You suits are quick.
Company Tied to Breach of 153M Driver's Licenses Hit With Multiple Lawsuits
https://www.pcmag.com/news/company-tied-to-breach-of-153m-drivers-licenses-hit-with-multiple-lawsuits
Company Tied to Breach of 153M Driver's Licenses Hit With Multiple Lawsuits
https://www.pcmag.com/news/company-tied-to-breach-of-153m-drivers-licenses-hit-with-multiple-lawsuits
PCMAG
Company Tied to Breach of 153M Driver's Licenses Hit With Multiple Lawsuits
The driver's license data popped up on the dark web via a site called Nexus and was allegedly stolen from IDScan.net. Consumers who believe they were affected are now suing.
π1
π¨π«π· PrΓ©fΓ©rence Formations dataset allegedly leaked on a cybercrime forum, 5.2K+ people claimed
β
PrΓ©fΓ©rence Formations, a French platform focused on vocational and professional training, is allegedly affected by a data exposure after a threat actor published what they claim is an internal dataset containing information associated with 5,265 people.
β
The advertised dataset includes:
β
β’ Names
β’ Email addresses
β’ Cities and locations
β’ Country information
β’ Time zone information
β’ Additional training-related contact records
β
The actor claims the dataset contains 5,381 lines and is approximately 375 KB in CSV format.
β
A sample record was published directly in the forum post, along with download links for the alleged dataset.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
PrΓ©fΓ©rence Formations, a French platform focused on vocational and professional training, is allegedly affected by a data exposure after a threat actor published what they claim is an internal dataset containing information associated with 5,265 people.
β
The advertised dataset includes:
β
β’ Names
β’ Email addresses
β’ Cities and locations
β’ Country information
β’ Time zone information
β’ Additional training-related contact records
β
The actor claims the dataset contains 5,381 lines and is approximately 375 KB in CSV format.
β
A sample record was published directly in the forum post, along with download links for the alleged dataset.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π«π· Clinique de Vontes dataset allegedly leaked on a cybercrime forum, 4.1K+ records claimed
β
Clinique de Vontes, a private mental health clinic located in Esvres-sur-Indre, Indre-et-Loire, France, is allegedly affected by a data exposure after a threat actor published what they claim is an internal dataset containing information associated with 4,111 people.
β
The advertised data includes:
β
β’ Names and identity-related fields
β’ Email addresses
β’ Mobile, landline and fax fields
β’ Language information
β’ Professional profiles and job functions
β’ Establishment and facility information
β’ Organizational group assignments
β’ Roles and responsibility information
β’ Service associations
β’ Workflow-related fields
β’ Administrative status information
β’ Additional internal account and personnel metadata
β
The actor claims the dataset contains 4,111 lines, is approximately 2.53 MB, and is provided in JSON format.
β
A sample record was published directly in the forum post, along with download links for the alleged dataset.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Clinique de Vontes, a private mental health clinic located in Esvres-sur-Indre, Indre-et-Loire, France, is allegedly affected by a data exposure after a threat actor published what they claim is an internal dataset containing information associated with 4,111 people.
β
The advertised data includes:
β
β’ Names and identity-related fields
β’ Email addresses
β’ Mobile, landline and fax fields
β’ Language information
β’ Professional profiles and job functions
β’ Establishment and facility information
β’ Organizational group assignments
β’ Roles and responsibility information
β’ Service associations
β’ Workflow-related fields
β’ Administrative status information
β’ Additional internal account and personnel metadata
β
The actor claims the dataset contains 4,111 lines, is approximately 2.53 MB, and is provided in JSON format.
β
A sample record was published directly in the forum post, along with download links for the alleged dataset.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π§πͺ CollΓ¨ge Saint-Michel Moodle dataset allegedly leaked on a cybercrime forum, 1.8K+ people claimed
β
Collège Saint-Michel, a Belgian educational institution, is allegedly affected by a data exposure after a threat actor published what they claim is a dataset associated with its Moodle online learning platform.
β
The actor claims the dataset contains information associated with 1,836 people.
