π¨π²πΎπ¬π§ Access to Malaysian investment holding and UK telecommunications companies advertised for sale on a cybercrime forum
β
A forum seller is advertising two separate corporate access listings, one targeting a Malaysian investment holding company and another involving VPN access to a UK telecommunications company.
β
The Malaysian listing claims:
β
β’ Verified credentials
β’ Company revenue exceeding $10 billion
β’ Asking price of $500
β’ Escrow-only transaction
β
The UK telecommunications listing claims:
β
β’ VPN access
β’ Verified credentials
β’ Company revenue exceeding $20 billion
β’ Asking price of $1,000
β’ Escrow-only transaction
β
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum seller is advertising two separate corporate access listings, one targeting a Malaysian investment holding company and another involving VPN access to a UK telecommunications company.
β
The Malaysian listing claims:
β
β’ Verified credentials
β’ Company revenue exceeding $10 billion
β’ Asking price of $500
β’ Escrow-only transaction
β
The UK telecommunications listing claims:
β
β’ VPN access
β’ Verified credentials
β’ Company revenue exceeding $20 billion
β’ Asking price of $1,000
β’ Escrow-only transaction
β
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ Never assume that "checking a box" will remove your image's metadata for you on upload.
Use something like ExifCleaner: https://github.com/szTheory/exifcleaner.
Windows, Mac, and Linux versions available.
Use something like ExifCleaner: https://github.com/szTheory/exifcleaner.
Windows, Mac, and Linux versions available.
β€3
Prolific Chinese Money Launderer Sentenced to 15 Years in Prison for Laundering Drug Trafficking Proceeds Following Homeland Security Task Force Investigation
Image via DoJ
https://www.justice.gov/opa/pr/prolific-chinese-money-launderer-sentenced-15-years-prison-laundering-drug-trafficking
Image via DoJ
https://www.justice.gov/opa/pr/prolific-chinese-money-launderer-sentenced-15-years-prison-laundering-drug-trafficking
Media is too big
VIEW IN TELEGRAM
The Hunt for Lux: The Internetβs Most Disturbed User
The Following Video Contains Content That Some Viewers May Find Disturbing or Unsettling.
In the early 2010s, law enforcement agencies around the world began a manhunt for a deeply disturbed internet user known only as "Lux."
Tracking him down would prove incredibly difficult. But the FBI and other agencies were determined to find him. Lux had rapidly become one of the most notorious and despised figures on the dark web, operating sites that hosted some of the most disturbing content imaginable.
For years, he remained hidden behind the anonymity of the internet while investigators worked to uncover the person behind the name.
This is the story of Lux, the worldwide hunt to identify him, and what happened next.
Video Credit: youtube.com/@Cryton
The Following Video Contains Content That Some Viewers May Find Disturbing or Unsettling.
In the early 2010s, law enforcement agencies around the world began a manhunt for a deeply disturbed internet user known only as "Lux."
Tracking him down would prove incredibly difficult. But the FBI and other agencies were determined to find him. Lux had rapidly become one of the most notorious and despised figures on the dark web, operating sites that hosted some of the most disturbing content imaginable.
For years, he remained hidden behind the anonymity of the internet while investigators worked to uncover the person behind the name.
This is the story of Lux, the worldwide hunt to identify him, and what happened next.
Video Credit: youtube.com/@Cryton
π1
βΌοΈ An updated Joint Cybersecurity Advisory on Medusa ransomware was provided by the FBI, CISA, and HHS.
PDF: https://www.ic3.gov/CSA/2026/260818.pdf
PDF: https://www.ic3.gov/CSA/2026/260818.pdf
π¨π¨π· Costa Rica's Supreme Electoral Tribunal allegedly breached, 3.75M records claimed leaked on a cybercrime forum
β
A forum user claims to have breached the Supreme Electoral Tribunal of Costa Rica (Tribunal Supremo de Elecciones) and obtained 3,751,244 records containing information tied to individuals across the country.
β
The exposed data shown in the sample includes:
β
β’ Full names
β’ Document and identification numbers
β’ Locality information
β’ Date-related fields
β’ Paternal surnames
β’ Maternal surnames
β’ Internal record identifiers
β
The listing also claims the leak contains a file that can associate an identification number with the location of an individual.
β
A 250,000-row proof of concept has been released, while the complete database is described as approximately 365 MB in DB format.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have breached the Supreme Electoral Tribunal of Costa Rica (Tribunal Supremo de Elecciones) and obtained 3,751,244 records containing information tied to individuals across the country.
β
The exposed data shown in the sample includes:
β
β’ Full names
β’ Document and identification numbers
β’ Locality information
β’ Date-related fields
β’ Paternal surnames
β’ Maternal surnames
β’ Internal record identifiers
β
The listing also claims the leak contains a file that can associate an identification number with the location of an individual.
β
A 250,000-row proof of concept has been released, while the complete database is described as approximately 365 MB in DB format.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Some fun things I've been called since I started DWI... and all of them are completely WRONG.
- Ransomware operator
- Ransomware negotiator
- Cybercriminal
- Darknet Market admin
- Illicit vendor
- Part of The Impact Team
- Forum operator
- Twitch streamer (literally)
- Initial access broker
- Threat actor
- Fed
- Informant
- LE
- Ransomware operator
- Ransomware negotiator
- Cybercriminal
- Darknet Market admin
- Illicit vendor
- Part of The Impact Team
- Forum operator
- Twitch streamer (literally)
- Initial access broker
- Threat actor
- Fed
- Informant
- LE
β€4π2π2π1
π¨π²π½ CONALEP Morelos student database allegedly leaked on a cybercrime forum, 24K+ records claimed
β
A forum user claims to have released the complete database of CONALEP Morelos, saying the new leak contains a larger volume of information than a previously shared dataset. The listing claims more than 24,000 records containing personal and student-related data.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ ZIP codes
β’ CURP identifiers
β’ RFC identifiers
β’ NSS numbers
β’ Student registration information
β’ Campus and program information
β’ Address-related data
β’ Date of birth and other demographic fields
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have released the complete database of CONALEP Morelos, saying the new leak contains a larger volume of information than a previously shared dataset. The listing claims more than 24,000 records containing personal and student-related data.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ ZIP codes
β’ CURP identifiers
β’ RFC identifiers
β’ NSS numbers
β’ Student registration information
β’ Campus and program information
β’ Address-related data
β’ Date of birth and other demographic fields
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΏπΌ Hamara allegedly breached, data tied to 11K+ users advertised on a cybercrime forum
β
A forum user claims to have breached Hamara, a Zimbabwe-based agriculture and farming platform, after allegedly obtaining exposed credentials and accessing an administrative account that lacked two-factor authentication.
β
The listing claims the compromised environment contains:
β
β’ User account data
β’ Names and usernames
β’ Email addresses
β’ Phone numbers
β’ Account roles and verification status
β’ Business information
β’ Business contracts
β’ Business PDF documents
β’ Audit logs
β’ Institution records
β’ Service data
β’ Event data
β’ Marketplace and unit information
β’ Administrator and manager data
β
The account reportedly had access to information associated with more than 11,000 users at the time of the alleged breach. Sample records containing customer names, usernames, emails, phone numbers and account roles were published in the thread.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have breached Hamara, a Zimbabwe-based agriculture and farming platform, after allegedly obtaining exposed credentials and accessing an administrative account that lacked two-factor authentication.
β
The listing claims the compromised environment contains:
β
β’ User account data
β’ Names and usernames
β’ Email addresses
β’ Phone numbers
β’ Account roles and verification status
β’ Business information
β’ Business contracts
β’ Business PDF documents
β’ Audit logs
β’ Institution records
β’ Service data
β’ Event data
β’ Marketplace and unit information
β’ Administrator and manager data
β
The account reportedly had access to information associated with more than 11,000 users at the time of the alleged breach. Sample records containing customer names, usernames, emails, phone numbers and account roles were published in the thread.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πͺ Slice For Life - Part 2 πͺ
Every comment in this post is 100% wrong and fucking stupid.
I love the newer comments about the gold checkmark. X doesn't require KYC for business verification. At the time I did it over a year ago it only required domain and website verification. But but you paid with something... yup and there is ways around not using my name. Some of you really are horny.
Edit: email domain*
Edit: email domain*
π1
π¨π¨π¦ Permis Plus Sherbrooke database allegedly leaked on a cybercrime forum, 1,292 records claimed
β
A forum user claims to have released a previously unpublished dataset allegedly belonging to Γcole de conduite Permis Plus Sherbrooke, part of the Permis Plus driving-school network in Quebec. (Γcole de conduite Permis Plus inc.)
β
The alleged leak contains 1,292 records, with the exposed fields including:
β
β’ User IDs
β’ Email addresses
β’ Usernames
β’ First and last names
β’ Account status information
β’ Deleted-account indicators
β’ User roles and permission classifications
β’ School owner accounts
β’ School administrator accounts
β’ Student/customer accounts
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have released a previously unpublished dataset allegedly belonging to Γcole de conduite Permis Plus Sherbrooke, part of the Permis Plus driving-school network in Quebec. (Γcole de conduite Permis Plus inc.)
β
The alleged leak contains 1,292 records, with the exposed fields including:
β
β’ User IDs
β’ Email addresses
β’ Usernames
β’ First and last names
β’ Account status information
β’ Deleted-account indicators
β’ User roles and permission classifications
β’ School owner accounts
β’ School administrator accounts
β’ Student/customer accounts
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯1
π¨ Dataset from an unidentified AI adult-content generation platform advertised for sale on a cybercrime forum
β
A forum user claims to be selling access to data allegedly obtained from an AI adult-content generation platform, saying the dataset contains information tied to more than 150,000 users and over 250,000 AI-generated videos with associated source images.
β
The advertised access reportedly includes:
β
β’ 150,000+ user accounts
β’ 250,000+ AI-generated videos
β’ Associated source images
β’ A reportedly still-active proof of concept capable of refreshing the database
β’ User activity and generation history
β’ Information allegedly identifying higher-income users
β
The listing explicitly claims some users generated explicit AI content involving themselves, friends or relatives, and markets the information as potential leads for blackmail and extortion.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to be selling access to data allegedly obtained from an AI adult-content generation platform, saying the dataset contains information tied to more than 150,000 users and over 250,000 AI-generated videos with associated source images.
β
The advertised access reportedly includes:
β
β’ 150,000+ user accounts
β’ 250,000+ AI-generated videos
β’ Associated source images
β’ A reportedly still-active proof of concept capable of refreshing the database
β’ User activity and generation history
β’ Information allegedly identifying higher-income users
β
The listing explicitly claims some users generated explicit AI content involving themselves, friends or relatives, and markets the information as potential leads for blackmail and extortion.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π1
π¨ Edge cryptocurrency wallet support data allegedly breached, 185K user emails claimed exposed
β
A forum user claims to have breached the Edge cryptocurrency wallet support system in 2026, allegedly exposing approximately 185,000 user email addresses along with additional support-related metadata.
β
The advertised data includes:
β
β’ 185,000 user email addresses
β’ Support ticket identifiers
β’ Assigned support agent information
β’ Ticket creation and update timestamps
β’ Ticket status information
β’ Satisfaction ratings
β’ Tags and ticket metadata
β’ Messaging channel information
β’ External and organization identifiers
β’ Support platform URLs and record references
β
A sample published in the thread appears to contain records associated with Edge's Zendesk support environment, including customer email addresses and ticket-related metadata.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have breached the Edge cryptocurrency wallet support system in 2026, allegedly exposing approximately 185,000 user email addresses along with additional support-related metadata.
β
The advertised data includes:
β
β’ 185,000 user email addresses
β’ Support ticket identifiers
β’ Assigned support agent information
β’ Ticket creation and update timestamps
β’ Ticket status information
β’ Satisfaction ratings
β’ Tags and ticket metadata
β’ Messaging channel information
β’ External and organization identifiers
β’ Support platform URLs and record references
β
A sample published in the thread appears to contain records associated with Edge's Zendesk support environment, including customer email addresses and ticket-related metadata.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers
Link: https://darkwebinformer.com/argentine-hardware-wallet-retailer-allegedly-exposed-linking-named-buyers-to-home-addresses-and-id-numbers/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers
Link: https://darkwebinformer.com/argentine-hardware-wallet-retailer-allegedly-exposed-linking-named-buyers-to-home-addresses-and-id-numbers/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers
A forum user posting as kingloki is offering what they describe as a complete order export from coincustody.io, an Argentine reseller of Trezor and Ledger hardware wallets, covering 212 orders placed between May 2025 and August 2026.
π¨ Moondancer ransomware group recruiting affiliates on a cybercrime forum
β
A forum actor is promoting a ransomware operation called Moondancer and says the group is actively recruiting affiliates to participate in attacks against organizations across Latin America.
β
The recruitment post claims:
β
β’ Operations are focused on Latin American companies
β’ Priority is given to organizations dependent on critical infrastructure and continuous uptime
β’ Healthcare services are explicitly excluded from targeting
β’ Affiliates can join without an upfront fee
β’ Applicants are expected to provide value to the group
β’ Additional details are hidden behind forum content
β’ Contact is offered through Telegram and Tox
β
The group describes the campaign as a "big game hunting" operation and appears to be seeking partners capable of helping expand its ransomware activity.
β
The claims and the capabilities, membership and operational scope of Moondancer have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor is promoting a ransomware operation called Moondancer and says the group is actively recruiting affiliates to participate in attacks against organizations across Latin America.
β
The recruitment post claims:
β
β’ Operations are focused on Latin American companies
β’ Priority is given to organizations dependent on critical infrastructure and continuous uptime
β’ Healthcare services are explicitly excluded from targeting
β’ Affiliates can join without an upfront fee
β’ Applicants are expected to provide value to the group
β’ Additional details are hidden behind forum content
β’ Contact is offered through Telegram and Tox
β
The group describes the campaign as a "big game hunting" operation and appears to be seeking partners capable of helping expand its ransomware activity.
β
The claims and the capabilities, membership and operational scope of Moondancer have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨ππ· Croatian Pension Insurance Institute allegedly breached, 105K records leaked on a cybercrime forum
β
A group identifying itself as INF GRUPA claims to have breached the Croatian Pension Insurance Institute (HZMO) and extracted personal information belonging to approximately 105,000 Croatian citizens.
β
The advertised data includes:
β
β’ Full names and surnames
β’ Phone numbers
β’ OIB personal identification numbers
β’ Email addresses
β
INF GRUPA says the dataset is being released for free and claims the operation was not financially motivated. The group states that it is not seeking a ransom or cryptocurrency payment and describes the breach as part of a broader campaign targeting Croatian institutions.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A group identifying itself as INF GRUPA claims to have breached the Croatian Pension Insurance Institute (HZMO) and extracted personal information belonging to approximately 105,000 Croatian citizens.
β
The advertised data includes:
β
β’ Full names and surnames
β’ Phone numbers
β’ OIB personal identification numbers
β’ Email addresses
β
INF GRUPA says the dataset is being released for free and claims the operation was not financially motivated. The group states that it is not seeking a ransom or cryptocurrency payment and describes the breach as part of a broader campaign targeting Croatian institutions.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π«π· Sport 2000 internal booking system allegedly breached, complete database released on a cybercrime forum
β
A forum actor claims to have breached Sport 2000's internal booking system, known as Pilot, and extracted reservation data from the platform. The alleged breach is dated August 19, 2026, with the released dataset containing 17,851 records.
β
The exposed data reportedly includes:
β
β’ Customer information
β’ Booking and reservation records
β’ Product information
β’ Transaction amounts
β’ Valid and cancelled bookings
β’ Legacy booking references
β’ Full reservation detail records
β
According to the listing, approximately 14,500 valid bookings were obtained from a bulk export, while roughly 3,350 cancelled bookings were collected individually because they were not included in the export. Around 700 older bookings were also reportedly matched to their corresponding records using legacy reference numbers.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have breached Sport 2000's internal booking system, known as Pilot, and extracted reservation data from the platform. The alleged breach is dated August 19, 2026, with the released dataset containing 17,851 records.
β
The exposed data reportedly includes:
β
β’ Customer information
β’ Booking and reservation records
β’ Product information
β’ Transaction amounts
β’ Valid and cancelled bookings
β’ Legacy booking references
β’ Full reservation detail records
β
According to the listing, approximately 14,500 valid bookings were obtained from a bulk export, while roughly 3,350 cancelled bookings were collected individually because they were not included in the export. Around 700 older bookings were also reportedly matched to their corresponding records using legacy reference numbers.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Securo: Self-hosted, privacy-first open-source personal finance manager.
GitHub: https://github.com/securo-finance/securo
GitHub: https://github.com/securo-finance/securo
β€1