulgaria, part of Germany-based PHOENIX group, is named in a cybercrime fo

mastodon:infosec-exchangeother23d ago kagi ↗

🚨🇷🇸🇧🇬 PHOENIX Pharma Serbia & Bulgaria allegedly breached, 293 MB of internal B2B data claimed ⠀ PHOENIX Pharma Serbia & Bulgaria, part of Germany-based PHOENIX group, is named in a cybercrime forum post where a threat actor claims to have obtained internal business-to-business data from the pharmaceutical wholesaler and healthcare services company. ⠀ Claimed exposure ⠀ • Usernames • Pharmacy

🚨🇧🇷 Claro Brasil allegedly breached, 46M+ phone numbers linked to CPF claimed ⠀ Claro Brasil, one of Brazil’s largest telecommunications providers, is named in a cybercrime forum post where a threa

mastodon:infosec-exchangeother22d ago kagi ↗

🚨🇧🇷 Claro Brasil allegedly breached, 46M+ phone numbers linked to CPF claimed ⠀ Claro Brasil, one of Brazil’s largest telecommunications providers, is named in a cybercrime forum post where a threat actor claims to have compromised an exposed API and extracted 46,033,380 telephone numbers linked to Brazilian CPF identifiers. ⠀ Claimed exposure ⠀ • 46,033,380 phone numbers • CPF identifiers link

🚨🇦🇷 Hospital Alemán and OSDEPYM allegedly breached, sensitive medical and customer data leaked ⠀ Hospital Alemán and OSDEPYM, two Argentine healthcare organizations, are named in a cybercrime forum

mastodon:infosec-exchangeother22d ago kagi ↗

🚨🇦🇷 Hospital Alemán and OSDEPYM allegedly breached, sensitive medical and customer data leaked ⠀ Hospital Alemán and OSDEPYM, two Argentine healthcare organizations, are named in a cybercrime forum post where a threat actor claims negotiations failed and data belonging to both organizations is now being released. ⠀ Hospital Alemán claimed exposure ⠀ • Approximately 84,000 prescription records •

🚨🇧🇷 Municipality of Rincão allegedly compromised, administrative access claimed ⠀ Prefeitura Municipal de Rincão, the municipal government of Rincão in São Paulo, Brazil, is named in a cybercrime f

mastodon:infosec-exchangeother22d ago kagi ↗

🚨🇧🇷 Municipality of Rincão allegedly compromised, administrative access claimed ⠀ Prefeitura Municipal de Rincão, the municipal government of Rincão in São Paulo, Brazil, is named in a cybercrime forum post where a threat actor claims to have compromised multiple administrative accounts and gained access to internal government systems. ⠀ Claimed access ⠀ • Government administrative accounts • F

🚨 ExEngine AV/EDR killer advertised on a cybercrime forum, Ring-3 rootkit and UAC bypass claimed ⠀ ExEngine, a malware tool advertised as an AV/EDR killer for Windows systems, is being promoted on a

mastodon:infosec-exchangeother22d ago kagi ↗

🚨 ExEngine AV/EDR killer advertised on a cybercrime forum, Ring-3 rootkit and UAC bypass claimed ⠀ ExEngine, a malware tool advertised as an AV/EDR killer for Windows systems, is being promoted on a cybercrime forum with claims that it can disable mainstream consumer antivirus products and allow additional payloads to execute with reduced interference. ⠀ Advertised capabilities ⠀ • AV/EDR termina