๐จ๐ซ๐ท Air Austral allegedly targeted in database leak
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from Air Austral, a French airline specializing in flights between the Indian Ocean, metropolitan France, southern Africa, and certain Asian destinations. The actor is releasing the data for free.
The actor claims the leak contains roughly 1K records in JSON format (~125 KB), appearing to be employee/staff data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Email addresses
โข Job titles (fonction)
โข Department/service
โข Location (localisation)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Air Austral
๐๐ผ๐๐ป๐๐ฟ๐: France ๐ซ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Aviation / Airline
๐๐ฐ๐๐ผ๐ฟ: ChimeraZ
๐๐น๐ฎ๐ถ๐บ: Leaked database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~1K records (~125 KB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from Air Austral, a French airline specializing in flights between the Indian Ocean, metropolitan France, southern Africa, and certain Asian destinations. The actor is releasing the data for free.
The actor claims the leak contains roughly 1K records in JSON format (~125 KB), appearing to be employee/staff data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Email addresses
โข Job titles (fonction)
โข Department/service
โข Location (localisation)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Air Austral
๐๐ผ๐๐ป๐๐ฟ๐: France ๐ซ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Aviation / Airline
๐๐ฐ๐๐ผ๐ฟ: ChimeraZ
๐๐น๐ฎ๐ถ๐บ: Leaked database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~1K records (~125 KB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ฌ๐ง๐ฎ๐ช Nando's allegedly targeted in employee database breach
A threat actor on an underground forum is claiming to sell an employee database allegedly originating from Nando's, the restaurant chain. The actor says the breach occurred as of May 30, 2026, and the data consists mainly of UK and Irish employees.
The actor claims the database contains 87,000 records of past and current "Nandoca" employees.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข Job titles and supervisory groups
โข Business and personal email addresses
โข Mobile and landline phone numbers
โข Employment locations
โข Employee roles
โข Business locations and numbers
โข Cost center information
โข Job listing information including salaries
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Nando's
๐๐ผ๐๐ป๐๐ฟ๐: United Kingdom ๐ฌ๐ง / Ireland ๐ฎ๐ช
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / Restaurant
๐๐ฐ๐๐ผ๐ฟ: failing2
๐๐น๐ฎ๐ถ๐บ: Leaked employee database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 87,000 records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: $1,000
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell an employee database allegedly originating from Nando's, the restaurant chain. The actor says the breach occurred as of May 30, 2026, and the data consists mainly of UK and Irish employees.
The actor claims the database contains 87,000 records of past and current "Nandoca" employees.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names
โข Job titles and supervisory groups
โข Business and personal email addresses
โข Mobile and landline phone numbers
โข Employment locations
โข Employee roles
โข Business locations and numbers
โข Cost center information
โข Job listing information including salaries
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Nando's
๐๐ผ๐๐ป๐๐ฟ๐: United Kingdom ๐ฌ๐ง / Ireland ๐ฎ๐ช
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / Restaurant
๐๐ฐ๐๐ผ๐ฟ: failing2
๐๐น๐ฎ๐ถ๐บ: Leaked employee database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 87,000 records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: $1,000
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ FedEx account checker tool advertised on underground forum
A threat actor on an underground forum is advertising a FedEx "mail pass" account checker, a credential-stuffing tool designed to validate stolen email/password combinations against FedEx accounts. The seller markets it as request-based with updated API handling and anti-bot bypass.
The listing promotes the tool to other forum members and claims it can pull account profile data from validated logins.
๐ช๐ต๐ฎ๐'๐ ๐ฏ๐ฒ๐ถ๐ป๐ด ๐ฎ๐ฑ๐๐ฒ๐ฟ๐๐ถ๐๐ฒ๐ฑ:
โข A request-based credential checker targeting FedEx accounts
โข Claimed anti-bot / WAF bypass handling
โข Automated validation of email:password combolists
โข Capture of account profile details from valid logins (name, contact info, address, account balance fields)
โข Marketed throughput of several hundred checks per minute
โข Sold as a single GO script copy
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: FedEx (account checker tooling)
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Cybercrime Tooling
๐๐ฐ๐๐ผ๐ฟ: DataKernel
๐๐น๐ฎ๐ถ๐บ: Selling FedEx credential-checking tool
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Account-validation / credential-stuffing tool
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Single copy (middleman accepted)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is advertising a FedEx "mail pass" account checker, a credential-stuffing tool designed to validate stolen email/password combinations against FedEx accounts. The seller markets it as request-based with updated API handling and anti-bot bypass.
The listing promotes the tool to other forum members and claims it can pull account profile data from validated logins.
๐ช๐ต๐ฎ๐'๐ ๐ฏ๐ฒ๐ถ๐ป๐ด ๐ฎ๐ฑ๐๐ฒ๐ฟ๐๐ถ๐๐ฒ๐ฑ:
โข A request-based credential checker targeting FedEx accounts
โข Claimed anti-bot / WAF bypass handling
โข Automated validation of email:password combolists
โข Capture of account profile details from valid logins (name, contact info, address, account balance fields)
โข Marketed throughput of several hundred checks per minute
โข Sold as a single GO script copy
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: FedEx (account checker tooling)
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Cybercrime Tooling
๐๐ฐ๐๐ผ๐ฟ: DataKernel
๐๐น๐ฎ๐ถ๐บ: Selling FedEx credential-checking tool
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Account-validation / credential-stuffing tool
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Single copy (middleman accepted)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ซ๐ท Avantages Enseignants allegedly targeted in 126K database leak
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from Avantages Enseignants, a French platform dedicated to education professionals (teachers and staff in the National Education system).
The actor claims the leak contains roughly 126K records across customer and account data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Email addresses
โข Passwords (hashed)
โข Telephone numbers
โข IP addresses
โข Fax and cart data
โข Tokens and codes
โข Account status and approval fields
โข Wishlist and custom field data
โข Profile pictures and newsletter status
โข Account creation and reminder timestamps
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Avantages Enseignants
๐๐ผ๐๐ป๐๐ฟ๐: France ๐ซ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education
๐๐ฐ๐๐ผ๐ฟ: kvantize
๐๐น๐ฎ๐ถ๐บ: Leaked database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~126K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 1 Point
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from Avantages Enseignants, a French platform dedicated to education professionals (teachers and staff in the National Education system).
The actor claims the leak contains roughly 126K records across customer and account data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Email addresses
โข Passwords (hashed)
โข Telephone numbers
โข IP addresses
โข Fax and cart data
โข Tokens and codes
โข Account status and approval fields
โข Wishlist and custom field data
โข Profile pictures and newsletter status
โข Account creation and reminder timestamps
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Avantages Enseignants
๐๐ผ๐๐ป๐๐ฟ๐: France ๐ซ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education
๐๐ฐ๐๐ผ๐ฟ: kvantize
๐๐น๐ฎ๐ถ๐บ: Leaked database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~126K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 1 Point
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐จ๐ด GamaSoft allegedly targeted in 150GB+ data breach
A threat actor on an underground forum is claiming to have exfiltrated data allegedly originating from GamaSoft, a Colombian company specializing in POS software for the food and beverage sector. The actor notes the company has over 25 years of experience, more than 4,200 installations across Colombia, and generates over 6 million invoices monthly.
The actor claims to have exfiltrated over 150 GB of data including software installers, databases, backups, invoices, and inventory information.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Client and contact names
โข Email addresses
โข Phone and mobile numbers
โข Addresses and municipality data
โข Representative names and identity documents
โข Business/owner details and roles
โข Tax and franchise data
โข Software installers and client databases
โข MySQL dumps (.csv, .sql) and backups from 2015 to 2017
โข PDF and XML invoices (facturas)
โข Support folder, activators, and software backups
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: GamaSoft
๐๐ผ๐๐ป๐๐ฟ๐: Colombia ๐จ๐ด
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Technology / POS Software
๐๐ฐ๐๐ผ๐ฟ: tillthaend
๐๐น๐ฎ๐ถ๐บ: Exfiltrated databases, clients, and software
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 150 GB+ of data
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free (reply to unlock)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have exfiltrated data allegedly originating from GamaSoft, a Colombian company specializing in POS software for the food and beverage sector. The actor notes the company has over 25 years of experience, more than 4,200 installations across Colombia, and generates over 6 million invoices monthly.
The actor claims to have exfiltrated over 150 GB of data including software installers, databases, backups, invoices, and inventory information.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Client and contact names
โข Email addresses
โข Phone and mobile numbers
โข Addresses and municipality data
โข Representative names and identity documents
โข Business/owner details and roles
โข Tax and franchise data
โข Software installers and client databases
โข MySQL dumps (.csv, .sql) and backups from 2015 to 2017
โข PDF and XML invoices (facturas)
โข Support folder, activators, and software backups
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: GamaSoft
๐๐ผ๐๐ป๐๐ฟ๐: Colombia ๐จ๐ด
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Technology / POS Software
๐๐ฐ๐๐ผ๐ฟ: tillthaend
๐๐น๐ฎ๐ถ๐บ: Exfiltrated databases, clients, and software
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 150 GB+ of data
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free (reply to unlock)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ฎ๐ท Hajj and Pilgrimage Organization allegedly targeted in breach exposing 168M+ records for $80,000 BTC
A threat actor on an underground forum is claiming to sell a database allegedly originating from the Hajj and Pilgrimage Organization in Iran, the government body managing pilgrimage travel.
The actor claims the dataset contains more than 168 million records spanning 1984 to 2024.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names, father's name, dates and places of birth
โข National codes (SSN), ID numbers, national card serial numbers
โข Marital status and occupation
โข Contact information (home/work addresses, postal codes, phone numbers)
โข Passport details (number, issue/expiration dates) and passport scans
โข Traveler photos
โข Travel flight and insurance information
โข Security deposit and banking/payment documents
โข Pilgrimage broker and accommodation information
โข Details of government officials, NAJA forces, Basij forces, and clerics
โข Allocated quota data (including martyr families)
โข Source code of Hajj apps and services
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Hajj and Pilgrimage Organization of Iran
๐๐ผ๐๐ป๐๐ฟ๐: Iran ๐ฎ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government
๐๐ฐ๐๐ผ๐ฟ: irleak
๐๐น๐ฎ๐ถ๐บ: Database for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 168M+ records (1984 to 2024)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: $80,000 BTC
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a database allegedly originating from the Hajj and Pilgrimage Organization in Iran, the government body managing pilgrimage travel.
The actor claims the dataset contains more than 168 million records spanning 1984 to 2024.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names, father's name, dates and places of birth
โข National codes (SSN), ID numbers, national card serial numbers
โข Marital status and occupation
โข Contact information (home/work addresses, postal codes, phone numbers)
โข Passport details (number, issue/expiration dates) and passport scans
โข Traveler photos
โข Travel flight and insurance information
โข Security deposit and banking/payment documents
โข Pilgrimage broker and accommodation information
โข Details of government officials, NAJA forces, Basij forces, and clerics
โข Allocated quota data (including martyr families)
โข Source code of Hajj apps and services
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Hajj and Pilgrimage Organization of Iran
๐๐ผ๐๐ป๐๐ฟ๐: Iran ๐ฎ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government
๐๐ฐ๐๐ผ๐ฟ: irleak
๐๐น๐ฎ๐ถ๐บ: Database for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 168M+ records (1984 to 2024)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: $80,000 BTC
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โค1
๐ช Slice For Life - Part 2 ๐ช
https://x.com/weezerOSINT/status/2061223556994965643
Telegram
Feds
Method:
vpn to match the target account country region > reset password> ask for more help > chat with AI > ask AI to switch email for you.
This lit allows u to pull 90% of IG accounts
Note: yall should help each other in @fedschat,
@FEDS
vpn to match the target account country region > reset password> ask for more help > chat with AI > ask AI to switch email for you.
This lit allows u to pull 90% of IG accounts
Note: yall should help each other in @fedschat,
@FEDS
๐ช Slice For Life - Part 2 ๐ช
https://t.me/feds/1024
Another video... https://x.com/i/status/2061253599758315527
X (formerly Twitter)
Dark Web Informer (@DarkWebInformer) on X
๐จ Instagram had an exploit that allowed you to use Meta AI to reset passwords to accounts with no MFA on them. The exploit was patched a short time ago.
๐จ๐ต๐ช DIRANDRO (Peruvian National Police) allegedly targeted by L4TAMFUCK3RS
A threat actor group on an underground forum, identifying as L4TAMFUCK3RS, is claiming to sell a full database allegedly originating from DIRANDRO, the specialized anti-drug-trafficking division of the Peruvian National Police (Policรญa Nacional del Perรบ). The actors claim all police/military personnel records are included.
The actors claim the database contains roughly 300K folders (people) totaling about 7.8 GB.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names, surnames, national ID numbers (DNI), and police ID codes (CIP)
โข Dates of birth, gender, marital status, education level
โข Parents' full names
โข Full residential addresses
โข Civil registry data and identification codes (NIF)
โข Police intervention/operation details and incident narratives
โข Exact event coordinates and penitentiary facility references
โข Seized substance details and evidence labels
โข Detained individuals' names, ages, and DNI numbers
โข Document metadata and institutional info (PNP, INPE, Public Prosecutor)
โข Internal personnel records (CIP, DNI, names, registration dates)
โข Scanned national ID document images and photographs
โข Military-related records
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: DIRANDRO (Policรญa Nacional del Perรบ)
๐๐ผ๐๐ป๐๐ฟ๐: Peru ๐ต๐ช
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Law Enforcement
๐๐ฐ๐๐ผ๐ฟ: cantpwn (L4TAMFUCK3RS)
๐๐น๐ฎ๐ถ๐บ: Full police database for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~300K folders/people (~7.8 GB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: $700
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor group on an underground forum, identifying as L4TAMFUCK3RS, is claiming to sell a full database allegedly originating from DIRANDRO, the specialized anti-drug-trafficking division of the Peruvian National Police (Policรญa Nacional del Perรบ). The actors claim all police/military personnel records are included.
The actors claim the database contains roughly 300K folders (people) totaling about 7.8 GB.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names, surnames, national ID numbers (DNI), and police ID codes (CIP)
โข Dates of birth, gender, marital status, education level
โข Parents' full names
โข Full residential addresses
โข Civil registry data and identification codes (NIF)
โข Police intervention/operation details and incident narratives
โข Exact event coordinates and penitentiary facility references
โข Seized substance details and evidence labels
โข Detained individuals' names, ages, and DNI numbers
โข Document metadata and institutional info (PNP, INPE, Public Prosecutor)
โข Internal personnel records (CIP, DNI, names, registration dates)
โข Scanned national ID document images and photographs
โข Military-related records
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: DIRANDRO (Policรญa Nacional del Perรบ)
๐๐ผ๐๐ป๐๐ฟ๐: Peru ๐ต๐ช
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Law Enforcement
๐๐ฐ๐๐ผ๐ฟ: cantpwn (L4TAMFUCK3RS)
๐๐น๐ฎ๐ถ๐บ: Full police database for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~300K folders/people (~7.8 GB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: $700
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ช๐ธ Spanish gas company allegedly targeted in database sale exposing IBANs and phones
A threat actor on an underground forum is claiming to sell a database allegedly belonging to a Spanish gas company. The actor describes the leads as fresh and says the data was obtained via a hack/vulnerability and has never been sold before.
The actor claims the database contains roughly 555K unique records including banking and contact details.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names (name, surname 1, surname 2)
โข Identification numbers and type
โข Phone numbers (two per record)
โข Email addresses
โข IBAN bank account numbers
โข Bank identifiers
โข Province, locality, and postal code
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Undisclosed Spanish gas company
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Energy / Utilities
๐๐ฐ๐๐ผ๐ฟ: jordanbelfortwolf
๐๐น๐ฎ๐ถ๐บ: Database for sale (obtained via hack/vulnerability)
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~555K unique records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (contact to purchase)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a database allegedly belonging to a Spanish gas company. The actor describes the leads as fresh and says the data was obtained via a hack/vulnerability and has never been sold before.
The actor claims the database contains roughly 555K unique records including banking and contact details.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names (name, surname 1, surname 2)
โข Identification numbers and type
โข Phone numbers (two per record)
โข Email addresses
โข IBAN bank account numbers
โข Bank identifiers
โข Province, locality, and postal code
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Undisclosed Spanish gas company
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Energy / Utilities
๐๐ฐ๐๐ผ๐ฟ: jordanbelfortwolf
๐๐น๐ฎ๐ถ๐บ: Database for sale (obtained via hack/vulnerability)
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~555K unique records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (contact to purchase)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โค1๐1
โผ๏ธ New Dark Web Informer Blog Post!
Title: Threat Actor Claims to Sell Live Web-Shell Access to a NASA Web Application
Link: https://darkwebinformer.com/threat-actor-claims-to-sell-live-web-shell-access-to-a-nasa-web-application/
Title: Threat Actor Claims to Sell Live Web-Shell Access to a NASA Web Application
Link: https://darkwebinformer.com/threat-actor-claims-to-sell-live-web-shell-access-to-a-nasa-web-application/
Dark Web Informer
Threat Actor Claims to Sell Live Web-Shell Access to a NASA Web Application
A threat actor using the alias hackformetome claims to be selling persistent web-shell access and a related exploit to a compromised NASA .gov web application, advertising remote code execution and the ability to pivot into internal network ranges.
๐จ Nornikovik hidden browser malware advertised on underground forum
A threat actor on an underground forum is advertising Nornikovik, a hidden-browser malware marketed as fileless and undetected. The seller describes it as a tool that runs a victim's browser silently in the background, lets the operator control it remotely, and can load the victim's saved browser data.
The listing promotes the tool to other forum members for the purpose of covert remote browser session hijacking and data theft.
๐ช๐ต๐ฎ๐'๐ ๐ฏ๐ฒ๐ถ๐ป๐ด ๐ฎ๐ฑ๐๐ฒ๐ฟ๐๐ถ๐๐ฒ๐ฑ:
โข A covert ("hidden") remote browser controlled by the attacker
โข Claimed fileless operation and self-deletion after execution
โข Ability to load victim browser data (cookies and autofills)
โข Support for multiple mainstream browsers (Chrome, Edge, Brave, Yandex, OperaGX, Vivaldi)
โข Claimed anti-analysis and anti-VM features
โข Multiple persistence methods
โข A builder and listener interface
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: N/A (offensive malware)
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Cybercrime Tooling / Malware-as-a-Service
๐๐ฐ๐๐ผ๐ฟ: solitaryElite
๐๐น๐ฎ๐ถ๐บ: Selling fileless hidden-browser malware
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Covert browser session hijacking and data theft tool
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Listed via autobuy (middleman accepted)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is advertising Nornikovik, a hidden-browser malware marketed as fileless and undetected. The seller describes it as a tool that runs a victim's browser silently in the background, lets the operator control it remotely, and can load the victim's saved browser data.
The listing promotes the tool to other forum members for the purpose of covert remote browser session hijacking and data theft.
๐ช๐ต๐ฎ๐'๐ ๐ฏ๐ฒ๐ถ๐ป๐ด ๐ฎ๐ฑ๐๐ฒ๐ฟ๐๐ถ๐๐ฒ๐ฑ:
โข A covert ("hidden") remote browser controlled by the attacker
โข Claimed fileless operation and self-deletion after execution
โข Ability to load victim browser data (cookies and autofills)
โข Support for multiple mainstream browsers (Chrome, Edge, Brave, Yandex, OperaGX, Vivaldi)
โข Claimed anti-analysis and anti-VM features
โข Multiple persistence methods
โข A builder and listener interface
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: N/A (offensive malware)
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Cybercrime Tooling / Malware-as-a-Service
๐๐ฐ๐๐ผ๐ฟ: solitaryElite
๐๐น๐ฎ๐ถ๐บ: Selling fileless hidden-browser malware
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Covert browser session hijacking and data theft tool
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Listed via autobuy (middleman accepted)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ซ๐ท Le Mรฉdia Pour Tous allegedly targeted in 13K database leak
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from Le Mรฉdia Pour Tous, an independent French media outlet created by Vincent Lapierre. The actor notes the data is not from the current year.
The actor claims the leak contains roughly 13K records across user and account data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Usernames and login names
โข Passwords (hashed)
โข First and last names / nicknames
โข Email addresses
โข User URLs
โข Registration dates and display names
โข User roles and account status
โข Session tokens
โข Account settings and metadata
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Le Mรฉdia Pour Tous
๐๐ผ๐๐ป๐๐ฟ๐: France ๐ซ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Media / Publishing
๐๐ฐ๐๐ผ๐ฟ: kvantize
๐๐น๐ฎ๐ถ๐บ: Leaked database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~13K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 1 Point
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from Le Mรฉdia Pour Tous, an independent French media outlet created by Vincent Lapierre. The actor notes the data is not from the current year.
The actor claims the leak contains roughly 13K records across user and account data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Usernames and login names
โข Passwords (hashed)
โข First and last names / nicknames
โข Email addresses
โข User URLs
โข Registration dates and display names
โข User roles and account status
โข Session tokens
โข Account settings and metadata
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Le Mรฉdia Pour Tous
๐๐ผ๐๐ป๐๐ฟ๐: France ๐ซ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Media / Publishing
๐๐ฐ๐๐ผ๐ฟ: kvantize
๐๐น๐ฎ๐ถ๐บ: Leaked database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~13K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 1 Point
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ฎ๐น Burger King Italy allegedly targeted in 5M database leak
A threat actor on an underground forum is claiming to sell a database allegedly originating from Burger King Italy, the well-established fast-food chain with more than 150 restaurants in the country.
The actor claims the database contains roughly 5M records, appearing to be loyalty program customer data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Email addresses
โข Loyalty card codes
โข Points and ranking points
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Burger King Italy
๐๐ผ๐๐ป๐๐ฟ๐: Italy ๐ฎ๐น
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / Restaurant
๐๐ฐ๐๐ผ๐ฟ: kvantize
๐๐น๐ฎ๐ถ๐บ: Database for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~5M records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (contact to purchase)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a database allegedly originating from Burger King Italy, the well-established fast-food chain with more than 150 restaurants in the country.
The actor claims the database contains roughly 5M records, appearing to be loyalty program customer data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Email addresses
โข Loyalty card codes
โข Points and ranking points
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Burger King Italy
๐๐ผ๐๐ป๐๐ฟ๐: Italy ๐ฎ๐น
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / Restaurant
๐๐ฐ๐๐ผ๐ฟ: kvantize
๐๐น๐ฎ๐ถ๐บ: Database for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~5M records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (contact to purchase)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐น๐ท Goknur Gida allegedly targeted in 10.7 TB breach with a ransom of 25 BTC
A threat actor on an underground forum is claiming to sell data allegedly originating from Goknur Gida A.ล., a Turkish food and beverage manufacturer. The actor claims to have compromised the company's infrastructure including Active Directory, SCADA/PLC systems, and virtualization environment.
The actor claims the breach totals roughly 10.7 TB, including 5.2 TB of backups, 3.3 TB of file servers, and 2.2 TB of user data and documents.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Active Directory architecture and NTDS.dit dumps
โข SCADA, PLC, and RTU configurations
โข Network device, ESXi, and virtualization infrastructure data
โข Customer information, contracts, and commercial data
โข Bank account information, financial records, and cash flow
โข Employee salary sheets, Turkish ID numbers, and authentication data
โข Employee passport information
โข Employee and executive phone numbers and contact directory
โข Production recipes, formulas, and industrial know-how
โข Product designs, CAD drawings, R&D data, and patents
โข Supply chain, procurement, and logistics data
โข Raw material, inventory, and stock management databases
โข ERP and CRM systems
โข IT infrastructure, backups, cybersecurity protocols, and firewall rules
โข Subcontractor, distributor, dealer, and service provider contracts
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Goknur Gida A.ล.
๐๐ผ๐๐ป๐๐ฟ๐: Turkey ๐น๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Food and Beverage / Manufacturing
๐๐ฐ๐๐ผ๐ฟ: DreamFyre
๐๐น๐ฎ๐ถ๐บ: Full infrastructure breach for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~10.7 TB
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 25 BTC
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell data allegedly originating from Goknur Gida A.ล., a Turkish food and beverage manufacturer. The actor claims to have compromised the company's infrastructure including Active Directory, SCADA/PLC systems, and virtualization environment.
The actor claims the breach totals roughly 10.7 TB, including 5.2 TB of backups, 3.3 TB of file servers, and 2.2 TB of user data and documents.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Active Directory architecture and NTDS.dit dumps
โข SCADA, PLC, and RTU configurations
โข Network device, ESXi, and virtualization infrastructure data
โข Customer information, contracts, and commercial data
โข Bank account information, financial records, and cash flow
โข Employee salary sheets, Turkish ID numbers, and authentication data
โข Employee passport information
โข Employee and executive phone numbers and contact directory
โข Production recipes, formulas, and industrial know-how
โข Product designs, CAD drawings, R&D data, and patents
โข Supply chain, procurement, and logistics data
โข Raw material, inventory, and stock management databases
โข ERP and CRM systems
โข IT infrastructure, backups, cybersecurity protocols, and firewall rules
โข Subcontractor, distributor, dealer, and service provider contracts
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Goknur Gida A.ล.
๐๐ผ๐๐ป๐๐ฟ๐: Turkey ๐น๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Food and Beverage / Manufacturing
๐๐ฐ๐๐ผ๐ฟ: DreamFyre
๐๐น๐ฎ๐ถ๐บ: Full infrastructure breach for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~10.7 TB
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 25 BTC
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations