2026 UPC (Peru) — student DB (upc_alumnos) forum leak; ~13.5k records (Apr)
Data compromised
Student identity and contact fields per OSINT summaries
Technical writeup
In April 2026, OSINT and dark-web monitoring accounts described a free forum dump attributed to persona “p2wnz” (BontenSec) allegedly sourced from Universidad Peruana de Ciencias Aplicadas (UPC) student systems, with roundups citing on the order of 13,489 rows and fields such as full names, student IDs, personal and institutional email addresses, and phone numbers. Specialist newsletters (e.g., Security Check-in quick hits) echoed the forum narrative. University or regulator confirmation should be read alongside criminal-forum provenance.
Root cause
Unauthorized exposure / forum distribution (method under investigation)