> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Threat Actor Selling Alleged Databases From Crypto, AI, and Finance Platforms Including MagicSlides, TLDR.Tech, and 365.loans
- URL: https://darkwebinformer.com/threat-actor-selling-alleged-databases-from-crypto-ai-and-finance-platforms-including-magicslides-tldr-tech-and-365-loans/
- Published: 2026-03-13T15:47:43.000Z
- Updated: 2026-03-13T15:47:43.000Z
- Author: Dark Web Informer
- Tags: Leads

Dark Web Informer - Cyber Threat Intelligence 

# Threat Actor Selling Alleged Databases From Crypto, AI, and Finance Platforms Including MagicSlides, TLDR.Tech, and 365.loans

March 13, 2026 - 4:28:44 AM UTC 

N/A 

Cryptocurrency / AI / Finance 

Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. 

[ View API](https://darkwebinformer.com/api-details/) 

 Unlock Exclusive Cyber Threat Intelligence

Powered by DarkWebInformer.com

Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously.

[ Subscribe Now](https://darkwebinformer.com/pricing) 

## Quick Facts

Date & Time 2026-03-13 04:28:44 UTC 

Threat Actor Sythe 

Victims Multiple Platforms 

Industry Crypto / AI / Finance 

Category Database Sale 

Alleged Records \~3.8 Million Emails 

Databases Listed 7 

Price Contact Seller 

Network Open Web 

Samples Available via Channel/PM 

##  Incident Overview

A threat actor going by Sythe is advertising the sale of multiple alleged databases spanning cryptocurrency, artificial intelligence, and finance platforms. The actor claims their group has been collecting private data across these sectors and is offering individual databases for purchase, with samples available through their channel or direct messages.

  
The listing breaks down into three categories with the following databases:

- **Crypto** \- BTC.Allo.xyz (91K unique emails), Metaxseed.io (5K unique emails), and YesNoError.com Crypto/AI Database (100K unique emails).
- **Finance** \- 365.loans (26K emails) and an unnamed 71K-user ecommerce website.
- **AI** \- MagicSlides.App (2.3 million emails), TLDR.Tech (1.2 million emails), and YesNoError.com Crypto/AI Database (100K unique emails).
  
The two largest databases by far are MagicSlides.App and TLDR.Tech, which are both AI-focused platforms - MagicSlides is a presentation generation tool and TLDR.Tech is a popular technology newsletter. Combined, those two alone account for roughly 3.5 million of the approximately 3.8 million total email addresses being offered. The actor notes that YesNoError.com appears in both the crypto and AI categories, suggesting it straddles both spaces. No pricing was listed publicly; interested buyers are directed to contact the seller directly.

##  Compromised Data Categories

 Email Addresses  User Account Data  Cryptocurrency Platform Records  Financial Service Records  AI Platform User Data  Ecommerce User Records 

##  Image Preview

[![Forum post by Sythe advertising private crypto, AI, and finance databases for sale with record counts per platform](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/25119393274302516286.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/25119393274302516286.png) 

##  Claim URL

Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. 

[ Subscribe](https://darkwebinformer.com/pricing) 

##  MITRE ATT&CK Mapping

[ T1589.002 Gather Victim Identity: Email Addresses Collects email addresses from compromised platforms for resale, enabling phishing campaigns, credential stuffing, and targeted social engineering. ](https://attack.mitre.org/techniques/T1589/002/) [ T1078 Valid Accounts Uses compromised or stolen credentials to gain unauthorized access to platforms and extract user databases. ](https://attack.mitre.org/techniques/T1078/) [ T1530 Data from Cloud Storage Accesses and extracts data from cloud-hosted databases and storage services used by SaaS platforms like MagicSlides and TLDR.Tech. ](https://attack.mitre.org/techniques/T1530/) [ T1213 Data from Information Repositories Extracts structured user data from application databases, CRM systems, or internal repositories containing email and account records. ](https://attack.mitre.org/techniques/T1213/) [ T1567 Exfiltration Over Web Service Uses web services and forums to distribute and sell stolen databases, leveraging public platforms for advertising and sample distribution. ](https://attack.mitre.org/techniques/T1567/) [ T1114 Email Collection Harvests email addresses and associated account data at scale from multiple platforms, aggregating them for bulk resale. ](https://attack.mitre.org/techniques/T1114/) 

Dark Web Informer © 2026 | Cyber Threat Intelligence  
[DarkWebInformer.com](https://darkwebinformer.com/)