β
The advertised data includes:
β
β’ User identifiers
β’ First and last names
β’ Email addresses
β’ City and location information
β’ Country information
β’ Additional Moodle-related user records
β
The actor claims the dataset contains 1,838 lines, is approximately 105 KB, and is provided in CSV format.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Collège Saint-Michel, a Belgian educational institution, is allegedly affected by a data exposure after a threat actor published what they claim is a dataset associated with its Moodle online learning platform.
β
The actor claims the dataset contains information associated with 1,836 people.
β
The advertised data includes:
β
β’ User identifiers
β’ First and last names
β’ Email addresses
β’ City and location information
β’ Country information
β’ Additional Moodle-related user records
β
The actor claims the dataset contains 1,838 lines, is approximately 105 KB, and is provided in CSV format.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ Trezor says the ShipMonk data breach is larger than previously disclosed.
An additional ~67,000 U.S. customers were affected, exposing names, emails, phone numbers, shipping addresses, and order numbers from 2019β2021.
Trezor says ShipMonk had previously confirmed the data was deleted.
Affected customers have been emailed directly. Users are warned of increased phishing and physical security risks.
https://x.com/Trezor/status/2095807665603584085
An additional ~67,000 U.S. customers were affected, exposing names, emails, phone numbers, shipping addresses, and order numbers from 2019β2021.
Trezor says ShipMonk had previously confirmed the data was deleted.
Affected customers have been emailed directly. Users are warned of increased phishing and physical security risks.
https://x.com/Trezor/status/2095807665603584085
X (formerly Twitter)
Trezor (@Trezor) on X
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.
Anothβ¦
Anothβ¦
π¨πΊπΈ HER dating platform dataset allegedly leaked on a cybercrime forum, 13.6K+ profiles and private messages claimed exposed
β
HER, a dating and community platform for queer women, nonbinary, trans and gender-nonconforming people, is allegedly affected by a data exposure after a threat actor published what they claim is data obtained from the platform.
β
The actor claims 13,622 user profiles were accessed through an IDOR vulnerability, alongside additional account, subscription, image and messaging data.
β
The advertised material includes:
β
β’ 13,622 user profiles
β’ 33,421 RevenueCat user records
β’ 165 premium account records
β’ 41,524 profile photos, claimed to total approximately 3.4 GB
β’ Additional user photos
β’ Private-message photos
β’ 128 private messages across 8 conversations
β’ Account and subscription-related information
β
The listing describes the main dataset as approximately 2.5 GB and claims tens of thousands of profile images were downloaded separately.
β
The actor published download links for the alleged material and specifically claims the profile information was obtained through an IDOR vulnerability.
β
The claims and the authenticity, source, scope and method of access to the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
HER, a dating and community platform for queer women, nonbinary, trans and gender-nonconforming people, is allegedly affected by a data exposure after a threat actor published what they claim is data obtained from the platform.
β
The actor claims 13,622 user profiles were accessed through an IDOR vulnerability, alongside additional account, subscription, image and messaging data.
β
The advertised material includes:
β
β’ 13,622 user profiles
β’ 33,421 RevenueCat user records
β’ 165 premium account records
β’ 41,524 profile photos, claimed to total approximately 3.4 GB
β’ Additional user photos
β’ Private-message photos
β’ 128 private messages across 8 conversations
β’ Account and subscription-related information
β
The listing describes the main dataset as approximately 2.5 GB and claims tens of thousands of profile images were downloaded separately.
β
The actor published download links for the alleged material and specifically claims the profile information was obtained through an IDOR vulnerability.
β
The claims and the authenticity, source, scope and method of access to the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π¨π· Factoa administrative account access allegedly exposed on a cybercrime forum
Factoa, a Costa Rica-based electronic invoicing platform, is allegedly affected by a security compromise after a threat actor claimed to have obtained access to an administrative account within the application.
The actor claims the access allows management of:
β’ Customers
β’ Suppliers
β’ Invoices
β’ Orders
β’ Additional store administration functions
The allegedly accessible data includes:
β’ National ID / tax identification numbers
β’ Full names of individuals and businesses
β’ Phone numbers
β’ Email addresses
β’ Physical addresses and locations
β’ Business and commercial names
β’ Legal entity names
β’ Taxpayer identification types
β’ Customer account status information
β’ Tax exemption information and certificates
β’ Supplier and customer directory records
The actor also published a screenshot presented as proof of access to the Factoa administrative dashboard.
No public asking price is shown in the listing.
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Factoa, a Costa Rica-based electronic invoicing platform, is allegedly affected by a security compromise after a threat actor claimed to have obtained access to an administrative account within the application.
The actor claims the access allows management of:
β’ Customers
β’ Suppliers
β’ Invoices
β’ Orders
β’ Additional store administration functions
The allegedly accessible data includes:
β’ National ID / tax identification numbers
β’ Full names of individuals and businesses
β’ Phone numbers
β’ Email addresses
β’ Physical addresses and locations
β’ Business and commercial names
β’ Legal entity names
β’ Taxpayer identification types
β’ Customer account status information
β’ Tax exemption information and certificates
β’ Supplier and customer directory records
The actor also published a screenshot presented as proof of access to the Factoa administrative dashboard.
No public asking price is shown in the listing.
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΊπΈ Access to unnamed U.S. healthcare services company allegedly offered for sale on a cybercrime forum
An unnamed U.S. healthcare services company, with claimed annual revenue of approximately $85 million, is allegedly compromised after a threat actor advertised access to multiple parts of its cloud and development environment.
The advertised access allegedly includes:
β’ GitHub
β’ Google Cloud Platform (GCP)
β’ Microsoft Azure
β’ Salesforce OAuth2 access
β’ Twilio access
β’ Additional internal cloud and application resources
The affected company is not identified in the listing, and no additional information is provided regarding privilege level, number of accounts, persistence, or the specific systems accessible through the advertised credentials.
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
An unnamed U.S. healthcare services company, with claimed annual revenue of approximately $85 million, is allegedly compromised after a threat actor advertised access to multiple parts of its cloud and development environment.
The advertised access allegedly includes:
β’ GitHub
β’ Google Cloud Platform (GCP)
β’ Microsoft Azure
β’ Salesforce OAuth2 access
β’ Twilio access
β’ Additional internal cloud and application resources
The affected company is not identified in the listing, and no additional information is provided regarding privilege level, number of accounts, persistence, or the specific systems accessible through the advertised credentials.
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π§π· Civil Police of ParΓ‘ allegedly breached, 2.5 TB of internal data offered for sale
The Civil Police of the State of ParΓ‘, Brazil, is allegedly affected by a major security breach after a threat actor claimed to have compromised its systems and extracted approximately 2.5 TB of internal data.
The actor claims the material includes 3.59M emails spanning 2016β2026, 2.65M attachments totaling ~871 GB, 7,564 police accounts, 102 MySQL datasets and full LDAP data.
Advertised data includes:
β’ Officer names, CPF/RG numbers, addresses and phone numbers
β’ Passport-style photos and fingerprints
β’ Police assignments and duty rosters
β’ Disciplinary and Internal Affairs records
β’ Court warrants, police and forensic reports
β’ Intelligence and operational communications
β’ Documents, spreadsheets, photos, video and audio evidence
β’ Password hashes and active session tokens
β’ 30 global administrator accounts
β’ Email system configurations, logs and backups
The actor also claims the material contains communications with other Brazilian law enforcement and government bodies and is asking 0.12 BTC for the alleged full dump.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
The Civil Police of the State of ParΓ‘, Brazil, is allegedly affected by a major security breach after a threat actor claimed to have compromised its systems and extracted approximately 2.5 TB of internal data.
The actor claims the material includes 3.59M emails spanning 2016β2026, 2.65M attachments totaling ~871 GB, 7,564 police accounts, 102 MySQL datasets and full LDAP data.
Advertised data includes:
β’ Officer names, CPF/RG numbers, addresses and phone numbers
β’ Passport-style photos and fingerprints
β’ Police assignments and duty rosters
β’ Disciplinary and Internal Affairs records
β’ Court warrants, police and forensic reports
β’ Intelligence and operational communications
β’ Documents, spreadsheets, photos, video and audio evidence
β’ Password hashes and active session tokens
β’ 30 global administrator accounts
β’ Email system configurations, logs and backups
The actor also claims the material contains communications with other Brazilian law enforcement and government bodies and is asking 0.12 BTC for the alleged full dump.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Media is too big
VIEW IN TELEGRAM
Chat, it's Friday. Listen to some tunes and vibe.
Twenty One Pilots - Ride
Twenty One Pilots - Ride
β€1π₯1
This media is not supported in your browser
VIEW IN TELEGRAM
βΌοΈ Exploit disclosed for CVE-2026-52924... 9.8 CVSS Linux Root Privilege Escalation
GitHub: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52924-ubuntu-7.0.0-28/
GitHub: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52924-ubuntu-7.0.0-28/
βΌοΈ ShinyHunters has a message for the actor who setup shop on 153M US drivers licenses for sale...
"We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think you will appreciate the numbers we have to offer you in return for the data you possess. What we are willing to offer you can be considered a payment as large as what you would get paid in a ransom. Reply to the DMs we are sending you on forum or simply contact shinygroup@onionmail.com"
"We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think you will appreciate the numbers we have to offer you in return for the data you possess. What we are willing to offer you can be considered a payment as large as what you would get paid in a ransom. Reply to the DMs we are sending you on forum or simply contact shinygroup@onionmail.com"
πͺ Slice For Life - Part 2 πͺ
βΌοΈ ShinyHunters has a message for the actor who setup shop on 153M US drivers licenses for sale... "We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think youβ¦
The forum being referenced is Exploit. Although not mention in SH post.
βΌοΈ A forum user is seeking a FedEx employee willing to provide internal information or facilitate physical drop-offs at a FedEx facility, offering monthly payments ranging from $500 to $10,000 depending on involvement.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: AMF Data Leaked With Plaintext Passwords for Town Hall Accounts
Link: https://darkwebinformer.com/amf-data-leaked-with-plaintext-passwords-for-town-hall-accounts/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: AMF Data Leaked With Plaintext Passwords for Town Hall Accounts
Link: https://darkwebinformer.com/amf-data-leaked-with-plaintext-passwords-for-town-hall-accounts/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
AMF Data Leaked With Plaintext Passwords for Town Hall Accounts
A forum actor posting as Alduin has published data attributed to amf.asso.fr, the site of the Association des Maires de France, which represents mayors and heads of intermunicipal bodies.
βΌοΈ New Dark Web Informer Blog Post!
Title: Online Banking Access to a BNP Paribas Savings Account Offered for Sale
Link: https://darkwebinformer.com/online-banking-access-to-a-bnp-paribas-savings-account-offered-for-sale/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Online Banking Access to a BNP Paribas Savings Account Offered for Sale
Link: https://darkwebinformer.com/online-banking-access-to-a-bnp-paribas-savings-account-offered-for-sale/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Online Banking Access to a BNP Paribas Savings Account Offered for Sale
A forum actor posting as HollowCrimeCorp is selling what they describe as verified and active access to a high value BNP Paribas account, offered as a username and password pair rather than as data.
Tails 7.12 has been released.
With Firefox moving to a two-week release cycle starting in September, Tor Browser and Tails are following the same schedule.
Tails 7.12 is the first release under this new cadence.
https://tails.net/news/version_7.12/
With Firefox moving to a two-week release cycle starting in September, Tor Browser and Tails are following the same schedule.
Tails 7.12 is the first release under this new cadence.
https://tails.net/news/version_7.12/
βΌοΈπ¨ Alleged 18-year-old hacker from Zerobytes group has been arrested.
News Source: https://www.20minutes.fr/justice/4242883-20260904-piratage-fisc-hacker-presume-groupe-zerobytes-mis-examen-ecroue
News Source: https://www.20minutes.fr/justice/4242883-20260904-piratage-fisc-hacker-presume-groupe-zerobytes-mis-examen-ecroue
π3
πͺ Slice For Life - Part 2 πͺ
βΌοΈπ¨ Alleged 18-year-old hacker from Zerobytes group has been arrested. News Source: https://www.20minutes.fr/justice/4242883-20260904-piratage-fisc-hacker-presume-groupe-zerobytes-mis-examen-ecroue
"A second suspect, aged under 16, was also arrested and taken into police custody, but later released, specifies the prosecution. Investigators will now exploit his computer equipment."