Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Brazil Fiscal Leak, US Fullz, Telecom Access, Endesa IBANs, and Mexico Fortinet Access
Aug 10, 2026
5 Mins Read
Moon
Summarize with:

Brazil Fiscal Leak, US Fullz, Telecom Access, Endesa IBANs, and Mexico Fortinet Access

SOCRadar Dark Web Team identified several new underground posts involving alleged large-scale data exposure and initial access sales. The findings include an alleged leak of 72 million Brazilian fiscal records, a claimed 1 million record U.S. Fullz dataset, unauthorized access to a major Asian telecom provider, an alleged Endesa Spain IBAN database, and Fortinet-related access to a large Mexican network.

Receive a Free Dark Web Report for Your Organization:

Alleged Brazil Fiscal Data Leak is Detected

brazil fiscal data leak 72 million records threat actor vaciarla

SOCRadar Dark Web Team detected a threat actor post claiming to leak 72 million Brazilian fiscal records. The post was published by an actor using the alias “vaciarla,” allegedly in collaboration with another user, and the data was distributed through a third-party file-sharing service.

The exact source and full contents of the dataset remain unconfirmed, but the claim points to sensitive fiscal information tied to Brazilian individuals. If authentic, this kind of exposure could increase the risk of identity theft, financial fraud, and targeted phishing campaigns, especially if the records include personal identifiers or tax-related data.

Alleged U.S. Fullz Database Sale is Detected

us fullz database sale 1 million loan records personal information

SOCRadar Dark Web Team detected a post advertising 1 million U.S. Fullz records, allegedly sourced from loan requests. The seller claimed the dataset contains verified personal information belonging to individuals across the United States, including full names, addresses, emails, phone numbers, SSNs, dates of birth, driver’s license details, employment information, and bank details.

The combination of identity, employment, and financial information makes this dataset especially dangerous if authentic. Attackers could use it for identity theft, unauthorized financial transactions, payroll fraud, or targeted social engineering attempts that appear credible because they reference real loan, income, or employer-related details.

Alleged Telecom Access in Asia is Detected

asia telecom access unnamed provider ssh vpn credentials

SOCRadar Dark Web Team detected an initial access listing advertising unauthorized access to an unnamed top 10 telecommunications provider in Asia. The actor claimed the target is a publicly traded company with around $4 billion in annual revenue and offered access involving SSH, corporate VPN, and load balancer credentials.

The listing priced the access at $500, which is unusually low for the claimed scale and may raise questions about the validity or persistence of the access. However, if the claim is accurate, access to VPN, SSH, and load balancer infrastructure could support lateral movement, data exfiltration, service disruption, or follow-on ransomware activity.

Alleged Endesa Spain IBAN Database Sale is Detected

endesa spain iban database 20 million records spartanx sale

SOCRadar Dark Web Team detected a post advertising an alleged Endesa Spain IBAN database containing more than 20 million records. The seller, identified as “SpartanX,” listed the dataset for $9,000 and claimed to provide a 10,000-record sample file through a third-party hosting service.

If the dataset is authentic, the exposure of IBANs could create financial fraud risks for affected customers. Banking identifiers may be abused in phishing, fraudulent billing attempts, or unauthorized direct debit schemes, making this claim particularly sensitive for utility customers and financial institutions handling related transactions.

Alleged Fortinet-Based Access in Mexico is Detected

fortinet access mexico 10000 hosts food retail manufacturing

SOCRadar Dark Web Team detected an initial access broker post auctioning alleged access to a large network in Mexico. The listing claimed more than 10,000 hosts across Food & Beverage, Retail, and Manufacturing sectors, with the actor stating that the access was related to a Fortinet product.

The auction started at $5,000, with a $500 step and a $7,500 blitz price. Although the claim remains unverified, Fortinet-related access is often attractive to threat actors because perimeter appliances can provide an entry point into corporate networks. If purchased and operationalized, the access could lead to data theft, ransomware deployment, or wider operational disruption.

Powered by DarkMirror™

Gaining visibility into deep and dark web threats can be extremely useful from an actionable threat intelligence and digital risk protection perspective. However, monitoring all sources is simply not feasible, which can be time-consuming and challenging. One click-by-mistake can result in malware bot infection. To tackle these challenges, SOCRadar’s DarkMirror™ screen empowers your SOC team to follow up with the latest posts of threat actors and groups filtered by the targeted country or industry.