πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.93K subscribers
1.2K photos
68 videos
1.07K links
Download Telegram
🚨 Corporate access broker advertises stolen access marketplace on cybercrime forum, 2 BTC deposit claimed
β €
A threat actor is advertising what they describe as a service for buying and selling corporate network access. The listing claims they work with all types of access and are seeking ongoing suppliers of compromised corporate environments.
β €
The advertised service includes:
β €
β€’ Corporate access brokerage
β€’ Multiple types of network access
β€’ Access from high-value targets
β€’ Initial access listings valued from $1,000+
β€’ Supplier relationships for future access sales
β €
The actor claims to only work with access involving organizations with revenues above $30 million and states they are looking for brokers to provide available listings.
β €
The listing references a claimed 2 BTC total deposit and states that verification is conducted through encrypted communication platforms.
β €
The claims and the authenticity, source and validity of the advertised access have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡ΊπŸ‡Έ Toledo Zoo database allegedly leaked on a cybercrime forum, 1.9M+ records claimed
β €
Toledo Zoo & Aquarium, an Ohio-based zoo and aquarium housing thousands of animals across hundreds of species, is allegedly the target of a claimed data breach after a threat actor advertised a database dump containing approximately 1.9 million records.
β €
The threat actor claims the database was obtained through a zero-day vulnerability in a third-party system and contains personally identifiable information.
β €
The advertised data includes:
β €
β€’ Email addresses
β€’ First names
β€’ Middle names
β€’ Last names
β€’ Spouse information
β€’ Street addresses
β€’ Cities, states and ZIP codes
β€’ Phone numbers
β€’ County information
β€’ Deceased status
β€’ Children count
β€’ Membership information
β€’ Titles and suffixes
β €
The listing includes samples of the alleged dataset and is being offered for $800 in cryptocurrency.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€ΌοΈπŸ‡ΊπŸ‡Έ An actor is offering VPN-based local user access to a US organizations internal network, claiming full visibility across 600+ hosts and revenue over $1 billion.

Access is priced at 1-2K with a PoC available on request.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
🚨 KodexGlobal database allegedly offered for sale on a cybercrime forum, 251K+ user accounts claimed
β €
KodexGlobal, a platform used by law enforcement agencies to submit and manage legal data requests, is allegedly the target of a breach after a threat actor claimed to have accessed its backend through an exposed administrative API and obtained a full database dump.
β €
The advertised data includes:
β €
β€’ 251,384 user accounts
β€’ Names
β€’ Email addresses
β€’ Phone numbers
β€’ Agency affiliations
β€’ User roles and access levels
β€’ 15,000+ law enforcement agencies
β€’ 187,462 records requests
β€’ Case numbers
β€’ Legal process information
β€’ Statute citations
β€’ 41,208 preservation requests
β€’ 9,743 non-disclosure orders with expiration dates
β€’ 1,284,517 request action logs
β€’ IP addresses and timestamps
β€’ Administrator and agent accounts
β€’ MFA status information
β €
The actor claims the dataset includes accounts associated with law enforcement agencies worldwide, including agencies such as the FBI and DEA.
β €
The database is being offered for $2,000, with the seller stating payment will only be accepted in XMR or BTC and that the sale will be limited to a single buyer.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!

Title: A French GDPR Compliance Provider's Client Records Shared on a Forum

Link: https://darkwebinformer.com/a-french-gdpr-compliance-providers-client-records-shared-on-a-forum/

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
β€ΌοΈπŸ‡ΊπŸ‡Έ National Kidney Registry has been claimed a victim to Direwolf Ransomware

πŸ‡ΊπŸ‡Έ National Kidney Registry - A U.S.-based nonprofit organization that facilitates kidney-paired donation and transplant matching between incompatible donor-recipient pairs.

The listing claims 253 GB of data was compromised.
These Domains Have Been Seized will finally be available for free in September. There is some bugs I am working on. The seizure images and any raid video will be independently added.

The initial data load comes from seized.fyi. Check out their site!
❀2
πŸš¨πŸ‡ΊπŸ‡Έ FBI traces crypto payment to dark web CSAM site, leading to arrest of Texas man

Federal authorities charged 39-year-old Jose Adrian Bosquez (pictured) of Amarillo with accessing child sexual abuse material with intent to view.

According to the criminal complaint, the FBI investigated a dark web site that sold subscription access to CSAM using cryptocurrency.

Investigators extracted wallet addresses used to pay the site and allegedly traced an April 2024 payment to a Coinbase account registered to Bosquez.

The FBI searched his home on August 19. During a non-custodial interview, Bosquez allegedly admitted sending cryptocurrency to access the site and visiting it around five times, most recently in February or March 2026.

He remains in custody pending his next federal court appearance.

Source: https://www.newschannel10.com/2026/08/25/feds-charge-amarillo-man-buying-explicit-images-children-dark-web/
🚨 INTERPOL operation targets Black Axe and other West African cybercrime networks across 22 countries

Operation Jackal IV resulted in 58 arrests and identified 263 suspects linked to organized crime groups involved in cyber-enabled financial fraud and money laundering.

The networks are tied to:

β€’ Romance scams
β€’ Cryptocurrency and investment fraud
β€’ Business email compromise
β€’ Money laundering
β€’ Sextortion
β€’ Crime-as-a-Service

In South Africa, authorities arrested 39 people, blocked 257 bank accounts, and seized $2.67M while targeting a syndicate running romance and investment scams against retirees.

Investigators in Argentina also identified 196 people linked to a Crime-as-a-Service network allegedly supplying domains and money-laundering services to West African criminal groups.

INTERPOL says some of these networks are increasingly using sextortion against minors as young as 14 and outsourcing criminal infrastructure through dark web service providers.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
Forum: sinister[.]ly
IP: 103[.]155[.]93[.]134
ASN: 45839 πŸ‡²πŸ‡Ύ
Org: Shinjiru Technology Sdn Bhd
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
😁2πŸ”₯1
🚨 Nitter development has stopped after X Corp. sent cease-and-desist letters demanding the permanent takedown of Nitter instances and the project’s repository.

The maintainer says nitter.net is now offline while legal advice is being sought. Nitter had operated for more than seven years.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
😭6