βΌοΈπΊπΈ Vantage Media AI allegedly has data exposed on a popular cybercrime forum.
Threat Actor: Sorb
Date: 03-31-2026
Category: Breach
Victim: Vantage Media AI
Industry: Data Analytics / Marketing
Sites: vantagemediacorp.com, vantagemedia.ai
Threat actor claims to have breached Vantage Media AI's MongoDB server on March 27, 2026.
Data contains: 381 GB of personal data totaling 628 million+ unique emails, 51 million+ phone numbers, 139 million+ address records, 180 million+ personal profiles, 31.4 million+ unique IPs, 59 million+ DOB records, and 11.9 million+ company records. Data fields include full name, full address, job title, industry, LinkedIn URL, gender, politics, religion, IP address, DOB, email, and phone.
The actor states numerous attempts to contact the company were unsuccessful. Priced at $15,000 as a single purchase.
Threat Actor: Sorb
Date: 03-31-2026
Category: Breach
Victim: Vantage Media AI
Industry: Data Analytics / Marketing
Sites: vantagemediacorp.com, vantagemedia.ai
Threat actor claims to have breached Vantage Media AI's MongoDB server on March 27, 2026.
Data contains: 381 GB of personal data totaling 628 million+ unique emails, 51 million+ phone numbers, 139 million+ address records, 180 million+ personal profiles, 31.4 million+ unique IPs, 59 million+ DOB records, and 11.9 million+ company records. Data fields include full name, full address, job title, industry, LinkedIn URL, gender, politics, religion, IP address, DOB, email, and phone.
The actor states numerous attempts to contact the company were unsuccessful. Priced at $15,000 as a single purchase.
β€1
β οΈ FBI Watchdog - DNS Change (A) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: DNS Change (A)
Time Detected: 2026-04-01 06:52:59 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: DNS Change (A)
Time Detected: 2026-04-01 06:52:59 UTC
Previous Records:
144.31.107.15
New Records:
38.54.84.75
β οΈ FBI Watchdog - IP Change (hosting migration) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 06:55:52 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 06:55:52 UTC
Previous Records:
A: 144.31.107.15
AAAA:
New Records:
A: 144.31.107.15 β 38.54.84.75
Classification: Complete IP replacement - likely hosting migration
π1
β οΈ FBI Watchdog - DNS Change (A) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: DNS Change (A)
Time Detected: 2026-04-01 07:18:45 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: DNS Change (A)
Time Detected: 2026-04-01 07:18:45 UTC
Previous Records:
38.54.84.75
New Records:
43.169.16.152
β οΈ FBI Watchdog - DNS Change (NS) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: DNS Change (NS)
Time Detected: 2026-04-01 07:18:47 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: DNS Change (NS)
Time Detected: 2026-04-01 07:18:47 UTC
Previous Records:
a.dnspod.com.
b.dnspod.com.
c.dnspod.com.
New Records:
ns1.teodns.com.
ns2.teodns.com.
β οΈ FBI Watchdog - WHOIS Change β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: WHOIS Change
Time Detected: 2026-04-01 07:21:21 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: WHOIS Change
Time Detected: 2026-04-01 07:21:21 UTC
Previous Records:
name_servers: ['a dnspod com c dnspod com']
New Records:
name_servers: ['a dnspod com c dnspod com'] β ['ns1 teodns com ns2 teodns com']
β οΈ FBI Watchdog - IP Change (hosting migration) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 07:21:23 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 07:21:23 UTC
Previous Records:
A: 38.54.84.75
AAAA:
New Records:
A: 38.54.84.75 β 43.169.16.152
Classification: Complete IP replacement - likely hosting migration
π1
β οΈ FBI Watchdog - DNS Change (A) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: DNS Change (A)
Time Detected: 2026-04-01 08:37:54 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: DNS Change (A)
Time Detected: 2026-04-01 08:37:54 UTC
Previous Records:
43.169.16.152
New Records:
43.169.13.152
43.169.14.152
β οΈ FBI Watchdog - IP Change (hosting migration) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 08:40:31 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 08:40:31 UTC
Previous Records:
A: 43.169.16.152
AAAA:
New Records:
A: 43.169.16.152 β 43.169.13.152, 43.169.14.152
Classification: Complete IP replacement - likely hosting migration
β οΈ FBI Watchdog - DNS Change (A) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: darkforums.su
Record Type: DNS Change (A)
Time Detected: 2026-04-01 09:07:06 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: darkforums.su
Record Type: DNS Change (A)
Time Detected: 2026-04-01 09:07:06 UTC
Previous Records:
104.21.50.249
172.67.215.116
New Records:
185.196.11.58
β οΈ FBI Watchdog - IP Change (hosting migration) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 09:09:31 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: handala-hack.tw
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 09:09:31 UTC
Previous Records:
A: 43.169.13.152, 43.169.14.152
AAAA:
New Records:
A: 43.169.13.152, 43.169.14.152 β 43.169.16.152
Classification: Complete IP replacement - likely hosting migration
β οΈ FBI Watchdog - IP Change (hosting migration) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: darkforums.su
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 09:09:32 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: darkforums.su
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 09:09:32 UTC
Previous Records:
A: 104.21.50.249, 172.67.215.116
AAAA: 2606:4700:3032::ac43:d774, 2606:4700:3033::6815:32f9
New Records:
A: 104.21.50.249, 172.67.215.116 β 185.196.11.58
AAAA: 2606:4700:3032::ac43:d774, 2606:4700:3033::6815:32f9 β None
Classification: Complete IP replacement - likely hosting migration
β οΈ FBI Watchdog - IP Change (hosting migration) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: darkforums.su
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 09:36:55 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: darkforums.su
Record Type: IP Change (hosting migration)
Time Detected: 2026-04-01 09:36:55 UTC
Previous Records:
A: 185.196.11.58
AAAA:
New Records:
A: 185.196.11.58 β 104.21.50.249, 172.67.215.116
AAAA: None β 2606:4700:3032::ac43:d774, 2606:4700:3033::6815:32f9
Classification: Complete IP replacement - likely hosting migration
β οΈ FBI Watchdog - DNS Change (TXT) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: veryleaks.cz
Record Type: DNS Change (TXT)
Time Detected: 2026-04-01 10:37:03 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: veryleaks.cz
Record Type: DNS Change (TXT)
Time Detected: 2026-04-01 10:37:03 UTC
Previous Records:
"google-site-verification=Z9AyafcDgfuC_ZdjUDcJr_01nuh0KQRfwOHNRsHIDts"
"v=spf1 +mx +a +ip4:185.165.169.146 ~all"
New Records:
"google-site-verification=Z9AyafcDgfuC_ZdjUDcJr_01nuh0KQRfwOHNRsHIDts"
"platform-verification=98efb374-0075-476d-ad67-3fbb9c37a238"
"v=spf1 +mx +a +ip4:185.165.169.146 ~all"