πͺ Slice For Life πͺ
βΌοΈπ¨π¦ A threat actor claims to have breached Loblaw, Canada's largest food and pharmacy retailer, threatening to publicly leak all data if the company does not respond by March 19th. The allegedly exfiltrated data includes 75.1M Salesforce customer PII recordsβ¦
βΌοΈπ¨π¦ The actor has released the first 251,366 Salesforce records of Loblaw and threatens more to come if the company does not contact them.
βΌοΈ BreachForums has been down for roughly a day now, but they claim they will be back up after an "internal problem," although @CCITIC has claimed to have knocked the forum offline (see secondary post).
https://x.com/DarkWebInformer/status/2032955324953477256
https://x.com/DarkWebInformer/status/2032955324953477256
β€1
If I can expand the threat feed to include replies in a different section or feed from forum posts, would you be interested? It would be something like check X hours, screenshot and add to separate feed. Haven't thought it all the way through yet.
Anonymous Poll
78%
Yes
5%
No
18%
Show Results
β οΈ FBI Watchdog - WHOIS Change β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: doxbin.net
Record Type: WHOIS Change
Time Detected: 2026-03-16 04:40:54 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: doxbin.net
Record Type: WHOIS Change
Time Detected: 2026-03-16 04:40:54 UTC
Previous Records:
status: ['clientdeleteprohibited', 'clienthold', 'clienttransferproh
New Records:
status: ['clientdeleteprohibited', 'clienthold', 'clienttransferprohibited'] β ['clientdeleteprohibited', 'clienttransferprohibited']
π1
β οΈ FBI Watchdog - IP Change (new ips added) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: doxbin.net
Record Type: IP Change (new ips added)
Time Detected: 2026-03-16 05:01:40 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: doxbin.net
Record Type: IP Change (new ips added)
Time Detected: 2026-03-16 05:01:40 UTC
Previous Records:
A: 104.20.41.231, 172.66.155.33
AAAA:
New Records:
AAAA: None β 2606:4700:10::6814:29e7, 2606:4700:10::ac42:9b21
Classification: 2 new IP(s) added
β οΈ FBI Watchdog - HTTP Fingerprint Change β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: enclave.cc
Record Type: HTTP Fingerprint Change
Time Detected: 2026-03-16 11:36:46 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: enclave.cc
Record Type: HTTP Fingerprint Change
Time Detected: 2026-03-16 11:36:46 UTC
Previous Records:
Status: 200
Body: 12f18a7445ce
New Records:
Status: 200 β 500
Redirect: https://www.enclave.cc/ β https://enclave.cc/
x-xss-protection: 0 β None
Body hash: 12f18a7445ce β e59fdfbc657b (size: 48,402 β 1,576)
β οΈ FBI Watchdog - HTTP Fingerprint Change β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: enclave.cc
Record Type: HTTP Fingerprint Change
Time Detected: 2026-03-16 13:54:00 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: enclave.cc
Record Type: HTTP Fingerprint Change
Time Detected: 2026-03-16 13:54:00 UTC
Previous Records:
Status: 500
Body: e59fdfbc657b
New Records:
Status: 500 β 200
Redirect: https://enclave.cc/ β https://www.enclave.cc/
x-xss-protection: None β 0
Body hash: e59fdfbc657b β 06d9ec7c57fb (size: 1,576 β 48,382)
βΌοΈπ¬π§ A threat actor is auctioning full admin access and shell access to a UK-based WordPress/Shopify store with 2,883 total orders and a 100% card payment rate.
The store uses an IFRAME form type, with recent order activity showing 79 orders in March, 44 in February, and 42 in January.
Starting bid: $200 | Step: $50 | Blitz: $600.
The store uses an IFRAME form type, with recent order activity showing 79 orders in March, 44 in February, and 42 in January.
Starting bid: $200 | Step: $50 | Blitz: $600.
β οΈ FBI Watchdog - IP Change (ips removed) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: cockbox.org
Record Type: IP Change (ips removed)
Time Detected: 2026-03-16 14:59:20 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: cockbox.org
Record Type: IP Change (ips removed)
Time Detected: 2026-03-16 14:59:20 UTC
Previous Records:
A: 193.239.85.202
AAAA: 2001:ac8:7d:1e::c0cc:2
New Records:
A: 193.239.85.202 β None
Classification: 1 IP(s) removed
β οΈ FBI Watchdog - IP Change (new ips added) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: cockbox.org
Record Type: IP Change (new ips added)
Time Detected: 2026-03-16 15:21:27 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: cockbox.org
Record Type: IP Change (new ips added)
Time Detected: 2026-03-16 15:21:27 UTC
Previous Records:
A:
AAAA: 2001:ac8:7d:1e::c0cc:2
New Records:
A: None β 193.239.85.202
Classification: 1 new IP(s) added
βΌοΈπ·πΊ A threat actor is allegedly selling the "Kordon" (ΠΠΎΡΠ΄ΠΎΠ½) database from the Russian Federal Border Service, claiming it was compromised in September 2023 and contains over 1 billion total records covering 79.5 million unique individuals, including foreign nationals.
The data reportedly includes full names, dates of birth, passport and travel document details, citizenship, entry/exit operations, border crossing dates and checkpoints, transport modes, flight numbers or vehicle plates, and departure/arrival cities. Records span from 2014 to 2023.
Price: $20,000.
The data reportedly includes full names, dates of birth, passport and travel document details, citizenship, entry/exit operations, border crossing dates and checkpoints, transport modes, flight numbers or vehicle plates, and departure/arrival cities. Records span from 2014 to 2023.
Price: $20,000.
β οΈ FBI Watchdog - HTTP Fingerprint Change β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: breachforums.as
Record Type: HTTP Fingerprint Change
Time Detected: 2026-03-16 15:43:52 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: breachforums.as
Record Type: HTTP Fingerprint Change
Time Detected: 2026-03-16 15:43:52 UTC
Previous Records:
Status: 403
Body: 5b13fb5957b8
New Records:
Status: 403 β 200
Redirect: https://breachforums.as/ β https://breachforums.as/info/download.php
x-content-type-options: nosniff β None
x-powered-by: None β PHP/8.2.29
x-xss-protection: 0 β None
x-frame-options: SAMEORIGIN β None
strict-transport-security: max-age=86400; includeSubDomains β None
Body hash: 5b13fb5957b8 β 3a1c652ed67c (size: 199 β 1,808)
FBI Watchdog 3.0.0: A multi-layered domain monitoring tool that detects law enforcement seizures, DNS changes, HTTP fingerprint shifts, WHOIS record mutations, and IP address changes across clearnet domains and Tor onion sites.
https://github.com/DarkWebInformer/FBI_Watchdog
https://github.com/DarkWebInformer/FBI_Watchdog
βΌοΈ New Dark Web Informer Blog Post!
Title: FBI Watchdog Feed
Link: https://darkwebinformer.com/fbi-watchdog-feed/
Title: FBI Watchdog Feed
Link: https://darkwebinformer.com/fbi-watchdog-feed/
Dark Web Informer
FBI Watchdog Feed
πͺ Slice For Life πͺ
βΌοΈ New Dark Web Informer Blog Post! Title: FBI Watchdog Feed Link: https://darkwebinformer.com/fbi-watchdog-feed/
The FBI Watchdog live feed can be access below for all paid subscribers: https://darkwebinformer.com/fbi-watchdog-feed/
It is currently capped to 10,000 events but will be increased later today.
It is currently capped to 10,000 events but will be increased later today.
Dark Web Informer
FBI Watchdog Feed
β€1
β οΈ FBI Watchdog - HTTP Fingerprint Change β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: breachforums.as
Record Type: HTTP Fingerprint Change
Time Detected: 2026-03-16 16:30:07 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: breachforums.as
Record Type: HTTP Fingerprint Change
Time Detected: 2026-03-16 16:30:07 UTC
Previous Records:
Status: 200
Body: 3a1c652ed67c
New Records:
Body hash: 3a1c652ed67c β a78bd6d0217a (size: 1,808 β 3,279)