πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.93K subscribers
1.2K photos
68 videos
1.07K links
Download Telegram
There is an issue with Telegram claims not showing on the threat feed, I'm looking into it and don't have a solution yet.
πŸš¨πŸ‡¨πŸ‡¦ Chatr Wireless exploit allegedly exposes subscriber data through phone-number lookups
β €
Chatr Wireless, a Canadian mobile service provider, is the subject of a cybercrime forum listing where a threat actor is selling what they claim is a vulnerability capable of retrieving extensive account information tied to a subscriber's real phone number.
β €
The allegedly exposed data includes:
β €
β€’ Full names
β€’ Email addresses
β€’ Phone numbers
β€’ Dates of birth
β€’ Account IDs and status
β€’ Account balances
β€’ Addresses and location information
β€’ Billing and payment-related fields
β€’ Plan and subscription information
β€’ Add-ons and account features
β€’ Account history and activity
β€’ Customer and service identifiers
β€’ Notification and preference settings
β€’ Additional internal account fields
β €
The actor claims the lookup requires a subscriber's real phone number rather than their Chatr virtual number and is offering three free lookups to prospective buyers who can provide a number confirmed to have a Chatr account.
β €
The primary exploit is advertised for $150 in XMR, with sales allegedly limited to five buyers. A second claimed exploit capable of scraping user information across ID ranges is being offered for an additional $30.
β €
The seller's claims and the functionality, scope and current validity of the alleged vulnerabilities have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Use the link below for anything CYBERLEEK related. This link is defanged so remove the brackets [.]

https://ju3hayvlyj4mbemqheplf3px5d6j673oszj6atv6ukta7phiy22a[.]arweave[.]net/TTZwYqvCeMCRkDkesu336Pyff26WU-BOvqKmD7zoxrQ
❀2
🚨 Hinge database allegedly offered for sale on a cybercrime forum, 34M+ unique user records claimed
β €
Hinge, a dating application operated by Match Group, is allegedly affected by a data exposure after a threat actor advertised what they claim is the platform's complete database containing more than 34 million unique user records.
β €
The advertised data includes:
β €
β€’ Full names
β€’ Email addresses
β€’ Phone numbers
β€’ Dates of birth and ages
β€’ Gender and pronouns
β€’ Sexual orientation
β€’ Cities, states and countries
β€’ Ethnicity and religion
β€’ Political preferences
β€’ Drinking and smoking information
β€’ Marijuana and drug-use preferences
β€’ Children and family plans
β€’ Dating intentions and relationship preferences
β€’ Education and employment information
β€’ Profile prompts and answers
β€’ Account and verification status
β€’ Subscription and billing metadata
β€’ Match, like and profile activity information
β €
The actor published a sample of the alleged database containing extensive account and profile fields and is offering the dataset for $350 in cryptocurrency.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1
πŸš¨πŸ‡«πŸ‡· I-RUN customer database allegedly leaked on a cybercrime forum, 1M+ records claimed
β €
I-RUN, a French online retailer specializing in running and trail-running footwear, apparel and sports equipment, is allegedly affected by a data exposure after a threat actor advertised a 2026 database containing more than 1 million records.
β €
The advertised data includes:
β €
β€’ First names
β€’ Last names
β€’ Email addresses
β€’ Physical addresses
β€’ Postal codes
β€’ Cities
β€’ Mobile phone numbers
β €
The listing describes the material as a structured database and includes a sample containing alleged customer records matching the advertised fields.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡¨πŸ‡³ Chinese booking website database allegedly leaked on a cybercrime forum, 1.94M records claimed
β €
An unnamed booking website operating in China is allegedly affected by a data exposure after a threat actor published what they claim is a database containing approximately 1.94 million records.
β €
The sample published with the listing appears to include:
β €
β€’ Full names
β€’ Email addresses
β€’ Usernames or account identifiers
β€’ Phone numbers
β€’ Chinese identification numbers
β€’ Account-related information
β €
The actor provided several sample records directly in the thread and is advertising the alleged database as a free download.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡ΊπŸ‡Έ Vercel employee dataset allegedly offered for sale on a cybercrime forum, 800+ records claimed
β €
Vercel, a US-based cloud platform used to build and deploy web applications, is allegedly affected by a data exposure after a threat actor advertised what they claim is an updated employee database containing more than 800 records.
β €
The advertised data includes:
β €
β€’ Employee email addresses
β€’ Display names
β€’ Account creation and update timestamps
β€’ Last-seen dates and times
β€’ Account status information
β€’ Administrator and guest access details
β€’ User identity information
β€’ Timezone data
β€’ Social Security numbers
β€’ Work phone numbers
β€’ Home addresses
β€’ Dates of birth
β €
The actor describes the material as a direct dump from Vercel's platform and states the dataset will be sold privately to a single buyer.
β €
The alleged dataset is priced at $1,000, with payment accepted in XMR or BTC through escrow.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ ShinyHunters is claiming to purchase AWS access key pairs (AKIA:SECRET) that have Bedrock permissions and confirmed model invocation access for specific Claude model variants.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
❀5
β€ΌοΈπŸš¨πŸ‡ΊπŸ‡Έ Big Claim... Qilin is claiming the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)

πŸ‡ΊπŸ‡Έ Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) - A U.S. federal law enforcement agency within the Department of Justice responsible for enforcing laws involving firearms, explosives, arson, and illegal alcohol and tobacco trafficking.

The listing was posted by Qilin on August 26, 2026; no claimed data volume or file details are shown.
1πŸ”₯3
This media is not supported in your browser
VIEW IN TELEGRAM
β€ΌοΈπŸ‡«πŸ‡· A French on-chain investigator has published a video tracing multiple French-Arabic threat actors allegedly converting roughly $23 million in BTC into XMR following a major social engineering heist.
πŸ”₯3
πŸš¨πŸ‡ΊπŸ‡Έ Mercor dataset and source code allegedly offered for sale on a cybercrime forum by LAPSUS$ Group, 4TB claimed
β €
Mercor, an AI-powered recruiting and hiring platform, is allegedly affected by a breach after a threat actor operating under the LAPSUS$ Group name advertised what they claim is approximately 4 TB of company data and source code.
β €
The advertised material includes:
β €
β€’ Company dataset
β€’ Source code
β€’ Approximately 4 TB of claimed data
β€’ Sample files provided by the actor
β €
The listing describes the material as originating from a 2026 Mercor breach and includes multiple sample links intended to demonstrate possession of the alleged data.
β €
The actor is asking $50,000 for the material and provided encrypted contact methods for prospective buyers.
β €
The claims and the authenticity, source and scope of the allegedly exposed data and source code have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 If you have any CLN Lightning nodes shut them down now, a critical vulnerability has been found in Core Lightning.
πŸš¨πŸ‡ΊπŸ‡Έ Virginia Beach daycare instructor investigated over alleged dark web CSAM purchases

Federal authorities are investigating Easton Craven, an instructor at Beach Montessori Christian Academy who reportedly supervised a classroom of 3-year-old children.

Investigators allege Craven accessed child sexual abuse material purchased through the dark web, including material depicting children as young as 4 or 5 years old.

The FBI investigation resulted in a federal case, with Craven appearing in court for a detention and preliminary hearing on August 24.

The allegations have raised concerns among parents because of Craven's employment working directly with young children.

The investigation remains ongoing.

Source: https://www.13newsnow.com/article/news/crime/easton-craven-virginia-beach-montessori-christian-academy-fbi/291-5f93a77d-5ecf-42ab-a99b-72cedfeb33fa
😈1
πŸš¨πŸ‡­πŸ‡Ί Complexpress Logisztika dataset allegedly offered for sale on a cybercrime forum, 1M+ records claimed

X: Sorbinfo
β €
Complexpress Logisztika Kft., a Hungarian logistics and e-commerce fulfillment provider, is allegedly affected by a data exposure after a threat actor advertised a 3.8 GB CSV dataset containing shipment and customer information.
β €
The actor claims the dataset contains approximately 1,018,000 unique personal records spanning 2021 through August 2026.
β €
The advertised data includes:
β €
β€’ Shipment tracking numbers
β€’ Parcel destinations
β€’ Parcel status information
β€’ Full names
β€’ Physical addresses
β€’ Email addresses, with 855K+ claimed unique
β€’ Phone numbers, with 1.018M claimed records
β€’ Declared shipment values
β€’ Parcel weights
β€’ Commission payment status
β€’ Sender and recipient information
β€’ Warehouse and logistics-related data
β€’ Additional internal company fields
β €
The listing includes samples of the alleged records and a link to what the actor describes as the full CSV dataset.
β €
The dataset is being offered for $1,200, with the seller stating escrow is accepted.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1