🚨 Four French organizations allegedly targeted in data leaks, including Tisséo, CRMA Occitanie, BCTI and Charbonneaux-Brabant
⠀
Threat actor ChimeraZ has published four separate datasets allegedly obtained from French organizations, exposing personnel, business, operational and identity-related information.
⠀
The affected organizations and claimed data include:
⠀
• CRMA Occitanie: 1,029 records in a 60 KB CSV dataset, including names, email addresses and regional/organizational information
• BCTI / partenaires.bcti.fr: 12 MB partial dataset in JSON/PDF format containing business mission, appointment, property and billing-related records, along with a folder allegedly containing 21 French identity cards
• Charbonneaux-Brabant: 2,863 records in a 660 KB JSON dataset containing names, email addresses, usernames, language, job functions, customer profiles and other account-related fields
• Tisséo: 13,446 records associated with 2,877 people in a 1.22 GB JSON dataset, including employee names, email addresses, personnel IDs, departments, services, job roles, work locations and additional internal workforce information
⠀
Tisséo operates Toulouse’s public transport network, while CRMA Occitanie supports businesses and artisans across the Occitanie region. Charbonneaux-Brabant specializes in packaging and household products, and the BCTI portal serves professional partners and organizations.
⠀
Samples were published for each alleged dataset, with the actor also providing download links for the material.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Threat actor ChimeraZ has published four separate datasets allegedly obtained from French organizations, exposing personnel, business, operational and identity-related information.
⠀
The affected organizations and claimed data include:
⠀
• CRMA Occitanie: 1,029 records in a 60 KB CSV dataset, including names, email addresses and regional/organizational information
• BCTI / partenaires.bcti.fr: 12 MB partial dataset in JSON/PDF format containing business mission, appointment, property and billing-related records, along with a folder allegedly containing 21 French identity cards
• Charbonneaux-Brabant: 2,863 records in a 660 KB JSON dataset containing names, email addresses, usernames, language, job functions, customer profiles and other account-related fields
• Tisséo: 13,446 records associated with 2,877 people in a 1.22 GB JSON dataset, including employee names, email addresses, personnel IDs, departments, services, job roles, work locations and additional internal workforce information
⠀
Tisséo operates Toulouse’s public transport network, while CRMA Occitanie supports businesses and artisans across the Occitanie region. Charbonneaux-Brabant specializes in packaging and household products, and the BCTI portal serves professional partners and organizations.
⠀
Samples were published for each alleged dataset, with the actor also providing download links for the material.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🔪 Slice For Life - Part 2 🔪
‼️ New Ransomware Group: Vexy Dark Web Onion: http://vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd[.]onion
‼️ Vexy Ransomware Affiliate Program
‼️ New Dark Web Informer Blog Post!
Title: ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars
Link: https://darkwebinformer.com/zerogaspi-customer-records-for-89-281-french-shoppers-sold-for-70-dollars/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars
Link: https://darkwebinformer.com/zerogaspi-customer-records-for-89-281-french-shoppers-sold-for-70-dollars/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars
A forum actor posting as ksye is selling what they describe as the customer database of zerogaspi.fr, a French retailer selling surplus and short dated groceries.
❤1
‼️ New Dark Web Informer Blog Post!
Title: 3.1 Million DZI Records Offered With National ID and Passport Numbers
Link: https://darkwebinformer.com/3-1-million-dzi-records-offered-with-national-id-and-passport-numbers/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: 3.1 Million DZI Records Offered With National ID and Passport Numbers
Link: https://darkwebinformer.com/3-1-million-dzi-records-offered-with-national-id-and-passport-numbers/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
3.1 Million DZI Records Offered With National ID and Passport Numbers
A forum actor posting as Intelligence is selling what they describe as 3,134,269 full personal data records belonging to customers of DZI Insurance, Bulgaria's oldest insurer and a subsidiary of Belgium's KBC Group.
🚨🇮🇳 FortiGate appliance credentials tied to multiple Indian IT companies allegedly offered for sale on a cybercrime forum
⠀
Multiple small and medium-sized IT and consulting companies in India are allegedly affected after a threat actor advertised credentials associated with their FortiGate appliances.
⠀
The seller describes the affected organizations as primarily providing IT support and consulting services, with claimed annual revenues ranging from approximately $300,000 to $1.5 million.
⠀
The advertised access includes:
⠀
• FortiGate appliance credentials
• IP addresses
• Usernames
• Passwords
• FortiGate identifiers
• Access associated with IT and consulting environments
⠀
The number of affected users or appliances is not specified in the listing.
⠀
The actor is asking $5,000 or a higher offer for the alleged access and is offering proof privately to prospective buyers.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised credentials have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Multiple small and medium-sized IT and consulting companies in India are allegedly affected after a threat actor advertised credentials associated with their FortiGate appliances.
⠀
The seller describes the affected organizations as primarily providing IT support and consulting services, with claimed annual revenues ranging from approximately $300,000 to $1.5 million.
⠀
The advertised access includes:
⠀
• FortiGate appliance credentials
• IP addresses
• Usernames
• Passwords
• FortiGate identifiers
• Access associated with IT and consulting environments
⠀
The number of affected users or appliances is not specified in the listing.
⠀
The actor is asking $5,000 or a higher offer for the alleged access and is offering proof privately to prospective buyers.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised credentials have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A forum actor is offering edge device access to three American organizations, including two with over 5 million in revenue/size and one multi-billion revenue entity, claiming the access allows reaching Domain Admin.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Motorola internal AI and GenAI infrastructure access allegedly offered for sale on a cybercrime forum
⠀
Motorola, a U.S.-based telecommunications and technology company, is allegedly affected by a significant security compromise after a threat actor claimed to have accessed internal environments supporting the company’s GenAI and AI engineering infrastructure.
⠀
The actor claims the compromised environment includes:
⠀
• Internal repositories and source code
• GenAI modules, proxies and custom agents
• Model Context Protocol (MCP) servers
• Jira MCP infrastructure
• Frog MCP infrastructure
• Bitbucket MCP infrastructure
• Enterprise integration systems
• CI/CD pipelines
• Salesforce-related pipelines
• ServiceNow-related pipelines
• Azure RAG infrastructure
• Internal documentation
• Chat transcripts
• Monitoring and reporting systems
• Additional AI engineering assets
⠀
The actor published multiple screenshots presented as proof of access and states that the compromised environment and associated assets are now being offered for sale.
⠀
No public asking price is provided, with prospective buyers directed to contact the actor privately for verification, additional details and pricing.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Motorola, a U.S.-based telecommunications and technology company, is allegedly affected by a significant security compromise after a threat actor claimed to have accessed internal environments supporting the company’s GenAI and AI engineering infrastructure.
⠀
The actor claims the compromised environment includes:
⠀
• Internal repositories and source code
• GenAI modules, proxies and custom agents
• Model Context Protocol (MCP) servers
• Jira MCP infrastructure
• Frog MCP infrastructure
• Bitbucket MCP infrastructure
• Enterprise integration systems
• CI/CD pipelines
• Salesforce-related pipelines
• ServiceNow-related pipelines
• Azure RAG infrastructure
• Internal documentation
• Chat transcripts
• Monitoring and reporting systems
• Additional AI engineering assets
⠀
The actor published multiple screenshots presented as proof of access and states that the compromised environment and associated assets are now being offered for sale.
⠀
No public asking price is provided, with prospective buyers directed to contact the actor privately for verification, additional details and pricing.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: More Than a Million Salt Mobile Records Offered for Sale
Link: https://darkwebinformer.com/more-than-a-million-salt-mobile-records-offered-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: More Than a Million Salt Mobile Records Offered for Sale
Link: https://darkwebinformer.com/more-than-a-million-salt-mobile-records-offered-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
More Than a Million Salt Mobile Records Offered for Sale
A forum actor posting as SaltMobile1 is selling what they describe as a database of Salt, a Swiss mobile operator, containing more than 1,090,000 records.
‼️ New Dark Web Informer Blog Post!
Title: HopCharge Analytics Export Published With Names, Phones and Coordinates
Link: https://darkwebinformer.com/hopcharge-analytics-export-published-with-names-phones-and-coordinates/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: HopCharge Analytics Export Published With Names, Phones and Coordinates
Link: https://darkwebinformer.com/hopcharge-analytics-export-published-with-names-phones-and-coordinates/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
HopCharge Analytics Export Published With Names, Phones and Coordinates
A forum actor posting as GoreTerminal has published what they describe as the database of hopcharge.com, an on demand doorstep electric vehicle charging service operating in India through mobile vans.
‼️ New Dark Web Informer Blog Post!
Title: Réso Files Totalling 675 GB Offered for Sale After a Silent Period Ends
Link: https://darkwebinformer.com/reso-files-totalling-675-gb-offered-for-sale-after-a-silent-period-ends/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Réso Files Totalling 675 GB Offered for Sale After a Silent Period Ends
Link: https://darkwebinformer.com/reso-files-totalling-675-gb-offered-for-sale-after-a-silent-period-ends/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Réso Files Totalling 675 GB Offered for Sale After a Silent Period Ends
A forum actor posting as caustic claims to hold 675 GB taken from the network of Réso, a French supplier of construction products including ceilings, partitions, floors and facades, with agencies across the country.
Instagram OSINT Relationship Analysis 👇
https://github.com/0x6rss/instagram-private-graph
Demo/Credit: https://x.com/0x6rss/status/2095553053931798806
https://github.com/0x6rss/instagram-private-graph
Demo/Credit: https://x.com/0x6rss/status/2095553053931798806
❤1
🚨🇪🇸 Dataset from unnamed Spanish InsurTech platform allegedly offered for sale, 2.15M+ records with IBAN data claimed
⠀
An unnamed major Spanish InsurTech platform is allegedly affected by a data exposure after a threat actor advertised what they describe as a complete internal customer dataset containing more than 2,153,505 records, including personal, business and banking information.
⠀
The actor claims the dataset includes approximately 1.79 million individual records tied to DNI/NIE identifiers, alongside more than 113,000 SL companies, 44,000 communities, 11,000 SA companies and other business entities.
⠀
The advertised data includes:
⠀
• First and last names
• DNI and NIE identifiers
• CIF identifiers
• Person and business entity types
• Dates of birth
• Physical addresses
• Postal codes
• Bank names
• Full IBANs
• Bank entity and branch codes
• Check digits
• Multiple mobile phone numbers
• Landline numbers
• International phone numbers
• Up to four email addresses per record
• Additional customer and financial profile data
⠀
The seller also claims the dataset contains international banking information, including approximately 3,100 IBANs from Andorra, 2,100 from Germany, and records associated with more than 20 additional countries.
⠀
The alleged dataset is being auctioned with a starting price of 8,000, a minimum bid increment of 500, and a buy-now price of 13,500.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
An unnamed major Spanish InsurTech platform is allegedly affected by a data exposure after a threat actor advertised what they describe as a complete internal customer dataset containing more than 2,153,505 records, including personal, business and banking information.
⠀
The actor claims the dataset includes approximately 1.79 million individual records tied to DNI/NIE identifiers, alongside more than 113,000 SL companies, 44,000 communities, 11,000 SA companies and other business entities.
⠀
The advertised data includes:
⠀
• First and last names
• DNI and NIE identifiers
• CIF identifiers
• Person and business entity types
• Dates of birth
• Physical addresses
• Postal codes
• Bank names
• Full IBANs
• Bank entity and branch codes
• Check digits
• Multiple mobile phone numbers
• Landline numbers
• International phone numbers
• Up to four email addresses per record
• Additional customer and financial profile data
⠀
The seller also claims the dataset contains international banking information, including approximately 3,100 IBANs from Andorra, 2,100 from Germany, and records associated with more than 20 additional countries.
⠀
The alleged dataset is being auctioned with a starting price of 8,000, a minimum bid increment of 500, and a buy-now price of 13,500.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 D.C. man pleads guilty to distributing CSAM after FBI undercover investigation
Hershel Andrew Green III, 43, aka “FitddyG,” pleaded guilty to one federal count of distributing child sexual abuse material.
The FBI identified Green while investigating another person involved in distributing CSAM.
In July 2025, an undercover FBI agent exchanged messages with Green and received several videos containing child sexual abuse material.
Investigators identified him through digital records, open-source research, and surveillance at his residence in Washington, D.C.’s Columbia Heights neighborhood.
Green faces between 5 and 20 years in federal prison.
Sentencing is scheduled for November 30.
Source: https://www.justice.gov/usao-dc/pr/dc-man-pleads-guilty-distributing-child-pornography
Hershel Andrew Green III, 43, aka “FitddyG,” pleaded guilty to one federal count of distributing child sexual abuse material.
The FBI identified Green while investigating another person involved in distributing CSAM.
In July 2025, an undercover FBI agent exchanged messages with Green and received several videos containing child sexual abuse material.
Investigators identified him through digital records, open-source research, and surveillance at his residence in Washington, D.C.’s Columbia Heights neighborhood.
Green faces between 5 and 20 years in federal prison.
Sentencing is scheduled for November 30.
Source: https://www.justice.gov/usao-dc/pr/dc-man-pleads-guilty-distributing-child-pornography
❤1🔥1
🔪 Slice For Life - Part 2 🔪
Vexy Ransomware: /chat /server-status
You guys closed /server-status pretty quick. 😭
😭3