π¨π§π· Civil Police of ParΓ‘ allegedly breached, 2.5 TB of internal data offered for sale
The Civil Police of the State of ParΓ‘, Brazil, is allegedly affected by a major security breach after a threat actor claimed to have compromised its systems and extracted approximately 2.5 TB of internal data.
The actor claims the material includes 3.59M emails spanning 2016β2026, 2.65M attachments totaling ~871 GB, 7,564 police accounts, 102 MySQL datasets and full LDAP data.
Advertised data includes:
β’ Officer names, CPF/RG numbers, addresses and phone numbers
β’ Passport-style photos and fingerprints
β’ Police assignments and duty rosters
β’ Disciplinary and Internal Affairs records
β’ Court warrants, police and forensic reports
β’ Intelligence and operational communications
β’ Documents, spreadsheets, photos, video and audio evidence
β’ Password hashes and active session tokens
β’ 30 global administrator accounts
β’ Email system configurations, logs and backups
The actor also claims the material contains communications with other Brazilian law enforcement and government bodies and is asking 0.12 BTC for the alleged full dump.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
The Civil Police of the State of ParΓ‘, Brazil, is allegedly affected by a major security breach after a threat actor claimed to have compromised its systems and extracted approximately 2.5 TB of internal data.
The actor claims the material includes 3.59M emails spanning 2016β2026, 2.65M attachments totaling ~871 GB, 7,564 police accounts, 102 MySQL datasets and full LDAP data.
Advertised data includes:
β’ Officer names, CPF/RG numbers, addresses and phone numbers
β’ Passport-style photos and fingerprints
β’ Police assignments and duty rosters
β’ Disciplinary and Internal Affairs records
β’ Court warrants, police and forensic reports
β’ Intelligence and operational communications
β’ Documents, spreadsheets, photos, video and audio evidence
β’ Password hashes and active session tokens
β’ 30 global administrator accounts
β’ Email system configurations, logs and backups
The actor also claims the material contains communications with other Brazilian law enforcement and government bodies and is asking 0.12 BTC for the alleged full dump.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Media is too big
VIEW IN TELEGRAM
Chat, it's Friday. Listen to some tunes and vibe.
Twenty One Pilots - Ride
Twenty One Pilots - Ride
β€1π₯1
This media is not supported in your browser
VIEW IN TELEGRAM
βΌοΈ Exploit disclosed for CVE-2026-52924... 9.8 CVSS Linux Root Privilege Escalation
GitHub: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52924-ubuntu-7.0.0-28/
GitHub: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52924-ubuntu-7.0.0-28/
βΌοΈ ShinyHunters has a message for the actor who setup shop on 153M US drivers licenses for sale...
"We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think you will appreciate the numbers we have to offer you in return for the data you possess. What we are willing to offer you can be considered a payment as large as what you would get paid in a ransom. Reply to the DMs we are sending you on forum or simply contact shinygroup@onionmail.com"
"We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think you will appreciate the numbers we have to offer you in return for the data you possess. What we are willing to offer you can be considered a payment as large as what you would get paid in a ransom. Reply to the DMs we are sending you on forum or simply contact shinygroup@onionmail.com"
πͺ Slice For Life - Part 2 πͺ
βΌοΈ ShinyHunters has a message for the actor who setup shop on 153M US drivers licenses for sale... "We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think youβ¦
The forum being referenced is Exploit. Although not mention in SH post.
βΌοΈ A forum user is seeking a FedEx employee willing to provide internal information or facilitate physical drop-offs at a FedEx facility, offering monthly payments ranging from $500 to $10,000 depending on involvement.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: AMF Data Leaked With Plaintext Passwords for Town Hall Accounts
Link: https://darkwebinformer.com/amf-data-leaked-with-plaintext-passwords-for-town-hall-accounts/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: AMF Data Leaked With Plaintext Passwords for Town Hall Accounts
Link: https://darkwebinformer.com/amf-data-leaked-with-plaintext-passwords-for-town-hall-accounts/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
AMF Data Leaked With Plaintext Passwords for Town Hall Accounts
A forum actor posting as Alduin has published data attributed to amf.asso.fr, the site of the Association des Maires de France, which represents mayors and heads of intermunicipal bodies.
βΌοΈ New Dark Web Informer Blog Post!
Title: Online Banking Access to a BNP Paribas Savings Account Offered for Sale
Link: https://darkwebinformer.com/online-banking-access-to-a-bnp-paribas-savings-account-offered-for-sale/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Online Banking Access to a BNP Paribas Savings Account Offered for Sale
Link: https://darkwebinformer.com/online-banking-access-to-a-bnp-paribas-savings-account-offered-for-sale/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Online Banking Access to a BNP Paribas Savings Account Offered for Sale
A forum actor posting as HollowCrimeCorp is selling what they describe as verified and active access to a high value BNP Paribas account, offered as a username and password pair rather than as data.
Tails 7.12 has been released.
With Firefox moving to a two-week release cycle starting in September, Tor Browser and Tails are following the same schedule.
Tails 7.12 is the first release under this new cadence.
https://tails.net/news/version_7.12/
With Firefox moving to a two-week release cycle starting in September, Tor Browser and Tails are following the same schedule.
Tails 7.12 is the first release under this new cadence.
https://tails.net/news/version_7.12/
βΌοΈπ¨ Alleged 18-year-old hacker from Zerobytes group has been arrested.
