🚨🇬🇧 MKE Engineering Group dataset allegedly leaked on a cybercrime forum, 430GB of data claimed
⠀
MKE Engineering Group, a UK-based mechanical and electrical engineering services provider headquartered in Sittingbourne, Kent, is allegedly affected by a breach after a threat actor claimed to have exfiltrated approximately 430 GB of company data.
⠀
The actor claims the exposed material contains approximately 20,000 folders and 450,000 files, with records spanning from the 2000s through 2026.
⠀
The advertised data includes:
⠀
• Customer and partner information
• Employee and contact records
• Names and email addresses
• Phone numbers
• Invoices
• Purchase orders
• Quotations
• Financial information
• Engineering tests
• Technical drawings
• Private communications
• Internal datasets
• Backups
• Job and service documentation
• Customer account information
• Additional internal business files
⠀
The forum post includes samples of alleged contact records, invoices, purchase orders, quotations and engineering job documentation as proof of the claimed breach.
⠀
The actor states the data remained accessible for approximately a week before publication and claims the company had not detected the intrusion during that period.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
MKE Engineering Group, a UK-based mechanical and electrical engineering services provider headquartered in Sittingbourne, Kent, is allegedly affected by a breach after a threat actor claimed to have exfiltrated approximately 430 GB of company data.
⠀
The actor claims the exposed material contains approximately 20,000 folders and 450,000 files, with records spanning from the 2000s through 2026.
⠀
The advertised data includes:
⠀
• Customer and partner information
• Employee and contact records
• Names and email addresses
• Phone numbers
• Invoices
• Purchase orders
• Quotations
• Financial information
• Engineering tests
• Technical drawings
• Private communications
• Internal datasets
• Backups
• Job and service documentation
• Customer account information
• Additional internal business files
⠀
The forum post includes samples of alleged contact records, invoices, purchase orders, quotations and engineering job documentation as proof of the claimed breach.
⠀
The actor states the data remained accessible for approximately a week before publication and claims the company had not detected the intrusion during that period.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🤔2
🚨🇫🇷 Five French fire and rescue services allegedly targeted in data leaks, nearly 20K personnel records claimed
⠀
A threat actor has published datasets allegedly belonging to five French departmental fire and rescue services (SDIS) across Vosges, Bas-Rhin, Moselle, Gard and Bouches-du-Rhône. Combined, the listings claim information associated with approximately 19,952 people across 22,555 records/lines.
⠀
The affected organizations and claimed figures include:
⠀
• SDIS 88, Vosges: 3,067 people, 4,226 lines, 175 MB CSV
• SDIS 67, Bas-Rhin: 3,584 people, 4,423 lines, 5.83 MB JSON
• SDIS 57, Moselle: 6,434 people, 6,449 lines, 3.20 MB JSON
• SDIS 30, Gard: 3,168 people, 3,757 lines, 300 KB CSV
• SDIS 13, Bouches-du-Rhône: 3,699 people, 3,700 lines, 635 KB JSON
⠀
The advertised data across the leaks includes:
⠀
• Personnel names
• Employee and personnel IDs
• Ranks and job titles
• Email addresses
• Phone numbers
• Fire and rescue center assignments
• Groups and departmental affiliations
• User and account records
• Access rights information
• Login and connection records
• Internal IP addresses
• Password recovery records
• Training and course information
• Additional internal personnel data
⠀
The actor published samples and download links for the alleged datasets. The SDIS 67 post also includes several links claimed to provide access to associated Google Drive folders.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A threat actor has published datasets allegedly belonging to five French departmental fire and rescue services (SDIS) across Vosges, Bas-Rhin, Moselle, Gard and Bouches-du-Rhône. Combined, the listings claim information associated with approximately 19,952 people across 22,555 records/lines.
⠀
The affected organizations and claimed figures include:
⠀
• SDIS 88, Vosges: 3,067 people, 4,226 lines, 175 MB CSV
• SDIS 67, Bas-Rhin: 3,584 people, 4,423 lines, 5.83 MB JSON
• SDIS 57, Moselle: 6,434 people, 6,449 lines, 3.20 MB JSON
• SDIS 30, Gard: 3,168 people, 3,757 lines, 300 KB CSV
• SDIS 13, Bouches-du-Rhône: 3,699 people, 3,700 lines, 635 KB JSON
⠀
The advertised data across the leaks includes:
⠀
• Personnel names
• Employee and personnel IDs
• Ranks and job titles
• Email addresses
• Phone numbers
• Fire and rescue center assignments
• Groups and departmental affiliations
• User and account records
• Access rights information
• Login and connection records
• Internal IP addresses
• Password recovery records
• Training and course information
• Additional internal personnel data
⠀
The actor published samples and download links for the alleged datasets. The SDIS 67 post also includes several links claimed to provide access to associated Google Drive folders.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
🚨🇫🇷 DELKO customer dataset allegedly offered for sale on a cybercrime forum, 50K+ customers claimed
⠀
DELKO, a French automotive maintenance and repair network providing vehicle servicing, mechanical repairs and tire services, is allegedly affected by a data exposure after a threat actor advertised what they claim is the company's complete customer dataset.
⠀
The actor claims the dataset contains information associated with more than 50,000 customers.
⠀
The advertised data includes:
⠀
• Customer IDs
• First and last names
• Email addresses
• Phone numbers
• Vehicle registration numbers
• Account creation dates
• Appointment dates
• Appointment types
• Mechanical service information
• Tire service information
• Vehicle inspection and maintenance records
• Service amounts and pricing fields
• Additional service and appointment details
⠀
The actor published samples of the alleged customer records along with images presented as proof of access.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
DELKO, a French automotive maintenance and repair network providing vehicle servicing, mechanical repairs and tire services, is allegedly affected by a data exposure after a threat actor advertised what they claim is the company's complete customer dataset.
⠀
The actor claims the dataset contains information associated with more than 50,000 customers.
⠀
The advertised data includes:
⠀
• Customer IDs
• First and last names
• Email addresses
• Phone numbers
• Vehicle registration numbers
• Account creation dates
• Appointment dates
• Appointment types
• Mechanical service information
• Tire service information
• Vehicle inspection and maintenance records
• Service amounts and pricing fields
• Additional service and appointment details
⠀
The actor published samples of the alleged customer records along with images presented as proof of access.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 Courir internal infrastructure allegedly compromised, persistent access offered for sale on a cybercrime forum by LAPSUS$ Group.
⠀
Courir, a French footwear and sneaker retailer, is allegedly affected by a significant security breach after a threat actor claimed to have compromised multiple segments of the company's production and development infrastructure.
⠀
The actor claims the intrusion followed a multi-week operation in which internal systems were mapped, compromised and data was exfiltrated. The group is now advertising what it describes as exclusive access packages to Courir's environment.
⠀
The advertised access includes:
⠀
• Internal developer panels
• Full administrative control over development portals
• Internal management interfaces
• High-privilege service accounts
• Alternative internal access points
• Persistent footholds across multiple infrastructure segments
• Internal routing pathways
• Claimed lateral movement across corporate environments
• Access to production and development systems
⠀
The post includes multiple screenshots presented as proof of access and attributes the alleged compromise to a member of the group operating under the name 3xpl0rat0r.
⠀
No public asking price is provided, with prospective buyers directed to negotiate privately.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Courir, a French footwear and sneaker retailer, is allegedly affected by a significant security breach after a threat actor claimed to have compromised multiple segments of the company's production and development infrastructure.
⠀
The actor claims the intrusion followed a multi-week operation in which internal systems were mapped, compromised and data was exfiltrated. The group is now advertising what it describes as exclusive access packages to Courir's environment.
⠀
The advertised access includes:
⠀
• Internal developer panels
• Full administrative control over development portals
• Internal management interfaces
• High-privilege service accounts
• Alternative internal access points
• Persistent footholds across multiple infrastructure segments
• Internal routing pathways
• Claimed lateral movement across corporate environments
• Access to production and development systems
⠀
The post includes multiple screenshots presented as proof of access and attributes the alleged compromise to a member of the group operating under the name 3xpl0rat0r.
⠀
No public asking price is provided, with prospective buyers directed to negotiate privately.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️🇦🇹🇹🇷🇨🇱 DireWolf Ransomware claims a well known video game publisher and 2 hospitals
🇦🇹 THQ Nordic - An Austrian video game publisher and developer based in Vienna, known for franchises including Darksiders, Destroy All Humans!, and SpongeBob SquarePants titles. The listing claims 335 GB of data.
🇹🇷 Erdem Hospital - A Turkish private healthcare provider operating hospitals and medical facilities offering a range of diagnostic, surgical, and specialist services. The listing claims 260 GB of data.
🇨🇱 Hospital Clínico Universidad de Chile - A major university teaching hospital in Santiago affiliated with the University of Chile, providing specialized medical care, education, and clinical research. The listing claims 240 GB of data.
🇦🇹 THQ Nordic - An Austrian video game publisher and developer based in Vienna, known for franchises including Darksiders, Destroy All Humans!, and SpongeBob SquarePants titles. The listing claims 335 GB of data.
🇹🇷 Erdem Hospital - A Turkish private healthcare provider operating hospitals and medical facilities offering a range of diagnostic, surgical, and specialist services. The listing claims 260 GB of data.
🇨🇱 Hospital Clínico Universidad de Chile - A major university teaching hospital in Santiago affiliated with the University of Chile, providing specialized medical care, education, and clinical research. The listing claims 240 GB of data.
🚨🇫🇷 Fédération Française de Tir access allegedly offered for sale on a cybercrime forum, data on up to 300K people claimed accessible
⠀
Fédération Française de Tir (FFTir), France’s national governing body for shooting sports, is allegedly affected by a security issue after a threat actor advertised access to its systems and claimed sensitive member information could potentially be retrieved.
⠀
The actor describes exploitation as high difficulty and claims to have identified a partial IDOR vulnerability, while the presence of SQL injection or other vulnerabilities remains unknown.
⠀
The allegedly accessible data includes:
⠀
• Shooting licence numbers
• Full names
• Email addresses
• Dates of birth
• Gender information
• Club identifiers
• Nationality information
• Disability-status fields
• Licence validity dates
• Account/activity status
• Association and departmental information
• Invoices
• Additional internal documents
⠀
The actor claims successful exploitation could expose information associated with approximately 300,000 people and published samples appearing to show member and licence-related records.
⠀
The listing makes clear that this is not a ready-to-download dataset and states that significant technical skill would be required to use the advertised access. No fixed price is provided, with the seller requesting offers privately.
⠀
The claims and the authenticity, scope and current validity of the alleged access and vulnerabilities have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Fédération Française de Tir (FFTir), France’s national governing body for shooting sports, is allegedly affected by a security issue after a threat actor advertised access to its systems and claimed sensitive member information could potentially be retrieved.
⠀
The actor describes exploitation as high difficulty and claims to have identified a partial IDOR vulnerability, while the presence of SQL injection or other vulnerabilities remains unknown.
⠀
The allegedly accessible data includes:
⠀
• Shooting licence numbers
• Full names
• Email addresses
• Dates of birth
• Gender information
• Club identifiers
• Nationality information
• Disability-status fields
• Licence validity dates
• Account/activity status
• Association and departmental information
• Invoices
• Additional internal documents
⠀
The actor claims successful exploitation could expose information associated with approximately 300,000 people and published samples appearing to show member and licence-related records.
⠀
The listing makes clear that this is not a ready-to-download dataset and states that significant technical skill would be required to use the advertised access. No fixed price is provided, with the seller requesting offers privately.
⠀
The claims and the authenticity, scope and current validity of the alleged access and vulnerabilities have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Windows HVNC malware with source code advertised on a cybercrime forum for $3,000
⠀
A threat actor is advertising Windows HVNC, a hidden virtual network computing tool designed to provide covert remote control over compromised Windows endpoints while remaining largely invisible to the victim.
⠀
The advertised features include:
⠀
• Hidden background operation
• Remote mouse and keyboard control
• Multi-victim C2 management
• Automatic client reconnection
• Remote system information collection
• Application and process control
• Remote browser launching
• File Explorer access
• PowerShell execution
• Native C++ implementation
• Code obfuscation
• Full source code and compiled binary
• EDR/AV evasion claims
• Ongoing support
⠀
The seller claims the malware currently receives a 1/36 detection result when compiled from source and advertises a proof-of-concept involving operation alongside Carbon Black EDR.
⠀
The package is priced at $3,000 and is advertised as including the full source code, binary, one-time FUD service and support, with payment handled through forum escrow.
⠀
The seller's claims and the capabilities, stealth, detection rate and effectiveness of the advertised malware have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A threat actor is advertising Windows HVNC, a hidden virtual network computing tool designed to provide covert remote control over compromised Windows endpoints while remaining largely invisible to the victim.
⠀
The advertised features include:
⠀
• Hidden background operation
• Remote mouse and keyboard control
• Multi-victim C2 management
• Automatic client reconnection
• Remote system information collection
• Application and process control
• Remote browser launching
• File Explorer access
• PowerShell execution
• Native C++ implementation
• Code obfuscation
• Full source code and compiled binary
• EDR/AV evasion claims
• Ongoing support
⠀
The seller claims the malware currently receives a 1/36 detection result when compiled from source and advertises a proof-of-concept involving operation alongside Carbon Black EDR.
⠀
The package is priced at $3,000 and is advertised as including the full source code, binary, one-time FUD service and support, with payment handled through forum escrow.
⠀
The seller's claims and the capabilities, stealth, detection rate and effectiveness of the advertised malware have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ Security researcher Nightmare Eclipse released another zero-day vulnerability.
"GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability"
GitHub: https://github.com/MSNightmare/PrettyPrague
"GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability"
GitHub: https://github.com/MSNightmare/PrettyPrague
❤3