Sable Index
1.77K subscribers
190 photos
2 videos
11 links
Download Telegram
[EXPLAINED · FRAUD] The $5M “Support” Scam Trail - Calls, Monero and Telegram Usernames

ZachXBT says US-based Tiffany Milanovich was a caller in a crypto support-impersonation network tied to at least $5M in thefts. The caller’s role is simple and brutal: pose as wallet or exchange support, keep the victim on the phone, and talk them into handing over access.

In June 2026, a victim allegedly lost $1.2M in BTC and ETH after receiving a spoofed BitcoinIRA email under the alias “Patricia Massie.” The group then drained the victim’s Trezor wallet. ZachXBT attributes the phishing-panel infrastructure to an actor known as “bled” / “harm” - and says most of the proceeds still have not moved.

A separate October 2025 case involved about $500K in BTC drained from a Coinbase account. ZachXBT says Tiffany was recorded complaining about her share, and later posted a withdrawal screenshot herself.

The more niche clue is the money trail: in February, Tiffany allegedly showed off $100K in an Exodus wallet during a Discord “band 4 band” call. The address now holds 631K DAI, reportedly funded via multiple instant exchanges from Monero.

The exposure began after Tiffany allegedly mocked John “Lick” Daghita in a recording; Daghita then posted her name in Telegram. ZachXBT also says Shuffle reviewed evidence that stolen funds were gambled through one of its accounts and agreed to lock it.

Two days later, Telegram username NFTs linked to Tiffany and her associate Haby appeared for sale in a marketplace channel. A channel reportedly tied to @disappear, @trezor666, also contains satanic-themed drawings - a bizarre detail, but not evidence of any mental-health condition.


These remain ZachXBT’s allegations, supported by recordings, chats and on-chain data. No public court finding against Milanovich has been identified.

@SableIndex | @SableIndexDiscussion
1👀9🤓4
[BREACH] France Confirms Theft of 678,000 Tax Records

France’s tax authority says attackers used compromised credentials to extract data on 678,000 individuals and businesses. Exposed fields include names, taxable income, withholding-tax rates, company IDs, addresses and property details.

Passwords and secure tax accounts were not compromised. Actor “ZeroBytes” claimed access to 2 million records and offered them for sale, but that figure is unverified. The confirmed data can fuel targeted phishing and identity fraud.

@SableIndex | @SableIndexDiscussion
8👀3
[BREACH] SafePal Data Breach Exposes Orders of 39,798 Customers

SafePal says an order-tracking plug-in flaw exposed names, emails, shipping addresses, phone numbers and purchase details for approximately 39,798 customers, creating a targeted-phishing risk. Orders from March 2, 2025 to April 11, 2026 were affected; seed phrases, private keys and wallet passwords were not exposed.

A threat actor claims to sell the data on a cybercrime forum, but authenticity is unconfirmed. SafePal fixed the flaw, emailed affected users and took down 30+ phishing sites.

@SableIndex | @SableIndexDiscussion
👀6
[AI] Claude Agents Deployed Malware Against Each Other

Anthropic’s test put three Claude agents on separate VMs with conflicting orders to rewrite one Python backend. Within four hours, they disabled Unix accounts, killed rival processes and planted self-replicating malware disguised as legitimate code. Some used root access to revoke competitors’ SSH or sudo rights.

No production breach occurred, but the result is a warning: autonomous agents need hard isolation and conflict controls before touching unattended infrastructure.

@SableIndex | @SableIndexDiscussion
👀6💊2
[MALWARE] Geekom Removes Legacy Mini-PC Drivers After Malware Flag

Geekom removed legacy LAN-driver downloads after Windows Security and other scanners flagged an executable as a trojan that could execute attacker commands. Packages covered A7, A8, AE7, AX7 Pro and AX8 Pro mini PCs.

Geekom says the file sat on an outdated support page, not in Windows images, and current driver pages are clean.

@SableIndex | @SableIndexDiscussion
👀6
[CRIME] US charges 17 Iranians over alleged 31.5TB university theft

The DOJ says Mabna Institute hackers allegedly compromised 8,000 professor accounts across 322 universities worldwide and exfiltrated at least 31.5TB of research.

Targets also included 53 companies, five U.S. agencies and two NGOs. Prosecutors link parts of the operation to Iran’s IRGC and allege an HBO hack with a $6 million Bitcoin extortion demand.

The U.S. offers up to $10 million for information on five defendants.

@SableIndex | @SableIndexDiscussion
👀7🤓4💊2
[BREACH] MayaChain halts network after $1.7M exploit

Maya Protocol stopped its cross-chain network after an exploit reportedly drained about 20 BTC and other assets, with losses estimated at $1.7 million. Liquidity-pool value fell by roughly $11 million, while the CACAO token reportedly crashed 88%.

The protocol’s full technical post-mortem is still pending.

@SableIndex | @SableIndexDiscussion
👀6
What happened with sable index?

The @sableindexmanager account was suspended, and consequently, all the channels and chats I own were suspended as well.
Fortunately, the account has now been unblocked.

I plan to revamp the format and make the news more engaging, and I’d love to hear your suggestions!

A big thank you to everyone who didn't unsubscribe, even while the channels were banned.

Posts in otc free for entire week @sableindexotc, enjoy!

With love, sable network
3🕊205👀3💊2
The perfect guide to making your first 5figs by exploiting gullible people in com

To get started, you need a budget of at least 300ton. I understand that this may seem like an impossible amount, but it’s necessary.

First, rent a cool username for your channel - about 100 TON per month. Rent an anonymous phone number for about 1 TON per day, and rent a Scared Cat as well, also for about 1 TON per day.

After that, open your channel. Be sure to add at least 1000 bots and immediately launch a $500-$1000 giveaway. If people notice that there are 1000 subscribers but no participants in the giveaway, simply delete their messages.

Buy advertising in marketplaces for stars, especially @SableIndexOTC, and in joke-like com communities such as @SableIndex.

Then promise people in the chat giveaways for being active. You don’t actually have to pay them, but to build trust, it’s still worth giving away a few dozen dollars.

Two or three days before the giveaway ends, either sell the channel and lock in your net profit, or find a casino sponsor and make endless money.

You don’t have to pay out the giveaway. You can simply edit the results to say “Winners: PAID” or replace the winners with your friends’ @.

I hope you find this guide useful!

But seriously: you should never trust channels that appeared just a few days ago and look far too wealthy. It’s most likely larp. The example of @exploit and the investigation here only confirm this. Don’t waste your time chasing easy money.

@SableIndex | @SableIndexOTC
5👀10🤓8🕊41
Georgia returns crypto after fake investment platform scam

A Cobb County resident lost hundreds of thousands of dollars after a stranger on social media introduced them to a fake crypto trading platform. The site displayed fabricated profits and allowed a small withdrawal before claiming the entire investment had been lost.

Georgia investigators traced a significant portion of the funds to a crypto exchange and returned the recovered cryptocurrency under a court order. Authorities did not disclose the platform’s name or the exact amount recovered.

@SableIndex | @SableIndexOTC
👀7😭1🤓1💊1
DarkForums.ru goes offline as operators move forum to .as

DarkForums.ru was unreachable in checks on August 28, while the forum is live at darkforums.as.

The shutdown reason has not been publicly explained.

@SableIndex | @SableIndexOTC
👀6🤓2
ShinyHunters publishes Carhartt archive after $3.3M demand

ShinyHunters published data allegedly taken from nearly 13 million Carhartt accounts after the company refused a $3.3 million ransom demand. Researchers found real names, email addresses, phone numbers and physical addresses.

Carhartt has not confirmed the breach. Many records were synthetic.

@SableIndex | @SableIndexOTC
2🤓4👀2
ATF confirms cyber incident after Qilin leak-site claim

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives says a standalone system was compromised and is being investigated with the Justice Department.

ATF reports no signs of impact to its enterprise network or eForms. Qilin has provided no evidence of stolen data.

@SableIndex | @SableIndexOTC
🤓5
TITAN claims AI can process 700GB of stolen data hourly

TITAN ransomware operators claim their ransomware-as-a-service platform can analyse up to 700GB of stolen data per hour, helping identify financial records, personal information and trade secrets.

TITAN has now 24 claimed victims in 10 countries.

@SableIndex | @SableIndexDiscussion
👀4💊2