π¨πΊπΈ Wyndham Hotels & Resorts employee data allegedly offered for sale
β
A forum actor claims to be selling an internal employee database belonging to Wyndham Hotels & Resorts, allegedly downloaded from the companyβs Azure/Entra environment using compromised credentials.
β
The listing advertises more than 9,000 records, including:
β
β’ Employee names and corporate email addresses
β’ Job titles, phone numbers and physical addresses
β’ Managers and direct-report relationships
β’ User group memberships and tenant account details
β’ Employee, service and other organizational accounts
β
A sample containing 600 records was published alongside the listing.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to be selling an internal employee database belonging to Wyndham Hotels & Resorts, allegedly downloaded from the companyβs Azure/Entra environment using compromised credentials.
β
The listing advertises more than 9,000 records, including:
β
β’ Employee names and corporate email addresses
β’ Job titles, phone numbers and physical addresses
β’ Managers and direct-report relationships
β’ User group memberships and tenant account details
β’ Employee, service and other organizational accounts
β
A sample containing 600 records was published alongside the listing.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π¬π§ InterContinental Hotels Group employee data allegedly offered for sale
β
A forum actor claims to be selling an internal employee database belonging to InterContinental Hotels Group, allegedly downloaded from the companyβs Azure/Entra environment using compromised credentials.
β
The listing advertises more than 185,000 records, including:
β
β’ Employee names and corporate email addresses
β’ Job titles, phone numbers and physical addresses
β’ Managers and direct-report relationships
β’ User group memberships and tenant account details
β’ Employee, service and other organizational accounts
β
A sample containing 5,000 records was published alongside the listing.
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
β
A forum actor claims to be selling an internal employee database belonging to InterContinental Hotels Group, allegedly downloaded from the companyβs Azure/Entra environment using compromised credentials.
β
The listing advertises more than 185,000 records, including:
β
β’ Employee names and corporate email addresses
β’ Job titles, phone numbers and physical addresses
β’ Managers and direct-report relationships
β’ User group memberships and tenant account details
β’ Employee, service and other organizational accounts
β
A sample containing 5,000 records was published alongside the listing.
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨π¨π΄ Davivienda analytics models and system access allegedly offered for sale
β
A forum actor claims to be selling data and system access obtained from a strategic partner of Davivienda, a Colombian financial services company. The listing references Emergia and analytics used to support Davivienda products and customer operations.
β
The advertised material allegedly includes:
β
β’ AI and machine-learning analytics models
β’ Potential-customer database analysis
β’ Predictive models for Davivienda TMK products
β’ Digital mobile credit models
β’ Digital revolving credit models
β’ Secured digital credit card analytics
β’ Access to hosts and a monitoring server
β’ User accounts, roles, creation dates and account statuses
β’ Real-time access to a system reportedly updated daily
β
The seller identifies one model as modelo_davivienda_crm_rot_tdc and claims additional ownership and model information is included. Access is priced at $999 in Monero.
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
β
A forum actor claims to be selling data and system access obtained from a strategic partner of Davivienda, a Colombian financial services company. The listing references Emergia and analytics used to support Davivienda products and customer operations.
β
The advertised material allegedly includes:
β
β’ AI and machine-learning analytics models
β’ Potential-customer database analysis
β’ Predictive models for Davivienda TMK products
β’ Digital mobile credit models
β’ Digital revolving credit models
β’ Secured digital credit card analytics
β’ Access to hosts and a monitoring server
β’ User accounts, roles, creation dates and account statuses
β’ Real-time access to a system reportedly updated daily
β
The seller identifies one model as modelo_davivienda_crm_rot_tdc and claims additional ownership and model information is included. Access is priced at $999 in Monero.
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨π·πΊ Moscow Department of Health database allegedly offered for sale
β
A forum actor claims to be selling a 2025 database associated with the Moscow Department of Health. The listing advertises approximately 87.85 million rows for $1,000.
β
The exposed data allegedly includes:
β
β’ Names, dates of birth, gender and phone numbers
β’ SNILS identifiers and compulsory medical insurance details
β’ Passport and other identity document information
β’ Residential and registration addresses
β’ Employment and education details
β’ Medical institution and physician information
β’ Patient record numbers and preliminary diagnoses
β’ Illness dates and treatment-related information
β’ Laboratory orders, specimen collection details and test results
β’ COVID-19 and other diagnostic testing records
β
A sample containing personal, insurance, clinical and laboratory information was published alongside the listing.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to be selling a 2025 database associated with the Moscow Department of Health. The listing advertises approximately 87.85 million rows for $1,000.
β
The exposed data allegedly includes:
β
β’ Names, dates of birth, gender and phone numbers
β’ SNILS identifiers and compulsory medical insurance details
β’ Passport and other identity document information
β’ Residential and registration addresses
β’ Employment and education details
β’ Medical institution and physician information
β’ Patient record numbers and preliminary diagnoses
β’ Illness dates and treatment-related information
β’ Laboratory orders, specimen collection details and test results
β’ COVID-19 and other diagnostic testing records
β
A sample containing personal, insurance, clinical and laboratory information was published alongside the listing.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π¨π³ Beijing Housing Fund Management Center citizen data allegedly offered for sale
β
A forum actor claims to be selling a database associated with the Beijing Housing Fund Management Center, a government-linked housing and financial registry serving formally employed residents of Beijing.
β
The listing advertises personal and employment-related information for approximately 17 million residents, including:
β
β’ Names and national identification numbers
β’ Phone numbers and other contact details
β’ Employer information
β’ Housing fund and financial status data
β’ Additional identity-linked registry information
β
A sample was published alongside the listing. The full dataset is priced at $1,700.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to be selling a database associated with the Beijing Housing Fund Management Center, a government-linked housing and financial registry serving formally employed residents of Beijing.
β
The listing advertises personal and employment-related information for approximately 17 million residents, including:
β
β’ Names and national identification numbers
β’ Phone numbers and other contact details
β’ Employer information
β’ Housing fund and financial status data
β’ Additional identity-linked registry information
β
A sample was published alongside the listing. The full dataset is priced at $1,700.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π·πΊ WineStyle customer and buyer database allegedly offered for sale
β
A forum actor claims to be selling a database belonging to WineStyle, a Russian omnichannel retailer specializing in wine, spirits and other imported alcoholic beverages.
β
The listing advertises approximately 1.1 million B2C and B2B buyer records, including:
β
β’ Customer and corporate buyer names
β’ Email addresses and phone numbers
β’ Order identifiers
β’ Complete purchase histories
β’ Transactional and account-related information
β’ Location-linked details associated with verified buyers
β
The actor claims the database contains active retail and corporate customers and is only available as a complete dataset.
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
β
A forum actor claims to be selling a database belonging to WineStyle, a Russian omnichannel retailer specializing in wine, spirits and other imported alcoholic beverages.
β
The listing advertises approximately 1.1 million B2C and B2B buyer records, including:
β
β’ Customer and corporate buyer names
β’ Email addresses and phone numbers
β’ Order identifiers
β’ Complete purchase histories
β’ Transactional and account-related information
β’ Location-linked details associated with verified buyers
β
The actor claims the database contains active retail and corporate customers and is only available as a complete dataset.
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨π§π· Brazilian Ministry of Defense documents allegedly leaked
β
A forum actor claims to have published two confidential military reports associated with Brazilβs Ministry of Defense, covering advanced radar, tactical defense and space-based surveillance capabilities.
β
The documents reportedly include:
β
β’ AI-assisted reconnaissance and threat prediction
β’ Over-the-horizon radar capabilities
β’ Early-warning and surveillance systems
β’ Tactical defense infrastructure improvements
β’ Military intelligence collection using surveillance satellites
β’ Autonomous monitoring and AI-based analysis
β’ Secure military communications
β’ Detection of threats linked to state and non-state actors
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have published two confidential military reports associated with Brazilβs Ministry of Defense, covering advanced radar, tactical defense and space-based surveillance capabilities.
β
The documents reportedly include:
β
β’ AI-assisted reconnaissance and threat prediction
β’ Over-the-horizon radar capabilities
β’ Early-warning and surveillance systems
β’ Tactical defense infrastructure improvements
β’ Military intelligence collection using surveillance satellites
β’ Autonomous monitoring and AI-based analysis
β’ Secure military communications
β’ Detection of threats linked to state and non-state actors
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π²π½ Hospital MΓ©xico Americano patient database and CT scans allegedly leaked
β
A forum actor claims to have published a 9.1GB collection belonging to Hospital MΓ©xico Americano containing patient records and medical imaging files, including CT scans.
β
The exposed data allegedly includes:
β
β’ Patient names and internal identifiers
β’ Gender, dates of birth and ages
β’ Study and accession numbers
β’ Examination descriptions
β’ Study dates and timestamps
β’ Associated CT scan images
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have published a 9.1GB collection belonging to Hospital MΓ©xico Americano containing patient records and medical imaging files, including CT scans.
β
The exposed data allegedly includes:
β
β’ Patient names and internal identifiers
β’ Gender, dates of birth and ages
β’ Study and accession numbers
β’ Examination descriptions
β’ Study dates and timestamps
β’ Associated CT scan images
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ ZoomShift user and activity data allegedly leaked
β
A forum actor claims to have leaked data belonging to ZoomShift, an employee scheduling and time-tracking platform used by restaurants, retailers and hospitality businesses.
β
The post advertises 10,507 active user accounts, 865,963 PII rows and 4,139,178 event-log records, including:
β
β’ Email addresses and user and company identifiers
β’ Subscription plans, billing terms, revenue data and user roles
β’ Team sizes, industries and numbers of business locations
β’ IP addresses, cities, countries and regions
β’ GPS coordinates collected through clock-in geofencing
β’ Device identifiers, models, brands and operating system details
β’ Mobile carriers, languages and platforms
β’ Visited URLs, page names and referral timestamps
β’ UTM tracking parameters and Google Ads identifiers
β’ Time zones, onboarding steps and employee invitation data
β
The files are listed as 174MB compressed and approximately 1.84GB uncompressed.
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
β
A forum actor claims to have leaked data belonging to ZoomShift, an employee scheduling and time-tracking platform used by restaurants, retailers and hospitality businesses.
β
The post advertises 10,507 active user accounts, 865,963 PII rows and 4,139,178 event-log records, including:
β
β’ Email addresses and user and company identifiers
β’ Subscription plans, billing terms, revenue data and user roles
β’ Team sizes, industries and numbers of business locations
β’ IP addresses, cities, countries and regions
β’ GPS coordinates collected through clock-in geofencing
β’ Device identifiers, models, brands and operating system details
β’ Mobile carriers, languages and platforms
β’ Visited URLs, page names and referral timestamps
β’ UTM tracking parameters and Google Ads identifiers
β’ Time zones, onboarding steps and employee invitation data
β
The files are listed as 174MB compressed and approximately 1.84GB uncompressed.
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨ Dante AI user and activity data allegedly leaked
β
A forum actor claims to have leaked data belonging to Dante AI, a platform used by businesses and individuals to build custom AI chatbots for customer support, lead generation and website integration.
β
The post advertises 2,924,201 PII records and an equal number of event logs linked to 73,547 active users, more than 130,000 unique IP addresses and users across 200+ countries, including:
β
β’ Email addresses, IP addresses and device identifiers
β’ Cities, countries, regions and GPS coordinates
β’ Session IDs, UUIDs and authentication methods
β’ Visited URLs, page paths and referral information
β’ Chatbot identifiers and selected LLM models, including Claude, GPT-4, Opus and Sonnet
β’ UTM parameters and Google, Facebook, LinkedIn, TikTok and Microsoft advertising identifiers
β’ Browser, operating system, device, manufacturer and mobile carrier details
β’ Languages, platforms and event timestamps
β’ Subscription plans, Stripe checkout referral data and Zapier integration metadata
β
The files are listed as 363MB compressed and approximately 5.5GB uncompressed.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have leaked data belonging to Dante AI, a platform used by businesses and individuals to build custom AI chatbots for customer support, lead generation and website integration.
β
The post advertises 2,924,201 PII records and an equal number of event logs linked to 73,547 active users, more than 130,000 unique IP addresses and users across 200+ countries, including:
β
β’ Email addresses, IP addresses and device identifiers
β’ Cities, countries, regions and GPS coordinates
β’ Session IDs, UUIDs and authentication methods
β’ Visited URLs, page paths and referral information
β’ Chatbot identifiers and selected LLM models, including Claude, GPT-4, Opus and Sonnet
β’ UTM parameters and Google, Facebook, LinkedIn, TikTok and Microsoft advertising identifiers
β’ Browser, operating system, device, manufacturer and mobile carrier details
β’ Languages, platforms and event timestamps
β’ Subscription plans, Stripe checkout referral data and Zapier integration metadata
β
The files are listed as 363MB compressed and approximately 5.5GB uncompressed.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΈπ¦ Blackbox LTD subscriber and billing data allegedly leaked
β
A forum actor claims to have leaked data belonging to Blackbox LTD, a value-added services provider operating across Beirut, Dubai and Riyadh that handles mobile subscription billing for Mobily and STC.
β
The post advertises 59,903 unique Saudi phone numbers and 88,501 transaction events, including:
β
β’ Mobile phone numbers and transaction timestamps
β’ Device models, iOS versions and mobile carriers
β’ IP addresses and location information
β’ Subscription, fraud and billing response codes
β’ Internal API endpoints
β’ Basic authentication credentials for billing APIs
β’ Affiliate tags, pixel identifiers and advertising IDs
β’ Server and customer IP addresses
β’ Fraud flags, PIN codes, billing types and service identifiers
β
The actor claims the records contain complete transaction histories.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have leaked data belonging to Blackbox LTD, a value-added services provider operating across Beirut, Dubai and Riyadh that handles mobile subscription billing for Mobily and STC.
β
The post advertises 59,903 unique Saudi phone numbers and 88,501 transaction events, including:
β
β’ Mobile phone numbers and transaction timestamps
β’ Device models, iOS versions and mobile carriers
β’ IP addresses and location information
β’ Subscription, fraud and billing response codes
β’ Internal API endpoints
β’ Basic authentication credentials for billing APIs
β’ Affiliate tags, pixel identifiers and advertising IDs
β’ Server and customer IP addresses
β’ Fraud flags, PIN codes, billing types and service identifiers
β
The actor claims the records contain complete transaction histories.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ Skywalk Group WordPress source code and database allegedly leaked
β
A forum actor claims to have breached Skywalk Group, a manufacturer of high-performance equipment for action and wind sports, and published data taken from the companyβs WordPress website.
β
The leaked material allegedly includes:
β
β’ WordPress website source code
β’ The associated website database
β’ A directory tree showing the affected files
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have breached Skywalk Group, a manufacturer of high-performance equipment for action and wind sports, and published data taken from the companyβs WordPress website.
β
The leaked material allegedly includes:
β
β’ WordPress website source code
β’ The associated website database
β’ A directory tree showing the affected files
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ An actor is seeking to recruit insider employees with high-privilege access to customer data at companies earning over β¬10 million in yearly revenue, offering 50% profit share for assistance in gaining unauthorized access.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π¨π± ESCIPOL student records and photographs allegedly leaked
β
A forum actor claims to have leaked data belonging to Chileβs Escuela de Investigaciones Policiales, the training academy associated with the PolicΓa de Investigaciones de Chile.
β
The 252MB collection allegedly includes student, applicant, instructor and academic records, including:
β
β’ RUT national identification numbers
β’ Student and applicant names
β’ Dates and places of birth
β’ Gender and marital status
β’ Phone numbers and email addresses
β’ Course and graduation-year information
β’ Student photographs
β’ Instructor names and identification numbers
β’ Subjects, grades and curriculum details
β’ Evaluation answers and completion statuses
β’ Current enrollment and probation statuses
β
The post references 160 detailed student records, 170 academic-grade records and 960 additional student records. Samples containing personal information and student photographs.
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
β
A forum actor claims to have leaked data belonging to Chileβs Escuela de Investigaciones Policiales, the training academy associated with the PolicΓa de Investigaciones de Chile.
β
The 252MB collection allegedly includes student, applicant, instructor and academic records, including:
β
β’ RUT national identification numbers
β’ Student and applicant names
β’ Dates and places of birth
β’ Gender and marital status
β’ Phone numbers and email addresses
β’ Course and graduation-year information
β’ Student photographs
β’ Instructor names and identification numbers
β’ Subjects, grades and curriculum details
β’ Evaluation answers and completion statuses
β’ Current enrollment and probation statuses
β
The post references 160 detailed student records, 170 academic-grade records and 960 additional student records. Samples containing personal information and student photographs.
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
β€1
IP Information for 75.126.104.235
ASN: 36351
ISP / Org: SOFTLAYER - IBM Cloud, US
Country: US
Network Range: 75.126.0.0/16
ASN: 36351
ISP / Org: SOFTLAYER - IBM Cloud, US
Country: US
Network Range: 75.126.0.0/16
WHOIS for coldcard.com
Domain: COLDCARD.COM
Registered On: 2003-07-27 18:50:15 UTC
Expires On: 2031-07-27 18:50:15 UTC
Updated On: 2021-10-04 17:35:37 UTC
Status:
clientTransferProhibited
Name Servers:
CODY.NS.CLOUDFLARE.COM
LILY.NS.CLOUDFLARE.COM
Registrar: Name.com, Inc.
IANA ID: 625
URL: Not Available
Abuse Email: abuse@name.com
Abuse Phone: 7202492374
Domain: COLDCARD.COM
Registered On: 2003-07-27 18:50:15 UTC
Expires On: 2031-07-27 18:50:15 UTC
Updated On: 2021-10-04 17:35:37 UTC
Status:
clientTransferProhibited
Name Servers:
CODY.NS.CLOUDFLARE.COM
LILY.NS.CLOUDFLARE.COM
Registrar: Name.com, Inc.
IANA ID: 625
URL: Not Available
Abuse Email: abuse@name.com
Abuse Phone: 7202492374