🚨🇮🇱 Israel Population and Immigration Authority database allegedly breached
⠀
A forum actor claims to have breached Israel’s Population and Immigration Authority and obtained a 2026 population database containing 9,220,583 records.
⠀
The exposed data allegedly includes:
⠀
• Israeli identification numbers
• First, last and former names
• Gender and marital status
• Full residential addresses
• Phone numbers
• Dates and countries of birth
• Immigration and Aliyah dates
• Death dates and status information
• Parents’ names and identification numbers
• Spouse and family identifiers
• Children and household relationship data
• Additional internal notes and record metadata
⠀
The actor published a 100,000-record sample as proof and claims the complete database is approximately 7.5GB in size. The post also highlights records purportedly associated with prominent Israeli figures.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
A forum actor claims to have breached Israel’s Population and Immigration Authority and obtained a 2026 population database containing 9,220,583 records.
⠀
The exposed data allegedly includes:
⠀
• Israeli identification numbers
• First, last and former names
• Gender and marital status
• Full residential addresses
• Phone numbers
• Dates and countries of birth
• Immigration and Aliyah dates
• Death dates and status information
• Parents’ names and identification numbers
• Spouse and family identifiers
• Children and household relationship data
• Additional internal notes and record metadata
⠀
The actor published a 100,000-record sample as proof and claims the complete database is approximately 7.5GB in size. The post also highlights records purportedly associated with prominent Israeli figures.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🔥1
🔪 Slice For Life - Part 2 🔪
An "entity" has been working with me for awhile now. They wish to have access to Doxxing websites and similarly be alerted with new pastes. Kind of like the forum alerts. I have always declined this, but I'm always open to changing things and having an open…
This is a legal entity btw, not an actor.
I have added 3 new incidents to the Physical Bitcoin Attacks page.
https://darkwebinformer.com/physical-bitcoin-attacks/
https://darkwebinformer.com/physical-bitcoin-attacks/
Dark Web Informer
Physical Bitcoin Attacks
A comprehensive database of known physical attacks against Bitcoin and crypto asset holders occurring in meatspace.
🚨🇫🇷 Roussel Agri 62 email, CRM and business documents allegedly leaked
⠀
A forum actor claims to have leaked data belonging to Roussel Agri 62, a French agricultural business. The post is described as the first in a series of alleged leaks connected to BlgCloud.
⠀
The advertised collection includes:
⠀
• 9.33GB of data
• 45,684 files
• 29,127 emails
• 23,816 CRM records
• 45,681 business documents
• Customer and business contact information
• Names, email addresses and phone numbers
• Postal and company addresses
• CRM relationship and account data
• Banking details, including IBAN information
• Orders, invoices and other commercial documents
⠀
The actor published email, CRM and document samples alongside the post.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to have leaked data belonging to Roussel Agri 62, a French agricultural business. The post is described as the first in a series of alleged leaks connected to BlgCloud.
⠀
The advertised collection includes:
⠀
• 9.33GB of data
• 45,684 files
• 29,127 emails
• 23,816 CRM records
• 45,681 business documents
• Customer and business contact information
• Names, email addresses and phone numbers
• Postal and company addresses
• CRM relationship and account data
• Banking details, including IBAN information
• Orders, invoices and other commercial documents
⠀
The actor published email, CRM and document samples alongside the post.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 CLCV consumer association database allegedly leaked
⠀
A forum actor claims to have leaked approximately 80,031 records associated with CLCV, a French national consumer and user advocacy organization.
⠀
The exposed data allegedly includes:
⠀
• Names and contact information
• Email addresses and phone numbers
• Postal addresses and cities
• Membership numbers
• Consumer request and complaint details
• Housing-related inquiries
• Mediation and intervention information
• Case status and follow-up details
• Sector and classification information
• Payment and transaction-related fields
⠀
The dataset is advertised in JSON format at roughly 109MB, with a sample published alongside the post.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to have leaked approximately 80,031 records associated with CLCV, a French national consumer and user advocacy organization.
⠀
The exposed data allegedly includes:
⠀
• Names and contact information
• Email addresses and phone numbers
• Postal addresses and cities
• Membership numbers
• Consumer request and complaint details
• Housing-related inquiries
• Mediation and intervention information
• Case status and follow-up details
• Sector and classification information
• Payment and transaction-related fields
⠀
The dataset is advertised in JSON format at roughly 109MB, with a sample published alongside the post.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 BlgCloud breach allegedly exposes data from more than 150 companies
⠀
A forum actor claims to have breached BlgCloud, a French cloud-based ERP and business management platform used by equipment dealers, rental companies, repair businesses and wholesalers.
⠀
The actor claims BlgCloud operates roughly 230 customer instances and that access was obtained to approximately 159 of them.
⠀
The compromised data allegedly includes:
⠀
• Customer and company CRM records
• Business contact information
• Email archives and attachments
• Invoices and commercial documents
• Banking information, including IBAN and BIC fields
• Customer addresses and phone numbers
• Company registration and legal information
• Internal account and user information
• Administrative credentials and configuration data
• Millions of documents across multiple customer environments
⠀
The actor published CRM, email and document samples alongside the post and claims both individual company datasets and the underlying access method are being offered for sale. The group also says it plans to release data from one affected company for free each day.
⠀
The listing describes the total exposure as potentially reaching terabytes of data across the affected BlgCloud customers.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to have breached BlgCloud, a French cloud-based ERP and business management platform used by equipment dealers, rental companies, repair businesses and wholesalers.
⠀
The actor claims BlgCloud operates roughly 230 customer instances and that access was obtained to approximately 159 of them.
⠀
The compromised data allegedly includes:
⠀
• Customer and company CRM records
• Business contact information
• Email archives and attachments
• Invoices and commercial documents
• Banking information, including IBAN and BIC fields
• Customer addresses and phone numbers
• Company registration and legal information
• Internal account and user information
• Administrative credentials and configuration data
• Millions of documents across multiple customer environments
⠀
The actor published CRM, email and document samples alongside the post and claims both individual company datasets and the underlying access method are being offered for sale. The group also says it plans to release data from one affected company for free each day.
⠀
The listing describes the total exposure as potentially reaching terabytes of data across the affected BlgCloud customers.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Pokémon Center vending machine data and broader retail SaaS infrastructure allegedly breached
⠀
A forum actor claims to have breached a US-based automated retail SaaS platform used to operate more than 217 smart vending machines and kiosks across 28 brands, including 66 Pokémon Center vending machines. The claim appears to target the underlying SwyftStore / Zoom Systems infrastructure rather than Pokémon directly.
⠀
The actor claims the exposed environment includes:
⠀
• 206,092 unique email addresses
• 70,546 payment card hashes
• 59,797 customer receipts containing masked card numbers
• 8,545 sales transactions with amounts and purchased products
• 217 vending machine locations with inventory and planogram data
• 66 Pokémon Center vending machines
• Customer and administrator PII
• Session and activity logs
• API credentials and backend reporting access
• Firebase databases, storage buckets and related cloud infrastructure
• Source code from three production applications
• 229 original source files
• Product catalogs, pricing, UPCs and SKU information
⠀
The actor claims the affected platform serves 28 brands, with records referencing Pokémon Company International, CVS Pharmacy, Best Buy, Disney, Google, Dollar Shave Club, Juul, Sennheiser, Vera Bradley, Nespresso and others.
⠀
A 1,000-record sample was published alongside the post. The actor is asking $3,000 for the full collection and claims some of the affected cloud services remained accessible when the listing was published.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to have breached a US-based automated retail SaaS platform used to operate more than 217 smart vending machines and kiosks across 28 brands, including 66 Pokémon Center vending machines. The claim appears to target the underlying SwyftStore / Zoom Systems infrastructure rather than Pokémon directly.
⠀
The actor claims the exposed environment includes:
⠀
• 206,092 unique email addresses
• 70,546 payment card hashes
• 59,797 customer receipts containing masked card numbers
• 8,545 sales transactions with amounts and purchased products
• 217 vending machine locations with inventory and planogram data
• 66 Pokémon Center vending machines
• Customer and administrator PII
• Session and activity logs
• API credentials and backend reporting access
• Firebase databases, storage buckets and related cloud infrastructure
• Source code from three production applications
• 229 original source files
• Product catalogs, pricing, UPCs and SKU information
⠀
The actor claims the affected platform serves 28 brands, with records referencing Pokémon Company International, CVS Pharmacy, Best Buy, Disney, Google, Dollar Shave Club, Juul, Sennheiser, Vera Bradley, Nespresso and others.
⠀
A 1,000-record sample was published alongside the post. The actor is asking $3,000 for the full collection and claims some of the affected cloud services remained accessible when the listing was published.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 WARDEN Stealer MaaS advertised with 360+ targets, browser theft, crypto grabbing and loader capabilities
⠀
A threat actor is advertising WARDEN, a malware-as-a-service platform combining an information stealer, grabber, crypto clipper and loader into a single Windows payload reportedly around 350KB in size.
⠀
The advertised capabilities include:
⠀
• Chromium and Gecko browser data theft across multiple profiles
• Passwords, cookies and active session cookies
• Stored payment cards, including cardholder and billing information
• Google OAuth tokens collected from Chromium-based browsers
• Autofill data, browsing history and search history
• More than 200 cryptocurrency wallet extensions
• More than 360 targeted applications across 13 categories
• Cryptocurrency wallets and related applications
• Messaging, email and gaming clients
• Password managers and 2FA applications
• VPN, FTP, RDP and VNC software
• Cloud, trading, notes and other applications
• Custom file and Windows Registry collection
• System information and desktop screenshots
• BTC, ETH, TRX, XMR, SOL and TON clipboard replacement
• Additional payload execution through an integrated loader
⠀
WARDEN also advertises infrastructure and evasion features including encrypted data transfer, segmented log delivery, duplicate filtering, automatic gateway failover, anti-VM checks and a code morphing system designed to alter builds between deployments.
⠀
The operator claims the platform includes a web panel with live log tracking, filtering, markers for high-value accounts, dashboards, Telegram notifications, configurable builds, statistics sharing and an API for higher-tier customers.
⠀
Three subscription tiers are advertised:
⠀
• Test: $90 per week
• Personal: $349 per month
• Premium: $499 per month
⠀
The Premium tier advertises increased build, gateway and log limits along with API access and priority builds. The seller also states that the malware is not intended to operate in CIS or Baltic countries.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A threat actor is advertising WARDEN, a malware-as-a-service platform combining an information stealer, grabber, crypto clipper and loader into a single Windows payload reportedly around 350KB in size.
⠀
The advertised capabilities include:
⠀
• Chromium and Gecko browser data theft across multiple profiles
• Passwords, cookies and active session cookies
• Stored payment cards, including cardholder and billing information
• Google OAuth tokens collected from Chromium-based browsers
• Autofill data, browsing history and search history
• More than 200 cryptocurrency wallet extensions
• More than 360 targeted applications across 13 categories
• Cryptocurrency wallets and related applications
• Messaging, email and gaming clients
• Password managers and 2FA applications
• VPN, FTP, RDP and VNC software
• Cloud, trading, notes and other applications
• Custom file and Windows Registry collection
• System information and desktop screenshots
• BTC, ETH, TRX, XMR, SOL and TON clipboard replacement
• Additional payload execution through an integrated loader
⠀
WARDEN also advertises infrastructure and evasion features including encrypted data transfer, segmented log delivery, duplicate filtering, automatic gateway failover, anti-VM checks and a code morphing system designed to alter builds between deployments.
⠀
The operator claims the platform includes a web panel with live log tracking, filtering, markers for high-value accounts, dashboards, Telegram notifications, configurable builds, statistics sharing and an API for higher-tier customers.
⠀
Three subscription tiers are advertised:
⠀
• Test: $90 per week
• Personal: $349 per month
• Premium: $499 per month
⠀
The Premium tier advertises increased build, gateway and log limits along with API access and priority builds. The seller also states that the malware is not intended to operate in CIS or Baltic countries.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Access to unidentified top 10 Asian telecom allegedly offered for sale
⠀
A forum actor claims to be selling access to a large, publicly traded telecommunications company in Asia with approximately $4 billion in annual revenue.
⠀
The advertised access allegedly includes:
⠀
• SSH access
• Corporate VPN access
• Load balancer access
• Access to a large internal network
• Network mapping information
⠀
The seller describes the victim as a top 10 telecommunications company in Asia and is asking $500 for the access.
⠀
The affected company was not publicly identified in the listing.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling access to a large, publicly traded telecommunications company in Asia with approximately $4 billion in annual revenue.
⠀
The advertised access allegedly includes:
⠀
• SSH access
• Corporate VPN access
• Load balancer access
• Access to a large internal network
• Network mapping information
⠀
The seller describes the victim as a top 10 telecommunications company in Asia and is asking $500 for the access.
⠀
The affected company was not publicly identified in the listing.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing