๐จ๐ซ๐ท Three French fire and rescue services allegedly targeted in separate data leaks
Forum actors ChimeraZ and Cybernox claim to have leaked data tied to SDIS 06 in Alpes-Maritimes, SDIS 40 in Landes, and SDIS 04 in Alpes-de-Haute-Provence.
The SDIS 06 listing advertises 2,331 records covering 2,325 people and 15,833 files totaling 22.5GB. The SDIS 40 post references 241 records and 3,205 files totaling 11.8GB, while the SDIS 04 listing advertises 145 personnel records.
The allegedly exposed information includes firefightersโ names, dates of birth, nationalities, ranks, assignments, email addresses, phone numbers, home addresses, biographies, internal operational material, and other private documents.
These claims are currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
Forum actors ChimeraZ and Cybernox claim to have leaked data tied to SDIS 06 in Alpes-Maritimes, SDIS 40 in Landes, and SDIS 04 in Alpes-de-Haute-Provence.
The SDIS 06 listing advertises 2,331 records covering 2,325 people and 15,833 files totaling 22.5GB. The SDIS 40 post references 241 records and 3,205 files totaling 11.8GB, while the SDIS 04 listing advertises 145 personnel records.
The allegedly exposed information includes firefightersโ names, dates of birth, nationalities, ranks, assignments, email addresses, phone numbers, home addresses, biographies, internal operational material, and other private documents.
These claims are currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐จ๐ณ๐ฑ Netherlands contact dataset containing 14 million records allegedly listed for sale
A forum actor claims to be selling a 2026 dataset containing approximately 14 million records tied to individuals in the Netherlands.
The seller is asking 2,500 in an unspecified currency and says the dataset will be sold exclusively to one buyer.
The allegedly exposed information includes names, dates of birth, genders, identification numbers, email addresses, mobile and home phone numbers, job titles, departments, account details, record ownership and creation metadata, contact preferences, and linked social media identifiers.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to be selling a 2026 dataset containing approximately 14 million records tied to individuals in the Netherlands.
The seller is asking 2,500 in an unspecified currency and says the dataset will be sold exclusively to one buyer.
The allegedly exposed information includes names, dates of birth, genders, identification numbers, email addresses, mobile and home phone numbers, job titles, departments, account details, record ownership and creation metadata, contact preferences, and linked social media identifiers.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐บ๐ธ๐บ๐ธ๐ฉ๐ช Root CMS access to three major companies allegedly listed for sale
A forum actor claims to be selling privileged CMS access tied to two unnamed US pharmaceutical and biotechnology companies and the German rail-freight division of a national railway.
The three organizations reportedly generate approximately $84.4 billion in combined annual revenue. The listings advertise root access to 18 CMS instances, including systems distributed across 10 countries.
The seller claims the access provides full read and write capabilities, including access to records, user account creation, file uploads, and email creation. Asking prices are listed at $16,000 for the biotechnology company, $40,000 for the pharmaceutical company, and $12,000 for the rail-freight operator.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling privileged CMS access tied to two unnamed US pharmaceutical and biotechnology companies and the German rail-freight division of a national railway.
The three organizations reportedly generate approximately $84.4 billion in combined annual revenue. The listings advertise root access to 18 CMS instances, including systems distributed across 10 countries.
The seller claims the access provides full read and write capabilities, including access to records, user account creation, file uploads, and email creation. Asking prices are listed at $16,000 for the biotechnology company, $40,000 for the pharmaceutical company, and $12,000 for the rail-freight operator.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐จ๐ฏ๐ต๐จ๐ฆ๐ฎ๐ฑ Root CMS access to three government platforms allegedly listed for sale
A forum actor claims to be selling privileged CMS access tied to Nara Prefectureโs Nara Super App in Japan, New Brunswickโs MyHealthNB platform in Canada, and Israelโs National Digital Agency.
The listings advertise prices of $2,000 for Nara Super App, $10,000 for MyHealthNB, and $5,000 for the Israeli government system. The seller claims the access provides full read and write capabilities, including control over user accounts, file uploads, and email creation.
The actor gave potential buyers 48 hours to purchase the access after publicly naming the affected platforms.
These claims are currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to be selling privileged CMS access tied to Nara Prefectureโs Nara Super App in Japan, New Brunswickโs MyHealthNB platform in Canada, and Israelโs National Digital Agency.
The listings advertise prices of $2,000 for Nara Super App, $10,000 for MyHealthNB, and $5,000 for the Israeli government system. The seller claims the access provides full read and write capabilities, including control over user accounts, file uploads, and email creation.
The actor gave potential buyers 48 hours to purchase the access after publicly naming the affected platforms.
These claims are currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ฌ๐ง UK Department for Education contact records allegedly leaked
A forum actor claims to have breached systems tied to the UK Department for Education and obtained data from its Help Portal and Turing Portal.
The listing advertises approximately 600,000 parent and staff contact records from the Help Portal, along with around 7,000 additional records from the Turing Portal. Samples containing names, email addresses, phone numbers, job titles, and internal contact identifiers were posted on the forum.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to have breached systems tied to the UK Department for Education and obtained data from its Help Portal and Turing Portal.
The listing advertises approximately 600,000 parent and staff contact records from the Help Portal, along with around 7,000 additional records from the Turing Portal. Samples containing names, email addresses, phone numbers, job titles, and internal contact identifiers were posted on the forum.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ฌ๐ง UK Police National Legal Database contact records allegedly leaked
A forum actor claims to have breached the Police National Legal Database, a UK police information resource containing criminal justice legislation, case summaries, regulations, offence codes, and other legal material used across England and Wales.
The post advertises approximately 135,000 law enforcement contact records. A published sample contains names, email addresses, phone numbers, police force areas, internal contact identifiers, account verification fields, and other profile metadata.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have breached the Police National Legal Database, a UK police information resource containing criminal justice legislation, case summaries, regulations, offence codes, and other legal material used across England and Wales.
The post advertises approximately 135,000 law enforcement contact records. A published sample contains names, email addresses, phone numbers, police force areas, internal contact identifiers, account verification fields, and other profile metadata.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐จ๐ช๐ธ Spanish Ministry of Foreign Affairs dataset containing 1.95 million records allegedly listed for sale
A forum actor claims to have exploited an IDOR vulnerability in a system tied to Spainโs Ministry of Foreign Affairs, European Union and Cooperation, allowing the enumeration and extraction of 1,953,721 registered user profiles.
The listing advertises a 2.45GB JSON archive for $1,500. The allegedly exposed information includes full names, primary and secondary email addresses, dates of birth, nationalities, phone numbers, identity document types and numbers, home addresses, countries, localities, postal codes, internal IP addresses, authentication tokens, CSRF values, company identifiers, user IDs, and internal platform metadata.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to have exploited an IDOR vulnerability in a system tied to Spainโs Ministry of Foreign Affairs, European Union and Cooperation, allowing the enumeration and extraction of 1,953,721 registered user profiles.
The listing advertises a 2.45GB JSON archive for $1,500. The allegedly exposed information includes full names, primary and secondary email addresses, dates of birth, nationalities, phone numbers, identity document types and numbers, home addresses, countries, localities, postal codes, internal IP addresses, authentication tokens, CSRF values, company identifiers, user IDs, and internal platform metadata.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐ฅ1
๐ช Slice For Life - Part 2 ๐ช
โผ๏ธ New Dark Web Informer Blog Post! Title: Dutch Police Seize Motherless Servers in International CSAM and Sexual Abuse Investigation Link: https://darkwebinformer.com/dutch-police-seize-motherless-servers-in-international-csam-and-sexual-abuse-investigation/โฆ
They are trying to come back up chat, but their IP is leaking because they are fucking idiots.
88[.]80[.]24[.]250
88[.]80[.]24[.]250
๐ฅ4๐1
๐จ Coinbase Cartel ransomware group launches partnership program for data and access brokers
The cybercrime group calling itself Coinbase Cartel is recruiting individuals and teams with exclusive stolen data or access to compromised organizations, offering to manage the extortion process through payment.
The group advertises negotiable revenue splits of up to 90/10 for exclusive datasets and up to 50/50 for corporate access. It is also seeking established access providers for long-term partnerships and says individuals with specialized skills, including social engineering, may be considered.
The advertisement directs prospective partners to the groupโs dark web site and encrypted contact channel. The group is not affiliated with the Coinbase cryptocurrency exchange.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
The cybercrime group calling itself Coinbase Cartel is recruiting individuals and teams with exclusive stolen data or access to compromised organizations, offering to manage the extortion process through payment.
The group advertises negotiable revenue splits of up to 90/10 for exclusive datasets and up to 50/50 for corporate access. It is also seeking established access providers for long-term partnerships and says individuals with specialized skills, including social engineering, may be considered.
The advertisement directs prospective partners to the groupโs dark web site and encrypted contact channel. The group is not affiliated with the Coinbase cryptocurrency exchange.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โค1๐ฅ1
๐ช Slice For Life - Part 2 ๐ช
โผ๏ธ raidforums[.]ac -> raidforums[.]ru 15[.]197[.]162[.]184 ASN: 16509 Org: Amazon.com, Inc.
Both domains suspended.
๐ญ6๐5
I tried many times today to incorporate XSS into the feed, but it is constantly giving a 502 error. So when they finally get their act together, I will be able to take care of it. ๐คทโโ๏ธ
โค1
๐จ๐ฐ๐ท Access to unnamed South Korean software company allegedly listed for sale
A forum actor claims to be selling access to a South Korean company operating in the software and hospitality sectors, with reported annual revenue of approximately $10 million.
The listing advertises MariaDB, SSH, and SFTP access across approximately 33 servers.
No company name, asking price, sample data, or technical proof of access was publicly provided.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling access to a South Korean company operating in the software and hospitality sectors, with reported annual revenue of approximately $10 million.
The listing advertises MariaDB, SSH, and SFTP access across approximately 33 servers.
No company name, asking price, sample data, or technical proof of access was publicly provided.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐จ๐ซ๐ท French Archery Federation dataset allegedly listed for sale
A forum actor claims to be selling an updated database tied to the Fรฉdรฉration Franรงaise de Tir ร lโArc, Franceโs national governing body for archery. The seller says the data was obtained through SQL injection and that an earlier version was sold approximately 18 months ago.
The listing advertises around 658,000 address records, 378,000 unique email addresses, 354,000 unique phone numbers, 92,600 legal representative records, 15,000 primary accounts, and 27,800 secondary accounts. The allegedly exposed information includes names, contact details, postal addresses, geographic coordinates, usernames, password hashes, authentication statuses, account timestamps, IP addresses, and administrative metadata.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling an updated database tied to the Fรฉdรฉration Franรงaise de Tir ร lโArc, Franceโs national governing body for archery. The seller says the data was obtained through SQL injection and that an earlier version was sold approximately 18 months ago.
The listing advertises around 658,000 address records, 378,000 unique email addresses, 354,000 unique phone numbers, 92,600 legal representative records, 15,000 primary accounts, and 27,800 secondary accounts. The allegedly exposed information includes names, contact details, postal addresses, geographic coordinates, usernames, password hashes, authentication statuses, account timestamps, IP addresses, and administrative metadata.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โค1
๐จ๐ซ๐ท Cartogip contact dataset containing approximately 1,200 records allegedly leaked
A forum actor claims to have leaked contact data tied to Cartogip, a French web-based geographic information system developed by GIP ATGeRi for mapping, geospatial data, and field operations.
The allegedly exposed information includes names, titles, mobile and landline phone numbers, company or municipal organization names, job functions, customer numbers, liaison identifiers, and internal organization IDs.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have leaked contact data tied to Cartogip, a French web-based geographic information system developed by GIP ATGeRi for mapping, geospatial data, and field operations.
The allegedly exposed information includes names, titles, mobile and landline phone numbers, company or municipal organization names, job functions, customer numbers, liaison identifiers, and internal organization IDs.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials