π¨πΆπ¦ Access to Qatar-based pharmacy chain infrastructure allegedly offered for sale on a cybercrime forum
β
An unnamed pharmacy chain in Qatar operating in the healthcare and pharmaceutical sector is allegedly compromised, with a threat actor advertising access to multiple parts of the company's cloud and communications infrastructure.
β
The advertised access includes:
β
β’ MongoDB
β’ Google Cloud Platform (GCP)
β’ SendGrid
β’ Twilio
β’ Access to healthcare/pharmaceutical infrastructure
β
The actor is accepting offers privately and states that payment will be accepted exclusively in Monero (XMR). No public asking price was provided in the listing.
β
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An unnamed pharmacy chain in Qatar operating in the healthcare and pharmaceutical sector is allegedly compromised, with a threat actor advertising access to multiple parts of the company's cloud and communications infrastructure.
β
The advertised access includes:
β
β’ MongoDB
β’ Google Cloud Platform (GCP)
β’ SendGrid
β’ Twilio
β’ Access to healthcare/pharmaceutical infrastructure
β
The actor is accepting offers privately and states that payment will be accepted exclusively in Monero (XMR). No public asking price was provided in the listing.
β
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π²π½ Universidad AutΓ³noma de Sinaloa employee documents allegedly leaked on a cybercrime forum
β
Universidad AutΓ³noma de Sinaloa (UAS), a public university in Sinaloa, Mexico, is allegedly affected by a data exposure after a threat actor claimed to have extracted employee information and documents from a university personnel system.
β
The actor claims the files were organized using employees' RFC and CURP identifiers and contain documentation associated with individual university staff members.
β
The advertised data includes:
β
β’ INE voter identification credentials
β’ Birth certificates
β’ CURP identifiers
β’ RFC tax identifiers
β’ Employee photographs
β’ Proof-of-address documents
β’ Tax and fiscal status certificates
β’ Academic diplomas
β’ Employment contracts and appointment letters
β’ Paid and unpaid leave documents
β’ Full names
β’ Dates of birth
β’ Gender information
β’ Phone numbers
β’ Email addresses
β’ SAT-related tax information
β’ Hire dates, seniority and employment history
β
The post also includes a sample of the alleged employee database and provides a download link for the claimed documents.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Universidad AutΓ³noma de Sinaloa (UAS), a public university in Sinaloa, Mexico, is allegedly affected by a data exposure after a threat actor claimed to have extracted employee information and documents from a university personnel system.
β
The actor claims the files were organized using employees' RFC and CURP identifiers and contain documentation associated with individual university staff members.
β
The advertised data includes:
β
β’ INE voter identification credentials
β’ Birth certificates
β’ CURP identifiers
β’ RFC tax identifiers
β’ Employee photographs
β’ Proof-of-address documents
β’ Tax and fiscal status certificates
β’ Academic diplomas
β’ Employment contracts and appointment letters
β’ Paid and unpaid leave documents
β’ Full names
β’ Dates of birth
β’ Gender information
β’ Phone numbers
β’ Email addresses
β’ SAT-related tax information
β’ Hire dates, seniority and employment history
β
The post also includes a sample of the alleged employee database and provides a download link for the claimed documents.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π¨π³ FBI knocks China-linked QScan and QTRouter hacking infrastructure offline
The DOJ and FBI seized domains powering two hacking platforms operated by QTFY, a Chinese state-sponsored group tied to Nanjing Xinjiuwei Network Technology Company.
U.S. officials say QTFY has compromised or targeted sensitive networks including NASA, the Federal Reserve, Department of Energy, DOJ, HHS, NIH, and the U.S. Senate.
QScan automatically scans for and infects thousands of IoT devices worldwide.
Those compromised devices are then incorporated into QTRouter, an obfuscation network combining hacked IoT devices, commercial proxies, and leased VPS infrastructure to hide the China-based origin of intrusion activity.
Court documents say QTFY sells hacking services to paying customers including China's Ministry of State Security and People's Liberation Army.
Because the seized domains were hard-coded into QScan and QTRouter for authentication and communications, the FBI says the operation rendered both platforms inoperable.
The infrastructure has been linked to malicious activity dating back to at least 2018.
Seized: qtproxy[.]xyz
Source: https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers
The DOJ and FBI seized domains powering two hacking platforms operated by QTFY, a Chinese state-sponsored group tied to Nanjing Xinjiuwei Network Technology Company.
U.S. officials say QTFY has compromised or targeted sensitive networks including NASA, the Federal Reserve, Department of Energy, DOJ, HHS, NIH, and the U.S. Senate.
QScan automatically scans for and infects thousands of IoT devices worldwide.
Those compromised devices are then incorporated into QTRouter, an obfuscation network combining hacked IoT devices, commercial proxies, and leased VPS infrastructure to hide the China-based origin of intrusion activity.
Court documents say QTFY sells hacking services to paying customers including China's Ministry of State Security and People's Liberation Army.
Because the seized domains were hard-coded into QScan and QTRouter for authentication and communications, the FBI says the operation rendered both platforms inoperable.
The infrastructure has been linked to malicious activity dating back to at least 2018.
Seized: qtproxy[.]xyz
Source: https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers
There is an issue with Telegram claims not showing on the threat feed, I'm looking into it and don't have a solution yet.
π¨π¨π¦ Chatr Wireless exploit allegedly exposes subscriber data through phone-number lookups
β
Chatr Wireless, a Canadian mobile service provider, is the subject of a cybercrime forum listing where a threat actor is selling what they claim is a vulnerability capable of retrieving extensive account information tied to a subscriber's real phone number.
β
The allegedly exposed data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Dates of birth
β’ Account IDs and status
β’ Account balances
β’ Addresses and location information
β’ Billing and payment-related fields
β’ Plan and subscription information
β’ Add-ons and account features
β’ Account history and activity
β’ Customer and service identifiers
β’ Notification and preference settings
β’ Additional internal account fields
β
The actor claims the lookup requires a subscriber's real phone number rather than their Chatr virtual number and is offering three free lookups to prospective buyers who can provide a number confirmed to have a Chatr account.
β
The primary exploit is advertised for $150 in XMR, with sales allegedly limited to five buyers. A second claimed exploit capable of scraping user information across ID ranges is being offered for an additional $30.
β
The seller's claims and the functionality, scope and current validity of the alleged vulnerabilities have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Chatr Wireless, a Canadian mobile service provider, is the subject of a cybercrime forum listing where a threat actor is selling what they claim is a vulnerability capable of retrieving extensive account information tied to a subscriber's real phone number.
β
The allegedly exposed data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Dates of birth
β’ Account IDs and status
β’ Account balances
β’ Addresses and location information
β’ Billing and payment-related fields
β’ Plan and subscription information
β’ Add-ons and account features
β’ Account history and activity
β’ Customer and service identifiers
β’ Notification and preference settings
β’ Additional internal account fields
β
The actor claims the lookup requires a subscriber's real phone number rather than their Chatr virtual number and is offering three free lookups to prospective buyers who can provide a number confirmed to have a Chatr account.
β
The primary exploit is advertised for $150 in XMR, with sales allegedly limited to five buyers. A second claimed exploit capable of scraping user information across ID ranges is being offered for an additional $30.
β
The seller's claims and the functionality, scope and current validity of the alleged vulnerabilities have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ Hinge database allegedly offered for sale on a cybercrime forum, 34M+ unique user records claimed
β
Hinge, a dating application operated by Match Group, is allegedly affected by a data exposure after a threat actor advertised what they claim is the platform's complete database containing more than 34 million unique user records.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Dates of birth and ages
β’ Gender and pronouns
β’ Sexual orientation
β’ Cities, states and countries
β’ Ethnicity and religion
β’ Political preferences
β’ Drinking and smoking information
β’ Marijuana and drug-use preferences
β’ Children and family plans
β’ Dating intentions and relationship preferences
β’ Education and employment information
β’ Profile prompts and answers
β’ Account and verification status
β’ Subscription and billing metadata
β’ Match, like and profile activity information
β
The actor published a sample of the alleged database containing extensive account and profile fields and is offering the dataset for $350 in cryptocurrency.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Hinge, a dating application operated by Match Group, is allegedly affected by a data exposure after a threat actor advertised what they claim is the platform's complete database containing more than 34 million unique user records.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Dates of birth and ages
β’ Gender and pronouns
β’ Sexual orientation
β’ Cities, states and countries
β’ Ethnicity and religion
β’ Political preferences
β’ Drinking and smoking information
β’ Marijuana and drug-use preferences
β’ Children and family plans
β’ Dating intentions and relationship preferences
β’ Education and employment information
β’ Profile prompts and answers
β’ Account and verification status
β’ Subscription and billing metadata
β’ Match, like and profile activity information
β
The actor published a sample of the alleged database containing extensive account and profile fields and is offering the dataset for $350 in cryptocurrency.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨π«π· I-RUN customer database allegedly leaked on a cybercrime forum, 1M+ records claimed
β
I-RUN, a French online retailer specializing in running and trail-running footwear, apparel and sports equipment, is allegedly affected by a data exposure after a threat actor advertised a 2026 database containing more than 1 million records.
β
The advertised data includes:
β
β’ First names
β’ Last names
β’ Email addresses
β’ Physical addresses
β’ Postal codes
β’ Cities
β’ Mobile phone numbers
β
The listing describes the material as a structured database and includes a sample containing alleged customer records matching the advertised fields.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
I-RUN, a French online retailer specializing in running and trail-running footwear, apparel and sports equipment, is allegedly affected by a data exposure after a threat actor advertised a 2026 database containing more than 1 million records.
β
The advertised data includes:
β
β’ First names
β’ Last names
β’ Email addresses
β’ Physical addresses
β’ Postal codes
β’ Cities
β’ Mobile phone numbers
β
The listing describes the material as a structured database and includes a sample containing alleged customer records matching the advertised fields.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π¨π³ Chinese booking website database allegedly leaked on a cybercrime forum, 1.94M records claimed
β
An unnamed booking website operating in China is allegedly affected by a data exposure after a threat actor published what they claim is a database containing approximately 1.94 million records.
β
The sample published with the listing appears to include:
β
β’ Full names
β’ Email addresses
β’ Usernames or account identifiers
β’ Phone numbers
β’ Chinese identification numbers
β’ Account-related information
β
The actor provided several sample records directly in the thread and is advertising the alleged database as a free download.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An unnamed booking website operating in China is allegedly affected by a data exposure after a threat actor published what they claim is a database containing approximately 1.94 million records.
β
The sample published with the listing appears to include:
β
β’ Full names
β’ Email addresses
β’ Usernames or account identifiers
β’ Phone numbers
β’ Chinese identification numbers
β’ Account-related information
β
The actor provided several sample records directly in the thread and is advertising the alleged database as a free download.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΊπΈ Vercel employee dataset allegedly offered for sale on a cybercrime forum, 800+ records claimed
β
Vercel, a US-based cloud platform used to build and deploy web applications, is allegedly affected by a data exposure after a threat actor advertised what they claim is an updated employee database containing more than 800 records.
β
The advertised data includes:
β
β’ Employee email addresses
β’ Display names
β’ Account creation and update timestamps
β’ Last-seen dates and times
β’ Account status information
β’ Administrator and guest access details
β’ User identity information
β’ Timezone data
β’ Social Security numbers
β’ Work phone numbers
β’ Home addresses
β’ Dates of birth
β
The actor describes the material as a direct dump from Vercel's platform and states the dataset will be sold privately to a single buyer.
β
The alleged dataset is priced at $1,000, with payment accepted in XMR or BTC through escrow.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Vercel, a US-based cloud platform used to build and deploy web applications, is allegedly affected by a data exposure after a threat actor advertised what they claim is an updated employee database containing more than 800 records.
β
The advertised data includes:
β
β’ Employee email addresses
β’ Display names
β’ Account creation and update timestamps
β’ Last-seen dates and times
β’ Account status information
β’ Administrator and guest access details
β’ User identity information
β’ Timezone data
β’ Social Security numbers
β’ Work phone numbers
β’ Home addresses
β’ Dates of birth
β
The actor describes the material as a direct dump from Vercel's platform and states the dataset will be sold privately to a single buyer.
β
The alleged dataset is priced at $1,000, with payment accepted in XMR or BTC through escrow.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: Comptoir de Location Data Published as the Fourteenth Leak From One Platform
Link: https://darkwebinformer.com/comptoir-de-location-data-published-as-the-fourteenth-leak-from-one-platform/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Comptoir de Location Data Published as the Fourteenth Leak From One Platform
Link: https://darkwebinformer.com/comptoir-de-location-data-published-as-the-fourteenth-leak-from-one-platform/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Comptoir de Location Data Published as the Fourteenth Leak From One Platform
A forum actor posting as NikolaT has published what they describe as the database of Comptoir de Location, a French company renting equipment to the construction, public works, materials handling and industrial sectors, giving a size of 13.48 GB across 323β¦
βΌοΈ ShinyHunters is claiming to purchase AWS access key pairs (AKIA:SECRET) that have Bedrock permissions and confirmed model invocation access for specific Claude model variants.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
β€5
βΌοΈ New Dark Web Informer Blog Post!
Title: Fanlore Wiki Accounts Circulating After OTW's Self Reported Breach
Link: https://darkwebinformer.com/fanlore-wiki-accounts-circulating-after-otws-self-reported-breach/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Fanlore Wiki Accounts Circulating After OTW's Self Reported Breach
Link: https://darkwebinformer.com/fanlore-wiki-accounts-circulating-after-otws-self-reported-breach/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Fanlore Wiki Accounts Circulating After OTW's Self Reported Breach
A forum actor posting as 584 has published what they describe as the account database of Fanlore.org, the fan culture wiki operated by the Organization for Transformative Works, the non profit behind Archive of Our Own.
βΌοΈ New Dark Web Informer Blog Post!
Title: 77 Diamonds Customer File Offered With Home Addresses and Appointment Budgets
Link: https://darkwebinformer.com/77-diamonds-customer-file-offered-with-home-addresses-and-appointment-budgets/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: 77 Diamonds Customer File Offered With Home Addresses and Appointment Budgets
Link: https://darkwebinformer.com/77-diamonds-customer-file-offered-with-home-addresses-and-appointment-budgets/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
77 Diamonds Customer File Offered With Home Addresses and Appointment Budgets
A forum actor posting as Jurak is selling what they describe as the customer database of 77 Diamonds, a London jeweller selling bespoke engagement and wedding jewellery through its website and showrooms in Mayfair, Manchester and Glasgow.
βΌοΈπ¨πΊπΈ Big Claim... Qilin is claiming the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)
πΊπΈ Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) - A U.S. federal law enforcement agency within the Department of Justice responsible for enforcing laws involving firearms, explosives, arson, and illegal alcohol and tobacco trafficking.
The listing was posted by Qilin on August 26, 2026; no claimed data volume or file details are shown.
πΊπΈ Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) - A U.S. federal law enforcement agency within the Department of Justice responsible for enforcing laws involving firearms, explosives, arson, and illegal alcohol and tobacco trafficking.
The listing was posted by Qilin on August 26, 2026; no claimed data volume or file details are shown.
1π₯3
This media is not supported in your browser
VIEW IN TELEGRAM
βΌοΈπ«π· A French on-chain investigator has published a video tracing multiple French-Arabic threat actors allegedly converting roughly $23 million in BTC into XMR following a major social engineering heist.
π₯3
π¨πΊπΈ Mercor dataset and source code allegedly offered for sale on a cybercrime forum by LAPSUS$ Group, 4TB claimed
β
Mercor, an AI-powered recruiting and hiring platform, is allegedly affected by a breach after a threat actor operating under the LAPSUS$ Group name advertised what they claim is approximately 4 TB of company data and source code.
β
The advertised material includes:
β
β’ Company dataset
β’ Source code
β’ Approximately 4 TB of claimed data
β’ Sample files provided by the actor
β
The listing describes the material as originating from a 2026 Mercor breach and includes multiple sample links intended to demonstrate possession of the alleged data.
β
The actor is asking $50,000 for the material and provided encrypted contact methods for prospective buyers.
β
The claims and the authenticity, source and scope of the allegedly exposed data and source code have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Mercor, an AI-powered recruiting and hiring platform, is allegedly affected by a breach after a threat actor operating under the LAPSUS$ Group name advertised what they claim is approximately 4 TB of company data and source code.
β
The advertised material includes:
β
β’ Company dataset
β’ Source code
β’ Approximately 4 TB of claimed data
β’ Sample files provided by the actor
β
The listing describes the material as originating from a 2026 Mercor breach and includes multiple sample links intended to demonstrate possession of the alleged data.
β
The actor is asking $50,000 for the material and provided encrypted contact methods for prospective buyers.
β
The claims and the authenticity, source and scope of the allegedly exposed data and source code have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing