πŸ”ͺ Slice For Life - Part 2 πŸ”ͺ
4.3K subscribers
807 photos
37 videos
744 links
Download Telegram
🚨 Experienced penetration testers recruited for corporate network intrusions on a cybercrime forum
β €
A forum actor is recruiting experienced operators for what they describe as ongoing work targeting corporate networks. The poster says this is intended to be long-term cooperation with a regular workload and payment based on successfully completed operations.
β €
The advertised skills and responsibilities include:
β €
β€’ Network reconnaissance and mapping
β€’ Discovery of hosts, ports and exposed services
β€’ Enumeration of SMB shares, NAS and file servers
β€’ Active Directory reconnaissance
β€’ Identification of domain controllers, trusts and hidden network segments
β€’ Privilege escalation from local user to Domain Admin
β€’ Kerberoasting and AS-REP Roasting
β€’ DCSync, Pass-the-Hash and Pass-the-Ticket
β€’ Golden Ticket and Silver Ticket techniques
β€’ Active Directory ACL abuse
β€’ AD CS exploitation, including ESC1 through ESC8
β€’ Lateral movement through WMI, PSRemoting, SMB, RDP and WinRM
β€’ EDR and antivirus evasion
β€’ Experience with CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, Sophos and Bitdefender
β€’ Data exfiltration from corporate file shares and servers
β€’ Identification and prioritization of financial, legal and personal data
β€’ Classification of stolen data for GDPR, CCPA, HIPAA and other regulatory exposure
β €
The poster claims recruits will receive access to an internal C2 environment and an AI-based system for analyzing stolen data. Payment is advertised in XMR, USDT or USDC after each completed stage, with the possibility of progressing to a team lead role receiving a percentage of profits.
β €
Applicants are expected to complete a test using a GOAD Active Directory lab before being assigned a live operation. The poster specifically states that inexperienced applicants and people with only course-based training are not being sought.
β €
The poster's claims and the nature of the advertised operation have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡ΊπŸ‡Έ Threat actor advertising interest in purchasing U.S. e-commerce web shells and administrative access
β €
A cybercrime forum user operating under the name "Atlantic Service" is advertising an ongoing effort to purchase compromised access targeting the U.S. market, with a particular focus on e-commerce and retail environments.
β €
The buyer is specifically seeking:
β €
β€’ Web shells on e-commerce and retail websites
β€’ Logs and administrative panel access
β€’ Recently compromised systems
β€’ Targets with high levels of U.S. traffic
β€’ Large online stores and retail platforms
β €
The poster says priority will be given to large stores, high-traffic targets and recently obtained access. The advertisement describes the operation as a serious purchasing effort and states that only currently active access is wanted.
β €
The poster's claims and the availability of the advertised access have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 This is at least the 3rd one I've seen since the recent disclosure.

🚨 Trezor customer data allegedly exposed through ShipMonk breach, 11,742 records advertised for sale
β €
A cybercrime forum seller is advertising customer data allegedly connected to Trezor, claiming the information was exposed through a breach involving shipping provider ShipMonk. The listing says 11,742 customers are affected across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
β €
The advertised data includes:
β €
β€’ Customer names and surnames
β€’ Email addresses
β€’ Phone numbers
β€’ Shipping addresses
β€’ Cities, regions and postal codes
β€’ Country information
β€’ Checkout IDs
β€’ Order timestamps
β€’ Order contents and quantities
β€’ Currency and total purchase price
β €
The seller claims the affected records relate to customers who placed orders within the 90 days preceding August 8, 2026. Sample entries shown in the listing include Trezor Model T purchases and associated customer and shipping information.
β €
The dataset is being advertised for $10,000.
β €
The seller's claims and the authenticity, source and scope of the advertised data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸ”ͺ Slice For Life - Part 2 πŸ”ͺ
Added to the scwapper - 27 forums monitored.
https://updap[.]com:7080/login.php
206[.]168[.]149[.]26

ASN: 26042 πŸ‡ΊπŸ‡Έ
Org: FiberState, LLC
😭2😁1
‼️ xpl0itrs Leak Site

IOC: http://2kieaq6jnwgrru62wwtxaafg35q6rzweg7y2xjfnbhvq5wd4eojqv6yd[.]onion
❀3
πŸš¨πŸ‡ΊπŸ‡Έ TaxAct user dataset allegedly leaked on a cybercrime forum, 450,000 accounts exposed
β €
A forum user claims to have obtained and released a 115 MB dataset containing 450,000 TaxAct user accounts. The poster alleges the data came from a user-account backend and lists the dump date as August 15, 2026.
β €
The advertised dataset includes:
β €
β€’ 450,000 usernames
β€’ 449,996 unique email addresses
β€’ 347,293 unique U.S. phone numbers
β€’ 357,221 email and phone pairs
β€’ Account status information
β€’ Email and phone verification flags
β€’ Last sign-in fields
β€’ Internal campaign IDs
β€’ Dummy phone number indicators
β €
The seller says 146,651 usernames were automatically generated from email addresses. According to the listing, the dump does not contain passwords, Social Security numbers, tax returns or financial information.
β €
The poster claims the dataset was obtained through a broader "CredHarvester V6" pipeline and provided samples of individual account records, phone number distributions and email domains.
β €
The poster's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡ΊπŸ‡Έ McDonald’s internal employee dataset allegedly stolen from Azure tenant, 1.7M+ records advertised on a cybercrime forum
β €
A forum seller claims to be offering an internal McDonald’s Corporation employee dataset allegedly downloaded directly from an Azure tenant using compromised credentials. The seller says the dump contains more than 1.7 million records.
β €
The advertised data includes:
β €
β€’ Full names
β€’ Employee IDs
β€’ Email addresses
β€’ Job titles
β€’ Departments
β€’ Phone numbers
β€’ Physical addresses
β€’ Employee account records
β€’ Service account records
β€’ Other tenant account information
β €
The seller has published a sample containing approximately 8,000 records and is asking interested buyers to submit offers. The poster also claims to possess additional company datasets available for sale.
β €
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
😭3πŸ”₯1
πŸš¨πŸ‡«πŸ‡· FranceCasse customer and order dataset allegedly scraped and leaked on a cybercrime forum
β €
A forum user claims to have released a newly obtained dataset from FranceCasse, a French automotive parts platform. The poster says the data was scraped during August 2026 and published samples from multiple files containing customer, address, order and product information.
β €
The advertised data includes:
β €
β€’ Customer names and usernames
β€’ Email addresses
β€’ Physical addresses and postal codes
β€’ Customer account information
β€’ Hashed passwords
β€’ Order and cart identifiers
β€’ Invoice and delivery information
β€’ Payment method fields
β€’ Order totals and shipping costs
β€’ Product IDs and descriptions
β€’ Product pricing and inventory information
β€’ Vehicle and automotive part information
β€’ Manufacturer and supplier fields
β€’ Customer and delivery address records
β €
The forum post includes samples from files identified as addresses.csv, customers.csv, orders.jsonl and products.jsonl, with the full FranceCasse dataset placed behind hidden forum content.
β €
The poster's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡«πŸ‡· Cravero Motoculture dataset allegedly leaked on a cybercrime forum
β €
A forum user claims to have leaked a database allegedly belonging to Cravero Motoculture, a French agricultural and outdoor equipment business. The post is labeled as part of the actor's "BlgCloud Leak" series.
β €
The advertised leak reportedly contains approximately 3.7 GB of data across 49,168 files.
β €
The exposed data shown in the samples includes:
β €
β€’ Customer and CRM records
β€’ Contact names
β€’ Email addresses
β€’ Phone numbers
β€’ Physical addresses
β€’ Company and account information
β€’ Customer and supplier references
β€’ Billing and invoicing fields
β€’ Commercial document metadata
β€’ PDF sales proposals and other documents
β€’ File names, hashes and storage paths
β€’ Internal record and attachment identifiers
β €
The poster's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡ΊπŸ‡Έ Gap Inc. internal employee dataset allegedly stolen from Azure tenant, 80K+ records advertised on a cybercrime forum
β €
A forum seller claims to be offering an internal Gap Inc. employee dataset allegedly downloaded directly from an Azure tenant using compromised credentials. The seller says the dataset contains more than 80,000 records.
β €
The advertised data includes:
β €
β€’ Full names
β€’ Employee IDs
β€’ Email addresses
β€’ Job titles
β€’ Departments
β€’ Phone numbers
β€’ Physical addresses
β€’ Employee account records
β€’ Service account records
β€’ Other Azure tenant account information
β €
The seller has published a sample containing approximately 1,000 records and is asking interested buyers to submit offers. The poster also claims to possess additional company datasets available for sale.
β €
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀2
πŸš¨πŸ‡°πŸ‡· South Korea National Health Insurance Service dataset allegedly leaked on a cybercrime forum, 48M records advertised for sale
β €
A forum seller claims to be offering a dataset allegedly containing personal and health insurance-related information from South Korea's National Health Insurance Service (NHIS). The seller says the dataset contains approximately 48 million records.
β €
The advertised data includes:
β €
β€’ Names
β€’ Resident registration numbers
β€’ Gender and dates of birth
β€’ Ages
β€’ Insurance types
β€’ Subscriber classifications
β€’ Employer information
β€’ Household identifiers
β€’ Monthly income information
β€’ Monthly insurance premiums
β€’ Premium share information
β€’ Number of dependents
β€’ Regional information
β€’ Insurance acquisition dates
β€’ Last health checkup dates
β€’ Long-term care grades
β€’ Payment arrears status
β€’ Card status
β€’ Data export dates
β €
The seller is asking $450 for the dataset and has published sample records in the forum listing.
β €
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Two corporate network accesses advertised for sale on a cybercrime forum
β €
A forum seller is advertising access to two companies operating in the business services sector, including one U.S. organization and another described only as being located in the Americas.
β €
The first advertised access includes:
β €
β€’ Approximately $500M in reported revenue
β€’ VPN and RDP access
β€’ Domain Admin privileges
β€’ Windows Defender environment
β€’ Approximately 500 hosts
β€’ 226 domain-joined machines
β€’ 2 domain controllers
β€’ More than 1 TB of data
β€’ Asking price of $2,000
β €
The second advertised access includes:
β €
β€’ Approximately $10M in reported revenue
β€’ VPN access
β€’ Standard VPN user privileges
β€’ Approximately 120 hosts
β€’ 64 domain-joined machines
β€’ 4 domain controllers
β€’ 8 Microsoft SQL Server systems
β€’ Veeam infrastructure identified
β€’ Asking price of $200
β €
The seller's claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Have I Been Flocked allows you to search your license plate to see if it has been scanned.

https://haveibeenflocked.com/
🚨 SafePal customer order data allegedly advertised for sale on a cybercrime forum
β €
A forum seller is advertising customer information allegedly connected to a SafePal order plugin data breach. The poster claims the affected records relate to customers who placed orders between March 2, 2025 and April 11, 2026.
β €
The advertised data includes:
β €
β€’ Customer names
β€’ Email addresses
β€’ Shipping addresses
β€’ Phone numbers
β€’ Purchase and order details
β€’ Country information
β €
The seller claims approximately 39,798 customers were affected and says prospective buyers can be provided with order and country information to verify records against SafePal's customer notification system.
β €
The listing also references SafePal's published security update concerning unauthorized access to customer order information.
β €
The seller's claims and the authenticity, source and scope of the advertised data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1