๐Ÿ”ช Slice For Life - Part 2 ๐Ÿ”ช
4.71K subscribers
1.1K photos
62 videos
979 links
Download Telegram
๐Ÿšจ๐ŸŒ Coinbase session cookie checker and account takeover service advertised on a cybercrime forum

A forum actor is advertising a bot that allegedly checks stolen Coinbase session cookies for account balances, provides access without valid email credentials, and supports rapid withdrawals using methods designed to evade antifraud systems. The listing also advertises 2FA removal for Coinbase, MEXC, Kraken, Bybit, and other cryptocurrency exchanges.

The seller says personally sourced material is required and prioritizes stealer logs, macOS logs, RDP access, hVNC, and botnet data. Accounts from the US and UK must reportedly hold at least $1,000, while accounts from Europe and other regions require balances of at least $8,000. Revenue-sharing terms of 60/40 and 50/50 are advertised depending on the account balance.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โค2
๐Ÿšจ๐Ÿ‡ซ๐Ÿ‡ท Alpissimo[.]fr user dataset containing approximately 600 records allegedly leaked

A forum actor claims to have breached alpissimo[.]fr and released data allegedly obtained from the website.

The listing advertises approximately 600 user records. A sample posted on the forum contains information submitted through the site, including names, email addresses, phone numbers, submission dates, and messages containing housing or travel requirements. The full download was placed behind the forumโ€™s reply requirement.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ซ๐Ÿ‡ท SDIS de la Marne personnel data and documents allegedly leaked

Forum actors ChimeraZ and Cybernox claim to have leaked a database and document archive tied to SDIS 51, the fire and rescue service for Franceโ€™s Marne department.

The post advertises 2,168 records covering 2,167 individuals, along with 1,021 files totaling approximately 700MB. The actors say the archive contains 1,020 documents related to firefighters and the organizationโ€™s website, provided in CSV and PDF formats.

The allegedly exposed information includes personnel names, work email addresses, phone numbers, job titles, departmental roles, and firefighter-related documents.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ซ๐Ÿ‡ท Three French fire and rescue services allegedly targeted in separate data leaks

Forum actors ChimeraZ and Cybernox claim to have leaked data tied to SDIS 06 in Alpes-Maritimes, SDIS 40 in Landes, and SDIS 04 in Alpes-de-Haute-Provence.

The SDIS 06 listing advertises 2,331 records covering 2,325 people and 15,833 files totaling 22.5GB. The SDIS 40 post references 241 records and 3,205 files totaling 11.8GB, while the SDIS 04 listing advertises 145 personnel records.

The allegedly exposed information includes firefightersโ€™ names, dates of birth, nationalities, ranks, assignments, email addresses, phone numbers, home addresses, biographies, internal operational material, and other private documents.

These claims are currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands contact dataset containing 14 million records allegedly listed for sale

A forum actor claims to be selling a 2026 dataset containing approximately 14 million records tied to individuals in the Netherlands.

The seller is asking 2,500 in an unspecified currency and says the dataset will be sold exclusively to one buyer.

The allegedly exposed information includes names, dates of birth, genders, identification numbers, email addresses, mobile and home phone numbers, job titles, departments, account details, record ownership and creation metadata, contact preferences, and linked social media identifiers.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ฉ๐Ÿ‡ช Root CMS access to three major companies allegedly listed for sale

A forum actor claims to be selling privileged CMS access tied to two unnamed US pharmaceutical and biotechnology companies and the German rail-freight division of a national railway.

The three organizations reportedly generate approximately $84.4 billion in combined annual revenue. The listings advertise root access to 18 CMS instances, including systems distributed across 10 countries.

The seller claims the access provides full read and write capabilities, including access to records, user account creation, file uploads, and email creation. Asking prices are listed at $16,000 for the biotechnology company, $40,000 for the pharmaceutical company, and $12,000 for the rail-freight operator.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡ฎ๐Ÿ‡ฑ Root CMS access to three government platforms allegedly listed for sale

A forum actor claims to be selling privileged CMS access tied to Nara Prefectureโ€™s Nara Super App in Japan, New Brunswickโ€™s MyHealthNB platform in Canada, and Israelโ€™s National Digital Agency.

The listings advertise prices of $2,000 for Nara Super App, $10,000 for MyHealthNB, and $5,000 for the Israeli government system. The seller claims the access provides full read and write capabilities, including control over user accounts, file uploads, and email creation.

The actor gave potential buyers 48 hours to purchase the access after publicly naming the affected platforms.

These claims are currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ฌ๐Ÿ‡ง UK Department for Education contact records allegedly leaked

A forum actor claims to have breached systems tied to the UK Department for Education and obtained data from its Help Portal and Turing Portal.

The listing advertises approximately 600,000 parent and staff contact records from the Help Portal, along with around 7,000 additional records from the Turing Portal. Samples containing names, email addresses, phone numbers, job titles, and internal contact identifiers were posted on the forum.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ฌ๐Ÿ‡ง UK Police National Legal Database contact records allegedly leaked

A forum actor claims to have breached the Police National Legal Database, a UK police information resource containing criminal justice legislation, case summaries, regulations, offence codes, and other legal material used across England and Wales.

The post advertises approximately 135,000 law enforcement contact records. A published sample contains names, email addresses, phone numbers, police force areas, internal contact identifiers, account verification fields, and other profile metadata.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ช๐Ÿ‡ธ Spanish Ministry of Foreign Affairs dataset containing 1.95 million records allegedly listed for sale

A forum actor claims to have exploited an IDOR vulnerability in a system tied to Spainโ€™s Ministry of Foreign Affairs, European Union and Cooperation, allowing the enumeration and extraction of 1,953,721 registered user profiles.

The listing advertises a 2.45GB JSON archive for $1,500. The allegedly exposed information includes full names, primary and secondary email addresses, dates of birth, nationalities, phone numbers, identity document types and numbers, home addresses, countries, localities, postal codes, internal IP addresses, authentication tokens, CSRF values, company identifiers, user IDs, and internal platform metadata.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿ”ฅ1
๐Ÿšจ Coinbase Cartel ransomware group launches partnership program for data and access brokers

The cybercrime group calling itself Coinbase Cartel is recruiting individuals and teams with exclusive stolen data or access to compromised organizations, offering to manage the extortion process through payment.

The group advertises negotiable revenue splits of up to 90/10 for exclusive datasets and up to 50/50 for corporate access. It is also seeking established access providers for long-term partnerships and says individuals with specialized skills, including social engineering, may be considered.

The advertisement directs prospective partners to the groupโ€™s dark web site and encrypted contact channel. The group is not affiliated with the Coinbase cryptocurrency exchange.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โค1๐Ÿ”ฅ1
โ€ผ๏ธ New Ransomware Group: Global Secret Group

Dark Web Onion: http://o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad[.]onion
โค1
โ€ผ๏ธ New Ransomware Group: SECTION9

Dark Web Onion: http://v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd[.]onion
โค2
I tried many times today to incorporate XSS into the feed, but it is constantly giving a 502 error. So when they finally get their act together, I will be able to take care of it. ๐Ÿคทโ€โ™€๏ธ
โค1