2026 Ukraine SMIDA (smida.gov.ua) — underground claims of ~327k administrative panel credentials (May)
Data compromised
Usernames, emails, passwords or session tokens per actor marketing summaries—authenticity and freshness disputed
Technical writeup
OSINT channels in May 2026 (including DailyDarkWeb‑style summaries circulating on X/Telegram) advertised a credential-oriented dump allegedly tied to `smida.gov.ua`, Ukraine’s SMIDA / ARIFRU securities-disclosure portal ecosystem, with marketing language on the order of ~327 000 panel login rows (usernames, emails, password or token material in criminal copy). SMIDA’s public site describes the agency as Ukraine’s stock market infrastructure development information hub. BreachHistory records the row as forum/reseller-claimed; ARIFRU had not issued a detailed corroborating bulletin in indexed English/Ukrainian summaries at catalog time, and the dump may overlap historical stealer composites—treat categorical exposure as pending attestation.
Root cause
Undetermined; alleged credential compromise or collection from administrative interfaces per underground marketing