πŸ”ͺ That Dark Web Guy - Part 2 πŸ”ͺ
4.87K subscribers
1.15K photos
64 videos
1.02K links
Download Telegram
β€ΌοΈπŸ‡ΊπŸ‡Έ ShinyHunters claims a U.S.-based financial technology.

πŸ‡ΊπŸ‡Έ Jack Henry & Associates - A U.S.-based financial technology company providing core banking, payment processing, digital banking, and other technology services to banks and credit unions.
πŸ”₯2❀1😁1😈1
πŸ”ͺ That Dark Web Guy - Part 2 πŸ”ͺ
β€ΌοΈπŸ‡ΊπŸ‡Έ ShinyHunters claims a U.S.-based financial technology. πŸ‡ΊπŸ‡Έ Jack Henry & Associates - A U.S.-based financial technology company providing core banking, payment processing, digital banking, and other technology services to banks and credit unions.
β€ΌοΈπŸ‡ΊπŸ‡ΈπŸ‡ΈπŸ‡ͺ ShinyHunters claims McKesson and Elekta AB.

πŸ‡ΊπŸ‡Έ McKesson Corporation - A U.S.-based healthcare company providing pharmaceutical distribution, medical supplies, healthcare technology, and related services. The listing claims hundreds of millions of records/rows were compromised, containing sensitive information ranging from PII to PHI.

πŸ‡ΈπŸ‡ͺ Elekta AB - A Swedish medical technology company specializing in radiation therapy, radiosurgery, and oncology software used in cancer treatment. The listing includes a September 1, 2026 deadline, but does not specify the claimed data volume or types of information compromised.
❀2πŸ”₯1😈1
πŸš¨πŸ‡«πŸ‡· ZΓ©ro Logement Vacant government dataset allegedly breached, 148M+ raw records claimed
β €
ZΓ©ro Logement Vacant (ZLV), a French government initiative connected to housing and property data, is allegedly affected by a major data exposure after a threat actor claimed to have compromised administrative infrastructure and extracted information linked to DGFiP/DataFoncier datasets.
β €
The actor claims the extraction contains 148,929,194 raw records, representing tens of millions of individuals after deduplication.
β €
The advertised data includes:
β €
β€’ 82,043,407 property-owner records
β€’ 66,874,995 national DGFiP/DataFoncier records
β€’ Names
β€’ Dates of birth
β€’ Physical addresses
β€’ Fiscal identifiers
β€’ 47,948,974 unique individuals by person ID
β€’ 71,065,268 unique individuals when matched by full name and date of birth
β€’ 3,538 ZLV user accounts
β€’ 3,448 bcrypt password hashes
β€’ 1,636 active session tokens
β€’ 3,204 OAuth account records
β€’ Email addresses and phone numbers
β€’ Government and local-authority account information
β€’ JWT and API-related metadata
β€’ Internal database connection information
β €
The threat actor claims access was obtained through an administrative Metabase environment connected to production infrastructure, providing visibility into ZLV application data and large national property-owner datasets.
β €
The listing includes a sample archive containing property-owner records and smaller samples of account, email, phone, session and authentication-related information. The complete alleged dataset is being offered privately, with the price listed as "Offer."
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
πŸ”₯1
πŸͺ½ GitHub Tool: LastSignal

LastSignal is an open-source, self-hosted dead man's switch designed to automatically deliver encrypted messages to selected recipients if you become unresponsive.

The system sends periodic email check-ins. If repeated check-ins are missed, it progresses through reminders, can notify a trusted contact, and eventually releases the configured messages.

The repo currently has 716 GitHub stars.

Key features include:

β€’ End-to-end encrypted messages
β€’ Zero-knowledge architecture
β€’ Self-hosted deployment
β€’ Configurable check-in intervals
β€’ Multiple reminder attempts
β€’ Trusted contact verification
β€’ Recipient-specific delivery delays
β€’ Optional machine-to-machine keep-alive webhook
β€’ Argon2id + XChaCha20-Poly1305 + X25519 cryptography
β€’ Docker and Kamal deployment support

πŸ”— GitHub: https://github.com/giovantenne/lastsignal
❀3
🚨 RaidForums domain has been suspended.

