Listen to this Post

A New Wave of Data Exposure
The cybersecurity landscape rarely gives people time to breathe. Just as organizations become more aware of ransomware, phishing, and credential theft, another danger continues to grow quietly in the background: the mass exposure of personal information.
Two reports circulating on August 11, 2026, highlight exactly why data security remains such a serious concern. One report says a threat actor known as Actor exfilar is offering a 110 GB dataset allegedly connected to Cuba’s Gran Caribe Hotel Group. The reported material supposedly contains 26,094 guest passport records, employee information, and access to corporate systems across eight properties.
A separate report alleges that a HerbaSis database has been leaked, potentially exposing Brazilian customers’ names, dates of birth, addresses, telephone numbers, email addresses, CPF numbers, and information relating to medical conditions.
The two incidents are very different in nature, but they share the same uncomfortable lesson: organizations can collect enormous quantities of sensitive information, while attackers only need one successful path into the environment to turn that data into a weapon.
The Gran Caribe Dataset Report
According to the cybersecurity post supplied for this report, Actor exfilar is allegedly offering a 110 GB dump associated with Gran Caribe Hotel Group.
The reported dataset is said to contain 26,094 guest passport records, employee files, and broader corporate-system information connected to eight Cuban properties.
Gran Caribe is a real Cuban hotel group operating multiple properties. Its official website confirms that guests are required to present valid passports during check-in, making identity-document information an important part of the group’s operational data environment.
That does not independently confirm that the advertised 110 GB dataset is genuine. It does, however, demonstrate why a compromise involving hotel infrastructure could become extremely sensitive.
Why Passport Records Are So Dangerous
A passport record is not simply another database entry.
It can contain highly valuable identity information that can potentially be combined with names, dates of birth, nationality information, reservation details, and other personal identifiers.
When such information appears alongside employee records and internal corporate data, the potential consequences become considerably more serious.
Attackers can potentially use stolen identity information for impersonation attempts, targeted phishing, fraudulent account creation, social engineering, and other forms of identity abuse.
The danger is therefore not limited to the hotel itself. The people represented inside the database can remain exposed long after the original intrusion has ended.
The 26,094-Record Figure
The reported figure of 26,094 passport records deserves particular attention.
Large numbers often make headlines, but the more important question is what each record contains.
A database with 26,094 minimal records could be less dangerous than a database with 2,000 exceptionally detailed identity profiles.
If the reported dataset contains passport-related information combined with booking history, contact information, payment-related metadata, or internal identifiers, its intelligence value could be significantly higher.
This is why breach investigations should focus on data sensitivity and relationships between datasets, rather than simply counting rows.
Eight Properties Raise the Stakes
The report also states that information from eight Gran Caribe properties is included.
If accurate, this could indicate that the incident was not limited to one isolated hotel network.
A multi-property compromise can point toward shared infrastructure, centralized management systems, common credentials, centralized databases, remote administration, or a broader corporate environment.
Gran
A weakness in a shared system can sometimes create consequences across multiple locations.
The Most Serious Part of the Allegation
The most concerning element is not necessarily the passport records.
The supplied report says the actor is offering full corporate systems in addition to personal information.
If independently verified, access to internal systems could provide attackers with considerably more opportunities than a simple database leak.
Corporate systems can contain authentication infrastructure, employee accounts, administrative tools, network information, business documents, application credentials, backups, and other sensitive resources.
The difference between stealing a database and obtaining persistent access to an organization can be enormous.
The HerbaSis Database Report
The second cybersecurity report concerns HerbaSis and is potentially even more sensitive from a privacy perspective.
The supplied report alleges that a HerbaSis database was leaked containing Brazilian customer information, including medical conditions, CPF numbers, names, dates of birth, addresses, telephone numbers, and email addresses.
HerbaSis identifies itself as a management system for consultants and describes functions including customer management, purchase history, sales, appointments, customer records, and wellness-related assessments. Its public registration interface also requests personal information such as name, date of birth, CPF, address, telephone number, and email.
This makes the reported categories of exposed information particularly important.
Sensitive Data Creates a Different Kind of Risk
A leaked email address can lead to spam and phishing.
A leaked CPF can contribute to identity fraud.
A leaked medical condition can create something much more personal: fear, embarrassment, discrimination, targeted manipulation, or long-term privacy consequences.
Health-related information is among the most sensitive categories of personal data because it can reveal details that people never intended to become public.
When health information is combined with government identifiers and contact information, the potential impact becomes substantially greater.
CPF Numbers Are High-Value Identifiers
Brazil’s CPF is a central personal identifier used in many financial and administrative contexts.
That makes a database containing CPF numbers especially attractive to criminals.
A threat actor does not necessarily need to publish every field publicly to cause damage. Even a private sale to another criminal group could turn the information into a valuable intelligence package.
The combination of CPF, full name, date of birth, address, phone number, and email can provide a powerful foundation for social engineering.
HerbaSis Appears to Handle Extensive Customer Data
The public HerbaSis website describes a platform capable of managing customer records, purchasing information, appointments, sales, indications, and wellness assessments.
That matters because an application does not need to be a hospital to become a valuable source of health-related information.
Modern wellness and customer-management platforms can accumulate surprisingly detailed personal profiles.
The security requirement therefore needs to match the sensitivity of the information being processed, not merely the industry’s traditional classification.
The Human Cost of a Data Leak
Cybersecurity reports often describe breaches in terms of gigabytes, databases, records, and systems.
People experience them differently.
For the individual, the incident can mean discovering that someone else may possess their identity information.
It can mean suspicious emails.
Unexpected phone calls.
Fraud attempts.
Fake customer-service messages.
Threatening communications.
Or simply the uncertainty of not knowing what information has escaped.
Behind every database row is a person who may have no idea that their information is circulating.
From Breach to Phishing Campaign
One of the most predictable consequences of large data leaks is targeted phishing.
Suppose an attacker has a
A generic phishing email can then become a highly convincing message about a reservation, travel document, account verification, or payment problem.
The victim may trust the message precisely because the attacker already knows details that appear private.
The same principle applies to HerbaSis customers.
An attacker who knows
Data Does Not Need to Be Public to Be Dangerous
There is a common misconception that a breach only becomes serious when stolen information is published openly.
That is not true.
Data can be sold privately.
It can be exchanged between criminal groups.
It can be used for targeted attacks.
It can be stored for later exploitation.
It can also be combined with information obtained from completely different breaches.
This is why cybersecurity teams should treat confirmed unauthorized access as a serious incident even before stolen information appears on a public forum.
The Bigger Problem: Data Aggregation
The modern cybercrime economy increasingly benefits from aggregation.
One breach may provide names.
Another may provide email addresses.
A third may provide phone numbers.
A fourth may reveal passwords.
A fifth may provide identity documents.
Criminals can combine these fragments into much richer profiles.
This means organizations cannot assume that a single exposed field is harmless simply because it appears elsewhere online.
The real threat comes from correlation.
What Undercode Say:
The Real Currency Is Identity
The cybersecurity industry often measures incidents by gigabytes and record counts.
Attackers increasingly measure them by usefulness.
A passport number can be more valuable than thousands of ordinary documents.
A CPF can be more valuable than a large collection of marketing emails.
A medical condition can provide leverage that an ordinary name cannot.
The real currency is therefore identity.
Hospitality Is a High-Value Target
Hotels naturally collect identity information.
Travelers provide passports.
Guests provide contact information.
Reservations create dates and locations.
Employees create internal accounts.
Corporate systems connect multiple properties.
This creates a dense concentration of valuable information.
Hospitality companies should therefore be treated as identity-rich environments rather than ordinary retail businesses.
Centralization Can Become a Weakness
Centralized systems simplify administration.
They also create attractive targets.
If multiple hotels depend on shared infrastructure, compromising that infrastructure could potentially provide access to multiple properties.
Segmentation becomes critical.
A hotel in Havana should not automatically provide a pathway into another property’s systems.
Administrative networks should be isolated from guest networks.
Guest Wi-Fi should never be treated as trusted infrastructure.
Identity Documents Require Special Protection
Passport information deserves stronger controls than ordinary customer preferences.
Organizations should minimize how long they retain identity documents.
They should encrypt sensitive fields.
Access should be logged.
Administrative access should require strong authentication.
Employees should only see information necessary for their jobs.
Old records should not remain indefinitely accessible simply because storage is inexpensive.
Medical Information Changes the Risk Calculation
HerbaSis demonstrates another important principle.
A wellness platform may appear less critical than a hospital.
Its data may still be extremely sensitive.
If a system records medical conditions or wellness assessments, security controls should reflect that sensitivity.
Organizations should classify information based on actual harm potential.
A database does not become low-risk simply because the company is not technically a healthcare provider.
Attackers Follow Convenience
Cybercriminals rarely care about organizational boundaries.
If one password works against multiple systems, they will try it.
If a remote-access portal is exposed, they will investigate it.
If employees reuse credentials, attackers can exploit the relationship.
If databases are accessible from poorly protected application endpoints, those endpoints become targets.
The attacker follows the easiest route.
MFA Is Necessary but Not Magical
Multi-factor authentication can dramatically reduce the value of stolen passwords.
It is not a complete security strategy.
Session theft, social engineering, compromised endpoints, poorly protected recovery methods, and privileged-account abuse can still create problems.
Organizations should combine MFA with device security, conditional access, privilege management, session monitoring, and strong identity governance.
Detection Matters as Much as Prevention
A perfectly secure organization does not exist.
The goal is to detect suspicious behavior quickly.
Security teams should monitor unusual database queries.
Large exports should trigger alerts.
Unexpected administrative activity should be investigated.
Authentication from unusual locations should receive additional scrutiny.
Sudden access to thousands of customer records should never look like ordinary activity.
The 110 GB Number Should Not Distract From the Evidence
A large file size sounds dramatic.
But size alone cannot establish authenticity.
Investigators should examine file structure, timestamps, schemas, sample records, metadata, authentication logs, database access records, and evidence from affected systems.
The same principle applies to the 26,094-record figure.
Numbers should be verified, not merely repeated.
Threat Intelligence Needs Verification
Dark web and breach-monitoring reports can provide valuable early warnings.
They can also contain exaggerated descriptions.
A threat actor may combine old information with new information.
They may inflate record counts.
They may advertise data they do not actually possess.
They may sell the same dataset repeatedly.
This is why defenders should use underground-market intelligence as an investigation lead rather than automatically treating every advertisement as independently verified evidence.
Organizations Should Assume Reuse
Once identity data escapes, organizations should assume attackers may reuse it elsewhere.
That means affected companies need to investigate credential reuse.
They should review password-reset attempts.
They should monitor suspicious account registrations.
They should warn customers about convincing impersonation campaigns.
Incident response must continue beyond the moment the stolen database is discovered.
Privacy Is a Security Issue
Privacy cannot be separated from cybersecurity.
A compromised database can become a privacy disaster.
A privacy failure can become a fraud problem.
A fraud problem can become a financial loss.
A financial loss can become a reputational crisis.
Cybersecurity teams must therefore work closely with privacy, legal, compliance, and communications teams.
The Most Dangerous Breach May Be the One Nobody Notices
A ransomware attack is loud.
A database theft can be quiet.
Attackers may spend weeks extracting information without disrupting operations.
That makes database monitoring essential.
Organizations need visibility into what data is being accessed, by whom, from where, and at what volume.
Customers Need Transparency
When personal data is compromised, vague communication can make the situation worse.
Affected individuals need clear information about what happened.
They need to know what categories of information may have been exposed.
They need practical steps to protect themselves.
And they need updates when investigations produce new findings.
Trust is difficult to rebuild when organizations communicate only after information appears publicly.
The Two Incidents Show Different Versions of the Same Problem
Gran Caribe represents the danger of concentrated travel and identity information.
HerbaSis represents the danger of personal and potentially sensitive wellness information.
Both demonstrate how modern organizations become repositories of information that criminals can monetize.
The sectors are different.
The security challenge is remarkably similar.
The Database Is No Longer the Perimeter
Modern applications connect databases to APIs, cloud services, employee devices, mobile applications, third-party integrations, and remote-access platforms.
Protecting the database itself is therefore insufficient.
Organizations need to protect the entire data pathway.
The Next Step Is Data Minimization
The safest sensitive record is often the record that does not need to exist.
If an organization does not require an identity document indefinitely, it should not retain it indefinitely.
If a system does not need full identifiers, it should use partial identifiers where possible.
If employees do not need complete records, access should be masked.
Less data means less potential damage.
Cybersecurity Is Ultimately About People
Technical controls matter.
Firewalls matter.
Encryption matters.
MFA matters.
Endpoint detection matters.
But the reason these controls exist is simple: people deserve to have their identities protected.
Every exposed record represents a person who trusted an organization with information.
That trust is the real asset at stake.
Deep Analysis: Investigating the Exposure Safely
Start With Indicators
Security teams investigating an incident should begin by collecting indicators from legitimate internal evidence, threat-intelligence feeds, authentication logs, database logs, and endpoint telemetry.
A basic Linux investigation can begin with:
grep -RniE "exfilar|GranCaribe|HerbaSis" /var/log 2>/dev/null
This searches local logs for relevant investigation terms without interacting with any external criminal infrastructure.
Search Authentication Logs
Unexpected access patterns can reveal compromised accounts.
grep -Ei "failed|accepted|authentication" /var/log/auth.log | tail -n 100
Security teams should compare these events against known administrator activity and expected maintenance windows.
Review Recent System Activity
On Linux systems, investigators can inspect recent processes with:
ps aux --sort=-%cpu | head -n 20
The purpose is not to identify a specific attacker from this command alone, but to establish whether unusual processes or resource consumption deserve deeper investigation.
Check Network Connections
A quick review of active network connections can provide additional context:
ss -tupn
Unexpected outbound connections should be investigated against known services, approved infrastructure, and security telemetry.
Look for Large File Transfers
Potential data theft can sometimes leave filesystem or network traces.
find /var/log -type f -size +100M -ls 2>/dev/null
Large logs are not automatically malicious, but unusual file growth can provide an investigation lead.
Review Scheduled Tasks
Attackers sometimes use scheduled execution for persistence.
crontab -l
Security teams should also inspect system-wide cron directories and compare entries with approved configuration baselines.
Examine Privileged Accounts
A compromised privileged account can dramatically increase the scope of an incident.
getent passwd | awk -F: ‘$3 == 0 {print $1}’
Any unexpected privileged account should immediately trigger investigation.
Verify Database Access
For database environments, security teams should examine query logs and audit records for unusual bulk exports.
A request accessing tens of thousands of records at once should have a legitimate business explanation.
If it does not, incident responders should treat it as a potential indicator of unauthorized collection.
Protect Evidence
Investigators should avoid modifying original evidence unnecessarily.
Logs should be preserved.
Timestamps should be documented.
Hashes should be generated for forensic copies.
Access should be restricted.
Incident-response teams should maintain a clear chain of custody.
Do Not Test Criminal Infrastructure
Organizations should never attempt to download stolen databases from criminal marketplaces merely to determine whether a leak is genuine.
Doing so can expose systems to malware and potentially create legal and operational risks.
Use established threat-intelligence providers, law-enforcement channels, internal telemetry, and trusted incident-response professionals instead.
Gran Caribe Exists and Collects Passport Information
✅ Verified: Gran Caribe Hotel Group is a real Cuban hotel organization, and its official booking policies state that guests must present valid passports during check-in.
The 110 GB Leak and 26,094 Passport Records
❌ Not independently verified: The supplied cybersecurity post reports the alleged dataset, but the available authoritative sources reviewed here do not independently confirm that Actor exfilar possesses or is selling the stated 110 GB dataset.
HerbaSis Handles Extensive Personal Information
✅ Verified: HerbaSis publicly describes customer-management functionality and its registration system requests names, birth dates, CPF numbers, addresses, telephone numbers, and email addresses. The reported database leak itself, however, is not independently confirmed by the sources reviewed.
Prediction
(+1) Personal Data Will Remain a Prime Cybercrime Target
Large identity datasets will continue to attract cybercriminal groups because they can be monetized through fraud, phishing, impersonation, and social engineering.
Hospitality organizations will remain attractive targets because travel operations naturally require identity and contact information.
Customer-management and wellness platforms will face increasing scrutiny as attackers recognize the value of sensitive personal profiles.
Organizations that adopt strong identity controls, segmentation, encryption, monitoring, and data minimization will be better positioned to contain future incidents.
(-1) The Damage Can Continue Long After the Initial Breach
Exposed identity information cannot simply be deleted from the internet once copied.
Victims may face targeted phishing and impersonation attempts months or even years later.
Reused credentials can create secondary compromises across unrelated services.
A breach involving sensitive information can permanently damage customer trust even after the technical vulnerability has been fixed.
The Bigger Warning
The reports involving Gran Caribe and HerbaSis should be viewed as more than two isolated cybersecurity headlines.
They represent two increasingly common realities of the digital economy.
Hotels collect passports because people need to prove who they are.
Customer-management platforms collect identifiers because businesses need to understand their customers.
Wellness systems collect sensitive information because users expect personalized services.
Every one of those legitimate functions creates a security responsibility.
The central lesson is simple: data becomes dangerous when organizations collect more of it than they can adequately protect.
Whether the reported datasets ultimately prove to be exactly as advertised, partially accurate, outdated, or substantially different, the underlying security problem remains real.
The organizations holding identity information are increasingly becoming high-value targets.
And for the people behind those records, cybersecurity is no longer an abstract technical issue.
It is the protection of their identity, privacy, reputation, and digital life.
▶️ Related Video (74% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




