πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.93K subscribers
1.2K photos
68 videos
1.07K links
Download Telegram
β€ΌοΈπŸ‡ΊπŸ‡Έ ShinyHunters names CyrusOne, LLC.

Per the listing:

"Update 23 Aug: We are removing the clients name off this post. They are refusing to pay a $13 million demand.

They have 24 hours left to engage with us. We hold 12.9 million Salesforce records along with:
Sharepoint: (369.6 GB Compressed / 645 GB Uncompressed) 288,729 Files, 60,513 Folders - More than 182,000 rows of Customer data Extracted from the "Contacts" Salesforce Object.

- Over 8,300 Rows of Employee PII (Full Name, Email, Job Title, Phone Number, ect.)
- Thousands of executed contracts, MSAs, NDAs, amendments, leases, and SOWs
- Extensive physical key inventory logs, verification photos, and contractor Green Badge audits
- Large collection of data center drawings, floor plans, electrical one-line diagrams, security system drawings, and site schematics
- Full CERM (Critical Environment Reliability Management) process library
- Physical and information security policy suite plus governance materials
- Regional security scorecards, KPI workbooks, GAM sheets, and signed performance packages
- Credential and access-control artifacts (including PasswordList.xlsx, Okta SSC Access lists, active badge reports, and multiple Data Center Access Control forms)"

Original listing https://x.com/DarkWebInformer/status/2090458094388105490
🚨 Ready-made executable crypter with Telegram bot, payment system and admin panel advertised on a cybercrime forum
β €
A cybercrime forum seller is advertising the source code for what they describe as a ready-made commercial crypter platform designed to process Windows PE x64 executables. The seller claims the project combines a native high-performance core, backend infrastructure, Telegram-based interface and separate administrative panel.
β €
The seller states that only three copies are being offered and advertises a claimed detection rate of 1/36.
β €
The advertised features include:
β €
β€’ Windows PE x64 executable processing
β€’ Automated file processing
β€’ Configurable settings and parameters
β€’ Resource and metadata handling
β€’ Queued and parallel task processing
β€’ User access and usage limits
β€’ Operation history
β€’ Automatic delivery of processed results
β€’ Subscription and pricing system
β€’ Integrated payment system
β€’ Referral program
β€’ Administrative panel
β€’ User and activity management
β€’ Multilingual interface
β€’ Private cryptographic methods
β€’ Telegram bot interface
β€’ Backend and native core components
β€’ Self-hosted deployment and infrastructure integration
β €
The seller's claims and the capabilities, effectiveness and detection rate of the advertised tool have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ CYBERLEEK, Grand Theft Auto 6, Dark Web Onion:

IOC: http://leekrdlpsy3xcxwcvfje7ovj34fo4y2xqaghdikhf3t7hatev346h6qd[.]onion/
πŸ”₯8❀1
🚨πŸ‡ͺπŸ‡Ί Rezcomm customer database allegedly leaked on a cybercrime forum, 17K+ records claimed
β €
A cybercrime forum user claims to have obtained the database of Rezcomm, an e-commerce platform provider serving industries including airports, parking facilities and cruise ports. The post claims the dataset contains information from more than 17,000 individuals across multiple databases.
β €
The advertised data includes:
β €
β€’ Usernames
β€’ Email addresses
β€’ Phone numbers
β€’ Full names
β€’ Customer account information
β€’ Address details
β€’ Airport and venue-related booking information
β€’ Transaction-related records
β€’ User activity information
β€’ Technical booking data
β€’ Internal database fields
β €
The seller claims the data was extracted from three databases totaling approximately 50 GB across 555 tables. The post includes sample CSV files and sample records allegedly demonstrating the exposed information.
β €
Rezcomm provides e-commerce solutions for airports, parking operators and travel-related businesses, including booking and reservation services.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1
πŸš¨πŸ‡«πŸ‡· Klark.ai database allegedly leaked on a cybercrime forum, 140GB of data claimed
β €
A cybercrime forum user claims to have obtained multiple databases belonging to Klark.ai, an artificial intelligence platform designed to help customer service teams generate responses and build knowledge bases from existing conversations.
β €
The threat actor claims the leak contains 4 databases totaling approximately 140 GB, with data allegedly stored across 162 CSV files. The seller claims many files contain millions of rows.
β €
The advertised data includes:
β €
β€’ Names and first names
β€’ Email addresses
β€’ Phone numbers
β€’ Hashed passwords
β€’ Customer conversations
β€’ Exchange-related information
β€’ Logs
β€’ API keys and secret API data
β€’ Banking-related information, including some IBAN details
β€’ Additional internal records
β €
The forum post includes claims that the attacker recovered additional data but stopped the extraction process before completion.
β €
Klark.ai provides AI-powered tools for customer service teams, including automated response generation and knowledge management features.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1
.@zachxbt has identified cybercriminal M1llionz aka RichMilly666... a French cybercriminal allegedly laundering assets linked to two violent home invasion robberies in πŸ‡«πŸ‡· France in April 2026, which reportedly generated a combined $667,000 in stolen funds.
😭1
🚨 Healthcare sector database allegedly for sale on a cybercrime forum, 1.3M+ users claimed
β €
A cybercrime forum user is advertising what they claim is a database belonging to a healthcare sector company containing information on more than 1.3 million users worldwide. The seller claims the dataset contains customer and contact-related records.
β €
The advertised data includes:
β €
β€’ Names
β€’ Email addresses
β€’ Phone numbers
β€’ Mobile and home phone information
β€’ Physical addresses
β€’ Dates of birth
β€’ Gender information
β€’ Account identifiers
β€’ Contact records
β€’ Healthcare-related account fields
β€’ Medical record numbers
β€’ Customer service information
β€’ Communication preferences
β€’ Account activity data
β€’ Internal Salesforce-related fields
β€’ Additional profile and demographic information
β €
The seller claims the database contains a large number of structured records and is offering a single copy for $2,000.
β €
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€ΌοΈπŸ‡«πŸ‡· A forum post shares login credentials and access window details for the member portal of Ordre National Infirmiers, a French nursing professional order.

The post includes a username, password, and login time window.
🚨 Cryptocurrency wallet drainer source code allegedly advertised on a cybercrime forum for $6,500
β €
A cybercrime forum user is advertising what they claim is the source code for an all-in-one cryptocurrency wallet drainer and monitoring platform named Nexus Core Vortex. The seller claims the tool includes automated withdrawal capabilities, address monitoring and support for multiple blockchain networks.
β €
The advertised features include:
β €
β€’ Cryptocurrency wallet draining functionality
β€’ Automated monitoring of blockchain addresses
β€’ Seed phrase and private key processing
β€’ Automated withdrawal systems
β€’ Support for Bitcoin, Litecoin, Bitcoin Cash, Dogecoin and Zcash
β€’ EVM network support across multiple chains
β€’ Support for seed phrase formats including BIP39
β€’ Telegram notifications and management features
β€’ Transaction monitoring and logging
β€’ Proxy rotation support
β€’ Custom derivation rules
β€’ API access
β€’ Administrative dashboard
β€’ Internal portfolio tracking
β€’ Multi-network asset monitoring
β€’ Node management capabilities
β €
The seller claims the tool supports dozens of blockchain networks and can monitor generated wallet addresses for incoming transactions before automatically attempting withdrawals.
β €
The listing is priced at $6,500 and includes access to a claimed demonstration panel. The seller also advertises optional updates and additional support.
β €
The seller's claims and the capabilities, effectiveness and legitimacy of the advertised tool have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1