๐ช Slice For Life - Part 2 ๐ช
https://x.com/weezerOSINT/status/2061223556994965643
Telegram
Feds
Method:
vpn to match the target account country region > reset password> ask for more help > chat with AI > ask AI to switch email for you.
This lit allows u to pull 90% of IG accounts
Note: yall should help each other in @fedschat,
@FEDS
vpn to match the target account country region > reset password> ask for more help > chat with AI > ask AI to switch email for you.
This lit allows u to pull 90% of IG accounts
Note: yall should help each other in @fedschat,
@FEDS
๐ช Slice For Life - Part 2 ๐ช
https://t.me/feds/1024
Another video... https://x.com/i/status/2061253599758315527
X (formerly Twitter)
Dark Web Informer (@DarkWebInformer) on X
๐จ Instagram had an exploit that allowed you to use Meta AI to reset passwords to accounts with no MFA on them. The exploit was patched a short time ago.
๐จ๐ต๐ช DIRANDRO (Peruvian National Police) allegedly targeted by L4TAMFUCK3RS
A threat actor group on an underground forum, identifying as L4TAMFUCK3RS, is claiming to sell a full database allegedly originating from DIRANDRO, the specialized anti-drug-trafficking division of the Peruvian National Police (Policรญa Nacional del Perรบ). The actors claim all police/military personnel records are included.
The actors claim the database contains roughly 300K folders (people) totaling about 7.8 GB.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names, surnames, national ID numbers (DNI), and police ID codes (CIP)
โข Dates of birth, gender, marital status, education level
โข Parents' full names
โข Full residential addresses
โข Civil registry data and identification codes (NIF)
โข Police intervention/operation details and incident narratives
โข Exact event coordinates and penitentiary facility references
โข Seized substance details and evidence labels
โข Detained individuals' names, ages, and DNI numbers
โข Document metadata and institutional info (PNP, INPE, Public Prosecutor)
โข Internal personnel records (CIP, DNI, names, registration dates)
โข Scanned national ID document images and photographs
โข Military-related records
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: DIRANDRO (Policรญa Nacional del Perรบ)
๐๐ผ๐๐ป๐๐ฟ๐: Peru ๐ต๐ช
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Law Enforcement
๐๐ฐ๐๐ผ๐ฟ: cantpwn (L4TAMFUCK3RS)
๐๐น๐ฎ๐ถ๐บ: Full police database for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~300K folders/people (~7.8 GB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: $700
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor group on an underground forum, identifying as L4TAMFUCK3RS, is claiming to sell a full database allegedly originating from DIRANDRO, the specialized anti-drug-trafficking division of the Peruvian National Police (Policรญa Nacional del Perรบ). The actors claim all police/military personnel records are included.
The actors claim the database contains roughly 300K folders (people) totaling about 7.8 GB.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names, surnames, national ID numbers (DNI), and police ID codes (CIP)
โข Dates of birth, gender, marital status, education level
โข Parents' full names
โข Full residential addresses
โข Civil registry data and identification codes (NIF)
โข Police intervention/operation details and incident narratives
โข Exact event coordinates and penitentiary facility references
โข Seized substance details and evidence labels
โข Detained individuals' names, ages, and DNI numbers
โข Document metadata and institutional info (PNP, INPE, Public Prosecutor)
โข Internal personnel records (CIP, DNI, names, registration dates)
โข Scanned national ID document images and photographs
โข Military-related records
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: DIRANDRO (Policรญa Nacional del Perรบ)
๐๐ผ๐๐ป๐๐ฟ๐: Peru ๐ต๐ช
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Government / Law Enforcement
๐๐ฐ๐๐ผ๐ฟ: cantpwn (L4TAMFUCK3RS)
๐๐น๐ฎ๐ถ๐บ: Full police database for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~300K folders/people (~7.8 GB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: $700
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ช๐ธ Spanish gas company allegedly targeted in database sale exposing IBANs and phones
A threat actor on an underground forum is claiming to sell a database allegedly belonging to a Spanish gas company. The actor describes the leads as fresh and says the data was obtained via a hack/vulnerability and has never been sold before.
The actor claims the database contains roughly 555K unique records including banking and contact details.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names (name, surname 1, surname 2)
โข Identification numbers and type
โข Phone numbers (two per record)
โข Email addresses
โข IBAN bank account numbers
โข Bank identifiers
โข Province, locality, and postal code
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Undisclosed Spanish gas company
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Energy / Utilities
๐๐ฐ๐๐ผ๐ฟ: jordanbelfortwolf
๐๐น๐ฎ๐ถ๐บ: Database for sale (obtained via hack/vulnerability)
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~555K unique records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (contact to purchase)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a database allegedly belonging to a Spanish gas company. The actor describes the leads as fresh and says the data was obtained via a hack/vulnerability and has never been sold before.
The actor claims the database contains roughly 555K unique records including banking and contact details.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names (name, surname 1, surname 2)
โข Identification numbers and type
โข Phone numbers (two per record)
โข Email addresses
โข IBAN bank account numbers
โข Bank identifiers
โข Province, locality, and postal code
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Undisclosed Spanish gas company
๐๐ผ๐๐ป๐๐ฟ๐: Spain ๐ช๐ธ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Energy / Utilities
๐๐ฐ๐๐ผ๐ฟ: jordanbelfortwolf
๐๐น๐ฎ๐ถ๐บ: Database for sale (obtained via hack/vulnerability)
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~555K unique records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (contact to purchase)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 31, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โค1๐1
โผ๏ธ New Dark Web Informer Blog Post!
Title: Threat Actor Claims to Sell Live Web-Shell Access to a NASA Web Application
Link: https://darkwebinformer.com/threat-actor-claims-to-sell-live-web-shell-access-to-a-nasa-web-application/
Title: Threat Actor Claims to Sell Live Web-Shell Access to a NASA Web Application
Link: https://darkwebinformer.com/threat-actor-claims-to-sell-live-web-shell-access-to-a-nasa-web-application/
Dark Web Informer
Threat Actor Claims to Sell Live Web-Shell Access to a NASA Web Application
A threat actor using the alias hackformetome claims to be selling persistent web-shell access and a related exploit to a compromised NASA .gov web application, advertising remote code execution and the ability to pivot into internal network ranges.
๐จ Nornikovik hidden browser malware advertised on underground forum
A threat actor on an underground forum is advertising Nornikovik, a hidden-browser malware marketed as fileless and undetected. The seller describes it as a tool that runs a victim's browser silently in the background, lets the operator control it remotely, and can load the victim's saved browser data.
The listing promotes the tool to other forum members for the purpose of covert remote browser session hijacking and data theft.
๐ช๐ต๐ฎ๐'๐ ๐ฏ๐ฒ๐ถ๐ป๐ด ๐ฎ๐ฑ๐๐ฒ๐ฟ๐๐ถ๐๐ฒ๐ฑ:
โข A covert ("hidden") remote browser controlled by the attacker
โข Claimed fileless operation and self-deletion after execution
โข Ability to load victim browser data (cookies and autofills)
โข Support for multiple mainstream browsers (Chrome, Edge, Brave, Yandex, OperaGX, Vivaldi)
โข Claimed anti-analysis and anti-VM features
โข Multiple persistence methods
โข A builder and listener interface
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: N/A (offensive malware)
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Cybercrime Tooling / Malware-as-a-Service
๐๐ฐ๐๐ผ๐ฟ: solitaryElite
๐๐น๐ฎ๐ถ๐บ: Selling fileless hidden-browser malware
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Covert browser session hijacking and data theft tool
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Listed via autobuy (middleman accepted)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is advertising Nornikovik, a hidden-browser malware marketed as fileless and undetected. The seller describes it as a tool that runs a victim's browser silently in the background, lets the operator control it remotely, and can load the victim's saved browser data.
The listing promotes the tool to other forum members for the purpose of covert remote browser session hijacking and data theft.
๐ช๐ต๐ฎ๐'๐ ๐ฏ๐ฒ๐ถ๐ป๐ด ๐ฎ๐ฑ๐๐ฒ๐ฟ๐๐ถ๐๐ฒ๐ฑ:
โข A covert ("hidden") remote browser controlled by the attacker
โข Claimed fileless operation and self-deletion after execution
โข Ability to load victim browser data (cookies and autofills)
โข Support for multiple mainstream browsers (Chrome, Edge, Brave, Yandex, OperaGX, Vivaldi)
โข Claimed anti-analysis and anti-VM features
โข Multiple persistence methods
โข A builder and listener interface
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: N/A (offensive malware)
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Cybercrime Tooling / Malware-as-a-Service
๐๐ฐ๐๐ผ๐ฟ: solitaryElite
๐๐น๐ฎ๐ถ๐บ: Selling fileless hidden-browser malware
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Covert browser session hijacking and data theft tool
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Listed via autobuy (middleman accepted)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ซ๐ท Le Mรฉdia Pour Tous allegedly targeted in 13K database leak
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from Le Mรฉdia Pour Tous, an independent French media outlet created by Vincent Lapierre. The actor notes the data is not from the current year.
The actor claims the leak contains roughly 13K records across user and account data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Usernames and login names
โข Passwords (hashed)
โข First and last names / nicknames
โข Email addresses
โข User URLs
โข Registration dates and display names
โข User roles and account status
โข Session tokens
โข Account settings and metadata
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Le Mรฉdia Pour Tous
๐๐ผ๐๐ป๐๐ฟ๐: France ๐ซ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Media / Publishing
๐๐ฐ๐๐ผ๐ฟ: kvantize
๐๐น๐ฎ๐ถ๐บ: Leaked database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~13K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 1 Point
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from Le Mรฉdia Pour Tous, an independent French media outlet created by Vincent Lapierre. The actor notes the data is not from the current year.
The actor claims the leak contains roughly 13K records across user and account data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Usernames and login names
โข Passwords (hashed)
โข First and last names / nicknames
โข Email addresses
โข User URLs
โข Registration dates and display names
โข User roles and account status
โข Session tokens
โข Account settings and metadata
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Le Mรฉdia Pour Tous
๐๐ผ๐๐ป๐๐ฟ๐: France ๐ซ๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Media / Publishing
๐๐ฐ๐๐ผ๐ฟ: kvantize
๐๐น๐ฎ๐ถ๐บ: Leaked database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~13K records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 1 Point
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ฎ๐น Burger King Italy allegedly targeted in 5M database leak
A threat actor on an underground forum is claiming to sell a database allegedly originating from Burger King Italy, the well-established fast-food chain with more than 150 restaurants in the country.
The actor claims the database contains roughly 5M records, appearing to be loyalty program customer data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Email addresses
โข Loyalty card codes
โข Points and ranking points
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Burger King Italy
๐๐ผ๐๐ป๐๐ฟ๐: Italy ๐ฎ๐น
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / Restaurant
๐๐ฐ๐๐ผ๐ฟ: kvantize
๐๐น๐ฎ๐ถ๐บ: Database for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~5M records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (contact to purchase)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell a database allegedly originating from Burger King Italy, the well-established fast-food chain with more than 150 restaurants in the country.
The actor claims the database contains roughly 5M records, appearing to be loyalty program customer data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข First and last names
โข Email addresses
โข Loyalty card codes
โข Points and ranking points
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Burger King Italy
๐๐ผ๐๐ป๐๐ฟ๐: Italy ๐ฎ๐น
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / Restaurant
๐๐ฐ๐๐ผ๐ฟ: kvantize
๐๐น๐ฎ๐ถ๐บ: Database for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~5M records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Not disclosed (contact to purchase)
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐น๐ท Goknur Gida allegedly targeted in 10.7 TB breach with a ransom of 25 BTC
A threat actor on an underground forum is claiming to sell data allegedly originating from Goknur Gida A.ล., a Turkish food and beverage manufacturer. The actor claims to have compromised the company's infrastructure including Active Directory, SCADA/PLC systems, and virtualization environment.
The actor claims the breach totals roughly 10.7 TB, including 5.2 TB of backups, 3.3 TB of file servers, and 2.2 TB of user data and documents.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Active Directory architecture and NTDS.dit dumps
โข SCADA, PLC, and RTU configurations
โข Network device, ESXi, and virtualization infrastructure data
โข Customer information, contracts, and commercial data
โข Bank account information, financial records, and cash flow
โข Employee salary sheets, Turkish ID numbers, and authentication data
โข Employee passport information
โข Employee and executive phone numbers and contact directory
โข Production recipes, formulas, and industrial know-how
โข Product designs, CAD drawings, R&D data, and patents
โข Supply chain, procurement, and logistics data
โข Raw material, inventory, and stock management databases
โข ERP and CRM systems
โข IT infrastructure, backups, cybersecurity protocols, and firewall rules
โข Subcontractor, distributor, dealer, and service provider contracts
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Goknur Gida A.ล.
๐๐ผ๐๐ป๐๐ฟ๐: Turkey ๐น๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Food and Beverage / Manufacturing
๐๐ฐ๐๐ผ๐ฟ: DreamFyre
๐๐น๐ฎ๐ถ๐บ: Full infrastructure breach for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~10.7 TB
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 25 BTC
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to sell data allegedly originating from Goknur Gida A.ล., a Turkish food and beverage manufacturer. The actor claims to have compromised the company's infrastructure including Active Directory, SCADA/PLC systems, and virtualization environment.
The actor claims the breach totals roughly 10.7 TB, including 5.2 TB of backups, 3.3 TB of file servers, and 2.2 TB of user data and documents.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Active Directory architecture and NTDS.dit dumps
โข SCADA, PLC, and RTU configurations
โข Network device, ESXi, and virtualization infrastructure data
โข Customer information, contracts, and commercial data
โข Bank account information, financial records, and cash flow
โข Employee salary sheets, Turkish ID numbers, and authentication data
โข Employee passport information
โข Employee and executive phone numbers and contact directory
โข Production recipes, formulas, and industrial know-how
โข Product designs, CAD drawings, R&D data, and patents
โข Supply chain, procurement, and logistics data
โข Raw material, inventory, and stock management databases
โข ERP and CRM systems
โข IT infrastructure, backups, cybersecurity protocols, and firewall rules
โข Subcontractor, distributor, dealer, and service provider contracts
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Goknur Gida A.ล.
๐๐ผ๐๐ป๐๐ฟ๐: Turkey ๐น๐ท
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Food and Beverage / Manufacturing
๐๐ฐ๐๐ผ๐ฟ: DreamFyre
๐๐น๐ฎ๐ถ๐บ: Full infrastructure breach for sale
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~10.7 TB
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 25 BTC
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ฒ๐ฝ Instituto Tecnolรณgico del Valle de Etla allegedly targeted in database leak
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from the Instituto Tecnolรณgico del Valle de Etla, a technological institute in Oaxaca, Mexico. The actor is releasing the data for free.
The actor claims the leak contains student and applicant records with extensive personal and academic data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names (first name, paternal and maternal surnames)
โข Mobile phone numbers
โข Dates of birth
โข Email addresses (Gmail)
โข Gender and age
โข CURP (national ID) and UID
โข Application folio and status
โข State of birth and nationality
โข Campus ID
โข Indigenous language and disability fields
โข Income received (financial aid)
โข Municipality violence/marginalization indicators
โข School records (general average, periods)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Instituto Tecnolรณgico del Valle de Etla
๐๐ผ๐๐ป๐๐ฟ๐: Mexico ๐ฒ๐ฝ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education
๐๐ฐ๐๐ผ๐ฟ: MagoSpeak
๐๐น๐ฎ๐ถ๐บ: Leaked student/applicant database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Student and applicant records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from the Instituto Tecnolรณgico del Valle de Etla, a technological institute in Oaxaca, Mexico. The actor is releasing the data for free.
The actor claims the leak contains student and applicant records with extensive personal and academic data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names (first name, paternal and maternal surnames)
โข Mobile phone numbers
โข Dates of birth
โข Email addresses (Gmail)
โข Gender and age
โข CURP (national ID) and UID
โข Application folio and status
โข State of birth and nationality
โข Campus ID
โข Indigenous language and disability fields
โข Income received (financial aid)
โข Municipality violence/marginalization indicators
โข School records (general average, periods)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Instituto Tecnolรณgico del Valle de Etla
๐๐ผ๐๐ป๐๐ฟ๐: Mexico ๐ฒ๐ฝ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education
๐๐ฐ๐๐ผ๐ฟ: MagoSpeak
๐๐น๐ฎ๐ถ๐บ: Leaked student/applicant database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: Student and applicant records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
๐จ๐ฒ๐ฝ Universidad Tecnolรณgica del Centro allegedly targeted in 4,361-record leak
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from the Universidad Tecnolรณgica del Centro, a technological university in Mexico. The actor is releasing the data for free.
The actor claims the leak contains 4,361 student/applicant records with extensive personal and academic data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names (first name, paternal and maternal surnames)
โข Mobile phone numbers
โข Dates of birth
โข Email addresses (Gmail)
โข Gender and age
โข CURP (national ID) and UID
โข Application folio and status
โข State of birth and nationality
โข Campus ID and SIGED campus key
โข School record key and campus
โข Indigenous language and disability fields
โข Income received (financial aid)
โข Municipality violence/marginalization indicators
โข School records (general average, periods)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Universidad Tecnolรณgica del Centro
๐๐ผ๐๐ป๐๐ฟ๐: Mexico ๐ฒ๐ฝ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education
๐๐ฐ๐๐ผ๐ฟ: MagoSpeak
๐๐น๐ฎ๐ถ๐บ: Leaked student/applicant database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 4,361 records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
A threat actor on an underground forum is claiming to have leaked a database allegedly originating from the Universidad Tecnolรณgica del Centro, a technological university in Mexico. The actor is releasing the data for free.
The actor claims the leak contains 4,361 student/applicant records with extensive personal and academic data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Full names (first name, paternal and maternal surnames)
โข Mobile phone numbers
โข Dates of birth
โข Email addresses (Gmail)
โข Gender and age
โข CURP (national ID) and UID
โข Application folio and status
โข State of birth and nationality
โข Campus ID and SIGED campus key
โข School record key and campus
โข Indigenous language and disability fields
โข Income received (financial aid)
โข Municipality violence/marginalization indicators
โข School records (general average, periods)
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Universidad Tecnolรณgica del Centro
๐๐ผ๐๐ป๐๐ฟ๐: Mexico ๐ฒ๐ฝ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Education
๐๐ฐ๐๐ผ๐ฟ: MagoSpeak
๐๐น๐ฎ๐ถ๐บ: Leaked student/applicant database
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: 4,361 records
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: Free
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
โผ๏ธ New Dark Web Informer Blog Post!
Title: Threat Actor Claims to Sell 24 Million Confidential SENIAT Venezuela Tax Records, 30 GB
Link: https://darkwebinformer.com/threat-actor-claims-to-sell-24-million-confidential-seniat-venezuela-tax-records-30-gb/
Title: Threat Actor Claims to Sell 24 Million Confidential SENIAT Venezuela Tax Records, 30 GB
Link: https://darkwebinformer.com/threat-actor-claims-to-sell-24-million-confidential-seniat-venezuela-tax-records-30-gb/
Dark Web Informer
Threat Actor Claims to Sell 24 Million Confidential SENIAT Venezuela Tax Records, 30 GB
A threat actor using the alias malconguerra2 claims to be selling a 30 GB confidential dataset attributed to SENIAT, Venezuela's national tax and customs authority.
โผ๏ธ New Dark Web Informer Blog Post!
Title: Threat Actor Claims to Leak an INEGI Mexico Database Dump, 122K Businesses + 30K PII Records
Link: https://darkwebinformer.com/threat-actor-claims-to-leak-an-inegi-mexico-database-dump-122k-businesses-30k-pii-records/
Title: Threat Actor Claims to Leak an INEGI Mexico Database Dump, 122K Businesses + 30K PII Records
Link: https://darkwebinformer.com/threat-actor-claims-to-leak-an-inegi-mexico-database-dump-122k-businesses-30k-pii-records/
Dark Web Informer
Threat Actor Claims to Leak an INEGI Mexico Database Dump, 122K Businesses + 30K PII Records
A threat actor using the alias sativa claims to have leaked a database dump attributed to INEGI, Mexico's national statistics institute, allegedly sourced from internal GOB.MX services.
๐จ๐ช๐ฌ Homzmart allegedly targeted in database leak
A threat actor on an underground forum is claiming to publish the full database allegedly originating from Homzmart, a furniture and home goods e-commerce marketplace based in Egypt.
The actor claims the leak includes a partial dump of roughly 4 GB plus a separate sellers database (~600M), covering customer, order, and seller data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Customer records (~1M) and customer addresses (~1M)
โข Sales order addresses (~3M)
โข Sales order payments, grids, orders, and invoices (~1M each)
โข Order items
โข Seller records, addresses, and business information
โข Seller bank accounts
โข User accounts
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Homzmart
๐๐ผ๐๐ป๐๐ฟ๐: Egypt ๐ช๐ฌ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / E-commerce
๐๐ฐ๐๐ผ๐ฟ: hackformetome
๐๐น๐ฎ๐ถ๐บ: Full database leak
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~4 GB partial dump plus ~600M sellers database
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 5 Points
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
A threat actor on an underground forum is claiming to publish the full database allegedly originating from Homzmart, a furniture and home goods e-commerce marketplace based in Egypt.
The actor claims the leak includes a partial dump of roughly 4 GB plus a separate sellers database (~600M), covering customer, order, and seller data.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Customer records (~1M) and customer addresses (~1M)
โข Sales order addresses (~3M)
โข Sales order payments, grids, orders, and invoices (~1M each)
โข Order items
โข Seller records, addresses, and business information
โข Seller bank accounts
โข User accounts
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Homzmart
๐๐ผ๐๐ป๐๐ฟ๐: Egypt ๐ช๐ฌ
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Retail / E-commerce
๐๐ฐ๐๐ผ๐ฟ: hackformetome
๐๐น๐ฎ๐ถ๐บ: Full database leak
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~4 GB partial dump plus ~600M sellers database
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 5 Points
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: June 1, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
Session announced on Friday that the project will be moving forward. The video is an hour long, but here is a good TLDR: https://x.com/VitalikButerin/status/2060407073196609539
https://x.com/session_app/status/2060268719864172545
https://x.com/session_app/status/2060268719864172545
X (formerly Twitter)
vitalik.eth (@VitalikButerin) on X
@session_app Pasting my (of course locally-generated) AI summary for those interested.
Glad to see you guys are able to keep going!
Glad to see you guys are able to keep going!
๐ฅ2
๐จ Possible detection of Red Hat infostealer credentials that may have been used in the npm attack. @SocketSecurity
https://x.com/whiteintel_io/status/2061549988765663609
https://x.com/whiteintel_io/status/2061549988765663609
X (formerly Twitter)
Whiteintel (@whiteintel_io) on X
We have detected a Red Hat GitHub credential and session cookie in infostealer logs on April 13 and May 15, 2026 - potentially linked to the Miasma supply chain attack. While we cannot confirm a direct connection, the timing is notably suspicious.
httpโฆ
httpโฆ