Forwarded from Dark Web Informer - Private
‼️ DOJ Press Release
━━━━━━━━━━━━━━━━━━━━━
Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions
Full Press Release → justice.gov
━━━━━━━━━━━━━━━━━━━━━
🕵️ Dark Web Informer • DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
━━━━━━━━━━━━━━━━━━━━━
Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions
Full Press Release → justice.gov
━━━━━━━━━━━━━━━━━━━━━
🕵️ Dark Web Informer • DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
Department of Justice
Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions
Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty today to a widespread computer hacking conspiracy that resulted in the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous…
❤1
🚨🇮🇩 Starlite Indonesia customer database allegedly offered for sale
⠀
A forum actor claims to be selling customer data belonging to Starlite Indonesia, a residential internet and Wi-Fi service provider operating in Indonesia.
⠀
The listing advertises:
⠀
• 352,543 customer records
• Database headers and sample records
• A sale price of 2 XMR
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor claims to be selling customer data belonging to Starlite Indonesia, a residential internet and Wi-Fi service provider operating in Indonesia.
⠀
The listing advertises:
⠀
• 352,543 customer records
• Database headers and sample records
• A sale price of 2 XMR
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: Uruguay's Primary Education Databases Allegedly Breached, 1M+ Children's Records Offered for Sale and Query
Link: https://darkwebinformer.com/uruguays-primary-education-databases-allegedly-breached-1m-childrens-records-offered-for-sale-and-query/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Uruguay's Primary Education Databases Allegedly Breached, 1M+ Children's Records Offered for Sale and Query
Link: https://darkwebinformer.com/uruguays-primary-education-databases-allegedly-breached-1m-childrens-records-offered-for-sale-and-query/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Uruguay's Primary Education Databases Allegedly Breached, 1M+ Children's Records Offered for Sale and Query
An actor posting as LaPampaLeaks claims to hold the databases behind GURI, the student management platform operated by Uruguay's CEIP primary education council, covering pupils enrolled between 2012 and 2025.
Forwarded from FBI Watchdog Alerts by Dark Web Informer
⚠️ FBI Watchdog - WHOIS Change ⚠️
🔗 DarkWebInformer.com - Cyber Threat Intelligence
Domain: xss.ac
Record Type: WHOIS Change
Time Detected: 2026-08-06 15:56:43 UTC
Previous Records:
New Records:
🔗 DarkWebInformer.com - Cyber Threat Intelligence
Domain: xss.ac
Record Type: WHOIS Change
Time Detected: 2026-08-06 15:56:43 UTC
Previous Records:
status: ['clientdeleteprohibited', 'clienttransferprohibited']
New Records:
status: ['clientdeleteprohibited', 'clienttransferprohibited'] → ['clientdeleteprohibited', 'clienthold', 'clienttransferprohibited']
🚨🇺🇸 New York identity and Social Security data allegedly offered for sale
⠀
A forum actor claims to be selling identity packages tied to individuals in New York, including government-issued identification and Social Security information.
⠀
The advertised packages allegedly include:
⠀
• Full names and residential addresses
• Social Security numbers
• Photographs of New York driver’s licenses
• Selfies showing individuals holding their identification
• Additional identity verification information
⠀
The seller advertises individual records for $25, two packages for $50, and 50 packages for $500. A sample containing highly sensitive personal information was published alongside the listing.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling identity packages tied to individuals in New York, including government-issued identification and Social Security information.
⠀
The advertised packages allegedly include:
⠀
• Full names and residential addresses
• Social Security numbers
• Photographs of New York driver’s licenses
• Selfies showing individuals holding their identification
• Additional identity verification information
⠀
The seller advertises individual records for $25, two packages for $50, and 50 packages for $500. A sample containing highly sensitive personal information was published alongside the listing.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 New Ransomware Group: Barracuda
Onion: http://uvm6hk4wwstfddja5z5htgtlehmfyflffijz6iozsuqyacyibzxefkqd[.]onion
Credit: https://x.com/fbgwls245
Onion: http://uvm6hk4wwstfddja5z5htgtlehmfyflffijz6iozsuqyacyibzxefkqd[.]onion
Credit: https://x.com/fbgwls245
X (formerly Twitter)
Bitshadow (@fbgwls245) on X
Ransomware & Dark Web tracker |
IOC sharing (hash / domain / IP) |
Self-taught threat hunter |
Forever learning, forever hunting | Student
(dnwls0719)
IOC sharing (hash / domain / IP) |
Self-taught threat hunter |
Forever learning, forever hunting | Student
(dnwls0719)
🚨🇮🇳 Tit-Bit Foods data allegedly leaked following ransomware attack
⠀
A forum actor claims to have infected a computer belonging to Tit-Bit Foods, an Indian food company, with ransomware and published company data after a payment was not made.
⠀
The post includes:
⠀
• Multiple download links containing the allegedly stolen files
• Images said to show the infected computer
• A claim that the attack involved “Luzy Ricardo Milos” ransomware
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to have infected a computer belonging to Tit-Bit Foods, an Indian food company, with ransomware and published company data after a payment was not made.
⠀
The post includes:
⠀
• Multiple download links containing the allegedly stolen files
• Images said to show the infected computer
• A claim that the attack involved “Luzy Ricardo Milos” ransomware
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇦🇷 Domain administrator access to Argentine healthcare organization allegedly offered for sale
⠀
A forum actor claims to be selling verified domain administrator access to an unidentified healthcare and social security organization in Argentina. The listing advertises an active session with access to Active Directory and an internal domain controller.
⠀
The actor claims the compromised environment includes:
⠀
• Approximately 450 domain-joined hosts currently online
• An organization with roughly 200,000 employees
• Member and beneficiary records
• Medical histories and clinical information
• Financial data and SQL databases
• Dumped password hashes
• The domain administrator password in plaintext
⠀
The affected organization is described only as using an .org.ar domain and generating between $80 million and $120 million in annual revenue. No price was publicly disclosed.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling verified domain administrator access to an unidentified healthcare and social security organization in Argentina. The listing advertises an active session with access to Active Directory and an internal domain controller.
⠀
The actor claims the compromised environment includes:
⠀
• Approximately 450 domain-joined hosts currently online
• An organization with roughly 200,000 employees
• Member and beneficiary records
• Medical histories and clinical information
• Financial data and SQL databases
• Dumped password hashes
• The domain administrator password in plaintext
⠀
The affected organization is described only as using an .org.ar domain and generating between $80 million and $120 million in annual revenue. No price was publicly disclosed.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 INSERM healthcare professional database allegedly offered for sale
⠀
A forum actor claims to be selling a 2026 database associated with INSERM, France’s National Institute of Health and Medical Research. The listing advertises 192,451 records connected to healthcare professionals, medical research and public health.
⠀
The exposed data allegedly includes:
⠀
• Names and dates of birth
• Email addresses and phone numbers
• RPPS and ADELI professional identifiers
• Gender and civil-status information
• Professional and account identifiers
• Account creation and login timestamps
• Password modification information
• Department, region and municipality details
• Postal addresses and geographic coordinates
• Employer or healthcare institution information
• SIRET business identifiers
• Account roles, profiles and suspension status
⠀
A sample containing personal, professional and account-related information was published alongside the listing.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling a 2026 database associated with INSERM, France’s National Institute of Health and Medical Research. The listing advertises 192,451 records connected to healthcare professionals, medical research and public health.
⠀
The exposed data allegedly includes:
⠀
• Names and dates of birth
• Email addresses and phone numbers
• RPPS and ADELI professional identifiers
• Gender and civil-status information
• Professional and account identifiers
• Account creation and login timestamps
• Password modification information
• Department, region and municipality details
• Postal addresses and geographic coordinates
• Employer or healthcare institution information
• SIRET business identifiers
• Account roles, profiles and suspension status
⠀
A sample containing personal, professional and account-related information was published alongside the listing.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
New Ransomware Group: Storm ⛈️👇
http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
❤2
I am in the process of onboarding another 5+ forums, but need to do a little maintenance on the scripts. The forum monitoring status on the threat feed will be updated tomorrow so you know what to look for. Pitch will be completed this weekend. Wamus, if you have any concerns send me a message on Pitch.
🚨🇪🇸 Juan de Diego customer, banking and invoicing database allegedly offered for sale
⠀
A forum actor claims to be selling approximately 80,000 Spanish customer and business records associated with Juan de Diego. The seller claims the collection contains no duplicate entries and includes banking and tax-related information.
⠀
The exposed data allegedly includes:
⠀
• Customer and company names
• CIF and NIF tax identification numbers
• IBAN and SWIFT banking details
• Email addresses, phone numbers and fax numbers
• Full postal addresses and websites
• Client, supplier and account identifiers
• Invoice, receipt and direct-debit mandate details
• Payment amounts, currencies and transaction dates
• Remittance, accounting and VAT information
• Purchase orders and financial ledger entries
⠀
Multiple samples containing personal, corporate and financial information were published alongside the listing.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
A forum actor claims to be selling approximately 80,000 Spanish customer and business records associated with Juan de Diego. The seller claims the collection contains no duplicate entries and includes banking and tax-related information.
⠀
The exposed data allegedly includes:
⠀
• Customer and company names
• CIF and NIF tax identification numbers
• IBAN and SWIFT banking details
• Email addresses, phone numbers and fax numbers
• Full postal addresses and websites
• Client, supplier and account identifiers
• Invoice, receipt and direct-debit mandate details
• Payment amounts, currencies and transaction dates
• Remittance, accounting and VAT information
• Purchase orders and financial ledger entries
⠀
Multiple samples containing personal, corporate and financial information were published alongside the listing.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
‼️ New Dark Web Informer Blog Post!
Title: CARMA Client Data Allegedly for Sale, Configurations for 3,500+ Organisations Including Government Bodies
Link: https://darkwebinformer.com/carma-client-data-allegedly-for-sale-configurations-for-3-500-organisations-including-government-bodies/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: CARMA Client Data Allegedly for Sale, Configurations for 3,500+ Organisations Including Government Bodies
Link: https://darkwebinformer.com/carma-client-data-allegedly-for-sale-configurations-for-3-500-organisations-including-government-bodies/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
CARMA Client Data Allegedly for Sale, Configurations for 3,500+ Organisations Including Government Bodies
A seller posting as 2019 is advertising what they describe as data from CARMA, a global media intelligence firm providing media monitoring, social listening, and PR measurement to more than 3,500 organisations, among them Fortune 500 companies, communications…
‼️ New Dark Web Informer Blog Post!
Title: French Basketball Federation Data Allegedly for Sale, 75,831 People and 2,000 CVs Listed
Link: https://darkwebinformer.com/french-basketball-federation-data-allegedly-for-sale-75-831-people-and-2-000-cvs-listed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: French Basketball Federation Data Allegedly for Sale, 75,831 People and 2,000 CVs Listed
Link: https://darkwebinformer.com/french-basketball-federation-data-allegedly-for-sale-75-831-people-and-2-000-cvs-listed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
French Basketball Federation Data Allegedly for Sale, 75,831 People and 2,000 CVs Listed
A seller posting as weykofa is advertising what they describe as the database of the Fédération Française de Basketball, the national governing body for basketball in France.
🔪 Slice For Life - Part 2 🔪
New Ransomware Group: Storm ⛈️👇 http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
🚨 Storm operation launches global affiliate recruitment campaign
⠀
The Storm operation is recruiting affiliates and other specialists through a newly advertised global partnership program focused on high-value engagements outside CIS countries.
⠀
The recruitment post emphasizes:
⠀
• Expansion of an international affiliate network
• Recruitment of experienced and highly skilled specialists
• A strict prohibition on targeting CIS countries
• Operational discretion and enhanced security protocols
• Protection of client interests and sensitive data
• High-end services focused on precision and reliability
• Confidential recruitment discussions through Tox
⠀
The group also published an onion address connected to the operation. No revenue split, technical capabilities or specific affiliate roles were publicly disclosed.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
The Storm operation is recruiting affiliates and other specialists through a newly advertised global partnership program focused on high-value engagements outside CIS countries.
⠀
The recruitment post emphasizes:
⠀
• Expansion of an international affiliate network
• Recruitment of experienced and highly skilled specialists
• A strict prohibition on targeting CIS countries
• Operational discretion and enhanced security protocols
• Protection of client interests and sensitive data
• High-end services focused on precision and reliability
• Confidential recruitment discussions through Tox
⠀
The group also published an onion address connected to the operation. No revenue split, technical capabilities or specific affiliate roles were publicly disclosed.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 AWS infrastructure access for unidentified Asian logistics company allegedly offered for sale
⠀
A forum actor claims to be selling access to an Asia-based logistics company described as a member of KLN, with approximately $34 million in revenue.
⠀
The advertised access allegedly includes:
⠀
• The company’s AWS cloud environment
• 34 cloud instances
• Warehouse management systems
• S3 storage buckets
• Backup servers
• Root access to an internal Linux server
⠀
The seller is asking $1,500 and claims proof of access will only be shown to verified buyers.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling access to an Asia-based logistics company described as a member of KLN, with approximately $34 million in revenue.
⠀
The advertised access allegedly includes:
⠀
• The company’s AWS cloud environment
• 34 cloud instances
• Warehouse management systems
• S3 storage buckets
• Backup servers
• Root access to an internal Linux server
⠀
The seller is asking $1,500 and claims proof of access will only be shown to verified buyers.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
WHOIS for xss.ac
Domain: xss.ac
Registered On: 2026-03-10 06:25:47 UTC
Expires On: 2027-03-10 06:25:47 UTC
Updated On: 2026-08-06 15:43:17 UTC
Status:
clientDeleteProhibited
clientHold
clientTransferProhibited
Name Servers:
ns1.ddos-guard.net
ns2.ddos-guard.net
Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED
URL: ['http://www.nicenic.net', 'https://nicenic.com']
Name: ['REDACTED', 'Alphred Fobazol']
Email: abuse@nicenic.net
Country: CV
Domain: xss.ac
Registered On: 2026-03-10 06:25:47 UTC
Expires On: 2027-03-10 06:25:47 UTC
Updated On: 2026-08-06 15:43:17 UTC
Status:
clientDeleteProhibited
clientHold
clientTransferProhibited
Name Servers:
ns1.ddos-guard.net
ns2.ddos-guard.net
Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED
URL: ['http://www.nicenic.net', 'https://nicenic.com']
Name: ['REDACTED', 'Alphred Fobazol']
Email: abuse@nicenic.net
Country: CV
🚨🇨🇴 Campoalto employee credentials and personal data allegedly leaked
⠀
A forum actor claims to have breached Campoalto, a Colombian education and vocational training institution, and published data taken from its internal systems.
⠀
The post allegedly includes:
⠀
• Employee usernames and passwords
• A file containing names and surnames
• Group or organizational information
• A screenshot presented as evidence of access
• Claims of additional compromised information
⠀
The actor says the intrusion was carried out in retaliation over the institution’s alleged treatment of employees.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor claims to have breached Campoalto, a Colombian education and vocational training institution, and published data taken from its internal systems.
⠀
The post allegedly includes:
⠀
• Employee usernames and passwords
• A file containing names and surnames
• Group or organizational information
• A screenshot presented as evidence of access
• Claims of additional compromised information
⠀
The actor says the intrusion was carried out in retaliation over the institution’s alleged treatment of employees.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing