← Blog

Kaya Iran Claim: DaOnlySpark 1.7M Leak Unverified

Share on X

Unverified claim. On 24 September 2026, Dark Web Informer reported that an actor posting as DaOnlySpark advertised a dump tied to Kaya (kaya.ir), an Iranian freelancing and project-services platform. The listing markets roughly 1.14 GB across 87 collections, totaling about 1,697,095 records, including roughly 50,649 user accounts, private chats, Iranian national ID material, bcrypt password hashes, and bank details such as IBAN/Sheba numbers. Kaya had not confirmed the intrusion at indexing. The dataset authenticity, counts, and full scope remain actor assertions — not company or regulator facts. Canonical BreachHistory row: https://breachhistory.com/kaya-iran/kaya-daonlyspark2026.

One line in the actor copy will travel farther than the rest: Kaya is described as a platform that connects Iranian professionals with international projects and that manages Freelancer.com accounts and bidding on clients’ behalf. That marketing sentence is not evidence that Freelancer.com itself was breached. Linked third-party account rows inside a local marketplace database — if real — would still be Kaya-side records. Do not collapse “Iranian freelancing broker named Freelancer.com in a leak post” into “Freelancer.com was hacked.”

Primary monitoring write-up for this claim: Dark Web Informer — Alleged Kaya Leak Includes 1.7 Million Records and Identity Data (24 September 2026). Everything below treats that article’s inventory as what the actor advertised, with DWI’s own caveat that samples do not prove possession of every advertised collection and that the hidden download was not accessed for verification.

What DaOnlySpark claimed on 24 September

According to the Dark Web Informer summary of the forum-style listing, DaOnlySpark named the organization as Kaya, tagged the country as Iran, and framed the sector as freelancing and project services. The post date shown on the listing is 24 September 2026. Download visibility was described as hidden until a reply is posted — a common gate that keeps outsiders from casually hashing the archive while still waving screenshots for pressure and prestige.

Actor-supplied scale language, as mirrored by DWI:

  • ~1.14 GB packaged across 87 collections
  • ~1,697,095 total records (unverified actor count)
  • ~50,649 user accounts
  • ~46,493 accounts with phone numbers
  • ~15,120 accounts with national ID numbers
  • ~784,081 private chat messages
  • ~173,997 freelance projects
  • ~3,468 project payment milestones
  • ~29,853 support tickets and ~71,327 ticket messages
  • ~16,432 identity-verification requests
  • ~16,428 linked Freelancer.com accounts (Kaya-side linkage claim — not a Freelancer.com compromise proof)
  • ~22,067 financial transactions and related payment/ledger subsets
  • Call-center / VoIP event tallies in the six-figure range in actor marketing

Field brags in the same post include full names, birth dates, gender, Iranian national IDs and identity-document images, bank account details including IBAN/Sheba, bcrypt password hashes, private messages, and customer caller numbers. A financial breakdown also lists thousands of Zarinpal payment records, user payments, withdrawal requests, invoices, ledger postings, and bank-account rows. No asking price appears in the materials DWI summarized; a Monero address in the signature is framed as a donation address rather than a classic ransom invoice.

Two screenshots accompany the claim: one showing inventory tallies and an identity-verification sample, another continuing the sample, a user sample (including an is_admin flag), a hidden download area, and actor contact details. DWI is careful here — and readers should be too. An is_admin boolean in a stolen user table does not prove the thief still has live admin sessions. A verification sample that references an identity-document file is not the same as publishing the document image. A registration or verification timestamp is not a breach date.

What we know vs what we do not

Supported as public reporting of a claim: DaOnlySpark named Kaya / kaya.ir; DWI published on 24 September 2026; the actor marketed ~1.7M records across 87 collections and ~50.6k accounts; advertised categories include national ID material, chats, bcrypt hashes, and IBAN/Sheba-style banking fields; download was gated; no company confirmation appears in the monitoring piece.

Not supported at indexing: Kaya confirmation; Iranian regulator attestation with a census; independent lab proof that the 1.14 GB archive is authentic production data; proof that every one of the 87 collections exists as advertised; cracking or reuse of the bcrypt hashes; compromise of Freelancer.com’s own infrastructure; a published ransom demand with a price.

Initial access is likewise unknown. The listing maps, in MITRE language DWI reproduces, to a claimed database collection story — not to a named VPN appliance, SSO bug, or upload RCE. Inventing “they phished a Kaya admin” or “Mongo was open to the internet” would be fiction. The only access narrative on the public record is the actor’s own: we breached Kaya and we have the collections.

To be clear: a gated download plus two screenshots can be a real theft, a partial sample, recycled data from another Iranian marketplace, or theater. Until Kaya or an independent investigator with primary access attests, the responsible framing is an unverified Kaya data breach claim — not “Kaya confirmed a 1.7 million record leak.”

Why ~1.7 million records is not ~1.7 million people

Extortion and leak posts love a single big integer. 1,697,095 sounds like a national-scale identity dump. Read the fine print the actor accidentally provided: that total spans 87 collections — chats, tickets, VoIP events, projects, payments, reviews, portfolios, call-center rows, and accounts. One person can appear in dozens of tables. One chat thread can explode into thousands of message rows. Treating 1.7 million as unique Iranian freelancers would invent precision the listing does not earn.

The sharper person-scale figure in the same post is the ~50,649 user accounts claim — still unverified, still not a company census, but closer to an “accounts” unit than a kitchen-sink row sum. Even that number is not “50,649 unique national IDs.” The actor separately cites ~15,120 accounts with national ID numbers and ~16,432 identity-verification requests. Those subsets matter more for identity-fraud risk modeling than the headline 1.7M.

BreachHistory carries the best available actor/reporter count for cataloging while labeling it unverified in prose. Readers searching “Kaya data breach 1.7 million” should remember the unit problem every time a social post truncates “records across 87 collections” into “1.7 million Iranians exposed.”

What was allegedly exposed — and what that would mean if true

If authentic, the advertised mix is ugly in the way marketplace platforms usually are: identity KYC, messaging, support history, and money movement sitting in one operational brain.

Identity and KYC

Iranian national ID numbers, birth dates, gender, and claimed identity-document images are classic fuel for impersonation, SIM-swap social engineering, and government-adjacent fraud workflows. Even without document images in the public screenshots, the mere claim that verification requests and national IDs are in the package raises the stakes above a simple email dump.

Credentials

Bcrypt password hashes are not plaintext passwords. They are still dangerous. Offline cracking, password reuse against email or banking, and credential stuffing against Kaya itself or sibling freelancing tools are the usual follow-ons. Hashes in a screenshot table of contents do not prove the hashes are complete, salted as claimed, or crackable at useful speed — but defenders should assume reuse risk the moment a marketplace with KYC is named.

Chats, tickets, and projects

~784k private messages plus support tickets and freelance project records — if real — expose business relationships, negotiation language, dispute history, and sometimes payment expectations. That material is gold for spear-phishing: “about your unfinished milestone on project X” lands harder than a generic breach SMS.

Banking and payments

IBAN/Sheba numbers, Zarinpal payment records, withdrawals, invoices, and ledger postings would support financial profiling and targeted payment-redirection scams. Iranian Sheba identifiers are not credit-card PANs, but they are enough to make fake “update your payout account after the Kaya leak” lures look informed.

Telephony metadata

Actor marketing of call-center records, VoIP events, and phone calls — if authentic — adds another harassment and vishing surface: numbers tied to support interactions, not just marketing SMS lists.

What the public samples do not establish: live admin control of Kaya today, Freelancer.com core compromise, or that every collection listed actually ships in the gated archive.

Freelancer.com: linked accounts are not a Freelancer breach

This deserves its own section because search traffic will mash the brands together.

Kaya’s public positioning, as restated in the actor/DWI materials, is that of an Iranian freelancing intermediary that helps professionals work international gigs and may manage Freelancer.com accounts and bidding on their behalf. The leak listing then cites roughly 16,428 linked Freelancer.com accounts inside the purported Kaya dataset.

That claim — even if every row were real — would mean Kaya stored pointers, credentials, or profile metadata for Freelancer.com accounts belonging to its users. It would not by itself mean attackers walked Freelancer.com’s production estate, dumped Freelancer.com’s global user base, or bypassed Freelancer.com’s authentication. Third-party “we manage your Freelancer profile” tooling is a classic place where OAuth tokens, stored passwords, or scraped profile mirrors accumulate on the broker.

If you are a Freelancer.com user with no Kaya relationship, this listing is not evidence you are in scope. If you used Kaya as a broker into Freelancer.com, your risk surface — if the claim were later confirmed — would be Kaya-held copies of whatever that broker stored, plus the usual phishing that will name Freelancer.com anyway. Distinct systems. Distinct evidence bars.

Journalists and Discord amplifiers who title posts “Freelancer.com breached via Iran” from this listing alone are doing the attacker’s marketing for free.

Who might be at risk if the claim were true

Until confirmation, treat the audiences below as hypothetical risk groups suggested by Kaya’s business model and by the actor’s field list — not as confirmed victims.

Kaya account holders in Iran

Freelancers, clients, and anyone who completed KYC on kaya.ir are the core audience the listing tries to scare. Elevated practical risk today means phishing and fake “re-verify your national ID” portals, not a proven public dump of your Sheba number.

People who completed identity verification

The ~16k verification-request claim is the sharpest identity-fraud signal. Anyone who uploaded national ID images to a freelancing marketplace should watch for impersonation that cites verification timestamps or document filenames — accuracy of a filename does not prove the caller is Kaya support.

Users with linked international freelancing profiles

If you asked Kaya to manage bidding on Freelancer.com or similar platforms, assume brokers may have stored more than a public profile URL. Rotate passwords on those international accounts if you reused them on Kaya; enable MFA; treat “we need your Freelancer password to secure your Kaya escrow” messages as hostile.

Clients who messaged freelancers on-platform

Private chat and project records cut both ways. Clients who negotiated rates, shared personal emails, or pasted temporary credentials into chat are in the phishing audience even when they never completed KYC themselves.

Support and call-center staff

Internal ticket systems and VoIP metadata, if stolen, help attackers impersonate staff to users and users to staff. Out-of-band verification beats trusting a callback number that appears in a “leaked” ticket thread.

Industry context: marketplace KYC dumps in 2026

Freelance marketplaces, classifieds, and “we’ll get you paid abroad” brokers concentrate exactly the data criminals want: government ID, selfies, payout rails, and chat logs that prove commercial relationships. 2026 leak trackers are crowded with unverified marketplace and fintech-adjacent claims that wave collection counts and bcrypt tables. Many never graduate to a company notice. Some do — and when they do, the useful artifacts are field lists and date ranges, not forum screenshots.

Iranian platforms sit in a harder information environment for outside researchers: English-language company blogs are thinner, regulator portals are less mirrored in Western trade press, and victims may stay quiet longer. That opacity cuts both ways. It makes unverified claims easier to inflate, and it makes confirmed incidents slower to reach global indexes. BreachHistory’s job is not to fill the silence with certainty. It is to catalog the named claim, keep the unverified label honest, and update if Kaya later confirms or denies with substance.

Compare the evidence bar to better-attested marketplace and consumer incidents elsewhere in this catalog — cases with company notices, regulator filings, or Have I Been Pwned loads. Those later artifacts are what turn rumor into verified rows. The Kaya DaOnlySpark story is earlier on that curve: named victim, actor inventory, DWI documentation, no company letter.

What Kaya and regulators have said

As of this article’s indexing timestamp, public materials reviewed for the catalog row did not include a Kaya customer notice, status-page attestation, or Iranian regulator filing that confirms DaOnlySpark’s dump. Dark Web Informer states explicitly that it has not independently verified the alleged breach, dataset authenticity, completeness, counts, or actor attribution, and that the hidden download was not accessed.

Silence is not proof of innocence and not proof of guilt. Platforms sometimes investigate for days before speaking. Until they speak — or a regulator files with substance — the Kaya claim remains an unverified leak-site / forum dump claim.

Ignore secondary blogs that quietly drop the word “alleged” and rewrite DWI’s inventory as confirmed fact. Amplification is not confirmation. Prefer primary Kaya language if it appears, plus reputable monitors that keep the caveat visible.

Timeline readers can use

  • 24 September 2026: DaOnlySpark listing observed / summarized — Kaya (kaya.ir), Iran, ~1.14 GB, ~1.7M records across 87 collections, ~50.6k accounts; national IDs, chats, bcrypt, IBAN/Sheba claimed; download gated.
  • 24 September 2026: Dark Web Informer publishes the monitoring article, labeling status unverified and noting Freelancer.com linkage does not establish a Freelancer.com compromise.
  • 27 September 2026: This BreachHistory blog indexes the claim as unverified with canonical path /kaya-iran/kaya-daonlyspark2026.

If later reporting adds a company FAQ, a denial with forensic detail, or a regulator census, those dates should be appended — not backfilled into the September 24 claim as if confirmation already existed.

Was I affected by a Kaya data breach?

Short answer: there is no attested Kaya census tied to this DaOnlySpark listing. You cannot truthfully say you were “in the dump” from the tracker article alone.

Steps that still make sense:

  1. Bookmark official Kaya help and privacy channels you already trust — before a panic search leads you to a lookalike domain collecting national ID uploads.
  2. Ignore third-party “breach check” sites that ask for your full Iranian national ID, Sheba number, or Freelancer.com password to “see if you are in the 1.7M.”
  3. If you later receive a message that claims to be from Kaya describing categories of data, verify the domain and any phone numbers against the official site before responding.
  4. Remember the unit mismatch: ~1.7M records ≠ ~1.7M unique people; ~50.6k accounts is still an unverified actor figure.
  5. If you never used Kaya, Freelancer.com headlines riding this story are almost certainly noise for you unless a separate Freelancer.com notice appears — which this listing does not provide.

Phishing and scam patterns to expect

Attackers do not need a real archive to cash a headline. Expect themes like:

  • “Kaya Security: re-upload your national ID after the DaOnlySpark leak — verify here.”
  • “Your Sheba payout is frozen after the 1.7M breach — enter IBAN to restore withdrawals.”
  • “Freelancer.com password reset required because Kaya was breached” (especially nasty, and still not proof Freelancer.com was hit).
  • “Pay a small Monero fee to remove your chat logs from the dump.”
  • Support vishing that reads back a real project title or ticket ID dredged from public samples or recycled old data.
  • Fake bcrypt “hash lookup” tools that steal the password you type to “test if you were cracked.”

Legitimate remediation, if it ever comes, will not ask you to wire cryptocurrency to a stranger, dictate one-time codes over the phone, or paste a Freelancer.com password into a random form. It will point to named instructions on domains you can verify.

What you should do

  1. Wait for official Kaya notices before assuming your national ID image or Sheba details left the company. Treat the September 24 listing as unverified actor marketing.
  2. If you have a Kaya account: change the password to something unique; enable any available MFA; do not reuse that password on email or banking.
  3. If you reused the Kaya password on Freelancer.com or other freelancing sites: rotate those passwords now — as hygiene, not as proof those sites were breached.
  4. KYC users: be extremely skeptical of any “re-verify identity” email or Telegram message citing DaOnlySpark or “87 collections.”
  5. Watch banking SMS and apps for unexpected payout changes or new beneficiary additions; confirm out of band with your bank if something looks wrong.
  6. Clients and freelancers with on-platform chat history: expect spear-phishing that quotes old milestones; verify payment changes by phone numbers you already trust.
  7. Do not download alleged Kaya proof packs from forums or Telegram — archives are often malware or unrelated recycled dumps.
  8. Do not pay anyone offering to “remove your row” from an unverified leak.
  9. Security teams: use the claim as a hunting trigger for unusual database exports and KYC-document store access — not as automatic evidence of a specific CVE at Kaya.
  10. Journalists: quote DaOnlySpark as an alleged listing; keep Freelancer.com out of the headline unless Freelancer.com confirms something separately.

None of those steps require you to believe the dump is real. They are the same hygiene you would apply after any high-profile marketplace leak rumor: slow down, verify out of band, and do not let the attacker set the narrative.

How to read actor IOCs without over-crediting them

DWI’s materials note identifiers visible in screenshots: the handle DaOnlySpark, domain kaya.ir, a Telegram handle, a Session ID, and a Monero donation address. Those strings help correlating future posts by the same brand. They do not independently prove control of Kaya’s databases, authenticity of the 1.14 GB archive, or that the Monero address belongs to the person who actually ran an intrusion. Domain mention identifies the named organization. It is not malware infrastructure.

Mapped ATT&CK techniques in the monitoring piece are labeled claimed or inferred for analytical convenience. They are not a forensic report from Kaya’s IR firm.

Canonical record and sources

BreachHistory indexes this incident as an unverified DaOnlySpark leak claim against Kaya (Iran / kaya.ir), observed via Dark Web Informer on 24 September 2026, marketing ~1.7 million records across 87 collections and ~50.6k accounts, with advertised national IDs, private chats, bcrypt hashes, and IBAN/Sheba-related financial fields. The listing’s Freelancer.com account-linkage language does not prove a Freelancer.com breach. Full catalog entry: https://breachhistory.com/kaya-iran/kaya-daonlyspark2026.

Primary open source for the claim language: Dark Web Informer — Alleged Kaya Leak Includes 1.7 Million Records and Identity Data.

Search intent covered in plain language includes Kaya data breach, Kaya Iran leak 2026, DaOnlySpark Kaya, kaya.ir breach claim, 1.7 million records unverified, 50,649 accounts, Iranian national ID freelancing leak, bcrypt marketplace dump, IBAN Sheba exposure claim, was I affected, what to do after, and why this does not equal a Freelancer.com compromise.

Bottom line: Unverified claim — DaOnlySpark advertised a large Kaya (kaya.ir) dataset on or about 24 September 2026; Dark Web Informer documented the listing with clear unverified status; Kaya had not confirmed; Freelancer.com was not shown to be breached. Harden phishing defenses if you used Kaya. Wait for primary confirmation before treating the inventory as fact.