News Source: https://www.20minutes.fr/justice/4242883-20260904-piratage-fisc-hacker-presume-groupe-zerobytes-mis-examen-ecroue
News Source: https://www.20minutes.fr/justice/4242883-20260904-piratage-fisc-hacker-presume-groupe-zerobytes-mis-examen-ecroue
π3
πͺ Slice For Life - Part 2 πͺ
βΌοΈπ¨ Alleged 18-year-old hacker from Zerobytes group has been arrested. News Source: https://www.20minutes.fr/justice/4242883-20260904-piratage-fisc-hacker-presume-groupe-zerobytes-mis-examen-ecroue
"A second suspect, aged under 16, was also arrested and taken into police custody, but later released, specifies the prosecution. Investigators will now exploit his computer equipment."
πͺ Slice For Life - Part 2 πͺ
"A second suspect, aged under 16, was also arrested and taken into police custody, but later released, specifies the prosecution. Investigators will now exploit his computer equipment."
βΌοΈ xCasquette (16-year-old) and ChatNoir (18-year-old) are the assumed aliases.
π¨π«π· Storia Mundi dataset allegedly leaked on a cybercrime forum, 17.8K+ user records and payment data claimed exposed
Storia Mundi is a French cultural media platform focused on history, art history and the humanities, offering online lectures, conferences and educational content.
A threat actor claims to have released a dataset containing information associated with approximately 17,850 users, alongside authentication, conference, payment and platform activity records.
The advertised data includes:
β’ Names, email addresses and postal addresses
β’ Dates of birth and language/culture information
β’ Usernames and normalized email addresses
β’ Password hashes and security stamps
β’ Phone numbers and two-factor authentication flags
β’ Account lockout and failed-login information
β’ 175K+ conference registration records
β’ Webinar and event attendance information
β’ 409K+ platform audit events
β’ Stripe customer, subscription, invoice and transaction records
β’ Payment card metadata, including cardholder names, billing addresses, expiry details, last four digits and card fingerprints
β’ CVC/AVS verification results and decline information
β’ Customer spending and subscription information
β’ Additional internal platform and billing metadata
The actor also claims the material contains historical Stripe payment records from 2024 and 2025, as well as extensive conference, authentication and user activity information.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Storia Mundi is a French cultural media platform focused on history, art history and the humanities, offering online lectures, conferences and educational content.
A threat actor claims to have released a dataset containing information associated with approximately 17,850 users, alongside authentication, conference, payment and platform activity records.
The advertised data includes:
β’ Names, email addresses and postal addresses
β’ Dates of birth and language/culture information
β’ Usernames and normalized email addresses
β’ Password hashes and security stamps
β’ Phone numbers and two-factor authentication flags
β’ Account lockout and failed-login information
β’ 175K+ conference registration records
β’ Webinar and event attendance information
β’ 409K+ platform audit events
β’ Stripe customer, subscription, invoice and transaction records
β’ Payment card metadata, including cardholder names, billing addresses, expiry details, last four digits and card fingerprints
β’ CVC/AVS verification results and decline information
β’ Customer spending and subscription information
β’ Additional internal platform and billing metadata
The actor also claims the material contains historical Stripe payment records from 2024 and 2025, as well as extensive conference, authentication and user activity information.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: INPI Registry Files With 27 Million Director Records Published
Link: https://darkwebinformer.com/inpi-registry-files-with-27-million-director-records-published/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: INPI Registry Files With 27 Million Director Records Published
Link: https://darkwebinformer.com/inpi-registry-files-with-27-million-director-records-published/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
INPI Registry Files With 27 Million Director Records Published
A forum actor posting as fuie has published data attributed to INPI, the French institute that administers industrial property and the national business register.
πͺ Slice For Life - Part 2 πͺ
βΌοΈ xCasquette (16-year-old) and ChatNoir (18-year-old) are the assumed aliases.
βΌοΈ ChatNoir and ZeroBytes have been banned from PF.
π2
I couldn't imagine not listening to music every day. I don't know how you actors do it tbh.
β€1
π¨π«π· Accent Rouge dataset allegedly leaked on a cybercrime forum, 1.6 GB claimed
β
Accent Rouge, a French high-end interior design and furnishing company with showrooms in Paris and Lyon, is named in a cybercrime forum post where a threat actor claims to have leaked a 1.6 GB dataset.
β
The advertised data includes:
β
β’ 32,583 customer records
β’ 79,336 customer address records
β’ Names, dates of birth, addresses, phone numbers and emails
β’ Sales orders, invoices and payment records
β’ Product, supplier, inventory and ERP data
β’ 1.49M+ internal Odoo mail messages
β’ 1.41M+ field-level change tracking records
β’ 22 user accounts with logins and password hashes
β
The actor also published a sample of customer address data as proof of the alleged leak.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Accent Rouge, a French high-end interior design and furnishing company with showrooms in Paris and Lyon, is named in a cybercrime forum post where a threat actor claims to have leaked a 1.6 GB dataset.
β
The advertised data includes:
β
β’ 32,583 customer records
β’ 79,336 customer address records
β’ Names, dates of birth, addresses, phone numbers and emails
β’ Sales orders, invoices and payment records
β’ Product, supplier, inventory and ERP data
β’ 1.49M+ internal Odoo mail messages
β’ 1.41M+ field-level change tracking records
β’ 22 user accounts with logins and password hashes
β
The actor also published a sample of customer address data as proof of the alleged leak.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing