π¨π¦π· Access to an Argentine municipal government system advertised for sale on a cybercrime forum
β
A forum seller claims to be offering access to an Argentine municipal government system, including administrative infrastructure, cloud resources and internal data.
β
The advertised access includes:
β
β’ Administrative panel access
β’ Government Gmail SMTP access
β’ AWS storage keys
β’ MySQL database access
β’ More than 2,000 records
β’ DNI identification numbers
β’ CUIL and CUIT numbers
β’ Dates of birth
β’ Phone numbers
β’ Government email addresses
β’ Physical addresses
β’ Locality and postal code information
β’ Professional and specialty information
β’ Contracts and PDF documents
β
The seller's claims and the authenticity, availability and scope of the advertised access and data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum seller claims to be offering access to an Argentine municipal government system, including administrative infrastructure, cloud resources and internal data.
β
The advertised access includes:
β
β’ Administrative panel access
β’ Government Gmail SMTP access
β’ AWS storage keys
β’ MySQL database access
β’ More than 2,000 records
β’ DNI identification numbers
β’ CUIL and CUIT numbers
β’ Dates of birth
β’ Phone numbers
β’ Government email addresses
β’ Physical addresses
β’ Locality and postal code information
β’ Professional and specialty information
β’ Contracts and PDF documents
β
The seller's claims and the authenticity, availability and scope of the advertised access and data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨πΏπ¦ Anova Health Institute patient dataset allegedly breached, 83.1K+ records advertised on a cybercrime forum
β
A forum seller claims to be offering a dataset allegedly obtained from Anova Health Institute, a South African public health organization. The listing claims the data contains information relating to more than 83,100 patients.
β
The advertised data includes:
β
β’ Patient first and last names
β’ Identification numbers
β’ Dates of birth and ages
β’ Gender information
β’ Physical addresses
β’ Telephone numbers
β’ Patient and facility file numbers
β’ District and sub-district information
β’ Healthcare facility information
β’ Patient enrollment and visit dates
β’ Enrollment outcome information
β’ ART start dates
β’ REDCap record and event identifiers
β’ Internal record creator information
β
The seller published samples of the alleged patient records and is accepting offers for a one-time sale.
β
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum seller claims to be offering a dataset allegedly obtained from Anova Health Institute, a South African public health organization. The listing claims the data contains information relating to more than 83,100 patients.
β
The advertised data includes:
β
β’ Patient first and last names
β’ Identification numbers
β’ Dates of birth and ages
β’ Gender information
β’ Physical addresses
β’ Telephone numbers
β’ Patient and facility file numbers
β’ District and sub-district information
β’ Healthcare facility information
β’ Patient enrollment and visit dates
β’ Enrollment outcome information
β’ ART start dates
β’ REDCap record and event identifiers
β’ Internal record creator information
β
The seller published samples of the alleged patient records and is accepting offers for a one-time sale.
β
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: Medical Imaging Backup From Beijing's 301 Hospital Offered for Sale, With an Unverifiable Headline Claim
Link: https://darkwebinformer.com/medical-imaging-backup-from-beijings-301-hospital-offered-for-sale-with-an-unverifiable-headline-claim/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Medical Imaging Backup From Beijing's 301 Hospital Offered for Sale, With an Unverifiable Headline Claim
Link: https://darkwebinformer.com/medical-imaging-backup-from-beijings-301-hospital-offered-for-sale-with-an-unverifiable-headline-claim/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Medical Imaging Backup From Beijing's 301 Hospital Offered for Sale, With an Unverifiable Headline Claim
A forum user posting as Knox is offering what they describe as backup data taken from the Chinese PLA General Hospital in Beijing, commonly known as 301 Hospital.
π¨πΊπΈ U.S. corporate network access advertised for sale on a cybercrime forum
β
A forum seller is advertising what they claim is privileged access to an unidentified U.S. company with approximately $453.5 million in revenue.
β
The advertised access includes:
β
β’ SSH access through FortiGate
β’ Super administrator privileges
β’ Approximately 378 hosts
β’ Corporate network access
β’ High-level administrative control
β
The seller is asking $2,000 for the access.
β
The seller's claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum seller is advertising what they claim is privileged access to an unidentified U.S. company with approximately $453.5 million in revenue.
β
The advertised access includes:
β
β’ SSH access through FortiGate
β’ Super administrator privileges
β’ Approximately 378 hosts
β’ Corporate network access
β’ High-level administrative control
β
The seller is asking $2,000 for the access.
β
The seller's claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Forwarded from Dark Web Informer - Private
βΌοΈ DOJ Press Release
βββββββββββββββββββββ
17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities
Full Press Release β justice.gov
βββββββββββββββββββββ
π΅οΈ Dark Web Informer β’ DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
βββββββββββββββββββββ
17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities
Full Press Release β justice.gov
βββββββββββββββββββββ
π΅οΈ Dark Web Informer β’ DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
Department of Justice
17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranianβ¦
For Immediate Release Office of Public Affairs
π¨π«π· Taveau allegedly breached, 21.2 GB of data leaked on a cybercrime forum
β
A forum actor claims to have leaked data allegedly belonging to Taveau, a French company specializing in the sale and distribution of new and used agricultural machinery. The release is labeled "BlgCloud Leak #10" and is described as part of a wider series of leaks.
β
The alleged leak reportedly contains 21.2 GB of data across 107,125 files.
β
The exposed data shown in the samples includes:
β
β’ Customer and CRM records
β’ Names and contact information
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
β’ Postal codes and locality information
β’ Geographic coordinates
β’ Company and account information
β’ Customer and supplier references
β’ Billing and invoicing fields
β’ Internal user and account identifiers
β’ Commercial document metadata
β’ PDF documents and attachments
β’ File names, hashes and storage paths
β’ Internal database and application records
β
The thread includes CRM and document samples from the alleged dataset.
β
The listing also teases another French company as the next intended release in the same leak series.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have leaked data allegedly belonging to Taveau, a French company specializing in the sale and distribution of new and used agricultural machinery. The release is labeled "BlgCloud Leak #10" and is described as part of a wider series of leaks.
β
The alleged leak reportedly contains 21.2 GB of data across 107,125 files.
β
The exposed data shown in the samples includes:
β
β’ Customer and CRM records
β’ Names and contact information
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
β’ Postal codes and locality information
β’ Geographic coordinates
β’ Company and account information
β’ Customer and supplier references
β’ Billing and invoicing fields
β’ Internal user and account identifiers
β’ Commercial document metadata
β’ PDF documents and attachments
β’ File names, hashes and storage paths
β’ Internal database and application records
β
The thread includes CRM and document samples from the alleged dataset.
β
The listing also teases another French company as the next intended release in the same leak series.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π°π· Full administrative access to thousands of NVR devices advertised for sale on a cybercrime forum
β
A forum seller is advertising access to network video recorder (NVR) devices from multiple vendors, with the majority of the systems described as South Korean.
β
The listing claims:
β
β’ Access to 2,980 of 3,943 tested NVR devices
β’ Claimed success rate of 75.6%
β’ Account credentials
β’ Root-level access
β’ Devices from multiple vendors
β’ Approximately 130,000 dedicated public IP addresses referenced in the listing
β
The access is being offered for $120,000, with interested buyers directed to contact the seller privately through Telegram.
β
The claims and the authenticity, availability and scope of the advertised NVR access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum seller is advertising access to network video recorder (NVR) devices from multiple vendors, with the majority of the systems described as South Korean.
β
The listing claims:
β
β’ Access to 2,980 of 3,943 tested NVR devices
β’ Claimed success rate of 75.6%
β’ Account credentials
β’ Root-level access
β’ Devices from multiple vendors
β’ Approximately 130,000 dedicated public IP addresses referenced in the listing
β
The access is being offered for $120,000, with interested buyers directed to contact the seller privately through Telegram.
β
The claims and the authenticity, availability and scope of the advertised NVR access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Alleged Grand Theft Auto 6 video has leaked.
https://x.com/DarkWebInformer/status/2089780551934693534
https://x.com/DarkWebInformer/status/2089780551934693534
X (formerly Twitter)
Dark Web Informer (@DarkWebInformer) on X
Alleged Grand Theft Auto 6 video has leaked.
1π₯4
πͺ Slice For Life - Part 2 πͺ
Alleged Grand Theft Auto 6 video has leaked. https://x.com/DarkWebInformer/status/2089780551934693534
The about page from the CyberLeek website. Hope you have good OpSec bro. Rockstar Games doesn't fuck around.π
π₯1
πͺ Slice For Life - Part 2 πͺ
The about page from the CyberLeek website. Hope you have good OpSec bro. Rockstar Games doesn't fuck around.π
The CyberLeek site leads to this IP: 49[.]13[.]45[.]141. Which provides this information when you go to the IP...
{"wallet":"34LYvMptiDvBP5sqfh1oAd6Q4qFsy4PWaZ1HTFmML7h5","programIds":{"core":"73YoECm6NKXpVRoe5f1Q9BcP5DJGPFUjnFy6AxBE5Nvh","gar":"89fNiiwgpFSPHKuqfNUkgYTYjtAJAhyqHjXmgXeppGpf","arns":"2yCUx5edFvUrkibYaUa2ZXWyx9kuJkS8CwyzsgHPWdZZ","ant":"2MWexMHfMhGJwMHv9Qm9YAVCqjUFUJwDJAysW4oCUGk5"},"ans104UnbundleFilter":{"never":true},"ans104IndexFilter":{"never":true},"supportedManifestVersions":["0.1.0","0.2.0"],"release":"83-pre","services":{"bundlers":[{"url":"https://turbo.ardrive.io/"}]},"rateLimiter":{"enabled":true,"dataEgress":{"buckets":{"resource":{"capacity":100000000,"refillRate":5000,"capacityBytes":102400000000,"refillRateBytesPerSec":5120000},"ip":{"capacity":5000000,"refillRate":512,"capacityBytes":5120000000,"refillRateBytesPerSec":524288}}}},"x402":{"enabled":true,"network":"base","walletAddress":"0xC456C09F702f74E306f5feA96863bd7A1788c63D","facilitatorUrl":"https://facilitator.x402.rs","dataEgress":{"pricing":{"perBytePrice":"0.0000000001","minPrice":"0.001000","maxPrice":"1.000000","currency":"USDC","exampleCosts":{"1KB":0.001,"1MB":0.001,"1GB":0.107374}},"rateLimiterCapacityMultiplier":10}},"httpsig":{"algorithm":"ed25519","solanaAddress":"34LYvMptiDvBP5sqfh1oAd6Q4qFsy4PWaZ1HTFmML7h5"}}
{"wallet":"34LYvMptiDvBP5sqfh1oAd6Q4qFsy4PWaZ1HTFmML7h5","programIds":{"core":"73YoECm6NKXpVRoe5f1Q9BcP5DJGPFUjnFy6AxBE5Nvh","gar":"89fNiiwgpFSPHKuqfNUkgYTYjtAJAhyqHjXmgXeppGpf","arns":"2yCUx5edFvUrkibYaUa2ZXWyx9kuJkS8CwyzsgHPWdZZ","ant":"2MWexMHfMhGJwMHv9Qm9YAVCqjUFUJwDJAysW4oCUGk5"},"ans104UnbundleFilter":{"never":true},"ans104IndexFilter":{"never":true},"supportedManifestVersions":["0.1.0","0.2.0"],"release":"83-pre","services":{"bundlers":[{"url":"https://turbo.ardrive.io/"}]},"rateLimiter":{"enabled":true,"dataEgress":{"buckets":{"resource":{"capacity":100000000,"refillRate":5000,"capacityBytes":102400000000,"refillRateBytesPerSec":5120000},"ip":{"capacity":5000000,"refillRate":512,"capacityBytes":5120000000,"refillRateBytesPerSec":524288}}}},"x402":{"enabled":true,"network":"base","walletAddress":"0xC456C09F702f74E306f5feA96863bd7A1788c63D","facilitatorUrl":"https://facilitator.x402.rs","dataEgress":{"pricing":{"perBytePrice":"0.0000000001","minPrice":"0.001000","maxPrice":"1.000000","currency":"USDC","exampleCosts":{"1KB":0.001,"1MB":0.001,"1GB":0.107374}},"rateLimiterCapacityMultiplier":10}},"httpsig":{"algorithm":"ed25519","solanaAddress":"34LYvMptiDvBP5sqfh1oAd6Q4qFsy4PWaZ1HTFmML7h5"}}
π3π2
For companies looking to purchase API access to Dark Web Informer:
I will NEVER provide my personal information, identification, home address, proof of residence, personal banking documents, or any other information that would identify me to satisfy your invoicing or accounting requirements.
There are no exceptions. NONE!
If your company cannot process a purchase without obtaining my private information, then you simply cannot purchase the service and this has always been stated on the API Details page.
My privacy is NOT negotiable.
I will NEVER provide my personal information, identification, home address, proof of residence, personal banking documents, or any other information that would identify me to satisfy your invoicing or accounting requirements.
There are no exceptions. NONE!
If your company cannot process a purchase without obtaining my private information, then you simply cannot purchase the service and this has always been stated on the API Details page.
My privacy is NOT negotiable.
β€4
π¨π²πΎπ¬π§ Access to Malaysian investment holding and UK telecommunications companies advertised for sale on a cybercrime forum
β
A forum seller is advertising two separate corporate access listings, one targeting a Malaysian investment holding company and another involving VPN access to a UK telecommunications company.
β
The Malaysian listing claims:
β
β’ Verified credentials
β’ Company revenue exceeding $10 billion
β’ Asking price of $500
β’ Escrow-only transaction
β
The UK telecommunications listing claims:
β
β’ VPN access
β’ Verified credentials
β’ Company revenue exceeding $20 billion
β’ Asking price of $1,000
β’ Escrow-only transaction
β
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum seller is advertising two separate corporate access listings, one targeting a Malaysian investment holding company and another involving VPN access to a UK telecommunications company.
β
The Malaysian listing claims:
β
β’ Verified credentials
β’ Company revenue exceeding $10 billion
β’ Asking price of $500
β’ Escrow-only transaction
β
The UK telecommunications listing claims:
β
β’ VPN access
β’ Verified credentials
β’ Company revenue exceeding $20 billion
β’ Asking price of $1,000
β’ Escrow-only transaction
β
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ Never assume that "checking a box" will remove your image's metadata for you on upload.
Use something like ExifCleaner: https://github.com/szTheory/exifcleaner.
Windows, Mac, and Linux versions available.
Use something like ExifCleaner: https://github.com/szTheory/exifcleaner.
Windows, Mac, and Linux versions available.
β€3
Prolific Chinese Money Launderer Sentenced to 15 Years in Prison for Laundering Drug Trafficking Proceeds Following Homeland Security Task Force Investigation
Image via DoJ
https://www.justice.gov/opa/pr/prolific-chinese-money-launderer-sentenced-15-years-prison-laundering-drug-trafficking
Image via DoJ
https://www.justice.gov/opa/pr/prolific-chinese-money-launderer-sentenced-15-years-prison-laundering-drug-trafficking
Media is too big
VIEW IN TELEGRAM
The Hunt for Lux: The Internetβs Most Disturbed User
The Following Video Contains Content That Some Viewers May Find Disturbing or Unsettling.
In the early 2010s, law enforcement agencies around the world began a manhunt for a deeply disturbed internet user known only as "Lux."
Tracking him down would prove incredibly difficult. But the FBI and other agencies were determined to find him. Lux had rapidly become one of the most notorious and despised figures on the dark web, operating sites that hosted some of the most disturbing content imaginable.
For years, he remained hidden behind the anonymity of the internet while investigators worked to uncover the person behind the name.
This is the story of Lux, the worldwide hunt to identify him, and what happened next.
Video Credit: youtube.com/@Cryton
The Following Video Contains Content That Some Viewers May Find Disturbing or Unsettling.
In the early 2010s, law enforcement agencies around the world began a manhunt for a deeply disturbed internet user known only as "Lux."
Tracking him down would prove incredibly difficult. But the FBI and other agencies were determined to find him. Lux had rapidly become one of the most notorious and despised figures on the dark web, operating sites that hosted some of the most disturbing content imaginable.
For years, he remained hidden behind the anonymity of the internet while investigators worked to uncover the person behind the name.
This is the story of Lux, the worldwide hunt to identify him, and what happened next.
Video Credit: youtube.com/@Cryton
π1
βΌοΈ An updated Joint Cybersecurity Advisory on Medusa ransomware was provided by the FBI, CISA, and HHS.
PDF: https://www.ic3.gov/CSA/2026/260818.pdf
PDF: https://www.ic3.gov/CSA/2026/260818.pdf