πŸ”ͺ That Dark Web Guy - Part 2 πŸ”ͺ
4.87K subscribers
1.15K photos
64 videos
1.02K links
Download Telegram
Someone asked why I'm sharing 480p video. Bro, tell them to stop recording at 480p... there is nothing I can do there. 😭
😭3
β€ΌοΈπŸ‡ΊπŸ‡Έ McKesson Corporation has filed form 8-K due to a cybersecurity incident.

On August 25, 2026, McKesson Corporation discovered a cybersecurity incident affecting its information systems. An investigation of the incident is in its early stages. Information about the incident, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity.

As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations.

PDF: https://d18rn0p25nwr6d.cloudfront.net/CIK-0000927653/5d76bf4d-9af6-40d2-89cc-6648aa9cbb59.pdf
⚠️ Dark Matter market is currently in maintenance status.

This market is currently the longest running market with a launch date of September 22nd, 2022.
😈2❀1
β€ΌοΈπŸš¨ Rhysida Ransomware claims a nonprofitt Federally Qualified Health Center for 37 BTC

πŸ‡ΊπŸ‡Έ Valley Health Team - A California-based nonprofit Federally Qualified Health Center providing medical, dental, behavioral health, and other primary care services across the Central Valley.

The listing claims 3.28 TB across 9,056,196 files, including SQL databases containing information on 160,870 patients, 4.18 million diagnoses, 7.6 million unencrypted EHR scans, Social Security numbers, passports, other personal data, financial statements, salaries, and tax records.

The data is being offered for 37 BTC.
β€ΌοΈπŸ‡ΊπŸ‡Έ ShinyHunters claims a U.S.-based financial technology.

πŸ‡ΊπŸ‡Έ Jack Henry & Associates - A U.S.-based financial technology company providing core banking, payment processing, digital banking, and other technology services to banks and credit unions.
πŸ”₯2❀1😁1😈1
πŸ”ͺ That Dark Web Guy - Part 2 πŸ”ͺ
β€ΌοΈπŸ‡ΊπŸ‡Έ ShinyHunters claims a U.S.-based financial technology. πŸ‡ΊπŸ‡Έ Jack Henry & Associates - A U.S.-based financial technology company providing core banking, payment processing, digital banking, and other technology services to banks and credit unions.
β€ΌοΈπŸ‡ΊπŸ‡ΈπŸ‡ΈπŸ‡ͺ ShinyHunters claims McKesson and Elekta AB.

πŸ‡ΊπŸ‡Έ McKesson Corporation - A U.S.-based healthcare company providing pharmaceutical distribution, medical supplies, healthcare technology, and related services. The listing claims hundreds of millions of records/rows were compromised, containing sensitive information ranging from PII to PHI.

πŸ‡ΈπŸ‡ͺ Elekta AB - A Swedish medical technology company specializing in radiation therapy, radiosurgery, and oncology software used in cancer treatment. The listing includes a September 1, 2026 deadline, but does not specify the claimed data volume or types of information compromised.
❀2πŸ”₯1😈1
πŸš¨πŸ‡«πŸ‡· ZΓ©ro Logement Vacant government dataset allegedly breached, 148M+ raw records claimed
β €
ZΓ©ro Logement Vacant (ZLV), a French government initiative connected to housing and property data, is allegedly affected by a major data exposure after a threat actor claimed to have compromised administrative infrastructure and extracted information linked to DGFiP/DataFoncier datasets.
β €
The actor claims the extraction contains 148,929,194 raw records, representing tens of millions of individuals after deduplication.
β €
The advertised data includes:
β €
β€’ 82,043,407 property-owner records
β€’ 66,874,995 national DGFiP/DataFoncier records
β€’ Names
β€’ Dates of birth
β€’ Physical addresses
β€’ Fiscal identifiers
β€’ 47,948,974 unique individuals by person ID
β€’ 71,065,268 unique individuals when matched by full name and date of birth
β€’ 3,538 ZLV user accounts
β€’ 3,448 bcrypt password hashes
β€’ 1,636 active session tokens
β€’ 3,204 OAuth account records
β€’ Email addresses and phone numbers
β€’ Government and local-authority account information
β€’ JWT and API-related metadata
β€’ Internal database connection information
β €
The threat actor claims access was obtained through an administrative Metabase environment connected to production infrastructure, providing visibility into ZLV application data and large national property-owner datasets.
β €
The listing includes a sample archive containing property-owner records and smaller samples of account, email, phone, session and authentication-related information. The complete alleged dataset is being offered privately, with the price listed as "Offer."
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
πŸ”₯1
πŸͺ½ GitHub Tool: LastSignal

LastSignal is an open-source, self-hosted dead man's switch designed to automatically deliver encrypted messages to selected recipients if you become unresponsive.

The system sends periodic email check-ins. If repeated check-ins are missed, it progresses through reminders, can notify a trusted contact, and eventually releases the configured messages.

The repo currently has 716 GitHub stars.

Key features include:

β€’ End-to-end encrypted messages
β€’ Zero-knowledge architecture
β€’ Self-hosted deployment
β€’ Configurable check-in intervals
β€’ Multiple reminder attempts
β€’ Trusted contact verification
β€’ Recipient-specific delivery delays
β€’ Optional machine-to-machine keep-alive webhook
β€’ Argon2id + XChaCha20-Poly1305 + X25519 cryptography
β€’ Docker and Kamal deployment support

πŸ”— GitHub: https://github.com/giovantenne/lastsignal
❀3
🚨 RaidForums domain has been suspended.

raidforums[.]as
😁2😭2❀1
πŸš¨πŸ‡§πŸ‡· Brazilian citizen dataset allegedly leaked on a cybercrime forum, 213M+ records claimed
β €
SERPRO (ServiΓ§o Federal de Processamento de Dados), Brazil’s federal data processing service, is named in a cybercrime forum post where a threat actor claims to have obtained a dataset containing 213,968,521 Brazilian citizen records.
β €
The advertised data includes:
β €
β€’ CPF identifiers
β€’ Full names
β€’ Gender information
β€’ Dates of birth
β€’ Additional citizen-related records
β €
The actor published what they describe as a 5 million-record proof of concept from the alleged dataset.
β €
The complete dataset is claimed to be approximately 13.6 GB and provided in .DB format.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 SAURON SWP Loader advertised for automated stealer and RAT deployment across WordPress sites
β €
A threat actor is advertising SAURON SWP Loader, a platform designed to automate the deployment of stealers, RATs, malicious JavaScript and PHP payloads across compromised WordPress websites.
β €
The advertised features include:
β €
β€’ High-volume log checking, claimed at 100K+
β€’ Log validation
β€’ Web shell uploading
β€’ WordPress plugin uploading
β€’ JavaScript injection
β€’ PHP injection
β€’ Automated content posting
β€’ SEO tracking for modified websites
β€’ Custom shell support
β€’ Custom JS and PHP payload support
β€’ Theme and plugin customization
β€’ Dedicated server environment for each customer
β€’ Support for FakeCaptcha-style delivery methods
β€’ Malware installation and JS injection workflows
β €
The seller claims the platform can process more than 20,000 WordPress sites per hour when used with suitable proxies and describes it as a tool for distributing stealers and RATs at scale.
β €
The service is advertised for $300 per month, with prospective buyers directed to contact the seller privately for purchases or testing.
β €
The seller's claims and the capabilities, performance and effectiveness of the advertised tool have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1
🚨 RightInbox dataset allegedly leaked on a cybercrime forum, 121K+ unique profiles and 39.47M activity records claimed
β €
RightInbox, a Gmail productivity tool used for email scheduling, reminders, tracking and recurring messages, is allegedly affected by a data exposure after a threat actor published what they claim is information tied to 121,616 unique user profiles.
β €
The actor additionally claims to have obtained approximately 39,471,186 user activity records associated with those profiles.
β €
The advertised data includes:
β €
β€’ 121,616 unique email addresses
β€’ 121,616 unique user IDs
β€’ 84,836 unique IP addresses
β€’ 12,151 cities
β€’ 2,299 regions
β€’ 219 countries
β€’ Account and subscription information
β€’ Subscription plan and payment-related fields
β€’ Failed payment status information
β€’ Notification status data
β€’ IP-based location information
β€’ Latitude and longitude data
β€’ Device brands and manufacturers
β€’ Device models and device types
β€’ Operating system information
β€’ Application platform information
β€’ Browser/app version information
β€’ Language settings
β€’ User properties and activity data
β €
The actor claims one file contains the 121,616 deduplicated profiles, while a second contains approximately 39.47 million associated activity records. The material is advertised as a free download, with the compressed package listed at approximately 445 MB.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing