🔪 Slice For Life - Part 2 🔪
4.69K subscribers
1.07K photos
59 videos
960 links
Download Telegram
🚨‼️ ShinyHunters claims 3 more victims

🇫🇷 Questel SAS - A Paris-based provider of intellectual-property, innovation-management, and legal software and services. The listing claims more than 21 million Salesforce records containing some PII and over 147 GB of internal corporate data.

🇮🇱 Lumenis Ltd. - An Israeli medical-technology company developing laser, intense-pulsed-light, and radio-frequency systems for aesthetic and vision treatments. The listing claims 1.1 million customer and employee records containing some PII and over 176 GB of internal corporate data.

🇨🇭 Alcon Inc. - A Switzerland-headquartered eye-care company producing surgical equipment, contact lenses, and other vision-care products. The listing claims more than 25 million Salesforce records containing some PII.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
😈1
🚨🇲🇽 SAIMEX citizen database allegedly leaked

A forum actor claims to have leaked a database associated with SAIMEX, the State of Mexico’s citizen management and public services platform.

The post advertises more than 134,000 records linked to government employees, journalists, academics, merchants and other citizens, including:

• Names and paternal and maternal surnames
• Gender, age range and occupation
• Countries and states of residence
• Street addresses, house numbers and postal codes
• Municipalities and neighborhoods
• Phone numbers and email addresses
• Applicant types and internal record identifiers

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇺🇸 Wyndham Hotels & Resorts employee data allegedly offered for sale

A forum actor claims to be selling an internal employee database belonging to Wyndham Hotels & Resorts, allegedly downloaded from the company’s Azure/Entra environment using compromised credentials.

The listing advertises more than 9,000 records, including:

• Employee names and corporate email addresses
• Job titles, phone numbers and physical addresses
• Managers and direct-report relationships
• User group memberships and tenant account details
• Employee, service and other organizational accounts

A sample containing 600 records was published alongside the listing.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇬🇧 InterContinental Hotels Group employee data allegedly offered for sale

A forum actor claims to be selling an internal employee database belonging to InterContinental Hotels Group, allegedly downloaded from the company’s Azure/Entra environment using compromised credentials.

The listing advertises more than 185,000 records, including:

• Employee names and corporate email addresses
• Job titles, phone numbers and physical addresses
• Managers and direct-report relationships
• User group memberships and tenant account details
• Employee, service and other organizational accounts

A sample containing 5,000 records was published alongside the listing.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇨🇴 Davivienda analytics models and system access allegedly offered for sale

A forum actor claims to be selling data and system access obtained from a strategic partner of Davivienda, a Colombian financial services company. The listing references Emergia and analytics used to support Davivienda products and customer operations.

The advertised material allegedly includes:

• AI and machine-learning analytics models
• Potential-customer database analysis
• Predictive models for Davivienda TMK products
• Digital mobile credit models
• Digital revolving credit models
• Secured digital credit card analytics
• Access to hosts and a monitoring server
• User accounts, roles, creation dates and account statuses
• Real-time access to a system reportedly updated daily

The seller identifies one model as modelo_davivienda_crm_rot_tdc and claims additional ownership and model information is included. Access is priced at $999 in Monero.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇷🇺 Moscow Department of Health database allegedly offered for sale

A forum actor claims to be selling a 2025 database associated with the Moscow Department of Health. The listing advertises approximately 87.85 million rows for $1,000.

The exposed data allegedly includes:

• Names, dates of birth, gender and phone numbers
• SNILS identifiers and compulsory medical insurance details
• Passport and other identity document information
• Residential and registration addresses
• Employment and education details
• Medical institution and physician information
• Patient record numbers and preliminary diagnoses
• Illness dates and treatment-related information
• Laboratory orders, specimen collection details and test results
• COVID-19 and other diagnostic testing records

A sample containing personal, insurance, clinical and laboratory information was published alongside the listing.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇨🇳 Beijing Housing Fund Management Center citizen data allegedly offered for sale

A forum actor claims to be selling a database associated with the Beijing Housing Fund Management Center, a government-linked housing and financial registry serving formally employed residents of Beijing.

The listing advertises personal and employment-related information for approximately 17 million residents, including:

• Names and national identification numbers
• Phone numbers and other contact details
• Employer information
• Housing fund and financial status data
• Additional identity-linked registry information

A sample was published alongside the listing. The full dataset is priced at $1,700.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇷🇺 WineStyle customer and buyer database allegedly offered for sale

A forum actor claims to be selling a database belonging to WineStyle, a Russian omnichannel retailer specializing in wine, spirits and other imported alcoholic beverages.

The listing advertises approximately 1.1 million B2C and B2B buyer records, including:

• Customer and corporate buyer names
• Email addresses and phone numbers
• Order identifiers
• Complete purchase histories
• Transactional and account-related information
• Location-linked details associated with verified buyers

The actor claims the database contains active retail and corporate customers and is only available as a complete dataset.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇧🇷 Brazilian Ministry of Defense documents allegedly leaked

A forum actor claims to have published two confidential military reports associated with Brazil’s Ministry of Defense, covering advanced radar, tactical defense and space-based surveillance capabilities.

The documents reportedly include:

• AI-assisted reconnaissance and threat prediction
• Over-the-horizon radar capabilities
• Early-warning and surveillance systems
• Tactical defense infrastructure improvements
• Military intelligence collection using surveillance satellites
• Autonomous monitoring and AI-based analysis
• Secure military communications
• Detection of threats linked to state and non-state actors

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇲🇽 Hospital México Americano patient database and CT scans allegedly leaked

A forum actor claims to have published a 9.1GB collection belonging to Hospital México Americano containing patient records and medical imaging files, including CT scans.

The exposed data allegedly includes:

• Patient names and internal identifiers
• Gender, dates of birth and ages
• Study and accession numbers
• Examination descriptions
• Study dates and timestamps
• Associated CT scan images

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 ZoomShift user and activity data allegedly leaked

A forum actor claims to have leaked data belonging to ZoomShift, an employee scheduling and time-tracking platform used by restaurants, retailers and hospitality businesses.

The post advertises 10,507 active user accounts, 865,963 PII rows and 4,139,178 event-log records, including:

• Email addresses and user and company identifiers
• Subscription plans, billing terms, revenue data and user roles
• Team sizes, industries and numbers of business locations
• IP addresses, cities, countries and regions
• GPS coordinates collected through clock-in geofencing
• Device identifiers, models, brands and operating system details
• Mobile carriers, languages and platforms
• Visited URLs, page names and referral timestamps
• UTM tracking parameters and Google Ads identifiers
• Time zones, onboarding steps and employee invitation data

The files are listed as 174MB compressed and approximately 1.84GB uncompressed.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨 Dante AI user and activity data allegedly leaked

A forum actor claims to have leaked data belonging to Dante AI, a platform used by businesses and individuals to build custom AI chatbots for customer support, lead generation and website integration.

The post advertises 2,924,201 PII records and an equal number of event logs linked to 73,547 active users, more than 130,000 unique IP addresses and users across 200+ countries, including:

• Email addresses, IP addresses and device identifiers
• Cities, countries, regions and GPS coordinates
• Session IDs, UUIDs and authentication methods
• Visited URLs, page paths and referral information
• Chatbot identifiers and selected LLM models, including Claude, GPT-4, Opus and Sonnet
• UTM parameters and Google, Facebook, LinkedIn, TikTok and Microsoft advertising identifiers
• Browser, operating system, device, manufacturer and mobile carrier details
• Languages, platforms and event timestamps
• Subscription plans, Stripe checkout referral data and Zapier integration metadata

The files are listed as 363MB compressed and approximately 5.5GB uncompressed.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇸🇦 Blackbox LTD subscriber and billing data allegedly leaked

A forum actor claims to have leaked data belonging to Blackbox LTD, a value-added services provider operating across Beirut, Dubai and Riyadh that handles mobile subscription billing for Mobily and STC.

The post advertises 59,903 unique Saudi phone numbers and 88,501 transaction events, including:

• Mobile phone numbers and transaction timestamps
• Device models, iOS versions and mobile carriers
• IP addresses and location information
• Subscription, fraud and billing response codes
• Internal API endpoints
• Basic authentication credentials for billing APIs
• Affiliate tags, pixel identifiers and advertising IDs
• Server and customer IP addresses
• Fraud flags, PIN codes, billing types and service identifiers

The actor claims the records contain complete transaction histories.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Skywalk Group WordPress source code and database allegedly leaked

A forum actor claims to have breached Skywalk Group, a manufacturer of high-performance equipment for action and wind sports, and published data taken from the company’s WordPress website.

The leaked material allegedly includes:

• WordPress website source code
• The associated website database
• A directory tree showing the affected files

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ An actor is seeking to recruit insider employees with high-privilege access to customer data at companies earning over €10 million in yearly revenue, offering 50% profit share for assistance in gaining unauthorized access.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing