πŸ”ͺ Slice For Life - Part 2 πŸ”ͺ
4.68K subscribers
1.07K photos
59 videos
959 links
Download Telegram
πŸš¨πŸ‡²πŸ‡½ SAIMEX citizen database allegedly leaked
β €
A forum actor claims to have leaked a database associated with SAIMEX, the State of Mexico’s citizen management and public services platform.
β €
The post advertises more than 134,000 records linked to government employees, journalists, academics, merchants and other citizens, including:
β €
β€’ Names and paternal and maternal surnames
β€’ Gender, age range and occupation
β€’ Countries and states of residence
β€’ Street addresses, house numbers and postal codes
β€’ Municipalities and neighborhoods
β€’ Phone numbers and email addresses
β€’ Applicant types and internal record identifiers
β €
This claim is currently unverified.
β €
πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡ΊπŸ‡Έ Wyndham Hotels & Resorts employee data allegedly offered for sale
β €
A forum actor claims to be selling an internal employee database belonging to Wyndham Hotels & Resorts, allegedly downloaded from the company’s Azure/Entra environment using compromised credentials.
β €
The listing advertises more than 9,000 records, including:
β €
β€’ Employee names and corporate email addresses
β€’ Job titles, phone numbers and physical addresses
β€’ Managers and direct-report relationships
β€’ User group memberships and tenant account details
β€’ Employee, service and other organizational accounts
β €
A sample containing 600 records was published alongside the listing.
β €
This claim is currently unverified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡¬πŸ‡§ InterContinental Hotels Group employee data allegedly offered for sale
β €
A forum actor claims to be selling an internal employee database belonging to InterContinental Hotels Group, allegedly downloaded from the company’s Azure/Entra environment using compromised credentials.
β €
The listing advertises more than 185,000 records, including:
β €
β€’ Employee names and corporate email addresses
β€’ Job titles, phone numbers and physical addresses
β€’ Managers and direct-report relationships
β€’ User group memberships and tenant account details
β€’ Employee, service and other organizational accounts
β €
A sample containing 5,000 records was published alongside the listing.
β €
This claim is currently unverified.
β €
πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡¨πŸ‡΄ Davivienda analytics models and system access allegedly offered for sale
β €
A forum actor claims to be selling data and system access obtained from a strategic partner of Davivienda, a Colombian financial services company. The listing references Emergia and analytics used to support Davivienda products and customer operations.
β €
The advertised material allegedly includes:
β €
β€’ AI and machine-learning analytics models
β€’ Potential-customer database analysis
β€’ Predictive models for Davivienda TMK products
β€’ Digital mobile credit models
β€’ Digital revolving credit models
β€’ Secured digital credit card analytics
β€’ Access to hosts and a monitoring server
β€’ User accounts, roles, creation dates and account statuses
β€’ Real-time access to a system reportedly updated daily
β €
The seller identifies one model as modelo_davivienda_crm_rot_tdc and claims additional ownership and model information is included. Access is priced at $999 in Monero.
β €
This claim is currently unverified.
β €
πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡·πŸ‡Ί Moscow Department of Health database allegedly offered for sale
β €
A forum actor claims to be selling a 2025 database associated with the Moscow Department of Health. The listing advertises approximately 87.85 million rows for $1,000.
β €
The exposed data allegedly includes:
β €
β€’ Names, dates of birth, gender and phone numbers
β€’ SNILS identifiers and compulsory medical insurance details
β€’ Passport and other identity document information
β€’ Residential and registration addresses
β€’ Employment and education details
β€’ Medical institution and physician information
β€’ Patient record numbers and preliminary diagnoses
β€’ Illness dates and treatment-related information
β€’ Laboratory orders, specimen collection details and test results
β€’ COVID-19 and other diagnostic testing records
β €
A sample containing personal, insurance, clinical and laboratory information was published alongside the listing.
β €
This claim is currently unverified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡¨πŸ‡³ Beijing Housing Fund Management Center citizen data allegedly offered for sale
β €
A forum actor claims to be selling a database associated with the Beijing Housing Fund Management Center, a government-linked housing and financial registry serving formally employed residents of Beijing.
β €
The listing advertises personal and employment-related information for approximately 17 million residents, including:
β €
β€’ Names and national identification numbers
β€’ Phone numbers and other contact details
β€’ Employer information
β€’ Housing fund and financial status data
β€’ Additional identity-linked registry information
β €
A sample was published alongside the listing. The full dataset is priced at $1,700.
β €
This claim is currently unverified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡·πŸ‡Ί WineStyle customer and buyer database allegedly offered for sale
β €
A forum actor claims to be selling a database belonging to WineStyle, a Russian omnichannel retailer specializing in wine, spirits and other imported alcoholic beverages.
β €
The listing advertises approximately 1.1 million B2C and B2B buyer records, including:
β €
β€’ Customer and corporate buyer names
β€’ Email addresses and phone numbers
β€’ Order identifiers
β€’ Complete purchase histories
β€’ Transactional and account-related information
β€’ Location-linked details associated with verified buyers
β €
The actor claims the database contains active retail and corporate customers and is only available as a complete dataset.
β €
This claim is currently unverified.
β €
πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡§πŸ‡· Brazilian Ministry of Defense documents allegedly leaked
β €
A forum actor claims to have published two confidential military reports associated with Brazil’s Ministry of Defense, covering advanced radar, tactical defense and space-based surveillance capabilities.
β €
The documents reportedly include:
β €
β€’ AI-assisted reconnaissance and threat prediction
β€’ Over-the-horizon radar capabilities
β€’ Early-warning and surveillance systems
β€’ Tactical defense infrastructure improvements
β€’ Military intelligence collection using surveillance satellites
β€’ Autonomous monitoring and AI-based analysis
β€’ Secure military communications
β€’ Detection of threats linked to state and non-state actors
β €
This claim is currently unverified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡²πŸ‡½ Hospital MΓ©xico Americano patient database and CT scans allegedly leaked
β €
A forum actor claims to have published a 9.1GB collection belonging to Hospital MΓ©xico Americano containing patient records and medical imaging files, including CT scans.
β €
The exposed data allegedly includes:
β €
β€’ Patient names and internal identifiers
β€’ Gender, dates of birth and ages
β€’ Study and accession numbers
β€’ Examination descriptions
β€’ Study dates and timestamps
β€’ Associated CT scan images
β €
This claim is currently unverified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 ZoomShift user and activity data allegedly leaked
β €
A forum actor claims to have leaked data belonging to ZoomShift, an employee scheduling and time-tracking platform used by restaurants, retailers and hospitality businesses.
β €
The post advertises 10,507 active user accounts, 865,963 PII rows and 4,139,178 event-log records, including:
β €
β€’ Email addresses and user and company identifiers
β€’ Subscription plans, billing terms, revenue data and user roles
β€’ Team sizes, industries and numbers of business locations
β€’ IP addresses, cities, countries and regions
β€’ GPS coordinates collected through clock-in geofencing
β€’ Device identifiers, models, brands and operating system details
β€’ Mobile carriers, languages and platforms
β€’ Visited URLs, page names and referral timestamps
β€’ UTM tracking parameters and Google Ads identifiers
β€’ Time zones, onboarding steps and employee invitation data
β €
The files are listed as 174MB compressed and approximately 1.84GB uncompressed.
β €
This claim is currently unverified.
β €
πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨 Dante AI user and activity data allegedly leaked
β €
A forum actor claims to have leaked data belonging to Dante AI, a platform used by businesses and individuals to build custom AI chatbots for customer support, lead generation and website integration.
β €
The post advertises 2,924,201 PII records and an equal number of event logs linked to 73,547 active users, more than 130,000 unique IP addresses and users across 200+ countries, including:
β €
β€’ Email addresses, IP addresses and device identifiers
β€’ Cities, countries, regions and GPS coordinates
β€’ Session IDs, UUIDs and authentication methods
β€’ Visited URLs, page paths and referral information
β€’ Chatbot identifiers and selected LLM models, including Claude, GPT-4, Opus and Sonnet
β€’ UTM parameters and Google, Facebook, LinkedIn, TikTok and Microsoft advertising identifiers
β€’ Browser, operating system, device, manufacturer and mobile carrier details
β€’ Languages, platforms and event timestamps
β€’ Subscription plans, Stripe checkout referral data and Zapier integration metadata
β €
The files are listed as 363MB compressed and approximately 5.5GB uncompressed.
β €
This claim is currently unverified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡ΈπŸ‡¦ Blackbox LTD subscriber and billing data allegedly leaked
β €
A forum actor claims to have leaked data belonging to Blackbox LTD, a value-added services provider operating across Beirut, Dubai and Riyadh that handles mobile subscription billing for Mobily and STC.
β €
The post advertises 59,903 unique Saudi phone numbers and 88,501 transaction events, including:
β €
β€’ Mobile phone numbers and transaction timestamps
β€’ Device models, iOS versions and mobile carriers
β€’ IP addresses and location information
β€’ Subscription, fraud and billing response codes
β€’ Internal API endpoints
β€’ Basic authentication credentials for billing APIs
β€’ Affiliate tags, pixel identifiers and advertising IDs
β€’ Server and customer IP addresses
β€’ Fraud flags, PIN codes, billing types and service identifiers
β €
The actor claims the records contain complete transaction histories.
β €
This claim is currently unverified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Skywalk Group WordPress source code and database allegedly leaked
β €
A forum actor claims to have breached Skywalk Group, a manufacturer of high-performance equipment for action and wind sports, and published data taken from the company’s WordPress website.
β €
The leaked material allegedly includes:
β €
β€’ WordPress website source code
β€’ The associated website database
β€’ A directory tree showing the affected files
β €
This claim is currently unverified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ An actor is seeking to recruit insider employees with high-privilege access to customer data at companies earning over €10 million in yearly revenue, offering 50% profit share for assistance in gaining unauthorized access.

πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡¨πŸ‡± ESCIPOL student records and photographs allegedly leaked
β €
A forum actor claims to have leaked data belonging to Chile’s Escuela de Investigaciones Policiales, the training academy associated with the PolicΓ­a de Investigaciones de Chile.
β €
The 252MB collection allegedly includes student, applicant, instructor and academic records, including:
β €
β€’ RUT national identification numbers
β€’ Student and applicant names
β€’ Dates and places of birth
β€’ Gender and marital status
β€’ Phone numbers and email addresses
β€’ Course and graduation-year information
β€’ Student photographs
β€’ Instructor names and identification numbers
β€’ Subjects, grades and curriculum details
β€’ Evaluation answers and completion statuses
β€’ Current enrollment and probation statuses
β €
The post references 160 detailed student records, 170 academic-grade records and 960 additional student records. Samples containing personal information and student photographs.
β €
This claim is currently unverified.
β €
πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
❀1