βΌοΈπΊπΈπ§πͺπͺπΈ Brain Cipher Ransomware names 8 victims
πΊπΈ Comprehensive Care Services (CCS) - A U.S.-based healthcare services company specializing in perfusion, autotransfusion, cardiac care, and related clinical services.
The listing claims approximately 306,000 documents and files totaling over 200 GB, including 160,000 files containing complete employee personnel records and other sensitive data.
πΊπΈ CR Meyer - A U.S.-based industrial general contractor providing engineering, construction, design-build, and maintenance services.
The listing claims approximately 275,000 documents and files totaling over 330 GB, including a customer dataset covering roughly 250 customers.
πΊπΈ Sago - A U.S.-headquartered global market research and insights company providing qualitative and quantitative research, audience recruitment, and research technology.
The listing claims approximately 56,000 documents and files, including information on business relationships with more than 800 clients and research participants.
πΊπΈ Ahad&Co - A New York-based CPA firm providing tax preparation, accounting, bookkeeping, payroll, and business advisory services.
The listing claims approximately 405,000 documents and files totaling over 300 GB, including a significant amount of banking information and other sensitive records.
π§πͺ Adviesbureau De Beuckelaer BV - A Belgian accounting and tax consultancy serving businesses and self-employed professionals.
The listing claims approximately 415,000 documents and files totaling over 150 GB, with the actor claiming virtually all of the material falls into protected categories, including financial data.
πͺπΈ Seeliger y Conde - A Spanish executive-search and leadership consulting firm.
The listing claims approximately 57,000 documents and files totaling over 40 GB, including personal data belonging to thousands of candidates for senior positions and other corporate information.
πΊπΈ AEI Consultants - A U.S.-based consulting firm providing environmental, building, land, sustainability, valuation, and commercial real-estate due diligence services.
The listing claims approximately 35,000 documents and files totaling over 55 GB, including personal data, real-estate data, internal security and HR information, and infrastructure-related records.
πͺπΈ ICOT - A Spanish IT company providing enterprise technology, communications, infrastructure, and digital-transformation solutions.
The listing claims the actor intends to publish more than 200 dataset backups associated with customers using its hosting services.
πΊπΈ Comprehensive Care Services (CCS) - A U.S.-based healthcare services company specializing in perfusion, autotransfusion, cardiac care, and related clinical services.
The listing claims approximately 306,000 documents and files totaling over 200 GB, including 160,000 files containing complete employee personnel records and other sensitive data.
πΊπΈ CR Meyer - A U.S.-based industrial general contractor providing engineering, construction, design-build, and maintenance services.
The listing claims approximately 275,000 documents and files totaling over 330 GB, including a customer dataset covering roughly 250 customers.
πΊπΈ Sago - A U.S.-headquartered global market research and insights company providing qualitative and quantitative research, audience recruitment, and research technology.
The listing claims approximately 56,000 documents and files, including information on business relationships with more than 800 clients and research participants.
πΊπΈ Ahad&Co - A New York-based CPA firm providing tax preparation, accounting, bookkeeping, payroll, and business advisory services.
The listing claims approximately 405,000 documents and files totaling over 300 GB, including a significant amount of banking information and other sensitive records.
π§πͺ Adviesbureau De Beuckelaer BV - A Belgian accounting and tax consultancy serving businesses and self-employed professionals.
The listing claims approximately 415,000 documents and files totaling over 150 GB, with the actor claiming virtually all of the material falls into protected categories, including financial data.
πͺπΈ Seeliger y Conde - A Spanish executive-search and leadership consulting firm.
The listing claims approximately 57,000 documents and files totaling over 40 GB, including personal data belonging to thousands of candidates for senior positions and other corporate information.
πΊπΈ AEI Consultants - A U.S.-based consulting firm providing environmental, building, land, sustainability, valuation, and commercial real-estate due diligence services.
The listing claims approximately 35,000 documents and files totaling over 55 GB, including personal data, real-estate data, internal security and HR information, and infrastructure-related records.
πͺπΈ ICOT - A Spanish IT company providing enterprise technology, communications, infrastructure, and digital-transformation solutions.
The listing claims the actor intends to publish more than 200 dataset backups associated with customers using its hosting services.
β€1
πΊπΈ FBI investigation leads to five Venezuelan nationals pleading guilty to attempting to jackpot Kansas ATMs
https://www.justice.gov/usao-ks/pr/fbi-investigation-leads-five-venezuelan-nationals-plead-guilty-attempting-jackpot-kansas
https://www.justice.gov/usao-ks/pr/fbi-investigation-leads-five-venezuelan-nationals-plead-guilty-attempting-jackpot-kansas
Department of Justice
FBI investigation leads to five Venezuelan nationals pleading guilty to attempting to jackpot Kansas ATMs
After a Federal Bureau of Investigation (FBI) investigation, five Venezuelan nationals admitted guilt in attempting to steal U.S. currency from automated teller machines (ATMs).
π₯1
WHOIS for pwnforums.st
Domain: pwnforums.st
Registered On: 2026-03-31 00:00:00 UTC
Expires On: 2027-03-31 00:00:00 UTC
Updated On: 2026-06-01 00:00:00 UTC
Status:
ok
Name Servers:
frank.ns.cloudflare.com
serenity.ns.cloudflare.com
Registrar: NordNIC
URL: Not Available
Name: Not Available
Email: Not Available
Country: Not Available
Domain: pwnforums.st
Registered On: 2026-03-31 00:00:00 UTC
Expires On: 2027-03-31 00:00:00 UTC
Updated On: 2026-06-01 00:00:00 UTC
Status:
ok
Name Servers:
frank.ns.cloudflare.com
serenity.ns.cloudflare.com
Registrar: NordNIC
URL: Not Available
Name: Not Available
Email: Not Available
Country: Not Available
πͺ Slice For Life - Part 2 πͺ
WHOIS for pwnforums.st Domain: pwnforums.st Registered On: 2026-03-31 00:00:00 UTC Expires On: 2027-03-31 00:00:00 UTC Updated On: 2026-06-01 00:00:00 UTC Status: ok Name Servers: frank.ns.cloudflare.com serenity.ns.cloudflare.com Registrar: NordNICβ¦
Dear John, Please fix your site.
πͺ Slice For Life - Part 2 πͺ
Dear John, Please fix your site.
No, actually don't.
π4π3π€1
π¨π«π· Mutuelle des Motards customer dataset allegedly offered for sale on a cybercrime forum, 1.3M records claimed
β
Mutuelle des Motards, a French mutual insurer specializing in motorcycle and two-wheel vehicle insurance, is allegedly affected by a data exposure after a threat actor advertised what they claim is a customer dataset containing approximately 1.3 million records.
β
The advertised data includes:
β
β’ Customer and contact identifiers
β’ First and last names
β’ Email addresses
β’ Telephone numbers
β’ Mobile numbers
β’ Postal codes
β’ Contact creation dates
β’ Marketing channel information
β’ Marketing scores
β’ Contact and opportunity types
β’ Offer indicators
β’ Call-related fields
β’ Processing and expected dates
β’ Record forwarding status
β’ Additional customer relationship fields
β
The actor describes the dataset as being in JSON format and published sample records containing customer contact and marketing-related information.
β
No public asking price or dataset size is provided in the listing.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Mutuelle des Motards, a French mutual insurer specializing in motorcycle and two-wheel vehicle insurance, is allegedly affected by a data exposure after a threat actor advertised what they claim is a customer dataset containing approximately 1.3 million records.
β
The advertised data includes:
β
β’ Customer and contact identifiers
β’ First and last names
β’ Email addresses
β’ Telephone numbers
β’ Mobile numbers
β’ Postal codes
β’ Contact creation dates
β’ Marketing channel information
β’ Marketing scores
β’ Contact and opportunity types
β’ Offer indicators
β’ Call-related fields
β’ Processing and expected dates
β’ Record forwarding status
β’ Additional customer relationship fields
β
The actor describes the dataset as being in JSON format and published sample records containing customer contact and marketing-related information.
β
No public asking price or dataset size is provided in the listing.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈπ¬π§ FulcrumSec announces Manchester Airports Group (MAG)
π¬π§ Manchester Airports Group (MAG) - A UK airport operator managing Manchester Airport, London Stansted Airport, and East Midlands Airport.
The listing claims approximately 550 GB of data, including 8,672,291 customer profiles, 1.169 billion marketing events, 2,482,763 purchases, 461,433 SMS messages, 108,077 vehicle registrations, platform configuration data, and future booking information.
The group claims access was obtained through exposed Iterable administrative keys in the airportsβ frontend code.
π¬π§ Manchester Airports Group (MAG) - A UK airport operator managing Manchester Airport, London Stansted Airport, and East Midlands Airport.
The listing claims approximately 550 GB of data, including 8,672,291 customer profiles, 1.169 billion marketing events, 2,482,763 purchases, 461,433 SMS messages, 108,077 vehicle registrations, platform configuration data, and future booking information.
The group claims access was obtained through exposed Iterable administrative keys in the airportsβ frontend code.
π¨πͺπΈ Reig Jofre dataset allegedly stolen and offered for sale on a cybercrime forum, WordPress records and internal data claimed
β
Laboratorio Reig Jofre, a Spanish pharmaceutical company, is allegedly affected by a security breach after a threat actor claimed to have compromised an internal asset, extracted company data and subsequently deleted the underlying dataset.
β
The advertised material includes:
β
β’ Full WordPress SQL dataset
β’ Approximately 6,098 user records
β’ Full names
β’ Email addresses
β’ Hashed passwords
β’ Pharmacy names
β’ CIF/NIF identifiers
β’ Postal codes
β’ Phone numbers
β’ Professional categories
β’ Contact form submissions
β’ Client and prospect communications
β’ Administrative and scheduler logs
β’ Cookie scan records
β’ Internal operational data
β’ Pharmacy professional and partner information
β’ Internal employee references
β’ Communication logs
β’ Custom WordPress tables and metadata
β
The actor claims the material includes multiple form submissions containing personal data and requests, alongside structured records associated with pharmacy professionals and partner organizations.
β
A password-protected sample was published as alleged proof of the dataset and access. The actor states the complete material is now being offered for sale.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Laboratorio Reig Jofre, a Spanish pharmaceutical company, is allegedly affected by a security breach after a threat actor claimed to have compromised an internal asset, extracted company data and subsequently deleted the underlying dataset.
β
The advertised material includes:
β
β’ Full WordPress SQL dataset
β’ Approximately 6,098 user records
β’ Full names
β’ Email addresses
β’ Hashed passwords
β’ Pharmacy names
β’ CIF/NIF identifiers
β’ Postal codes
β’ Phone numbers
β’ Professional categories
β’ Contact form submissions
β’ Client and prospect communications
β’ Administrative and scheduler logs
β’ Cookie scan records
β’ Internal operational data
β’ Pharmacy professional and partner information
β’ Internal employee references
β’ Communication logs
β’ Custom WordPress tables and metadata
β
The actor claims the material includes multiple form submissions containing personal data and requests, alongside structured records associated with pharmacy professionals and partner organizations.
β
A password-protected sample was published as alleged proof of the dataset and access. The actor states the complete material is now being offered for sale.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π¦π· Access to Argentinian insurance company allegedly offered for sale on a cybercrime forum for $2,000
β
An unnamed insurance company in Argentina, with claimed annual revenue of approximately $30 million, is allegedly compromised after a threat actor advertised access to its corporate environment.
β
The advertised access includes:
β
β’ Domain user access
β’ VNC remote access
β’ Access to a domain-joined system
β’ Microsoft Defender present on the environment
β’ Insurance sector organization
β’ Privately held company
β
The actor is asking $2,000 for the access. The listing does not identify the affected company or provide additional information regarding the size of the network or level of privileges available.
β
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An unnamed insurance company in Argentina, with claimed annual revenue of approximately $30 million, is allegedly compromised after a threat actor advertised access to its corporate environment.
β
The advertised access includes:
β
β’ Domain user access
β’ VNC remote access
β’ Access to a domain-joined system
β’ Microsoft Defender present on the environment
β’ Insurance sector organization
β’ Privately held company
β
The actor is asking $2,000 for the access. The listing does not identify the affected company or provide additional information regarding the size of the network or level of privileges available.
β
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ If you are receiving a large number of unsolicited password reset emails on X, make sure you have βPassword Reset Protectβ enabled.
I also highly recommend enabling an authenticator app, or even better, using a security key.
I also highly recommend enabling an authenticator app, or even better, using a security key.
πͺ Slice For Life - Part 2 πͺ
βΌοΈ If you are receiving a large number of unsolicited password reset emails on X, make sure you have βPassword Reset Protectβ enabled. I also highly recommend enabling an authenticator app, or even better, using a security key.
Settings and Privacy -> Security and account access -> Security
Media is too big
VIEW IN TELEGRAM
I Live For This S***
Video Credit: Mr. Robot
Video Credit: Mr. Robot