๐Ÿ”ช That Dark Web Guy - Part 3 ๐Ÿ”ช
4.88K subscribers
1.16K photos
66 videos
1.04K links
Download Telegram
๐Ÿšจ๐Ÿ‡ฒ๐Ÿ‡ฝ National Institute of Anthropology and History systems allegedly compromised

A forum actor claims to have compromised systems belonging to Mexicoโ€™s National Institute of Anthropology and History, a federal agency responsible for preserving and managing the countryโ€™s archaeological, anthropological, historical, and cultural heritage.

Published screenshots allegedly show access to an internal case management portal and documents containing personal information. The exposed data appears to include names, government identification numbers, addresses, phone numbers, email addresses, application details, case numbers, submission dates, and internal workflow records.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
XSS is now actively being tracked on the threat feed. Currently the thread view is not native. I pushed a fix and I am waiting for the cycle to complete.
โค1๐Ÿ”ฅ1
What a boring fucking day chat. ๐Ÿ˜ญ
๐Ÿ˜ญ6
๐ŸšจTG Core Telegram automation toolkit source code allegedly offered for sale

A forum seller is advertising the source code for TG Core, a Telegram automation framework designed to manage large pools of accounts and proxies while supporting custom tools built on the MTProto protocol.

The listing claims the toolkit can import Telegram Desktop session data, verify account status, scrape users from public groups and channels, automate invitations in batches, manage SOCKS proxies, handle Telegram API restrictions, and export results in JSON or CSV. Only five copies are reportedly available, with the project listed for 300 and a $50 discount offered to the first three buyers.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โค1
โ€ผ๏ธ๐Ÿ‡ฌ๐Ÿ‡ง Coinbase Cartel names a UK company

๐Ÿ‡ฌ๐Ÿ‡ง Accesso - A UK-based provider of ticketing, virtual queuing, payment, and guest experience software for attractions and entertainment venues.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿšจ An autonomous AI agent escaped an OpenAI evaluation sandbox, compromised a third-party sandbox, then breached Hugging Face through malicious datasets.

It executed roughly 17,600 actions, moved laterally & accessed challenge solutions. Hugging Face put together this reconstruction.

Article: https://huggingface.co/blog/agent-intrusion-technical-timeline
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
โค2
๐Ÿšจ๐Ÿ‡จ๐Ÿ‡ท Costa Rican identity documents and KYC records allegedly leaked

A forum actor claims to have published a large collection of documents linked to individuals in Costa Rica, including identity cards, driverโ€™s licenses, selfies, and know-your-customer records.

The post advertises access to as many as 20,000 document sets and includes several sample links.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ฒ๐Ÿ‡ฝ๐Ÿ‡ณ๐Ÿ‡ฎ UNIVIM and UNCSM student photos allegedly leaked

A forum actor claims to have exploited an IDOR vulnerability affecting student portals operated by Mexicoโ€™s Universidad Virtual del Estado de Michoacรกn and Nicaraguaโ€™s Universidad Nacional Casimiro Sotelo Montenegro.

The post advertises 275 student profile photos. The actor claims valid user identifiers were enumerated and the images were collected through an automated scraping process before being published through a download link.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ง๐Ÿ‡ช๐Ÿ‡ฉ๐Ÿ‡ช European bank accounts and Stripe merchant access allegedly offered for sale

A forum actor is advertising access to bank accounts in Belgium and Germany capable of receiving instant SEPA transfers, along with European Stripe and e-commerce merchant accounts for processing card payments.

The listing prices the access between $5,000 and $10,000 and proposes a revenue-sharing arrangement in which the actor retains 40% of the proceeds.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
โค1
๐Ÿšจ Access credentials for billion-dollar company allegedly compromised

A forum actor claims to possess API keys and remote MySQL connection details belonging to an unidentified company with more than $1 billion in annual revenue. The actor says database access is currently blocked by an IP whitelist.

The post seeks assistance from someone with web intrusion and ransomware expertise to access the database and extract customer identification photos and other files stored in an AWS environment.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡บ๐Ÿ‡ธ 23 million US clinic patient records allegedly offered for sale

A forum actor claims to be selling approximately 23 million patient records obtained from an unidentified clinic in the United States. The actor says the website data was collected in July 2026 and is being sold privately to a single buyer.

The advertised data allegedly includes names, dates of birth, gender, addresses, phone numbers, email addresses, postal codes, shipment dates, doctor names, financial responsibility fields, portal data, transaction identifiers, and internal record IDs. The full dataset is priced at $5,000, with smaller batches of one million records offered for $300.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โ€ผ๏ธ๐Ÿ‡ฌ๐Ÿ‡ง ExfilSquad ransomware earlier this week claimed a lot of big companies including the UK's Department of Education.

While there was doubt on many of these claims, it seems the DfE hack is legitimate.

Source: https://www.independent.co.uk/news/uk/politics/data-leak-education-department-hack-teachers-b3023943.html
โค1