π¨πͺπΊ Rezcomm customer database allegedly leaked on a cybercrime forum, 17K+ records claimed
β
A cybercrime forum user claims to have obtained the database of Rezcomm, an e-commerce platform provider serving industries including airports, parking facilities and cruise ports. The post claims the dataset contains information from more than 17,000 individuals across multiple databases.
β
The advertised data includes:
β
β’ Usernames
β’ Email addresses
β’ Phone numbers
β’ Full names
β’ Customer account information
β’ Address details
β’ Airport and venue-related booking information
β’ Transaction-related records
β’ User activity information
β’ Technical booking data
β’ Internal database fields
β
The seller claims the data was extracted from three databases totaling approximately 50 GB across 555 tables. The post includes sample CSV files and sample records allegedly demonstrating the exposed information.
β
Rezcomm provides e-commerce solutions for airports, parking operators and travel-related businesses, including booking and reservation services.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A cybercrime forum user claims to have obtained the database of Rezcomm, an e-commerce platform provider serving industries including airports, parking facilities and cruise ports. The post claims the dataset contains information from more than 17,000 individuals across multiple databases.
β
The advertised data includes:
β
β’ Usernames
β’ Email addresses
β’ Phone numbers
β’ Full names
β’ Customer account information
β’ Address details
β’ Airport and venue-related booking information
β’ Transaction-related records
β’ User activity information
β’ Technical booking data
β’ Internal database fields
β
The seller claims the data was extracted from three databases totaling approximately 50 GB across 555 tables. The post includes sample CSV files and sample records allegedly demonstrating the exposed information.
β
Rezcomm provides e-commerce solutions for airports, parking operators and travel-related businesses, including booking and reservation services.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨π«π· Klark.ai database allegedly leaked on a cybercrime forum, 140GB of data claimed
β
A cybercrime forum user claims to have obtained multiple databases belonging to Klark.ai, an artificial intelligence platform designed to help customer service teams generate responses and build knowledge bases from existing conversations.
β
The threat actor claims the leak contains 4 databases totaling approximately 140 GB, with data allegedly stored across 162 CSV files. The seller claims many files contain millions of rows.
β
The advertised data includes:
β
β’ Names and first names
β’ Email addresses
β’ Phone numbers
β’ Hashed passwords
β’ Customer conversations
β’ Exchange-related information
β’ Logs
β’ API keys and secret API data
β’ Banking-related information, including some IBAN details
β’ Additional internal records
β
The forum post includes claims that the attacker recovered additional data but stopped the extraction process before completion.
β
Klark.ai provides AI-powered tools for customer service teams, including automated response generation and knowledge management features.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A cybercrime forum user claims to have obtained multiple databases belonging to Klark.ai, an artificial intelligence platform designed to help customer service teams generate responses and build knowledge bases from existing conversations.
β
The threat actor claims the leak contains 4 databases totaling approximately 140 GB, with data allegedly stored across 162 CSV files. The seller claims many files contain millions of rows.
β
The advertised data includes:
β
β’ Names and first names
β’ Email addresses
β’ Phone numbers
β’ Hashed passwords
β’ Customer conversations
β’ Exchange-related information
β’ Logs
β’ API keys and secret API data
β’ Banking-related information, including some IBAN details
β’ Additional internal records
β
The forum post includes claims that the attacker recovered additional data but stopped the extraction process before completion.
β
Klark.ai provides AI-powered tools for customer service teams, including automated response generation and knowledge management features.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
.@zachxbt has identified cybercriminal M1llionz aka RichMilly666... a French cybercriminal allegedly laundering assets linked to two violent home invasion robberies in π«π· France in April 2026, which reportedly generated a combined $667,000 in stolen funds.
π1
πͺ That Dark Web Guy - Part 3 πͺ
.@zachxbt has identified cybercriminal M1llionz aka RichMilly666... a French cybercriminal allegedly laundering assets linked to two violent home invasion robberies in π«π· France in April 2026, which reportedly generated a combined $667,000 in stolen funds.
Full thread: https://x.com/zachxbt/status/2091858014236295170
X (formerly Twitter)
ZachXBT (@zachxbt) on X
1/ Meet M1llionz (RichMilly666), a French cybercriminal allegedly laundering assets from two violent home invasion robberies in France in April 2026 that netted $667K total, with a history of openβ¦
π¨ Healthcare sector database allegedly for sale on a cybercrime forum, 1.3M+ users claimed
β
A cybercrime forum user is advertising what they claim is a database belonging to a healthcare sector company containing information on more than 1.3 million users worldwide. The seller claims the dataset contains customer and contact-related records.
β
The advertised data includes:
β
β’ Names
β’ Email addresses
β’ Phone numbers
β’ Mobile and home phone information
β’ Physical addresses
β’ Dates of birth
β’ Gender information
β’ Account identifiers
β’ Contact records
β’ Healthcare-related account fields
β’ Medical record numbers
β’ Customer service information
β’ Communication preferences
β’ Account activity data
β’ Internal Salesforce-related fields
β’ Additional profile and demographic information
β
The seller claims the database contains a large number of structured records and is offering a single copy for $2,000.
β
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A cybercrime forum user is advertising what they claim is a database belonging to a healthcare sector company containing information on more than 1.3 million users worldwide. The seller claims the dataset contains customer and contact-related records.
β
The advertised data includes:
β
β’ Names
β’ Email addresses
β’ Phone numbers
β’ Mobile and home phone information
β’ Physical addresses
β’ Dates of birth
β’ Gender information
β’ Account identifiers
β’ Contact records
β’ Healthcare-related account fields
β’ Medical record numbers
β’ Customer service information
β’ Communication preferences
β’ Account activity data
β’ Internal Salesforce-related fields
β’ Additional profile and demographic information
β
The seller claims the database contains a large number of structured records and is offering a single copy for $2,000.
β
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: YouFid Loyalty Profiles on 1.9 Million French Customers Offered for 1,000 Euros
Link: https://darkwebinformer.com/youfid-loyalty-profiles-on-1-9-million-french-customers-offered-for-1-000-euros/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: YouFid Loyalty Profiles on 1.9 Million French Customers Offered for 1,000 Euros
Link: https://darkwebinformer.com/youfid-loyalty-profiles-on-1-9-million-french-customers-offered-for-1-000-euros/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
YouFid Loyalty Profiles on 1.9 Million French Customers Offered for 1,000 Euros
A forum user posting as Lagui1337 is selling what they describe as the user database of YouFid, a French customer loyalty platform used by restaurant and retail merchants.
π¨ Cryptocurrency wallet drainer source code allegedly advertised on a cybercrime forum for $6,500
β
A cybercrime forum user is advertising what they claim is the source code for an all-in-one cryptocurrency wallet drainer and monitoring platform named Nexus Core Vortex. The seller claims the tool includes automated withdrawal capabilities, address monitoring and support for multiple blockchain networks.
β
The advertised features include:
β
β’ Cryptocurrency wallet draining functionality
β’ Automated monitoring of blockchain addresses
β’ Seed phrase and private key processing
β’ Automated withdrawal systems
β’ Support for Bitcoin, Litecoin, Bitcoin Cash, Dogecoin and Zcash
β’ EVM network support across multiple chains
β’ Support for seed phrase formats including BIP39
β’ Telegram notifications and management features
β’ Transaction monitoring and logging
β’ Proxy rotation support
β’ Custom derivation rules
β’ API access
β’ Administrative dashboard
β’ Internal portfolio tracking
β’ Multi-network asset monitoring
β’ Node management capabilities
β
The seller claims the tool supports dozens of blockchain networks and can monitor generated wallet addresses for incoming transactions before automatically attempting withdrawals.
β
The listing is priced at $6,500 and includes access to a claimed demonstration panel. The seller also advertises optional updates and additional support.
β
The seller's claims and the capabilities, effectiveness and legitimacy of the advertised tool have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A cybercrime forum user is advertising what they claim is the source code for an all-in-one cryptocurrency wallet drainer and monitoring platform named Nexus Core Vortex. The seller claims the tool includes automated withdrawal capabilities, address monitoring and support for multiple blockchain networks.
β
The advertised features include:
β
β’ Cryptocurrency wallet draining functionality
β’ Automated monitoring of blockchain addresses
β’ Seed phrase and private key processing
β’ Automated withdrawal systems
β’ Support for Bitcoin, Litecoin, Bitcoin Cash, Dogecoin and Zcash
β’ EVM network support across multiple chains
β’ Support for seed phrase formats including BIP39
β’ Telegram notifications and management features
β’ Transaction monitoring and logging
β’ Proxy rotation support
β’ Custom derivation rules
β’ API access
β’ Administrative dashboard
β’ Internal portfolio tracking
β’ Multi-network asset monitoring
β’ Node management capabilities
β
The seller claims the tool supports dozens of blockchain networks and can monitor generated wallet addresses for incoming transactions before automatically attempting withdrawals.
β
The listing is priced at $6,500 and includes access to a claimed demonstration panel. The seller also advertises optional updates and additional support.
β
The seller's claims and the capabilities, effectiveness and legitimacy of the advertised tool have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
βΌοΈ New Dark Web Informer Blog Post!
Title: Groupe Bernard Data Published Free as the Thirteenth Leak From One Platform
Link: https://darkwebinformer.com/groupe-bernard-data-published-free-as-the-thirteenth-leak-from-one-platform/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Groupe Bernard Data Published Free as the Thirteenth Leak From One Platform
Link: https://darkwebinformer.com/groupe-bernard-data-published-free-as-the-thirteenth-leak-from-one-platform/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Groupe Bernard Data Published Free as the Thirteenth Leak From One Platform
A forum user posting as NikolaT has published what they describe as the database of Groupe Bernard, a French group working in grain, animal nutrition and agriculture, giving a size of 22.25 GB across 330,563 files.
πͺ That Dark Web Guy - Part 3 πͺ
βΌοΈ CYBERLEEK, Grand Theft Auto 6, Dark Web Onion: IOC: http://leekrdlpsy3xcxwcvfje7ovj34fo4y2xqaghdikhf3t7hatev346h6qd[.]onion/
Someone caught the "gamer" who went to Rockstar North's office on video and a direct look from his point of view.
π2
π¨πΊπΈ SteelSeries TeamCity environment allegedly breached, employee data and credentials claimed exposed
β
A cybercrime forum user claims to have breached the SteelSeries TeamCity environment and obtained access to internal project-related data. The post claims the database contains information belonging to 35 users with employee accounts.
β
The advertised data includes:
β
β’ Employee account information
β’ User IDs
β’ Names
β’ Email addresses
β’ Last login details
β’ User roles
β’ Azure signing keys
β’ VCS credentials
β’ SSH keys
β’ SVN-related credentials
β
The forum post includes a sample of the allegedly exposed user records and claims additional data is available for download.
β
SteelSeries is a gaming peripherals company known for products including gaming mice, keyboards, headsets and accessories.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A cybercrime forum user claims to have breached the SteelSeries TeamCity environment and obtained access to internal project-related data. The post claims the database contains information belonging to 35 users with employee accounts.
β
The advertised data includes:
β
β’ Employee account information
β’ User IDs
β’ Names
β’ Email addresses
β’ Last login details
β’ User roles
β’ Azure signing keys
β’ VCS credentials
β’ SSH keys
β’ SVN-related credentials
β
The forum post includes a sample of the allegedly exposed user records and claims additional data is available for download.
β
SteelSeries is a gaming peripherals company known for products including gaming mice, keyboards, headsets and accessories.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart
GitHub: https://github.com/toanln-cov/CVE-2026-76565
A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart β€ 6.1.7 for Joomla.
The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.
The PoC demonstrates:
β’ Reflected XSS through crafted GET parameters
β’ Exploitation of vulnerable price filter inputs
β’ Attribute-context injection caused by missing htmlspecialchars() encoding
β’ No authentication requirement for exploitation
β’ Affected versions: PhocaCart β€ 6.1.7
β’ Fixed version: PhocaCart 6.1.8
π₯ No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
GitHub: https://github.com/toanln-cov/CVE-2026-76565
A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart β€ 6.1.7 for Joomla.
The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.
The PoC demonstrates:
β’ Reflected XSS through crafted GET parameters
β’ Exploitation of vulnerable price filter inputs
β’ Attribute-context injection caused by missing htmlspecialchars() encoding
β’ No authentication requirement for exploitation
β’ Affected versions: PhocaCart β€ 6.1.7
β’ Fixed version: PhocaCart 6.1.8
π₯ No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
β€1
π¨πΊπΈ Access to major US technology company infrastructure allegedly offered for sale on cybercrime forum
β
A cybercrime forum user is advertising what they claim is access to the infrastructure of a major American technology company operating in cloud technologies and artificial intelligence. The seller claims the access provides visibility into internal systems and enterprise resources.
β
The advertised access includes:
β
β’ Corporate Git hosting with organization administrator rights
β’ Claimed persistence access within company infrastructure
β’ Private container registry credentials
β’ Internal communication channels and webhooks
β’ API keys for internal services
β’ Access to a claimed vulnerability allowing credential retrieval
β
The seller is asking $10,000 and states the access will be sold to a single buyer through escrow.
β
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A cybercrime forum user is advertising what they claim is access to the infrastructure of a major American technology company operating in cloud technologies and artificial intelligence. The seller claims the access provides visibility into internal systems and enterprise resources.
β
The advertised access includes:
β
β’ Corporate Git hosting with organization administrator rights
β’ Claimed persistence access within company infrastructure
β’ Private container registry credentials
β’ Internal communication channels and webhooks
β’ API keys for internal services
β’ Access to a claimed vulnerability allowing credential retrieval
β
The seller is asking $10,000 and states the access will be sold to a single buyer through escrow.
β
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€2
π¨πΈπ¦ STC TV user database allegedly leaked on a cybercrime forum, 3M+ records claimed
β
An actor claims to have obtained a database belonging to STC TV, a Saudi Arabia-based streaming service. The seller claims the dataset contains information belonging to more than 3 million users.
β
The advertised data includes:
β
β’ Full names
β’ User points
β’ Gender information
β’ Mobile numbers
β’ Email addresses
β’ Dates of birth
β’ Nationality information
β’ Barcode-related data
β
The seller is advertising the alleged dataset for $2,000 and has included a sample of records as proof of the claimed data.
β
STC TV is a digital entertainment platform operated by Saudi Telecom Company (stc), offering streaming content and subscription-based services.
β
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An actor claims to have obtained a database belonging to STC TV, a Saudi Arabia-based streaming service. The seller claims the dataset contains information belonging to more than 3 million users.
β
The advertised data includes:
β
β’ Full names
β’ User points
β’ Gender information
β’ Mobile numbers
β’ Email addresses
β’ Dates of birth
β’ Nationality information
β’ Barcode-related data
β
The seller is advertising the alleged dataset for $2,000 and has included a sample of records as proof of the claimed data.
β
STC TV is a digital entertainment platform operated by Saudi Telecom Company (stc), offering streaming content and subscription-based services.
β
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Hono: A small, simple, and ultrafast web framework built on Web Standards
GitHub: https://github.com/honojs/hono
GitHub: https://github.com/honojs/hono
π₯1