๐จ๐จ๐ด Punto Vital allegedly targeted in patient records leak
A threat actor on an underground forum is claiming to have leaked patient records allegedly originating from Punto Vital, a private healthcare provider (IPS) in Colombia. The actor says the data spans from 2019 to 2026.
The actor claims the leak contains over 3K patient expedientes (case files) including personal and medical record data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข Dates of birth
โข Phone numbers
โข Addresses
โข Place of birth
โข Patient signatures
โข Patient photos
โข Additional record data
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Punto Vital
๐๐ผ๐๐ป๐๐ฟ๐: Colombia ๐จ๐ด
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Healthcare
๐๐ฐ๐๐ผ๐ฟ: Bytedope157sp
๐๐น๐ฎ๐ถ๐บ: Leaked patient expedientes (2019 to 2026)
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: +3K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked patient records allegedly originating from Punto Vital, a private healthcare provider (IPS) in Colombia. The actor says the data spans from 2019 to 2026.
The actor claims the leak contains over 3K patient expedientes (case files) including personal and medical record data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข Dates of birth
โข Phone numbers
โข Addresses
โข Place of birth
โข Patient signatures
โข Patient photos
โข Additional record data
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Punto Vital
๐๐ผ๐๐ป๐๐ฟ๐: Colombia ๐จ๐ด
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Healthcare
๐๐ฐ๐๐ผ๐ฟ: Bytedope157sp
๐๐น๐ฎ๐ถ๐บ: Leaked patient expedientes (2019 to 2026)
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: +3K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ญ๐ท Croatian government site (*.gov.hr) allegedly targeted in 60K records leak
A threat actor on an underground forum, claiming affiliation with a group called INFGRUPA, says they have breached a *.gov.hr (Croatian government) website and are releasing the data for free.
The actor claims the leak contains roughly 60,000 people records including national identification numbers.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข OIB (Personal Identification Number)
โข JMBG (Unique Citizen Identification Number)
โข Dates of birth
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: *.gov.hr (Croatian government website)
๐๐ผ๐๐ป๐๐ฟ๐: Croatia ๐ญ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government
๐๐ฐ๐๐ผ๐ฟ: vvvv (INFGRUPA)
๐๐น๐ฎ๐ถ๐บ: Breached government website, data released for free
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~60,000 records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum, claiming affiliation with a group called INFGRUPA, says they have breached a *.gov.hr (Croatian government) website and are releasing the data for free.
The actor claims the leak contains roughly 60,000 people records including national identification numbers.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข OIB (Personal Identification Number)
โข JMBG (Unique Citizen Identification Number)
โข Dates of birth
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: *.gov.hr (Croatian government website)
๐๐ผ๐๐ป๐๐ฟ๐: Croatia ๐ญ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government
๐๐ฐ๐๐ผ๐ฟ: vvvv (INFGRUPA)
๐๐น๐ฎ๐ถ๐บ: Breached government website, data released for free
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~60,000 records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ช๐จ Revista Vistazo allegedly targeted in data leak exposing credit card info
A threat actor on an underground forum is claiming to have leaked a dataset allegedly originating from Revista Vistazo, an Ecuadorian magazine and media organization. The actor is releasing the data for free.
The actor claims the leak exposes roughly 19K Ecuadorians, including subscriber and payment card information.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข ID numbers (Cรฉdula / CI-Ecuador)
โข Email addresses
โข Phone numbers
โข Shipping addresses
โข Credit card details (cardholder, partial number, type, expiration)
โข Subscription plan and payment data
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Revista Vistazo
๐๐ผ๐๐ป๐๐ฟ๐: Ecuador ๐ช๐จ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Media / Publishing
๐๐ฐ๐๐ผ๐ฟ: GondorPe
๐๐น๐ฎ๐ถ๐บ: Data leak with credit card information
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~19K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked a dataset allegedly originating from Revista Vistazo, an Ecuadorian magazine and media organization. The actor is releasing the data for free.
The actor claims the leak exposes roughly 19K Ecuadorians, including subscriber and payment card information.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข ID numbers (Cรฉdula / CI-Ecuador)
โข Email addresses
โข Phone numbers
โข Shipping addresses
โข Credit card details (cardholder, partial number, type, expiration)
โข Subscription plan and payment data
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Revista Vistazo
๐๐ผ๐๐ป๐๐ฟ๐: Ecuador ๐ช๐จ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Media / Publishing
๐๐ฐ๐๐ผ๐ฟ: GondorPe
๐๐น๐ฎ๐ถ๐บ: Data leak with credit card information
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~19K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ฒ๐ฝ CECyTE Coahuila allegedly targeted in database leak
A threat actor on an underground forum is claiming to have leaked databases allegedly originating from CECyTE Coahuila, a public technical education institution in Coahuila, Mexico.
The actor claims the leak contains over 30K records covering suppliers, students, teachers, and administrators.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Suppliers (proveedores)
โข Students (alumnos)
โข Teachers (docentes)
โข Administrators (administrativos)
โข Usernames and passwords (hashed)
โข Full names, emails, phone numbers
โข Employee numbers and bank account fields
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: CECyTE Coahuila
๐๐ผ๐๐ป๐๐ฟ๐: Mexico ๐ฒ๐ฝ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education
๐๐ฐ๐๐ผ๐ฟ: hackstage
๐๐น๐ฎ๐ถ๐บ: Leaked databases
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: +30K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked databases allegedly originating from CECyTE Coahuila, a public technical education institution in Coahuila, Mexico.
The actor claims the leak contains over 30K records covering suppliers, students, teachers, and administrators.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Suppliers (proveedores)
โข Students (alumnos)
โข Teachers (docentes)
โข Administrators (administrativos)
โข Usernames and passwords (hashed)
โข Full names, emails, phone numbers
โข Employee numbers and bank account fields
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: CECyTE Coahuila
๐๐ผ๐๐ป๐๐ฟ๐: Mexico ๐ฒ๐ฝ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education
๐๐ฐ๐๐ผ๐ฟ: hackstage
๐๐น๐ฎ๐ถ๐บ: Leaked databases
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: +30K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ท๐ธ BeotelNet (Telekom Serbia) allegedly targeted in customer database breach
A threat actor on an underground forum is claiming to have breached BeotelNet, a Telekom company in Serbia, and extracted customers' sensitive information. The actor says customers using ADSL, fixed broadband, Wi-Fi, fiber/Ethernet, business internet, IPTV/TV, VoIP telephony, web hosting, VPS/cloud, data center, and carrier services may be affected.
The actor claims to hold over 150,000 records spanning 2020 to 2026, and threatens to publish the database on June 1, 2026 if no agreement is reached.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข JMBG (Unique Master Citizen Number)
โข Addresses
โข Cities
โข Postal codes
โข Phone numbers
โข Cell phone numbers
โข Email addresses
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: BeotelNet (Telekom Serbia)
๐๐ผ๐๐ป๐๐ฟ๐: Serbia ๐ท๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Telecom
๐๐ฐ๐๐ผ๐ฟ: QilinZeus
๐๐น๐ฎ๐ถ๐บ: Breached customer database, threatening publication
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 150,000+ records (2020 to 2026)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Extortion (publication threatened June 1, 2026)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have breached BeotelNet, a Telekom company in Serbia, and extracted customers' sensitive information. The actor says customers using ADSL, fixed broadband, Wi-Fi, fiber/Ethernet, business internet, IPTV/TV, VoIP telephony, web hosting, VPS/cloud, data center, and carrier services may be affected.
The actor claims to hold over 150,000 records spanning 2020 to 2026, and threatens to publish the database on June 1, 2026 if no agreement is reached.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข JMBG (Unique Master Citizen Number)
โข Addresses
โข Cities
โข Postal codes
โข Phone numbers
โข Cell phone numbers
โข Email addresses
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: BeotelNet (Telekom Serbia)
๐๐ผ๐๐ป๐๐ฟ๐: Serbia ๐ท๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Telecom
๐๐ฐ๐๐ผ๐ฟ: QilinZeus
๐๐น๐ฎ๐ถ๐บ: Breached customer database, threatening publication
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 150,000+ records (2020 to 2026)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Extortion (publication threatened June 1, 2026)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โผ๏ธ New Dark Web Informer Blog Post!
Title: Root in One Request: Pre-Auth RCE in Marimo (CVE-2026-39987)
Link: https://darkwebinformer.com/root-in-one-request-pre-auth-rce-in-marimo-cve-2026-39987/
Title: Root in One Request: Pre-Auth RCE in Marimo (CVE-2026-39987)
Link: https://darkwebinformer.com/root-in-one-request-pre-auth-rce-in-marimo-cve-2026-39987/
Dark Web Informer
Root in One Request: Pre-Auth RCE in Marimo (CVE-2026-39987)
CVE-2026-39987 is a critical pre-authentication remote code execution flaw in Marimo, a popular open-source reactive Python notebook framework and a modern alternative to Jupyter with roughly 19.6k GitHub stars.
Media is too big
VIEW IN TELEGRAM
How a Billion-Dollar Cybercrime Empire Took Root in Cambodia
Video Credit: youtube.com/@business
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
Video Credit: youtube.com/@business
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
This is one of the reasons why I do not actively monitor forums that require a big fee just to join. It's not worth it.
RIP DaMaGeLaB.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
RIP DaMaGeLaB.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โผ๏ธ๐ธ๐ฆ 0day Syndicate names Braincell as a victim
Brancell is a Riyadh-based startup that provides AI, automation, real-time analytics, and business process mapping solutions to improve operational efficiency.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
Brancell is a Riyadh-based startup that provides AI, automation, real-time analytics, and business process mapping solutions to improve operational efficiency.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ 0day Syndicate has a security check page... /verify.php?id=1&confirm_hash= that tells people not to scrape their information.
The funny thing is that the onion url at the bottom of the security check message goes to 0APT which shows the hacked KRYBIT message from earlier this month.
Clicking the verify human button takes you to 0day Syndicate.
Possible rebrand?
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
The funny thing is that the onion url at the bottom of the security check message goes to 0APT which shows the hacked KRYBIT message from earlier this month.
Clicking the verify human button takes you to 0day Syndicate.
Possible rebrand?
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐ช Slice For Life - Part 2 ๐ช
๐จ 0day Syndicate has a security check page... /verify.php?id=1&confirm_hash= that tells people not to scrape their information. The funny thing is that the onion url at the bottom of the security check message goes to 0APT which shows the hacked KRYBIT messageโฆ
Note, this security check page never shows when going directly to the site, the page was found using a directory search.
Cybersecurity Incident Disclosure
Fri, 29 May 2026 16:05:38 EDT
A cybersecurity incident has been disclosed by ORRSTOWN FINANCIAL SERVICES INC, Inc CIK: 0000826154, Ticker: $ORRF.
View SEC Filing
Fri, 29 May 2026 16:05:38 EDT
A cybersecurity incident has been disclosed by ORRSTOWN FINANCIAL SERVICES INC, Inc CIK: 0000826154, Ticker: $ORRF.
View SEC Filing
๐จ๐ฒ๐ฆ Multiple Moroccan government and corporate databases allegedly listed for sale
A threat actor on an underground forum is claiming to sell a bunch of Moroccan databases, attributed to a group/dumper known as PKA291. The listing spans both government-related and corporate datasets.
The actor claims the combined datasets total millions of records across justice, transport, training, and private sector entities.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Ministry of Justice (2 million documents, 150K lawsuit cases) - $3,000
โข NARSA (2 million lines) - $800
โข RADEM Maroc (1.1 million documents) - $600
โข OFPPT (400K lines) - $300
โข LNM6 (95K documents) - $500
โข Delivery companies (8 million lines) - $1,800
โข Insurance company (initial access) - $600
โข Other companies (500K lines) - $350
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Multiple Moroccan government and corporate entities
๐๐ผ๐๐ป๐๐ฟ๐: Morocco ๐ฒ๐ฆ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Multiple
๐๐ฐ๐๐ผ๐ฟ: anisanas2 (dumped by PKA291)
๐๐น๐ฎ๐ถ๐บ: Multiple databases for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Millions of records across multiple datasets
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Individual listings $300 to $3,000; special offer $5,500 for all
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a bunch of Moroccan databases, attributed to a group/dumper known as PKA291. The listing spans both government-related and corporate datasets.
The actor claims the combined datasets total millions of records across justice, transport, training, and private sector entities.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Ministry of Justice (2 million documents, 150K lawsuit cases) - $3,000
โข NARSA (2 million lines) - $800
โข RADEM Maroc (1.1 million documents) - $600
โข OFPPT (400K lines) - $300
โข LNM6 (95K documents) - $500
โข Delivery companies (8 million lines) - $1,800
โข Insurance company (initial access) - $600
โข Other companies (500K lines) - $350
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Multiple Moroccan government and corporate entities
๐๐ผ๐๐ป๐๐ฟ๐: Morocco ๐ฒ๐ฆ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Multiple
๐๐ฐ๐๐ผ๐ฟ: anisanas2 (dumped by PKA291)
๐๐น๐ฎ๐ถ๐บ: Multiple databases for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Millions of records across multiple datasets
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Individual listings $300 to $3,000; special offer $5,500 for all
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐ช Slice For Life - Part 2 ๐ช
John Daghita aka "lick" appeared yesterday morning before the indictment chamber of the Court of Appeal in Basse-Terre, where judges wereset to review an extradition request. The magistrates have reserved their decision until May 28. John Daghitaโs lawyerโฆ
John Daghita aka "lick" will be extradited back to the United States after a judge approved it. h/t: @vxdb
https://rci.fm/deuxiles/infos/Justice/Le-hacker-John-Daghita-soupconne-dun-vol-de-46-millions-de-dollars-en-cryptommonaie
https://rci.fm/deuxiles/infos/Justice/Le-hacker-John-Daghita-soupconne-dun-vol-de-46-millions-de-dollars-en-cryptommonaie
RCI
Le hacker John Daghita, soupรงonnรฉ d'un vol de 46 millions de dollars en cryptomonnaie, autorisรฉ ร rejoindre les รtats-Unis
Interpellรฉ ร Saint-Martin en mars dernier et soupรงonnรฉ d'avoir dรฉtournรฉ 46 millions de dollars en cryptomonnaies, le hacker amรฉricain John Daghita a obtenu le feu vert de la justice franรงaise pour son extradition rapide vers les รtats-Unis, oรน il doit รชtreโฆ
โผ๏ธ๐ณ๐ฑ LAPSUS$ Group has announced INGKA Group, the largest IKEA franchisee holding company, in a new listing.
The actor claims to be auctioning 180GB of internal data, with bidding starting at $100,000 USD.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
The actor claims to be auctioning 180GB of internal data, with bidding starting at $100,000 USD.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ Keybe.ai allegedly targeted in customer database leak
A threat actor on an underground forum is claiming that Keybe.ai, an AI platform, suffered a data breach in May 2026 resulting in the full compromise of its customer database.
The actor claims the leak contains roughly 1.9M CSV records (~156M in size), partially released.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Names and surnames
โข Cities
โข Email addresses
โข Phone numbers
โข Account status and creation dates
โข Service, campaign, and lead source data
โข Commercial agent and WhatsApp update fields
โข Comments and contact history
โข Various marketing and CRM metadata
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Keybe.ai
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Technology / AI Platform
๐๐ฐ๐๐ผ๐ฟ: zSenior
๐๐น๐ฎ๐ถ๐บ: Full customer database compromise
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~1,919,063 records (~156M)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming that Keybe.ai, an AI platform, suffered a data breach in May 2026 resulting in the full compromise of its customer database.
The actor claims the leak contains roughly 1.9M CSV records (~156M in size), partially released.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Names and surnames
โข Cities
โข Email addresses
โข Phone numbers
โข Account status and creation dates
โข Service, campaign, and lead source data
โข Commercial agent and WhatsApp update fields
โข Comments and contact history
โข Various marketing and CRM metadata
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Keybe.ai
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Technology / AI Platform
๐๐ฐ๐๐ผ๐ฟ: zSenior
๐๐น๐ฎ๐ถ๐บ: Full customer database compromise
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~1,919,063 records (~156M)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โผ๏ธ๐บ๐ธ DentaQuest has had 234GB+ leaked on to ShinyHunters Pay or Leak Dark Web portal
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ช๐ธ Spain allegedly targeted in massive 19 million biometric photos and ID cards leak
A threat actor group on an underground forum, identifying as EsqueleSquad, is claiming to expose more than 19 million Spanish citizens and politicians in a consolidated 13 GB database. The actors claim the credentials were taken from the General Directorate of the Police system.
The actors claim the dataset contains biometric photos, ID cards, residence information, and emails.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Biometric photos of citizens
โข National ID cards (DNI)
โข Residence information
โข Email addresses
โข Full names and personal details
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: General Directorate of the Police (Spain)
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Law Enforcement
๐๐ฐ๐๐ผ๐ฟ: Skull1172 (EsqueleSquad)
๐๐น๐ฎ๐ถ๐บ: Leaked biometric photos and ID cards
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 19M+ records (~13 GB)
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor group on an underground forum, identifying as EsqueleSquad, is claiming to expose more than 19 million Spanish citizens and politicians in a consolidated 13 GB database. The actors claim the credentials were taken from the General Directorate of the Police system.
The actors claim the dataset contains biometric photos, ID cards, residence information, and emails.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Biometric photos of citizens
โข National ID cards (DNI)
โข Residence information
โข Email addresses
โข Full names and personal details
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: General Directorate of the Police (Spain)
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Law Enforcement
๐๐ฐ๐๐ผ๐ฟ: Skull1172 (EsqueleSquad)
๐๐น๐ฎ๐ถ๐บ: Leaked biometric photos and ID cards
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 19M+ records (~13 GB)
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โค3