> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Alleged Kaya Leak Includes 1.7 Million Records and Identity Data
- URL: https://darkwebinformer.com/alleged-kaya-leak-includes-1-7-million-records-and-identity-data/
- Published: 2026-09-24T17:31:44.000Z
- Updated: 2026-09-24T17:31:44.000Z
- Author: Dark Web Informer
- Tags: Leaks

Data Exposure Report Iran Dataset Leak Identity Data Financial Records Unverified 

## Alleged Kaya Leak Includes 1.7 Million Records and Identity Data

Claimed dataset size1.14 GB

Claimed total records1.7M

Claimed user accounts50,649

Claimed collections87

Severity HIGH 

### Overview

An actor using the handle **"DaOnlySpark"** claims to have breached **Kaya** and released a **1.14 GB dataset containing 1,697,095 records across 87 collections**. The post describes Kaya as an Iranian freelancing platform that connects professionals with international projects and manages Freelancer.com accounts and bidding on their behalf.

The claimed contents include **50,649 user accounts, 784,081 private chat messages, identity-verification records, financial data and bcrypt password hashes**. Two screenshots show portions of purported identity-verification and user records, followed by a hidden download area and actor contact details. **The breach, dataset authenticity, counts and full scope of exposed information have not been independently verified.**

### Post details

OrganizationKaya

Country Iran

SectorFreelancing and project services

Actor"DaOnlySpark"

Claimed total records1,697,095 across 87 collections

Claimed user accounts50,649

Download visibilityHidden until a reply is posted

Post date shownSep 24, 2026

### What the post claims

- 1.14 GB across 87 collections
- 1,697,095 total records
- 50,649 user accounts
- 46,493 accounts with phone numbers
- 15,120 accounts with national ID numbers
- 784,081 private chat messages
- 173,997 freelance projects
- 3,468 project payment milestones
- 29,853 support tickets
- 71,327 support ticket messages
- 16,432 identity-verification requests
- 16,428 linked Freelancer.com accounts
- 22,067 financial transactions
- 22,049 uploaded-file records
- 2,171 event signups
- 1,295 contact-form submissions
- 686 reviews and 392 freelancer portfolios
- 120,636 call-center records
- 96,179 VoIP events and 24,457 phone calls
- Full names, birth dates and gender
- Iranian national IDs and identity-document images
- Bank account details, including IBAN/Sheba
- bcrypt password hashes
- Private messages and customer caller numbers

The financial breakdown also lists **8,410 Zarinpal payment records**, 3,346 user payments, 489 withdrawal requests, 165 invoices, 962 ledger postings and 1,372 bank-account records. These are actor-provided figures. **No asking price is shown.** The Monero address in the signature is presented as a donation address.

Sponsored

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel)

### Screenshots

[Screenshot 1Source screenshot![Kaya dataset leak claim listing record counts and data categories, followed by an identity-verification sample](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/523798597682359768239587698627359872.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/523798597682359768239587698627359872.png) [Screenshot 2Source screenshot![Continuation of the Kaya identity-verification sample, a user sample, hidden download area and actor contact details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/523798597682359768239587698627359873.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/523798597682359768239587698627359873.png) 

Two supplied captures of the listing and its purported samples. The user sample includes an is\_admin flag; this field alone does not demonstrate usable admin access. The verification sample references an identity-document file, but no document image is shown. The download destination is hidden.

### IOCs & contact identifiers

Identifiers visible in the source screenshots. Contacts and the donation address support correlation; they do not independently establish identity, control or compromise.

| Type                      | Identifier                                                                                      | Source       |
| ------------------------- | ----------------------------------------------------------------------------------------------- | ------------ |
| Actor handle              | DaOnlySpark                                                                                     | Screenshot 1 |
| Named organization domain | kaya\[.\]ir                                                                                     | Screenshot 1 |
| Session ID                | 05f0c154aa452d2d610628fb375d3ef80efb4a5c377b6ee409d99988d80f00605f                              | Screenshot 2 |
| Telegram handle           | @DaOnlySpark                                                                                    | Screenshot 2 |
| Monero donation address   | 89RAbi5JYC6coBuBSGkdSfAmoZUSKEEJsjmcsLtX1VYqDRL8G1kJTk3XbSvxtixe95S9ZQQmupH9EhV28PkYehNj5ufSYQ8 | Screenshot 2 |

The domain identifies the organization named in the claim, not malicious infrastructure. No Tox ID, malware hash or attacker-controlled IP address is visible. Customer identifiers shown in the purported evidence are not included in this table. The Session ID and Monero address were checked against the screenshot; their ownership has not been verified. URLs to any data will always be blurred out, but are available to subscribers on the threat feed or ransomware feed.

### Mapped techniques

**Claimed** identifies behavior explicitly described by the actor. **Inferred** identifies an analytical mapping supported by the supplied material. Neither label means the activity has been independently verified.

- Collection [T1213.006](https://attack.mitre.org/techniques/T1213/006/) [Data from Information Repositories: Databases](https://attack.mitre.org/techniques/T1213/006/) Claimed The actor claims to have breached Kaya and released records from 87 collections, including account, messaging, verification and financial data. This maps the claimed collection of database contents; the screenshots do not establish the access vector, database engine or extraction method.
- Reconnaissance [T1589.001](https://attack.mitre.org/techniques/T1589/001/) [Gather Victim Identity Information: Credentials](https://attack.mitre.org/techniques/T1589/001/) Inferred The claimed inclusion of bcrypt password hashes supports an inferred mapping to obtaining credential material that could be used for later targeting. Hashes are not visible in the supplied samples, and no password recovery, credential reuse or account takeover is demonstrated.

### Potential impact

If authentic, **identity records, national ID numbers and document images** could support impersonation and identity fraud, while private messages, support history and project information could expose confidential communications and business relationships. Bank details and transaction records could support financial profiling and targeted scams. Claimed bcrypt hashes create potential credential risk, but do not establish that passwords are usable or have been recovered. **The 1,697,095 records span multiple collections and are not a count of distinct affected people.**

### Status Unverified

Dark Web Informer has **not independently verified** the alleged breach, dataset authenticity, completeness, counts or actor attribution. The visible samples contain identity-related fields, document references, account roles and timestamps, but do not demonstrate possession of all advertised collections. A registration timestamp and verification timestamp do not establish the breach date. The listing's reference to linked Freelancer.com accounts does not establish a compromise of Freelancer.com itself. The hidden download was not accessed, and no company confirmation or independent technical evidence of the intrusion is included in the supplied material.

Want everything on this threat? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=kaya-dataset-leak-2026-09-24&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=kaya-dataset-leak-2026-09-24&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=kaya-dataset-leak-2026-09-24&utm%5Fcontent=footer)