βΌοΈ An updated Joint Cybersecurity Advisory on Medusa ransomware was provided by the FBI, CISA, and HHS.
PDF: https://www.ic3.gov/CSA/2026/260818.pdf
PDF: https://www.ic3.gov/CSA/2026/260818.pdf
π¨π¨π· Costa Rica's Supreme Electoral Tribunal allegedly breached, 3.75M records claimed leaked on a cybercrime forum
β
A forum user claims to have breached the Supreme Electoral Tribunal of Costa Rica (Tribunal Supremo de Elecciones) and obtained 3,751,244 records containing information tied to individuals across the country.
β
The exposed data shown in the sample includes:
β
β’ Full names
β’ Document and identification numbers
β’ Locality information
β’ Date-related fields
β’ Paternal surnames
β’ Maternal surnames
β’ Internal record identifiers
β
The listing also claims the leak contains a file that can associate an identification number with the location of an individual.
β
A 250,000-row proof of concept has been released, while the complete database is described as approximately 365 MB in DB format.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have breached the Supreme Electoral Tribunal of Costa Rica (Tribunal Supremo de Elecciones) and obtained 3,751,244 records containing information tied to individuals across the country.
β
The exposed data shown in the sample includes:
β
β’ Full names
β’ Document and identification numbers
β’ Locality information
β’ Date-related fields
β’ Paternal surnames
β’ Maternal surnames
β’ Internal record identifiers
β
The listing also claims the leak contains a file that can associate an identification number with the location of an individual.
β
A 250,000-row proof of concept has been released, while the complete database is described as approximately 365 MB in DB format.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Some fun things I've been called since I started DWI... and all of them are completely WRONG.
- Ransomware operator
- Ransomware negotiator
- Cybercriminal
- Darknet Market admin
- Illicit vendor
- Part of The Impact Team
- Forum operator
- Twitch streamer (literally)
- Initial access broker
- Threat actor
- Fed
- Informant
- LE
- Ransomware operator
- Ransomware negotiator
- Cybercriminal
- Darknet Market admin
- Illicit vendor
- Part of The Impact Team
- Forum operator
- Twitch streamer (literally)
- Initial access broker
- Threat actor
- Fed
- Informant
- LE
β€4π2π2π1
π¨π²π½ CONALEP Morelos student database allegedly leaked on a cybercrime forum, 24K+ records claimed
β
A forum user claims to have released the complete database of CONALEP Morelos, saying the new leak contains a larger volume of information than a previously shared dataset. The listing claims more than 24,000 records containing personal and student-related data.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ ZIP codes
β’ CURP identifiers
β’ RFC identifiers
β’ NSS numbers
β’ Student registration information
β’ Campus and program information
β’ Address-related data
β’ Date of birth and other demographic fields
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have released the complete database of CONALEP Morelos, saying the new leak contains a larger volume of information than a previously shared dataset. The listing claims more than 24,000 records containing personal and student-related data.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ ZIP codes
β’ CURP identifiers
β’ RFC identifiers
β’ NSS numbers
β’ Student registration information
β’ Campus and program information
β’ Address-related data
β’ Date of birth and other demographic fields
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΏπΌ Hamara allegedly breached, data tied to 11K+ users advertised on a cybercrime forum
β
A forum user claims to have breached Hamara, a Zimbabwe-based agriculture and farming platform, after allegedly obtaining exposed credentials and accessing an administrative account that lacked two-factor authentication.
β
The listing claims the compromised environment contains:
β
β’ User account data
β’ Names and usernames
β’ Email addresses
β’ Phone numbers
β’ Account roles and verification status
β’ Business information
β’ Business contracts
β’ Business PDF documents
β’ Audit logs
β’ Institution records
β’ Service data
β’ Event data
β’ Marketplace and unit information
β’ Administrator and manager data
β
The account reportedly had access to information associated with more than 11,000 users at the time of the alleged breach. Sample records containing customer names, usernames, emails, phone numbers and account roles were published in the thread.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have breached Hamara, a Zimbabwe-based agriculture and farming platform, after allegedly obtaining exposed credentials and accessing an administrative account that lacked two-factor authentication.
β
The listing claims the compromised environment contains:
β
β’ User account data
β’ Names and usernames
β’ Email addresses
β’ Phone numbers
β’ Account roles and verification status
β’ Business information
β’ Business contracts
β’ Business PDF documents
β’ Audit logs
β’ Institution records
β’ Service data
β’ Event data
β’ Marketplace and unit information
β’ Administrator and manager data
β
The account reportedly had access to information associated with more than 11,000 users at the time of the alleged breach. Sample records containing customer names, usernames, emails, phone numbers and account roles were published in the thread.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πͺ Slice For Life - Part 2 πͺ
Every comment in this post is 100% wrong and fucking stupid.
I love the newer comments about the gold checkmark. X doesn't require KYC for business verification. At the time I did it over a year ago it only required domain and website verification. But but you paid with something... yup and there is ways around not using my name. Some of you really are horny.
Edit: email domain*
Edit: email domain*
π1
π¨π¨π¦ Permis Plus Sherbrooke database allegedly leaked on a cybercrime forum, 1,292 records claimed
β
A forum user claims to have released a previously unpublished dataset allegedly belonging to Γcole de conduite Permis Plus Sherbrooke, part of the Permis Plus driving-school network in Quebec. (Γcole de conduite Permis Plus inc.)
β
The alleged leak contains 1,292 records, with the exposed fields including:
β
β’ User IDs
β’ Email addresses
β’ Usernames
β’ First and last names
β’ Account status information
β’ Deleted-account indicators
β’ User roles and permission classifications
β’ School owner accounts
β’ School administrator accounts
β’ Student/customer accounts
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have released a previously unpublished dataset allegedly belonging to Γcole de conduite Permis Plus Sherbrooke, part of the Permis Plus driving-school network in Quebec. (Γcole de conduite Permis Plus inc.)
β
The alleged leak contains 1,292 records, with the exposed fields including:
β
β’ User IDs
β’ Email addresses
β’ Usernames
β’ First and last names
β’ Account status information
β’ Deleted-account indicators
β’ User roles and permission classifications
β’ School owner accounts
β’ School administrator accounts
β’ Student/customer accounts
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯1
π¨ Dataset from an unidentified AI adult-content generation platform advertised for sale on a cybercrime forum
β
A forum user claims to be selling access to data allegedly obtained from an AI adult-content generation platform, saying the dataset contains information tied to more than 150,000 users and over 250,000 AI-generated videos with associated source images.
β
The advertised access reportedly includes:
β
β’ 150,000+ user accounts
β’ 250,000+ AI-generated videos
β’ Associated source images
β’ A reportedly still-active proof of concept capable of refreshing the database
β’ User activity and generation history
β’ Information allegedly identifying higher-income users
β
The listing explicitly claims some users generated explicit AI content involving themselves, friends or relatives, and markets the information as potential leads for blackmail and extortion.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to be selling access to data allegedly obtained from an AI adult-content generation platform, saying the dataset contains information tied to more than 150,000 users and over 250,000 AI-generated videos with associated source images.
β
The advertised access reportedly includes:
β
β’ 150,000+ user accounts
β’ 250,000+ AI-generated videos
β’ Associated source images
β’ A reportedly still-active proof of concept capable of refreshing the database
β’ User activity and generation history
β’ Information allegedly identifying higher-income users
β
The listing explicitly claims some users generated explicit AI content involving themselves, friends or relatives, and markets the information as potential leads for blackmail and extortion.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π1
π¨ Edge cryptocurrency wallet support data allegedly breached, 185K user emails claimed exposed
β
A forum user claims to have breached the Edge cryptocurrency wallet support system in 2026, allegedly exposing approximately 185,000 user email addresses along with additional support-related metadata.
β
The advertised data includes:
β
β’ 185,000 user email addresses
β’ Support ticket identifiers
β’ Assigned support agent information
β’ Ticket creation and update timestamps
β’ Ticket status information
β’ Satisfaction ratings
β’ Tags and ticket metadata
β’ Messaging channel information
β’ External and organization identifiers
β’ Support platform URLs and record references
β
A sample published in the thread appears to contain records associated with Edge's Zendesk support environment, including customer email addresses and ticket-related metadata.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have breached the Edge cryptocurrency wallet support system in 2026, allegedly exposing approximately 185,000 user email addresses along with additional support-related metadata.
β
The advertised data includes:
β
β’ 185,000 user email addresses
β’ Support ticket identifiers
β’ Assigned support agent information
β’ Ticket creation and update timestamps
β’ Ticket status information
β’ Satisfaction ratings
β’ Tags and ticket metadata
β’ Messaging channel information
β’ External and organization identifiers
β’ Support platform URLs and record references
β
A sample published in the thread appears to contain records associated with Edge's Zendesk support environment, including customer email addresses and ticket-related metadata.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers
Link: https://darkwebinformer.com/argentine-hardware-wallet-retailer-allegedly-exposed-linking-named-buyers-to-home-addresses-and-id-numbers/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers
Link: https://darkwebinformer.com/argentine-hardware-wallet-retailer-allegedly-exposed-linking-named-buyers-to-home-addresses-and-id-numbers/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers
A forum user posting as kingloki is offering what they describe as a complete order export from coincustody.io, an Argentine reseller of Trezor and Ledger hardware wallets, covering 212 orders placed between May 2025 and August 2026.
π¨ Moondancer ransomware group recruiting affiliates on a cybercrime forum
β
A forum actor is promoting a ransomware operation called Moondancer and says the group is actively recruiting affiliates to participate in attacks against organizations across Latin America.
β
The recruitment post claims:
β
β’ Operations are focused on Latin American companies
β’ Priority is given to organizations dependent on critical infrastructure and continuous uptime
β’ Healthcare services are explicitly excluded from targeting
β’ Affiliates can join without an upfront fee
β’ Applicants are expected to provide value to the group
β’ Additional details are hidden behind forum content
β’ Contact is offered through Telegram and Tox
β
The group describes the campaign as a "big game hunting" operation and appears to be seeking partners capable of helping expand its ransomware activity.
β
The claims and the capabilities, membership and operational scope of Moondancer have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor is promoting a ransomware operation called Moondancer and says the group is actively recruiting affiliates to participate in attacks against organizations across Latin America.
β
The recruitment post claims:
β
β’ Operations are focused on Latin American companies
β’ Priority is given to organizations dependent on critical infrastructure and continuous uptime
β’ Healthcare services are explicitly excluded from targeting
β’ Affiliates can join without an upfront fee
β’ Applicants are expected to provide value to the group
β’ Additional details are hidden behind forum content
β’ Contact is offered through Telegram and Tox
β
The group describes the campaign as a "big game hunting" operation and appears to be seeking partners capable of helping expand its ransomware activity.
β
The claims and the capabilities, membership and operational scope of Moondancer have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨ππ· Croatian Pension Insurance Institute allegedly breached, 105K records leaked on a cybercrime forum
β
A group identifying itself as INF GRUPA claims to have breached the Croatian Pension Insurance Institute (HZMO) and extracted personal information belonging to approximately 105,000 Croatian citizens.
β
The advertised data includes:
β
β’ Full names and surnames
β’ Phone numbers
β’ OIB personal identification numbers
β’ Email addresses
β
INF GRUPA says the dataset is being released for free and claims the operation was not financially motivated. The group states that it is not seeking a ransom or cryptocurrency payment and describes the breach as part of a broader campaign targeting Croatian institutions.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A group identifying itself as INF GRUPA claims to have breached the Croatian Pension Insurance Institute (HZMO) and extracted personal information belonging to approximately 105,000 Croatian citizens.
β
The advertised data includes:
β
β’ Full names and surnames
β’ Phone numbers
β’ OIB personal identification numbers
β’ Email addresses
β
INF GRUPA says the dataset is being released for free and claims the operation was not financially motivated. The group states that it is not seeking a ransom or cryptocurrency payment and describes the breach as part of a broader campaign targeting Croatian institutions.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π«π· Sport 2000 internal booking system allegedly breached, complete database released on a cybercrime forum
β
A forum actor claims to have breached Sport 2000's internal booking system, known as Pilot, and extracted reservation data from the platform. The alleged breach is dated August 19, 2026, with the released dataset containing 17,851 records.
β
The exposed data reportedly includes:
β
β’ Customer information
β’ Booking and reservation records
β’ Product information
β’ Transaction amounts
β’ Valid and cancelled bookings
β’ Legacy booking references
β’ Full reservation detail records
β
According to the listing, approximately 14,500 valid bookings were obtained from a bulk export, while roughly 3,350 cancelled bookings were collected individually because they were not included in the export. Around 700 older bookings were also reportedly matched to their corresponding records using legacy reference numbers.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have breached Sport 2000's internal booking system, known as Pilot, and extracted reservation data from the platform. The alleged breach is dated August 19, 2026, with the released dataset containing 17,851 records.
β
The exposed data reportedly includes:
β
β’ Customer information
β’ Booking and reservation records
β’ Product information
β’ Transaction amounts
β’ Valid and cancelled bookings
β’ Legacy booking references
β’ Full reservation detail records
β
According to the listing, approximately 14,500 valid bookings were obtained from a bulk export, while roughly 3,350 cancelled bookings were collected individually because they were not included in the export. Around 700 older bookings were also reportedly matched to their corresponding records using legacy reference numbers.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Securo: Self-hosted, privacy-first open-source personal finance manager.
GitHub: https://github.com/securo-finance/securo
GitHub: https://github.com/securo-finance/securo
β€1
βΌοΈ New Dark Web Informer Blog Post!
Title: CareCloud Data Breach Exposes Medical Records of More Than 3.75 Million Patients
Link: https://darkwebinformer.com/carecloud-data-breach-exposes-medical-records-of-more-than-3-75-million-patients/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: CareCloud Data Breach Exposes Medical Records of More Than 3.75 Million Patients
Link: https://darkwebinformer.com/carecloud-data-breach-exposes-medical-records-of-more-than-3-75-million-patients/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
CareCloud Data Breach Exposes Medical Records of More Than 3.75 Million Patients
Healthcare technology company CareCloud has confirmed that hackers stole personal information and medical records belonging to more than 3.75 million people during a cyberattack earlier this year.
π¨ Public PoC available for high-severity Android ContactsProvider flaw
https://github.com/qm4rs/cve-2026-0075
CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction.
Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS.
The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel.
Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers.
The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device.
Devices with the June 5, 2026 Android security patch level or later address the issue.
https://github.com/qm4rs/cve-2026-0075
CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction.
Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS.
The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel.
Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers.
The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device.
Devices with the June 5, 2026 Android security patch level or later address the issue.
π₯1
Tails 7.11 has been released... update if you haven't already done so.
https://tails.net/news/version_7.11/
https://tails.net/news/version_7.11/
βΌοΈ A forum actor advertises the sale of RDP and VPN access, offering to use a guarantor (escrow) for the transaction.
No specific victim organization or details are provided.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
No specific victim organization or details are provided.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
βΌοΈπΊπΈ A forum actor is offering for sale super_admin-level SSH access to a FortiGate device belonging to an unnamed US retail company with reported revenue of $453.5 million, covering 378 hosts.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials