🔪 That Dark Web Guy - Part 3 🔪
4.93K subscribers
1.2K photos
68 videos
1.07K links
Download Telegram
🔪 That Dark Web Guy - Part 3 🔪
‼️🚨🇺🇸 Big Claim... Qilin is claiming the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) 🇺🇸 Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) - A U.S. federal law enforcement agency within the Department of Justice responsible for enforcing…
🚨🇺🇸 The ATF has released a press release regarding Qilin Ransomware's claim.

"WASHINGTON - The Bureau of Alcohol, Tobacco, Firearms and Explosives is responding to a cybersecurity incident affecting a standalone system. The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system.

Upon discovery of the incident, ATF immediately terminated connections to the affected environment and initiated incident‑response and forensic activities. ATF is coordinating closely with the Department of Justice to investigate.

Senior Department officials have designated the event a “major incident” under applicable federal guidelines, and required notifications have been completed.

The incident has not impacted ATF’s ability to perform its missions."

Source: https://www.atf.gov/news/press-releases/atf-responds-to-cybersecurity-incident
🚨🇷🇺 "Legal services" aimed at cybercrime forum members advertised with prices up to 50,000

An actor on a Russian-language cybercrime forum is advertising what they describe as a full range of legal services, promoting assistance with criminal, financial, military and civil legal matters while emphasizing confidentiality.

The advertised services include:

• Consultations across areas of Russian law
• Assessment of income sources and potential criminal or civil legal risks
• Criminal defense-related assistance
• Military law and deferment assistance
• Help obtaining military documentation
• Contracts, claims and other legal documents
• Debt and microfinance-related disputes
• Challenges involving restrictions on leaving the country
• Assistance with restrictions under Russian 115-FZ and 161-FZ
• Preparation of legal agreements
• Analysis of complex or unusual legal situations

The actor claims to have formal legal education and practical experience, and states that they have received reviews on other underground forums.

The listing displays a price range of 1,500 to 50,000, although the currency is not specified, with prospective clients directed to contact the seller privately.

The advertised qualifications, services and claims have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
I guess TeamPCP forgot about the extended look of GTA 6 today.
😭7
🚨🇺🇸 Initial Access: US AI Company

A threat actor is advertising access to an unnamed U.S. artificial intelligence/fintech company reportedly generating $11M in revenue.

The advertised access includes Slack, Auth0, GCP, MongoDB, Azure, SendGrid, and Grok. Payment is requested in XMR.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ Allure Darknet Market launches 1.5

Dark Web: http://allureg32wdtbv7yzcybds6iakavl3dd6z2aten3l26xpsmeo7dq47id[.]onion

Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/3e4cf9f309984f61f924
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
‼️ DarkForums is back up under the domain I discovered earlier today:

darkforums[.]as

https://x.com/DarkWebInformer/status/2093018895846162799?s=20
6🔥1😁1
🚨🇫🇷 Actis Location dataset allegedly leaked on a cybercrime forum, 464GB and 666K+ files claimed

Actis Location, a French company specializing in the rental of construction, industrial and professional equipment, is allegedly affected by a data exposure after a threat actor published what they claim is company data obtained as part of the BigCloud leak series.

The actor claims the exposed material totals approximately 464 GB and contains 666,155 files, with portions of the data converted to text for publication.

The advertised data includes:

• Email communications
• Employee and customer names
• Email addresses
• Phone numbers
• Physical addresses
• Cities, postal codes and countries
• CRM records
• Customer and company account information
• Internal reference numbers
• Rental and quotation documents
• Contract-related information
• Equipment and product details
• Pricing and payment-related information
• Rental dates and durations
• Additional internal business documents

The forum post includes samples of alleged email, CRM and document data, along with download links for the material. The actor describes Actis Location as BigCloud Leak #15.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇩🇪 EggyWall advertises privacy-focused "bulletproof" VPS hosting with DDoS protection

EggyWall, a hosting provider advertising VPS infrastructure in Frankfurt, Germany, is promoting what it describes as privacy-focused hosting with built-in DDoS protection and minimal restrictions on customer content.

The advertised features include:

• VPS hosting in Frankfurt, Germany
• NVMe SSD storage
• High-speed uplinks
• Full root access
• Free DDoS protection
• Layer 7 WAF protection
• Filtering against malicious HTTP traffic
• Full server control
• Privacy-focused hosting
• "Bulletproof" hosting
• Responsive support

The provider states that DDoS protection is included with every server at no additional cost and advertises a policy summarized as "Your server, your content, your responsibility."

No public pricing is displayed in the forum advertisement, with prospective customers instead directed to contact the provider or initiate a contract.

The provider's claims and the effectiveness, scope and resilience of the advertised hosting and DDoS protections have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇶🇦 Qatar General Retirement & Social Insurance Authority allegedly breached, internal accounts and API tokens exposed

Qatar General Retirement & Social Insurance Authority (GRSIA) is allegedly affected by a breach after a threat actor published samples claiming to originate from systems associated with the authority.

The advertised data includes:

• Internal and partner user accounts
• First and last names
• Email addresses
• User and partner account types
• Partner IDs
• Store IDs
• Account roles and permissions
• Account status information
• API names and environment identifiers
• API authentication tokens
• Token expiration dates
• Record creation and update timestamps

The samples include entries labeled API Testing and GRSIA_PROD, along with records for internal users, partner administrators and store users. Several organizations and partner accounts also appear within the sample data.

The actor additionally published what they claim is a publicly reachable system endpoint and provided a download link containing the alleged material.

The claims and the authenticity, source and scope of the allegedly exposed data and credentials have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing