🚨🇺🇸 Arizona Caregiver Training user dataset allegedly leaked
A forum actor claims to have leaked a recently obtained dataset tied to the online Arizona Caregiver Training portal.
The allegedly exposed information includes usernames, password hashes, identification numbers, full names, email addresses, phone numbers, institutions, departments, street addresses, cities, countries, languages, account roles, confirmation status, suspension status, and other administrative fields.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have leaked a recently obtained dataset tied to the online Arizona Caregiver Training portal.
The allegedly exposed information includes usernames, password hashes, identification numbers, full names, email addresses, phone numbers, institutions, departments, street addresses, cities, countries, languages, account roles, confirmation status, suspension status, and other administrative fields.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
❤1
🚨🇪🇸 Endesa customer and IBAN dataset allegedly listed for sale
A forum actor claims to be selling a dataset allegedly obtained from Endesa, a Spanish energy company serving residential and business customers.
The listing advertises information tied to more than 20 million individuals in a single SQL file. The actor describes the material as fresh 2026 data and lists a total size of approximately 1.06TB.
The post specifically references IBAN information and includes links to a file-tree preview, a sample archive, and 10,000 sample records.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling a dataset allegedly obtained from Endesa, a Spanish energy company serving residential and business customers.
The listing advertises information tied to more than 20 million individuals in a single SQL file. The actor describes the material as fresh 2026 data and lists a total size of approximately 1.06TB.
The post specifically references IBAN information and includes links to a file-tree preview, a sample archive, and 10,000 sample records.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
❤2😭2😈1
🔪 That Dark Web Guy - Part 3 🔪
‼️ The Coca-Cola Company has filed form 8-K due to a cybersecurity incident on behalf of fairlife, LLC. "On July 16, 2026, The Coca-Cola Company (the “Company”) announced that fairlife, LLC (“fairlife”), a dairy company owned by the Company, identified unauthorized…
🚨 Anubis ransomware claims Fairlife // Coca-Cola as a victim
Anubis claims the servers have been locked and 1 TB of data has been stolen.
Anubis claims the servers have been locked and 1 TB of data has been stolen.
🚨 The Craneware Group has filed a notice of Cyber Security incident with the London Stock Exchange
https://www.londonstockexchange.com/news-article/CRW/notice-of-cyber-security-incident/17694735
"Craneware (AIM: CRW.L), a leader in healthcare financial performance solutions, reports that it has identified and is responding to a cyber security incident involving unauthorised access to a subset of its data environment.
The Company's incident response plan has been activated, including the appointment by the Board of external cyber security and forensic specialists. Their investigation is ongoing, alongside the Craneware IT team and the Company's retained cyber security service providers.
The incident has been contained and there has been no disruption to customer services or to the Company's operations. The external specialists have confirmed that there are no residual indicators of compromise arising from the cyber security incident in the Company's systems
The Company has notified the relevant regulators and law enforcement agencies, including the Information Commissioner's Office in the UK and Federal Bureau of Investigations in the US.
Investigations so far have established that a significant volume of file names were viewed and exfiltrated. The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data. A percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated.
The Company is continuing to assess the precise nature and scope of all the data involved and is working with its advisers to identify affected parties and prepare appropriate notifications, including any required further notifications to relevant authorities, in each case in accordance with applicable regulatory obligations.
The Company will update the market as appropriate."
https://www.londonstockexchange.com/news-article/CRW/notice-of-cyber-security-incident/17694735
"Craneware (AIM: CRW.L), a leader in healthcare financial performance solutions, reports that it has identified and is responding to a cyber security incident involving unauthorised access to a subset of its data environment.
The Company's incident response plan has been activated, including the appointment by the Board of external cyber security and forensic specialists. Their investigation is ongoing, alongside the Craneware IT team and the Company's retained cyber security service providers.
The incident has been contained and there has been no disruption to customer services or to the Company's operations. The external specialists have confirmed that there are no residual indicators of compromise arising from the cyber security incident in the Company's systems
The Company has notified the relevant regulators and law enforcement agencies, including the Information Commissioner's Office in the UK and Federal Bureau of Investigations in the US.
Investigations so far have established that a significant volume of file names were viewed and exfiltrated. The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data. A percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated.
The Company is continuing to assess the precise nature and scope of all the data involved and is working with its advisers to identify affected parties and prepare appropriate notifications, including any required further notifications to relevant authorities, in each case in accordance with applicable regulatory obligations.
The Company will update the market as appropriate."
🚨🇲🇽 Alinnco student data allegedly leaked
A forum actor claims to have released data belonging to students and faculty members of Alinnco, a Mexican educational institution operating at alinnco.edu.mx.
The post describes the material as a dataset containing records for all students and includes a public download link. No record count or archive size was disclosed.
The allegedly exposed material includes INE identity documents, academic transcripts, faculty curricula vitae, CURP identifiers, birth certificates, professional degrees, and other educational records.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have released data belonging to students and faculty members of Alinnco, a Mexican educational institution operating at alinnco.edu.mx.
The post describes the material as a dataset containing records for all students and includes a public download link. No record count or archive size was disclosed.
The allegedly exposed material includes INE identity documents, academic transcripts, faculty curricula vitae, CURP identifiers, birth certificates, professional degrees, and other educational records.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇲🇽 Universidad Mundo Maya systems and data allegedly compromised
A forum actor claims to have compromised Universidad Mundo Maya, a private university in Mexico, and dumped databases connected to the institution’s academic and administrative systems.
The listing shows an extensive collection of databases apparently tied to multiple campuses, libraries, surveys, events, graduates, employees, human resources, student portals, file storage, sessions, and other internal platforms.
The actor also claims to possess more than 20,000 images and personal documents belonging to students, teachers, and other staff members. A sample link was published, with the actor stating that the full material would be released and offered for sale in the coming days.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have compromised Universidad Mundo Maya, a private university in Mexico, and dumped databases connected to the institution’s academic and administrative systems.
The listing shows an extensive collection of databases apparently tied to multiple campuses, libraries, surveys, events, graduates, employees, human resources, student portals, file storage, sessions, and other internal platforms.
The actor also claims to possess more than 20,000 images and personal documents belonging to students, teachers, and other staff members. A sample link was published, with the actor stating that the full material would be released and offered for sale in the coming days.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇲🇽 Culiacán municipal employee dataset allegedly listed for sale
A forum actor claims to be selling a dataset allegedly obtained from the Culiacán municipal government in Sinaloa, Mexico.
The listing advertises records tied to approximately 20,000 municipal employees and includes a screenshot and sample showing personnel and payroll-related fields.
The allegedly exposed information includes full names, RFC and CURP identifiers, employee numbers, departments, positions, employment dates, salaries, payroll concepts, bank account details, birth dates, home addresses, phone numbers, blood types, marital status, education, family information, contract details, tax regimes, and other human resources records.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling a dataset allegedly obtained from the Culiacán municipal government in Sinaloa, Mexico.
The listing advertises records tied to approximately 20,000 municipal employees and includes a screenshot and sample showing personnel and payroll-related fields.
The allegedly exposed information includes full names, RFC and CURP identifiers, employee numbers, departments, positions, employment dates, salaries, payroll concepts, bank account details, birth dates, home addresses, phone numbers, blood types, marital status, education, family information, contract details, tax regimes, and other human resources records.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇮🇹 Italian confectionery retailer webmail administrator access allegedly listed for sale
A forum actor claims to be selling webmail administrator access and customer data tied to an unidentified Italian online retailer based in Chianciano Terme, Siena. The company reportedly sells traditional Tuscan biscuits, artisan cookies, cantucci, panforte, cakes, pastries, chocolates, and other confectionery products.
The listing includes a screenshot presented as proof of access to the organization’s mailbox, along with a sample of the allegedly obtained customer dataset.
The allegedly exposed information includes customer IDs, full names, tax identification codes, regional and municipal codes, postal addresses, email addresses, telephone and mobile numbers, professions, languages, privacy and marketing consent settings, customer categories, and IP address authorization data.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling webmail administrator access and customer data tied to an unidentified Italian online retailer based in Chianciano Terme, Siena. The company reportedly sells traditional Tuscan biscuits, artisan cookies, cantucci, panforte, cakes, pastries, chocolates, and other confectionery products.
The listing includes a screenshot presented as proof of access to the organization’s mailbox, along with a sample of the allegedly obtained customer dataset.
The allegedly exposed information includes customer IDs, full names, tax identification codes, regional and municipal codes, postal addresses, email addresses, telephone and mobile numbers, professions, languages, privacy and marketing consent settings, customer categories, and IP address authorization data.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: Georgian Court Systems and the High Council of Justice Allegedly Breached, 5TB of Judiciary Data for Sale
Link: https://darkwebinformer.com/georgian-court-systems-and-the-high-council-of-justice-allegedly-breached-5tb-of-judiciary-data-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Georgian Court Systems and the High Council of Justice Allegedly Breached, 5TB of Judiciary Data for Sale
Link: https://darkwebinformer.com/georgian-court-systems-and-the-high-council-of-justice-allegedly-breached-5tb-of-judiciary-data-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Georgian Court Systems and the High Council of Justice Allegedly Breached, 5TB of Judiciary Data for Sale
A threat actor using the alias bytetobreach is advertising the sale of data they claim to have taken from Georgia's court systems and the High Council of Justice of Georgia.
‼️ New Dark Web Informer Blog Post!
Title: Bogotá Mobility Secretariat Allegedly Breached, 5.6GB of Traffic Agent and Citation Data Listed for $500
Link: https://darkwebinformer.com/bogota-mobility-secretariat-allegedly-breached-5-6gb-of-traffic-agent-and-citation-data-listed-for-500/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Bogotá Mobility Secretariat Allegedly Breached, 5.6GB of Traffic Agent and Citation Data Listed for $500
Link: https://darkwebinformer.com/bogota-mobility-secretariat-allegedly-breached-5-6gb-of-traffic-agent-and-citation-data-listed-for-500/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Bogotá Mobility Secretariat Allegedly Breached, 5.6GB of Traffic Agent and Citation Data Listed for $500
A threat actor posting under the alias PescobarLegado, working with a group identified in the post as NyxarGroup, claims to have obtained internal data from the Secretaría Distrital de Movilidad de Bogotá, the mobility authority under the Bogotá Mayor's Office…
‼️ New Dark Web Informer Blog Post!
Title: Hugging Face Breach Linked to Autonomous AI Agent Exposes Internal Datasets and Credentials
Link: https://darkwebinformer.com/hugging-face-breach-linked-to-autonomous-ai-agent-exposes-internal-datasets-and-credentials/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Hugging Face Breach Linked to Autonomous AI Agent Exposes Internal Datasets and Credentials
Link: https://darkwebinformer.com/hugging-face-breach-linked-to-autonomous-ai-agent-exposes-internal-datasets-and-credentials/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Hugging Face Breach Linked to Autonomous AI Agent Exposes Internal Datasets and Credentials
Hugging Face has disclosed a security breach in which an autonomous AI agent system compromised part of its production infrastructure and gained access to internal datasets and service credentials.
‼️🇨🇦 Kairos ransomware claims Collège O’Sullivan de Québec as a victim
🇨🇦 Collège O’Sullivan de Québec - Canadian private college offering career-focused programs in administration, insurance, IT, web development, and marketing.
Revenue: $25.2 million.
🇨🇦 Collège O’Sullivan de Québec - Canadian private college offering career-focused programs in administration, insurance, IT, web development, and marketing.
Revenue: $25.2 million.