🚨🇯🇵 PeakManager customer dataset allegedly listed for sale
A forum actor claims to have breached PeakManager, a Japanese reservation platform used by salons, clinics, and other appointment-based businesses, and extracted more than 32.5 million database rows.
The seller says a deduplicated version contains approximately 6.1 million records. The listing also advertises PeakManager source code, access to its intranet, and remote database access, with a reported asking price of $70,000.
Advertised data includes:
▪️Customer names and phonetic name readings
▪️Dates of birth and genders
▪️Phone numbers and email addresses
▪️Postal codes, prefectures, and street addresses
▪️Password-related fields
▪️Customer IDs, membership details, and account statuses
▪️Appointment, sales, and communication metadata
Internal company, shop, and administrator identifiers
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have breached PeakManager, a Japanese reservation platform used by salons, clinics, and other appointment-based businesses, and extracted more than 32.5 million database rows.
The seller says a deduplicated version contains approximately 6.1 million records. The listing also advertises PeakManager source code, access to its intranet, and remote database access, with a reported asking price of $70,000.
Advertised data includes:
▪️Customer names and phonetic name readings
▪️Dates of birth and genders
▪️Phone numbers and email addresses
▪️Postal codes, prefectures, and street addresses
▪️Password-related fields
▪️Customer IDs, membership details, and account statuses
▪️Appointment, sales, and communication metadata
Internal company, shop, and administrator identifiers
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
❤1
‼️ New Dark Web Informer Blog Post!
Title: Moroccan Medical Provider Distamed Allegedly Breached, Patient Records and 13 Years of Company Archive Claimed
Link: https://darkwebinformer.com/moroccan-medical-provider-distamed-allegedly-breached-patient-records-and-13-years-of-company-archive-claimed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Moroccan Medical Provider Distamed Allegedly Breached, Patient Records and 13 Years of Company Archive Claimed
Link: https://darkwebinformer.com/moroccan-medical-provider-distamed-allegedly-breached-patient-records-and-13-years-of-company-archive-claimed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Moroccan Medical Provider Distamed Allegedly Breached, Patient Records and 13 Years of Company Archive Claimed
A threat actor posting as anisanas2 claims to have extracted the full database of Distamed Morocco, a supplier of medical devices and healthcare solutions to hospitals, clinics, and practitioners, with a stated focus on cardiology, pulmonology, neurology…
🚨🇲🇽 El Colegio de la Frontera Norte alumni dataset allegedly leaked
A forum actor claims to have leaked a database tied to El Colegio de la Frontera Norte, a Mexican academic and research institution.
The listing says the dataset contains information belonging to more than 4,000 former students.
The allegedly exposed information includes full names, CURP identifiers, dates of birth, ages, genders, marital statuses, email addresses, phone numbers, home addresses, cities, municipalities, states, postal codes, student IDs, enrollment numbers, academic programs, graduation years, and student statuses.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to have leaked a database tied to El Colegio de la Frontera Norte, a Mexican academic and research institution.
The listing says the dataset contains information belonging to more than 4,000 former students.
The allegedly exposed information includes full names, CURP identifiers, dates of birth, ages, genders, marital statuses, email addresses, phone numbers, home addresses, cities, municipalities, states, postal codes, student IDs, enrollment numbers, academic programs, graduation years, and student statuses.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇧🇷 IBAPE-PR member records and professional documents allegedly leaked
A forum actor claims to have breached the Instituto Brasileiro de Avaliações e Perícias de Engenharia do Paraná, an organization representing engineering appraisal and expert examination professionals in Paraná, Brazil.
The post says more than 3,700 personal records and 2,080 document files were released for free. The material allegedly contains information belonging to registered engineers and associated members.
The allegedly exposed information includes full names, CPF and RG identifiers, CREA registration numbers, dates of birth, email addresses, phone numbers, home and business addresses, postal codes, job titles, professions, company details, membership and payment records, account passwords, billing tokens, social media profiles, photographs, registration dates, and professional documents.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have breached the Instituto Brasileiro de Avaliações e Perícias de Engenharia do Paraná, an organization representing engineering appraisal and expert examination professionals in Paraná, Brazil.
The post says more than 3,700 personal records and 2,080 document files were released for free. The material allegedly contains information belonging to registered engineers and associated members.
The allegedly exposed information includes full names, CPF and RG identifiers, CREA registration numbers, dates of birth, email addresses, phone numbers, home and business addresses, postal codes, job titles, professions, company details, membership and payment records, account passwords, billing tokens, social media profiles, photographs, registration dates, and professional documents.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: Michoacán State Government CADPE Portal Allegedly Breached, 37,000 Supplier Identity Documents Published
Link: https://darkwebinformer.com/michoacan-state-government-cadpe-portal-allegedly-breached-37-000-supplier-identity-documents-published/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Michoacán State Government CADPE Portal Allegedly Breached, 37,000 Supplier Identity Documents Published
Link: https://darkwebinformer.com/michoacan-state-government-cadpe-portal-allegedly-breached-37-000-supplier-identity-documents-published/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Michoacán State Government CADPE Portal Allegedly Breached, 37,000 Supplier Identity Documents Published
Threat actors posting as homercracker and cenfecracked claim to have extracted the full contents of CADPE, the executive procurement and administrative platform of the Michoacán State Government in Mexico, which handles public tenders and supplier registration.
‼️ New Dark Web Informer Blog Post!
Title: SMSA Express Allegedly Breached, 124.7 Million Shipment Records With Sender and Recipient Details for Sale
Link: https://darkwebinformer.com/smsa-express-allegedly-breached-124-7-million-shipment-records-with-sender-and-recipient-details-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: SMSA Express Allegedly Breached, 124.7 Million Shipment Records With Sender and Recipient Details for Sale
Link: https://darkwebinformer.com/smsa-express-allegedly-breached-124-7-million-shipment-records-with-sender-and-recipient-details-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
SMSA Express Allegedly Breached, 124.7 Million Shipment Records With Sender and Recipient Details for Sale
A seller posting as Demetrius is advertising what they describe as a corporate dataset from SMSA Express, one of Saudi Arabia's largest courier and logistics operators.
😁1
‼️ New Dark Web Informer Blog Post!
Title: Podomoro University Allegedly Breached, 75 Databases and Full Website Source Code Offered for $7,000
Link: https://darkwebinformer.com/podomoro-university-allegedly-breached-75-databases-and-full-website-source-code-offered-for-7-000/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Podomoro University Allegedly Breached, 75 Databases and Full Website Source Code Offered for $7,000
Link: https://darkwebinformer.com/podomoro-university-allegedly-breached-75-databases-and-full-website-source-code-offered-for-7-000/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Podomoro University Allegedly Breached, 75 Databases and Full Website Source Code Offered for $7,000
A seller posting as LordVoldemort is advertising what they describe as a complete compromise of Podomoro University in Indonesia, an institution established in 2014 under the Agung Podomoro Education Foundation.
🚨🇲🇽 Michoacán Es Mejor citizen petition records allegedly leaked
A forum actor claims to have leaked data from Michoacán Es Mejor, a citizen request and government services platform associated with the state of Michoacán, Mexico.
A sample posted on the forum contains records involving public service requests and administrative procedures, including interactions with the state tax administration service.
The allegedly exposed information includes petition numbers, request descriptions, government responses, case statuses, submission and response dates, service categories, responsible agencies, citizens’ full names, home addresses, phone numbers, email addresses, genders, online submission details, and internal user identifiers.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to have leaked data from Michoacán Es Mejor, a citizen request and government services platform associated with the state of Michoacán, Mexico.
A sample posted on the forum contains records involving public service requests and administrative procedures, including interactions with the state tax administration service.
The allegedly exposed information includes petition numbers, request descriptions, government responses, case statuses, submission and response dates, service categories, responsible agencies, citizens’ full names, home addresses, phone numbers, email addresses, genders, online submission details, and internal user identifiers.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇨🇴 Data from five Colombian government domains allegedly leaked
A forum actor claims to have released an 897MB archive containing data obtained from five Colombian government domains.
The listing advertises more than 1.1 million records, including 932,207 vehicle tax debtor entries, 175,742 court collection records, 41,276 judicial embargo orders, 12,734 tax retention certificates, and 977 medical PDFs allegedly tied to ESE Hospital La María.
The allegedly exposed information also includes clinical histories, medical authorizations and referrals, employee payroll records, names, Colombian identification numbers, salaries, banking details, transportation payment documents, database credentials, Joomla configurations, and FTP credentials. The actor claims the tax-related records represent approximately COP 165.1 billion.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have released an 897MB archive containing data obtained from five Colombian government domains.
The listing advertises more than 1.1 million records, including 932,207 vehicle tax debtor entries, 175,742 court collection records, 41,276 judicial embargo orders, 12,734 tax retention certificates, and 977 medical PDFs allegedly tied to ESE Hospital La María.
The allegedly exposed information also includes clinical histories, medical authorizations and referrals, employee payroll records, names, Colombian identification numbers, salaries, banking details, transportation payment documents, database credentials, Joomla configurations, and FTP credentials. The actor claims the tax-related records represent approximately COP 165.1 billion.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
❤1
‼️ New Dark Web Informer Blog Post!
Title: BENY New Energy Allegedly Breached, User Data Plus Access to EV Charging and Firmware Platforms Shown
Link: https://darkwebinformer.com/beny-new-energy-allegedly-breached-user-data-plus-access-to-ev-charging-and-firmware-platforms-shown/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: BENY New Energy Allegedly Breached, User Data Plus Access to EV Charging and Firmware Platforms Shown
Link: https://darkwebinformer.com/beny-new-energy-allegedly-breached-user-data-plus-access-to-ev-charging-and-firmware-platforms-shown/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
BENY New Energy Allegedly Breached, User Data Plus Access to EV Charging and Firmware Platforms Shown
A forum user posting as 888 has published what they describe as a breach of Beny.com, operated by BENY New Energy, a manufacturer of solar photovoltaic safety equipment, microinverters, battery storage systems, and EV charging hardware.
‼️🇺🇸 Brooklyn Defender Services has been claimed a victim to INSOMNIA ransomware
🇺🇸 Brooklyn Defender Services - A Brooklyn-based public defense office providing free, client-centered legal representation and advocacy.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
🇺🇸 Brooklyn Defender Services - A Brooklyn-based public defense office providing free, client-centered legal representation and advocacy.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
🚨🇧🇷 Celso Lisboa University student and employee data allegedly leaked
A forum actor claims to have breached Celso Lisboa University in Rio de Janeiro, Brazil, and released separate datasets containing personal information belonging to students and staff.
The post advertises more than 51,200 student records and 2,223 employee records.
The allegedly exposed information includes names, dates of birth, genders, marital statuses, contact details, home addresses, CPF and identity document numbers, education details, family information, special-needs data, employee roles, payroll and banking information, account credentials, passwords, and internal administrative records.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to have breached Celso Lisboa University in Rio de Janeiro, Brazil, and released separate datasets containing personal information belonging to students and staff.
The post advertises more than 51,200 student records and 2,223 employee records.
The allegedly exposed information includes names, dates of birth, genders, marital statuses, contact details, home addresses, CPF and identity document numbers, education details, family information, special-needs data, employee roles, payroll and banking information, account credentials, passwords, and internal administrative records.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️🇺🇸 Metropolitan Construction Systems has been claimed a victim to PEAR ransomware
🇺🇸 Metropolitan Construction Systems - A U.S.-based construction management company providing project planning, coordination, and building services.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🇺🇸 Metropolitan Construction Systems - A U.S.-based construction management company providing project planning, coordination, and building services.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
‼️🇺🇸🇦🇷 Qilin ransomware names 4 victims
🇺🇸 Stryker - A medical technology company that manufactures surgical equipment, implants, and healthcare products.
🇺🇸 Highline Community College - A public community college in Des Moines, Washington, offering academic and workforce education programs.
🇺🇸 Kean University - A public university in New Jersey offering undergraduate, graduate, and professional degree programs.
🇦🇷 Argentine Army - The land warfare branch of the Argentine Armed Forces.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🇺🇸 Stryker - A medical technology company that manufactures surgical equipment, implants, and healthcare products.
🇺🇸 Highline Community College - A public community college in Des Moines, Washington, offering academic and workforce education programs.
🇺🇸 Kean University - A public university in New Jersey offering undergraduate, graduate, and professional degree programs.
🇦🇷 Argentine Army - The land warfare branch of the Argentine Armed Forces.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🚨 AWS STS access tied to an unnamed telecommunications company allegedly listed for sale for $140,000.
A forum actor claims to be selling AWS Security Token Service access associated with an unidentified telecommunications company reporting approximately $9 billion in revenue.
The listing references 18 Amazon SQS queues, each allegedly processing or exposing up to 100,000 records per week. The seller also claims the access supports an “SQS downgrade attack” and set the asking price at $140,000.
No company name, sample data, proof of access, or additional technical details were publicly provided.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling AWS Security Token Service access associated with an unidentified telecommunications company reporting approximately $9 billion in revenue.
The listing references 18 Amazon SQS queues, each allegedly processing or exposing up to 100,000 records per week. The seller also claims the access supports an “SQS downgrade attack” and set the asking price at $140,000.
No company name, sample data, proof of access, or additional technical details were publicly provided.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
This media is not supported in your browser
VIEW IN TELEGRAM
💥 Cariddi: Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
GitHub: https://github.com/edoardottt/cariddi
GitHub: https://github.com/edoardottt/cariddi
‼️ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVSS: 10
Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630
CVSS: 10
Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630
❤1
‼️ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVSS: 9.1
Scanner: https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Details and Mitigation: https://support.checkpoint.com/results/sk/sk185169/
CVSS: 9.1
Scanner: https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Details and Mitigation: https://support.checkpoint.com/results/sk/sk185169/
❤1
‼️ PoC released for CVE-2026-54121 codenamed Certighost
CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.
GitHub: https://github.com/aniqfakhrul/cve-2026-54121
CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.
GitHub: https://github.com/aniqfakhrul/cve-2026-54121
❤1😭1
🚨 CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability
CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.
CVSS: 9.3
More information: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835
CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.
CVSS: 9.3
More information: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835
❤1
🚨🇲🇽 Acomee customer dataset containing more than 17,000 records allegedly leaked
A forum actor claims to have leaked data tied to Acomee, a Mexican distributor of telecommunications, networking, surveillance, and electrical equipment.
The post advertises slightly more than 17,000 records.
The allegedly exposed information includes names, RFC identifiers, email addresses, usernames, password fields, registration dates, street addresses, phone numbers, cities, states, postal codes, account permissions, vendor details, purchasing preferences, marketplace settings, tax regimes, subscription validity dates, account statuses, and internal file references.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have leaked data tied to Acomee, a Mexican distributor of telecommunications, networking, surveillance, and electrical equipment.
The post advertises slightly more than 17,000 records.
The allegedly exposed information includes names, RFC identifiers, email addresses, usernames, password fields, registration dates, street addresses, phone numbers, cities, states, postal codes, account permissions, vendor details, purchasing preferences, marketplace settings, tax regimes, subscription validity dates, account statuses, and internal file references.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials