Who the fuck just wakes up one day and is like... fuck it I'm going to leak GTA 6 gameplay and go to prison for it.
π5π3
βΌοΈ New Dark Web Informer Blog Post!
Title: French Beauty Retailer Data Allegedly Up for Sale, With the Seller Crediting a Third Party Source
Link: https://darkwebinformer.com/french-beauty-retailer-data-allegedly-up-for-sale-with-the-seller-crediting-a-third-party-source/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: French Beauty Retailer Data Allegedly Up for Sale, With the Seller Crediting a Third Party Source
Link: https://darkwebinformer.com/french-beauty-retailer-data-allegedly-up-for-sale-with-the-seller-crediting-a-third-party-source/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
French Beauty Retailer Data Allegedly Up for Sale, With the Seller Crediting a Third Party Source
A forum user posting as misere is selling what they describe as the database of beautysuccess.fr, a French beauty and cosmetics retailer, listing 10,279,819 total records reducing to 5,169,727 unique.
βΌοΈ New Dark Web Informer Blog Post!
Title: Bureau VallΓ©e Customer Data Allegedly Taken From a Supplier That Exported Every Store Daily
Link: https://darkwebinformer.com/bureau-vallee-customer-data-allegedly-taken-from-a-supplier-that-exported-every-store-daily/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Bureau VallΓ©e Customer Data Allegedly Taken From a Supplier That Exported Every Store Daily
Link: https://darkwebinformer.com/bureau-vallee-customer-data-allegedly-taken-from-a-supplier-that-exported-every-store-daily/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Bureau VallΓ©e Customer Data Allegedly Taken From a Supplier That Exported Every Store Daily
A forum user posting as misere is selling what they describe as the customer database of bureau-vallee.fr, a French office supplies chain, listing 13,725,669 total records reducing to 4,819,927 unique.
Fixed a bug in the API that was causing ransomware screenshots to remain null if they weren't successfully captured during the initial scrape, even if the screenshot was captured successfully afterward.
Screenshot URLs are now displaying properly for each claim. If you still see null, it means I don't currently have a scraper for that particular ransomware group.
Screenshot URLs are now displaying properly for each claim. If you still see null, it means I don't currently have a scraper for that particular ransomware group.
β€1
π¨π²π½ Municipal Government of Altamira allegedly breached, database and admin access leaked on a cybercrime forum
β
A forum user claims to have compromised the Municipal Government of Altamira, Tamaulipas, Mexico, releasing access and data allegedly taken from an active government server. The breach is dated August 14, 2026.
β
The advertised access and data includes:
β
β’ Administrative username and password credentials
β’ Active JWT session cookie
β’ Server technology information
β’ Access to an official DIF travel database
β’ Travel and trip records
β’ Travel expense information
β’ Reimbursement records
β’ Traveler information
β’ Locations and dates
β’ Financial amount fields
β
The claims and the authenticity, source and scope of the allegedly exposed data and administrative access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum user claims to have compromised the Municipal Government of Altamira, Tamaulipas, Mexico, releasing access and data allegedly taken from an active government server. The breach is dated August 14, 2026.
β
The advertised access and data includes:
β
β’ Administrative username and password credentials
β’ Active JWT session cookie
β’ Server technology information
β’ Access to an official DIF travel database
β’ Travel and trip records
β’ Travel expense information
β’ Reimbursement records
β’ Traveler information
β’ Locations and dates
β’ Financial amount fields
β
The claims and the authenticity, source and scope of the allegedly exposed data and administrative access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
CYBERLEEK.. create a PGP and sign your messages.
π6β€2
π¨π«π· SQL injection access targeting Solimut Mutuelle de France advertised for sale on a cybercrime forum
β
A forum actor is advertising an SQL injection vulnerability affecting Solimut Mutuelle de France, a French nonprofit mutual insurance organization. The listing claims the underlying database is too large and the connection too slow to extract in full, so access to the vulnerability itself is being offered instead.
β
The advertised access reportedly includes:
β
β’ Error-based SQL injection
β’ Sybase database backend
β’ Access to a main database containing 1,074 tables
β’ A sample table containing 770,467 entries
β’ Customer names
β’ IBANs
β’ BICs
β’ Internal identifiers
β’ Additional member-related records
β
The listing references Solimut Mutuelle de France as having approximately 770,000 members and includes a sample of records allegedly retrieved through the vulnerable system.
β
The claims and the authenticity, availability and scope of the advertised SQL injection access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor is advertising an SQL injection vulnerability affecting Solimut Mutuelle de France, a French nonprofit mutual insurance organization. The listing claims the underlying database is too large and the connection too slow to extract in full, so access to the vulnerability itself is being offered instead.
β
The advertised access reportedly includes:
β
β’ Error-based SQL injection
β’ Sybase database backend
β’ Access to a main database containing 1,074 tables
β’ A sample table containing 770,467 entries
β’ Customer names
β’ IBANs
β’ BICs
β’ Internal identifiers
β’ Additional member-related records
β
The listing references Solimut Mutuelle de France as having approximately 770,000 members and includes a sample of records allegedly retrieved through the vulnerable system.
β
The claims and the authenticity, availability and scope of the advertised SQL injection access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π«π· DRON Location allegedly breached, 44 GB of data leaked on a cybercrime forum
β
A forum actor claims to have leaked data allegedly belonging to DRON Location, a French company specializing in equipment rental for construction, industry, public authorities and events. The release is labeled "BlgCloud Leak #12" and is described as part of a wider series of alleged breaches.
β
The leak reportedly contains approximately 44 GB of data across 49,035 files.
β
The exposed data shown in the samples includes:
β
β’ Internal email communications
β’ Customer and CRM records
β’ Employee and contact information
β’ Names and business email addresses
β’ Phone numbers
β’ Physical addresses
β’ Company registration information
β’ IBAN and BIC banking details
β’ Customer and supplier references
β’ Contracts and commercial documents
β’ PDF attachments
β’ Document images
β’ File names, hashes and storage paths
β’ Internal record and account identifiers
β
The thread includes samples of internal emails, CRM records and documents allegedly taken from the company's systems.
β
The listing also identifies Bernard Groupe as the intended target of the next release in the same leak series.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have leaked data allegedly belonging to DRON Location, a French company specializing in equipment rental for construction, industry, public authorities and events. The release is labeled "BlgCloud Leak #12" and is described as part of a wider series of alleged breaches.
β
The leak reportedly contains approximately 44 GB of data across 49,035 files.
β
The exposed data shown in the samples includes:
β
β’ Internal email communications
β’ Customer and CRM records
β’ Employee and contact information
β’ Names and business email addresses
β’ Phone numbers
β’ Physical addresses
β’ Company registration information
β’ IBAN and BIC banking details
β’ Customer and supplier references
β’ Contracts and commercial documents
β’ PDF attachments
β’ Document images
β’ File names, hashes and storage paths
β’ Internal record and account identifiers
β
The thread includes samples of internal emails, CRM records and documents allegedly taken from the company's systems.
β
The listing also identifies Bernard Groupe as the intended target of the next release in the same leak series.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ ImbrellaPacker multi-stage payload packer advertised on a cybercrime forum with EDR evasion claims
β
A forum seller is advertising ImbrellaPacker, a multi-stage packing service designed to modify Cobalt Strike beacon payloads and improve their ability to evade modern endpoint detection and response products.
β
The advertised features include:
β
β’ One-click upload, processing and download workflow
β’ Preconfigured Cobalt Strike profiles
β’ Separate configurations for different EDR products
β’ Quick and advanced build modes
β’ Polymorphic builds intended to reduce signature-based detection
β’ More than 10 advertised execution methods
β’ Multiple allocation methods
β’ Anti-sandbox functionality
β’ Anti-debug functionality
β’ Domain-check options
β’ Multiple delivery and export configurations
β’ Private web-based dashboard and builder
β
The service claims to have been tested against CrowdStrike, SentinelOne, Cortex, Sophos and Microsoft Defender for Endpoint.
β
Pricing is advertised at $2,000 per month for up to 10 builds per day or $7,000 for permanent access with unlimited builds. Free demonstrations are reportedly available to established forum users and prospective buyers.
β
The seller's claims and the effectiveness of the advertised EDR evasion capabilities have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum seller is advertising ImbrellaPacker, a multi-stage packing service designed to modify Cobalt Strike beacon payloads and improve their ability to evade modern endpoint detection and response products.
β
The advertised features include:
β
β’ One-click upload, processing and download workflow
β’ Preconfigured Cobalt Strike profiles
β’ Separate configurations for different EDR products
β’ Quick and advanced build modes
β’ Polymorphic builds intended to reduce signature-based detection
β’ More than 10 advertised execution methods
β’ Multiple allocation methods
β’ Anti-sandbox functionality
β’ Anti-debug functionality
β’ Domain-check options
β’ Multiple delivery and export configurations
β’ Private web-based dashboard and builder
β
The service claims to have been tested against CrowdStrike, SentinelOne, Cortex, Sophos and Microsoft Defender for Endpoint.
β
Pricing is advertised at $2,000 per month for up to 10 builds per day or $7,000 for permanent access with unlimited builds. Free demonstrations are reportedly available to established forum users and prospective buyers.
β
The seller's claims and the effectiveness of the advertised EDR evasion capabilities have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ Trezor phishing injection tool advertised on a cybercrime forum for $3,000
β
A forum seller is advertising AntiTrezor, a phishing injection tool designed to impersonate the Trezor Suite interface and capture cryptocurrency wallet recovery seed phrases.
β
The advertised features include:
β
β’ Injection directly into the Trezor Suite interface
β’ Phishing flow styled to resemble the legitimate application
β’ Seed phrase capture
β’ Persistence across system reboots
β’ Windows 10 and 11 support
β’ Support for multiple Trezor device models
β’ Fake error and troubleshooting prompts intended to pressure victims
β’ Ability to display captured wallet balances in an operator panel
β’ Administrative notifications when a victim interacts with the phishing flow
β
The listing claims the tool can prevent victims from moving funds after submitting their recovery phrase and is designed to operate without modifying official Trezor executables.
β
The source code is being advertised for $3,000.
β
The seller's claims and the capabilities of the tool have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum seller is advertising AntiTrezor, a phishing injection tool designed to impersonate the Trezor Suite interface and capture cryptocurrency wallet recovery seed phrases.
β
The advertised features include:
β
β’ Injection directly into the Trezor Suite interface
β’ Phishing flow styled to resemble the legitimate application
β’ Seed phrase capture
β’ Persistence across system reboots
β’ Windows 10 and 11 support
β’ Support for multiple Trezor device models
β’ Fake error and troubleshooting prompts intended to pressure victims
β’ Ability to display captured wallet balances in an operator panel
β’ Administrative notifications when a victim interacts with the phishing flow
β
The listing claims the tool can prevent victims from moving funds after submitting their recovery phrase and is designed to operate without modifying official Trezor executables.
β
The source code is being advertised for $3,000.
β
The seller's claims and the capabilities of the tool have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π«π· iMapper allegedly breached through critical Metabase vulnerability, account data and database access leaked on a cybercrime forum
β
A forum actor claims to have compromised iMapper, a French web-connected 2D laser measurement platform for building professionals, using a vulnerability identified in the listing as CVE-2026-72898 with a claimed CVSS score of 10.0.
β
The exposed account dataset reportedly contains 2,463 records and includes:
β
β’ User IDs and usernames
β’ Password hashes
β’ Account roles
β’ Email addresses
β’ Phone numbers
β’ Professions
β’ MFA status and related metadata
β’ Language preferences
β’ Stripe customer IDs
β’ Stripe tax-related identifiers
β’ Measurement and display configuration fields
β
The data is being distributed in XLSX format. The listing also claims the compromised environment contains additional database tables and offers credentials that could provide access to those systems.
β
The claims, exploitation method and authenticity, availability and scope of the allegedly exposed data and database access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have compromised iMapper, a French web-connected 2D laser measurement platform for building professionals, using a vulnerability identified in the listing as CVE-2026-72898 with a claimed CVSS score of 10.0.
β
The exposed account dataset reportedly contains 2,463 records and includes:
β
β’ User IDs and usernames
β’ Password hashes
β’ Account roles
β’ Email addresses
β’ Phone numbers
β’ Professions
β’ MFA status and related metadata
β’ Language preferences
β’ Stripe customer IDs
β’ Stripe tax-related identifiers
β’ Measurement and display configuration fields
β
The data is being distributed in XLSX format. The listing also claims the compromised environment contains additional database tables and offers credentials that could provide access to those systems.
β
The claims, exploitation method and authenticity, availability and scope of the allegedly exposed data and database access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈπΊπΈπ¨π ShinyHunters names two new victims
πΊπΈ BOK Financial - A U.S.-based regional financial services company headquartered in Tulsa, Oklahoma, providing commercial banking, consumer banking, wealth management, lending, and treasury services.
π¨π Novocure Limited - A global oncology company headquartered in Baar, Switzerland, developing and commercializing Tumor Treating Fields therapies for aggressive forms of cancer.
πΊπΈ BOK Financial - A U.S.-based regional financial services company headquartered in Tulsa, Oklahoma, providing commercial banking, consumer banking, wealth management, lending, and treasury services.
π¨π Novocure Limited - A global oncology company headquartered in Baar, Switzerland, developing and commercializing Tumor Treating Fields therapies for aggressive forms of cancer.
π2