🔪 Slice For Life - Part 2 🔪
4.3K subscribers
807 photos
37 videos
744 links
Download Telegram
🚨🇺🇸 Allstate-branded staging CRM data allegedly exposed through misconfigured Firebase database

A forum actor claims to have discovered a publicly accessible Firebase Realtime Database tied to an Allstate-branded tax preparation and client management platform. The actor says the staging environment allowed unauthenticated read and write access.

The exposed data allegedly includes:

• 968 Stripe transactions totaling approximately $182,830
• 20 Stripe production customer identifiers
• Seven business accounts with tax and incorporation information
• Eleven user profiles containing names, emails, phone numbers and Social Security numbers
• Session, ID and refresh tokens
• Nine SMS threads containing 26 messages between agents and clients
• Tax return documents and other conversation attachments
• Eleven employee pay periods with hours worked
• Six Firebase Storage download tokens
• Billing records, invoice identifiers and payment statuses

The actor claims write access was tested across five database endpoints, potentially allowing records, accounts, conversations and payment information to be modified. A database export and supporting files were also advertised for download.

The post attributes the environment to Allstate, but the displayed records reference Allstate Tax LLC and other tax preparation clients. The relationship to Allstate Corporation has not been independently confirmed.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
Media is too big
VIEW IN TELEGRAM
How the NSA Hacks the World: The TAO Unit Exposed

Video Credit: youtube.com/Vice
🔥3
Forwarded from Dark Web Informer - Private
‼️ DOJ Press Release
━━━━━━━━━━━━━━━━━━━━━

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions

Full Press Release → justice.gov

━━━━━━━━━━━━━━━━━━━━━
🕵️ Dark Web Informer • DOJ Monitor

Note: DOJ articles that are not Cyber related will be removed manually.
1
🚨🇮🇩 Starlite Indonesia customer database allegedly offered for sale

A forum actor claims to be selling customer data belonging to Starlite Indonesia, a residential internet and Wi-Fi service provider operating in Indonesia.

The listing advertises:

• 352,543 customer records
• Database headers and sample records
• A sale price of 2 XMR

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⚠️ FBI Watchdog - WHOIS Change ⚠️
🔗 DarkWebInformer.com - Cyber Threat Intelligence

Domain: xss.ac
Record Type: WHOIS Change
Time Detected: 2026-08-06 15:56:43 UTC

Previous Records:
status: ['clientdeleteprohibited', 'clienttransferprohibited']

New Records:
status: ['clientdeleteprohibited', 'clienttransferprohibited'] → ['clientdeleteprohibited', 'clienthold', 'clienttransferprohibited']
🚨🇺🇸 New York identity and Social Security data allegedly offered for sale

A forum actor claims to be selling identity packages tied to individuals in New York, including government-issued identification and Social Security information.

The advertised packages allegedly include:

• Full names and residential addresses
• Social Security numbers
• Photographs of New York driver’s licenses
• Selfies showing individuals holding their identification
• Additional identity verification information

The seller advertises individual records for $25, two packages for $50, and 50 packages for $500. A sample containing highly sensitive personal information was published alongside the listing.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇮🇳 Tit-Bit Foods data allegedly leaked following ransomware attack

A forum actor claims to have infected a computer belonging to Tit-Bit Foods, an Indian food company, with ransomware and published company data after a payment was not made.

The post includes:

• Multiple download links containing the allegedly stolen files
• Images said to show the infected computer
• A claim that the attack involved “Luzy Ricardo Milos” ransomware

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇦🇷 Domain administrator access to Argentine healthcare organization allegedly offered for sale

A forum actor claims to be selling verified domain administrator access to an unidentified healthcare and social security organization in Argentina. The listing advertises an active session with access to Active Directory and an internal domain controller.

The actor claims the compromised environment includes:

• Approximately 450 domain-joined hosts currently online
• An organization with roughly 200,000 employees
• Member and beneficiary records
• Medical histories and clinical information
• Financial data and SQL databases
• Dumped password hashes
• The domain administrator password in plaintext

The affected organization is described only as using an .org.ar domain and generating between $80 million and $120 million in annual revenue. No price was publicly disclosed.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 INSERM healthcare professional database allegedly offered for sale

A forum actor claims to be selling a 2026 database associated with INSERM, France’s National Institute of Health and Medical Research. The listing advertises 192,451 records connected to healthcare professionals, medical research and public health.

The exposed data allegedly includes:

• Names and dates of birth
• Email addresses and phone numbers
• RPPS and ADELI professional identifiers
• Gender and civil-status information
• Professional and account identifiers
• Account creation and login timestamps
• Password modification information
• Department, region and municipality details
• Postal addresses and geographic coordinates
• Employer or healthcare institution information
• SIRET business identifiers
• Account roles, profiles and suspension status

A sample containing personal, professional and account-related information was published alongside the listing.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
New Ransomware Group: Storm ⛈️👇

http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
2
I am in the process of onboarding another 5+ forums, but need to do a little maintenance on the scripts. The forum monitoring status on the threat feed will be updated tomorrow so you know what to look for. Pitch will be completed this weekend. Wamus, if you have any concerns send me a message on Pitch.
🚨🇪🇸 Juan de Diego customer, banking and invoicing database allegedly offered for sale

A forum actor claims to be selling approximately 80,000 Spanish customer and business records associated with Juan de Diego. The seller claims the collection contains no duplicate entries and includes banking and tax-related information.

The exposed data allegedly includes:

• Customer and company names
• CIF and NIF tax identification numbers
• IBAN and SWIFT banking details
• Email addresses, phone numbers and fax numbers
• Full postal addresses and websites
• Client, supplier and account identifiers
• Invoice, receipt and direct-debit mandate details
• Payment amounts, currencies and transaction dates
• Remittance, accounting and VAT information
• Purchase orders and financial ledger entries

Multiple samples containing personal, corporate and financial information were published alongside the listing.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🔪 Slice For Life - Part 2 🔪
New Ransomware Group: Storm ⛈️👇 http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
🚨 Storm operation launches global affiliate recruitment campaign

The Storm operation is recruiting affiliates and other specialists through a newly advertised global partnership program focused on high-value engagements outside CIS countries.

The recruitment post emphasizes:

• Expansion of an international affiliate network
• Recruitment of experienced and highly skilled specialists
• A strict prohibition on targeting CIS countries
• Operational discretion and enhanced security protocols
• Protection of client interests and sensitive data
• High-end services focused on precision and reliability
• Confidential recruitment discussions through Tox

The group also published an onion address connected to the operation. No revenue split, technical capabilities or specific affiliate roles were publicly disclosed.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 AWS infrastructure access for unidentified Asian logistics company allegedly offered for sale

A forum actor claims to be selling access to an Asia-based logistics company described as a member of KLN, with approximately $34 million in revenue.

The advertised access allegedly includes:

• The company’s AWS cloud environment
• 34 cloud instances
• Warehouse management systems
• S3 storage buckets
• Backup servers
• Root access to an internal Linux server

The seller is asking $1,500 and claims proof of access will only be shown to verified buyers.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
1