‼️ New Ransomware Group: Panzer
http://pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion
Panzer ransomware operation launches affiliate recruitment program
⠀
The Panzer ransomware operation is recruiting penetration testers and other affiliates, offering access to a management platform, multi-platform lockers and an 80/20 revenue-sharing model.
⠀
Advertised affiliate features include:
⠀
• Individual dashboards with unique access links
• Earnings, balances, active builds, tickets and team activity tracking
• Cryptocurrency deposits, withdrawals and transaction histories
• Lockers supporting Windows, Linux, ESXi and FreeBSD
• More than 15 customizable commands and claimed anti-detection features
• Real-time monitoring and configurable panels deployed with each build
• Automatically generated onion-based victim negotiation chats
• File attachments, searchable histories and real-time messaging
• Bitcoin invoice generation directly inside victim chats
• Automatic crediting of confirmed payments to affiliate balances
• Team accounts with configurable permissions
• Support tickets, platform announcements and operational rules
⠀
The operation also provides a leak-site publishing system where affiliates can submit victim names, stolen-data samples, download links and descriptions for approval. Higher-profile attacks may reportedly receive additional promotion to increase pressure on victims.
⠀
Panzer advertises an 80% share for affiliates and 20% for the operators, automatically deducted from each payment.
⠀
Recruitment rules reportedly prohibit:
⠀
• Targeting organizations in CIS countries
• Targeting companies involved in abuse of children or minors
• Violating the operation’s internal rules
• Remaining inactive for more than one week after joining
⠀
Applications are handled through the operation’s Tox support channel.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
http://pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion
Panzer ransomware operation launches affiliate recruitment program
⠀
The Panzer ransomware operation is recruiting penetration testers and other affiliates, offering access to a management platform, multi-platform lockers and an 80/20 revenue-sharing model.
⠀
Advertised affiliate features include:
⠀
• Individual dashboards with unique access links
• Earnings, balances, active builds, tickets and team activity tracking
• Cryptocurrency deposits, withdrawals and transaction histories
• Lockers supporting Windows, Linux, ESXi and FreeBSD
• More than 15 customizable commands and claimed anti-detection features
• Real-time monitoring and configurable panels deployed with each build
• Automatically generated onion-based victim negotiation chats
• File attachments, searchable histories and real-time messaging
• Bitcoin invoice generation directly inside victim chats
• Automatic crediting of confirmed payments to affiliate balances
• Team accounts with configurable permissions
• Support tickets, platform announcements and operational rules
⠀
The operation also provides a leak-site publishing system where affiliates can submit victim names, stolen-data samples, download links and descriptions for approval. Higher-profile attacks may reportedly receive additional promotion to increase pressure on victims.
⠀
Panzer advertises an 80% share for affiliates and 20% for the operators, automatically deducted from each payment.
⠀
Recruitment rules reportedly prohibit:
⠀
• Targeting organizations in CIS countries
• Targeting companies involved in abuse of children or minors
• Violating the operation’s internal rules
• Remaining inactive for more than one week after joining
⠀
Applications are handled through the operation’s Tox support channel.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤2
‼️ New Dark Web Informer Blog Post!
Title: Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR
Link: https://darkwebinformer.com/qara-platform-allegedly-exposed-actor-claims-live-write-access-to-app-deployment-for-saint-gobain-lidl-and-spar/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR
Link: https://darkwebinformer.com/qara-platform-allegedly-exposed-actor-claims-live-write-access-to-app-deployment-for-saint-gobain-lidl-and-spar/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR
An actor posting as exfilar claims that Qara, an Egyptian supply-chain SaaS platform handling QR anti-counterfeit, feature flags, and mobile app deployment for 14+ enterprise tenants, left its backend databases publicly readable and writable with no authentication.
‼️ New Dark Web Informer Blog Post!
Title: Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed
Link: https://darkwebinformer.com/twelve-databases-leaked-in-single-dump-14-453-customer-records-from-wordpress-sites-exposed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed
Link: https://darkwebinformer.com/twelve-databases-leaked-in-single-dump-14-453-customer-records-from-wordpress-sites-exposed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed
A forum user posting as NightBroker has published 12 databases in a single release, claiming the sites were located through search engine reconnaissance and required minimal effort to access.
🚨🇩🇿🇬🇧🇪🇨 VPN credentials for three organizations allegedly offered for sale
⠀
A forum actor is advertising access to three organizations across Algeria, the United Kingdom and Ecuador. The seller claims the credentials have been verified and requires transactions to use escrow.
⠀
The listings include:
⠀
• 🇩🇿 Algeria Ministry of Commerce VPN access: $500
• 🇬🇧 UK cloud-based provider web VPN access: $200
• 🇪🇨 Ecuador national university access: $200
⠀
The UK provider is described as generating more than $8 million in revenue. No revenue figures or further access details were provided for the Algerian ministry or Ecuadorian university.
⠀
These claims are currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor is advertising access to three organizations across Algeria, the United Kingdom and Ecuador. The seller claims the credentials have been verified and requires transactions to use escrow.
⠀
The listings include:
⠀
• 🇩🇿 Algeria Ministry of Commerce VPN access: $500
• 🇬🇧 UK cloud-based provider web VPN access: $200
• 🇪🇨 Ecuador national university access: $200
⠀
The UK provider is described as generating more than $8 million in revenue. No revenue figures or further access details were provided for the Algerian ministry or Ecuadorian university.
⠀
These claims are currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: BudBoard Storage Bucket Allegedly Left Public, Exposing 18 Dispensaries and a Production POS Integration Key
Link: https://darkwebinformer.com/budboard-storage-bucket-allegedly-left-public-exposing-18-dispensaries-and-a-production-pos-integration-key/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: BudBoard Storage Bucket Allegedly Left Public, Exposing 18 Dispensaries and a Production POS Integration Key
Link: https://darkwebinformer.com/budboard-storage-bucket-allegedly-left-public-exposing-18-dispensaries-and-a-production-pos-integration-key/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
BudBoard Storage Bucket Allegedly Left Public, Exposing 18 Dispensaries and a Production POS Integration Key
An actor posting as exfilar claims that BudBoard, a US cannabis digital signage platform providing dispensary screen management and point-of-sale integration, left its cloud storage bucket publicly readable with no authentication.
ZeroOsintX: A powerful OSINT toolkit designed for security researchers and penetration testers.
GitHub: https://github.com/roothackerslab/ZeroOsintX
It gathers intelligence on domains, IP addresses, email addresses, phone numbers, and social media accounts, then presents the findings in polished, interactive reports.
GitHub: https://github.com/roothackerslab/ZeroOsintX
It gathers intelligence on domains, IP addresses, email addresses, phone numbers, and social media accounts, then presents the findings in polished, interactive reports.
❤1
⚠️ Boltz has disabled swap services until further notice after a sharp rise in automated, AI-assisted attacks targeting its infrastructure. They state no user funds were at risk, refunds remain available, and support is still online.
Source: https://boltz.exchange/
Source: https://boltz.exchange/
❤1
‼️ New Dark Web Informer Blog Post!
Title: Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations
Link: https://darkwebinformer.com/canadian-hacker-pleads-guilty-in-cloud-breach-spree-affecting-more-than-165-organizations/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations
Link: https://darkwebinformer.com/canadian-hacker-pleads-guilty-in-cloud-breach-spree-affecting-more-than-165-organizations/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations
A Canadian man has pleaded guilty to participating in a widespread cloud hacking and extortion campaign that compromised more than 165 organizations and exposed information belonging to at least 100 million people.
‼️🇺🇸 A forum user is seeking to buy or take a percentage cut of network accesses to US healthcare/pharma organizations, requesting details such as AV, access type, revenue, and host/credential counts (DU/DA).
The buyer specifies target company revenue ranging from 50 million to 100 billion USD and offers escrow.
The buyer specifies target company revenue ranging from 50 million to 100 billion USD and offers escrow.
🚨🇫🇷 Maxi Zoo customer records allegedly offered for sale
⠀
A forum actor claims to be selling a database belonging to Maxi Zoo, a major pet supplies retailer operating in France.
⠀
The listing advertises 3,416,030 customer records dated August 1, 2026, including:
⠀
• First and last names
• Primary and secondary phone numbers
• Email addresses
• Street addresses
• Postal codes and cities
⠀
A sample was published alongside the listing. The full dataset is priced at $700.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling a database belonging to Maxi Zoo, a major pet supplies retailer operating in France.
⠀
The listing advertises 3,416,030 customer records dated August 1, 2026, including:
⠀
• First and last names
• Primary and secondary phone numbers
• Email addresses
• Street addresses
• Postal codes and cities
⠀
A sample was published alongside the listing. The full dataset is priced at $700.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 HVMN customer and payment-related data allegedly leaked
⠀
A forum actor claims to have leaked data belonging to HVMN, formerly known as Nootrobox and now operating as Ketone-IQ, a US performance nutrition company.
⠀
The post advertises 86,904 user profiles, including:
⠀
• 57,209 unique email addresses
• 44,474 unique full names
• 48,201 unique IP addresses
• 6,785 card-on-file records
• 39,230 Stripe customer identifiers
• 8,993 cities across 41 countries
• 14,424 shipping postal codes
• 1,273 subscription identifiers
⠀
The exposed fields allegedly include:
⠀
• Names, email addresses and phone numbers
• IP addresses and internal user identifiers
• Shipping and billing addresses
• Stripe customer and subscription data
• Revenue and Google Analytics identifiers
• Masked payment card numbers and security codes
• Card expiration dates and billing postal codes
• Account creation timestamps
The actor also claims additional user and event data may be released later.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor claims to have leaked data belonging to HVMN, formerly known as Nootrobox and now operating as Ketone-IQ, a US performance nutrition company.
⠀
The post advertises 86,904 user profiles, including:
⠀
• 57,209 unique email addresses
• 44,474 unique full names
• 48,201 unique IP addresses
• 6,785 card-on-file records
• 39,230 Stripe customer identifiers
• 8,993 cities across 41 countries
• 14,424 shipping postal codes
• 1,273 subscription identifiers
⠀
The exposed fields allegedly include:
⠀
• Names, email addresses and phone numbers
• IP addresses and internal user identifiers
• Shipping and billing addresses
• Stripe customer and subscription data
• Revenue and Google Analytics identifiers
• Masked payment card numbers and security codes
• Card expiration dates and billing postal codes
• Account creation timestamps
The actor also claims additional user and event data may be released later.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇮🇳 Extramarks source code and website backup allegedly leaked
⠀
A forum actor claims to have breached Extramarks, an Indian education technology company, and published a complete backup of the company’s online platform.
⠀
The 1.8GB compressed collection allegedly includes:
⠀
• Website source code and core application files
• Databases
• Uploaded media and other stored content
• SEO files and sitemaps
• Configuration files
• System and application logs
⠀
The actor claims the archive is available for download through a Telegram channel. No record count or details about exposed student, parent or employee information were provided.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor claims to have breached Extramarks, an Indian education technology company, and published a complete backup of the company’s online platform.
⠀
The 1.8GB compressed collection allegedly includes:
⠀
• Website source code and core application files
• Databases
• Uploaded media and other stored content
• SEO files and sitemaps
• Configuration files
• System and application logs
⠀
The actor claims the archive is available for download through a Telegram channel. No record count or details about exposed student, parent or employee information were provided.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
❤1
🚨🇺🇸 Allstate-branded staging CRM data allegedly exposed through misconfigured Firebase database
⠀
A forum actor claims to have discovered a publicly accessible Firebase Realtime Database tied to an Allstate-branded tax preparation and client management platform. The actor says the staging environment allowed unauthenticated read and write access.
⠀
The exposed data allegedly includes:
⠀
• 968 Stripe transactions totaling approximately $182,830
• 20 Stripe production customer identifiers
• Seven business accounts with tax and incorporation information
• Eleven user profiles containing names, emails, phone numbers and Social Security numbers
• Session, ID and refresh tokens
• Nine SMS threads containing 26 messages between agents and clients
• Tax return documents and other conversation attachments
• Eleven employee pay periods with hours worked
• Six Firebase Storage download tokens
• Billing records, invoice identifiers and payment statuses
⠀
The actor claims write access was tested across five database endpoints, potentially allowing records, accounts, conversations and payment information to be modified. A database export and supporting files were also advertised for download.
⠀
The post attributes the environment to Allstate, but the displayed records reference Allstate Tax LLC and other tax preparation clients. The relationship to Allstate Corporation has not been independently confirmed.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor claims to have discovered a publicly accessible Firebase Realtime Database tied to an Allstate-branded tax preparation and client management platform. The actor says the staging environment allowed unauthenticated read and write access.
⠀
The exposed data allegedly includes:
⠀
• 968 Stripe transactions totaling approximately $182,830
• 20 Stripe production customer identifiers
• Seven business accounts with tax and incorporation information
• Eleven user profiles containing names, emails, phone numbers and Social Security numbers
• Session, ID and refresh tokens
• Nine SMS threads containing 26 messages between agents and clients
• Tax return documents and other conversation attachments
• Eleven employee pay periods with hours worked
• Six Firebase Storage download tokens
• Billing records, invoice identifiers and payment statuses
⠀
The actor claims write access was tested across five database endpoints, potentially allowing records, accounts, conversations and payment information to be modified. A database export and supporting files were also advertised for download.
⠀
The post attributes the environment to Allstate, but the displayed records reference Allstate Tax LLC and other tax preparation clients. The relationship to Allstate Corporation has not been independently confirmed.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing