โผ๏ธ The IRS is warning cryptocurrency holders about fake, official-looking letters being mailed to victims and directing them to a fraudulent โDigital Asset Compliance Portal.โ
The letters contain a QR code that leads to a fake IRS website designed to collect sensitive information, potentially including personal details, wallet information, exchange credentials, and other account data.
The IRS says it does not operate a โDigital Asset Compliance Portalโ and did not send these letters.
Coinbase and DarkTower reportedly traced infrastructure linked to the campaign to a recently registered domain hosted in Romania.
If you receive one of these letters, do not scan the QR code, visit the linked website, or provide any information.
The letters contain a QR code that leads to a fake IRS website designed to collect sensitive information, potentially including personal details, wallet information, exchange credentials, and other account data.
The IRS says it does not operate a โDigital Asset Compliance Portalโ and did not send these letters.
Coinbase and DarkTower reportedly traced infrastructure linked to the campaign to a recently registered domain hosted in Romania.
If you receive one of these letters, do not scan the QR code, visit the linked website, or provide any information.
๐จ Adornis GmbH source code allegedly leaked on a cybercrime forum
โ
A forum actor claims to have released the source code for Adornis Engine, an internal application framework associated with Adornis GmbH / NDI New Digital Intelligence. The project is described as a modular TypeScript monorepo used to build business web applications.
โ
The allegedly leaked source code includes:
โ
โข Approximately 90 independent npm packages and modules
โข TypeScript-based full-stack framework components
โข Authentication and routing modules
โข MongoDB integration
โข BaseQL query layer
โข MCP server functionality for AI agents
โข AI and LLM integration modules
โข CRM and CMS functionality
โข Wiki, task and calendar modules
โข Chat and collaboration features
โข Expense reimbursement functionality
โข Electronic signature support
โข Survey and payment modules
โข EBICS banking functionality
โข Collaborative document editing
โข TinyMCE and Monaco-based editing components
โข Internationalization and translation support
โข Caching and analytics modules
โข Prometheus metrics integration
โข Testing utilities
โ
The listing describes Adornis Engine as an actively maintained internal framework used to rapidly build custom line-of-business applications.
โ
The claims and the authenticity, source and completeness of the allegedly leaked code have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum actor claims to have released the source code for Adornis Engine, an internal application framework associated with Adornis GmbH / NDI New Digital Intelligence. The project is described as a modular TypeScript monorepo used to build business web applications.
โ
The allegedly leaked source code includes:
โ
โข Approximately 90 independent npm packages and modules
โข TypeScript-based full-stack framework components
โข Authentication and routing modules
โข MongoDB integration
โข BaseQL query layer
โข MCP server functionality for AI agents
โข AI and LLM integration modules
โข CRM and CMS functionality
โข Wiki, task and calendar modules
โข Chat and collaboration features
โข Expense reimbursement functionality
โข Electronic signature support
โข Survey and payment modules
โข EBICS banking functionality
โข Collaborative document editing
โข TinyMCE and Monaco-based editing components
โข Internationalization and translation support
โข Caching and analytics modules
โข Prometheus metrics integration
โข Testing utilities
โ
The listing describes Adornis Engine as an actively maintained internal framework used to rapidly build custom line-of-business applications.
โ
The claims and the authenticity, source and completeness of the allegedly leaked code have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ฎ๐ณ University of Delhi database allegedly breached and advertised for sale on a cybercrime forum
โ
A forum user claims that LidaBroker and DYSPHOR1A breached the University of Delhi and are now selling data allegedly obtained from university systems.
โ
The exposed sample includes:
โ
โข Full names
โข Email addresses
โข Phone numbers
โข Student or applicant identifiers
โข Application and approval status
โข Departments
โข Academic programs and qualifications
โข Registration or enrollment references
โข Timestamps
โข Profile and document image filenames
โข University-hosted file and image references
โ
The listing includes sample records associated with multiple university departments and academic programs.
โ
The database is being advertised for $450, with the price stated as non-negotiable and middleman services accepted.
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
DYSPHOR1A Ransomware:
https://x.com/DarkWebInformer/status/2090460630583017979
โ
A forum user claims that LidaBroker and DYSPHOR1A breached the University of Delhi and are now selling data allegedly obtained from university systems.
โ
The exposed sample includes:
โ
โข Full names
โข Email addresses
โข Phone numbers
โข Student or applicant identifiers
โข Application and approval status
โข Departments
โข Academic programs and qualifications
โข Registration or enrollment references
โข Timestamps
โข Profile and document image filenames
โข University-hosted file and image references
โ
The listing includes sample records associated with multiple university departments and academic programs.
โ
The database is being advertised for $450, with the price stated as non-negotiable and middleman services accepted.
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
DYSPHOR1A Ransomware:
https://x.com/DarkWebInformer/status/2090460630583017979
โผ๏ธ New Dark Web Informer Blog Post!
Title: Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
Link: https://darkwebinformer.com/wrappiness-customer-database-allegedly-offered-for-sale-with-3-million-order-records/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
Link: https://darkwebinformer.com/wrappiness-customer-database-allegedly-offered-for-sale-with-3-million-order-records/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
A forum user posting as Satanic is selling what they describe as the full database of Wrappiness.co, a United States retailer of personalised and custom gifts including wood signs, ornaments and keychains.
๐จ๐น๐ญ๐ฎ๐ณ๐ธ๐ช๐ซ๐ท๐บ๐ธ Five corporate network accesses advertised on a cybercrime forum
โ
A forum broker is advertising access to five organizations across Thailand, India, Sweden, France and the United States, spanning the education, software, food and beverage, and business services sectors.
โ
The advertised accesses include:
โ
๐น๐ญ Thailand, Education: VPN access with Domain User privileges, approximately 250 hosts, 2,300 domain computers, 4 domain controllers, 5 MSSQL servers and Veeam infrastructure. Symantec, Trend Micro and Windows Defender are reportedly deployed. Revenue listed at approximately $6M.
โ
๐ฎ๐ณ India, Education: VPN access with standard user privileges. Revenue listed at approximately $100M. Antivirus and EDR information is listed as unknown.
โ
๐ธ๐ช Sweden, Software: Domain User access covering approximately 520 domain users, 350 domain computers, 3 domain controllers and an Entra ID environment. Windows Defender and Sophos Intercept X EDR are reportedly deployed. Revenue listed at approximately $25M.
โ
๐ซ๐ท France, Food and Beverage: VPN access with user-level privileges, approximately 100 hosts and 2 domain controllers. Revenue listed at approximately $40M.
โ
๐บ๐ธ United States, Business Services: VPN access with user-level privileges, approximately 120 hosts, 80 domain-joined machines, 4 domain controllers, 8 MSSQL servers and Veeam infrastructure. Revenue listed at approximately $10M.
โ
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum broker is advertising access to five organizations across Thailand, India, Sweden, France and the United States, spanning the education, software, food and beverage, and business services sectors.
โ
The advertised accesses include:
โ
๐น๐ญ Thailand, Education: VPN access with Domain User privileges, approximately 250 hosts, 2,300 domain computers, 4 domain controllers, 5 MSSQL servers and Veeam infrastructure. Symantec, Trend Micro and Windows Defender are reportedly deployed. Revenue listed at approximately $6M.
โ
๐ฎ๐ณ India, Education: VPN access with standard user privileges. Revenue listed at approximately $100M. Antivirus and EDR information is listed as unknown.
โ
๐ธ๐ช Sweden, Software: Domain User access covering approximately 520 domain users, 350 domain computers, 3 domain controllers and an Entra ID environment. Windows Defender and Sophos Intercept X EDR are reportedly deployed. Revenue listed at approximately $25M.
โ
๐ซ๐ท France, Food and Beverage: VPN access with user-level privileges, approximately 100 hosts and 2 domain controllers. Revenue listed at approximately $40M.
โ
๐บ๐ธ United States, Business Services: VPN access with user-level privileges, approximately 120 hosts, 80 domain-joined machines, 4 domain controllers, 8 MSSQL servers and Veeam infrastructure. Revenue listed at approximately $10M.
โ
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โผ๏ธ New Dark Web Informer Blog Post!
Title: French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys
Link: https://darkwebinformer.com/french-restaurant-platform-frenchinnov-allegedly-scraped-exposing-client-credentials-and-live-payment-keys/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys
Link: https://darkwebinformer.com/french-restaurant-platform-frenchinnov-allegedly-scraped-exposing-client-credentials-and-live-payment-keys/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys
A forum user posting as Alduin claims to have scraped the CRM behind frenchinnov.fr, a French platform that centralises restaurant operations including point of sale, stock, staff planning, loyalty and delivery platform integration.
Media is too big
VIEW IN TELEGRAM
Life Hackers: Inside the Real Lives of Cybersecurity Experts Across America
Video Credit: youtube.com/@Lufsec
Video Credit: youtube.com/@Lufsec
Forwarded from Dark Web Informer - Private
โผ๏ธ DOJ Press Release
โโโโโโโโโโโโโโโโโโโโโ
Colorado Man Convicted at Trial of Sexually Abusing a Child on Camera And Advertising the Videos for Sale Over the Dark Web
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
โโโโโโโโโโโโโโโโโโโโโ
Colorado Man Convicted at Trial of Sexually Abusing a Child on Camera And Advertising the Videos for Sale Over the Dark Web
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
Department of Justice
Colorado Man Convicted at Trial of Sexually Abusing a Child on Camera And Advertising the Videos for Sale Over the Dark Web
A federal jury convicted a Colorado man yesterday for conspiring with his wife to film themselves sexually abusing a prepubescent child in Mexico and for advertising the videos for sale online.
โผ๏ธ New Dark Web Informer Blog Post!
Title: Bergerat Rent Data Allegedly Leaked in Eleventh Release, With the Shared Platform Now Named
Link: https://darkwebinformer.com/bergerat-rent-data-allegedly-leaked-in-eleventh-release-with-the-shared-platform-now-named/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Bergerat Rent Data Allegedly Leaked in Eleventh Release, With the Shared Platform Now Named
Link: https://darkwebinformer.com/bergerat-rent-data-allegedly-leaked-in-eleventh-release-with-the-shared-platform-now-named/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Bergerat Rent Data Allegedly Leaked in Eleventh Release, With the Shared Platform Now Named
A forum user posting as ChimeraZ has published what they describe as the database of bergerat-rent.com, a French company renting construction, industrial and handling equipment, comprising 43GB across 132,433 files.
โผ๏ธ๐ฎ๐น xpl0itrs names an Italian education technology
๐ฎ๐น Gruppo Spaggiari Parma - An Italian education technology company providing school management and digital register platforms.
The listing claims 6.1 TB of data affecting 3,000+ schools, including student medical data, teacher resumes, dates of birth, addresses, employment history, driverโs licenses, emails, phone numbers, and other personal information.
๐ฎ๐น Gruppo Spaggiari Parma - An Italian education technology company providing school management and digital register platforms.
The listing claims 6.1 TB of data affecting 3,000+ schools, including student medical data, teacher resumes, dates of birth, addresses, employment history, driverโs licenses, emails, phone numbers, and other personal information.
"unlikely to be many people in my area using Tor"
Says the guy saying that. You now claim to be in a small area, much bigger chance LEA would want to make an example out of you
Dread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/c959a828a2c8254ff316
Says the guy saying that. You now claim to be in a small area, much bigger chance LEA would want to make an example out of you
Dread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/c959a828a2c8254ff316