๐จ๐ง๐ด Instituto Tรฉcnico Los รngeles principal account and student database access advertised on a cybercrime forum
โ
A forum user claims to be selling access to a principal-level account belonging to Instituto Tรฉcnico Los รngeles in Bolivia, providing administrative control over the institution's student management system.
โ
The advertised access reportedly includes:
โ
โข Principal-level administrative access
โข Student database access
โข Personal student information
โข Academic records
โข Ability to modify student information
โข Ability to change grades
โข Degree and certificate issuance functions
โข Enrollment and registration management
โข Teacher administration
โข Course and program management
โข Access to institutional documents and statistics
โ
A screenshot provided as proof of access shows the institution's administrative dashboard and a grade certificate management interface containing student records.
โ
The seller states that the access will only remain available while the compromised account continues to work.
โ
The claims and the authenticity, availability and scope of the advertised access have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum user claims to be selling access to a principal-level account belonging to Instituto Tรฉcnico Los รngeles in Bolivia, providing administrative control over the institution's student management system.
โ
The advertised access reportedly includes:
โ
โข Principal-level administrative access
โข Student database access
โข Personal student information
โข Academic records
โข Ability to modify student information
โข Ability to change grades
โข Degree and certificate issuance functions
โข Enrollment and registration management
โข Teacher administration
โข Course and program management
โข Access to institutional documents and statistics
โ
A screenshot provided as proof of access shows the institution's administrative dashboard and a grade certificate management interface containing student records.
โ
The seller states that the access will only remain available while the compromised account continues to work.
โ
The claims and the authenticity, availability and scope of the advertised access have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โผ๏ธ New Dark Web Informer Blog Post!
Title: Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics
Link: https://darkwebinformer.com/developer-sought-on-a-breach-forum-to-build-a-mexican-kyc-bot-capturing-id-scans-and-face-biometrics/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics
Link: https://darkwebinformer.com/developer-sought-on-a-breach-forum-to-build-a-mexican-kyc-bot-capturing-id-scans-and-face-biometrics/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics
A member posting as Cookiegen131 is recruiting a developer to build a Telegram based identity verification system for a stated Mexican telecom project.
โผ๏ธ New Darknet Market: KONTOR Marketplace
Operator claims 400 buyers which I find hard to believe since this was just announced.
Dark Web: http://kontorvn7xkfebifxy7c5jgtjclur6twtiuivl34wodfam7wmrmw5cyd[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/f6fc6038002a27d9876b
Operator claims 400 buyers which I find hard to believe since this was just announced.
Dark Web: http://kontorvn7xkfebifxy7c5jgtjclur6twtiuivl34wodfam7wmrmw5cyd[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/f6fc6038002a27d9876b
โผ๏ธUnverified Claim... Possible Police Sting Operation
๐จ๐ท๐ด A Darknet user warns /u/RomanianPowder may be compromised in alleged Romanian police operation
Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/1bab89f8a3a2065b0c6e
โ
A darknet forum user is warning customers of RomanianPowder, claiming the vendor may have been infiltrated, arrested, or cooperating with Romanian authorities.
โ
According to the warning, an order allegedly arrived with a QR code directing the buyer to a Signal contact. The contact reportedly attempted to recruit the customer for local dead drops before offering to send another order directly at a cheaper price.
โ
The user claims:
โ
โข A QR code was included with the shipment
โข The QR code directed to a Signal account called "Flavour Man"
โข The Signal contact allegedly attempted to recruit them for dead drops
โข A subsequent package was delivered to a parcel locker
โข Police were allegedly positioned around the pickup location
โข Officers reportedly remained near the location for two days
โข The package was eventually returned after going uncollected
โข No payment was ever requested for the shipment
โข The Signal account subsequently went offline
โข RomanianPowder is currently shown as being on "vacation"
โ
The warning urges other Romanian customers not to scan QR codes or communicate with contacts associated with the deliveries.
โ
These allegations are based on an individual forum user's account and have not been independently verified. There is currently no confirmation that RomanianPowder is compromised or involved in a law enforcement operation.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ท๐ด A Darknet user warns /u/RomanianPowder may be compromised in alleged Romanian police operation
Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/1bab89f8a3a2065b0c6e
โ
A darknet forum user is warning customers of RomanianPowder, claiming the vendor may have been infiltrated, arrested, or cooperating with Romanian authorities.
โ
According to the warning, an order allegedly arrived with a QR code directing the buyer to a Signal contact. The contact reportedly attempted to recruit the customer for local dead drops before offering to send another order directly at a cheaper price.
โ
The user claims:
โ
โข A QR code was included with the shipment
โข The QR code directed to a Signal account called "Flavour Man"
โข The Signal contact allegedly attempted to recruit them for dead drops
โข A subsequent package was delivered to a parcel locker
โข Police were allegedly positioned around the pickup location
โข Officers reportedly remained near the location for two days
โข The package was eventually returned after going uncollected
โข No payment was ever requested for the shipment
โข The Signal account subsequently went offline
โข RomanianPowder is currently shown as being on "vacation"
โ
The warning urges other Romanian customers not to scan QR codes or communicate with contacts associated with the deliveries.
โ
These allegations are based on an individual forum user's account and have not been independently verified. There is currently no confirmation that RomanianPowder is compromised or involved in a law enforcement operation.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ง๐ท Quero Namoro allegedly breached, 19K Brazilian users and 5 GB website backup leaked on a cybercrime forum
โ
A forum user claims to have released a full website backup belonging to Quero Namoro, a Brazilian dating platform, containing information associated with approximately 19,000 users. The listing describes the complete backup as roughly 5 GB.
โ
The advertised data includes:
โ
โข Names
โข Email addresses
โข Password-related fields
โข Telephone and mobile numbers
โข Dates of birth
โข Gender information
โข Cities and states
โข Professions
โข Monthly income information
โข Physical address fields
โข Postal codes
โข Usernames
โข Account and profile information
โข User photographs
โข Registration and account activity metadata
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum user claims to have released a full website backup belonging to Quero Namoro, a Brazilian dating platform, containing information associated with approximately 19,000 users. The listing describes the complete backup as roughly 5 GB.
โ
The advertised data includes:
โ
โข Names
โข Email addresses
โข Password-related fields
โข Telephone and mobile numbers
โข Dates of birth
โข Gender information
โข Cities and states
โข Professions
โข Monthly income information
โข Physical address fields
โข Postal codes
โข Usernames
โข Account and profile information
โข User photographs
โข Registration and account activity metadata
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โผ๏ธ The IRS is warning cryptocurrency holders about fake, official-looking letters being mailed to victims and directing them to a fraudulent โDigital Asset Compliance Portal.โ
The letters contain a QR code that leads to a fake IRS website designed to collect sensitive information, potentially including personal details, wallet information, exchange credentials, and other account data.
The IRS says it does not operate a โDigital Asset Compliance Portalโ and did not send these letters.
Coinbase and DarkTower reportedly traced infrastructure linked to the campaign to a recently registered domain hosted in Romania.
If you receive one of these letters, do not scan the QR code, visit the linked website, or provide any information.
The letters contain a QR code that leads to a fake IRS website designed to collect sensitive information, potentially including personal details, wallet information, exchange credentials, and other account data.
The IRS says it does not operate a โDigital Asset Compliance Portalโ and did not send these letters.
Coinbase and DarkTower reportedly traced infrastructure linked to the campaign to a recently registered domain hosted in Romania.
If you receive one of these letters, do not scan the QR code, visit the linked website, or provide any information.
๐จ Adornis GmbH source code allegedly leaked on a cybercrime forum
โ
A forum actor claims to have released the source code for Adornis Engine, an internal application framework associated with Adornis GmbH / NDI New Digital Intelligence. The project is described as a modular TypeScript monorepo used to build business web applications.
โ
The allegedly leaked source code includes:
โ
โข Approximately 90 independent npm packages and modules
โข TypeScript-based full-stack framework components
โข Authentication and routing modules
โข MongoDB integration
โข BaseQL query layer
โข MCP server functionality for AI agents
โข AI and LLM integration modules
โข CRM and CMS functionality
โข Wiki, task and calendar modules
โข Chat and collaboration features
โข Expense reimbursement functionality
โข Electronic signature support
โข Survey and payment modules
โข EBICS banking functionality
โข Collaborative document editing
โข TinyMCE and Monaco-based editing components
โข Internationalization and translation support
โข Caching and analytics modules
โข Prometheus metrics integration
โข Testing utilities
โ
The listing describes Adornis Engine as an actively maintained internal framework used to rapidly build custom line-of-business applications.
โ
The claims and the authenticity, source and completeness of the allegedly leaked code have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum actor claims to have released the source code for Adornis Engine, an internal application framework associated with Adornis GmbH / NDI New Digital Intelligence. The project is described as a modular TypeScript monorepo used to build business web applications.
โ
The allegedly leaked source code includes:
โ
โข Approximately 90 independent npm packages and modules
โข TypeScript-based full-stack framework components
โข Authentication and routing modules
โข MongoDB integration
โข BaseQL query layer
โข MCP server functionality for AI agents
โข AI and LLM integration modules
โข CRM and CMS functionality
โข Wiki, task and calendar modules
โข Chat and collaboration features
โข Expense reimbursement functionality
โข Electronic signature support
โข Survey and payment modules
โข EBICS banking functionality
โข Collaborative document editing
โข TinyMCE and Monaco-based editing components
โข Internationalization and translation support
โข Caching and analytics modules
โข Prometheus metrics integration
โข Testing utilities
โ
The listing describes Adornis Engine as an actively maintained internal framework used to rapidly build custom line-of-business applications.
โ
The claims and the authenticity, source and completeness of the allegedly leaked code have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ฎ๐ณ University of Delhi database allegedly breached and advertised for sale on a cybercrime forum
โ
A forum user claims that LidaBroker and DYSPHOR1A breached the University of Delhi and are now selling data allegedly obtained from university systems.
โ
The exposed sample includes:
โ
โข Full names
โข Email addresses
โข Phone numbers
โข Student or applicant identifiers
โข Application and approval status
โข Departments
โข Academic programs and qualifications
โข Registration or enrollment references
โข Timestamps
โข Profile and document image filenames
โข University-hosted file and image references
โ
The listing includes sample records associated with multiple university departments and academic programs.
โ
The database is being advertised for $450, with the price stated as non-negotiable and middleman services accepted.
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
DYSPHOR1A Ransomware:
https://x.com/DarkWebInformer/status/2090460630583017979
โ
A forum user claims that LidaBroker and DYSPHOR1A breached the University of Delhi and are now selling data allegedly obtained from university systems.
โ
The exposed sample includes:
โ
โข Full names
โข Email addresses
โข Phone numbers
โข Student or applicant identifiers
โข Application and approval status
โข Departments
โข Academic programs and qualifications
โข Registration or enrollment references
โข Timestamps
โข Profile and document image filenames
โข University-hosted file and image references
โ
The listing includes sample records associated with multiple university departments and academic programs.
โ
The database is being advertised for $450, with the price stated as non-negotiable and middleman services accepted.
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
DYSPHOR1A Ransomware:
https://x.com/DarkWebInformer/status/2090460630583017979
โผ๏ธ New Dark Web Informer Blog Post!
Title: Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
Link: https://darkwebinformer.com/wrappiness-customer-database-allegedly-offered-for-sale-with-3-million-order-records/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
Link: https://darkwebinformer.com/wrappiness-customer-database-allegedly-offered-for-sale-with-3-million-order-records/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
A forum user posting as Satanic is selling what they describe as the full database of Wrappiness.co, a United States retailer of personalised and custom gifts including wood signs, ornaments and keychains.
๐จ๐น๐ญ๐ฎ๐ณ๐ธ๐ช๐ซ๐ท๐บ๐ธ Five corporate network accesses advertised on a cybercrime forum
โ
A forum broker is advertising access to five organizations across Thailand, India, Sweden, France and the United States, spanning the education, software, food and beverage, and business services sectors.
โ
The advertised accesses include:
โ
๐น๐ญ Thailand, Education: VPN access with Domain User privileges, approximately 250 hosts, 2,300 domain computers, 4 domain controllers, 5 MSSQL servers and Veeam infrastructure. Symantec, Trend Micro and Windows Defender are reportedly deployed. Revenue listed at approximately $6M.
โ
๐ฎ๐ณ India, Education: VPN access with standard user privileges. Revenue listed at approximately $100M. Antivirus and EDR information is listed as unknown.
โ
๐ธ๐ช Sweden, Software: Domain User access covering approximately 520 domain users, 350 domain computers, 3 domain controllers and an Entra ID environment. Windows Defender and Sophos Intercept X EDR are reportedly deployed. Revenue listed at approximately $25M.
โ
๐ซ๐ท France, Food and Beverage: VPN access with user-level privileges, approximately 100 hosts and 2 domain controllers. Revenue listed at approximately $40M.
โ
๐บ๐ธ United States, Business Services: VPN access with user-level privileges, approximately 120 hosts, 80 domain-joined machines, 4 domain controllers, 8 MSSQL servers and Veeam infrastructure. Revenue listed at approximately $10M.
โ
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum broker is advertising access to five organizations across Thailand, India, Sweden, France and the United States, spanning the education, software, food and beverage, and business services sectors.
โ
The advertised accesses include:
โ
๐น๐ญ Thailand, Education: VPN access with Domain User privileges, approximately 250 hosts, 2,300 domain computers, 4 domain controllers, 5 MSSQL servers and Veeam infrastructure. Symantec, Trend Micro and Windows Defender are reportedly deployed. Revenue listed at approximately $6M.
โ
๐ฎ๐ณ India, Education: VPN access with standard user privileges. Revenue listed at approximately $100M. Antivirus and EDR information is listed as unknown.
โ
๐ธ๐ช Sweden, Software: Domain User access covering approximately 520 domain users, 350 domain computers, 3 domain controllers and an Entra ID environment. Windows Defender and Sophos Intercept X EDR are reportedly deployed. Revenue listed at approximately $25M.
โ
๐ซ๐ท France, Food and Beverage: VPN access with user-level privileges, approximately 100 hosts and 2 domain controllers. Revenue listed at approximately $40M.
โ
๐บ๐ธ United States, Business Services: VPN access with user-level privileges, approximately 120 hosts, 80 domain-joined machines, 4 domain controllers, 8 MSSQL servers and Veeam infrastructure. Revenue listed at approximately $10M.
โ
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โผ๏ธ New Dark Web Informer Blog Post!
Title: French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys
Link: https://darkwebinformer.com/french-restaurant-platform-frenchinnov-allegedly-scraped-exposing-client-credentials-and-live-payment-keys/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys
Link: https://darkwebinformer.com/french-restaurant-platform-frenchinnov-allegedly-scraped-exposing-client-credentials-and-live-payment-keys/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys
A forum user posting as Alduin claims to have scraped the CRM behind frenchinnov.fr, a French platform that centralises restaurant operations including point of sale, stock, staff planning, loyalty and delivery platform integration.
Media is too big
VIEW IN TELEGRAM
Life Hackers: Inside the Real Lives of Cybersecurity Experts Across America
Video Credit: youtube.com/@Lufsec
Video Credit: youtube.com/@Lufsec
Forwarded from Dark Web Informer - Private
โผ๏ธ DOJ Press Release
โโโโโโโโโโโโโโโโโโโโโ
Colorado Man Convicted at Trial of Sexually Abusing a Child on Camera And Advertising the Videos for Sale Over the Dark Web
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
โโโโโโโโโโโโโโโโโโโโโ
Colorado Man Convicted at Trial of Sexually Abusing a Child on Camera And Advertising the Videos for Sale Over the Dark Web
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
Department of Justice
Colorado Man Convicted at Trial of Sexually Abusing a Child on Camera And Advertising the Videos for Sale Over the Dark Web
A federal jury convicted a Colorado man yesterday for conspiring with his wife to film themselves sexually abusing a prepubescent child in Mexico and for advertising the videos for sale online.