The threat actor leaderboard and cybercrime website leaderboard that are in the early access program may stop working every once and a while for the next couple of weeks as I make changes for Threat Feed 3.0. Apologies in advance. Bonk me if I don't notice it.
โผ๏ธ New Dark Web Informer Blog Post!
Title: Daily Dose of Dark Web Informer - May 28th, 2026
Link: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-28th-2026/
Title: Daily Dose of Dark Web Informer - May 28th, 2026
Link: https://darkwebinformer.com/daily-dose-of-dark-web-informer-may-28th-2026/
Dark Web Informer
Daily Dose of Dark Web Informer - May 28th, 2026
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
๐จ๐บ๐ธ Smoker's Choice USA allegedly targeted in 980GB corporate document leak
A threat actor on an underground forum is claiming to sell a corporate document leak allegedly originating from Smoker's Choice USA, one of the largest cigarette and tobacco outlets in the United States, with over 50 retail locations across New York and Pennsylvania.
The actor claims the leak totals roughly 980 GB across more than 303,000 files covering a wide range of internal topics.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Billing and payments
โข Laboratory reports
โข Internal employee documents and directives
โข Employee resumes
โข Tests
โข Goods movements
โข Operations of individual representative stores
โข Product certification
โข Bank statements and checks
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Smoker's Choice USA
๐๐ผ๐๐ป๐๐ฟ๐: United States ๐บ๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / Tobacco
๐๐ฐ๐๐ผ๐ฟ: Masterbyte
๐๐น๐ฎ๐ถ๐บ: Corporate document leak, one-time sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~980 GB (303,000+ files)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a corporate document leak allegedly originating from Smoker's Choice USA, one of the largest cigarette and tobacco outlets in the United States, with over 50 retail locations across New York and Pennsylvania.
The actor claims the leak totals roughly 980 GB across more than 303,000 files covering a wide range of internal topics.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Billing and payments
โข Laboratory reports
โข Internal employee documents and directives
โข Employee resumes
โข Tests
โข Goods movements
โข Operations of individual representative stores
โข Product certification
โข Bank statements and checks
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Smoker's Choice USA
๐๐ผ๐๐ป๐๐ฟ๐: United States ๐บ๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / Tobacco
๐๐ฐ๐๐ผ๐ฟ: Masterbyte
๐๐น๐ฎ๐ถ๐บ: Corporate document leak, one-time sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~980 GB (303,000+ files)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐ฅ1
๐จ๐ช๐ฌ Citex Systems allegedly targeted in database breach
A threat actor on an underground forum is claiming access to databases allegedly originating from Citex Systems, a major integrated telecom and business solutions provider headquartered in Giza, Cairo, Egypt, founded in 2003. The company provides telecom and ICT, smart card and banking payment systems, GIS projects, and customized software.
The actor claims access to employee, project, and mailing databases covering around 800 personnel.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Employee management database (names list, positions, ~800 persons)
โข Projects management database (available projects, responsible parties, worker names, dates, and locations)
โข Mailing data (all mails and contacts in the mailing system)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Citex Systems
๐๐ผ๐๐ป๐๐ฟ๐: Egypt ๐ช๐ฌ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Telecom / ICT
๐๐ฐ๐๐ผ๐ฟ: Keymous
๐๐น๐ฎ๐ถ๐บ: Database access
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Employee, project, and mailing databases (~800 personnel)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming access to databases allegedly originating from Citex Systems, a major integrated telecom and business solutions provider headquartered in Giza, Cairo, Egypt, founded in 2003. The company provides telecom and ICT, smart card and banking payment systems, GIS projects, and customized software.
The actor claims access to employee, project, and mailing databases covering around 800 personnel.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Employee management database (names list, positions, ~800 persons)
โข Projects management database (available projects, responsible parties, worker names, dates, and locations)
โข Mailing data (all mails and contacts in the mailing system)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Citex Systems
๐๐ผ๐๐ป๐๐ฟ๐: Egypt ๐ช๐ฌ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Telecom / ICT
๐๐ฐ๐๐ผ๐ฟ: Keymous
๐๐น๐ฎ๐ถ๐บ: Database access
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Employee, project, and mailing databases (~800 personnel)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ Allianz allegedly targeted in ~500 internal Docker images leak
A threat actor on an underground forum is claiming to release a full dump of roughly 500 Docker images, totaling around 40 GB, allegedly originating from Allianz internal infrastructure.