raidforums[.]as
😁2😭2❀1
πŸš¨πŸ‡§πŸ‡· Brazilian citizen dataset allegedly leaked on a cybercrime forum, 213M+ records claimed
β €
SERPRO (ServiΓ§o Federal de Processamento de Dados), Brazil’s federal data processing service, is named in a cybercrime forum post where a threat actor claims to have obtained a dataset containing 213,968,521 Brazilian citizen records.
β €
The advertised data includes:
β €
β€’ CPF identifiers
β€’ Full names
β€’ Gender information
β€’ Dates of birth
β€’ Additional citizen-related records
β €
The actor published what they describe as a 5 million-record proof of concept from the alleged dataset.
β €
The complete dataset is claimed to be approximately 13.6 GB and provided in .DB format.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 SAURON SWP Loader advertised for automated stealer and RAT deployment across WordPress sites
β €
A threat actor is advertising SAURON SWP Loader, a platform designed to automate the deployment of stealers, RATs, malicious JavaScript and PHP payloads across compromised WordPress websites.
β €
The advertised features include:
β €
β€’ High-volume log checking, claimed at 100K+
β€’ Log validation
β€’ Web shell uploading
β€’ WordPress plugin uploading
β€’ JavaScript injection
β€’ PHP injection
β€’ Automated content posting
β€’ SEO tracking for modified websites
β€’ Custom shell support
β€’ Custom JS and PHP payload support
β€’ Theme and plugin customization
β€’ Dedicated server environment for each customer
β€’ Support for FakeCaptcha-style delivery methods
β€’ Malware installation and JS injection workflows
β €
The seller claims the platform can process more than 20,000 WordPress sites per hour when used with suitable proxies and describes it as a tool for distributing stealers and RATs at scale.
β €
The service is advertised for $300 per month, with prospective buyers directed to contact the seller privately for purchases or testing.
β €
The seller's claims and the capabilities, performance and effectiveness of the advertised tool have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1
🚨 RightInbox dataset allegedly leaked on a cybercrime forum, 121K+ unique profiles and 39.47M activity records claimed
β €
RightInbox, a Gmail productivity tool used for email scheduling, reminders, tracking and recurring messages, is allegedly affected by a data exposure after a threat actor published what they claim is information tied to 121,616 unique user profiles.
β €
The actor additionally claims to have obtained approximately 39,471,186 user activity records associated with those profiles.
β €
The advertised data includes:
β €
β€’ 121,616 unique email addresses
β€’ 121,616 unique user IDs
β€’ 84,836 unique IP addresses
β€’ 12,151 cities
β€’ 2,299 regions
β€’ 219 countries
β€’ Account and subscription information
β€’ Subscription plan and payment-related fields
β€’ Failed payment status information
β€’ Notification status data
β€’ IP-based location information
β€’ Latitude and longitude data
β€’ Device brands and manufacturers
β€’ Device models and device types
β€’ Operating system information
β€’ Application platform information
β€’ Browser/app version information
β€’ Language settings
β€’ User properties and activity data
β €
The actor claims one file contains the 121,616 deduplicated profiles, while a second contains approximately 39.47 million associated activity records. The material is advertised as a free download, with the compressed package listed at approximately 445 MB.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ Security researcher Nightmare Eclipse has released a new zero-day dubbed HardBreacher, an elevation-of-privilege vulnerability affecting Kaspersky Endpoint Security.

GitHub: https://github.com/MSNightmare/HardBreacher
❀2
πŸš¨πŸ‡¬πŸ‡ͺ Scroll customer dataset and source code allegedly offered for sale on a cybercrime forum
β €
Scroll, a Georgian kicksharing service, is allegedly affected by a breach after a threat actor claimed to have extracted its customer dataset and obtained access to the company's source code.
β €
The advertised data includes:
β €
β€’ Customer names
β€’ Email addresses
β€’ Phone numbers
β€’ Secondary email and phone information
β€’ Account identifiers
β€’ Payment card metadata
β€’ Masked card numbers
β€’ Card types
β€’ Card expiration dates
β€’ Additional account-related records
β €
The actor also claims to have obtained GitHub fine-grained access tokens providing access to Scroll's repositories and says they downloaded the company's latest source code.
β €
The alleged customer dataset is being offered for $2,500, while the claimed GitHub access and source code are priced separately at $1,000.
β €
The claims and the authenticity, source and scope of the allegedly exposed data, credentials and source code have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New RaidForums domain:

raidforums[.]im

95[.]216[.]247[.]178
πŸ”₯5😭5
1. You do realize there is multiple versions of the D*xbin leak.
2. I don't even know what you're saying. One, what makes this a honeypot? Two... whatever your talking about with searching databases or providing credentials, is not what this platform does, at all.

Some of you are really fucking stupid.
😭4😁3❀1
β€ΌοΈπŸ‡ΊπŸ‡Έ ShinyHunters claims a U.S.-based food and animal safety company.

πŸ‡ΊπŸ‡Έ Neogen Corporation - A U.S.-based food and animal safety company that develops diagnostic tests, veterinary products, genomic solutions, and food-safety technologies.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials