π¨ Wellbees customer dataset allegedly leaked
A forum actor claims to have leaked customer data tied to playground.wellbees.com.
The listing advertises approximately 18,000 records and includes a sample containing customer account, company, billing, and contact information. The full download was placed behind the forumβs points-based content lock.
The allegedly exposed information includes names, email addresses, phone numbers, dates of birth, genders, companies, customer identifiers, account creation dates, billing and shipping addresses, cities, states, postal codes, countries, tax and VAT numbers, account lock status, customer notes, and Mailchimp-related fields.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have leaked customer data tied to playground.wellbees.com.
The listing advertises approximately 18,000 records and includes a sample containing customer account, company, billing, and contact information. The full download was placed behind the forumβs points-based content lock.
The allegedly exposed information includes names, email addresses, phone numbers, dates of birth, genders, companies, customer identifiers, account creation dates, billing and shipping addresses, cities, states, postal codes, countries, tax and VAT numbers, account lock status, customer notes, and Mailchimp-related fields.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨π·πΊ SplitVPN user, device, and connection logs allegedly leaked
A forum actor claims to have leaked data from SplitVPN, formerly known as NotVPN, a Russian VPN service used to bypass internet restrictions.
The listing advertises approximately 23.4 million users, 58 million proxy connection logs, 23.9 million authorization records, 13.6 million devices, and 2.6 million Tinkoff payment records. The actor says the compressed SQL dump is approximately 5GB and published a public download link.
The allegedly exposed information includes email addresses, IP addresses, countries, subscription statuses, masked payment card numbers, transaction amounts and timestamps, authentication tokens, device identifiers, proxy targets, administrator accounts and activity logs, Telegram accounts, Apple IDs, WireGuard peers, server metrics, and internal infrastructure details.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have leaked data from SplitVPN, formerly known as NotVPN, a Russian VPN service used to bypass internet restrictions.
The listing advertises approximately 23.4 million users, 58 million proxy connection logs, 23.9 million authorization records, 13.6 million devices, and 2.6 million Tinkoff payment records. The actor says the compressed SQL dump is approximately 5GB and published a public download link.
The allegedly exposed information includes email addresses, IP addresses, countries, subscription statuses, masked payment card numbers, transaction amounts and timestamps, authentication tokens, device identifiers, proxy targets, administrator accounts and activity logs, Telegram accounts, Apple IDs, WireGuard peers, server metrics, and internal infrastructure details.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π₯ Telegram Drive: Turn your Telegram account into an unlimited, secure cloud storage drive.
GitHub: https://github.com/caamer20/Telegram-Drive
GitHub: https://github.com/caamer20/Telegram-Drive
β€1π1
π¨ Qilin ransomware claims 7 victims
πΊπΈ P & A Construction - New Jersey contractor specializing in paving, utilities, sewer systems, road reconstruction and civil infrastructure projects.
πΊπΈ Salida Union School District - California public school district serving kindergarten through eighth-grade students.
π¨π± RECSA - Chilean asset-recovery and debt-collection company serving businesses across Latin America.
π¨π¦ PrimeLine Logistics - Ontario-based freight company providing FTL, LTL, expedited and temperature-controlled transportation services.
πΊπΈ Infina Health - Pennsylvania medical transportation provider offering emergency, non-emergency and specialized patient transport services.
π΅π° EFU Life Assurance - Pakistani insurance company providing life insurance, savings and protection products.
πΊπΈ CPCG - Healthcare business-services company providing outsourced staffing, billing, analytics and operational support.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
πΊπΈ P & A Construction - New Jersey contractor specializing in paving, utilities, sewer systems, road reconstruction and civil infrastructure projects.
πΊπΈ Salida Union School District - California public school district serving kindergarten through eighth-grade students.
π¨π± RECSA - Chilean asset-recovery and debt-collection company serving businesses across Latin America.
π¨π¦ PrimeLine Logistics - Ontario-based freight company providing FTL, LTL, expedited and temperature-controlled transportation services.
πΊπΈ Infina Health - Pennsylvania medical transportation provider offering emergency, non-emergency and specialized patient transport services.
π΅π° EFU Life Assurance - Pakistani insurance company providing life insurance, savings and protection products.
πΊπΈ CPCG - Healthcare business-services company providing outsourced staffing, billing, analytics and operational support.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨ LAPSUS$ claims it is permanently ending operations after meeting its financial objectives, stating there will be no further communications, leaks, or access offerings.
The group also taunted investigators and TeamPCP, while alleging that Mercor user data, including personal information, biometric records, and recordings, was sold to Chinese entities.
These claims remain unverified.
Source: lapsus[.]bz
The group also taunted investigators and TeamPCP, while alleging that Mercor user data, including personal information, biometric records, and recordings, was sold to Chinese entities.
These claims remain unverified.
Source: lapsus[.]bz
π2β€1
π¨π²π½ Sinaloa vehicle registry dataset containing 2 million records allegedly advertised
A forum actor claims to have obtained a unified vehicle control dataset tied to the government of Sinaloa, Mexico.
The listing advertises approximately 2 million records and says the material combines vehicle ownership, taxpayer, technical, registration, and administrative information.
The allegedly exposed information includes vehicle ownersβ names, RFC tax identifiers, phone numbers, home and billing addresses, municipalities, postal codes, vehicle makes and models, colors, cylinder counts, passenger capacities, VINs, engine numbers, current and previous license plates, registration statuses, and internal taxpayer and location identifiers.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have obtained a unified vehicle control dataset tied to the government of Sinaloa, Mexico.
The listing advertises approximately 2 million records and says the material combines vehicle ownership, taxpayer, technical, registration, and administrative information.
The allegedly exposed information includes vehicle ownersβ names, RFC tax identifiers, phone numbers, home and billing addresses, municipalities, postal codes, vehicle makes and models, colors, cylinder counts, passenger capacities, VINs, engine numbers, current and previous license plates, registration statuses, and internal taxpayer and location identifiers.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨ A Go-based PoC scanner is available for CVE-2026-43499, also known as GhostLock, a Linux kernel use-after-free vulnerability that may allow local privilege escalation.
GitHub: https://github.com/gagaltotal/CVE-2026-43499-PoC-Scanner
The tool includes a passive scan mode and a PoC trigger that may cause a kernel panic or system crash.
GitHub: https://github.com/gagaltotal/CVE-2026-43499-PoC-Scanner
The tool includes a passive scan mode and a PoC trigger that may cause a kernel panic or system crash.
β€2
WHOIS for raidforums.ac
Domain: raidforums.ac
Registered On: 2026-07-17 19:50:00 UTC
Expires On: 2027-07-17 19:50:00 UTC
Updated On: 2026-07-22 19:50:02 UTC
Status:
clientTransferProhibited
Name Servers:
launch1.spaceship.net
launch2.spaceship.net
Registrar: Spaceship, Inc.
URL: Not Available
Name: REDACTED
Email: abuse@spaceship.com
Country: IS
Domain: raidforums.ac
Registered On: 2026-07-17 19:50:00 UTC
Expires On: 2027-07-17 19:50:00 UTC
Updated On: 2026-07-22 19:50:02 UTC
Status:
clientTransferProhibited
Name Servers:
launch1.spaceship.net
launch2.spaceship.net
Registrar: Spaceship, Inc.
URL: Not Available
Name: REDACTED
Email: abuse@spaceship.com
Country: IS
WHOIS lookup failed for lapsus.bz
Error: % TCI Whois Service. Terms of use:
% https://tcinet.ru/documents/whois_ru_rf.pdf (in Russian)
% https://tcinet.ru/documents/whois_su.pdf (in Russian)
No entries found for the selected source(s).
Last updated on 2026-07-22T20:08:01Z
Error: % TCI Whois Service. Terms of use:
% https://tcinet.ru/documents/whois_ru_rf.pdf (in Russian)
% https://tcinet.ru/documents/whois_su.pdf (in Russian)
No entries found for the selected source(s).
Last updated on 2026-07-22T20:08:01Z
Media is too big
VIEW IN TELEGRAM
In 1999, a file-sharing program created in a Boston dorm room sent shock waves across the music industry and served notice that a major cultural shift was underway.
This is a Napster documentary by NYT.
This is a Napster documentary by NYT.
π₯1
βΌοΈ Five Below, Inc. has filed form 8-K due to a cybersecurity incident
"On July 15, 2026, Five Below, Inc. (the βCompanyβ) identified anomalous activity on a Company-issued computer belonging to an employee. Upon detection, the Company promptly activated its cybersecurity incident response plan, initiated a forensic investigation, with assistance from third-party cybersecurity experts, and took immediate steps to contain the activity.
The investigation determined that on July 14, 2026, a threat actor used social engineering techniques that enabled unauthorized access to that employeeβs Company-issued computer. The threat actor exfiltrated a number of files from the affected computer.
As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, that the incident was limited to the affected employeeβs environment, that no personally identifiable information was accessed or exfiltrated, and that the incident did not affect the Companyβs other systems, platforms, data, or environments.
Based on information available as of the date of this filing, the Company does not believe the incident has had, or is reasonably likely to have, a material impact on the Companyβs business strategy, operations, financial condition, or results of operations."
Source: https://www.sec.gov/Archives/edgar/data/1177609/000119312526312573/d19155d8k.htm
"On July 15, 2026, Five Below, Inc. (the βCompanyβ) identified anomalous activity on a Company-issued computer belonging to an employee. Upon detection, the Company promptly activated its cybersecurity incident response plan, initiated a forensic investigation, with assistance from third-party cybersecurity experts, and took immediate steps to contain the activity.
The investigation determined that on July 14, 2026, a threat actor used social engineering techniques that enabled unauthorized access to that employeeβs Company-issued computer. The threat actor exfiltrated a number of files from the affected computer.
As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, that the incident was limited to the affected employeeβs environment, that no personally identifiable information was accessed or exfiltrated, and that the incident did not affect the Companyβs other systems, platforms, data, or environments.
Based on information available as of the date of this filing, the Company does not believe the incident has had, or is reasonably likely to have, a material impact on the Companyβs business strategy, operations, financial condition, or results of operations."
Source: https://www.sec.gov/Archives/edgar/data/1177609/000119312526312573/d19155d8k.htm
β€1
Forwarded from Dark Web Informer - Private
Cybersecurity Incident Disclosure
Wed, 22 Jul 2026 17:19:51 EDT
A cybersecurity incident has been disclosed by FIVE BELOW, INC, Inc CIK: 0001177609, Ticker: $FIVE.
View SEC Filing
Wed, 22 Jul 2026 17:19:51 EDT
A cybersecurity incident has been disclosed by FIVE BELOW, INC, Inc CIK: 0001177609, Ticker: $FIVE.
View SEC Filing
π₯ ASNmap: Go CLI and Library for quickly mapping organization network ranges using ASN information.
GitHub: https://github.com/projectdiscovery/asnmap
GitHub: https://github.com/projectdiscovery/asnmap