๐Ÿ”ช Slice For Life - Part 2 ๐Ÿ”ช
3.1K subscribers
701 photos
18 videos
509 links
Download Telegram
๐Ÿšจ๐Ÿ‡ณ๐Ÿ‡ฌ General Directorate of Public Accounting and Treasury of Nigeria allegedly breached: 70GB of government financial and employee data leaked

A threat actor claims to have leaked data tied to the General Directorate of Public Accounting and Treasury of Nigeria (DGCPT) following an alleged ransomware-related cyberattack.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Target: General Directorate of Public Accounting and Treasury of Nigeria
Sector: Government / Public Finance / Treasury
Incident: Data Breach / Ransomware Leak
Exposure: 70GB+
Actor: 0xSec
Country: Nigeria
Date: 18/05/2026
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Whatโ€™s allegedly included:

โ–ช๏ธ Government employee records allegedly linked to DGCPT systems
โ–ช๏ธ Employee ID, first name, and last name fields
โ–ช๏ธ Phone number and contact-related data
โ–ช๏ธ Bank, branch, and account-related fields
โ–ช๏ธ Additional financial identifiers referenced in SQL files
โ–ช๏ธ Multiple SQL database files containing employee and treasury-related records

Potential impact:

The exposed data could be used for identity theft, payroll fraud, banking fraud, phishing, impersonation, and targeted social engineering against government employees and financial administration contacts.

Status:

Unverified underground forum claim. The actor states the archive contains more than 70GB of exfiltrated data and references multiple SQL files.

Stop guessing what's redacted. Subscribers see everything โ†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐Ÿšจ๐Ÿ‡ง๐Ÿ‡ท Econet Editora allegedly breached: 163GB full database advertised for sale from Brazilian education publishing platform

A threat actor claims to be selling a full database tied to Econet Editora, a Brazilian publishing platform focused on educational content, books, digital resources, and learning materials for students and educators.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Target: Econet Editora
Sector: Education / Publishing / Digital Learning
Incident: Database Leak / Data Sale
Exposure: 163GB
Actor: [Citizen] joaoestrella
Country: Brazil
Date: 18/05/2026
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Whatโ€™s allegedly included:

โ–ช๏ธ Full database allegedly linked to Econet Editora
โ–ช๏ธ Email address fields
โ–ช๏ธ Plaintext password claims
โ–ช๏ธ User/account-related database records
โ–ช๏ธ Platform and publishing service data
โ–ช๏ธ Database and table listings shared as proof
โ–ช๏ธ Additional unspecified internal records referenced by the actor

Potential impact:

The exposed data could be used for credential stuffing, account takeover, phishing, identity theft, and targeted scams against students, educators, and platform users.

Status:

Unverified underground forum sale listing. The actor claims the database totals 163GB and includes emails, plaintext passwords, and additional database content.

Stop guessing what's redacted. Subscribers see everything โ†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โš ๏ธ FBI Watchdog - WHOIS Change โš ๏ธ
๐Ÿ”— DarkWebInformer.com - Cyber Threat Intelligence

Domain: breached.st
Record Type: WHOIS Change
Time Detected: 2026-05-19 01:23:42 UTC

Previous Records:
status: ['ok']

New Records:
status: ['ok'] โ†’ ['clienttransferprohibited']
๐Ÿ˜2
Hackers laying it on thick...
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐Ÿšจ๐Ÿ‡บ๐Ÿ‡ธ Peetโ€™s Coffee allegedly breached: 115K customer records exposed from U.S. coffee retail database

A threat actor claims to have leaked part of a customer database tied to Peetโ€™s Coffee, a U.S. coffee retailer and cafรฉ chain known for its specialty coffee products and retail locations.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Target: Peetโ€™s Coffee
Sector: Retail / Food & Beverage / Customer Data
Incident: Database Leak
Exposure: 115,000 records / 120MB
Actor: zSenior
Country: United States
Date: 18/05/2026
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Whatโ€™s allegedly included:

โ–ช๏ธ Customer records allegedly linked to Peetโ€™s Coffee
โ–ช๏ธ First name and last name fields
โ–ช๏ธ Primary email address fields
โ–ช๏ธ Primary phone number fields
โ–ช๏ธ Full address and street address fields
โ–ช๏ธ City, state, and ZIP code records
โ–ช๏ธ Customer profile and contact metadata
โ–ช๏ธ Partial sample data shared through the forum thread

Potential impact:

The exposed data could be used for phishing, customer impersonation, loyalty fraud, account targeting, and retail scam campaigns against Peetโ€™s Coffee customers.

Status:

Unverified underground forum claim. The actor posted sample customer records and claims a 5K-record partial leak is available through hidden forum content.

Stop guessing what's redacted. Subscribers see everything โ†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐Ÿšจ๐Ÿ‡ฒ๐Ÿ‡ฝ Escuela Normal Experimental allegedly breached: 3,414 student/application records exposed from Mexican school database

A threat actor claims to have leaked a database tied to Escuela Normal Experimental in Mexico, allegedly exposing student and application-related records from an education system.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Target: Escuela Normal Experimental
Sector: Education / School Administration
Incident: Database Leak
Exposure: 3,414 records
Actor: Z3r00 and MagoSpeak
Country: Mexico
Date: 19/05/2026
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Whatโ€™s allegedly included:

โ–ช๏ธ Student and application records allegedly linked to the school
โ–ช๏ธ Application folio and request status fields
โ–ช๏ธ CURP identity-related fields
โ–ช๏ธ Names, paternal surnames, and maternal surnames
โ–ช๏ธ Age, birth date, gender, nationality, and birth entity fields
โ–ช๏ธ Email, fixed phone, and mobile phone fields
โ–ช๏ธ Address and municipality-related records
โ–ช๏ธ School file and subsystem-related administrative fields

Potential impact:

The exposed data could be used for identity theft, phishing, student impersonation, education fraud, and targeted social engineering against applicants, students, and school staff.

Status:

Unverified underground forum claim. The actor posted a field list and claims the database is available through an external file-hosting link.
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐Ÿšจ๐Ÿ‡ฒ๐Ÿ‡ฝ Instituto Tecnolรณgico del Istmo allegedly breached: 3,640 student/application records exposed from Oaxaca education database

A threat actor claims to have leaked a database tied to Instituto Tecnolรณgico del Istmo in Oaxaca, Mexico, allegedly exposing student and application-related records from an education system.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Target: Instituto Tecnolรณgico del Istmo
Sector: Education / Higher Education / School Administration
Incident: Database Leak
Exposure: 3,640 records
Actor: Z3r00 and MagoSpeak
Country: Mexico
Date: 19/05/2026
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Whatโ€™s allegedly included:

โ–ช๏ธ Student and application records allegedly linked to the institute
โ–ช๏ธ Application folio and request status fields
โ–ช๏ธ CURP identity-related fields
โ–ช๏ธ Names, paternal surnames, and maternal surnames
โ–ช๏ธ Age, birth date, gender, nationality, and birth entity fields
โ–ช๏ธ Email, fixed phone, and mobile phone fields
โ–ช๏ธ Address, state, and municipality-related records
โ–ช๏ธ Administrative school system fields tied to application workflows

Potential impact:

The exposed data could be used for identity theft, phishing, student impersonation, education fraud, and targeted social engineering against applicants, students, and school staff.

Status:

Unverified underground forum claim. The actor posted a field list and claims the database is available through an external file-hosting link.

Stop guessing what's redacted. Subscribers see everything โ†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐ŸšจDeath Stealer 2026 advertised: information-stealing malware post shared on underground forum

A forum user is advertising โ€œDeath Stealer 2026,โ€ described as an information-stealing malware concept associated with credential theft, browser data collection, and unauthorized extraction of sensitive user data.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Service: Death Stealer 2026
Sector: Malware / Info-Stealer / Cybercrime Tools
Incident: Malware Advertisement
Exposure: Credential theft and browser data collection tool
Actor: Jake Elliott
Country: Unknown / Global
Date: 19/05/2026
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Whatโ€™s being advertised:

โ–ช๏ธ Information-stealing malware branded as โ€œDeath Stealer 2026โ€
โ–ช๏ธ Credential and browser data targeting claims
โ–ช๏ธ Sensitive application and system data collection references
โ–ช๏ธ External server communication for stolen data transfer
โ–ช๏ธ Malware behavior framed around stealth and detection avoidance
โ–ช๏ธ VirusTotal scan result section referenced in the post
โ–ช๏ธ Download link section included by the actor

Potential impact:

The advertised tool could be used for credential theft, account takeover, financial fraud, identity theft, and broader compromise of personal or enterprise systems.

Status:

Underground forum advertisement. The post presents a short malware summary, key capabilities, scan-result references, and a download section.

Stop guessing what's redacted. Subscribers see everything โ†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐Ÿšจ๐Ÿ‡ซ๐Ÿ‡ท Lagrange Vacances allegedly breached: 44K holiday rental reservation records exposed from French travel booking database

A threat actor claims to have leaked a database tied to Lagrange Vacances, a French holiday rental and vacation accommodation provider offering apartments, holiday homes, and leisure stays across France and Europe.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Target: Lagrange Vacances
Sector: Hospitality / Travel / Holiday Rentals
Incident: Database Leak
Exposure: 44K records / 35MB
Actor: ChimeraZ
Country: France
Date: 19/05/2026
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Whatโ€™s allegedly included:

โ–ช๏ธ Reservation records allegedly linked to Lagrange Vacances bookings
โ–ช๏ธ Customer and participant identity fields
โ–ช๏ธ Booking references and reservation IDs
โ–ช๏ธ Vendor, lodging, and product-related records
โ–ช๏ธ Guest count fields including adults and children
โ–ช๏ธ Stay dates, arrival/departure times, and accommodation details
โ–ช๏ธ Pricing, commission, fees, and payment-related booking metadata
โ–ช๏ธ Customer comments and special booking notes

Potential impact:

The exposed data could be used for booking impersonation, targeted phishing, travel fraud, customer scams, and social engineering against travelers, guests, and booking partners.

Status:

Unverified underground forum claim. The actor posted structured JSON reservation samples and claims the download links are hidden behind forum access.

Stop guessing what's redacted. Subscribers see everything โ†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โค1
๐Ÿšจ๐Ÿ‡จ๐Ÿ‡ฎ Unknown Ivory Coast ID dataset advertised: 10.6K ID document files offered for sale

A threat actor claims to be selling an unidentified dataset containing Ivory Coast identity document images, including front-side ID images, back-side ID images, and selfie verification photos.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Target: Unknown Ivory Coast ID dataset
Sector: Identity Documents / KYC Data
Incident: Data Sale
Exposure: 32,009 files / 2.10GB
Actor: azrekx
Country: Cรดte dโ€™Ivoire
Price: $5,000 full dataset / $1 per record
Date: 18/05/2026
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Whatโ€™s allegedly included:

โ–ช๏ธ Ivory Coast ID document images
โ–ช๏ธ Front and back ID card files
โ–ช๏ธ Selfie verification images
โ–ช๏ธ KYC-style identity verification records
โ–ช๏ธ Personal identity document data
โ–ช๏ธ Image archive samples allegedly shared through external channels

Potential impact:

The exposed documents could be used for identity theft, account fraud, KYC bypass, impersonation, and financial scams involving affected individuals.

Status:

Unverified underground forum sale listing. The actor claims the dataset was found on a server, continues to grow, and may not be tied to a known source organization.

Stop guessing what's redacted. Subscribers see everything โ†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐Ÿšจ๐Ÿ‡ฆ๐Ÿ‡ช Bayut allegedly breached: 986K real estate customer records and identity documents exposed

A threat actor claims to have leaked a large dataset allegedly tied to Bayut, one of the UAEโ€™s major real estate platforms.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Target: Bayut
Sector: Real Estate / Property Technology / Customer Data
Incident: Data Leak
Exposure: 986,506 records
Actor: attacker_company
Country: United Arab Emirates
Date: 19/05/2026
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Whatโ€™s allegedly included:

โ–ช๏ธ Customer records allegedly linked to Bayut
โ–ช๏ธ Full names and login/user identifier fields
โ–ช๏ธ Password-related values
โ–ช๏ธ Phone numbers, WhatsApp contact fields, and email addresses
โ–ช๏ธ IP address logs and location classification fields
โ–ช๏ธ Physical address and ZIP/postal data
โ–ช๏ธ Passport, Golden Card, and ID document images
โ–ช๏ธ Title deed and property ownership document samples

Potential impact:

The exposed data could be used for identity theft, real estate fraud, account takeover, phishing, property-owner impersonation, and targeted scams against Bayut users and customers.

Status:

Unverified underground forum claim. The actor posted sample identity documents, property ownership document previews, and claims additional personal information data is hidden behind forum access.

Stop guessing what's redacted. Subscribers see everything โ†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐Ÿšจ๐Ÿ‡ง๐Ÿ‡ท Speedio allegedly breached: 62M Brazilian B2B marketing records exposed

A threat actor claims to have leaked a large B2B marketing database tied to Speedio, a Brazilian business intelligence and sales prospecting platform.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Target: Speedio
Sector: B2B Marketing / Sales Intelligence / Business Data
Incident: Database Leak
Exposure: 62M lines / 27,652,184 unique emails
Actor: Claude
Country: Brazil
Date: 19/05/2026
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Whatโ€™s allegedly included:

โ–ช๏ธ Brazilian company and business profile records
โ–ช๏ธ Legal names and trading names
โ–ช๏ธ Company identifiers and MongoDB-related record IDs
โ–ช๏ธ Business status, legal nature, and founding date fields
โ–ช๏ธ Primary and secondary economic activity classifications
โ–ช๏ธ Company size, capital amount, and tax regime metadata
โ–ช๏ธ Email addresses, phone numbers, and WhatsApp contact fields
โ–ช๏ธ Address and WhatsApp validation-related data

Potential impact:

The exposed data could be used for B2B phishing, business impersonation, spam campaigns, targeted scams, lead fraud, and social engineering against Brazilian companies and contacts.

Status:

Unverified underground forum claim. The actor posted structured JSON samples and claims the dataset contains 62M total lines, including more than 27.6M unique email addresses.

Stop guessing what's redacted. Subscribers see everything โ†’ darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐Ÿ”ฅ1
โ€ผ๏ธ DOJ Press Release
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Justice Department Notifies Washington of Investigation into Whether Housing Biological Men in Womenโ€™s Prison Violates Constitution

Full Press Release โ†’ justice.gov

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
๐Ÿ•ต๏ธ Dark Web Informer โ€ข DOJ Monitor

Note: DOJ articles that are not Cyber related will be removed manually.
๐Ÿ˜1๐Ÿ˜ˆ1