On August 12, 2026, the cybersecurity platform VECERT Analyzer issued a preventive alert regarding a series of unconfirmed reports of data breaches, unauthorized access, and global information exposure. According to a post on X (formerly Twitter) by the account @VECERTRadar, the incidents were detected on forums and channels of the dark web, where threat actors appear to be offering databases and system access across various sectors.
The alert, marked as "UNCONFIRMED", includes a list of incidents spanning governments, companies, educational institutions, and financial services in countries such as Peru, Bolivia, Nigeria, France, Denmark, the Netherlands, Colombia, South Korea, the United States, Jordan, Spain, Italy, Brazil, Mexico, and others. Below are the most notable cases.
Reported Incidents by Sector
Government and Public Infrastructure
- cultura.gob.pe (Peru): Actor Jinx5 posted about the institutional portal of the Ministry of Culture.
- Bolivia Judicial: Alleged data exposure attributed to actor konata_izumi_shell.
- Access to Nigerian government sites: Actor BigBrother offers to sell administrative access to government websites.
- 138k Government Boundaries (Global): A geographic or governmental database exposed by exfilar.
- impots.gouv.fr (France): Alleged tax database with 678,000 records, attributed to actor ZeroBytes.
Corporate, Healthcare, and Industrial Sector
- Novo Nordisk (Denmark): Publication of the second phase of exfiltration by FulcrumSec.
- Fagron Tech (Netherlands): Exposure of internal tools totaling 16GB by actor lyuboy.
- Net2phone (Colombia): Record attributed to actors PescobarLegado and Petro_Escobar.
- NAMYANG Industrial Co. Ltd. (South Korea): Industrial data offered by actor BRKD.
Education and Fintech
- Gladiolos Education Spain (Spain): Educational records published by LosChalacos.
- Al-Isra' University (Jordan): Academic data exposure attributed to imostafaa6.
- National Money Mart Company (USA): Data exposed by actor V0idix.
Preventive Technical Recommendations
VECERT Analyzer, through its intelligence console, suggests that security operations centers (SOCs) and system administrators take the following steps:
- Independent verification of samples: Analyze the test files published by actors before classifying an incident as confirmed.
- Preventive credential rotation: Force password and access token changes for personnel with accounts in affected domains.
- Review of logs and perimeter connections: Monitor access records to administrative panels and internal tools associated with the listed assets.
The alert emphasizes that all information is preliminary and that the real impact, authenticity of samples, and integrity of exposed databases are still under investigation. Users and organizations are advised to stay tuned for official updates and strengthen their security measures.
For more details, you can consult VECERT's monitoring system at analyzer.vecert.io and the console at monitor.vecert.io.
Source: VECERT Analyzer (@VECERTRadar) on X, August 12, 2026.