🚨🇮🇳 Tit-Bit Foods data allegedly leaked following ransomware attack
⠀
A forum actor claims to have infected a computer belonging to Tit-Bit Foods, an Indian food company, with ransomware and published company data after a payment was not made.
⠀
The post includes:
⠀
• Multiple download links containing the allegedly stolen files
• Images said to show the infected computer
• A claim that the attack involved “Luzy Ricardo Milos” ransomware
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to have infected a computer belonging to Tit-Bit Foods, an Indian food company, with ransomware and published company data after a payment was not made.
⠀
The post includes:
⠀
• Multiple download links containing the allegedly stolen files
• Images said to show the infected computer
• A claim that the attack involved “Luzy Ricardo Milos” ransomware
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇦🇷 Domain administrator access to Argentine healthcare organization allegedly offered for sale
⠀
A forum actor claims to be selling verified domain administrator access to an unidentified healthcare and social security organization in Argentina. The listing advertises an active session with access to Active Directory and an internal domain controller.
⠀
The actor claims the compromised environment includes:
⠀
• Approximately 450 domain-joined hosts currently online
• An organization with roughly 200,000 employees
• Member and beneficiary records
• Medical histories and clinical information
• Financial data and SQL databases
• Dumped password hashes
• The domain administrator password in plaintext
⠀
The affected organization is described only as using an .org.ar domain and generating between $80 million and $120 million in annual revenue. No price was publicly disclosed.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling verified domain administrator access to an unidentified healthcare and social security organization in Argentina. The listing advertises an active session with access to Active Directory and an internal domain controller.
⠀
The actor claims the compromised environment includes:
⠀
• Approximately 450 domain-joined hosts currently online
• An organization with roughly 200,000 employees
• Member and beneficiary records
• Medical histories and clinical information
• Financial data and SQL databases
• Dumped password hashes
• The domain administrator password in plaintext
⠀
The affected organization is described only as using an .org.ar domain and generating between $80 million and $120 million in annual revenue. No price was publicly disclosed.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 INSERM healthcare professional database allegedly offered for sale
⠀
A forum actor claims to be selling a 2026 database associated with INSERM, France’s National Institute of Health and Medical Research. The listing advertises 192,451 records connected to healthcare professionals, medical research and public health.
⠀
The exposed data allegedly includes:
⠀
• Names and dates of birth
• Email addresses and phone numbers
• RPPS and ADELI professional identifiers
• Gender and civil-status information
• Professional and account identifiers
• Account creation and login timestamps
• Password modification information
• Department, region and municipality details
• Postal addresses and geographic coordinates
• Employer or healthcare institution information
• SIRET business identifiers
• Account roles, profiles and suspension status
⠀
A sample containing personal, professional and account-related information was published alongside the listing.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling a 2026 database associated with INSERM, France’s National Institute of Health and Medical Research. The listing advertises 192,451 records connected to healthcare professionals, medical research and public health.
⠀
The exposed data allegedly includes:
⠀
• Names and dates of birth
• Email addresses and phone numbers
• RPPS and ADELI professional identifiers
• Gender and civil-status information
• Professional and account identifiers
• Account creation and login timestamps
• Password modification information
• Department, region and municipality details
• Postal addresses and geographic coordinates
• Employer or healthcare institution information
• SIRET business identifiers
• Account roles, profiles and suspension status
⠀
A sample containing personal, professional and account-related information was published alongside the listing.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
New Ransomware Group: Storm ⛈️👇
http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
❤2
I am in the process of onboarding another 5+ forums, but need to do a little maintenance on the scripts. The forum monitoring status on the threat feed will be updated tomorrow so you know what to look for. Pitch will be completed this weekend. Wamus, if you have any concerns send me a message on Pitch.
🚨🇪🇸 Juan de Diego customer, banking and invoicing database allegedly offered for sale
⠀
A forum actor claims to be selling approximately 80,000 Spanish customer and business records associated with Juan de Diego. The seller claims the collection contains no duplicate entries and includes banking and tax-related information.
⠀
The exposed data allegedly includes:
⠀
• Customer and company names
• CIF and NIF tax identification numbers
• IBAN and SWIFT banking details
• Email addresses, phone numbers and fax numbers
• Full postal addresses and websites
• Client, supplier and account identifiers
• Invoice, receipt and direct-debit mandate details
• Payment amounts, currencies and transaction dates
• Remittance, accounting and VAT information
• Purchase orders and financial ledger entries
⠀
Multiple samples containing personal, corporate and financial information were published alongside the listing.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
A forum actor claims to be selling approximately 80,000 Spanish customer and business records associated with Juan de Diego. The seller claims the collection contains no duplicate entries and includes banking and tax-related information.
⠀
The exposed data allegedly includes:
⠀
• Customer and company names
• CIF and NIF tax identification numbers
• IBAN and SWIFT banking details
• Email addresses, phone numbers and fax numbers
• Full postal addresses and websites
• Client, supplier and account identifiers
• Invoice, receipt and direct-debit mandate details
• Payment amounts, currencies and transaction dates
• Remittance, accounting and VAT information
• Purchase orders and financial ledger entries
⠀
Multiple samples containing personal, corporate and financial information were published alongside the listing.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
‼️ New Dark Web Informer Blog Post!
Title: CARMA Client Data Allegedly for Sale, Configurations for 3,500+ Organisations Including Government Bodies
Link: https://darkwebinformer.com/carma-client-data-allegedly-for-sale-configurations-for-3-500-organisations-including-government-bodies/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: CARMA Client Data Allegedly for Sale, Configurations for 3,500+ Organisations Including Government Bodies
Link: https://darkwebinformer.com/carma-client-data-allegedly-for-sale-configurations-for-3-500-organisations-including-government-bodies/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
CARMA Client Data Allegedly for Sale, Configurations for 3,500+ Organisations Including Government Bodies
A seller posting as 2019 is advertising what they describe as data from CARMA, a global media intelligence firm providing media monitoring, social listening, and PR measurement to more than 3,500 organisations, among them Fortune 500 companies, communications…
‼️ New Dark Web Informer Blog Post!
Title: French Basketball Federation Data Allegedly for Sale, 75,831 People and 2,000 CVs Listed
Link: https://darkwebinformer.com/french-basketball-federation-data-allegedly-for-sale-75-831-people-and-2-000-cvs-listed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: French Basketball Federation Data Allegedly for Sale, 75,831 People and 2,000 CVs Listed
Link: https://darkwebinformer.com/french-basketball-federation-data-allegedly-for-sale-75-831-people-and-2-000-cvs-listed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
French Basketball Federation Data Allegedly for Sale, 75,831 People and 2,000 CVs Listed
A seller posting as weykofa is advertising what they describe as the database of the Fédération Française de Basketball, the national governing body for basketball in France.
🔪 Slice For Life - Part 2 🔪
New Ransomware Group: Storm ⛈️👇 http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion
🚨 Storm operation launches global affiliate recruitment campaign
⠀
The Storm operation is recruiting affiliates and other specialists through a newly advertised global partnership program focused on high-value engagements outside CIS countries.
⠀
The recruitment post emphasizes:
⠀
• Expansion of an international affiliate network
• Recruitment of experienced and highly skilled specialists
• A strict prohibition on targeting CIS countries
• Operational discretion and enhanced security protocols
• Protection of client interests and sensitive data
• High-end services focused on precision and reliability
• Confidential recruitment discussions through Tox
⠀
The group also published an onion address connected to the operation. No revenue split, technical capabilities or specific affiliate roles were publicly disclosed.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
The Storm operation is recruiting affiliates and other specialists through a newly advertised global partnership program focused on high-value engagements outside CIS countries.
⠀
The recruitment post emphasizes:
⠀
• Expansion of an international affiliate network
• Recruitment of experienced and highly skilled specialists
• A strict prohibition on targeting CIS countries
• Operational discretion and enhanced security protocols
• Protection of client interests and sensitive data
• High-end services focused on precision and reliability
• Confidential recruitment discussions through Tox
⠀
The group also published an onion address connected to the operation. No revenue split, technical capabilities or specific affiliate roles were publicly disclosed.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 AWS infrastructure access for unidentified Asian logistics company allegedly offered for sale
⠀
A forum actor claims to be selling access to an Asia-based logistics company described as a member of KLN, with approximately $34 million in revenue.
⠀
The advertised access allegedly includes:
⠀
• The company’s AWS cloud environment
• 34 cloud instances
• Warehouse management systems
• S3 storage buckets
• Backup servers
• Root access to an internal Linux server
⠀
The seller is asking $1,500 and claims proof of access will only be shown to verified buyers.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling access to an Asia-based logistics company described as a member of KLN, with approximately $34 million in revenue.
⠀
The advertised access allegedly includes:
⠀
• The company’s AWS cloud environment
• 34 cloud instances
• Warehouse management systems
• S3 storage buckets
• Backup servers
• Root access to an internal Linux server
⠀
The seller is asking $1,500 and claims proof of access will only be shown to verified buyers.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
WHOIS for xss.ac
Domain: xss.ac
Registered On: 2026-03-10 06:25:47 UTC
Expires On: 2027-03-10 06:25:47 UTC
Updated On: 2026-08-06 15:43:17 UTC
Status:
clientDeleteProhibited
clientHold
clientTransferProhibited
Name Servers:
ns1.ddos-guard.net
ns2.ddos-guard.net
Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED
URL: ['http://www.nicenic.net', 'https://nicenic.com']
Name: ['REDACTED', 'Alphred Fobazol']
Email: abuse@nicenic.net
Country: CV
Domain: xss.ac
Registered On: 2026-03-10 06:25:47 UTC
Expires On: 2027-03-10 06:25:47 UTC
Updated On: 2026-08-06 15:43:17 UTC
Status:
clientDeleteProhibited
clientHold
clientTransferProhibited
Name Servers:
ns1.ddos-guard.net
ns2.ddos-guard.net
Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED
URL: ['http://www.nicenic.net', 'https://nicenic.com']
Name: ['REDACTED', 'Alphred Fobazol']
Email: abuse@nicenic.net
Country: CV
🚨🇨🇴 Campoalto employee credentials and personal data allegedly leaked
⠀
A forum actor claims to have breached Campoalto, a Colombian education and vocational training institution, and published data taken from its internal systems.
⠀
The post allegedly includes:
⠀
• Employee usernames and passwords
• A file containing names and surnames
• Group or organizational information
• A screenshot presented as evidence of access
• Claims of additional compromised information
⠀
The actor says the intrusion was carried out in retaliation over the institution’s alleged treatment of employees.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor claims to have breached Campoalto, a Colombian education and vocational training institution, and published data taken from its internal systems.
⠀
The post allegedly includes:
⠀
• Employee usernames and passwords
• A file containing names and surnames
• Group or organizational information
• A screenshot presented as evidence of access
• Claims of additional compromised information
⠀
The actor says the intrusion was carried out in retaliation over the institution’s alleged treatment of employees.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
Going forward, I will delete any Free accounts that have not been accessed in 30 days. This helps keep things clean.
This does not apply to paid accounts. If your account is paid and has not been accessed for more than 30 days, it will still be there. 💙
You are free to sign up again at any point.
This does not apply to paid accounts. If your account is paid and has not been accessed for more than 30 days, it will still be there. 💙
You are free to sign up again at any point.
🔪 Slice For Life - Part 2 🔪
‼️ New Ransomware Group: L group Onion: http://4zrjdyuq4sjogm2epwwoleegquavhwo3o7fakstnlgox6guqt3qpe4qd[.]onion
Apache Server Status for L group Ransomware
/server-status
/server-status
🚨🇮🇳 Pulse Secure VPN access to major Indian financial services company allegedly offered for sale
⠀
A forum actor claims to be selling VPN access to an unidentified financial services organization in India with estimated annual revenue between $1 billion and $5 billion.
⠀
The advertised access allegedly includes:
⠀
• Pulse Secure VPN access
• Local administrator privileges
• Access to a network containing approximately 10,000+ hosts
• Carbon Black deployed as the organization’s AV/EDR solution
⠀
The seller did not publicly identify the affected company or disclose a sale price.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling VPN access to an unidentified financial services organization in India with estimated annual revenue between $1 billion and $5 billion.
⠀
The advertised access allegedly includes:
⠀
• Pulse Secure VPN access
• Local administrator privileges
• Access to a network containing approximately 10,000+ hosts
• Carbon Black deployed as the organization’s AV/EDR solution
⠀
The seller did not publicly identify the affected company or disclose a sale price.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys
Link: https://darkwebinformer.com/acre-africa-breach-allegedly-exposes-14-300-smallholder-farmers-alongside-source-code-and-private-keys/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys
Link: https://darkwebinformer.com/acre-africa-breach-allegedly-exposes-14-300-smallholder-farmers-alongside-source-code-and-private-keys/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys
A forum user posting as 888 has published what they describe as a breach of ACRE Africa, an authorised insurance intermediary providing agricultural and climate risk cover to smallholder farmers across the continent.