โผ๏ธ๐บ๐ธ A forum user is seeking to buy or take a percentage cut of network accesses to US healthcare/pharma organizations, requesting details such as AV, access type, revenue, and host/credential counts (DU/DA).
The buyer specifies target company revenue ranging from 50 million to 100 billion USD and offers escrow.
The buyer specifies target company revenue ranging from 50 million to 100 billion USD and offers escrow.
๐จ๐ซ๐ท Maxi Zoo customer records allegedly offered for sale
โ
A forum actor claims to be selling a database belonging to Maxi Zoo, a major pet supplies retailer operating in France.
โ
The listing advertises 3,416,030 customer records dated August 1, 2026, including:
โ
โข First and last names
โข Primary and secondary phone numbers
โข Email addresses
โข Street addresses
โข Postal codes and cities
โ
A sample was published alongside the listing. The full dataset is priced at $700.
โ
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum actor claims to be selling a database belonging to Maxi Zoo, a major pet supplies retailer operating in France.
โ
The listing advertises 3,416,030 customer records dated August 1, 2026, including:
โ
โข First and last names
โข Primary and secondary phone numbers
โข Email addresses
โข Street addresses
โข Postal codes and cities
โ
A sample was published alongside the listing. The full dataset is priced at $700.
โ
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐บ๐ธ HVMN customer and payment-related data allegedly leaked
โ
A forum actor claims to have leaked data belonging to HVMN, formerly known as Nootrobox and now operating as Ketone-IQ, a US performance nutrition company.
โ
The post advertises 86,904 user profiles, including:
โ
โข 57,209 unique email addresses
โข 44,474 unique full names
โข 48,201 unique IP addresses
โข 6,785 card-on-file records
โข 39,230 Stripe customer identifiers
โข 8,993 cities across 41 countries
โข 14,424 shipping postal codes
โข 1,273 subscription identifiers
โ
The exposed fields allegedly include:
โ
โข Names, email addresses and phone numbers
โข IP addresses and internal user identifiers
โข Shipping and billing addresses
โข Stripe customer and subscription data
โข Revenue and Google Analytics identifiers
โข Masked payment card numbers and security codes
โข Card expiration dates and billing postal codes
โข Account creation timestamps
The actor also claims additional user and event data may be released later.
โ
This claim is currently unverified.
โ
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โ
A forum actor claims to have leaked data belonging to HVMN, formerly known as Nootrobox and now operating as Ketone-IQ, a US performance nutrition company.
โ
The post advertises 86,904 user profiles, including:
โ
โข 57,209 unique email addresses
โข 44,474 unique full names
โข 48,201 unique IP addresses
โข 6,785 card-on-file records
โข 39,230 Stripe customer identifiers
โข 8,993 cities across 41 countries
โข 14,424 shipping postal codes
โข 1,273 subscription identifiers
โ
The exposed fields allegedly include:
โ
โข Names, email addresses and phone numbers
โข IP addresses and internal user identifiers
โข Shipping and billing addresses
โข Stripe customer and subscription data
โข Revenue and Google Analytics identifiers
โข Masked payment card numbers and security codes
โข Card expiration dates and billing postal codes
โข Account creation timestamps
The actor also claims additional user and event data may be released later.
โ
This claim is currently unverified.
โ
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐จ๐ฎ๐ณ Extramarks source code and website backup allegedly leaked
โ
A forum actor claims to have breached Extramarks, an Indian education technology company, and published a complete backup of the companyโs online platform.
โ
The 1.8GB compressed collection allegedly includes:
โ
โข Website source code and core application files
โข Databases
โข Uploaded media and other stored content
โข SEO files and sitemaps
โข Configuration files
โข System and application logs
โ
The actor claims the archive is available for download through a Telegram channel. No record count or details about exposed student, parent or employee information were provided.
โ
This claim is currently unverified.
โ
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โ
A forum actor claims to have breached Extramarks, an Indian education technology company, and published a complete backup of the companyโs online platform.
โ
The 1.8GB compressed collection allegedly includes:
โ
โข Website source code and core application files
โข Databases
โข Uploaded media and other stored content
โข SEO files and sitemaps
โข Configuration files
โข System and application logs
โ
The actor claims the archive is available for download through a Telegram channel. No record count or details about exposed student, parent or employee information were provided.
โ
This claim is currently unverified.
โ
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โค1
๐จ๐บ๐ธ Allstate-branded staging CRM data allegedly exposed through misconfigured Firebase database
โ
A forum actor claims to have discovered a publicly accessible Firebase Realtime Database tied to an Allstate-branded tax preparation and client management platform. The actor says the staging environment allowed unauthenticated read and write access.
โ
The exposed data allegedly includes:
โ
โข 968 Stripe transactions totaling approximately $182,830
โข 20 Stripe production customer identifiers
โข Seven business accounts with tax and incorporation information
โข Eleven user profiles containing names, emails, phone numbers and Social Security numbers
โข Session, ID and refresh tokens
โข Nine SMS threads containing 26 messages between agents and clients
โข Tax return documents and other conversation attachments
โข Eleven employee pay periods with hours worked
โข Six Firebase Storage download tokens
โข Billing records, invoice identifiers and payment statuses
โ
The actor claims write access was tested across five database endpoints, potentially allowing records, accounts, conversations and payment information to be modified. A database export and supporting files were also advertised for download.
โ
The post attributes the environment to Allstate, but the displayed records reference Allstate Tax LLC and other tax preparation clients. The relationship to Allstate Corporation has not been independently confirmed.
โ
This claim is currently unverified.
โ
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โ
A forum actor claims to have discovered a publicly accessible Firebase Realtime Database tied to an Allstate-branded tax preparation and client management platform. The actor says the staging environment allowed unauthenticated read and write access.
โ
The exposed data allegedly includes:
โ
โข 968 Stripe transactions totaling approximately $182,830
โข 20 Stripe production customer identifiers
โข Seven business accounts with tax and incorporation information
โข Eleven user profiles containing names, emails, phone numbers and Social Security numbers
โข Session, ID and refresh tokens
โข Nine SMS threads containing 26 messages between agents and clients
โข Tax return documents and other conversation attachments
โข Eleven employee pay periods with hours worked
โข Six Firebase Storage download tokens
โข Billing records, invoice identifiers and payment statuses
โ
The actor claims write access was tested across five database endpoints, potentially allowing records, accounts, conversations and payment information to be modified. A database export and supporting files were also advertised for download.
โ
The post attributes the environment to Allstate, but the displayed records reference Allstate Tax LLC and other tax preparation clients. The relationship to Allstate Corporation has not been independently confirmed.
โ
This claim is currently unverified.
โ
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
Forwarded from Dark Web Informer - Private
โผ๏ธ DOJ Press Release
โโโโโโโโโโโโโโโโโโโโโ
Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
โโโโโโโโโโโโโโโโโโโโโ
Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
Department of Justice
Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions
Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty today to a widespread computer hacking conspiracy that resulted in the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerousโฆ
โค1
๐จ๐ฎ๐ฉ Starlite Indonesia customer database allegedly offered for sale
โ
A forum actor claims to be selling customer data belonging to Starlite Indonesia, a residential internet and Wi-Fi service provider operating in Indonesia.
โ
The listing advertises:
โ
โข 352,543 customer records
โข Database headers and sample records
โข A sale price of 2 XMR
โ
This claim is currently unverified.
โ
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โ
A forum actor claims to be selling customer data belonging to Starlite Indonesia, a residential internet and Wi-Fi service provider operating in Indonesia.
โ
The listing advertises:
โ
โข 352,543 customer records
โข Database headers and sample records
โข A sale price of 2 XMR
โ
This claim is currently unverified.
โ
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โผ๏ธ New Dark Web Informer Blog Post!
Title: Uruguay's Primary Education Databases Allegedly Breached, 1M+ Children's Records Offered for Sale and Query
Link: https://darkwebinformer.com/uruguays-primary-education-databases-allegedly-breached-1m-childrens-records-offered-for-sale-and-query/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Uruguay's Primary Education Databases Allegedly Breached, 1M+ Children's Records Offered for Sale and Query
Link: https://darkwebinformer.com/uruguays-primary-education-databases-allegedly-breached-1m-childrens-records-offered-for-sale-and-query/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Uruguay's Primary Education Databases Allegedly Breached, 1M+ Children's Records Offered for Sale and Query
An actor posting as LaPampaLeaks claims to hold the databases behind GURI, the student management platform operated by Uruguay's CEIP primary education council, covering pupils enrolled between 2012 and 2025.
Forwarded from FBI Watchdog Alerts by Dark Web Informer
โ ๏ธ FBI Watchdog - WHOIS Change โ ๏ธ
๐ DarkWebInformer.com - Cyber Threat Intelligence
Domain: xss.ac
Record Type: WHOIS Change
Time Detected: 2026-08-06 15:56:43 UTC
Previous Records:
New Records:
๐ DarkWebInformer.com - Cyber Threat Intelligence
Domain: xss.ac
Record Type: WHOIS Change
Time Detected: 2026-08-06 15:56:43 UTC
Previous Records:
status: ['clientdeleteprohibited', 'clienttransferprohibited']
New Records:
status: ['clientdeleteprohibited', 'clienttransferprohibited'] โ ['clientdeleteprohibited', 'clienthold', 'clienttransferprohibited']
๐จ๐บ๐ธ New York identity and Social Security data allegedly offered for sale
โ
A forum actor claims to be selling identity packages tied to individuals in New York, including government-issued identification and Social Security information.
โ
The advertised packages allegedly include:
โ
โข Full names and residential addresses
โข Social Security numbers
โข Photographs of New York driverโs licenses
โข Selfies showing individuals holding their identification
โข Additional identity verification information
โ
The seller advertises individual records for $25, two packages for $50, and 50 packages for $500. A sample containing highly sensitive personal information was published alongside the listing.
โ
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum actor claims to be selling identity packages tied to individuals in New York, including government-issued identification and Social Security information.
โ
The advertised packages allegedly include:
โ
โข Full names and residential addresses
โข Social Security numbers
โข Photographs of New York driverโs licenses
โข Selfies showing individuals holding their identification
โข Additional identity verification information
โ
The seller advertises individual records for $25, two packages for $50, and 50 packages for $500. A sample containing highly sensitive personal information was published alongside the listing.
โ
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ New Ransomware Group: Barracuda
Onion: http://uvm6hk4wwstfddja5z5htgtlehmfyflffijz6iozsuqyacyibzxefkqd[.]onion
Credit: https://x.com/fbgwls245
Onion: http://uvm6hk4wwstfddja5z5htgtlehmfyflffijz6iozsuqyacyibzxefkqd[.]onion
Credit: https://x.com/fbgwls245
X (formerly Twitter)
Bitshadow (@fbgwls245) on X
Ransomware & Dark Web tracker |
IOC sharing (hash / domain / IP) |
Self-taught threat hunter |
Forever learning, forever hunting | Student
(dnwls0719)
IOC sharing (hash / domain / IP) |
Self-taught threat hunter |
Forever learning, forever hunting | Student
(dnwls0719)
๐จ๐ฎ๐ณ Tit-Bit Foods data allegedly leaked following ransomware attack
โ
A forum actor claims to have infected a computer belonging to Tit-Bit Foods, an Indian food company, with ransomware and published company data after a payment was not made.
โ
The post includes:
โ
โข Multiple download links containing the allegedly stolen files
โข Images said to show the infected computer
โข A claim that the attack involved โLuzy Ricardo Milosโ ransomware
โ
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum actor claims to have infected a computer belonging to Tit-Bit Foods, an Indian food company, with ransomware and published company data after a payment was not made.
โ
The post includes:
โ
โข Multiple download links containing the allegedly stolen files
โข Images said to show the infected computer
โข A claim that the attack involved โLuzy Ricardo Milosโ ransomware
โ
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ฆ๐ท Domain administrator access to Argentine healthcare organization allegedly offered for sale
โ
A forum actor claims to be selling verified domain administrator access to an unidentified healthcare and social security organization in Argentina. The listing advertises an active session with access to Active Directory and an internal domain controller.
โ
The actor claims the compromised environment includes:
โ
โข Approximately 450 domain-joined hosts currently online
โข An organization with roughly 200,000 employees
โข Member and beneficiary records
โข Medical histories and clinical information
โข Financial data and SQL databases
โข Dumped password hashes
โข The domain administrator password in plaintext
โ
The affected organization is described only as using an .org.ar domain and generating between $80 million and $120 million in annual revenue. No price was publicly disclosed.
โ
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum actor claims to be selling verified domain administrator access to an unidentified healthcare and social security organization in Argentina. The listing advertises an active session with access to Active Directory and an internal domain controller.
โ
The actor claims the compromised environment includes:
โ
โข Approximately 450 domain-joined hosts currently online
โข An organization with roughly 200,000 employees
โข Member and beneficiary records
โข Medical histories and clinical information
โข Financial data and SQL databases
โข Dumped password hashes
โข The domain administrator password in plaintext
โ
The affected organization is described only as using an .org.ar domain and generating between $80 million and $120 million in annual revenue. No price was publicly disclosed.
โ
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ซ๐ท INSERM healthcare professional database allegedly offered for sale
โ
A forum actor claims to be selling a 2026 database associated with INSERM, Franceโs National Institute of Health and Medical Research. The listing advertises 192,451 records connected to healthcare professionals, medical research and public health.
โ
The exposed data allegedly includes:
โ
โข Names and dates of birth
โข Email addresses and phone numbers
โข RPPS and ADELI professional identifiers
โข Gender and civil-status information
โข Professional and account identifiers
โข Account creation and login timestamps
โข Password modification information
โข Department, region and municipality details
โข Postal addresses and geographic coordinates
โข Employer or healthcare institution information
โข SIRET business identifiers
โข Account roles, profiles and suspension status
โ
A sample containing personal, professional and account-related information was published alongside the listing.
โ
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum actor claims to be selling a 2026 database associated with INSERM, Franceโs National Institute of Health and Medical Research. The listing advertises 192,451 records connected to healthcare professionals, medical research and public health.
โ
The exposed data allegedly includes:
โ
โข Names and dates of birth
โข Email addresses and phone numbers
โข RPPS and ADELI professional identifiers
โข Gender and civil-status information
โข Professional and account identifiers
โข Account creation and login timestamps
โข Password modification information
โข Department, region and municipality details
โข Postal addresses and geographic coordinates
โข Employer or healthcare institution information
โข SIRET business identifiers
โข Account roles, profiles and suspension status
โ
A sample containing personal, professional and account-related information was published alongside the listing.
โ
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
New Ransomware Group: Storm โ๏ธ๐
http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
โค2
I am in the process of onboarding another 5+ forums, but need to do a little maintenance on the scripts. The forum monitoring status on the threat feed will be updated tomorrow so you know what to look for. Pitch will be completed this weekend. Wamus, if you have any concerns send me a message on Pitch.
๐จ๐ช๐ธ Juan de Diego customer, banking and invoicing database allegedly offered for sale
โ
A forum actor claims to be selling approximately 80,000 Spanish customer and business records associated with Juan de Diego. The seller claims the collection contains no duplicate entries and includes banking and tax-related information.
โ
The exposed data allegedly includes:
โ
โข Customer and company names
โข CIF and NIF tax identification numbers
โข IBAN and SWIFT banking details
โข Email addresses, phone numbers and fax numbers
โข Full postal addresses and websites
โข Client, supplier and account identifiers
โข Invoice, receipt and direct-debit mandate details
โข Payment amounts, currencies and transaction dates
โข Remittance, accounting and VAT information
โข Purchase orders and financial ledger entries
โ
Multiple samples containing personal, corporate and financial information were published alongside the listing.
โ
This claim is currently unverified.
โ
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
โ
A forum actor claims to be selling approximately 80,000 Spanish customer and business records associated with Juan de Diego. The seller claims the collection contains no duplicate entries and includes banking and tax-related information.
โ
The exposed data allegedly includes:
โ
โข Customer and company names
โข CIF and NIF tax identification numbers
โข IBAN and SWIFT banking details
โข Email addresses, phone numbers and fax numbers
โข Full postal addresses and websites
โข Client, supplier and account identifiers
โข Invoice, receipt and direct-debit mandate details
โข Payment amounts, currencies and transaction dates
โข Remittance, accounting and VAT information
โข Purchase orders and financial ledger entries
โ
Multiple samples containing personal, corporate and financial information were published alongside the listing.
โ
This claim is currently unverified.
โ
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials