🔪 Slice For Life - Part 2 🔪
4.29K subscribers
792 photos
36 videos
735 links
Download Telegram
🚨 New Ransomware Group: Sovcali

Found via XSS forum.

Dark Web Onion IOC: http://z3mojpjnxt5tgqvu4wgosihl7pxvrcbyjcgquw2bwkyye5gwbhnf4kqd[.]onion/
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🚨🇮🇱 Israel Population and Immigration Authority database allegedly breached

A forum actor claims to have breached Israel’s Population and Immigration Authority and obtained a 2026 population database containing 9,220,583 records.

The exposed data allegedly includes:

• Israeli identification numbers
• First, last and former names
• Gender and marital status
• Full residential addresses
• Phone numbers
• Dates and countries of birth
• Immigration and Aliyah dates
• Death dates and status information
• Parents’ names and identification numbers
• Spouse and family identifiers
• Children and household relationship data
• Additional internal notes and record metadata

The actor published a 100,000-record sample as proof and claims the complete database is approximately 7.5GB in size. The post also highlights records purportedly associated with prominent Israeli figures.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🔥1
Please open Telegram to view this post
VIEW IN TELEGRAM
2
🚨🇫🇷 Roussel Agri 62 email, CRM and business documents allegedly leaked

A forum actor claims to have leaked data belonging to Roussel Agri 62, a French agricultural business. The post is described as the first in a series of alleged leaks connected to BlgCloud.

The advertised collection includes:

• 9.33GB of data
• 45,684 files
• 29,127 emails
• 23,816 CRM records
• 45,681 business documents
• Customer and business contact information
• Names, email addresses and phone numbers
• Postal and company addresses
• CRM relationship and account data
• Banking details, including IBAN information
• Orders, invoices and other commercial documents

The actor published email, CRM and document samples alongside the post.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 CLCV consumer association database allegedly leaked

A forum actor claims to have leaked approximately 80,031 records associated with CLCV, a French national consumer and user advocacy organization.

The exposed data allegedly includes:

• Names and contact information
• Email addresses and phone numbers
• Postal addresses and cities
• Membership numbers
• Consumer request and complaint details
• Housing-related inquiries
• Mediation and intervention information
• Case status and follow-up details
• Sector and classification information
• Payment and transaction-related fields

The dataset is advertised in JSON format at roughly 109MB, with a sample published alongside the post.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️🇫🇷 An actor claims to be selling access to Ameli Pro, the French health insurance system, allowing lookup of personal information tied to individuals social security numbers.

The post includes purported proof images and a Telegram contact for sale negotiations.
🚨🇫🇷 BlgCloud breach allegedly exposes data from more than 150 companies

A forum actor claims to have breached BlgCloud, a French cloud-based ERP and business management platform used by equipment dealers, rental companies, repair businesses and wholesalers.

The actor claims BlgCloud operates roughly 230 customer instances and that access was obtained to approximately 159 of them.

The compromised data allegedly includes:

• Customer and company CRM records
• Business contact information
• Email archives and attachments
• Invoices and commercial documents
• Banking information, including IBAN and BIC fields
• Customer addresses and phone numbers
• Company registration and legal information
• Internal account and user information
• Administrative credentials and configuration data
• Millions of documents across multiple customer environments

The actor published CRM, email and document samples alongside the post and claims both individual company datasets and the underlying access method are being offered for sale. The group also says it plans to release data from one affected company for free each day.

The listing describes the total exposure as potentially reaching terabytes of data across the affected BlgCloud customers.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Pokémon Center vending machine data and broader retail SaaS infrastructure allegedly breached

A forum actor claims to have breached a US-based automated retail SaaS platform used to operate more than 217 smart vending machines and kiosks across 28 brands, including 66 Pokémon Center vending machines. The claim appears to target the underlying SwyftStore / Zoom Systems infrastructure rather than Pokémon directly.

The actor claims the exposed environment includes:

• 206,092 unique email addresses
• 70,546 payment card hashes
• 59,797 customer receipts containing masked card numbers
• 8,545 sales transactions with amounts and purchased products
• 217 vending machine locations with inventory and planogram data
• 66 Pokémon Center vending machines
• Customer and administrator PII
• Session and activity logs
• API credentials and backend reporting access
• Firebase databases, storage buckets and related cloud infrastructure
• Source code from three production applications
• 229 original source files
• Product catalogs, pricing, UPCs and SKU information

The actor claims the affected platform serves 28 brands, with records referencing Pokémon Company International, CVS Pharmacy, Best Buy, Disney, Google, Dollar Shave Club, Juul, Sennheiser, Vera Bradley, Nespresso and others.

A 1,000-record sample was published alongside the post. The actor is asking $3,000 for the full collection and claims some of the affected cloud services remained accessible when the listing was published.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️🇨🇦 An actor is offering for sale super admin level SSH/Fortigate access to 89 hosts belonging to a Canadian business services company with reported revenue of $50M.
🚨 WARDEN Stealer MaaS advertised with 360+ targets, browser theft, crypto grabbing and loader capabilities

A threat actor is advertising WARDEN, a malware-as-a-service platform combining an information stealer, grabber, crypto clipper and loader into a single Windows payload reportedly around 350KB in size.

The advertised capabilities include:

• Chromium and Gecko browser data theft across multiple profiles
• Passwords, cookies and active session cookies
• Stored payment cards, including cardholder and billing information
• Google OAuth tokens collected from Chromium-based browsers
• Autofill data, browsing history and search history
• More than 200 cryptocurrency wallet extensions
• More than 360 targeted applications across 13 categories
• Cryptocurrency wallets and related applications
• Messaging, email and gaming clients
• Password managers and 2FA applications
• VPN, FTP, RDP and VNC software
• Cloud, trading, notes and other applications
• Custom file and Windows Registry collection
• System information and desktop screenshots
• BTC, ETH, TRX, XMR, SOL and TON clipboard replacement
• Additional payload execution through an integrated loader

WARDEN also advertises infrastructure and evasion features including encrypted data transfer, segmented log delivery, duplicate filtering, automatic gateway failover, anti-VM checks and a code morphing system designed to alter builds between deployments.

The operator claims the platform includes a web panel with live log tracking, filtering, markers for high-value accounts, dashboards, Telegram notifications, configurable builds, statistics sharing and an API for higher-tier customers.

Three subscription tiers are advertised:

• Test: $90 per week
• Personal: $349 per month
• Premium: $499 per month

The Premium tier advertises increased build, gateway and log limits along with API access and priority builds. The seller also states that the malware is not intended to operate in CIS or Baltic countries.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing