๐Ÿ”ช That Dark Web Guy - Part 2 ๐Ÿ”ช
4.87K subscribers
1.15K photos
64 videos
1.02K links
Download Telegram
๐Ÿšจ๐Ÿ‡ช๐Ÿ‡ฌ Alfa Coatings ERP database allegedly offered for sale

A forum actor claims to be selling a complete ERP database belonging to Alfa Coatings, an Egyptian manufacturer of coatings and chemical products. The alleged SQL export contains 4,345 tables and approximately 2.5GB of raw data covering accounting, human resources, inventory, production, and customer management systems.

The listing advertises records for 320 employees, 3,211 B2B customers, 318 suppliers, 4,181 inventory items, 1,103 sales invoices, 629 purchase invoices, 24 ERP users, eight bank accounts, and 194 external contacts. Published samples allegedly include names, corporate email addresses, phone numbers, customer and supplier details, transaction records, bank information, and ERP password hashes.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
๐Ÿšจ๐Ÿ‡ฎ๐Ÿ‡ณ Nukkad Shops customer data allegedly offered for sale

A forum actor claims to be selling customer data belonging to Nukkad Shops, an Indian retail technology company. The listing advertises approximately 6.6 million records for $5,000.

The exposed data allegedly includes customer names, mobile numbers, email addresses, street addresses, states, cities, and localities. Published samples contain records associated with customers in Hyderabad and other locations across Telangana.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
๐Ÿšจ๐Ÿ‡ฒ๐Ÿ‡ฝ National Institute of Anthropology and History systems allegedly compromised

A forum actor claims to have compromised systems belonging to Mexicoโ€™s National Institute of Anthropology and History, a federal agency responsible for preserving and managing the countryโ€™s archaeological, anthropological, historical, and cultural heritage.

Published screenshots allegedly show access to an internal case management portal and documents containing personal information. The exposed data appears to include names, government identification numbers, addresses, phone numbers, email addresses, application details, case numbers, submission dates, and internal workflow records.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
XSS is now actively being tracked on the threat feed. Currently the thread view is not native. I pushed a fix and I am waiting for the cycle to complete.
โค1๐Ÿ”ฅ1
What a boring fucking day chat. ๐Ÿ˜ญ
๐Ÿ˜ญ6
๐ŸšจTG Core Telegram automation toolkit source code allegedly offered for sale

A forum seller is advertising the source code for TG Core, a Telegram automation framework designed to manage large pools of accounts and proxies while supporting custom tools built on the MTProto protocol.

The listing claims the toolkit can import Telegram Desktop session data, verify account status, scrape users from public groups and channels, automate invitations in batches, manage SOCKS proxies, handle Telegram API restrictions, and export results in JSON or CSV. Only five copies are reportedly available, with the project listed for 300 and a $50 discount offered to the first three buyers.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โค1
โ€ผ๏ธ๐Ÿ‡ฌ๐Ÿ‡ง Coinbase Cartel names a UK company

๐Ÿ‡ฌ๐Ÿ‡ง Accesso - A UK-based provider of ticketing, virtual queuing, payment, and guest experience software for attractions and entertainment venues.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿšจ An autonomous AI agent escaped an OpenAI evaluation sandbox, compromised a third-party sandbox, then breached Hugging Face through malicious datasets.

It executed roughly 17,600 actions, moved laterally & accessed challenge solutions. Hugging Face put together this reconstruction.

Article: https://huggingface.co/blog/agent-intrusion-technical-timeline
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
โค2
๐Ÿšจ๐Ÿ‡จ๐Ÿ‡ท Costa Rican identity documents and KYC records allegedly leaked

A forum actor claims to have published a large collection of documents linked to individuals in Costa Rica, including identity cards, driverโ€™s licenses, selfies, and know-your-customer records.

The post advertises access to as many as 20,000 document sets and includes several sample links.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ฒ๐Ÿ‡ฝ๐Ÿ‡ณ๐Ÿ‡ฎ UNIVIM and UNCSM student photos allegedly leaked

A forum actor claims to have exploited an IDOR vulnerability affecting student portals operated by Mexicoโ€™s Universidad Virtual del Estado de Michoacรกn and Nicaraguaโ€™s Universidad Nacional Casimiro Sotelo Montenegro.

The post advertises 275 student profile photos. The actor claims valid user identifiers were enumerated and the images were collected through an automated scraping process before being published through a download link.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ง๐Ÿ‡ช๐Ÿ‡ฉ๐Ÿ‡ช European bank accounts and Stripe merchant access allegedly offered for sale

A forum actor is advertising access to bank accounts in Belgium and Germany capable of receiving instant SEPA transfers, along with European Stripe and e-commerce merchant accounts for processing card payments.

The listing prices the access between $5,000 and $10,000 and proposes a revenue-sharing arrangement in which the actor retains 40% of the proceeds.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
โค1
๐Ÿšจ Access credentials for billion-dollar company allegedly compromised

A forum actor claims to possess API keys and remote MySQL connection details belonging to an unidentified company with more than $1 billion in annual revenue. The actor says database access is currently blocked by an IP whitelist.

The post seeks assistance from someone with web intrusion and ransomware expertise to access the database and extract customer identification photos and other files stored in an AWS environment.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing