๐Ÿ”ช Slice For Life - Part 2 ๐Ÿ”ช
4.3K subscribers
807 photos
37 videos
744 links
Download Telegram
โ€ผ๏ธ๐Ÿ‡บ๐Ÿ‡ธ A forum user is seeking to buy or take a percentage cut of network accesses to US healthcare/pharma organizations, requesting details such as AV, access type, revenue, and host/credential counts (DU/DA).

The buyer specifies target company revenue ranging from 50 million to 100 billion USD and offers escrow.
๐Ÿšจ๐Ÿ‡ซ๐Ÿ‡ท Maxi Zoo customer records allegedly offered for sale
โ €
A forum actor claims to be selling a database belonging to Maxi Zoo, a major pet supplies retailer operating in France.
โ €
The listing advertises 3,416,030 customer records dated August 1, 2026, including:
โ €
โ€ข First and last names
โ€ข Primary and secondary phone numbers
โ€ข Email addresses
โ€ข Street addresses
โ€ข Postal codes and cities
โ €
A sample was published alongside the listing. The full dataset is priced at $700.
โ €
This claim is currently unverified.
โ €
๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡บ๐Ÿ‡ธ HVMN customer and payment-related data allegedly leaked
โ €
A forum actor claims to have leaked data belonging to HVMN, formerly known as Nootrobox and now operating as Ketone-IQ, a US performance nutrition company.
โ €
The post advertises 86,904 user profiles, including:
โ €
โ€ข 57,209 unique email addresses
โ€ข 44,474 unique full names
โ€ข 48,201 unique IP addresses
โ€ข 6,785 card-on-file records
โ€ข 39,230 Stripe customer identifiers
โ€ข 8,993 cities across 41 countries
โ€ข 14,424 shipping postal codes
โ€ข 1,273 subscription identifiers
โ €
The exposed fields allegedly include:
โ €
โ€ข Names, email addresses and phone numbers
โ€ข IP addresses and internal user identifiers
โ€ข Shipping and billing addresses
โ€ข Stripe customer and subscription data
โ€ข Revenue and Google Analytics identifiers
โ€ข Masked payment card numbers and security codes
โ€ข Card expiration dates and billing postal codes
โ€ข Account creation timestamps

The actor also claims additional user and event data may be released later.
โ €
This claim is currently unverified.
โ €
๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ฎ๐Ÿ‡ณ Extramarks source code and website backup allegedly leaked
โ €
A forum actor claims to have breached Extramarks, an Indian education technology company, and published a complete backup of the companyโ€™s online platform.
โ €
The 1.8GB compressed collection allegedly includes:
โ €
โ€ข Website source code and core application files
โ€ข Databases
โ€ข Uploaded media and other stored content
โ€ข SEO files and sitemaps
โ€ข Configuration files
โ€ข System and application logs
โ €
The actor claims the archive is available for download through a Telegram channel. No record count or details about exposed student, parent or employee information were provided.
โ €
This claim is currently unverified.
โ €
๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โค1
๐Ÿšจ๐Ÿ‡บ๐Ÿ‡ธ Allstate-branded staging CRM data allegedly exposed through misconfigured Firebase database
โ €
A forum actor claims to have discovered a publicly accessible Firebase Realtime Database tied to an Allstate-branded tax preparation and client management platform. The actor says the staging environment allowed unauthenticated read and write access.
โ €
The exposed data allegedly includes:
โ €
โ€ข 968 Stripe transactions totaling approximately $182,830
โ€ข 20 Stripe production customer identifiers
โ€ข Seven business accounts with tax and incorporation information
โ€ข Eleven user profiles containing names, emails, phone numbers and Social Security numbers
โ€ข Session, ID and refresh tokens
โ€ข Nine SMS threads containing 26 messages between agents and clients
โ€ข Tax return documents and other conversation attachments
โ€ข Eleven employee pay periods with hours worked
โ€ข Six Firebase Storage download tokens
โ€ข Billing records, invoice identifiers and payment statuses
โ €
The actor claims write access was tested across five database endpoints, potentially allowing records, accounts, conversations and payment information to be modified. A database export and supporting files were also advertised for download.
โ €
The post attributes the environment to Allstate, but the displayed records reference Allstate Tax LLC and other tax preparation clients. The relationship to Allstate Corporation has not been independently confirmed.
โ €
This claim is currently unverified.
โ €
๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
Media is too big
VIEW IN TELEGRAM
How the NSA Hacks the World: The TAO Unit Exposed

Video Credit: youtube.com/Vice
๐Ÿ”ฅ3
Forwarded from Dark Web Informer - Private
โ€ผ๏ธ DOJ Press Release
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions

Full Press Release โ†’ justice.gov

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
๐Ÿ•ต๏ธ Dark Web Informer โ€ข DOJ Monitor

Note: DOJ articles that are not Cyber related will be removed manually.
โค1
๐Ÿšจ๐Ÿ‡ฎ๐Ÿ‡ฉ Starlite Indonesia customer database allegedly offered for sale
โ €
A forum actor claims to be selling customer data belonging to Starlite Indonesia, a residential internet and Wi-Fi service provider operating in Indonesia.
โ €
The listing advertises:
โ €
โ€ข 352,543 customer records
โ€ข Database headers and sample records
โ€ข A sale price of 2 XMR
โ €
This claim is currently unverified.
โ €
๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โš ๏ธ FBI Watchdog - WHOIS Change โš ๏ธ
๐Ÿ”— DarkWebInformer.com - Cyber Threat Intelligence

Domain: xss.ac
Record Type: WHOIS Change
Time Detected: 2026-08-06 15:56:43 UTC

Previous Records:
status: ['clientdeleteprohibited', 'clienttransferprohibited']

New Records:
status: ['clientdeleteprohibited', 'clienttransferprohibited'] โ†’ ['clientdeleteprohibited', 'clienthold', 'clienttransferprohibited']
๐Ÿšจ๐Ÿ‡บ๐Ÿ‡ธ New York identity and Social Security data allegedly offered for sale
โ €
A forum actor claims to be selling identity packages tied to individuals in New York, including government-issued identification and Social Security information.
โ €
The advertised packages allegedly include:
โ €
โ€ข Full names and residential addresses
โ€ข Social Security numbers
โ€ข Photographs of New York driverโ€™s licenses
โ€ข Selfies showing individuals holding their identification
โ€ข Additional identity verification information
โ €
The seller advertises individual records for $25, two packages for $50, and 50 packages for $500. A sample containing highly sensitive personal information was published alongside the listing.
โ €
This claim is currently unverified.
โ €
๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ฎ๐Ÿ‡ณ Tit-Bit Foods data allegedly leaked following ransomware attack
โ €
A forum actor claims to have infected a computer belonging to Tit-Bit Foods, an Indian food company, with ransomware and published company data after a payment was not made.
โ €
The post includes:
โ €
โ€ข Multiple download links containing the allegedly stolen files
โ€ข Images said to show the infected computer
โ€ข A claim that the attack involved โ€œLuzy Ricardo Milosโ€ ransomware
โ €
This claim is currently unverified.
โ €
๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ฆ๐Ÿ‡ท Domain administrator access to Argentine healthcare organization allegedly offered for sale
โ €
A forum actor claims to be selling verified domain administrator access to an unidentified healthcare and social security organization in Argentina. The listing advertises an active session with access to Active Directory and an internal domain controller.
โ €
The actor claims the compromised environment includes:
โ €
โ€ข Approximately 450 domain-joined hosts currently online
โ€ข An organization with roughly 200,000 employees
โ€ข Member and beneficiary records
โ€ข Medical histories and clinical information
โ€ข Financial data and SQL databases
โ€ข Dumped password hashes
โ€ข The domain administrator password in plaintext
โ €
The affected organization is described only as using an .org.ar domain and generating between $80 million and $120 million in annual revenue. No price was publicly disclosed.
โ €
This claim is currently unverified.
โ €
๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ซ๐Ÿ‡ท INSERM healthcare professional database allegedly offered for sale
โ €
A forum actor claims to be selling a 2026 database associated with INSERM, Franceโ€™s National Institute of Health and Medical Research. The listing advertises 192,451 records connected to healthcare professionals, medical research and public health.
โ €
The exposed data allegedly includes:
โ €
โ€ข Names and dates of birth
โ€ข Email addresses and phone numbers
โ€ข RPPS and ADELI professional identifiers
โ€ข Gender and civil-status information
โ€ข Professional and account identifiers
โ€ข Account creation and login timestamps
โ€ข Password modification information
โ€ข Department, region and municipality details
โ€ข Postal addresses and geographic coordinates
โ€ข Employer or healthcare institution information
โ€ข SIRET business identifiers
โ€ข Account roles, profiles and suspension status
โ €
A sample containing personal, professional and account-related information was published alongside the listing.
โ €
This claim is currently unverified.
โ €
๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
New Ransomware Group: Storm โ›ˆ๏ธ๐Ÿ‘‡

http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
โค2
I am in the process of onboarding another 5+ forums, but need to do a little maintenance on the scripts. The forum monitoring status on the threat feed will be updated tomorrow so you know what to look for. Pitch will be completed this weekend. Wamus, if you have any concerns send me a message on Pitch.
๐Ÿšจ๐Ÿ‡ช๐Ÿ‡ธ Juan de Diego customer, banking and invoicing database allegedly offered for sale
โ €
A forum actor claims to be selling approximately 80,000 Spanish customer and business records associated with Juan de Diego. The seller claims the collection contains no duplicate entries and includes banking and tax-related information.
โ €
The exposed data allegedly includes:
โ €
โ€ข Customer and company names
โ€ข CIF and NIF tax identification numbers
โ€ข IBAN and SWIFT banking details
โ€ข Email addresses, phone numbers and fax numbers
โ€ข Full postal addresses and websites
โ€ข Client, supplier and account identifiers
โ€ข Invoice, receipt and direct-debit mandate details
โ€ข Payment amounts, currencies and transaction dates
โ€ข Remittance, accounting and VAT information
โ€ข Purchase orders and financial ledger entries
โ €
Multiple samples containing personal, corporate and financial information were published alongside the listing.
โ €
This claim is currently unverified.
โ €
๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials