βΌοΈ New Dark Web Informer Blog Post!
Title: Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers
Link: https://darkwebinformer.com/argentine-hardware-wallet-retailer-allegedly-exposed-linking-named-buyers-to-home-addresses-and-id-numbers/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers
Link: https://darkwebinformer.com/argentine-hardware-wallet-retailer-allegedly-exposed-linking-named-buyers-to-home-addresses-and-id-numbers/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers
A forum user posting as kingloki is offering what they describe as a complete order export from coincustody.io, an Argentine reseller of Trezor and Ledger hardware wallets, covering 212 orders placed between May 2025 and August 2026.
π¨ Moondancer ransomware group recruiting affiliates on a cybercrime forum
β
A forum actor is promoting a ransomware operation called Moondancer and says the group is actively recruiting affiliates to participate in attacks against organizations across Latin America.
β
The recruitment post claims:
β
β’ Operations are focused on Latin American companies
β’ Priority is given to organizations dependent on critical infrastructure and continuous uptime
β’ Healthcare services are explicitly excluded from targeting
β’ Affiliates can join without an upfront fee
β’ Applicants are expected to provide value to the group
β’ Additional details are hidden behind forum content
β’ Contact is offered through Telegram and Tox
β
The group describes the campaign as a "big game hunting" operation and appears to be seeking partners capable of helping expand its ransomware activity.
β
The claims and the capabilities, membership and operational scope of Moondancer have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor is promoting a ransomware operation called Moondancer and says the group is actively recruiting affiliates to participate in attacks against organizations across Latin America.
β
The recruitment post claims:
β
β’ Operations are focused on Latin American companies
β’ Priority is given to organizations dependent on critical infrastructure and continuous uptime
β’ Healthcare services are explicitly excluded from targeting
β’ Affiliates can join without an upfront fee
β’ Applicants are expected to provide value to the group
β’ Additional details are hidden behind forum content
β’ Contact is offered through Telegram and Tox
β
The group describes the campaign as a "big game hunting" operation and appears to be seeking partners capable of helping expand its ransomware activity.
β
The claims and the capabilities, membership and operational scope of Moondancer have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨ππ· Croatian Pension Insurance Institute allegedly breached, 105K records leaked on a cybercrime forum
β
A group identifying itself as INF GRUPA claims to have breached the Croatian Pension Insurance Institute (HZMO) and extracted personal information belonging to approximately 105,000 Croatian citizens.
β
The advertised data includes:
β
β’ Full names and surnames
β’ Phone numbers
β’ OIB personal identification numbers
β’ Email addresses
β
INF GRUPA says the dataset is being released for free and claims the operation was not financially motivated. The group states that it is not seeking a ransom or cryptocurrency payment and describes the breach as part of a broader campaign targeting Croatian institutions.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A group identifying itself as INF GRUPA claims to have breached the Croatian Pension Insurance Institute (HZMO) and extracted personal information belonging to approximately 105,000 Croatian citizens.
β
The advertised data includes:
β
β’ Full names and surnames
β’ Phone numbers
β’ OIB personal identification numbers
β’ Email addresses
β
INF GRUPA says the dataset is being released for free and claims the operation was not financially motivated. The group states that it is not seeking a ransom or cryptocurrency payment and describes the breach as part of a broader campaign targeting Croatian institutions.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π«π· Sport 2000 internal booking system allegedly breached, complete database released on a cybercrime forum
β
A forum actor claims to have breached Sport 2000's internal booking system, known as Pilot, and extracted reservation data from the platform. The alleged breach is dated August 19, 2026, with the released dataset containing 17,851 records.
β
The exposed data reportedly includes:
β
β’ Customer information
β’ Booking and reservation records
β’ Product information
β’ Transaction amounts
β’ Valid and cancelled bookings
β’ Legacy booking references
β’ Full reservation detail records
β
According to the listing, approximately 14,500 valid bookings were obtained from a bulk export, while roughly 3,350 cancelled bookings were collected individually because they were not included in the export. Around 700 older bookings were also reportedly matched to their corresponding records using legacy reference numbers.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have breached Sport 2000's internal booking system, known as Pilot, and extracted reservation data from the platform. The alleged breach is dated August 19, 2026, with the released dataset containing 17,851 records.
β
The exposed data reportedly includes:
β
β’ Customer information
β’ Booking and reservation records
β’ Product information
β’ Transaction amounts
β’ Valid and cancelled bookings
β’ Legacy booking references
β’ Full reservation detail records
β
According to the listing, approximately 14,500 valid bookings were obtained from a bulk export, while roughly 3,350 cancelled bookings were collected individually because they were not included in the export. Around 700 older bookings were also reportedly matched to their corresponding records using legacy reference numbers.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Securo: Self-hosted, privacy-first open-source personal finance manager.
GitHub: https://github.com/securo-finance/securo
GitHub: https://github.com/securo-finance/securo
β€1
βΌοΈ New Dark Web Informer Blog Post!
Title: CareCloud Data Breach Exposes Medical Records of More Than 3.75 Million Patients
Link: https://darkwebinformer.com/carecloud-data-breach-exposes-medical-records-of-more-than-3-75-million-patients/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: CareCloud Data Breach Exposes Medical Records of More Than 3.75 Million Patients
Link: https://darkwebinformer.com/carecloud-data-breach-exposes-medical-records-of-more-than-3-75-million-patients/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
CareCloud Data Breach Exposes Medical Records of More Than 3.75 Million Patients
Healthcare technology company CareCloud has confirmed that hackers stole personal information and medical records belonging to more than 3.75 million people during a cyberattack earlier this year.
π¨ Public PoC available for high-severity Android ContactsProvider flaw
https://github.com/qm4rs/cve-2026-0075
CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction.
Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS.
The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel.
Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers.
The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device.
Devices with the June 5, 2026 Android security patch level or later address the issue.
https://github.com/qm4rs/cve-2026-0075
CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction.
Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS.
The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel.
Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers.
The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device.
Devices with the June 5, 2026 Android security patch level or later address the issue.
Tails 7.11 has been released... update if you haven't already done so.
https://tails.net/news/version_7.11/
https://tails.net/news/version_7.11/
βΌοΈ A forum actor advertises the sale of RDP and VPN access, offering to use a guarantor (escrow) for the transaction.
No specific victim organization or details are provided.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
No specific victim organization or details are provided.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
βΌοΈπΊπΈ A forum actor is offering for sale super_admin-level SSH access to a FortiGate device belonging to an unnamed US retail company with reported revenue of $453.5 million, covering 378 hosts.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨ WP-Admin, cPanel, Plesk and WHM administrative access advertised for sale on a cybercrime forum
β
A forum seller is advertising compromised administrative access to websites and hosting control panels, claiming the credentials are valid and provide full administrator privileges.
β
The advertised access includes:
β
β’ WordPress administrator accounts with plugin installation privileges
β’ cPanel accounts with verified panel access and no 2FA
β’ Plesk accounts with verified panel access and no 2FA
β’ WHM accounts with verified panel access and no 2FA
β’ Login credentials included with each access
β
Pricing is advertised at $1 per WordPress admin, $3 per cPanel account, $3 per Plesk account and $25 per WHM account. The listing requires a $200 minimum purchase, with escrow available at the buyer's expense.
β
The seller states that website characteristics, domains and SEO metrics have not been pre-screened.
β
The claims and the authenticity, availability and scope of the advertised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum seller is advertising compromised administrative access to websites and hosting control panels, claiming the credentials are valid and provide full administrator privileges.
β
The advertised access includes:
β
β’ WordPress administrator accounts with plugin installation privileges
β’ cPanel accounts with verified panel access and no 2FA
β’ Plesk accounts with verified panel access and no 2FA
β’ WHM accounts with verified panel access and no 2FA
β’ Login credentials included with each access
β
Pricing is advertised at $1 per WordPress admin, $3 per cPanel account, $3 per Plesk account and $25 per WHM account. The listing requires a $200 minimum purchase, with escrow available at the buyer's expense.
β
The seller states that website characteristics, domains and SEO metrics have not been pre-screened.
β
The claims and the authenticity, availability and scope of the advertised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ EliteCrypt malware crypter and loader advertised on a cybercrime forum with Windows security bypass claims
β
A forum seller is advertising EliteCrypt, a malware crypter and loader service designed to conceal malicious payloads and bypass Windows security controls during both scan-time and runtime execution.
β
The advertised features include:
β
β’ Windows Defender 10/11 bypass
β’ Microsoft SmartScreen bypass
β’ Chrome security bypass claims
β’ UAC bypass
β’ Scan-time and runtime evasion
β’ Support for stealers, RATs and cryptocurrency miners
β’ Compatibility with Vidar, WebRAT, DCRat, HVNC, Stealc and other payloads
β’ Native x64, x86 and .NET support
β’ C-based loader stub
β’ Unique builds rather than a shared static stub
β’ DLL sideloading functionality
β’ .LNK payload delivery
β’ Ability to disguise .LNK loaders as PDF, DOCX, TXT and XLSX files
β
Pricing is advertised at $37 for the standard crypt, $75 for DLL sideloading and $80 for the .LNK loader.
β
The seller's claims and the capabilities of the tool have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum seller is advertising EliteCrypt, a malware crypter and loader service designed to conceal malicious payloads and bypass Windows security controls during both scan-time and runtime execution.
β
The advertised features include:
β
β’ Windows Defender 10/11 bypass
β’ Microsoft SmartScreen bypass
β’ Chrome security bypass claims
β’ UAC bypass
β’ Scan-time and runtime evasion
β’ Support for stealers, RATs and cryptocurrency miners
β’ Compatibility with Vidar, WebRAT, DCRat, HVNC, Stealc and other payloads
β’ Native x64, x86 and .NET support
β’ C-based loader stub
β’ Unique builds rather than a shared static stub
β’ DLL sideloading functionality
β’ .LNK payload delivery
β’ Ability to disguise .LNK loaders as PDF, DOCX, TXT and XLSX files
β
Pricing is advertised at $37 for the standard crypt, $75 for DLL sideloading and $80 for the .LNK loader.
β
The seller's claims and the capabilities of the tool have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
βΌοΈ New Dark Web Informer Blog Post!
Title: Solana Asset Discovery Service Advertised on a Criminal Forum With Bulk Wallet Scanning
Link: https://darkwebinformer.com/solana-asset-discovery-service-advertised-on-a-criminal-forum-with-bulk-wallet-scanning/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Solana Asset Discovery Service Advertised on a Criminal Forum With Bulk Wallet Scanning
Link: https://darkwebinformer.com/solana-asset-discovery-service-advertised-on-a-criminal-forum-with-bulk-wallet-scanning/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Solana Asset Discovery Service Advertised on a Criminal Forum With Bulk Wallet Scanning
A newly registered user posting as danbalan is advertising Checkermax, a subscription service that scans Solana wallet addresses for holdings not visible in a standard balance view.
π¨ Bugatti Cloud credential log distribution service advertised on a cybercrime forum
β
A forum user is promoting Bugatti Cloud, a service distributing credential logs and other compromised data. The operator claims the project has attracted more than 2,000 users and has published over 1 million logs since launching.
β
The advertised features include:
β
β’ More than 1 million previously published logs
β’ 10+ GB of new material reportedly added each week
β’ Logs collected from multiple sources
β’ SEO-related logs
β’ YouTube-related logs
β’ Cryptocurrency exchange-related logs
β’ Access to downloadable log archives
β’ Extended exports and "HQ combo" datasets
β’ Community access and active support
β’ Private access through Bugatti Private Cloud
β’ Exclusive material reportedly added every 2 days
β’ Personalized support and potential collaboration opportunities
β
The operator's claims and the authenticity, source and scope of the advertised logs have not been independently verified.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
β
A forum user is promoting Bugatti Cloud, a service distributing credential logs and other compromised data. The operator claims the project has attracted more than 2,000 users and has published over 1 million logs since launching.
β
The advertised features include:
β
β’ More than 1 million previously published logs
β’ 10+ GB of new material reportedly added each week
β’ Logs collected from multiple sources
β’ SEO-related logs
β’ YouTube-related logs
β’ Cryptocurrency exchange-related logs
β’ Access to downloadable log archives
β’ Extended exports and "HQ combo" datasets
β’ Community access and active support
β’ Private access through Bugatti Private Cloud
β’ Exclusive material reportedly added every 2 days
β’ Personalized support and potential collaboration opportunities
β
The operator's claims and the authenticity, source and scope of the advertised logs have not been independently verified.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
Kriminal AI: "The AI That Answers Everything"
https://kriminal[.]ai
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
https://kriminal[.]ai
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
β€3π₯1
The fake X account claiming to be the Grand Theft Auto 6 leakers was just suspended by X.
x.com/cyberleek_ar_io
x.com/cyberleek_ar_io
π2β€1
π¨π«π· Alaxione allegedly breached, 6.8M patient records and 10.1M appointment records advertised on a cybercrime forum
β
A forum actor claims to have breached Alaxione, a French e-health company, and extracted approximately 12.8 GB of data spanning more than 18 million records. The listing claims the compromised data includes 6,835,489 patient/user records and 10,145,988 appointment records.
β
The advertised data includes:
β
β’ First and last names
β’ Email and billing email addresses
β’ Phone and fax numbers
β’ Dates of birth
β’ Gender information
β’ Physical addresses and postal codes
β’ Cities and professions
β’ Account identifiers and user roles
β’ Healthcare practitioner information
β’ Insurance and healthcare-related fields
β’ Appointment dates and times
β’ Patient and practitioner identifiers
β’ Appointment locations and statuses
β’ Appointment reasons and results
β’ Waiting-time information
β’ Discussion and messaging records
β’ Internal application and account metadata
β
The listing also references two discussion datasets containing approximately 144,310 and 129,729 records, along with additional practitioner-related information. Samples from multiple datasets were published directly in the thread.
β
The data is being offered for $5,000 without exclusivity, with a higher price requested for an exclusive sale.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have breached Alaxione, a French e-health company, and extracted approximately 12.8 GB of data spanning more than 18 million records. The listing claims the compromised data includes 6,835,489 patient/user records and 10,145,988 appointment records.
β
The advertised data includes:
β
β’ First and last names
β’ Email and billing email addresses
β’ Phone and fax numbers
β’ Dates of birth
β’ Gender information
β’ Physical addresses and postal codes
β’ Cities and professions
β’ Account identifiers and user roles
β’ Healthcare practitioner information
β’ Insurance and healthcare-related fields
β’ Appointment dates and times
β’ Patient and practitioner identifiers
β’ Appointment locations and statuses
β’ Appointment reasons and results
β’ Waiting-time information
β’ Discussion and messaging records
β’ Internal application and account metadata
β
The listing also references two discussion datasets containing approximately 144,310 and 129,729 records, along with additional practitioner-related information. Samples from multiple datasets were published directly in the thread.
β
The data is being offered for $5,000 without exclusivity, with a higher price requested for an exclusive sale.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯1
More shiity OpSec...
π¨ Investigators may have left the Coldcard Wave 1 hacker with nowhere to hide
The attacker behind the largest wave of the Coldcard Bitcoin theft allegedly used a paid account at a major blockchain data provider while preparing and carrying out the drains.
Block investigators found that the providerβs internal logs closely matched the number, timing, and sequence of queries associated with the theft. Information connected to the account was then provided to law enforcement.
Wave 1 drained 1,082.65 BTC from vulnerable wallets in just 41 minutes. The stolen Bitcoin remains largely unmoved.
Galaxy Researchβs Alex Thorn says the Wave 1 attackerβs identity βmay be known to law enforcement,β although the FBI has not publicly confirmed identifying, arresting, or charging anyone.
The theft exploited weak wallet seeds generated by affected Coldcard firmware after a 2021 random-number generation flaw reduced their effective entropy.
Multiple attack waves have since pushed confirmed losses beyond 1,700 BTC.
The blockchain may be public, but apparently the hackerβs API bill was too.
Source: https://bitcoinmagazine.com/technical/hunting-down-the-coldcard-hacker-wave-1-thief-may-be-known-to-fbi
π¨ Investigators may have left the Coldcard Wave 1 hacker with nowhere to hide
The attacker behind the largest wave of the Coldcard Bitcoin theft allegedly used a paid account at a major blockchain data provider while preparing and carrying out the drains.
Block investigators found that the providerβs internal logs closely matched the number, timing, and sequence of queries associated with the theft. Information connected to the account was then provided to law enforcement.
Wave 1 drained 1,082.65 BTC from vulnerable wallets in just 41 minutes. The stolen Bitcoin remains largely unmoved.
Galaxy Researchβs Alex Thorn says the Wave 1 attackerβs identity βmay be known to law enforcement,β although the FBI has not publicly confirmed identifying, arresting, or charging anyone.
The theft exploited weak wallet seeds generated by affected Coldcard firmware after a 2021 random-number generation flaw reduced their effective entropy.
Multiple attack waves have since pushed confirmed losses beyond 1,700 BTC.
The blockchain may be public, but apparently the hackerβs API bill was too.
Source: https://bitcoinmagazine.com/technical/hunting-down-the-coldcard-hacker-wave-1-thief-may-be-known-to-fbi
Bitcoin Magazine
The Coldcard Hacker Left A Paper Trail That May Already Be In Law Enforcement Hands
Shared GPG keys, matching patterns, and a bug that produced exactly the outcome Coinkite once warned about. The public record is thinβbut not empty.
π1π1