Iran's Leading Chat Platform Nazdika Allegedly Breached with 150GB of Private Messages Exposed
🧩 Standalone API Access Now Available
Access high-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more – independently from the above standard subscriptions.
View API AccessUnlock Exclusive Cyber Threat Intelligence
Powered by DarkWebInformer.com
Foundational access to breach intelligence. Track breaches, leaks, and threats in real time with high quality screenshots and concise expert summaries.
Continuously updated breach reports and threat summaries.
Daily breach, leak, and DDoS alerts.
Live tracking with JSON export.
Direct access to claims and posts.
Concise summaries of DDoS, defacements, and breaches.
Verified index of dark web sites and services.
Live status of 500+ sites.
Integrated checks inside breach posts.
Uncompressed, watermark free evidence.
Browser alerts for tracked terms.
Quick Facts
Incident Overview
A threat actor using the handle "xploitleaks" claims to have obtained one of the biggest and most confidential databases ever from Iran. The breach allegedly affects Nazdika, described as Iran's biggest chatting service. The threat actor is offering the database exclusively through Telegram.
- Service Description: Iran's biggest chatting service (Nazdika)
- Database Size: Over 150GB of plain text data
- Claim Significance: One of the biggest and most confidential databases ever from Iran
- Database Content: Private conversations, personal shared media files, and documents
- Private Conversations: Complete chat message history
- Personal Shared Media: Images, videos, and other multimedia files shared in chats
- Documents: Files and documents exchanged through the platform
- Message Metadata: Complete metadata including IDs, paths, and timestamps
- Data Fields: id, _index, _source/imagePath, _source/message, _source/replyId, _source/senderId, _source/targetId, _source/timestamp
- Message Aliases: pv-messages-alias identifiers
- Sample Data: Multiple message entries visible with Persian/Farsi text content, phone numbers, and message IDs
- Contact Method: @xploitleaks_support (Telegram)
- Availability: Only available at https://t.me/xploitleaks
- Distribution: Exclusive Telegram-only sale
Indicators of Compromise (IOCs)
Telegram Channel
https://t[.]me/xploitleaks
Note: This is the threat actor's main Telegram channel where the data is exclusively available.
Telegram Support Handle
https://t[.]me/xploitleaks_support
Note: This is the threat actor's support contact for inquiries about the data sale.
Breach Claim URL
Unlock Exclusive Cyber Threat Intelligence
Powered by DarkWebInformer.com
Foundational access to breach intelligence. Track breaches, leaks, and threats in real time with high quality screenshots and concise expert summaries.
Continuously updated breach reports and threat summaries.
Daily breach, leak, and DDoS alerts.
Live tracking with JSON export.
Direct access to claims and posts.
Concise summaries of DDoS, defacements, and breaches.
Verified index of dark web sites and services.
Live status of 500+ sites.
Integrated checks inside breach posts.
Uncompressed, watermark free evidence.
Browser alerts for tracked terms.
Dark Web Informer © 2026 | Cyber Threat Intelligence