The actor claims the images contain exposed configuration files, source code, credentials, and private keys.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Exposed configuration files with API keys, DB passwords, and service tokens
โข Internal microservices with source code
โข Hardcoded credentials for staging and prod environments
โข TLS private keys and internal CA certs
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Allianz
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Insurance / Financial Services
๐๐ฐ๐๐ผ๐ฟ: hackformetome
๐๐น๐ฎ๐ถ๐บ: Full dump of internal Docker images
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~500 Docker images (~40 GB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 10 Points
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to release a full dump of roughly 500 Docker images, totaling around 40 GB, allegedly originating from Allianz internal infrastructure.
The actor claims the images contain exposed configuration files, source code, credentials, and private keys.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Exposed configuration files with API keys, DB passwords, and service tokens
โข Internal microservices with source code
โข Hardcoded credentials for staging and prod environments
โข TLS private keys and internal CA certs
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Allianz
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Insurance / Financial Services
๐๐ฐ๐๐ผ๐ฟ: hackformetome
๐๐น๐ฎ๐ถ๐บ: Full dump of internal Docker images
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~500 Docker images (~40 GB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 10 Points
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โค1
Cyberattack News Alert
โโโโโโโโโโโโโโโโโโโโโโโโโ
Victim: Landeszentrale fรผr politische Bildung
Domain:
Country: ๐ฉ๐ช DE
Date: May 28th, 2026
Summary:
The Landeszentrale fรผr politische Bildung has fallen victim to a cyberattack, according to its own statements. The institution was forced to isolate its websites as well as those of its memorials, rendering them currently inaccessible. The organization is investigating whether subscriber and customer data may have been exfiltrated as a result of the incident.
Source: https://www.rheinpfalz.de/lokal/pfalz-ticker_artikel,-landeszentrale-und-gedenkstรคtten-komplett-offline-_arid,5894846.html
โโโโโโโโโโโโโโโโโโโโโโโโโ
Victim: Landeszentrale fรผr politische Bildung
Domain:
lpb.rlp.deCountry: ๐ฉ๐ช DE
Date: May 28th, 2026
Summary:
The Landeszentrale fรผr politische Bildung has fallen victim to a cyberattack, according to its own statements. The institution was forced to isolate its websites as well as those of its memorials, rendering them currently inaccessible. The organization is investigating whether subscriber and customer data may have been exfiltrated as a result of the incident.
Source: https://www.rheinpfalz.de/lokal/pfalz-ticker_artikel,-landeszentrale-und-gedenkstรคtten-komplett-offline-_arid,5894846.html
DIE RHEINPFALZ
Landeszentrale und Gedenkstรคtten komplett offline
Die Landeszentrale fรผr politische Bildung ist nach eigenen Angaben offenbar Opfer eines Hackerangriffs geworden. Die staatliche Einrichtung mit Sitz in Mainz teilte am Freitag mit, dass ihre eigenen Webseiten und die ihrer Gedenkstรคtten in Osthofen und Hinzertโฆ
โผ๏ธ New Dark Web Informer Blog Post!
Title: French Real-Estate Co-op Platform Amepi Hit by Alleged 6K-Record Leak
Link: https://darkwebinformer.com/french-real-estate-co-op-platform-amepi-hit-by-alleged-6k-record-leak/
Title: French Real-Estate Co-op Platform Amepi Hit by Alleged 6K-Record Leak
Link: https://darkwebinformer.com/french-real-estate-co-op-platform-amepi-hit-by-alleged-6k-record-leak/
Dark Web Informer
French Real-Estate Co-op Platform Amepi Hit by Alleged 6K-Record Leak
A threat actor using the alias ChimeraZ claims to have leaked a database allegedly belonging to Amepi (Amanda), described as the leading French cooperative platform for sharing exclusive listings among real-estate agencies.
โผ๏ธ New Dark Web Informer Blog Post!
Title: Argentine Healthcare Provider Swiss Medical Listed in Alleged 458K-Record Member Data Sale
Link: https://darkwebinformer.com/argentine-healthcare-provider-swiss-medical-listed-in-alleged-458k-record-member-data-sale/
Title: Argentine Healthcare Provider Swiss Medical Listed in Alleged 458K-Record Member Data Sale
Link: https://darkwebinformer.com/argentine-healthcare-provider-swiss-medical-listed-in-alleged-458k-record-member-data-sale/
Dark Web Informer
Argentine Healthcare Provider Swiss Medical Listed in Alleged 458K-Record Member Data Sale
A threat actor using the alias Moelester claims to be selling a dataset allegedly originating from Swiss Medical, a major Argentine private healthcare and health-insurance company.
โผ๏ธ๐ณ๐ฑ BCD Travel has been named a victim on ShinyHunters Pay or Leak dark web portal
BCD Travel is a global corporate travel management company that helps businesses manage travel programs, bookings, meetings, and traveler support.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
BCD Travel is a global corporate travel management company that helps businesses manage travel programs, bookings, meetings, and traveler support.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ง๐ท Autoline allegedly targeted in 812K automotive contacts database sale
A threat actor on an underground forum is claiming to sell a dataset allegedly originating from Autoline, a Brazilian automotive organization. The actor says the data is organized across 3 interconnected sections covering contacts, vehicle inquiries, and service requests.
The actor claims the dataset contains roughly 812K records of automotive contacts, inquiries, and service data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Contacts (names, emails, primary/secondary phones, city, state, address, lead source, account tier, birth date, industry segment, LinkedIn/Twitter handles, vehicles owned)
โข Vehicle inquiries (vehicle model, client message, contact details, status, priority, assigned staff, pipeline stage, vehicle condition, campaign data, case reference numbers)
โข Service requests (requested service, descriptions, customer contact details, technician assignments, payment status, account IDs, contract type, warranty coverage, cost estimates)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Autoline
๐๐ผ๐๐ป๐๐ฟ๐: Brazil ๐ง๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Automotive
๐๐ฐ๐๐ผ๐ฟ: Rupert
๐๐น๐ฎ๐ถ๐บ: Automotive contacts database sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~812K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: $1,000
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a dataset allegedly originating from Autoline, a Brazilian automotive organization. The actor says the data is organized across 3 interconnected sections covering contacts, vehicle inquiries, and service requests.
The actor claims the dataset contains roughly 812K records of automotive contacts, inquiries, and service data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Contacts (names, emails, primary/secondary phones, city, state, address, lead source, account tier, birth date, industry segment, LinkedIn/Twitter handles, vehicles owned)
โข Vehicle inquiries (vehicle model, client message, contact details, status, priority, assigned staff, pipeline stage, vehicle condition, campaign data, case reference numbers)
โข Service requests (requested service, descriptions, customer contact details, technician assignments, payment status, account IDs, contract type, warranty coverage, cost estimates)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Autoline
๐๐ผ๐๐ป๐๐ฟ๐: Brazil ๐ง๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Automotive
๐๐ฐ๐๐ผ๐ฟ: Rupert
๐๐น๐ฎ๐ถ๐บ: Automotive contacts database sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~812K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: $1,000
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
STIX endpoints for API customers are now available. The docs page and sandbox have been updated with the information needed to make requests.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
Telegram
๐ช Slice For Life - Part 2 ๐ช
Backup: t.me/SliceForLifeeee
Website: darkwebinformer.com
Website Pricing (Includes Crypto): darkwebinformer.com/pricing
Socials: darkwebinformer.com/socials
API Access: https://darkwebinformer.com/api-details
Donate: darkwebinformer.com/donations
Website: darkwebinformer.com
Website Pricing (Includes Crypto): darkwebinformer.com/pricing
Socials: darkwebinformer.com/socials
API Access: https://darkwebinformer.com/api-details
Donate: darkwebinformer.com/donations
๐จ๐จ๐ด Punto Vital allegedly targeted in patient records leak
A threat actor on an underground forum is claiming to have leaked patient records allegedly originating from Punto Vital, a private healthcare provider (IPS) in Colombia. The actor says the data spans from 2019 to 2026.
The actor claims the leak contains over 3K patient expedientes (case files) including personal and medical record data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข Dates of birth
โข Phone numbers
โข Addresses
โข Place of birth
โข Patient signatures
โข Patient photos
โข Additional record data
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Punto Vital
๐๐ผ๐๐ป๐๐ฟ๐: Colombia ๐จ๐ด
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Healthcare
๐๐ฐ๐๐ผ๐ฟ: Bytedope157sp
๐๐น๐ฎ๐ถ๐บ: Leaked patient expedientes (2019 to 2026)
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: +3K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked patient records allegedly originating from Punto Vital, a private healthcare provider (IPS) in Colombia. The actor says the data spans from 2019 to 2026.
The actor claims the leak contains over 3K patient expedientes (case files) including personal and medical record data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข Dates of birth
โข Phone numbers
โข Addresses
โข Place of birth
โข Patient signatures
โข Patient photos
โข Additional record data
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Punto Vital
๐๐ผ๐๐ป๐๐ฟ๐: Colombia ๐จ๐ด
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Healthcare
๐๐ฐ๐๐ผ๐ฟ: Bytedope157sp
๐๐น๐ฎ๐ถ๐บ: Leaked patient expedientes (2019 to 2026)
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: +3K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ญ๐ท Croatian government site (*.gov.hr) allegedly targeted in 60K records leak
A threat actor on an underground forum, claiming affiliation with a group called INFGRUPA, says they have breached a *.gov.hr (Croatian government) website and are releasing the data for free.
The actor claims the leak contains roughly 60,000 people records including national identification numbers.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข OIB (Personal Identification Number)
โข JMBG (Unique Citizen Identification Number)
โข Dates of birth
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: *.gov.hr (Croatian government website)
๐๐ผ๐๐ป๐๐ฟ๐: Croatia ๐ญ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government
๐๐ฐ๐๐ผ๐ฟ: vvvv (INFGRUPA)
๐๐น๐ฎ๐ถ๐บ: Breached government website, data released for free
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~60,000 records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum, claiming affiliation with a group called INFGRUPA, says they have breached a *.gov.hr (Croatian government) website and are releasing the data for free.
The actor claims the leak contains roughly 60,000 people records including national identification numbers.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข OIB (Personal Identification Number)
โข JMBG (Unique Citizen Identification Number)
โข Dates of birth
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: *.gov.hr (Croatian government website)
๐๐ผ๐๐ป๐๐ฟ๐: Croatia ๐ญ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government
๐๐ฐ๐๐ผ๐ฟ: vvvv (INFGRUPA)
๐๐น๐ฎ๐ถ๐บ: Breached government website, data released for free
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~60,000 records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ช๐จ Revista Vistazo allegedly targeted in data leak exposing credit card info
A threat actor on an underground forum is claiming to have leaked a dataset allegedly originating from Revista Vistazo, an Ecuadorian magazine and media organization. The actor is releasing the data for free.
The actor claims the leak exposes roughly 19K Ecuadorians, including subscriber and payment card information.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข ID numbers (Cรฉdula / CI-Ecuador)
โข Email addresses
โข Phone numbers
โข Shipping addresses
โข Credit card details (cardholder, partial number, type, expiration)
โข Subscription plan and payment data
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Revista Vistazo
๐๐ผ๐๐ป๐๐ฟ๐: Ecuador ๐ช๐จ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Media / Publishing
๐๐ฐ๐๐ผ๐ฟ: GondorPe
๐๐น๐ฎ๐ถ๐บ: Data leak with credit card information
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~19K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked a dataset allegedly originating from Revista Vistazo, an Ecuadorian magazine and media organization. The actor is releasing the data for free.
The actor claims the leak exposes roughly 19K Ecuadorians, including subscriber and payment card information.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข ID numbers (Cรฉdula / CI-Ecuador)
โข Email addresses
โข Phone numbers
โข Shipping addresses
โข Credit card details (cardholder, partial number, type, expiration)
โข Subscription plan and payment data
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Revista Vistazo
๐๐ผ๐๐ป๐๐ฟ๐: Ecuador ๐ช๐จ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Media / Publishing
๐๐ฐ๐๐ผ๐ฟ: GondorPe
๐๐น๐ฎ๐ถ๐บ: Data leak with credit card information
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~19K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ฒ๐ฝ CECyTE Coahuila allegedly targeted in database leak
A threat actor on an underground forum is claiming to have leaked databases allegedly originating from CECyTE Coahuila, a public technical education institution in Coahuila, Mexico.
The actor claims the leak contains over 30K records covering suppliers, students, teachers, and administrators.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Suppliers (proveedores)
โข Students (alumnos)
โข Teachers (docentes)
โข Administrators (administrativos)
โข Usernames and passwords (hashed)
โข Full names, emails, phone numbers
โข Employee numbers and bank account fields
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: CECyTE Coahuila
๐๐ผ๐๐ป๐๐ฟ๐: Mexico ๐ฒ๐ฝ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education
๐๐ฐ๐๐ผ๐ฟ: hackstage
๐๐น๐ฎ๐ถ๐บ: Leaked databases
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: +30K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked databases allegedly originating from CECyTE Coahuila, a public technical education institution in Coahuila, Mexico.
The actor claims the leak contains over 30K records covering suppliers, students, teachers, and administrators.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Suppliers (proveedores)
โข Students (alumnos)
โข Teachers (docentes)
โข Administrators (administrativos)
โข Usernames and passwords (hashed)
โข Full names, emails, phone numbers
โข Employee numbers and bank account fields
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: CECyTE Coahuila
๐๐ผ๐๐ป๐๐ฟ๐: Mexico ๐ฒ๐ฝ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education
๐๐ฐ๐๐ผ๐ฟ: hackstage
๐๐น๐ฎ๐ถ๐บ: Leaked databases
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: +30K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ท๐ธ BeotelNet (Telekom Serbia) allegedly targeted in customer database breach
A threat actor on an underground forum is claiming to have breached BeotelNet, a Telekom company in Serbia, and extracted customers' sensitive information. The actor says customers using ADSL, fixed broadband, Wi-Fi, fiber/Ethernet, business internet, IPTV/TV, VoIP telephony, web hosting, VPS/cloud, data center, and carrier services may be affected.
The actor claims to hold over 150,000 records spanning 2020 to 2026, and threatens to publish the database on June 1, 2026 if no agreement is reached.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข JMBG (Unique Master Citizen Number)
โข Addresses
โข Cities
โข Postal codes
โข Phone numbers
โข Cell phone numbers
โข Email addresses
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: BeotelNet (Telekom Serbia)
๐๐ผ๐๐ป๐๐ฟ๐: Serbia ๐ท๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Telecom
๐๐ฐ๐๐ผ๐ฟ: QilinZeus
๐๐น๐ฎ๐ถ๐บ: Breached customer database, threatening publication
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 150,000+ records (2020 to 2026)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Extortion (publication threatened June 1, 2026)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have breached BeotelNet, a Telekom company in Serbia, and extracted customers' sensitive information. The actor says customers using ADSL, fixed broadband, Wi-Fi, fiber/Ethernet, business internet, IPTV/TV, VoIP telephony, web hosting, VPS/cloud, data center, and carrier services may be affected.
The actor claims to hold over 150,000 records spanning 2020 to 2026, and threatens to publish the database on June 1, 2026 if no agreement is reached.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข JMBG (Unique Master Citizen Number)
โข Addresses
โข Cities
โข Postal codes
โข Phone numbers
โข Cell phone numbers
โข Email addresses
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: BeotelNet (Telekom Serbia)
๐๐ผ๐๐ป๐๐ฟ๐: Serbia ๐ท๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Telecom
๐๐ฐ๐๐ผ๐ฟ: QilinZeus
๐๐น๐ฎ๐ถ๐บ: Breached customer database, threatening publication
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 150,000+ records (2020 to 2026)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Extortion (publication threatened June 1, 2026)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations