βΌοΈ New Dark Web Informer Blog Post!
Title: B9 Neobank Data Allegedly Scraped, 36,000 Records With Partial SSNs and Dates of Birth Posted
Link: https://darkwebinformer.com/b9-neobank-data-allegedly-scraped-36-000-records-with-partial-ssns-and-dates-of-birth-posted/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: B9 Neobank Data Allegedly Scraped, 36,000 Records With Partial SSNs and Dates of Birth Posted
Link: https://darkwebinformer.com/b9-neobank-data-allegedly-scraped-36-000-records-with-partial-ssns-and-dates-of-birth-posted/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
B9 Neobank Data Allegedly Scraped, 36,000 Records With Partial SSNs and Dates of Birth Posted
A forum user posting as riche has published what they describe as a database from Bnine.com, the platform operated by B9, a US neobank offering checking accounts, debit cards, and early direct deposit.
π¨ AI video editing SaaS customer dataset allegedly listed for sale
A forum actor claims to be selling a customer dataset allegedly obtained from an unnamed, well-known AI video editing and clipping platform.
The listing advertises more than 78,000 verified customer records, including approximately 76,000 active subscribers and 2,400 churned accounts. The seller claims the data spans 35 months from 2023 to 2026 and tracks roughly $2.3 million in monthly recurring revenue, $27 million in annual recurring revenue, and $8.1 million in cumulative revenue.
The allegedly exposed information includes customer names, email addresses, subscription plans, billing cycles, monthly and lifetime revenue, Stripe customer identifiers, account activity status, revenue tiers, organization identifiers, and projected account revenue.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling a customer dataset allegedly obtained from an unnamed, well-known AI video editing and clipping platform.
The listing advertises more than 78,000 verified customer records, including approximately 76,000 active subscribers and 2,400 churned accounts. The seller claims the data spans 35 months from 2023 to 2026 and tracks roughly $2.3 million in monthly recurring revenue, $27 million in annual recurring revenue, and $8.1 million in cumulative revenue.
The allegedly exposed information includes customer names, email addresses, subscription plans, billing cycles, monthly and lifetime revenue, Stripe customer identifiers, account activity status, revenue tiers, organization identifiers, and projected account revenue.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨ 3WiFi global access point dataset containing more than 25 million records posted on a forum
A forum actor claims to have converted the 3WiFi database from SQL to CSV and posted the resulting files for download. The data is described as current through April 16, 2026.
The listing advertises 15,684,934 network records and 9,957,467 geolocation records, with a third table also included.
The posted information allegedly includes Wi-Fi network names, BSSIDs, security configurations, Wi-Fi keys, WPS PINs, IP addresses, ports, authorization data, LAN and WAN settings, gateways, DNS servers, latitude and longitude coordinates, source information, and timestamps.
3WiFi is an open-source database and mapping service for Wi-Fi access points worldwide.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have converted the 3WiFi database from SQL to CSV and posted the resulting files for download. The data is described as current through April 16, 2026.
The listing advertises 15,684,934 network records and 9,957,467 geolocation records, with a third table also included.
The posted information allegedly includes Wi-Fi network names, BSSIDs, security configurations, Wi-Fi keys, WPS PINs, IP addresses, ports, authorization data, LAN and WAN settings, gateways, DNS servers, latitude and longitude coordinates, source information, and timestamps.
3WiFi is an open-source database and mapping service for Wi-Fi access points worldwide.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨πΉπ· Kaya Hotels & Resorts data and website files allegedly leaked
A forum actor claims to have obtained data tied to Kaya Hotels & Resorts, a Turkish hotel and resort operator, and published a link described as the full dataset.
The actor says the material includes stealer logs allegedly connected to the company and claims URL fuzzing provided access to its website and downloadable files. Multiple links and screenshots were posted as proof of access.
The post references website files, internal data, and stealer-log material, but does not disclose a record count, archive size, or detailed breakdown of the allegedly exposed information.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have obtained data tied to Kaya Hotels & Resorts, a Turkish hotel and resort operator, and published a link described as the full dataset.
The actor says the material includes stealer logs allegedly connected to the company and claims URL fuzzing provided access to its website and downloadable files. Multiple links and screenshots were posted as proof of access.
The post references website files, internal data, and stealer-log material, but does not disclose a record count, archive size, or detailed breakdown of the allegedly exposed information.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
β€1
βΌοΈ New Dark Web Informer Blog Post!
Title: Bolivia's Ministry of Health SSSRO Database Allegedly Leaked, 41,406 Records on Rural Health Interns Published
Link: https://darkwebinformer.com/bolivias-ministry-of-health-sssro-database-allegedly-leaked-41-406-records-on-rural-health-interns-published/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Bolivia's Ministry of Health SSSRO Database Allegedly Leaked, 41,406 Records on Rural Health Interns Published
Link: https://darkwebinformer.com/bolivias-ministry-of-health-sssro-database-allegedly-leaked-41-406-records-on-rural-health-interns-published/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Bolivia's Ministry of Health SSSRO Database Allegedly Leaked, 41,406 Records on Rural Health Interns Published
A threat actor posting as konata_izumi_shell claims to have breached a system belonging to Bolivia's Ministry of Health and Sports and extracted the complete database behind the Servicio Social de Salud Rural Obligatorio, the programme under which healthβ¦
Damn did Telegram really remove the ability to put an invisible character in the Name field?
π2π2
π¨π§π· Vakinha customer dataset allegedly listed for sale
A forum actor claims to be selling customer data allegedly obtained from Vakinha, a Brazilian crowdfunding platform.
The listing advertises approximately 18,000 customer records dated July 7, 2026. The actor claims the data was extracted after gaining unauthorized access to an administrator account on Vakinhaβs management portal.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling customer data allegedly obtained from Vakinha, a Brazilian crowdfunding platform.
The listing advertises approximately 18,000 customer records dated July 7, 2026. The actor claims the data was extracted after gaining unauthorized access to an administrator account on Vakinhaβs management portal.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
βΌοΈ New Dark Web Informer Blog Post!
Title: PokemonGym.nl Database Allegedly Leaked, 19,600 Player Accounts and Private Messages Published
Link: https://darkwebinformer.com/pokemongym-nl-database-allegedly-leaked-19-600-player-accounts-and-private-messages-published/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: PokemonGym.nl Database Allegedly Leaked, 19,600 Player Accounts and Private Messages Published
Link: https://darkwebinformer.com/pokemongym-nl-database-allegedly-leaked-19-600-player-accounts-and-private-messages-published/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
PokemonGym.nl Database Allegedly Leaked, 19,600 Player Accounts and Private Messages Published
A forum user posting as 888 has published what they describe as the database of PokemonGym.nl, a Dutch online PokΓ©mon RPG.
βΌοΈπΊπΈ 313 Team has taken responsibility for the DDoS on Microsoft 365 services.
IP Information for 154.29.74.158
ASN: 397423
ISP / Org: TIER-NET - Tier.Net Technologies LLC, US
Country: US
Network Range: 154.29.64.0/20
ASN: 397423
ISP / Org: TIER-NET - Tier.Net Technologies LLC, US
Country: US
Network Range: 154.29.64.0/20
π3
πͺ Slice For Life - Part 2 πͺ
IP Information for 154.29.74.158 ASN: 397423 ISP / Org: TIER-NET - Tier.Net Technologies LLC, US Country: US Network Range: 154.29.64.0/20
X (formerly Twitter)
DarkJester (@DarkJstr) on X
π¨ NightSpire ransomware DLS exposed on clearnet.
154.29.74[.]158 - AS397423 / https://t.co/FnxpLYGowc Technologies LLC (US)
Laravel backend (XSRF-TOKEN + session cookie), HTTP title: "RaaS Serviβ¦
154.29.74[.]158 - AS397423 / https://t.co/FnxpLYGowc Technologies LLC (US)
Laravel backend (XSRF-TOKEN + session cookie), HTTP title: "RaaS Serviβ¦
π¨π·πΊ Russian state-backed hackers can steal 90 days of Zimbra emails when a victim simply views a message
A joint international advisory warns that LAUNDRY BEAR is exploiting CVE-2025-66376 against unpatched Zimbra Collaboration Suite servers.
The malicious JavaScript executes when an email is viewed in a vulnerable version of Zimbra webmail. No link click, attachment, or additional interaction is required.
The groupβs Ulej tool attempts to steal:
β’ The victimβs last 90 days of emails
β’ Email addresses and organization directories
β’ Saved passwords
β’ 2FA recovery codes
β’ Newly created application passwords
The attackers can also enable IMAP and create an application password named βZimbraWebβ to maintain access to compromised mailboxes.
The vulnerability was patched in Zimbra 10.0.18 and 10.1.13. Organizations running older versions should update immediately and investigate for signs of compromise.
Full details: https://www.ic3.gov/CSA/2026/260723.pdf
A joint international advisory warns that LAUNDRY BEAR is exploiting CVE-2025-66376 against unpatched Zimbra Collaboration Suite servers.
The malicious JavaScript executes when an email is viewed in a vulnerable version of Zimbra webmail. No link click, attachment, or additional interaction is required.
The groupβs Ulej tool attempts to steal:
β’ The victimβs last 90 days of emails
β’ Email addresses and organization directories
β’ Saved passwords
β’ 2FA recovery codes
β’ Newly created application passwords
The attackers can also enable IMAP and create an application password named βZimbraWebβ to maintain access to compromised mailboxes.
The vulnerability was patched in Zimbra 10.0.18 and 10.1.13. Organizations running older versions should update immediately and investigate for signs of compromise.
Full details: https://www.ic3.gov/CSA/2026/260723.pdf