🔪 Slice For Life - Part 2 🔪
4.69K subscribers
1.07K photos
59 videos
964 links
Download Telegram
🚨 ZoomShift user and activity data allegedly leaked

A forum actor claims to have leaked data belonging to ZoomShift, an employee scheduling and time-tracking platform used by restaurants, retailers and hospitality businesses.

The post advertises 10,507 active user accounts, 865,963 PII rows and 4,139,178 event-log records, including:

• Email addresses and user and company identifiers
• Subscription plans, billing terms, revenue data and user roles
• Team sizes, industries and numbers of business locations
• IP addresses, cities, countries and regions
• GPS coordinates collected through clock-in geofencing
• Device identifiers, models, brands and operating system details
• Mobile carriers, languages and platforms
• Visited URLs, page names and referral timestamps
• UTM tracking parameters and Google Ads identifiers
• Time zones, onboarding steps and employee invitation data

The files are listed as 174MB compressed and approximately 1.84GB uncompressed.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨 Dante AI user and activity data allegedly leaked

A forum actor claims to have leaked data belonging to Dante AI, a platform used by businesses and individuals to build custom AI chatbots for customer support, lead generation and website integration.

The post advertises 2,924,201 PII records and an equal number of event logs linked to 73,547 active users, more than 130,000 unique IP addresses and users across 200+ countries, including:

• Email addresses, IP addresses and device identifiers
• Cities, countries, regions and GPS coordinates
• Session IDs, UUIDs and authentication methods
• Visited URLs, page paths and referral information
• Chatbot identifiers and selected LLM models, including Claude, GPT-4, Opus and Sonnet
• UTM parameters and Google, Facebook, LinkedIn, TikTok and Microsoft advertising identifiers
• Browser, operating system, device, manufacturer and mobile carrier details
• Languages, platforms and event timestamps
• Subscription plans, Stripe checkout referral data and Zapier integration metadata

The files are listed as 363MB compressed and approximately 5.5GB uncompressed.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇸🇦 Blackbox LTD subscriber and billing data allegedly leaked

A forum actor claims to have leaked data belonging to Blackbox LTD, a value-added services provider operating across Beirut, Dubai and Riyadh that handles mobile subscription billing for Mobily and STC.

The post advertises 59,903 unique Saudi phone numbers and 88,501 transaction events, including:

• Mobile phone numbers and transaction timestamps
• Device models, iOS versions and mobile carriers
• IP addresses and location information
• Subscription, fraud and billing response codes
• Internal API endpoints
• Basic authentication credentials for billing APIs
• Affiliate tags, pixel identifiers and advertising IDs
• Server and customer IP addresses
• Fraud flags, PIN codes, billing types and service identifiers

The actor claims the records contain complete transaction histories.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Skywalk Group WordPress source code and database allegedly leaked

A forum actor claims to have breached Skywalk Group, a manufacturer of high-performance equipment for action and wind sports, and published data taken from the company’s WordPress website.

The leaked material allegedly includes:

• WordPress website source code
• The associated website database
• A directory tree showing the affected files

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ An actor is seeking to recruit insider employees with high-privilege access to customer data at companies earning over €10 million in yearly revenue, offering 50% profit share for assistance in gaining unauthorized access.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇨🇱 ESCIPOL student records and photographs allegedly leaked

A forum actor claims to have leaked data belonging to Chile’s Escuela de Investigaciones Policiales, the training academy associated with the Policía de Investigaciones de Chile.

The 252MB collection allegedly includes student, applicant, instructor and academic records, including:

• RUT national identification numbers
• Student and applicant names
• Dates and places of birth
• Gender and marital status
• Phone numbers and email addresses
• Course and graduation-year information
• Student photographs
• Instructor names and identification numbers
• Subjects, grades and curriculum details
• Evaluation answers and completion statuses
• Current enrollment and probation statuses

The post references 160 detailed student records, 170 academic-grade records and 960 additional student records. Samples containing personal information and student photographs.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
1
IP Information for 75.126.104.235

ASN: 36351
ISP / Org: SOFTLAYER - IBM Cloud, US
Country: US
Network Range: 75.126.0.0/16
WHOIS for coldcard.com

Domain: COLDCARD.COM
Registered On: 2003-07-27 18:50:15 UTC
Expires On: 2031-07-27 18:50:15 UTC
Updated On: 2021-10-04 17:35:37 UTC
Status:
clientTransferProhibited
Name Servers:
CODY.NS.CLOUDFLARE.COM
LILY.NS.CLOUDFLARE.COM
Registrar: Name.com, Inc.
IANA ID: 625
URL: Not Available
Abuse Email: abuse@name.com
Abuse Phone: 7202492374
WHOIS for coldcardpass.com

Domain: COLDCARDPASS.COM
Registered On: 2022-08-10 12:45:10 UTC
Expires On: 2027-08-10 12:45:10 UTC
Updated On: 2026-07-16 16:24:05 UTC
Status:
clientTransferProhibited
Name Servers:
NS1MPZ.NAME.COM
NS2BTZ.NAME.COM
NS3JWX.NAME.COM
NS4FQZ.NAME.COM
Registrar: Name.com, Inc.
IANA ID: 625
URL: Not Available
Abuse Email: abuse@name.com
Abuse Phone: 7202492374
coldcardpass[.]com -> coldcard[.]com

IP: 75[.]126[.]104[.]235
Chat, I have a lot of IRL stuff I need to get done today. Once I'm done I will post anything that seems to be worth it. If you are a paid subscriber the feed runs 24/7/365. If I see anything major, you will know. ✌️
5
This media is not supported in your browser
VIEW IN TELEGRAM
🚨🇩🇪 Archetyp Darknet Market operator charged over €330M darknet drug trade

German prosecutors charged a 31-year-old man accused of founding and administering Archetyp Market, once described as the world’s largest darknet marketplace for illegal drugs.

Authorities say the platform processed around 2.3 million orders between November 2022 and its June 2025 shutdown, generating an estimated €330 million in sales.

Archetyp allegedly had more than 600,000 customer accounts, around 3,000 professional vendors, and 17,000 listings for cocaine, heroin, fentanyl, methamphetamine, cannabis, prescription drugs, and other substances.

The suspect allegedly collected a 5% commission and other fees, earning around €20 million.

He was arrested (video) in Barcelona during Operation Deep Sentinel and later extradited to Germany. Authorities have seized nearly €10 million in cryptocurrency, cash, and luxury vehicles.

He faces up to 15 years in prison if convicted.
1😭1
🚨 Two unauthenticated MyBB SQL injection zero-days allegedly offered for sale

A forum actor claims to be selling two unauthenticated SQL injection zero-day vulnerabilities affecting commonly used MyBB plugins with more than 20,000 downloads.

The actor claims the flaws could expose MyBB forums running one of the affected plugins and cites different forums as examples of platforms using MyBB.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
1
🚨🇮🇷 JANFADA member personal data allegedly leaked

A forum actor claims to have leaked 14,418 member records associated with JANFADA in Iran. The dataset was published as a free download alongside a sample.

The exposed data allegedly includes:

• Names and personal identifiers
• National ID and birth-certificate numbers
• Phone numbers and home addresses
• Education and occupation details
• Skills and areas of expertise
• Geographic areas of activity
• Membership and participation information
• Types of organizational activities

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇪🇸 GTD defense project files allegedly offered for sale

A forum actor claims to be selling 3.58GB of files belonging to GTD, a Spanish defense technology company involved in sensitive aerospace, naval and military projects.

The listing references work connected to Navantia, Airbus, the European Space Agency and other defense programs.

The advertised files allegedly include:

• Technical diagrams, cabling plans and hardware specifications
• Sensor and weapons integration documentation
• Operations and maintenance manuals
• Factory acceptance and impedance test reports
• Contracts, meeting minutes and progress reports
• Confidentiality and ITAR-related clauses
• Spare-parts lists, lead times and reliability data
• Chemical specifications for coatings used in military equipment
• PDF, Excel and CAD files marked confidential

The seller claims the compressed dataset totals 2.71GB and is seeking offers for the full collection.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇲🇽 Irapuato municipal job board applicant data allegedly leaked

A forum actor claims to have leaked approximately 17,000 records from Bolsa de Empleo Irapuato, a municipal employment portal operated by the Government of Irapuato in Mexico.

The exposed data allegedly includes:

• Applicant names and facial photographs
• CURP national identification numbers
• Home addresses, phone numbers and email addresses
• Complete résumés and employment histories
• Skills and desired salaries
• Preferred positions and employment types
• Job categories
• Education histories, grades and previous schools

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing