๐จ๐ช๐ฌ Alfa Coatings ERP database allegedly offered for sale
A forum actor claims to be selling a complete ERP database belonging to Alfa Coatings, an Egyptian manufacturer of coatings and chemical products. The alleged SQL export contains 4,345 tables and approximately 2.5GB of raw data covering accounting, human resources, inventory, production, and customer management systems.
The listing advertises records for 320 employees, 3,211 B2B customers, 318 suppliers, 4,181 inventory items, 1,103 sales invoices, 629 purchase invoices, 24 ERP users, eight bank accounts, and 194 external contacts. Published samples allegedly include names, corporate email addresses, phone numbers, customer and supplier details, transaction records, bank information, and ERP password hashes.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling a complete ERP database belonging to Alfa Coatings, an Egyptian manufacturer of coatings and chemical products. The alleged SQL export contains 4,345 tables and approximately 2.5GB of raw data covering accounting, human resources, inventory, production, and customer management systems.
The listing advertises records for 320 employees, 3,211 B2B customers, 318 suppliers, 4,181 inventory items, 1,103 sales invoices, 629 purchase invoices, 24 ERP users, eight bank accounts, and 194 external contacts. Published samples allegedly include names, corporate email addresses, phone numbers, customer and supplier details, transaction records, bank information, and ERP password hashes.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
๐จ๐ฎ๐ณ Nukkad Shops customer data allegedly offered for sale
A forum actor claims to be selling customer data belonging to Nukkad Shops, an Indian retail technology company. The listing advertises approximately 6.6 million records for $5,000.
The exposed data allegedly includes customer names, mobile numbers, email addresses, street addresses, states, cities, and localities. Published samples contain records associated with customers in Hyderabad and other locations across Telangana.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling customer data belonging to Nukkad Shops, an Indian retail technology company. The listing advertises approximately 6.6 million records for $5,000.
The exposed data allegedly includes customer names, mobile numbers, email addresses, street addresses, states, cities, and localities. Published samples contain records associated with customers in Hyderabad and other locations across Telangana.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
๐จ๐ฒ๐ฝ National Institute of Anthropology and History systems allegedly compromised
A forum actor claims to have compromised systems belonging to Mexicoโs National Institute of Anthropology and History, a federal agency responsible for preserving and managing the countryโs archaeological, anthropological, historical, and cultural heritage.
Published screenshots allegedly show access to an internal case management portal and documents containing personal information. The exposed data appears to include names, government identification numbers, addresses, phone numbers, email addresses, application details, case numbers, submission dates, and internal workflow records.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to have compromised systems belonging to Mexicoโs National Institute of Anthropology and History, a federal agency responsible for preserving and managing the countryโs archaeological, anthropological, historical, and cultural heritage.
Published screenshots allegedly show access to an internal case management portal and documents containing personal information. The exposed data appears to include names, government identification numbers, addresses, phone numbers, email addresses, application details, case numbers, submission dates, and internal workflow records.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
XSS is now actively being tracked on the threat feed. Currently the thread view is not native. I pushed a fix and I am waiting for the cycle to complete.
โค1๐ฅ1
โผ๏ธ New Dark Web Informer Blog Post!
Title: Shopee Customer Database Allegedly for Sale, 300 Million Records Claimed Across Asia and Latin America
Link: https://darkwebinformer.com/shopee-customer-database-allegedly-for-sale-300-million-records-claimed-across-asia-and-latin-america/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Shopee Customer Database Allegedly for Sale, 300 Million Records Claimed Across Asia and Latin America
Link: https://darkwebinformer.com/shopee-customer-database-allegedly-for-sale-300-million-records-claimed-across-asia-and-latin-america/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Shopee Customer Database Allegedly for Sale, 300 Million Records Claimed Across Asia and Latin America
A seller posting as 666op is advertising what they describe as a customer database from Shopee, the e-commerce marketplace operated by Sea Limited.
๐ช That Dark Web Guy - Part 2 ๐ช
๐จโผ๏ธ CVE-2026-61511: A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server. CVSS: 9.8 Exploit: https://ssd-disclosure.com/vbulletin-runtimeโฆ
โผ๏ธ CVE-2026-61511: Improper Neutralization of Directives in Dynamically Evaluated Code
FOFA Query: app="vBulletin"
FOFA: https://en.fofa.info/result?qbase64=YXBwPSJ2QnVsbGV0aW4i
Results: 11,081
FOFA Query: app="vBulletin"
FOFA: https://en.fofa.info/result?qbase64=YXBwPSJ2QnVsbGV0aW4i
Results: 11,081
โผ๏ธ New Dark Web Informer Blog Post!
Title: Planity Database Allegedly for Sale, 999,451 Customers of French Salons and Spas Listed
Link: https://darkwebinformer.com/planity-database-allegedly-for-sale-999-451-customers-of-french-salons-and-spas-listed/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Planity Database Allegedly for Sale, 999,451 Customers of French Salons and Spas Listed
Link: https://darkwebinformer.com/planity-database-allegedly-for-sale-999-451-customers-of-french-salons-and-spas-listed/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Planity Database Allegedly for Sale, 999,451 Customers of French Salons and Spas Listed
A seller posting as weykofa is advertising what they describe as the database of Planity, the French online booking platform used by hair salons, beauty businesses, and spas to manage appointments and customer records.
๐จTG Core Telegram automation toolkit source code allegedly offered for sale
A forum seller is advertising the source code for TG Core, a Telegram automation framework designed to manage large pools of accounts and proxies while supporting custom tools built on the MTProto protocol.
The listing claims the toolkit can import Telegram Desktop session data, verify account status, scrape users from public groups and channels, automate invitations in batches, manage SOCKS proxies, handle Telegram API restrictions, and export results in JSON or CSV. Only five copies are reportedly available, with the project listed for 300 and a $50 discount offered to the first three buyers.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum seller is advertising the source code for TG Core, a Telegram automation framework designed to manage large pools of accounts and proxies while supporting custom tools built on the MTProto protocol.
The listing claims the toolkit can import Telegram Desktop session data, verify account status, scrape users from public groups and channels, automate invitations in batches, manage SOCKS proxies, handle Telegram API restrictions, and export results in JSON or CSV. Only five copies are reportedly available, with the project listed for 300 and a $50 discount offered to the first three buyers.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โค1
โผ๏ธ๐ฌ๐ง Coinbase Cartel names a UK company
๐ฌ๐ง Accesso - A UK-based provider of ticketing, virtual queuing, payment, and guest experience software for attractions and entertainment venues.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐ฌ๐ง Accesso - A UK-based provider of ticketing, virtual queuing, payment, and guest experience software for attractions and entertainment venues.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
This media is not supported in your browser
VIEW IN TELEGRAM
๐จ An autonomous AI agent escaped an OpenAI evaluation sandbox, compromised a third-party sandbox, then breached Hugging Face through malicious datasets.
It executed roughly 17,600 actions, moved laterally & accessed challenge solutions. Hugging Face put together this reconstruction.
Article: https://huggingface.co/blog/agent-intrusion-technical-timeline
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
It executed roughly 17,600 actions, moved laterally & accessed challenge solutions. Hugging Face put together this reconstruction.
Article: https://huggingface.co/blog/agent-intrusion-technical-timeline
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
โค2
โผ๏ธ New Dark Web Informer Blog Post!
Title: Lire Demain Database Allegedly Leaked, 5,974 School and Local Authority Client Records Published
Link: https://darkwebinformer.com/lire-demain-database-allegedly-leaked-5-974-school-and-local-authority-client-records-published/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Lire Demain Database Allegedly Leaked, 5,974 School and Local Authority Client Records Published
Link: https://darkwebinformer.com/lire-demain-database-allegedly-leaked-5-974-school-and-local-authority-client-records-published/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Lire Demain Database Allegedly Leaked, 5,974 School and Local Authority Client Records Published
A forum user posting as 0xSec has published what they describe as the database of Lire Demain, the schools and institutions network of the French children's publisher Auzou, which supplies books, kamishibai theatres, and educational materials to schools,โฆ
๐จ๐จ๐ท Costa Rican identity documents and KYC records allegedly leaked
A forum actor claims to have published a large collection of documents linked to individuals in Costa Rica, including identity cards, driverโs licenses, selfies, and know-your-customer records.
The post advertises access to as many as 20,000 document sets and includes several sample links.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have published a large collection of documents linked to individuals in Costa Rica, including identity cards, driverโs licenses, selfies, and know-your-customer records.
The post advertises access to as many as 20,000 document sets and includes several sample links.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐จ๐ฒ๐ฝ๐ณ๐ฎ UNIVIM and UNCSM student photos allegedly leaked
A forum actor claims to have exploited an IDOR vulnerability affecting student portals operated by Mexicoโs Universidad Virtual del Estado de Michoacรกn and Nicaraguaโs Universidad Nacional Casimiro Sotelo Montenegro.
The post advertises 275 student profile photos. The actor claims valid user identifiers were enumerated and the images were collected through an automated scraping process before being published through a download link.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to have exploited an IDOR vulnerability affecting student portals operated by Mexicoโs Universidad Virtual del Estado de Michoacรกn and Nicaraguaโs Universidad Nacional Casimiro Sotelo Montenegro.
The post advertises 275 student profile photos. The actor claims valid user identifiers were enumerated and the images were collected through an automated scraping process before being published through a download link.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ง๐ช๐ฉ๐ช European bank accounts and Stripe merchant access allegedly offered for sale
A forum actor is advertising access to bank accounts in Belgium and Germany capable of receiving instant SEPA transfers, along with European Stripe and e-commerce merchant accounts for processing card payments.
The listing prices the access between $5,000 and $10,000 and proposes a revenue-sharing arrangement in which the actor retains 40% of the proceeds.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor is advertising access to bank accounts in Belgium and Germany capable of receiving instant SEPA transfers, along with European Stripe and e-commerce merchant accounts for processing card payments.
The listing prices the access between $5,000 and $10,000 and proposes a revenue-sharing arrangement in which the actor retains 40% of the proceeds.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
โค1
๐จ Access credentials for billion-dollar company allegedly compromised
A forum actor claims to possess API keys and remote MySQL connection details belonging to an unidentified company with more than $1 billion in annual revenue. The actor says database access is currently blocked by an IP whitelist.
The post seeks assistance from someone with web intrusion and ransomware expertise to access the database and extract customer identification photos and other files stored in an AWS environment.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to possess API keys and remote MySQL connection details belonging to an unidentified company with more than $1 billion in annual revenue. The actor says database access is currently blocked by an IP whitelist.
The post seeks assistance from someone with web intrusion and ransomware expertise to access the database and extract customer identification photos and other files stored in an AWS environment.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing