πͺ Slice For Life - Part 2 πͺ
"A second suspect, aged under 16, was also arrested and taken into police custody, but later released, specifies the prosecution. Investigators will now exploit his computer equipment."
βΌοΈ xCasquette (16-year-old) and ChatNoir (18-year-old) are the assumed aliases.
π¨π«π· Storia Mundi dataset allegedly leaked on a cybercrime forum, 17.8K+ user records and payment data claimed exposed
Storia Mundi is a French cultural media platform focused on history, art history and the humanities, offering online lectures, conferences and educational content.
A threat actor claims to have released a dataset containing information associated with approximately 17,850 users, alongside authentication, conference, payment and platform activity records.
The advertised data includes:
β’ Names, email addresses and postal addresses
β’ Dates of birth and language/culture information
β’ Usernames and normalized email addresses
β’ Password hashes and security stamps
β’ Phone numbers and two-factor authentication flags
β’ Account lockout and failed-login information
β’ 175K+ conference registration records
β’ Webinar and event attendance information
β’ 409K+ platform audit events
β’ Stripe customer, subscription, invoice and transaction records
β’ Payment card metadata, including cardholder names, billing addresses, expiry details, last four digits and card fingerprints
β’ CVC/AVS verification results and decline information
β’ Customer spending and subscription information
β’ Additional internal platform and billing metadata
The actor also claims the material contains historical Stripe payment records from 2024 and 2025, as well as extensive conference, authentication and user activity information.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Storia Mundi is a French cultural media platform focused on history, art history and the humanities, offering online lectures, conferences and educational content.
A threat actor claims to have released a dataset containing information associated with approximately 17,850 users, alongside authentication, conference, payment and platform activity records.
The advertised data includes:
β’ Names, email addresses and postal addresses
β’ Dates of birth and language/culture information
β’ Usernames and normalized email addresses
β’ Password hashes and security stamps
β’ Phone numbers and two-factor authentication flags
β’ Account lockout and failed-login information
β’ 175K+ conference registration records
β’ Webinar and event attendance information
β’ 409K+ platform audit events
β’ Stripe customer, subscription, invoice and transaction records
β’ Payment card metadata, including cardholder names, billing addresses, expiry details, last four digits and card fingerprints
β’ CVC/AVS verification results and decline information
β’ Customer spending and subscription information
β’ Additional internal platform and billing metadata
The actor also claims the material contains historical Stripe payment records from 2024 and 2025, as well as extensive conference, authentication and user activity information.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: INPI Registry Files With 27 Million Director Records Published
Link: https://darkwebinformer.com/inpi-registry-files-with-27-million-director-records-published/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: INPI Registry Files With 27 Million Director Records Published
Link: https://darkwebinformer.com/inpi-registry-files-with-27-million-director-records-published/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
INPI Registry Files With 27 Million Director Records Published
A forum actor posting as fuie has published data attributed to INPI, the French institute that administers industrial property and the national business register.
πͺ Slice For Life - Part 2 πͺ
βΌοΈ xCasquette (16-year-old) and ChatNoir (18-year-old) are the assumed aliases.
βΌοΈ ChatNoir and ZeroBytes have been banned from PF.
π2
I couldn't imagine not listening to music every day. I don't know how you actors do it tbh.
β€1
π¨π«π· Accent Rouge dataset allegedly leaked on a cybercrime forum, 1.6 GB claimed
β
Accent Rouge, a French high-end interior design and furnishing company with showrooms in Paris and Lyon, is named in a cybercrime forum post where a threat actor claims to have leaked a 1.6 GB dataset.
β
The advertised data includes:
β
β’ 32,583 customer records
β’ 79,336 customer address records
β’ Names, dates of birth, addresses, phone numbers and emails
β’ Sales orders, invoices and payment records
β’ Product, supplier, inventory and ERP data
β’ 1.49M+ internal Odoo mail messages
β’ 1.41M+ field-level change tracking records
β’ 22 user accounts with logins and password hashes
β
The actor also published a sample of customer address data as proof of the alleged leak.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Accent Rouge, a French high-end interior design and furnishing company with showrooms in Paris and Lyon, is named in a cybercrime forum post where a threat actor claims to have leaked a 1.6 GB dataset.
β
The advertised data includes:
β
β’ 32,583 customer records
β’ 79,336 customer address records
β’ Names, dates of birth, addresses, phone numbers and emails
β’ Sales orders, invoices and payment records
β’ Product, supplier, inventory and ERP data
β’ 1.49M+ internal Odoo mail messages
β’ 1.41M+ field-level change tracking records
β’ 22 user accounts with logins and password hashes
β
The actor also published a sample of customer address data as proof of the alleged leak.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Yall motherfuckers need to start using PGPs though. That shit is triggering.
π6β€1
πͺ Slice For Life - Part 2 πͺ
βΌοΈ ShinyHunters has a message for the actor who setup shop on 153M US drivers licenses for sale... "We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think youβ¦
βΌοΈ ShinyHunters has since removed the message from their portal.
π2π1π1
πͺ Slice For Life - Part 2 πͺ
βΌοΈ ShinyHunters has since removed the message from their portal.
"This service is no longer available." message on the Nexus onion no longer resolves. Possible the data was purchased by ShinyHunters.
Mullvad VPN: Shutting down our public encrypted DNS servers and sponsoring Quad9 instead
https://mullvad.net/en/blog/2026/9/3/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead
https://mullvad.net/en/blog/2026/9/3/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead
Mullvad VPN
Shutting down our public encrypted DNS servers and sponsoring Quad9 instead | Mullvad VPN
Mullvad has operated public encrypted DNS (DoH) servers since 2022. They are unnecessary when using Mullvad VPN β traffic is already encrypted and Mullvad VPN's internal DNS handles all queries.
π11
π¨π§π· CBFS Academy CRM dataset allegedly offered for sale on a cybercrime forum, 43K+ leads claimed
β
CBFS Academy, a Brazilian football coaching and EdTech organization, is named in a cybercrime forum post where a threat actor claims to be selling live Supabase access to its CRM data.
β
The advertised dataset includes:
β
β’ 43,498 unique leads
β’ 27,114 unique email addresses
β’ 39,149 unique phone numbers
β’ Full names and contact information
β’ Purchase history and revenue data
β’ UTM source, campaign and marketing data
β’ First-contact and interaction timestamps
β’ Last products purchased and sale dates
β
The actor claims the data was active through August 31, 2026 and is being provided in NDJSON/CSV format.
β
An optional full dataset is also advertised as containing 298 tables and approximately 3.3 million rows, including conversations, workflow execution data and AI agent logs.
β
The listing is priced at $800β$1,000, with BTC and XMR accepted.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
CBFS Academy, a Brazilian football coaching and EdTech organization, is named in a cybercrime forum post where a threat actor claims to be selling live Supabase access to its CRM data.
β
The advertised dataset includes:
β
β’ 43,498 unique leads
β’ 27,114 unique email addresses
β’ 39,149 unique phone numbers
β’ Full names and contact information
β’ Purchase history and revenue data
β’ UTM source, campaign and marketing data
β’ First-contact and interaction timestamps
β’ Last products purchased and sale dates
β
The actor claims the data was active through August 31, 2026 and is being provided in NDJSON/CSV format.
β
An optional full dataset is also advertised as containing 298 tables and approximately 3.3 million rows, including conversations, workflow execution data and AI agent logs.
β
The listing is priced at $800β$1,000, with BTC and XMR accepted.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨π³π¬ Nestuge App user dataset allegedly offered for sale on a cybercrime forum, 326K+ records claimed
β
Nestuge App, described in the listing as a Nigerian job and earning platform, is named in a cybercrime forum post where a threat actor claims to be selling a Firebase Firestore export containing 326,578 user records.
β
The advertised dataset includes:
β
β’ 326,524 unique email addresses
β’ 324,900 records with names
β’ 12,006 records with phone numbers
β’ Full names
β’ Email addresses
β’ Phone numbers where available
β
The actor claims the dataset was extracted on August 24, 2026 from a live application user base and says re-extraction is available.
β
The data is advertised in JSON format, with Nigeria listed as the primary country alongside users in the global diaspora.
β
The listing is priced at $800β$1,000, with BTC and XMR accepted.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Nestuge App, described in the listing as a Nigerian job and earning platform, is named in a cybercrime forum post where a threat actor claims to be selling a Firebase Firestore export containing 326,578 user records.
β
The advertised dataset includes:
β
β’ 326,524 unique email addresses
β’ 324,900 records with names
β’ 12,006 records with phone numbers
β’ Full names
β’ Email addresses
β’ Phone numbers where available
β
The actor claims the dataset was extracted on August 24, 2026 from a live application user base and says re-extraction is available.
β
The data is advertised in JSON format, with Nigeria listed as the primary country alongside users in the global diaspora.
β
The listing is priced at $800β$1,000, with BTC and XMR accepted.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨π²π½ SISEEMS student records allegedly leaked on a cybercrime forum
β
SISEEMS (Sistema de Servicios Escolares de la EducaciΓ³n Media Superior), Mexicoβs upper-secondary education school services system, is named in a cybercrime forum post where a threat actor claims to have leaked student records associated with DGETI and DGETAyCM.
β
The advertised data includes:
β
β’ Full names
β’ Student IDs
β’ School names and codes
β’ Academic programs
β’ GPA information
β’ Credits completed
β’ Document status
β’ Official folio numbers
β’ Issuance dates
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
SISEEMS (Sistema de Servicios Escolares de la EducaciΓ³n Media Superior), Mexicoβs upper-secondary education school services system, is named in a cybercrime forum post where a threat actor claims to have leaked student records associated with DGETI and DGETAyCM.
β
The advertised data includes:
β
β’ Full names
β’ Student IDs
β’ School names and codes
β’ Academic programs
β’ GPA information
β’ Credits completed
β’ Document status
β’ Official folio numbers
β’ Issuance dates
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π΅πͺ Peruvian Air Force dataset allegedly leaked on a cybercrime forum, 13K+ files claimed
β
Fuerza AΓ©rea del PerΓΊ (FAP), the Peruvian Air Force, is named in a cybercrime forum post where a threat actor claims to have leaked a database containing 13,037 images totaling approximately 1.3 GB.
β
The actor claims:
β
β’ 13,037 image files
β’ Approximately 1.3 GB of data
β’ The release represents the complete database
β’ Additional specific databases may also be available
β
The actor published a download for the allegedly exposed material and also named Argentina as a βnext target.β
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Fuerza AΓ©rea del PerΓΊ (FAP), the Peruvian Air Force, is named in a cybercrime forum post where a threat actor claims to have leaked a database containing 13,037 images totaling approximately 1.3 GB.
β
The actor claims:
β
β’ 13,037 image files
β’ Approximately 1.3 GB of data
β’ The release represents the complete database
β’ Additional specific databases may also be available
β
The actor published a download for the allegedly exposed material and also named Argentina as a βnext target.β
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨π«π· Pass Pass dataset allegedly leaked on a cybercrime forum, 18K+ people claimed
β
Pass Pass, a regional public transport and mobility service in Hauts-de-France, France, is named in a cybercrime forum post where a threat actor claims to have leaked a partial dataset containing information tied to 18,861 people.
β
The advertised data includes:
β
β’ Customer names and email addresses
β’ Billing and delivery information
β’ Order and transaction records
β’ Invoice data
β’ Payment metadata
β’ Product and transport-related information
β’ Application and system logs
β
The actor claims the leak contains 92,178 lines of data totaling approximately 214 MB, provided in CSV and JSON formats.
β
Files shown in the post include datasets related to orders, invoices and historical application logs.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Pass Pass, a regional public transport and mobility service in Hauts-de-France, France, is named in a cybercrime forum post where a threat actor claims to have leaked a partial dataset containing information tied to 18,861 people.
β
The advertised data includes:
β
β’ Customer names and email addresses
β’ Billing and delivery information
β’ Order and transaction records
β’ Invoice data
β’ Payment metadata
β’ Product and transport-related information
β’ Application and system logs
β
The actor claims the leak contains 92,178 lines of data totaling approximately 214 MB, provided in CSV and JSON formats.
β
Files shown in the post include datasets related to orders, invoices and historical application logs.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing