๐จ๐ง๐ท iGreen Energy allegedly targeted in massive database leak
A threat actor on an underground forum is claiming to have extracted and is selling a dataset allegedly originating from iGreen Energy, the Brazilian renewable energy company.
The actor claims the dataset contains roughly 5M total records across clients, consultants, financial, and operational data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข 1M+ client records (CPF/CNPJ, RG, DOB, email, phone, full address, utility account numbers, contract history)
โข Plain-text passwords for tens of thousands of utility accounts (RGE, CEMIG, CEEE, EDP, CELESC, ELEKTRO, COPEL, ENEL, LIGHT, and others)
โข 94,859 consultant records with PIX keys, balances, and withdrawal history
โข 5,579 iGreenBank KYC accounts (CPF, mother's full name, KYC document type with issue date)
โข 205,246 financial withdrawal records (CPF, PIX key, amount, date)
โข 3.5M+ energy bill records (barcode, amount, due date, bill URL, kWh)
โข 88,498 telecom contracts, 17,420 solar contracts, 20 active auto insurance records (CPF, license plate, VIN/chassis, RENAVAM, ICCID, holder data)
โข 592 backoffice staff records (corporate email, access level, bcrypt + MD5 hashes)
โข 1,507 physical document files (IDs, utility bill photos, articles of incorporation, CNPJ cards) with predictable S3 URLs
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: iGreen Energy
๐๐ผ๐๐ป๐๐ฟ๐: Brazil ๐ง๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Energy / Renewables
๐๐ฐ๐๐ผ๐ฟ: masterblack
๐๐น๐ฎ๐ถ๐บ: Direct sale, dump extracted exclusively by actor
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~5M total records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (single buyer only, no bulk resale)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 27, 2026
๐ฅ Stop guessing what's redacted. Subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have extracted and is selling a dataset allegedly originating from iGreen Energy, the Brazilian renewable energy company.
The actor claims the dataset contains roughly 5M total records across clients, consultants, financial, and operational data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข 1M+ client records (CPF/CNPJ, RG, DOB, email, phone, full address, utility account numbers, contract history)
โข Plain-text passwords for tens of thousands of utility accounts (RGE, CEMIG, CEEE, EDP, CELESC, ELEKTRO, COPEL, ENEL, LIGHT, and others)
โข 94,859 consultant records with PIX keys, balances, and withdrawal history
โข 5,579 iGreenBank KYC accounts (CPF, mother's full name, KYC document type with issue date)
โข 205,246 financial withdrawal records (CPF, PIX key, amount, date)
โข 3.5M+ energy bill records (barcode, amount, due date, bill URL, kWh)
โข 88,498 telecom contracts, 17,420 solar contracts, 20 active auto insurance records (CPF, license plate, VIN/chassis, RENAVAM, ICCID, holder data)
โข 592 backoffice staff records (corporate email, access level, bcrypt + MD5 hashes)
โข 1,507 physical document files (IDs, utility bill photos, articles of incorporation, CNPJ cards) with predictable S3 URLs
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: iGreen Energy
๐๐ผ๐๐ป๐๐ฟ๐: Brazil ๐ง๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Energy / Renewables
๐๐ฐ๐๐ผ๐ฟ: masterblack
๐๐น๐ฎ๐ถ๐บ: Direct sale, dump extracted exclusively by actor
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~5M total records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (single buyer only, no bulk resale)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 27, 2026
๐ฅ Stop guessing what's redacted. Subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
Cyberattack News Alert
โโโโโโโโโโโโโโโโโโโโโโโโโ
Victim: Serpa
Domain:
Country: ๐ต๐ท PR
Date: May 27th, 2026
Summary:
The municipality of Serpa fell victim to an external cyberattack targeting its IT infrastructure. The incident was immediately reported to the relevant authorities, including the National Cybersecurity Centre. Although the system is considered secure, municipal services continue to operate under constraints, including the absence of fixed and mobile communications.
Source: https://www.vozdaplanicie.pt/index.php/noticias/camara-municipal-de-serpa-alvo-de-ataque-informatico
โโโโโโโโโโโโโโโโโโโโโโโโโ
Victim: Serpa
Domain:
cm-serpa.ptCountry: ๐ต๐ท PR
Date: May 27th, 2026
Summary:
The municipality of Serpa fell victim to an external cyberattack targeting its IT infrastructure. The incident was immediately reported to the relevant authorities, including the National Cybersecurity Centre. Although the system is considered secure, municipal services continue to operate under constraints, including the absence of fixed and mobile communications.
Source: https://www.vozdaplanicie.pt/index.php/noticias/camara-municipal-de-serpa-alvo-de-ataque-informatico
Rรกdio Voz da Planรญcie - 104.5FM - Beja
Autarquia de Serpa alvo de ataque informรกtico | Rรกdio Voz da Planรญcie - 104.5FM - Beja
A Cรขmara Municipal de Serpa informa atravรฉs da sua pรกgina de Facebook Serpa Terra Forte, que a infraestrutura informรกtica do municรญpio "foi alvo de um ataque externo, imediatamente reportado ร s autoridades competentes, designadamente ao Centro Nacional deโฆ
๐จ๐ฎ๐ณ 850M India Nationwide Identity Dataset allegedly listed for sale
A threat actor on an underground forum is claiming to sell a nationwide identity dataset allegedly originating from HITEK, containing telecom-linked Aadhaar records from India.
The actor claims the dataset contains roughly 850M records in JSON format (~109 GB).
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข Father's names
โข Aadhaar numbers (if linked)
โข Full addresses
โข Mobile numbers
โข Alternative mobile numbers
โข Email addresses
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: HITEK
๐๐ผ๐๐ป๐๐ฟ๐: India ๐ฎ๐ณ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Telecom / Identity
๐๐ฐ๐๐ผ๐ฟ: deb163
๐๐น๐ฎ๐ถ๐บ: Full PII / Telecom-linked Aadhaar records
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~850,000,000 records (~109 GB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 8 Points
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a nationwide identity dataset allegedly originating from HITEK, containing telecom-linked Aadhaar records from India.
The actor claims the dataset contains roughly 850M records in JSON format (~109 GB).
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข Father's names
โข Aadhaar numbers (if linked)
โข Full addresses
โข Mobile numbers
โข Alternative mobile numbers
โข Email addresses
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: HITEK
๐๐ผ๐๐ป๐๐ฟ๐: India ๐ฎ๐ณ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Telecom / Identity
๐๐ฐ๐๐ผ๐ฟ: deb163
๐๐น๐ฎ๐ถ๐บ: Full PII / Telecom-linked Aadhaar records
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~850,000,000 records (~109 GB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 8 Points
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โผ๏ธ New Dark Web Informer Blog Post!
Title: Brazilian Food-Delivery Giant iFood Targeted in Alleged 43.8M-Record Customer Data Extortion
Link: https://darkwebinformer.com/brazilian-food-delivery-giant-ifood-targeted-in-alleged-43-8m-record-customer-data-extortion/
Title: Brazilian Food-Delivery Giant iFood Targeted in Alleged 43.8M-Record Customer Data Extortion
Link: https://darkwebinformer.com/brazilian-food-delivery-giant-ifood-targeted-in-alleged-43-8m-record-customer-data-extortion/
Dark Web Informer
Brazilian Food-Delivery Giant iFood Targeted in Alleged 43.8M-Record Customer Data Extortion
A threat actor using the alias bacen claims to hold 43,847,219 Brazilian iFood customer records, said to include CPF national IDs, full names, emails, phone numbers, and credit-card data.
โผ๏ธ ShinyHunters has leaked 42 Million records of data from Charter Communications.
DentaQuest has also been relisted after being taken down due to possible negotiations.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
DentaQuest has also been relisted after being taken down due to possible negotiations.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
STIX endpoints will be available for users who subscribe to the API sometime tomorrow as promised. I just need to finish updating the docs.
https://darkwebinformer.com/api-details/
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
https://darkwebinformer.com/api-details/
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
Dark Web Informer
API Subscription Access
๐ฅ1
โผ๏ธ New Dark Web Informer Blog Post!
Title: French Government Platform Resana Listed in Alleged 990K-Record User Data Sale
Link: https://darkwebinformer.com/french-government-platform-resana-listed-in-alleged-990k-record-user-data-sale/
Title: French Government Platform Resana Listed in Alleged 990K-Record User Data Sale
Link: https://darkwebinformer.com/french-government-platform-resana-listed-in-alleged-990k-record-user-data-sale/
Dark Web Informer
French Government Platform Resana Listed in Alleged 990K-Record User Data Sale
A threat actor using the alias xMetah claims to be selling a database allegedly belonging to Resana, a French government collaboration platform hosted on the state's numerique.gouv.fr domain.
โผ๏ธ New Dark Web Informer Blog Post!
Title: French Real-Estate Platform Figaro Immobilier Hit by Alleged 100K Invoice Leak
Link: https://darkwebinformer.com/french-real-estate-platform-figaro-immobilier-hit-by-alleged-100k-invoice-leak/
Title: French Real-Estate Platform Figaro Immobilier Hit by Alleged 100K Invoice Leak
Link: https://darkwebinformer.com/french-real-estate-platform-figaro-immobilier-hit-by-alleged-100k-invoice-leak/
Dark Web Informer
French Real-Estate Platform Figaro Immobilier Hit by Alleged 100K Invoice Leak
A threat actor using the alias ChimeraZ claims to have leaked a database allegedly belonging to Figaro Immobilier / Explorimmo, a French real-estate platform offering property listings for sale, rent, and vacation stays.
โค1
โผ๏ธ New Dark Web Informer Blog Post!
Title: French Real-Estate Tour Platform EnVisite Hit by Alleged 138K-Record Leak
Link: https://darkwebinformer.com/french-real-estate-tour-platform-envisite-hit-by-alleged-138k-record-leak/
Title: French Real-Estate Tour Platform EnVisite Hit by Alleged 138K-Record Leak
Link: https://darkwebinformer.com/french-real-estate-tour-platform-envisite-hit-by-alleged-138k-record-leak/
Dark Web Informer
French Real-Estate Tour Platform EnVisite Hit by Alleged 138K-Record Leak
A threat actor using the alias ChimeraZ claims to have leaked a database allegedly belonging to EnVisite, a French platform for real-estate virtual tours used by agents to create and share interactive property presentations.
โผ๏ธ New Dark Web Informer Blog Post!
Title: One Forged Header: Unauthenticated Authentication Bypass in Fortinet FortiClient EMS (CVE-2026-35616)
Link: https://darkwebinformer.com/one-forged-header-unauthenticated-authentication-bypass-in-fortinet-forticlient-ems-cve-2026-35616/
Title: One Forged Header: Unauthenticated Authentication Bypass in Fortinet FortiClient EMS (CVE-2026-35616)
Link: https://darkwebinformer.com/one-forged-header-unauthenticated-authentication-bypass-in-fortinet-forticlient-ems-cve-2026-35616/
Dark Web Informer
One Forged Header: Unauthenticated Authentication Bypass in Fortinet FortiClient EMS (CVE-2026-35616)
Fortinet has disclosed a critical authentication bypass affecting FortiClient Endpoint Management Server (EMS).
โผ๏ธ New Dark Web Informer Blog Post!
Title: US Student Mental-Health Provider Mindpath College Health Listed on Ransomware Leak Site
Link: https://darkwebinformer.com/us-student-mental-health-provider-mindpath-college-health-listed-on-ransomware-leak-site/
Title: US Student Mental-Health Provider Mindpath College Health Listed on Ransomware Leak Site
Link: https://darkwebinformer.com/us-student-mental-health-provider-mindpath-college-health-listed-on-ransomware-leak-site/
Dark Web Informer
US Student Mental-Health Provider Mindpath College Health Listed on Ransomware Leak Site
Mindpath College Health, a US provider of mental and behavioral health services for college students, has been listed on a ransomware group's data-leak site.
๐จ๐ซ๐ท Groupe IMA allegedly targeted in 6.2GB data leak
A threat actor on an underground forum is claiming to have leaked data allegedly originating from Groupe IMA (Inter Mutuelles Habitat), a major French assistance provider that delivers 24/7 emergency support services, including roadside assistance, medical aid, and home repairs, on behalf of insurance companies and mutuals.
The actor claims the leak contains roughly 6.2 GB of data including invoices and other customer information.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Invoices
โข Customer information
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Groupe IMA (Inter Mutuelles Habitat)
๐๐ผ๐๐ป๐๐ฟ๐: France ๐ซ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Insurance / Assistance Services
๐๐ฐ๐๐ผ๐ฟ: NightLeVrai
๐๐น๐ฎ๐ถ๐บ: Leaked data
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~6.2 GB
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked data allegedly originating from Groupe IMA (Inter Mutuelles Habitat), a major French assistance provider that delivers 24/7 emergency support services, including roadside assistance, medical aid, and home repairs, on behalf of insurance companies and mutuals.
The actor claims the leak contains roughly 6.2 GB of data including invoices and other customer information.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Invoices
โข Customer information
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Groupe IMA (Inter Mutuelles Habitat)
๐๐ผ๐๐ป๐๐ฟ๐: France ๐ซ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Insurance / Assistance Services
๐๐ฐ๐๐ผ๐ฟ: NightLeVrai
๐๐น๐ฎ๐ถ๐บ: Leaked data
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~6.2 GB
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โค1
๐จ๐ช๐จ Ecuadorian Armed Forces allegedly targeted in confidential insurance document leak
A threat actor on an underground forum is claiming to have leaked confidential insurance policy information allegedly originating from the Armed Forces of Ecuador (Fuerzas Armadas del Ecuador).
The actor claims the documents cover insurance policies worth more than $200,000,000 and include sensitive military data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Confidential insurance policy information
โข Inventories
โข Armament data
โข Military vehicles
โข Combat aircraft
โข Warship details
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Fuerzas Armadas del Ecuador (Armed Forces of Ecuador)
๐๐ผ๐๐ป๐๐ฟ๐: Ecuador ๐ช๐จ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Military / Defense
๐๐ฐ๐๐ผ๐ฟ: V0lt4r0x
๐๐น๐ฎ๐ถ๐บ: Leaked confidential insurance documents
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Insurance policies valued over $200,000,000
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked confidential insurance policy information allegedly originating from the Armed Forces of Ecuador (Fuerzas Armadas del Ecuador).
The actor claims the documents cover insurance policies worth more than $200,000,000 and include sensitive military data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Confidential insurance policy information
โข Inventories
โข Armament data
โข Military vehicles
โข Combat aircraft
โข Warship details
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Fuerzas Armadas del Ecuador (Armed Forces of Ecuador)
๐๐ผ๐๐ป๐๐ฟ๐: Ecuador ๐ช๐จ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Military / Defense
๐๐ฐ๐๐ผ๐ฟ: V0lt4r0x
๐๐น๐ฎ๐ถ๐บ: Leaked confidential insurance documents
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Insurance policies valued over $200,000,000
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
The threat actor leaderboard and cybercrime website leaderboard that are in the early access program may stop working every once and a while for the next couple of weeks as I make changes for Threat Feed 3.0. Apologies in advance. Bonk me if I don't notice it.
โผ๏ธ New Dark Web Informer Blog Post!
Title: Daily Dose of Dark Web Informer - May 28th, 2026
Link: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-28th-2026/
Title: Daily Dose of Dark Web Informer - May 28th, 2026
Link: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-28th-2026/
Dark Web Informer
Daily Dose of Dark Web Informer - May 28th, 2026
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
๐จ๐บ๐ธ Smoker's Choice USA allegedly targeted in 980GB corporate document leak
A threat actor on an underground forum is claiming to sell a corporate document leak allegedly originating from Smoker's Choice USA, one of the largest cigarette and tobacco outlets in the United States, with over 50 retail locations across New York and Pennsylvania.
The actor claims the leak totals roughly 980 GB across more than 303,000 files covering a wide range of internal topics.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Billing and payments
โข Laboratory reports
โข Internal employee documents and directives
โข Employee resumes
โข Tests
โข Goods movements
โข Operations of individual representative stores
โข Product certification
โข Bank statements and checks
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Smoker's Choice USA
๐๐ผ๐๐ป๐๐ฟ๐: United States ๐บ๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / Tobacco
๐๐ฐ๐๐ผ๐ฟ: Masterbyte
๐๐น๐ฎ๐ถ๐บ: Corporate document leak, one-time sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~980 GB (303,000+ files)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a corporate document leak allegedly originating from Smoker's Choice USA, one of the largest cigarette and tobacco outlets in the United States, with over 50 retail locations across New York and Pennsylvania.
The actor claims the leak totals roughly 980 GB across more than 303,000 files covering a wide range of internal topics.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Billing and payments
โข Laboratory reports
โข Internal employee documents and directives
โข Employee resumes
โข Tests
โข Goods movements
โข Operations of individual representative stores
โข Product certification
โข Bank statements and checks
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Smoker's Choice USA
๐๐ผ๐๐ป๐๐ฟ๐: United States ๐บ๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / Tobacco
๐๐ฐ๐๐ผ๐ฟ: Masterbyte
๐๐น๐ฎ๐ถ๐บ: Corporate document leak, one-time sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~980 GB (303,000+ files)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐ฅ1
๐จ๐ช๐ฌ Citex Systems allegedly targeted in database breach
A threat actor on an underground forum is claiming access to databases allegedly originating from Citex Systems, a major integrated telecom and business solutions provider headquartered in Giza, Cairo, Egypt, founded in 2003. The company provides telecom and ICT, smart card and banking payment systems, GIS projects, and customized software.
The actor claims access to employee, project, and mailing databases covering around 800 personnel.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Employee management database (names list, positions, ~800 persons)
โข Projects management database (available projects, responsible parties, worker names, dates, and locations)
โข Mailing data (all mails and contacts in the mailing system)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Citex Systems
๐๐ผ๐๐ป๐๐ฟ๐: Egypt ๐ช๐ฌ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Telecom / ICT
๐๐ฐ๐๐ผ๐ฟ: Keymous
๐๐น๐ฎ๐ถ๐บ: Database access
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Employee, project, and mailing databases (~800 personnel)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming access to databases allegedly originating from Citex Systems, a major integrated telecom and business solutions provider headquartered in Giza, Cairo, Egypt, founded in 2003. The company provides telecom and ICT, smart card and banking payment systems, GIS projects, and customized software.
The actor claims access to employee, project, and mailing databases covering around 800 personnel.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Employee management database (names list, positions, ~800 persons)
โข Projects management database (available projects, responsible parties, worker names, dates, and locations)
โข Mailing data (all mails and contacts in the mailing system)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Citex Systems
๐๐ผ๐๐ป๐๐ฟ๐: Egypt ๐ช๐ฌ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Telecom / ICT
๐๐ฐ๐๐ผ๐ฟ: Keymous
๐๐น๐ฎ๐ถ๐บ: Database access
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Employee, project, and mailing databases (~800 personnel)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations