🚨🇬🇧 Businessmad.com dataset allegedly breached, 1.19M records advertised for sale on a cybercrime forum
⠀
A forum seller claims to be offering a database allegedly obtained from Businessmad.com, containing 1,199,359 records. The seller dates the dataset to July 2026 and also claims the sale includes Stripe-related keys and live access.
⠀
The advertised data includes:
⠀
• Names and email addresses
• Phone numbers
• Physical addresses and postal codes
• Company names and registration numbers
• Employee and employment information
• Job titles, professions and work experience
• Account usernames and password fields
• Login and signup information
• Geographic coordinates and location data
• Social media profiles and identifiers
• Website and business listing information
• Subscription information
• Customer consent and verification fields
• Invoice payment totals
• Past-due and refunded invoice totals
• Turnover ranges
• Internal IDs, tokens and credential fields
⠀
The seller is asking $1,000 for the dataset.
⠀
The seller's claims and the authenticity, source and scope of the allegedly exposed data and access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum seller claims to be offering a database allegedly obtained from Businessmad.com, containing 1,199,359 records. The seller dates the dataset to July 2026 and also claims the sale includes Stripe-related keys and live access.
⠀
The advertised data includes:
⠀
• Names and email addresses
• Phone numbers
• Physical addresses and postal codes
• Company names and registration numbers
• Employee and employment information
• Job titles, professions and work experience
• Account usernames and password fields
• Login and signup information
• Geographic coordinates and location data
• Social media profiles and identifiers
• Website and business listing information
• Subscription information
• Customer consent and verification fields
• Invoice payment totals
• Past-due and refunded invoice totals
• Turnover ranges
• Internal IDs, tokens and credential fields
⠀
The seller is asking $1,000 for the dataset.
⠀
The seller's claims and the authenticity, source and scope of the allegedly exposed data and access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: Web3 Casino Intraverse Allegedly Exposed by a Keyless Firebase Database, Including Its Own House Bot Stack
Link: https://darkwebinformer.com/web3-casino-intraverse-allegedly-exposed-by-a-keyless-firebase-database-including-its-own-house-bot-stack/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Web3 Casino Intraverse Allegedly Exposed by a Keyless Firebase Database, Including Its Own House Bot Stack
Link: https://darkwebinformer.com/web3-casino-intraverse-allegedly-exposed-by-a-keyless-firebase-database-including-its-own-house-bot-stack/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Web3 Casino Intraverse Allegedly Exposed by a Keyless Firebase Database, Including Its Own House Bot Stack
A forum user posting as exfilar has published what they describe as the full production Realtime Database behind intraverse.io, the Intraverse/Gamifi web3 gambling platform, totalling 16,898,017 database leaves across roughly 518MB of JSON.
‼️ New Dark Web Informer Blog Post!
Title: Serbian National Health Insurance Databases Allegedly Published Across Multiple File Mirrors
Link: https://darkwebinformer.com/serbian-national-health-insurance-databases-allegedly-published-across-multiple-file-mirrors/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Serbian National Health Insurance Databases Allegedly Published Across Multiple File Mirrors
Link: https://darkwebinformer.com/serbian-national-health-insurance-databases-allegedly-published-across-multiple-file-mirrors/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Serbian National Health Insurance Databases Allegedly Published Across Multiple File Mirrors
A forum user posting as bytetobreach claims to hold databases belonging to RFZO, the Republic Fund for Health Insurance of Serbia, and has posted links to the material across five separate file hosting services.
‼️ New Dark Web Informer Blog Post!
Title: Kenyan Recruitment Platform Snapstartalent Allegedly Dumped With National IDs, Resumes and Recorded Video Interviews
Link: https://darkwebinformer.com/kenyan-recruitment-platform-snapstartalent-allegedly-dumped-with-national-ids-resumes-and-recorded-video-interviews/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Kenyan Recruitment Platform Snapstartalent Allegedly Dumped With National IDs, Resumes and Recorded Video Interviews
Link: https://darkwebinformer.com/kenyan-recruitment-platform-snapstartalent-allegedly-dumped-with-national-ids-resumes-and-recorded-video-interviews/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Kenyan Recruitment Platform Snapstartalent Allegedly Dumped With National IDs, Resumes and Recorded Video Interviews
A forum user posting as exfilar is offering what they describe as a live extraction of the production backend behind Snapstartalent.com, a Kenyan recruitment platform, comprising 176,795 database records and 249GB of downloaded files.
Media is too big
VIEW IN TELEGRAM
‼️ Detection Artifact Generator for Citrix NetScaler CVE-2026-8452
GitHub: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
Writeup: https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
GitHub: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
Writeup: https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
Tick tock. Tick tock. Another shitty forum is on the IP leak clock.
People ask, why leak an illegal forum’s IP? Why not just tell the operator and get paid? Because “getting paid by the operator of an illegal forum” sounds like the kind of sentence that gets read back to you in court. I like touching grass every once and awhile... not never.
😭4
IP Information for 188.93.233.227
ASN: 47674
ISP / Org: NETSOLUTIONS - Net Solutions - Consultoria Em Tecnologias De Informacao, Sociedade Unipessoal LDA, MO
Country: PT
Network Range: 188.93.233.0/24
ASN: 47674
ISP / Org: NETSOLUTIONS - Net Solutions - Consultoria Em Tecnologias De Informacao, Sociedade Unipessoal LDA, MO
Country: PT
Network Range: 188.93.233.0/24
WHOIS for cardvilla.cc
Domain: CARDVILLA.CC
Registered On: 2019-04-04 12:32:01 UTC
Expires On: 2027-04-04 12:32:01 UTC
Updated On: 2026-02-01 14:21:15 UTC
Status:
clientTransferProhibited
Name Servers:
CLYDE.NS.CLOUDFLARE.COM
KARINA.NS.CLOUDFLARE.COM
Registrar: Eranet International Limited
IANA ID: 1868
URL: Not Available
Abuse Email: cs@eranet.com
Abuse Phone: +85239995400
Domain: CARDVILLA.CC
Registered On: 2019-04-04 12:32:01 UTC
Expires On: 2027-04-04 12:32:01 UTC
Updated On: 2026-02-01 14:21:15 UTC
Status:
clientTransferProhibited
Name Servers:
CLYDE.NS.CLOUDFLARE.COM
KARINA.NS.CLOUDFLARE.COM
Registrar: Eranet International Limited
IANA ID: 1868
URL: Not Available
Abuse Email: cs@eranet.com
Abuse Phone: +85239995400
‼️🇦🇺 A forum actor is selling a dataset allegedly containing 436,000 records from the Australian government domain dfat.gov.au for $200.
Media is too big
VIEW IN TELEGRAM
🚨‼️The Darkest Web: Inside the internet’s most hidden corners to save kids
THIS DOCUMENTARY DEALS WITH CHILD SEXUAL ABUSE AND CONTAINS SCENES WHICH VIEWERS MAY FIND DISTURBING.
An extraordinary global team of undercover officers takes on a nearly impossible mission: infiltrating the darkest corners of the internet to rescue vulnerable children and bring hope where it once seemed impossible.
Credit: youtube.com/BBC
THIS DOCUMENTARY DEALS WITH CHILD SEXUAL ABUSE AND CONTAINS SCENES WHICH VIEWERS MAY FIND DISTURBING.
An extraordinary global team of undercover officers takes on a nearly impossible mission: infiltrating the darkest corners of the internet to rescue vulnerable children and bring hope where it once seemed impossible.
Credit: youtube.com/BBC
❤3
🔪 Slice For Life - Part 2 🔪
🚨🇺🇸 McDonald’s internal employee dataset allegedly stolen from Azure tenant, 1.7M+ records advertised on a cybercrime forum ⠀ A forum seller claims to be offering an internal McDonald’s Corporation employee dataset allegedly downloaded directly from an Azure…
https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
This is why I stopped listening to people about claims... if I don't post it someone else will and then people come at me for not posting it. Lul
This is why I stopped listening to people about claims... if I don't post it someone else will and then people come at me for not posting it. Lul
BleepingComputer
Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.
‼️ New Dark Web Informer Blog Post!
Title: Bolivian Departmental Government Allegedly Breached, Exposing Food Handler Medical Records and ID Photographs
Link: https://darkwebinformer.com/bolivian-departmental-government-allegedly-breached-exposing-food-handler-medical-records-and-id-photographs/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Bolivian Departmental Government Allegedly Breached, Exposing Food Handler Medical Records and ID Photographs
Link: https://darkwebinformer.com/bolivian-departmental-government-allegedly-breached-exposing-food-handler-medical-records-and-id-photographs/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Bolivian Departmental Government Allegedly Breached, Exposing Food Handler Medical Records and ID Photographs
A forum user posting as konata_izumi_shell claims to have breached INOCUIDAD, the food safety and sanitary control system operated by the Autonomous Departmental Government of Santa Cruz in Bolivia, and has published the data for free download.
‼️ New Dark Web Informer Blog Post!
Title: French Ministry of Education Allegedly Breached, With Staff Directories and Student Monitoring Records Offered for Sale
Link: https://darkwebinformer.com/french-ministry-of-education-allegedly-breached-with-staff-directories-and-student-monitoring-records-offered-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: French Ministry of Education Allegedly Breached, With Staff Directories and Student Monitoring Records Offered for Sale
Link: https://darkwebinformer.com/french-ministry-of-education-allegedly-breached-with-staff-directories-and-student-monitoring-records-offered-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
French Ministry of Education Allegedly Breached, With Staff Directories and Student Monitoring Records Offered for Sale
A forum user posting as ZeroBytes claims to have breached Éducation Nationale, the French national education ministry, and is selling what they describe as a partial database totalling 346,178,591 raw lines across three folders.
🔪 Slice For Life - Part 2 🔪
‼️ New Dark Web Informer Blog Post! Title: French Ministry of Education Allegedly Breached, With Staff Directories and Student Monitoring Records Offered for Sale Link: https://darkwebinformer.com/french-ministry-of-education-allegedly-breached-with-staff…
Oh rip, I missed the X account as part of the TG post: X: ZeroBytesG
🔪 Slice For Life - Part 2 🔪
An "entity" has been working with me for awhile now. They wish to have access to Doxxing websites and similarly be alerted with new pastes. Kind of like the forum alerts. I have always declined this, but I'm always open to changing things and having an open…
I think it's time to start providing resources to this since "OSINT" is blowing up.
Send me any website you know about related to doxxing via https://darkwebinformer.com/tips/. It can be the common doxbin or something that really hasn't been talked about. Assume that I'm a dummy and haven't heard of it yet. I'm building this along side a Bulletproof Hosting resource. Both of which will be in the Threat Surface Sources subscribers section.
You do not need to provide an email address. All links are defanged automatically when sent back to me. I am still thinking about how a "doxxing" feed could be done while staying legal.
Edit: 10 so far
Send me any website you know about related to doxxing via https://darkwebinformer.com/tips/. It can be the common doxbin or something that really hasn't been talked about. Assume that I'm a dummy and haven't heard of it yet. I'm building this along side a Bulletproof Hosting resource. Both of which will be in the Threat Surface Sources subscribers section.
You do not need to provide an email address. All links are defanged automatically when sent back to me. I am still thinking about how a "doxxing" feed could be done while staying legal.
Edit: 10 so far
Dark Web Informer
Submit a Tip | Dark Web Informer
Seen a breach, leak, ransomware activity, or threat actor worth flagging? Send Dark Web Informer a tip. No account or name required, and you can stay anonymous.