Cybersecurity Incident Disclosure
Fri, 29 May 2026 16:05:38 EDT
A cybersecurity incident has been disclosed by ORRSTOWN FINANCIAL SERVICES INC, Inc CIK: 0000826154, Ticker: $ORRF.
View SEC Filing
Fri, 29 May 2026 16:05:38 EDT
A cybersecurity incident has been disclosed by ORRSTOWN FINANCIAL SERVICES INC, Inc CIK: 0000826154, Ticker: $ORRF.
View SEC Filing
๐จ๐ฒ๐ฆ Multiple Moroccan government and corporate databases allegedly listed for sale
A threat actor on an underground forum is claiming to sell a bunch of Moroccan databases, attributed to a group/dumper known as PKA291. The listing spans both government-related and corporate datasets.
The actor claims the combined datasets total millions of records across justice, transport, training, and private sector entities.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Ministry of Justice (2 million documents, 150K lawsuit cases) - $3,000
โข NARSA (2 million lines) - $800
โข RADEM Maroc (1.1 million documents) - $600
โข OFPPT (400K lines) - $300
โข LNM6 (95K documents) - $500
โข Delivery companies (8 million lines) - $1,800
โข Insurance company (initial access) - $600
โข Other companies (500K lines) - $350
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Multiple Moroccan government and corporate entities
๐๐ผ๐๐ป๐๐ฟ๐: Morocco ๐ฒ๐ฆ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Multiple
๐๐ฐ๐๐ผ๐ฟ: anisanas2 (dumped by PKA291)
๐๐น๐ฎ๐ถ๐บ: Multiple databases for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Millions of records across multiple datasets
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Individual listings $300 to $3,000; special offer $5,500 for all
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a bunch of Moroccan databases, attributed to a group/dumper known as PKA291. The listing spans both government-related and corporate datasets.
The actor claims the combined datasets total millions of records across justice, transport, training, and private sector entities.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Ministry of Justice (2 million documents, 150K lawsuit cases) - $3,000
โข NARSA (2 million lines) - $800
โข RADEM Maroc (1.1 million documents) - $600
โข OFPPT (400K lines) - $300
โข LNM6 (95K documents) - $500
โข Delivery companies (8 million lines) - $1,800
โข Insurance company (initial access) - $600
โข Other companies (500K lines) - $350
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Multiple Moroccan government and corporate entities
๐๐ผ๐๐ป๐๐ฟ๐: Morocco ๐ฒ๐ฆ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Multiple
๐๐ฐ๐๐ผ๐ฟ: anisanas2 (dumped by PKA291)
๐๐น๐ฎ๐ถ๐บ: Multiple databases for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Millions of records across multiple datasets
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Individual listings $300 to $3,000; special offer $5,500 for all
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐ช Slice For Life - Part 2 ๐ช
John Daghita aka "lick" appeared yesterday morning before the indictment chamber of the Court of Appeal in Basse-Terre, where judges wereset to review an extradition request. The magistrates have reserved their decision until May 28. John Daghitaโs lawyerโฆ
John Daghita aka "lick" will be extradited back to the United States after a judge approved it. h/t: @vxdb
https://rci.fm/deuxiles/infos/Justice/Le-hacker-John-Daghita-soupconne-dun-vol-de-46-millions-de-dollars-en-cryptommonaie
https://rci.fm/deuxiles/infos/Justice/Le-hacker-John-Daghita-soupconne-dun-vol-de-46-millions-de-dollars-en-cryptommonaie
RCI
Le hacker John Daghita, soupรงonnรฉ d'un vol de 46 millions de dollars en cryptomonnaie, autorisรฉ ร rejoindre les รtats-Unis
Interpellรฉ ร Saint-Martin en mars dernier et soupรงonnรฉ d'avoir dรฉtournรฉ 46 millions de dollars en cryptomonnaies, le hacker amรฉricain John Daghita a obtenu le feu vert de la justice franรงaise pour son extradition rapide vers les รtats-Unis, oรน il doit รชtreโฆ
โผ๏ธ๐ณ๐ฑ LAPSUS$ Group has announced INGKA Group, the largest IKEA franchisee holding company, in a new listing.
The actor claims to be auctioning 180GB of internal data, with bidding starting at $100,000 USD.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
The actor claims to be auctioning 180GB of internal data, with bidding starting at $100,000 USD.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ Keybe.ai allegedly targeted in customer database leak
A threat actor on an underground forum is claiming that Keybe.ai, an AI platform, suffered a data breach in May 2026 resulting in the full compromise of its customer database.
The actor claims the leak contains roughly 1.9M CSV records (~156M in size), partially released.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Names and surnames
โข Cities
โข Email addresses
โข Phone numbers
โข Account status and creation dates
โข Service, campaign, and lead source data
โข Commercial agent and WhatsApp update fields
โข Comments and contact history
โข Various marketing and CRM metadata
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Keybe.ai
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Technology / AI Platform
๐๐ฐ๐๐ผ๐ฟ: zSenior
๐๐น๐ฎ๐ถ๐บ: Full customer database compromise
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~1,919,063 records (~156M)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming that Keybe.ai, an AI platform, suffered a data breach in May 2026 resulting in the full compromise of its customer database.
The actor claims the leak contains roughly 1.9M CSV records (~156M in size), partially released.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Names and surnames
โข Cities
โข Email addresses
โข Phone numbers
โข Account status and creation dates
โข Service, campaign, and lead source data
โข Commercial agent and WhatsApp update fields
โข Comments and contact history
โข Various marketing and CRM metadata
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Keybe.ai
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Technology / AI Platform
๐๐ฐ๐๐ผ๐ฟ: zSenior
๐๐น๐ฎ๐ถ๐บ: Full customer database compromise
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~1,919,063 records (~156M)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 29, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โผ๏ธ๐บ๐ธ DentaQuest has had 234GB+ leaked on to ShinyHunters Pay or Leak Dark Web portal
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ช๐ธ Spain allegedly targeted in massive 19 million biometric photos and ID cards leak
A threat actor group on an underground forum, identifying as EsqueleSquad, is claiming to expose more than 19 million Spanish citizens and politicians in a consolidated 13 GB database. The actors claim the credentials were taken from the General Directorate of the Police system.
The actors claim the dataset contains biometric photos, ID cards, residence information, and emails.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Biometric photos of citizens
โข National ID cards (DNI)
โข Residence information
โข Email addresses
โข Full names and personal details
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: General Directorate of the Police (Spain)
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Law Enforcement
๐๐ฐ๐๐ผ๐ฟ: Skull1172 (EsqueleSquad)
๐๐น๐ฎ๐ถ๐บ: Leaked biometric photos and ID cards
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 19M+ records (~13 GB)
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor group on an underground forum, identifying as EsqueleSquad, is claiming to expose more than 19 million Spanish citizens and politicians in a consolidated 13 GB database. The actors claim the credentials were taken from the General Directorate of the Police system.
The actors claim the dataset contains biometric photos, ID cards, residence information, and emails.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Biometric photos of citizens
โข National ID cards (DNI)
โข Residence information
โข Email addresses
โข Full names and personal details
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: General Directorate of the Police (Spain)
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Law Enforcement
๐๐ฐ๐๐ผ๐ฟ: Skull1172 (EsqueleSquad)
๐๐น๐ฎ๐ถ๐บ: Leaked biometric photos and ID cards
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 19M+ records (~13 GB)
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โค3
๐จ๐ช๐ธ Podoservice allegedly targeted in 100K database sale
A threat actor on an underground forum is claiming to sell a database allegedly originating from Podoservice, a Spanish podiatry services platform.
The actor claims the database contains roughly 100K records across customer and contact data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Company and alias fields
โข Addresses, postal codes, and cities
โข Phone and mobile numbers
โข VAT numbers and DNI (national ID)
โข Email addresses
โข Passwords (hashed)
โข Dates of birth
โข Newsletter, registration IP, and account metadata
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Podoservice
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Healthcare / Podiatry Services
๐๐ฐ๐๐ผ๐ฟ: Sophia
๐๐น๐ฎ๐ถ๐บ: Database sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~100K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (contact to purchase)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a database allegedly originating from Podoservice, a Spanish podiatry services platform.
The actor claims the database contains roughly 100K records across customer and contact data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Company and alias fields
โข Addresses, postal codes, and cities
โข Phone and mobile numbers
โข VAT numbers and DNI (national ID)
โข Email addresses
โข Passwords (hashed)
โข Dates of birth
โข Newsletter, registration IP, and account metadata
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Podoservice
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Healthcare / Podiatry Services
๐๐ฐ๐๐ผ๐ฟ: Sophia
๐๐น๐ฎ๐ถ๐บ: Database sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~100K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (contact to purchase)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ช๐ธ Bambuy allegedly targeted in free database leak
A threat actor on an underground forum is claiming to have published a database allegedly originating from Bambuy, a Spanish e-commerce platform. The actor is releasing the data for free.
The actor claims the leaked SQL database contains customer and address records.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Company and alias fields
โข Addresses, postal codes, and cities
โข Phone and mobile numbers
โข VAT numbers and DNI (national ID)
โข Country and state data
โข Account creation and update timestamps
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Bambuy
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / E-commerce
๐๐ฐ๐๐ผ๐ฟ: Bambi
๐๐น๐ฎ๐ถ๐บ: Free database leak
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Customer and address records (SQL database)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have published a database allegedly originating from Bambuy, a Spanish e-commerce platform. The actor is releasing the data for free.
The actor claims the leaked SQL database contains customer and address records.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Company and alias fields
โข Addresses, postal codes, and cities
โข Phone and mobile numbers
โข VAT numbers and DNI (national ID)
โข Country and state data
โข Account creation and update timestamps
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Bambuy
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / E-commerce
๐๐ฐ๐๐ผ๐ฟ: Bambi
๐๐น๐ฎ๐ถ๐บ: Free database leak
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Customer and address records (SQL database)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐ญ1
๐จ๐ฒ๐ฝ INCODIS allegedly targeted in leak exposing 20,000+ users with disabilities
A threat actor on an underground forum, attributing the leak to a group called Olympus_Group, is claiming to have leaked data allegedly originating from INCODIS, the State of Colima's institute for the inclusion and protection of people with disabilities in Mexico. The actor is releasing the data for free.
The actor claims the leak contains over 20,000 users and 6,000 documents and photos.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข Photos
โข Personal documents
โข 6,000 documents and photos in total
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: INCODIS (State of Colima)
๐๐ผ๐๐ป๐๐ฟ๐: Mexico ๐ฒ๐ฝ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Social Services
๐๐ฐ๐๐ผ๐ฟ: Hermes_Olymp (Olympus_Group)
๐๐น๐ฎ๐ถ๐บ: Leaked user records, documents, and photos
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 20,000+ users, 6,000 documents and photos
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum, attributing the leak to a group called Olympus_Group, is claiming to have leaked data allegedly originating from INCODIS, the State of Colima's institute for the inclusion and protection of people with disabilities in Mexico. The actor is releasing the data for free.
The actor claims the leak contains over 20,000 users and 6,000 documents and photos.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข Photos
โข Personal documents
โข 6,000 documents and photos in total
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: INCODIS (State of Colima)
๐๐ผ๐๐ป๐๐ฟ๐: Mexico ๐ฒ๐ฝ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Social Services
๐๐ฐ๐๐ผ๐ฟ: Hermes_Olymp (Olympus_Group)
๐๐น๐ฎ๐ถ๐บ: Leaked user records, documents, and photos
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 20,000+ users, 6,000 documents and photos
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โค1
๐จ๐ญ๐ฐ Hong Kong school and food sector orgs allegedly targeted in 120K database leak
A threat actor group on an underground forum, identifying as Anka Red Team (TurkHackTeam), is claiming to have dumped a database allegedly originating from Hong Kong based school and food sector entities.
The actors claim the leak contains roughly 120,000 records, with targets listed as a Hong Kong education institution and a food sector company.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Member and company names
โข Member language and address fields
โข Usernames and login names
โข Passwords (hashed)
โข User emails
โข Account creation IPs and timestamps
โข User roles (including Administrator accounts)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Hong Kong school and food sector entities
๐๐ผ๐๐ป๐๐ฟ๐: Hong Kong ๐ญ๐ฐ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education / Food
๐๐ฐ๐๐ผ๐ฟ: 'SALDIRGAN (Anka Red Team / TurkHackTeam)
๐๐น๐ฎ๐ถ๐บ: Database dump
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~120,000 records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 3 Credits
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor group on an underground forum, identifying as Anka Red Team (TurkHackTeam), is claiming to have dumped a database allegedly originating from Hong Kong based school and food sector entities.
The actors claim the leak contains roughly 120,000 records, with targets listed as a Hong Kong education institution and a food sector company.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Member and company names
โข Member language and address fields
โข Usernames and login names
โข Passwords (hashed)
โข User emails
โข Account creation IPs and timestamps
โข User roles (including Administrator accounts)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Hong Kong school and food sector entities
๐๐ผ๐๐ป๐๐ฟ๐: Hong Kong ๐ญ๐ฐ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education / Food
๐๐ฐ๐๐ผ๐ฟ: 'SALDIRGAN (Anka Red Team / TurkHackTeam)
๐๐น๐ฎ๐ถ๐บ: Database dump
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~120,000 records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 3 Credits
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐จ๐ด Colombian government systems allegedly compromised by EsqueleSquad (150 GB)
A threat actor group on an underground forum, identifying as EsqueleSquad, is claiming to have compromised 15 official Colombian government databases, extracted directly from internal servers. The actors are threatening to release the full package after election day.
The actors claim to hold roughly 150 GB of data and around 75 million rows across critical national systems.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข DIAN - taxes, RUT, income tax returns, companies (48.5 GB)
โข Registradurรญa - IDs, biometrics, civil registry, electoral data (28.3 GB)
โข ICETEX - educational debts of millions (19.7 GB)
โข Colpensiones - pensions and financial data of retirees (16.8 GB)
โข ICFES - student exam results and educational data (24.7 GB combined)
โข Migraciรณn Colombia - passports, visas, migration records (9.1 GB)
โข Seguridad Social - EPS health affiliations and social security (7.4 GB)
โข Policรญa - internal National Police data (3.2 GB)
โข Fiscalรญa - criminal investigations and legal cases (2.8 GB)
โข DANE, CNSC, Gobierno Bogotรก, Medellรญn, Datos.gov (national statistics, public competitions, city government, open data)
โข Intelligence reports, SISBEN + Prosperidad Social (15M+ records), and 2026 campaign financing data
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Multiple Colombian government agencies
๐๐ผ๐๐ป๐๐ฟ๐: Colombia ๐จ๐ด
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government
๐๐ฐ๐๐ผ๐ฟ: Skull1172 (EsqueleSquad)
๐๐น๐ฎ๐ถ๐บ: 15 official government databases compromised
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~75 million rows (~155 GB total)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free (samples now, full release threatened after election day)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor group on an underground forum, identifying as EsqueleSquad, is claiming to have compromised 15 official Colombian government databases, extracted directly from internal servers. The actors are threatening to release the full package after election day.
The actors claim to hold roughly 150 GB of data and around 75 million rows across critical national systems.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข DIAN - taxes, RUT, income tax returns, companies (48.5 GB)
โข Registradurรญa - IDs, biometrics, civil registry, electoral data (28.3 GB)
โข ICETEX - educational debts of millions (19.7 GB)
โข Colpensiones - pensions and financial data of retirees (16.8 GB)
โข ICFES - student exam results and educational data (24.7 GB combined)
โข Migraciรณn Colombia - passports, visas, migration records (9.1 GB)
โข Seguridad Social - EPS health affiliations and social security (7.4 GB)
โข Policรญa - internal National Police data (3.2 GB)
โข Fiscalรญa - criminal investigations and legal cases (2.8 GB)
โข DANE, CNSC, Gobierno Bogotรก, Medellรญn, Datos.gov (national statistics, public competitions, city government, open data)
โข Intelligence reports, SISBEN + Prosperidad Social (15M+ records), and 2026 campaign financing data
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Multiple Colombian government agencies
๐๐ผ๐๐ป๐๐ฟ๐: Colombia ๐จ๐ด
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government
๐๐ฐ๐๐ผ๐ฟ: Skull1172 (EsqueleSquad)
๐๐น๐ฎ๐ถ๐บ: 15 official government databases compromised
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~75 million rows (~155 GB total)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free (samples now, full release threatened after election day)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
Here are SOME features coming to the new Threat Feed in June.
- OCR Text Scanning. Click a button to scan the screenshot, wait a couple seconds and it will pull any links, session IDs, tox, telegrams from the screenshot back to you with easy to copy buttons
- Threat report generation. You can run it per Threat Alert or via bookmarks, the first 100 alerts, etc.
- Ability to search different APIs. I don't want to name openly for now.
- Search WhiteIntels stealer log database for any domain (no longer limited by alert). It will currently return only stats for that domain. But surely your company is safe, right? RIGHT?
- Search filters that are also now bound to the filtered export button. Multiple exports daily, not limited to 1.
Many new features coming. Just wanted to provide a simple update. Don't worry I'm cooking.
- OCR Text Scanning. Click a button to scan the screenshot, wait a couple seconds and it will pull any links, session IDs, tox, telegrams from the screenshot back to you with easy to copy buttons
- Threat report generation. You can run it per Threat Alert or via bookmarks, the first 100 alerts, etc.
- Ability to search different APIs. I don't want to name openly for now.
- Search WhiteIntels stealer log database for any domain (no longer limited by alert). It will currently return only stats for that domain. But surely your company is safe, right? RIGHT?
- Search filters that are also now bound to the filtered export button. Multiple exports daily, not limited to 1.
Many new features coming. Just wanted to provide a simple update. Don't worry I'm cooking.
โค1
๐จ GoldenBullet cracking tool advertised on underground forum
A threat actor on an underground forum marketplace is advertising GoldenBullet, an automation and web testing framework being promoted as a credential-stuffing and account-checking tool. The post markets version 2.1 with a refreshed UI and updated libraries.
The actor is promoting the tool's account-cracking, proxy, and config management capabilities to other forum users.
๐ช๐ต๐ฎ๐'๐ ๐ฏ๐ฒ๐ถ๐ป๐ด ๐ฎ๐ฑ๐๐ฒ๐ฟ๐๐ถ๐๐ฒ๐ฑ:
โข Multi-run job engine with bot/proxy stats and hit outputs to database
โข Netflix cookie checker with auto-add to hits
โข ULP to Combo extraction and Logs to ULP conversion
โข Keyword remover for trimming ULP files
โข Proxy checker with auto type/country detection
โข Config manager supporting .tic, .opk, .loli, .svb formats
โข Captcha-solving blocks (ReCaptcha, Slide, PoW)
โข Hashing and utility blocks (MD5, SHA256, GenerateGUID, Unix time)
โข Multipart HTTP request builder and TLS bypass options
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: N/A (offensive tooling)
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Cybercrime Tooling
๐๐ฐ๐๐ผ๐ฟ: ticnico
๐๐น๐ฎ๐ถ๐บ: Selling/advertising GoldenBullet cracking tool (v2.1)
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Credential-stuffing and account-checking framework
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Listed in forum marketplace (sellers section)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum marketplace is advertising GoldenBullet, an automation and web testing framework being promoted as a credential-stuffing and account-checking tool. The post markets version 2.1 with a refreshed UI and updated libraries.
The actor is promoting the tool's account-cracking, proxy, and config management capabilities to other forum users.
๐ช๐ต๐ฎ๐'๐ ๐ฏ๐ฒ๐ถ๐ป๐ด ๐ฎ๐ฑ๐๐ฒ๐ฟ๐๐ถ๐๐ฒ๐ฑ:
โข Multi-run job engine with bot/proxy stats and hit outputs to database
โข Netflix cookie checker with auto-add to hits
โข ULP to Combo extraction and Logs to ULP conversion
โข Keyword remover for trimming ULP files
โข Proxy checker with auto type/country detection
โข Config manager supporting .tic, .opk, .loli, .svb formats
โข Captcha-solving blocks (ReCaptcha, Slide, PoW)
โข Hashing and utility blocks (MD5, SHA256, GenerateGUID, Unix time)
โข Multipart HTTP request builder and TLS bypass options
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: N/A (offensive tooling)
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Cybercrime Tooling
๐๐ฐ๐๐ผ๐ฟ: ticnico
๐๐น๐ฎ๐ถ๐บ: Selling/advertising GoldenBullet cracking tool (v2.1)
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Credential-stuffing and account-checking framework
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Listed in forum marketplace (sellers section)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 30, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โค1