πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.94K subscribers
1.2K photos
68 videos
1.07K links
Download Telegram
These Domains Have Been Seized will finally be available for free in September. There is some bugs I am working on. The seizure images and any raid video will be independently added.

The initial data load comes from seized.fyi. Check out their site!
❀2
πŸš¨πŸ‡ΊπŸ‡Έ FBI traces crypto payment to dark web CSAM site, leading to arrest of Texas man

Federal authorities charged 39-year-old Jose Adrian Bosquez (pictured) of Amarillo with accessing child sexual abuse material with intent to view.

According to the criminal complaint, the FBI investigated a dark web site that sold subscription access to CSAM using cryptocurrency.

Investigators extracted wallet addresses used to pay the site and allegedly traced an April 2024 payment to a Coinbase account registered to Bosquez.

The FBI searched his home on August 19. During a non-custodial interview, Bosquez allegedly admitted sending cryptocurrency to access the site and visiting it around five times, most recently in February or March 2026.

He remains in custody pending his next federal court appearance.

Source: https://www.newschannel10.com/2026/08/25/feds-charge-amarillo-man-buying-explicit-images-children-dark-web/
🚨 INTERPOL operation targets Black Axe and other West African cybercrime networks across 22 countries

Operation Jackal IV resulted in 58 arrests and identified 263 suspects linked to organized crime groups involved in cyber-enabled financial fraud and money laundering.

The networks are tied to:

β€’ Romance scams
β€’ Cryptocurrency and investment fraud
β€’ Business email compromise
β€’ Money laundering
β€’ Sextortion
β€’ Crime-as-a-Service

In South Africa, authorities arrested 39 people, blocked 257 bank accounts, and seized $2.67M while targeting a syndicate running romance and investment scams against retirees.

Investigators in Argentina also identified 196 people linked to a Crime-as-a-Service network allegedly supplying domains and money-laundering services to West African criminal groups.

INTERPOL says some of these networks are increasingly using sextortion against minors as young as 14 and outsourcing criminal infrastructure through dark web service providers.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
Forum: sinister[.]ly
IP: 103[.]155[.]93[.]134
ASN: 45839 πŸ‡²πŸ‡Ύ
Org: Shinjiru Technology Sdn Bhd
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
😁2πŸ”₯1
🚨 Nitter development has stopped after X Corp. sent cease-and-desist letters demanding the permanent takedown of Nitter instances and the project’s repository.

The maintainer says nitter.net is now offline while legal advice is being sought. Nitter had operated for more than seven years.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
😭6
πŸš¨πŸ‡«πŸ‡· MsSantΓ© database allegedly offered for sale on a cybercrime forum, 535K+ records claimed
β €
MsSantΓ©, France's secure healthcare messaging ecosystem, is allegedly affected by a data exposure after a threat actor advertised a database containing 535,358 records.
β €
The sample published with the listing appears to contain information associated with healthcare professionals and organizations.
β €
The advertised data includes:
β €
β€’ First and last names
β€’ National professional identifiers
β€’ Healthcare professional ID numbers
β€’ Professional categories
β€’ Medical specialties
β€’ Organization and facility names
β€’ Department and service information
β€’ Business and practice addresses
β€’ Cities and postal codes
β€’ Professional role information
β€’ Additional healthcare directory-related fields
β €
The actor included a sample of the alleged records and provided contact information for prospective buyers.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
πŸš¨πŸ‡΅πŸ‡Έ Palestinian Ministry of Interior citizen database allegedly leaked on a cybercrime forum, 3.56M records claimed
β €
A threat actor claims to have obtained a database attributed to the Palestinian Ministry of Interior containing information on 3,559,378 Palestinian citizens.
β €
The advertised data appears to include:
β €
β€’ Citizen identification numbers
β€’ Full names
β€’ Dates of birth
β€’ Arabic-language identity records
β€’ Additional demographic and registry-related fields
β €
The actor published what they describe as a 500,000-record proof of concept from the alleged dataset. The complete database is claimed to be approximately 445 MB and provided in .DB format.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
😭2😁1
πŸš¨πŸ‡ΆπŸ‡¦ Access to Qatar-based pharmacy chain infrastructure allegedly offered for sale on a cybercrime forum
β €
An unnamed pharmacy chain in Qatar operating in the healthcare and pharmaceutical sector is allegedly compromised, with a threat actor advertising access to multiple parts of the company's cloud and communications infrastructure.
β €
The advertised access includes:
β €
β€’ MongoDB
β€’ Google Cloud Platform (GCP)
β€’ SendGrid
β€’ Twilio
β€’ Access to healthcare/pharmaceutical infrastructure
β €
The actor is accepting offers privately and states that payment will be accepted exclusively in Monero (XMR). No public asking price was provided in the listing.
β €
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡²πŸ‡½ Universidad AutΓ³noma de Sinaloa employee documents allegedly leaked on a cybercrime forum
β €
Universidad AutΓ³noma de Sinaloa (UAS), a public university in Sinaloa, Mexico, is allegedly affected by a data exposure after a threat actor claimed to have extracted employee information and documents from a university personnel system.
β €
The actor claims the files were organized using employees' RFC and CURP identifiers and contain documentation associated with individual university staff members.
β €
The advertised data includes:
β €
β€’ INE voter identification credentials
β€’ Birth certificates
β€’ CURP identifiers
β€’ RFC tax identifiers
β€’ Employee photographs
β€’ Proof-of-address documents
β€’ Tax and fiscal status certificates
β€’ Academic diplomas
β€’ Employment contracts and appointment letters
β€’ Paid and unpaid leave documents
β€’ Full names
β€’ Dates of birth
β€’ Gender information
β€’ Phone numbers
β€’ Email addresses
β€’ SAT-related tax information
β€’ Hire dates, seniority and employment history
β €
The post also includes a sample of the alleged employee database and provides a download link for the claimed documents.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡¨πŸ‡³ FBI knocks China-linked QScan and QTRouter hacking infrastructure offline

The DOJ and FBI seized domains powering two hacking platforms operated by QTFY, a Chinese state-sponsored group tied to Nanjing Xinjiuwei Network Technology Company.

U.S. officials say QTFY has compromised or targeted sensitive networks including NASA, the Federal Reserve, Department of Energy, DOJ, HHS, NIH, and the U.S. Senate.

QScan automatically scans for and infects thousands of IoT devices worldwide.

Those compromised devices are then incorporated into QTRouter, an obfuscation network combining hacked IoT devices, commercial proxies, and leased VPS infrastructure to hide the China-based origin of intrusion activity.

Court documents say QTFY sells hacking services to paying customers including China's Ministry of State Security and People's Liberation Army.

Because the seized domains were hard-coded into QScan and QTRouter for authentication and communications, the FBI says the operation rendered both platforms inoperable.

The infrastructure has been linked to malicious activity dating back to at least 2018.

Seized: qtproxy[.]xyz

Source: https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers
There is an issue with Telegram claims not showing on the threat feed, I'm looking into it and don't have a solution yet.