🚨🇺🇸 FLA Wireless dataset reposted on a cybercrime forum, 57K+ order records included
⠀
FLA Wireless, which operates under Florida-based Techy and provides phone accessories, pre-owned devices and device resale services, is the subject of a previously circulated leak that has been reposted on a cybercrime forum.
⠀
The actor states the material was originally posted by another threat actor and contains five CSV files covering orders, invoices, shipments, products and discount codes.
⠀
The advertised data includes:
⠀
• 57,120 order records
• 3,250 invoice records
• 2,065 shipment records
• 14,244 product records
• Customer names
• Email addresses
• Phone and mobile numbers
• Billing and shipping addresses
• Cities, states and ZIP codes
• Payment provider information
• Order and payment status
• Product and pricing information
• Shipping methods and tracking-related fields
• Customer and invoice identifiers
• Discount code information
⠀
The post includes samples from each portion of the alleged dataset and states the material is being reposted after previously being publicly available, rather than presented as a newly obtained breach.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
FLA Wireless, which operates under Florida-based Techy and provides phone accessories, pre-owned devices and device resale services, is the subject of a previously circulated leak that has been reposted on a cybercrime forum.
⠀
The actor states the material was originally posted by another threat actor and contains five CSV files covering orders, invoices, shipments, products and discount codes.
⠀
The advertised data includes:
⠀
• 57,120 order records
• 3,250 invoice records
• 2,065 shipment records
• 14,244 product records
• Customer names
• Email addresses
• Phone and mobile numbers
• Billing and shipping addresses
• Cities, states and ZIP codes
• Payment provider information
• Order and payment status
• Product and pricing information
• Shipping methods and tracking-related fields
• Customer and invoice identifiers
• Discount code information
⠀
The post includes samples from each portion of the alleged dataset and states the material is being reposted after previously being publicly available, rather than presented as a newly obtained breach.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Brian Krebs put together a good article that goes into depth on TeamPCP... "Two Alleged ‘TeamPCP’ Hackers Arrested in Australia"
https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/
https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/
🚨🇬🇧 Loveelectric employee and driver dataset allegedly offered for sale on a cybercrime forum, 877K records claimed
⠀
Loveelectric, a UK-based electric vehicle leasing and employee benefits platform specializing in EV salary sacrifice schemes, is allegedly affected by a data exposure after a threat actor advertised a dataset containing approximately 877,000 records.
⠀
The actor claims the information was obtained in August 2026 through a zero-day vulnerability in a third-party system.
⠀
The advertised data includes:
⠀
• First and last names
• Email addresses
• Phone numbers
• Dates of birth
• Street addresses
• Cities and countries
• Postcodes
• National Insurance numbers
• Driving licence numbers
• Driving licence countries
• User IDs
• Quote IDs
• Weekly working hours
• Occupation information
• Titles
⠀
The listing includes a sample of the alleged dataset and is being offered for $600, with the price described as negotiable.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Loveelectric, a UK-based electric vehicle leasing and employee benefits platform specializing in EV salary sacrifice schemes, is allegedly affected by a data exposure after a threat actor advertised a dataset containing approximately 877,000 records.
⠀
The actor claims the information was obtained in August 2026 through a zero-day vulnerability in a third-party system.
⠀
The advertised data includes:
⠀
• First and last names
• Email addresses
• Phone numbers
• Dates of birth
• Street addresses
• Cities and countries
• Postcodes
• National Insurance numbers
• Driving licence numbers
• Driving licence countries
• User IDs
• Quote IDs
• Weekly working hours
• Occupation information
• Titles
⠀
The listing includes a sample of the alleged dataset and is being offered for $600, with the price described as negotiable.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️🇮🇹 A threat actor is offering for sale a dataset of Italian healthcare leads containing 38 million records, including names, tax numbers, addresses, phone numbers, emails, and birth dates.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🔪 That Dark Web Guy - Part 3 🔪
There is an issue with Telegram claims not showing on the threat feed, I'm looking into it and don't have a solution yet.
Telegram alerts are working again. Also in the midst of figuring that issue out, I found another bug where cybercrime alerts found in the news/media were not populating on the feed for the Cyberattack category. So both issues are fixed now.
🚨🇹🇬 Togolese National Police dataset and identity card records allegedly leaked on a cybercrime forum
⠀
Police Nationale Togolaise, Togo's national police force, is allegedly affected by a data exposure after a threat actor claimed to have leaked government-related records associated with the country's police control system.
⠀
The actor claims the leak contains:
⠀
• 148,882 dataset records
• 90,118 identity card records
• Nationality-related identifiers
• Identity information
• Additional police and government-related records
⠀
The post includes a sample of the alleged dataset along with multiple images presented as proof of access.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Police Nationale Togolaise, Togo's national police force, is allegedly affected by a data exposure after a threat actor claimed to have leaked government-related records associated with the country's police control system.
⠀
The actor claims the leak contains:
⠀
• 148,882 dataset records
• 90,118 identity card records
• Nationality-related identifiers
• Identity information
• Additional police and government-related records
⠀
The post includes a sample of the alleged dataset along with multiple images presented as proof of access.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇸🇦 Nawaqis dataset allegedly leaked on a cybercrime forum, 28GB of data claimed
⠀
Nawaqis, a Saudi Arabia-based B2B wholesale procurement marketplace connecting verified businesses with vendors, is allegedly affected by a major data breach after a threat actor published what they claim is the platform's complete 28GB dataset, compressed to approximately 1GB.
⠀
The actor claims the exposed material includes:
⠀
• 6,374 business accounts
• 7,079 user accounts
• 30,583 product catalog entries
• 734,912 tiered pricing records
• 608,519 inventory records
• 1.97M RFQ line items
• 41,871 quotations
• 3.28M quoted line items
• 3.22M shopping cart records
• 64,483 orders with 4.88M order line items
• 128,710 invoices with 2.48M invoice line items
• Payment and gateway transaction records
• Vendor storefront and business agreement data
• 315,813 notification records across email, WhatsApp, SMS and in-app channels
• Millions of integration and webhook records
• Geocoded shipping address information
• Product analytics and purchase activity
• 5.03M audit log entries
⠀
The actor also claims the material contains password hashes, access tokens, Firebase/FCM tokens and OTP codes.
⠀
According to the listing, the exposed records document approximately SAR 498.3 million in orders between October 2024 and August 2026. The actor is offering the alleged dataset as a free download and additionally claims to have wiped the underlying data after extracting it.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Nawaqis, a Saudi Arabia-based B2B wholesale procurement marketplace connecting verified businesses with vendors, is allegedly affected by a major data breach after a threat actor published what they claim is the platform's complete 28GB dataset, compressed to approximately 1GB.
⠀
The actor claims the exposed material includes:
⠀
• 6,374 business accounts
• 7,079 user accounts
• 30,583 product catalog entries
• 734,912 tiered pricing records
• 608,519 inventory records
• 1.97M RFQ line items
• 41,871 quotations
• 3.28M quoted line items
• 3.22M shopping cart records
• 64,483 orders with 4.88M order line items
• 128,710 invoices with 2.48M invoice line items
• Payment and gateway transaction records
• Vendor storefront and business agreement data
• 315,813 notification records across email, WhatsApp, SMS and in-app channels
• Millions of integration and webhook records
• Geocoded shipping address information
• Product analytics and purchase activity
• 5.03M audit log entries
⠀
The actor also claims the material contains password hashes, access tokens, Firebase/FCM tokens and OTP codes.
⠀
According to the listing, the exposed records document approximately SAR 498.3 million in orders between October 2024 and August 2026. The actor is offering the alleged dataset as a free download and additionally claims to have wiped the underlying data after extracting it.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇪🇸 ODF Energía customer dataset allegedly offered for sale on a cybercrime forum, 22K+ records claimed
⠀
ODF Energía, a Spanish energy company, is allegedly affected by a data exposure after a threat actor advertised what they describe as a fresh dataset containing information on 22,278 individuals in Spain.
⠀
The advertised data includes:
⠀
• Customer status information
• Internal customer codes
• CUPS identifiers
• Postal codes and provinces
• Physical addresses
• Product information
• Contract and activation dates
• Validation and processing dates
• Energy consumption information
• Contracted power details
• Electricity tariff information
• Signature method
• Company names
• CIF tax identifiers
• Email addresses
• Phone numbers
• Scoring information
• Gender
• Dates of birth
⠀
The actor published a sample containing 50 alleged customer records and states that 500 records from the dataset are being offered free to serious prospective buyers.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
ODF Energía, a Spanish energy company, is allegedly affected by a data exposure after a threat actor advertised what they describe as a fresh dataset containing information on 22,278 individuals in Spain.
⠀
The advertised data includes:
⠀
• Customer status information
• Internal customer codes
• CUPS identifiers
• Postal codes and provinces
• Physical addresses
• Product information
• Contract and activation dates
• Validation and processing dates
• Energy consumption information
• Contracted power details
• Electricity tariff information
• Signature method
• Company names
• CIF tax identifiers
• Email addresses
• Phone numbers
• Scoring information
• Gender
• Dates of birth
⠀
The actor published a sample containing 50 alleged customer records and states that 500 records from the dataset are being offered free to serious prospective buyers.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇪🇸 Feníe Energía customer dataset allegedly offered for sale on a cybercrime forum, 555K+ records claimed
⠀
Feníe Energía, a Spanish energy company, is allegedly affected by a data exposure after a threat actor advertised what they describe as a fresh dataset containing information on 555,089 individuals in Spain.
⠀
The advertised data includes:
⠀
• Customer IDs
• Identification numbers
• Identification document types, including NIF/NIE/CIF
• First names
• Surnames
• Phone numbers
• Email addresses
• IBANs
• Bank information
• Provinces
• Municipalities/localities
• Postal codes
⠀
The actor published a sample containing 50 alleged customer records and states that 1,000 records from the dataset are being offered free to serious prospective buyers.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Feníe Energía, a Spanish energy company, is allegedly affected by a data exposure after a threat actor advertised what they describe as a fresh dataset containing information on 555,089 individuals in Spain.
⠀
The advertised data includes:
⠀
• Customer IDs
• Identification numbers
• Identification document types, including NIF/NIE/CIF
• First names
• Surnames
• Phone numbers
• Email addresses
• IBANs
• Bank information
• Provinces
• Municipalities/localities
• Postal codes
⠀
The actor published a sample containing 50 alleged customer records and states that 1,000 records from the dataset are being offered free to serious prospective buyers.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
This media is not supported in your browser
VIEW IN TELEGRAM
🚨🇬🇧 Cyberattack exposes data belonging to 8.7 million customers across three UK airports
Manchester Airports Group says an unauthorized third party obtained customer data connected to Manchester Airport, London Stansted, and East Midlands Airport.
The stolen information relates to airport WiFi sign-ups and car park, lounge, and Fast Track bookings.
Exposed data includes:
• Email addresses
• Phone numbers
• Vehicle registration numbers
• Postcodes
MAG says neither it nor the affected system stores customers' banking or payment information.
Airport operations were not disrupted, and passenger safety and aviation security were not affected.
The company says it contained the incident, restricted access to affected systems, brought in cybersecurity specialists, and notified relevant authorities.
Affected customers are being warned to watch for phishing emails, texts, and calls using the stolen information.
Source: https://news.sky.com/story/customer-data-stolen-after-manchester-airport-targeted-in-cyber-attack-13577714?dcmp=snt-sf-twitter
Manchester Airports Group says an unauthorized third party obtained customer data connected to Manchester Airport, London Stansted, and East Midlands Airport.
The stolen information relates to airport WiFi sign-ups and car park, lounge, and Fast Track bookings.
Exposed data includes:
• Email addresses
• Phone numbers
• Vehicle registration numbers
• Postcodes
MAG says neither it nor the affected system stores customers' banking or payment information.
Airport operations were not disrupted, and passenger safety and aviation security were not affected.
The company says it contained the incident, restricted access to affected systems, brought in cybersecurity specialists, and notified relevant authorities.
Affected customers are being warned to watch for phishing emails, texts, and calls using the stolen information.
Source: https://news.sky.com/story/customer-data-stolen-after-manchester-airport-targeted-in-cyber-attack-13577714?dcmp=snt-sf-twitter
‼️🇨🇭 A threat actor is offering for sale SSL-VPN (Fortinet) access along with root-level SSH access to a Swiss construction management company with $1.2 billion in revenue, spanning 120 hosts.
The seller is requesting $2,000 in BTC/XMR via escrow.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
The seller is requesting $2,000 in BTC/XMR via escrow.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🔪 That Dark Web Guy - Part 3 🔪
‼️🚨🇺🇸 Big Claim... Qilin is claiming the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) 🇺🇸 Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) - A U.S. federal law enforcement agency within the Department of Justice responsible for enforcing…
🚨🇺🇸 The ATF has released a press release regarding Qilin Ransomware's claim.
"WASHINGTON - The Bureau of Alcohol, Tobacco, Firearms and Explosives is responding to a cybersecurity incident affecting a standalone system. The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system.
Upon discovery of the incident, ATF immediately terminated connections to the affected environment and initiated incident‑response and forensic activities. ATF is coordinating closely with the Department of Justice to investigate.
Senior Department officials have designated the event a “major incident” under applicable federal guidelines, and required notifications have been completed.
The incident has not impacted ATF’s ability to perform its missions."
Source: https://www.atf.gov/news/press-releases/atf-responds-to-cybersecurity-incident
"WASHINGTON - The Bureau of Alcohol, Tobacco, Firearms and Explosives is responding to a cybersecurity incident affecting a standalone system. The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system.
Upon discovery of the incident, ATF immediately terminated connections to the affected environment and initiated incident‑response and forensic activities. ATF is coordinating closely with the Department of Justice to investigate.
Senior Department officials have designated the event a “major incident” under applicable federal guidelines, and required notifications have been completed.
The incident has not impacted ATF’s ability to perform its missions."
Source: https://www.atf.gov/news/press-releases/atf-responds-to-cybersecurity-incident
www.atf.gov
ATF responds to cybersecurity incident | ATF
WASHINGTON - The Bureau of Alcohol, Tobacco, Firearms and Explosives is responding to a cybersecurity incident affecting a standalone system. The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident…
🔪 That Dark Web Guy - Part 3 🔪
‼️🇺🇸 ShinyHunters names CyrusOne, LLC. Per the listing: "Update 23 Aug: We are removing the clients name off this post. They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records along…
‼️🇺🇸 ShinyHunters has published the data of CyrusOne, LLC.
‼️ New Dark Web Informer Blog Post!
Title: Journaux.fr Delivery Records Shared Alongside an Unpatched Credit Flaw
Link: https://darkwebinformer.com/journaux-fr-delivery-records-shared-alongside-an-unpatched-credit-flaw/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Journaux.fr Delivery Records Shared Alongside an Unpatched Credit Flaw
Link: https://darkwebinformer.com/journaux-fr-delivery-records-shared-alongside-an-unpatched-credit-flaw/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Journaux.fr Delivery Records Shared Alongside an Unpatched Credit Flaw
A forum actor posting as Alduin has published what they describe as the billing data of journaux.fr, a French site selling newspapers and magazines by issue or subscription in print and digital form.
‼️ New Dark Web Informer Blog Post!
Title: Roomer Travel Account Data on More Than 200,000 Users Shared on a Forum
Link: https://darkwebinformer.com/roomer-travel-account-data-on-more-than-200-000-users-shared-on-a-forum/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Roomer Travel Account Data on More Than 200,000 Users Shared on a Forum
Link: https://darkwebinformer.com/roomer-travel-account-data-on-more-than-200-000-users-shared-on-a-forum/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Roomer Travel Account Data on More Than 200,000 Users Shared on a Forum
A forum actor posting as slvsh3r has published what they describe as the client database of Roomer Travel, a marketplace and mobile app for buying and reselling non refundable hotel reservations.
🚨🇷🇺 "Legal services" aimed at cybercrime forum members advertised with prices up to 50,000
⠀
An actor on a Russian-language cybercrime forum is advertising what they describe as a full range of legal services, promoting assistance with criminal, financial, military and civil legal matters while emphasizing confidentiality.
⠀
The advertised services include:
⠀
• Consultations across areas of Russian law
• Assessment of income sources and potential criminal or civil legal risks
• Criminal defense-related assistance
• Military law and deferment assistance
• Help obtaining military documentation
• Contracts, claims and other legal documents
• Debt and microfinance-related disputes
• Challenges involving restrictions on leaving the country
• Assistance with restrictions under Russian 115-FZ and 161-FZ
• Preparation of legal agreements
• Analysis of complex or unusual legal situations
⠀
The actor claims to have formal legal education and practical experience, and states that they have received reviews on other underground forums.
⠀
The listing displays a price range of 1,500 to 50,000, although the currency is not specified, with prospective clients directed to contact the seller privately.
⠀
The advertised qualifications, services and claims have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
An actor on a Russian-language cybercrime forum is advertising what they describe as a full range of legal services, promoting assistance with criminal, financial, military and civil legal matters while emphasizing confidentiality.
⠀
The advertised services include:
⠀
• Consultations across areas of Russian law
• Assessment of income sources and potential criminal or civil legal risks
• Criminal defense-related assistance
• Military law and deferment assistance
• Help obtaining military documentation
• Contracts, claims and other legal documents
• Debt and microfinance-related disputes
• Challenges involving restrictions on leaving the country
• Assistance with restrictions under Russian 115-FZ and 161-FZ
• Preparation of legal agreements
• Analysis of complex or unusual legal situations
⠀
The actor claims to have formal legal education and practical experience, and states that they have received reviews on other underground forums.
⠀
The listing displays a price range of 1,500 to 50,000, although the currency is not specified, with prospective clients directed to contact the seller privately.
⠀
The advertised qualifications, services and claims have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
I guess TeamPCP forgot about the extended look of GTA 6 today.
😭7