๐จ๐บ๐ธ D.C. man pleads guilty to distributing CSAM after FBI undercover investigation
Hershel Andrew Green III, 43, aka โFitddyG,โ pleaded guilty to one federal count of distributing child sexual abuse material.
The FBI identified Green while investigating another person involved in distributing CSAM.
In July 2025, an undercover FBI agent exchanged messages with Green and received several videos containing child sexual abuse material.
Investigators identified him through digital records, open-source research, and surveillance at his residence in Washington, D.C.โs Columbia Heights neighborhood.
Green faces between 5 and 20 years in federal prison.
Sentencing is scheduled for November 30.
Source: https://www.justice.gov/usao-dc/pr/dc-man-pleads-guilty-distributing-child-pornography
Hershel Andrew Green III, 43, aka โFitddyG,โ pleaded guilty to one federal count of distributing child sexual abuse material.
The FBI identified Green while investigating another person involved in distributing CSAM.
In July 2025, an undercover FBI agent exchanged messages with Green and received several videos containing child sexual abuse material.
Investigators identified him through digital records, open-source research, and surveillance at his residence in Washington, D.C.โs Columbia Heights neighborhood.
Green faces between 5 and 20 years in federal prison.
Sentencing is scheduled for November 30.
Source: https://www.justice.gov/usao-dc/pr/dc-man-pleads-guilty-distributing-child-pornography
โค1๐ฅ1
๐ช Slice For Life - Part 2 ๐ช
Vexy Ransomware: /chat /server-status
You guys closed /server-status pretty quick. ๐ญ
๐ญ3
๐ช Slice For Life - Part 2 ๐ช
โผ๏ธ Fraud Shop: Findsome findsome[.]io [.]ru 192[.]142[.]1[.]95 ASN: 214036 ๐ณ๐ฑ Org: Ultahost, Inc.
Everything is fair game by the way.
๐4๐ค1
๐ช Slice For Life - Part 2 ๐ช
I'm just curious.
I probably should have added more choices.
๐ญ3๐ค1
You suits are quick.
Company Tied to Breach of 153M Driver's Licenses Hit With Multiple Lawsuits
https://www.pcmag.com/news/company-tied-to-breach-of-153m-drivers-licenses-hit-with-multiple-lawsuits
Company Tied to Breach of 153M Driver's Licenses Hit With Multiple Lawsuits
https://www.pcmag.com/news/company-tied-to-breach-of-153m-drivers-licenses-hit-with-multiple-lawsuits
PCMAG
Company Tied to Breach of 153M Driver's Licenses Hit With Multiple Lawsuits
The driver's license data popped up on the dark web via a site called Nexus and was allegedly stolen from IDScan.net. Consumers who believe they were affected are now suing.
๐1
๐จ๐ซ๐ท Prรฉfรฉrence Formations dataset allegedly leaked on a cybercrime forum, 5.2K+ people claimed
โ
Prรฉfรฉrence Formations, a French platform focused on vocational and professional training, is allegedly affected by a data exposure after a threat actor published what they claim is an internal dataset containing information associated with 5,265 people.
โ
The advertised dataset includes:
โ
โข Names
โข Email addresses
โข Cities and locations
โข Country information
โข Time zone information
โข Additional training-related contact records
โ
The actor claims the dataset contains 5,381 lines and is approximately 375 KB in CSV format.
โ
A sample record was published directly in the forum post, along with download links for the alleged dataset.
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
Prรฉfรฉrence Formations, a French platform focused on vocational and professional training, is allegedly affected by a data exposure after a threat actor published what they claim is an internal dataset containing information associated with 5,265 people.
โ
The advertised dataset includes:
โ
โข Names
โข Email addresses
โข Cities and locations
โข Country information
โข Time zone information
โข Additional training-related contact records
โ
The actor claims the dataset contains 5,381 lines and is approximately 375 KB in CSV format.
โ
A sample record was published directly in the forum post, along with download links for the alleged dataset.
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ซ๐ท Clinique de Vontes dataset allegedly leaked on a cybercrime forum, 4.1K+ records claimed
โ
Clinique de Vontes, a private mental health clinic located in Esvres-sur-Indre, Indre-et-Loire, France, is allegedly affected by a data exposure after a threat actor published what they claim is an internal dataset containing information associated with 4,111 people.
โ
The advertised data includes:
โ
โข Names and identity-related fields
โข Email addresses
โข Mobile, landline and fax fields
โข Language information
โข Professional profiles and job functions
โข Establishment and facility information
โข Organizational group assignments
โข Roles and responsibility information
โข Service associations
โข Workflow-related fields
โข Administrative status information
โข Additional internal account and personnel metadata
โ
The actor claims the dataset contains 4,111 lines, is approximately 2.53 MB, and is provided in JSON format.
โ
A sample record was published directly in the forum post, along with download links for the alleged dataset.
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
Clinique de Vontes, a private mental health clinic located in Esvres-sur-Indre, Indre-et-Loire, France, is allegedly affected by a data exposure after a threat actor published what they claim is an internal dataset containing information associated with 4,111 people.
โ
The advertised data includes:
โ
โข Names and identity-related fields
โข Email addresses
โข Mobile, landline and fax fields
โข Language information
โข Professional profiles and job functions
โข Establishment and facility information
โข Organizational group assignments
โข Roles and responsibility information
โข Service associations
โข Workflow-related fields
โข Administrative status information
โข Additional internal account and personnel metadata
โ
The actor claims the dataset contains 4,111 lines, is approximately 2.53 MB, and is provided in JSON format.
โ
A sample record was published directly in the forum post, along with download links for the alleged dataset.
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ง๐ช Collรจge Saint-Michel Moodle dataset allegedly leaked on a cybercrime forum, 1.8K+ people claimed
โ
Collรจge Saint-Michel, a Belgian educational institution, is allegedly affected by a data exposure after a threat actor published what they claim is a dataset associated with its Moodle online learning platform.
โ
The actor claims the dataset contains information associated with 1,836 people.
โ
The advertised data includes:
โ
โข User identifiers
โข First and last names
โข Email addresses
โข City and location information
โข Country information
โข Additional Moodle-related user records
โ
The actor claims the dataset contains 1,838 lines, is approximately 105 KB, and is provided in CSV format.
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
Collรจge Saint-Michel, a Belgian educational institution, is allegedly affected by a data exposure after a threat actor published what they claim is a dataset associated with its Moodle online learning platform.
โ
The actor claims the dataset contains information associated with 1,836 people.
โ
The advertised data includes:
โ
โข User identifiers
โข First and last names
โข Email addresses
โข City and location information
โข Country information
โข Additional Moodle-related user records
โ
The actor claims the dataset contains 1,838 lines, is approximately 105 KB, and is provided in CSV format.
โ
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ Trezor says the ShipMonk data breach is larger than previously disclosed.
An additional ~67,000 U.S. customers were affected, exposing names, emails, phone numbers, shipping addresses, and order numbers from 2019โ2021.
Trezor says ShipMonk had previously confirmed the data was deleted.
Affected customers have been emailed directly. Users are warned of increased phishing and physical security risks.
https://x.com/Trezor/status/2095807665603584085
An additional ~67,000 U.S. customers were affected, exposing names, emails, phone numbers, shipping addresses, and order numbers from 2019โ2021.
Trezor says ShipMonk had previously confirmed the data was deleted.
Affected customers have been emailed directly. Users are warned of increased phishing and physical security risks.
https://x.com/Trezor/status/2095807665603584085
X (formerly Twitter)
Trezor (@Trezor) on X
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.
Anothโฆ
Anothโฆ
๐จ๐บ๐ธ HER dating platform dataset allegedly leaked on a cybercrime forum, 13.6K+ profiles and private messages claimed exposed
โ
HER, a dating and community platform for queer women, nonbinary, trans and gender-nonconforming people, is allegedly affected by a data exposure after a threat actor published what they claim is data obtained from the platform.
โ
The actor claims 13,622 user profiles were accessed through an IDOR vulnerability, alongside additional account, subscription, image and messaging data.
โ
The advertised material includes:
โ
โข 13,622 user profiles
โข 33,421 RevenueCat user records
โข 165 premium account records
โข 41,524 profile photos, claimed to total approximately 3.4 GB
โข Additional user photos
โข Private-message photos
โข 128 private messages across 8 conversations
โข Account and subscription-related information
โ
The listing describes the main dataset as approximately 2.5 GB and claims tens of thousands of profile images were downloaded separately.
โ
The actor published download links for the alleged material and specifically claims the profile information was obtained through an IDOR vulnerability.
โ
The claims and the authenticity, source, scope and method of access to the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
HER, a dating and community platform for queer women, nonbinary, trans and gender-nonconforming people, is allegedly affected by a data exposure after a threat actor published what they claim is data obtained from the platform.
โ
The actor claims 13,622 user profiles were accessed through an IDOR vulnerability, alongside additional account, subscription, image and messaging data.
โ
The advertised material includes:
โ
โข 13,622 user profiles
โข 33,421 RevenueCat user records
โข 165 premium account records
โข 41,524 profile photos, claimed to total approximately 3.4 GB
โข Additional user photos
โข Private-message photos
โข 128 private messages across 8 conversations
โข Account and subscription-related information
โ
The listing describes the main dataset as approximately 2.5 GB and claims tens of thousands of profile images were downloaded separately.
โ
The actor published download links for the alleged material and specifically claims the profile information was obtained through an IDOR vulnerability.
โ
The claims and the authenticity, source, scope and method of access to the allegedly exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐จ๐ท Factoa administrative account access allegedly exposed on a cybercrime forum
Factoa, a Costa Rica-based electronic invoicing platform, is allegedly affected by a security compromise after a threat actor claimed to have obtained access to an administrative account within the application.
The actor claims the access allows management of:
โข Customers
โข Suppliers
โข Invoices
โข Orders
โข Additional store administration functions
The allegedly accessible data includes:
โข National ID / tax identification numbers
โข Full names of individuals and businesses
โข Phone numbers
โข Email addresses
โข Physical addresses and locations
โข Business and commercial names
โข Legal entity names
โข Taxpayer identification types
โข Customer account status information
โข Tax exemption information and certificates
โข Supplier and customer directory records
The actor also published a screenshot presented as proof of access to the Factoa administrative dashboard.
No public asking price is shown in the listing.
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Factoa, a Costa Rica-based electronic invoicing platform, is allegedly affected by a security compromise after a threat actor claimed to have obtained access to an administrative account within the application.
The actor claims the access allows management of:
โข Customers
โข Suppliers
โข Invoices
โข Orders
โข Additional store administration functions
The allegedly accessible data includes:
โข National ID / tax identification numbers
โข Full names of individuals and businesses
โข Phone numbers
โข Email addresses
โข Physical addresses and locations
โข Business and commercial names
โข Legal entity names
โข Taxpayer identification types
โข Customer account status information
โข Tax exemption information and certificates
โข Supplier and customer directory records
The actor also published a screenshot presented as proof of access to the Factoa administrative dashboard.
No public asking price is shown in the listing.
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐บ๐ธ Access to unnamed U.S. healthcare services company allegedly offered for sale on a cybercrime forum
An unnamed U.S. healthcare services company, with claimed annual revenue of approximately $85 million, is allegedly compromised after a threat actor advertised access to multiple parts of its cloud and development environment.
The advertised access allegedly includes:
โข GitHub
โข Google Cloud Platform (GCP)
โข Microsoft Azure
โข Salesforce OAuth2 access
โข Twilio access
โข Additional internal cloud and application resources
The affected company is not identified in the listing, and no additional information is provided regarding privilege level, number of accounts, persistence, or the specific systems accessible through the advertised credentials.
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
An unnamed U.S. healthcare services company, with claimed annual revenue of approximately $85 million, is allegedly compromised after a threat actor advertised access to multiple parts of its cloud and development environment.
The advertised access allegedly includes:
โข GitHub
โข Google Cloud Platform (GCP)
โข Microsoft Azure
โข Salesforce OAuth2 access
โข Twilio access
โข Additional internal cloud and application resources
The affected company is not identified in the listing, and no additional information is provided regarding privilege level, number of accounts, persistence, or the specific systems accessible through the advertised credentials.
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing