‼️ New Dark Web Informer Blog Post!
Title: Silvi AI User Data Allegedly Exposed via API Flaw, 16,483 Researcher Records Published
Link: https://darkwebinformer.com/silvi-ai-user-data-allegedly-exposed-via-api-flaw-16-483-researcher-records-published/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Silvi AI User Data Allegedly Exposed via API Flaw, 16,483 Researcher Records Published
Link: https://darkwebinformer.com/silvi-ai-user-data-allegedly-exposed-via-api-flaw-16-483-researcher-records-published/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Silvi AI User Data Allegedly Exposed via API Flaw, 16,483 Researcher Records Published
A forum user posting as NightBroker has published what they describe as the user database of Silvi AI, a Danish service that automates academic literature reviews.
‼️ Amgen Inc. has filed form 8-K due to a Cybersecurity incident
https://www.sec.gov/Archives/edgar/data/318154/000031815426000119/amgn-20260729.htm
In July 2026, Amgen Inc. (the "Company") identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. Upon detecting the activity, the Company activated its cybersecurity response plan, implemented containment measures, and engaged independent cybersecurity forensic experts.
The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments. To date, the Company has not identified any impact to its products, manufacturing operations, or financial reporting systems, or to the Company's ability to meet patient needs. The investigation remains ongoing. The Company continues to assess whether, and/or the extent to which, patient, confidential business information, intellectual property, research and development, or other information may have been accessed, acquired, or exfiltrated and to evaluate the potential impact of the incident on the Company.
On July 29, 2026, in connection with our evaluation of the volume of the files that appear to have been impacted and the potential that the types of information in such files could be sensitive, the Company determined that this incident is material.
The Company believes, as of the date of this Current Report on Form 8-K, that the incident is not reasonably likely to have a material impact on the Company's financial condition or results of operations.
The Company takes its obligation to safeguard privacy and security of its patients’ data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients.
To the extent any information required by Item 1.05(a) of Form 8-K was not determined or was unavailable at the time of this filing, the Company will amend this Current Report on Form 8-K as such information is determined or becomes available.
https://www.sec.gov/Archives/edgar/data/318154/000031815426000119/amgn-20260729.htm
In July 2026, Amgen Inc. (the "Company") identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. Upon detecting the activity, the Company activated its cybersecurity response plan, implemented containment measures, and engaged independent cybersecurity forensic experts.
The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments. To date, the Company has not identified any impact to its products, manufacturing operations, or financial reporting systems, or to the Company's ability to meet patient needs. The investigation remains ongoing. The Company continues to assess whether, and/or the extent to which, patient, confidential business information, intellectual property, research and development, or other information may have been accessed, acquired, or exfiltrated and to evaluate the potential impact of the incident on the Company.
On July 29, 2026, in connection with our evaluation of the volume of the files that appear to have been impacted and the potential that the types of information in such files could be sensitive, the Company determined that this incident is material.
The Company believes, as of the date of this Current Report on Form 8-K, that the incident is not reasonably likely to have a material impact on the Company's financial condition or results of operations.
The Company takes its obligation to safeguard privacy and security of its patients’ data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients.
To the extent any information required by Item 1.05(a) of Form 8-K was not determined or was unavailable at the time of this filing, the Company will amend this Current Report on Form 8-K as such information is determined or becomes available.
Forwarded from Dark Web Informer - Private
Cybersecurity Incident Disclosure
Fri, 31 Jul 2026 16:03:44 EDT
A cybersecurity incident has been disclosed by AMGEN INC, Inc CIK: 0000318154, Ticker: $AMGN.
View SEC Filing
Fri, 31 Jul 2026 16:03:44 EDT
A cybersecurity incident has been disclosed by AMGEN INC, Inc CIK: 0000318154, Ticker: $AMGN.
View SEC Filing
yesitsme: A Python-based OSINT tool that helps users locate Instagram profiles potentially connected to a person’s name, email address, or phone number.
GitHub: https://github.com/0x0be/yesitsme
The script collects usernames indexed by Dumpor and uses Toutatis to obtain partially masked contact details for each account.
It then compares those details with the information provided by the user, reducing the amount of manual research required.
GitHub: https://github.com/0x0be/yesitsme
The script collects usernames indexed by Dumpor and uses Toutatis to obtain partially masked contact details for each account.
It then compares those details with the information provided by the user, reducing the amount of manual research required.
"Sleep at Night Technology" 🤡
Re: https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep
Re: https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep
🔥1😭1
🔪 Slice For Life - Part 2 🔪
🚨🇺🇸 Minnesota water systems hit in two-day wave of coordinated OT attacks More than 30 community water systems were targeted on July 26 and 27, triggering a statewide cybersecurity response. Braham’s water plant was temporarily knocked offline after attackers…
‼️🇺🇸 The Washington Post reports: "U.S. intelligence agencies have assessed that Iran was likely behind a coordinated cyberattack on more than 30 municipal water systems in Minnesota this week, according to several U.S. officials."
https://www.washingtonpost.com/national-security/2026/07/30/us-spy-agencies-suspect-iran-launched-cyberattack-minnesota-water-facilities/
https://www.washingtonpost.com/national-security/2026/07/30/us-spy-agencies-suspect-iran-launched-cyberattack-minnesota-water-facilities/
The Washington Post
U.S. spy agencies suspect Iran launched cyberattack on Minnesota water facilities
Intelligence agencies have assessed that Iran was likely behind a coordinated attack on more than 30 municipal water systems in the state.
🚨🇹🇷 Denizli Private Egekent Hospital patient data allegedly leaked
A forum actor claims to have leaked a database belonging to Denizli Private Egekent Hospital in Turkey. The post advertises approximately 20,000 patient records and provides a free download link.
The data allegedly includes national identification numbers, names, gender, dates and places of birth, parents’ names, home addresses, visit dates and times, departments, doctors, room numbers, diagnoses, prescription numbers, prescribed medications, treatment fees, payment methods, and insurance provider information.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have leaked a database belonging to Denizli Private Egekent Hospital in Turkey. The post advertises approximately 20,000 patient records and provides a free download link.
The data allegedly includes national identification numbers, names, gender, dates and places of birth, parents’ names, home addresses, visit dates and times, departments, doctors, room numbers, diagnoses, prescription numbers, prescribed medications, treatment fees, payment methods, and insurance provider information.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️🇮🇩 A forum seller is offering alleged backend access to an Indonesian government system for $200, with escrow support offered for the transaction. No further details on the specific agency or data exposed are provided.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
😭2
🚨 Kyndryl Azure/Entra tenant data allegedly offered for sale
A forum actor claims to be selling an internal data dump belonging to Kyndryl, a global IT infrastructure services company operating across more than 60 countries. The actor says the data was downloaded directly from the company’s Azure/Entra environment using compromised credentials.
The listing advertises more than 170,000 records, including employee accounts, service accounts, administrative roles, display names, email addresses, and other tenant account information.
A sample containing 2,200 records was published alongside the post.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to be selling an internal data dump belonging to Kyndryl, a global IT infrastructure services company operating across more than 60 countries. The actor says the data was downloaded directly from the company’s Azure/Entra environment using compromised credentials.
The listing advertises more than 170,000 records, including employee accounts, service accounts, administrative roles, display names, email addresses, and other tenant account information.
A sample containing 2,200 records was published alongside the post.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇮🇶 Qi Mobile ISC customer data allegedly leaked
A forum actor claims to have breached Qi Mobile ISC, an Iraqi mobile telecommunications and digital services provider, and published a 2.03GB uncompressed database containing 970,949 unique customer profiles.
The listing advertises:
• 970,949 unique phone numbers
• 11,168 unique account numbers
• 357,504 unique IP addresses
• Session cookies, JWTs, and JSESSIONIDs
• KYC verification, payment, balance, and CSRF token activity
• Devices, applications, languages, API endpoints, REST paths, and session events
• First and last request, session, and activity timestamps
The actor also exposed an internal IP address and a Telegram bot token associated with the company’s infrastructure.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have breached Qi Mobile ISC, an Iraqi mobile telecommunications and digital services provider, and published a 2.03GB uncompressed database containing 970,949 unique customer profiles.
The listing advertises:
• 970,949 unique phone numbers
• 11,168 unique account numbers
• 357,504 unique IP addresses
• Session cookies, JWTs, and JSESSIONIDs
• KYC verification, payment, balance, and CSRF token activity
• Devices, applications, languages, API endpoints, REST paths, and session events
• First and last request, session, and activity timestamps
The actor also exposed an internal IP address and a Telegram bot token associated with the company’s infrastructure.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨 PedidosYa customer credentials allegedly leaked
EsqueleSquad claims to have leaked a database associated with PedidosYa, a Latin American food delivery platform operating across multiple countries.
The post advertises more than 9.25 million customer records connected to:
• Argentina
• Bolivia
• Chile
• Ecuador
• Paraguay
• Peru
• Uruguay
• Venezuela
The exposed data allegedly includes:
• Email addresses
• BLAKE3 password hashes
• Home addresses
• Country information
The actor published a database sample and claims the full SQL dump is available for free.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
EsqueleSquad claims to have leaked a database associated with PedidosYa, a Latin American food delivery platform operating across multiple countries.
The post advertises more than 9.25 million customer records connected to:
• Argentina
• Bolivia
• Chile
• Ecuador
• Paraguay
• Peru
• Uruguay
• Venezuela
The exposed data allegedly includes:
• Email addresses
• BLAKE3 password hashes
• Home addresses
• Country information
The actor published a database sample and claims the full SQL dump is available for free.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 Xplor Resamania member database allegedly leaked
A forum actor claims to have leaked a database belonging to Xplor Resamania, a fitness and sports club management platform. The post advertises 5,273,884 records linked to users and clubs across France, Switzerland, Belgium, Luxembourg, the United Kingdom, Germany, and Spain.
The exposed data allegedly includes:
• Names and dates of birth
• Email addresses and phone numbers
• Home addresses, cities, and postal codes
• Club names and locations
• Staff and account status fields
• Membership plans, prices, and subscription dates
• Cancellation dates and internal identifiers
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have leaked a database belonging to Xplor Resamania, a fitness and sports club management platform. The post advertises 5,273,884 records linked to users and clubs across France, Switzerland, Belgium, Luxembourg, the United Kingdom, Germany, and Spain.
The exposed data allegedly includes:
• Names and dates of birth
• Email addresses and phone numbers
• Home addresses, cities, and postal codes
• Club names and locations
• Staff and account status fields
• Membership plans, prices, and subscription dates
• Cancellation dates and internal identifiers
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
❤1
A 2nd wave of attacks attributed to the Coldcard hacker(s) is ongoing with 1,158.81 BTC stolen from 2,673 addresses...
Thread: https://x.com/glxyresearch/status/2083560940469981591
Thread: https://x.com/glxyresearch/status/2083560940469981591
X (formerly Twitter)
Galaxy Research (@glxyresearch) on X
We identified a 2nd wave of sweeps likely attributed to the same Coldcard hacker as the wave we described in the thread below.
We are now tracking 1,158.81 BTC stolen from 2,673 addresses and hel…
We are now tracking 1,158.81 BTC stolen from 2,673 addresses and hel…
❤1
‼️ A forum actor is offering for sale alleged access to a hospital/patient portal located in the Middle East, priced at $300.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
❤1
🚨🇫🇷 Groupe T2MC HR data and employee documents allegedly leaked
⠀
A forum actor claims to have leaked recruitment and human resources data belonging to Groupe T2MC, a French company specializing in industrial cleaning and reception services.
⠀
The listing advertises 26GB of supporting documents across approximately 82,000 files, including:
⠀
• Names, dates of birth and nationalities
• Addresses, email addresses and phone numbers
• Social Security numbers and employee codes
• Employment status, agencies, managers and applicants
• Contract types, hourly rates and working hours
• Contract dates, absence reasons and replacement details
• Identity cards, bank details and proof-of-address documents
• Health insurance cards, residence permits and work authorizations
• Schedules, purchase orders and internal HR comments
⠀
A sample containing personal and employment information was published alongside the post.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
A forum actor claims to have leaked recruitment and human resources data belonging to Groupe T2MC, a French company specializing in industrial cleaning and reception services.
⠀
The listing advertises 26GB of supporting documents across approximately 82,000 files, including:
⠀
• Names, dates of birth and nationalities
• Addresses, email addresses and phone numbers
• Social Security numbers and employee codes
• Employment status, agencies, managers and applicants
• Contract types, hourly rates and working hours
• Contract dates, absence reasons and replacement details
• Identity cards, bank details and proof-of-address documents
• Health insurance cards, residence permits and work authorizations
• Schedules, purchase orders and internal HR comments
⠀
A sample containing personal and employment information was published alongside the post.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🚨 ICARUS ClickFix malware delivery platform offered for rent
⠀
A forum seller is advertising ICARUS ClickFix, a traffic-management and payload-delivery platform designed to automate ClickFix campaigns while providing centralized control over server-side and client-side operations.
⠀
Advertised capabilities include:
⠀
• Real-time conversion analytics covering views, copied commands, CAPTCHA activity and payload executions
• Filtering by campaign token, country and time range
• Creation of uniquely named traffic streams with globally unique tracking links
• Centralized storage for EXE, DLL and MSI files up to 50MB
• Automated crypting and generation of token-specific executable builds
• Multi-engine AntiTotal scanning every five hours
• WordPress plugin generation that injects operator-controlled scripts through wp_head
• Telegram alerts for command executions and campaign activity
• Automatically generated commands for different integration methods
• A library of customizable CAPTCHA templates
• Real-time editing of visual elements without restarting the platform
• Full masking of plugin names, versions, authors and other metadata
• Configurable plugins designed to appear legitimate to administrators and security tools
• Cloaking intended to hide campaign infrastructure from bots and automated scanners
⠀
Rental pricing is advertised at:
⠀
• One week: $299
• Two weeks: $499
• One month: $799
⠀
The seller also offers temporary access in exchange for a review.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
A forum seller is advertising ICARUS ClickFix, a traffic-management and payload-delivery platform designed to automate ClickFix campaigns while providing centralized control over server-side and client-side operations.
⠀
Advertised capabilities include:
⠀
• Real-time conversion analytics covering views, copied commands, CAPTCHA activity and payload executions
• Filtering by campaign token, country and time range
• Creation of uniquely named traffic streams with globally unique tracking links
• Centralized storage for EXE, DLL and MSI files up to 50MB
• Automated crypting and generation of token-specific executable builds
• Multi-engine AntiTotal scanning every five hours
• WordPress plugin generation that injects operator-controlled scripts through wp_head
• Telegram alerts for command executions and campaign activity
• Automatically generated commands for different integration methods
• A library of customizable CAPTCHA templates
• Real-time editing of visual elements without restarting the platform
• Full masking of plugin names, versions, authors and other metadata
• Configurable plugins designed to appear legitimate to administrators and security tools
• Cloaking intended to hide campaign infrastructure from bots and automated scanners
⠀
Rental pricing is advertised at:
⠀
• One week: $299
• Two weeks: $499
• One month: $799
⠀
The seller also offers temporary access in exchange for a review.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
❤1😁1