🔪 Slice For Life - Part 2 🔪
🚨🇩🇪 Archetyp Darknet Market operator charged over €330M darknet drug trade German prosecutors charged a 31-year-old man accused of founding and administering Archetyp Market, once described as the world’s largest darknet marketplace for illegal drugs. Authorities…
euronews
Alleged operator of major darknet drugs platform charged in Germany
The suspect was arrested at his home in Barcelona in June 2025 by a special unit of the Spanish National Police and was later extradited to Germany.
🚨 Two unauthenticated MyBB SQL injection zero-days allegedly offered for sale
⠀
A forum actor claims to be selling two unauthenticated SQL injection zero-day vulnerabilities affecting commonly used MyBB plugins with more than 20,000 downloads.
⠀
The actor claims the flaws could expose MyBB forums running one of the affected plugins and cites different forums as examples of platforms using MyBB.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling two unauthenticated SQL injection zero-day vulnerabilities affecting commonly used MyBB plugins with more than 20,000 downloads.
⠀
The actor claims the flaws could expose MyBB forums running one of the affected plugins and cites different forums as examples of platforms using MyBB.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
🚨🇮🇷 JANFADA member personal data allegedly leaked
⠀
A forum actor claims to have leaked 14,418 member records associated with JANFADA in Iran. The dataset was published as a free download alongside a sample.
⠀
The exposed data allegedly includes:
⠀
• Names and personal identifiers
• National ID and birth-certificate numbers
• Phone numbers and home addresses
• Education and occupation details
• Skills and areas of expertise
• Geographic areas of activity
• Membership and participation information
• Types of organizational activities
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor claims to have leaked 14,418 member records associated with JANFADA in Iran. The dataset was published as a free download alongside a sample.
⠀
The exposed data allegedly includes:
⠀
• Names and personal identifiers
• National ID and birth-certificate numbers
• Phone numbers and home addresses
• Education and occupation details
• Skills and areas of expertise
• Geographic areas of activity
• Membership and participation information
• Types of organizational activities
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇪🇸 GTD defense project files allegedly offered for sale
⠀
A forum actor claims to be selling 3.58GB of files belonging to GTD, a Spanish defense technology company involved in sensitive aerospace, naval and military projects.
⠀
The listing references work connected to Navantia, Airbus, the European Space Agency and other defense programs.
⠀
The advertised files allegedly include:
⠀
• Technical diagrams, cabling plans and hardware specifications
• Sensor and weapons integration documentation
• Operations and maintenance manuals
• Factory acceptance and impedance test reports
• Contracts, meeting minutes and progress reports
• Confidentiality and ITAR-related clauses
• Spare-parts lists, lead times and reliability data
• Chemical specifications for coatings used in military equipment
• PDF, Excel and CAD files marked confidential
⠀
The seller claims the compressed dataset totals 2.71GB and is seeking offers for the full collection.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling 3.58GB of files belonging to GTD, a Spanish defense technology company involved in sensitive aerospace, naval and military projects.
⠀
The listing references work connected to Navantia, Airbus, the European Space Agency and other defense programs.
⠀
The advertised files allegedly include:
⠀
• Technical diagrams, cabling plans and hardware specifications
• Sensor and weapons integration documentation
• Operations and maintenance manuals
• Factory acceptance and impedance test reports
• Contracts, meeting minutes and progress reports
• Confidentiality and ITAR-related clauses
• Spare-parts lists, lead times and reliability data
• Chemical specifications for coatings used in military equipment
• PDF, Excel and CAD files marked confidential
⠀
The seller claims the compressed dataset totals 2.71GB and is seeking offers for the full collection.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇲🇽 Irapuato municipal job board applicant data allegedly leaked
⠀
A forum actor claims to have leaked approximately 17,000 records from Bolsa de Empleo Irapuato, a municipal employment portal operated by the Government of Irapuato in Mexico.
⠀
The exposed data allegedly includes:
⠀
• Applicant names and facial photographs
• CURP national identification numbers
• Home addresses, phone numbers and email addresses
• Complete résumés and employment histories
• Skills and desired salaries
• Preferred positions and employment types
• Job categories
• Education histories, grades and previous schools
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor claims to have leaked approximately 17,000 records from Bolsa de Empleo Irapuato, a municipal employment portal operated by the Government of Irapuato in Mexico.
⠀
The exposed data allegedly includes:
⠀
• Applicant names and facial photographs
• CURP national identification numbers
• Home addresses, phone numbers and email addresses
• Complete résumés and employment histories
• Skills and desired salaries
• Preferred positions and employment types
• Job categories
• Education histories, grades and previous schools
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: Waggle Database Allegedly Leaked, 106,800+ Pet Camera Customers Exposed Across Three Tables
Link: https://darkwebinformer.com/waggle-database-allegedly-leaked-106-800-pet-camera-customers-exposed-across-three-tables/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Waggle Database Allegedly Leaked, 106,800+ Pet Camera Customers Exposed Across Three Tables
Link: https://darkwebinformer.com/waggle-database-allegedly-leaked-106-800-pet-camera-customers-exposed-across-three-tables/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Waggle Database Allegedly Leaked, 106,800+ Pet Camera Customers Exposed Across Three Tables
A forum user posting as 2019 has published what they describe as the customer database of Waggle, a US pet technology company whose products include a smart camera offering live video, two-way audio, treat dispensing, and real-time alerts.
‼️ New Dark Web Informer Blog Post!
Title: Vendor Advertises Fraudulently Verified Crypto Exchange Accounts With European Bank Rails
Link: https://darkwebinformer.com/vendor-advertises-fraudulently-verified-crypto-exchange-accounts-with-european-bank-rails/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Vendor Advertises Fraudulently Verified Crypto Exchange Accounts With European Bank Rails
Link: https://darkwebinformer.com/vendor-advertises-fraudulently-verified-crypto-exchange-accounts-with-european-bank-rails/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Vendor Advertises Fraudulently Verified Crypto Exchange Accounts With European Bank Rails
A seller posting as RasselKyc is advertising made-to-order cryptocurrency exchange accounts registered under names supplied by the buyer.
‼️ New Dark Web Informer Blog Post!
Title: Ramp4u Cybercrime Forum Allegedly Breached, 340,000 IP Logs and Private Messages Published
Link: https://darkwebinformer.com/ramp4u-cybercrime-forum-allegedly-breached-340-000-ip-logs-and-private-messages-published/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Ramp4u Cybercrime Forum Allegedly Breached, 340,000 IP Logs and Private Messages Published
Link: https://darkwebinformer.com/ramp4u-cybercrime-forum-allegedly-breached-340-000-ip-logs-and-private-messages-published/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Ramp4u Cybercrime Forum Allegedly Breached, 340,000 IP Logs and Private Messages Published
A forum user posting as kitta has published what they describe as the database of Ramp4u, a Russian-language cybercrime and dark web forum.
‼️ New Dark Web Informer Blog Post!
Title: Branch Furniture Customer Database Allegedly for Sale, 480,276 Records Listed at $200
Link: https://darkwebinformer.com/branch-furniture-customer-database-allegedly-for-sale-480-276-records-listed-at-200/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Branch Furniture Customer Database Allegedly for Sale, 480,276 Records Listed at $200
Link: https://darkwebinformer.com/branch-furniture-customer-database-allegedly-for-sale-480-276-records-listed-at-200/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Branch Furniture Customer Database Allegedly for Sale, 480,276 Records Listed at $200
A seller posting as dreamss is advertising what they describe as the customer database of Branch Furniture, a US direct-to-consumer office furniture company selling to home offices, startups, and businesses.
🚨13,323 Coldcard-linked wallets allegedly swept in mass drain operation
⠀
A forum actor claims to have conducted an August 2026 cryptocurrency draining operation targeting wallets described as associated with Coldcard Q1 MK4 devices.
⠀
The published operation log allegedly contains:
⠀
• 8,716 recovered seed phrases
• 13,323 Bitcoin addresses
• Approximately 1.5 BTC reportedly drained
• 1,092.91 BTC in historical incoming transactions
• 64,720 recorded transactions
• 11,432 addresses previously holding funds
• Mnemonic phrases and private keys for wallets now showing zero balances
⠀
The actor published the alleged output as a full dataset and included several samples, along with a ranking of addresses by historical Bitcoin received.
⠀
The seller says the tool still requires improvements to UTXO selection and fee estimation and claims additional runs are planned. The post does not explain how the seed material was obtained or establish that Coldcard hardware or firmware was compromised.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to have conducted an August 2026 cryptocurrency draining operation targeting wallets described as associated with Coldcard Q1 MK4 devices.
⠀
The published operation log allegedly contains:
⠀
• 8,716 recovered seed phrases
• 13,323 Bitcoin addresses
• Approximately 1.5 BTC reportedly drained
• 1,092.91 BTC in historical incoming transactions
• 64,720 recorded transactions
• 11,432 addresses previously holding funds
• Mnemonic phrases and private keys for wallets now showing zero balances
⠀
The actor published the alleged output as a full dataset and included several samples, along with a ranking of addresses by historical Bitcoin received.
⠀
The seller says the tool still requires improvements to UTXO selection and fee estimation and claims additional runs are planned. The post does not explain how the seed material was obtained or establish that Coldcard hardware or firmware was compromised.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Server crashed, restarting. Give me a little bit. No alerts are missed and once it is backup it will catch everything.
🔪 Slice For Life - Part 2 🔪
Server crashed, restarting. Give me a little bit. No alerts are missed and once it is backup it will catch everything.
Issue is resolved. Give it a couple cycles (couple of hours) for the claims to catch up.
‼️ New Ransomware Group: Panzer
http://pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion
Panzer ransomware operation launches affiliate recruitment program
⠀
The Panzer ransomware operation is recruiting penetration testers and other affiliates, offering access to a management platform, multi-platform lockers and an 80/20 revenue-sharing model.
⠀
Advertised affiliate features include:
⠀
• Individual dashboards with unique access links
• Earnings, balances, active builds, tickets and team activity tracking
• Cryptocurrency deposits, withdrawals and transaction histories
• Lockers supporting Windows, Linux, ESXi and FreeBSD
• More than 15 customizable commands and claimed anti-detection features
• Real-time monitoring and configurable panels deployed with each build
• Automatically generated onion-based victim negotiation chats
• File attachments, searchable histories and real-time messaging
• Bitcoin invoice generation directly inside victim chats
• Automatic crediting of confirmed payments to affiliate balances
• Team accounts with configurable permissions
• Support tickets, platform announcements and operational rules
⠀
The operation also provides a leak-site publishing system where affiliates can submit victim names, stolen-data samples, download links and descriptions for approval. Higher-profile attacks may reportedly receive additional promotion to increase pressure on victims.
⠀
Panzer advertises an 80% share for affiliates and 20% for the operators, automatically deducted from each payment.
⠀
Recruitment rules reportedly prohibit:
⠀
• Targeting organizations in CIS countries
• Targeting companies involved in abuse of children or minors
• Violating the operation’s internal rules
• Remaining inactive for more than one week after joining
⠀
Applications are handled through the operation’s Tox support channel.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
http://pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion
Panzer ransomware operation launches affiliate recruitment program
⠀
The Panzer ransomware operation is recruiting penetration testers and other affiliates, offering access to a management platform, multi-platform lockers and an 80/20 revenue-sharing model.
⠀
Advertised affiliate features include:
⠀
• Individual dashboards with unique access links
• Earnings, balances, active builds, tickets and team activity tracking
• Cryptocurrency deposits, withdrawals and transaction histories
• Lockers supporting Windows, Linux, ESXi and FreeBSD
• More than 15 customizable commands and claimed anti-detection features
• Real-time monitoring and configurable panels deployed with each build
• Automatically generated onion-based victim negotiation chats
• File attachments, searchable histories and real-time messaging
• Bitcoin invoice generation directly inside victim chats
• Automatic crediting of confirmed payments to affiliate balances
• Team accounts with configurable permissions
• Support tickets, platform announcements and operational rules
⠀
The operation also provides a leak-site publishing system where affiliates can submit victim names, stolen-data samples, download links and descriptions for approval. Higher-profile attacks may reportedly receive additional promotion to increase pressure on victims.
⠀
Panzer advertises an 80% share for affiliates and 20% for the operators, automatically deducted from each payment.
⠀
Recruitment rules reportedly prohibit:
⠀
• Targeting organizations in CIS countries
• Targeting companies involved in abuse of children or minors
• Violating the operation’s internal rules
• Remaining inactive for more than one week after joining
⠀
Applications are handled through the operation’s Tox support channel.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤2
‼️ New Dark Web Informer Blog Post!
Title: Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR
Link: https://darkwebinformer.com/qara-platform-allegedly-exposed-actor-claims-live-write-access-to-app-deployment-for-saint-gobain-lidl-and-spar/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR
Link: https://darkwebinformer.com/qara-platform-allegedly-exposed-actor-claims-live-write-access-to-app-deployment-for-saint-gobain-lidl-and-spar/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR
An actor posting as exfilar claims that Qara, an Egyptian supply-chain SaaS platform handling QR anti-counterfeit, feature flags, and mobile app deployment for 14+ enterprise tenants, left its backend databases publicly readable and writable with no authentication.
‼️ New Dark Web Informer Blog Post!
Title: Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed
Link: https://darkwebinformer.com/twelve-databases-leaked-in-single-dump-14-453-customer-records-from-wordpress-sites-exposed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed
Link: https://darkwebinformer.com/twelve-databases-leaked-in-single-dump-14-453-customer-records-from-wordpress-sites-exposed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed
A forum user posting as NightBroker has published 12 databases in a single release, claiming the sites were located through search engine reconnaissance and required minimal effort to access.
🚨🇩🇿🇬🇧🇪🇨 VPN credentials for three organizations allegedly offered for sale
⠀
A forum actor is advertising access to three organizations across Algeria, the United Kingdom and Ecuador. The seller claims the credentials have been verified and requires transactions to use escrow.
⠀
The listings include:
⠀
• 🇩🇿 Algeria Ministry of Commerce VPN access: $500
• 🇬🇧 UK cloud-based provider web VPN access: $200
• 🇪🇨 Ecuador national university access: $200
⠀
The UK provider is described as generating more than $8 million in revenue. No revenue figures or further access details were provided for the Algerian ministry or Ecuadorian university.
⠀
These claims are currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor is advertising access to three organizations across Algeria, the United Kingdom and Ecuador. The seller claims the credentials have been verified and requires transactions to use escrow.
⠀
The listings include:
⠀
• 🇩🇿 Algeria Ministry of Commerce VPN access: $500
• 🇬🇧 UK cloud-based provider web VPN access: $200
• 🇪🇨 Ecuador national university access: $200
⠀
The UK provider is described as generating more than $8 million in revenue. No revenue figures or further access details were provided for the Algerian ministry or Ecuadorian university.
⠀
These claims are currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing