πŸ”ͺ Slice For Life - Part 2 πŸ”ͺ
3.1K subscribers
701 photos
18 videos
506 links
Download Telegram
πŸš¨πŸ‡«πŸ‡· MediaVacances allegedly breached: 256K invoice and holiday rental records exposed from French vacation booking platform

A threat actor claims to have leaked a database tied to MediaVacances, a French holiday rental platform offering apartments, houses, cottages, and short-stay accommodations.

━━━━━━━━━━━━━━━━━━━━
Target: MediaVacances
Sector: Hospitality / Travel / Holiday Rentals
Incident: Database Leak
Exposure: 256K records / 188MB
Actor: ChimeraZ
Country: France
Date: 18/05/2026
━━━━━━━━━━━━━━━━━━━━

What’s allegedly included:

β–ͺ️ Invoice records allegedly linked to MediaVacances
β–ͺ️ Booking and rental listing-related records
β–ͺ️ Customer billing and payment reference fields
β–ͺ️ Invoice dates, invoice numbers, and transaction text fields
β–ͺ️ Accommodation advertising and subscription-related details
β–ͺ️ Company registration, VAT, and business identifier references
β–ͺ️ Structured JSON records shared as proof of access

Potential impact:

The exposed data could be used for phishing, invoice fraud, booking impersonation, rental scams, and targeted social engineering against customers, hosts, and platform users.

Status:

Unverified underground forum claim. The actor posted JSON invoice samples and claims.

Stop guessing what's redacted. Subscribers see everything β†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
GitHub Advisories feed was updated with the following and is currently for Elite subscribers only:

β–ͺ️Removed the Unreviewed feed toggle and related JS logic. I didn't find it useful. When the CVE feed is available it will have everything.

β–ͺ️Added Priority / Newest sort, with Newestt as the default.

β–ͺ️Collapsed CVSS/CWE/Ecosystem into Advanced filters by default.

β–ͺ️Improved advisory cards with package/ecosystem/affected/fixed-version display.

β–ͺ️Added priority badges: Priority, Watch, Routine.

β–ͺ️Added a better error state with a Retry button.

β–ͺ️Performance improvements

β–ͺ️Bug fixes.

https://darkwebinformer.com/github-advisories-feed/
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
❀1
Is there any interest in a phishing/scam intelligence feed?
Anonymous Poll
73%
Yes
15%
No
12%
Show Results
Pentest Agent Suite for Claude Code: Autonomous bug-bounty framework for Claude Code and 6 other AI coding tools - 50 agents, 26 commands, 19 CLI tools, 11 skills, 2 MCP servers.

GitHub: https://github.com/H-mmer/pentest-agents
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
PF onion is having some issues right now.
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
😁1
πŸš¨πŸ‡³πŸ‡¬ General Directorate of Public Accounting and Treasury of Nigeria allegedly breached: 70GB of government financial and employee data leaked

A threat actor claims to have leaked data tied to the General Directorate of Public Accounting and Treasury of Nigeria (DGCPT) following an alleged ransomware-related cyberattack.

━━━━━━━━━━━━━━━━━━━━
Target: General Directorate of Public Accounting and Treasury of Nigeria
Sector: Government / Public Finance / Treasury
Incident: Data Breach / Ransomware Leak
Exposure: 70GB+
Actor: 0xSec
Country: Nigeria
Date: 18/05/2026
━━━━━━━━━━━━━━━━━━━━

What’s allegedly included:

β–ͺ️ Government employee records allegedly linked to DGCPT systems
β–ͺ️ Employee ID, first name, and last name fields
β–ͺ️ Phone number and contact-related data
β–ͺ️ Bank, branch, and account-related fields
β–ͺ️ Additional financial identifiers referenced in SQL files
β–ͺ️ Multiple SQL database files containing employee and treasury-related records

Potential impact:

The exposed data could be used for identity theft, payroll fraud, banking fraud, phishing, impersonation, and targeted social engineering against government employees and financial administration contacts.

Status:

Unverified underground forum claim. The actor states the archive contains more than 70GB of exfiltrated data and references multiple SQL files.

Stop guessing what's redacted. Subscribers see everything β†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
πŸš¨πŸ‡§πŸ‡· Econet Editora allegedly breached: 163GB full database advertised for sale from Brazilian education publishing platform

A threat actor claims to be selling a full database tied to Econet Editora, a Brazilian publishing platform focused on educational content, books, digital resources, and learning materials for students and educators.

━━━━━━━━━━━━━━━━━━━━
Target: Econet Editora
Sector: Education / Publishing / Digital Learning
Incident: Database Leak / Data Sale
Exposure: 163GB
Actor: [Citizen] joaoestrella
Country: Brazil
Date: 18/05/2026
━━━━━━━━━━━━━━━━━━━━

What’s allegedly included:

β–ͺ️ Full database allegedly linked to Econet Editora
β–ͺ️ Email address fields
β–ͺ️ Plaintext password claims
β–ͺ️ User/account-related database records
β–ͺ️ Platform and publishing service data
β–ͺ️ Database and table listings shared as proof
β–ͺ️ Additional unspecified internal records referenced by the actor

Potential impact:

The exposed data could be used for credential stuffing, account takeover, phishing, identity theft, and targeted scams against students, educators, and platform users.

Status:

Unverified underground forum sale listing. The actor claims the database totals 163GB and includes emails, plaintext passwords, and additional database content.

Stop guessing what's redacted. Subscribers see everything β†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
⚠️ FBI Watchdog - WHOIS Change ⚠️
πŸ”— DarkWebInformer.com - Cyber Threat Intelligence

Domain: breached.st
Record Type: WHOIS Change
Time Detected: 2026-05-19 01:23:42 UTC

Previous Records:
status: ['ok']

New Records:
status: ['ok'] β†’ ['clienttransferprohibited']
😁2
Hackers laying it on thick...
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
πŸš¨πŸ‡ΊπŸ‡Έ Peet’s Coffee allegedly breached: 115K customer records exposed from U.S. coffee retail database

A threat actor claims to have leaked part of a customer database tied to Peet’s Coffee, a U.S. coffee retailer and cafΓ© chain known for its specialty coffee products and retail locations.

━━━━━━━━━━━━━━━━━━━━
Target: Peet’s Coffee
Sector: Retail / Food & Beverage / Customer Data
Incident: Database Leak
Exposure: 115,000 records / 120MB
Actor: zSenior
Country: United States
Date: 18/05/2026
━━━━━━━━━━━━━━━━━━━━

What’s allegedly included:

β–ͺ️ Customer records allegedly linked to Peet’s Coffee
β–ͺ️ First name and last name fields
β–ͺ️ Primary email address fields
β–ͺ️ Primary phone number fields
β–ͺ️ Full address and street address fields
β–ͺ️ City, state, and ZIP code records
β–ͺ️ Customer profile and contact metadata
β–ͺ️ Partial sample data shared through the forum thread

Potential impact:

The exposed data could be used for phishing, customer impersonation, loyalty fraud, account targeting, and retail scam campaigns against Peet’s Coffee customers.

Status:

Unverified underground forum claim. The actor posted sample customer records and claims a 5K-record partial leak is available through hidden forum content.

Stop guessing what's redacted. Subscribers see everything β†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
πŸš¨πŸ‡²πŸ‡½ Escuela Normal Experimental allegedly breached: 3,414 student/application records exposed from Mexican school database

A threat actor claims to have leaked a database tied to Escuela Normal Experimental in Mexico, allegedly exposing student and application-related records from an education system.

━━━━━━━━━━━━━━━━━━━━
Target: Escuela Normal Experimental
Sector: Education / School Administration
Incident: Database Leak
Exposure: 3,414 records
Actor: Z3r00 and MagoSpeak
Country: Mexico
Date: 19/05/2026
━━━━━━━━━━━━━━━━━━━━

What’s allegedly included:

β–ͺ️ Student and application records allegedly linked to the school
β–ͺ️ Application folio and request status fields
β–ͺ️ CURP identity-related fields
β–ͺ️ Names, paternal surnames, and maternal surnames
β–ͺ️ Age, birth date, gender, nationality, and birth entity fields
β–ͺ️ Email, fixed phone, and mobile phone fields
β–ͺ️ Address and municipality-related records
β–ͺ️ School file and subsystem-related administrative fields

Potential impact:

The exposed data could be used for identity theft, phishing, student impersonation, education fraud, and targeted social engineering against applicants, students, and school staff.

Status:

Unverified underground forum claim. The actor posted a field list and claims the database is available through an external file-hosting link.
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
πŸš¨πŸ‡²πŸ‡½ Instituto TecnolΓ³gico del Istmo allegedly breached: 3,640 student/application records exposed from Oaxaca education database

A threat actor claims to have leaked a database tied to Instituto TecnolΓ³gico del Istmo in Oaxaca, Mexico, allegedly exposing student and application-related records from an education system.

━━━━━━━━━━━━━━━━━━━━
Target: Instituto TecnolΓ³gico del Istmo
Sector: Education / Higher Education / School Administration
Incident: Database Leak
Exposure: 3,640 records
Actor: Z3r00 and MagoSpeak
Country: Mexico
Date: 19/05/2026
━━━━━━━━━━━━━━━━━━━━

What’s allegedly included:

β–ͺ️ Student and application records allegedly linked to the institute
β–ͺ️ Application folio and request status fields
β–ͺ️ CURP identity-related fields
β–ͺ️ Names, paternal surnames, and maternal surnames
β–ͺ️ Age, birth date, gender, nationality, and birth entity fields
β–ͺ️ Email, fixed phone, and mobile phone fields
β–ͺ️ Address, state, and municipality-related records
β–ͺ️ Administrative school system fields tied to application workflows

Potential impact:

The exposed data could be used for identity theft, phishing, student impersonation, education fraud, and targeted social engineering against applicants, students, and school staff.

Status:

Unverified underground forum claim. The actor posted a field list and claims the database is available through an external file-hosting link.

Stop guessing what's redacted. Subscribers see everything β†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
🚨Death Stealer 2026 advertised: information-stealing malware post shared on underground forum

A forum user is advertising β€œDeath Stealer 2026,” described as an information-stealing malware concept associated with credential theft, browser data collection, and unauthorized extraction of sensitive user data.

━━━━━━━━━━━━━━━━━━━━
Service: Death Stealer 2026
Sector: Malware / Info-Stealer / Cybercrime Tools
Incident: Malware Advertisement
Exposure: Credential theft and browser data collection tool
Actor: Jake Elliott
Country: Unknown / Global
Date: 19/05/2026
━━━━━━━━━━━━━━━━━━━━

What’s being advertised:

β–ͺ️ Information-stealing malware branded as β€œDeath Stealer 2026”
β–ͺ️ Credential and browser data targeting claims
β–ͺ️ Sensitive application and system data collection references
β–ͺ️ External server communication for stolen data transfer
β–ͺ️ Malware behavior framed around stealth and detection avoidance
β–ͺ️ VirusTotal scan result section referenced in the post
β–ͺ️ Download link section included by the actor

Potential impact:

The advertised tool could be used for credential theft, account takeover, financial fraud, identity theft, and broader compromise of personal or enterprise systems.

Status:

Underground forum advertisement. The post presents a short malware summary, key capabilities, scan-result references, and a download section.

Stop guessing what's redacted. Subscribers see everything β†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations