πͺ Slice For Life - Part 2 πͺ
βΌοΈ xCasquette (16-year-old) and ChatNoir (18-year-old) are the assumed aliases.
βΌοΈ ChatNoir and ZeroBytes have been banned from PF.
π2
I couldn't imagine not listening to music every day. I don't know how you actors do it tbh.
β€1
π¨π«π· Accent Rouge dataset allegedly leaked on a cybercrime forum, 1.6 GB claimed
β
Accent Rouge, a French high-end interior design and furnishing company with showrooms in Paris and Lyon, is named in a cybercrime forum post where a threat actor claims to have leaked a 1.6 GB dataset.
β
The advertised data includes:
β
β’ 32,583 customer records
β’ 79,336 customer address records
β’ Names, dates of birth, addresses, phone numbers and emails
β’ Sales orders, invoices and payment records
β’ Product, supplier, inventory and ERP data
β’ 1.49M+ internal Odoo mail messages
β’ 1.41M+ field-level change tracking records
β’ 22 user accounts with logins and password hashes
β
The actor also published a sample of customer address data as proof of the alleged leak.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Accent Rouge, a French high-end interior design and furnishing company with showrooms in Paris and Lyon, is named in a cybercrime forum post where a threat actor claims to have leaked a 1.6 GB dataset.
β
The advertised data includes:
β
β’ 32,583 customer records
β’ 79,336 customer address records
β’ Names, dates of birth, addresses, phone numbers and emails
β’ Sales orders, invoices and payment records
β’ Product, supplier, inventory and ERP data
β’ 1.49M+ internal Odoo mail messages
β’ 1.41M+ field-level change tracking records
β’ 22 user accounts with logins and password hashes
β
The actor also published a sample of customer address data as proof of the alleged leak.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Yall motherfuckers need to start using PGPs though. That shit is triggering.
π6β€1
πͺ Slice For Life - Part 2 πͺ
βΌοΈ ShinyHunters has a message for the actor who setup shop on 153M US drivers licenses for sale... "We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think youβ¦
βΌοΈ ShinyHunters has since removed the message from their portal.
π2π1π1
πͺ Slice For Life - Part 2 πͺ
βΌοΈ ShinyHunters has since removed the message from their portal.
"This service is no longer available." message on the Nexus onion no longer resolves. Possible the data was purchased by ShinyHunters.
Mullvad VPN: Shutting down our public encrypted DNS servers and sponsoring Quad9 instead
https://mullvad.net/en/blog/2026/9/3/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead
https://mullvad.net/en/blog/2026/9/3/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead
Mullvad VPN
Shutting down our public encrypted DNS servers and sponsoring Quad9 instead | Mullvad VPN
Mullvad has operated public encrypted DNS (DoH) servers since 2022. They are unnecessary when using Mullvad VPN β traffic is already encrypted and Mullvad VPN's internal DNS handles all queries.
π11
π¨π§π· CBFS Academy CRM dataset allegedly offered for sale on a cybercrime forum, 43K+ leads claimed
β
CBFS Academy, a Brazilian football coaching and EdTech organization, is named in a cybercrime forum post where a threat actor claims to be selling live Supabase access to its CRM data.
β
The advertised dataset includes:
β
β’ 43,498 unique leads
β’ 27,114 unique email addresses
β’ 39,149 unique phone numbers
β’ Full names and contact information
β’ Purchase history and revenue data
β’ UTM source, campaign and marketing data
β’ First-contact and interaction timestamps
β’ Last products purchased and sale dates
β
The actor claims the data was active through August 31, 2026 and is being provided in NDJSON/CSV format.
β
An optional full dataset is also advertised as containing 298 tables and approximately 3.3 million rows, including conversations, workflow execution data and AI agent logs.
β
The listing is priced at $800β$1,000, with BTC and XMR accepted.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
CBFS Academy, a Brazilian football coaching and EdTech organization, is named in a cybercrime forum post where a threat actor claims to be selling live Supabase access to its CRM data.
β
The advertised dataset includes:
β
β’ 43,498 unique leads
β’ 27,114 unique email addresses
β’ 39,149 unique phone numbers
β’ Full names and contact information
β’ Purchase history and revenue data
β’ UTM source, campaign and marketing data
β’ First-contact and interaction timestamps
β’ Last products purchased and sale dates
β
The actor claims the data was active through August 31, 2026 and is being provided in NDJSON/CSV format.
β
An optional full dataset is also advertised as containing 298 tables and approximately 3.3 million rows, including conversations, workflow execution data and AI agent logs.
β
The listing is priced at $800β$1,000, with BTC and XMR accepted.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨π³π¬ Nestuge App user dataset allegedly offered for sale on a cybercrime forum, 326K+ records claimed
β
Nestuge App, described in the listing as a Nigerian job and earning platform, is named in a cybercrime forum post where a threat actor claims to be selling a Firebase Firestore export containing 326,578 user records.
β
The advertised dataset includes:
β
β’ 326,524 unique email addresses
β’ 324,900 records with names
β’ 12,006 records with phone numbers
β’ Full names
β’ Email addresses
β’ Phone numbers where available
β
The actor claims the dataset was extracted on August 24, 2026 from a live application user base and says re-extraction is available.
β
The data is advertised in JSON format, with Nigeria listed as the primary country alongside users in the global diaspora.
β
The listing is priced at $800β$1,000, with BTC and XMR accepted.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Nestuge App, described in the listing as a Nigerian job and earning platform, is named in a cybercrime forum post where a threat actor claims to be selling a Firebase Firestore export containing 326,578 user records.
β
The advertised dataset includes:
β
β’ 326,524 unique email addresses
β’ 324,900 records with names
β’ 12,006 records with phone numbers
β’ Full names
β’ Email addresses
β’ Phone numbers where available
β
The actor claims the dataset was extracted on August 24, 2026 from a live application user base and says re-extraction is available.
β
The data is advertised in JSON format, with Nigeria listed as the primary country alongside users in the global diaspora.
β
The listing is priced at $800β$1,000, with BTC and XMR accepted.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨π²π½ SISEEMS student records allegedly leaked on a cybercrime forum
β
SISEEMS (Sistema de Servicios Escolares de la EducaciΓ³n Media Superior), Mexicoβs upper-secondary education school services system, is named in a cybercrime forum post where a threat actor claims to have leaked student records associated with DGETI and DGETAyCM.
β
The advertised data includes:
β
β’ Full names
β’ Student IDs
β’ School names and codes
β’ Academic programs
β’ GPA information
β’ Credits completed
β’ Document status
β’ Official folio numbers
β’ Issuance dates
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
SISEEMS (Sistema de Servicios Escolares de la EducaciΓ³n Media Superior), Mexicoβs upper-secondary education school services system, is named in a cybercrime forum post where a threat actor claims to have leaked student records associated with DGETI and DGETAyCM.
β
The advertised data includes:
β
β’ Full names
β’ Student IDs
β’ School names and codes
β’ Academic programs
β’ GPA information
β’ Credits completed
β’ Document status
β’ Official folio numbers
β’ Issuance dates
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π΅πͺ Peruvian Air Force dataset allegedly leaked on a cybercrime forum, 13K+ files claimed
β
Fuerza AΓ©rea del PerΓΊ (FAP), the Peruvian Air Force, is named in a cybercrime forum post where a threat actor claims to have leaked a database containing 13,037 images totaling approximately 1.3 GB.
β
The actor claims:
β
β’ 13,037 image files
β’ Approximately 1.3 GB of data
β’ The release represents the complete database
β’ Additional specific databases may also be available
β
The actor published a download for the allegedly exposed material and also named Argentina as a βnext target.β
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Fuerza AΓ©rea del PerΓΊ (FAP), the Peruvian Air Force, is named in a cybercrime forum post where a threat actor claims to have leaked a database containing 13,037 images totaling approximately 1.3 GB.
β
The actor claims:
β
β’ 13,037 image files
β’ Approximately 1.3 GB of data
β’ The release represents the complete database
β’ Additional specific databases may also be available
β
The actor published a download for the allegedly exposed material and also named Argentina as a βnext target.β
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨π«π· Pass Pass dataset allegedly leaked on a cybercrime forum, 18K+ people claimed
β
Pass Pass, a regional public transport and mobility service in Hauts-de-France, France, is named in a cybercrime forum post where a threat actor claims to have leaked a partial dataset containing information tied to 18,861 people.
β
The advertised data includes:
β
β’ Customer names and email addresses
β’ Billing and delivery information
β’ Order and transaction records
β’ Invoice data
β’ Payment metadata
β’ Product and transport-related information
β’ Application and system logs
β
The actor claims the leak contains 92,178 lines of data totaling approximately 214 MB, provided in CSV and JSON formats.
β
Files shown in the post include datasets related to orders, invoices and historical application logs.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Pass Pass, a regional public transport and mobility service in Hauts-de-France, France, is named in a cybercrime forum post where a threat actor claims to have leaked a partial dataset containing information tied to 18,861 people.
β
The advertised data includes:
β
β’ Customer names and email addresses
β’ Billing and delivery information
β’ Order and transaction records
β’ Invoice data
β’ Payment metadata
β’ Product and transport-related information
β’ Application and system logs
β
The actor claims the leak contains 92,178 lines of data totaling approximately 214 MB, provided in CSV and JSON formats.
β
Files shown in the post include datasets related to orders, invoices and historical application logs.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π«π· YouFID dataset allegedly leaked on a cybercrime forum, 7.8K people claimed
β
YouFID, a French customer loyalty and engagement platform that helps businesses manage digital loyalty programs and rewards, is named in a cybercrime forum post where a threat actor claims to have leaked a partial dataset containing information tied to 7,880 people.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Associated date fields
β
The actor claims the dataset contains 7,880 lines of data totaling approximately 805 KB, provided in JSON format.
β
A sample of the allegedly exposed records was also published in the forum post.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
YouFID, a French customer loyalty and engagement platform that helps businesses manage digital loyalty programs and rewards, is named in a cybercrime forum post where a threat actor claims to have leaked a partial dataset containing information tied to 7,880 people.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Associated date fields
β
The actor claims the dataset contains 7,880 lines of data totaling approximately 805 KB, provided in JSON format.
β
A sample of the allegedly exposed records was also published in the forum post.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πͺ Slice For Life - Part 2 πͺ
https://x.com/DarkWebInformer/status/2096267679044649190
ASN: 53667 π±πΊ
Org: FranTech Solutions
Org: FranTech Solutions
π¨π¬π§ Initial access to a UK IT consulting company allegedly offered for sale on a cybercrime forum
β
An unnamed UK IT consulting company operating in the finance sector is referenced in a cybercrime forum post where a threat actor claims to be selling privileged access to its environment.
β
The advertised access includes:
β
β’ Personal Access Token (PAT)
β’ Administrative access to GitLab
β’ Access associated with a company reportedly generating $225M in revenue
β
The actor did not publicly identify the affected company in the listing.
β
The claims and the authenticity, scope and validity of the advertised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An unnamed UK IT consulting company operating in the finance sector is referenced in a cybercrime forum post where a threat actor claims to be selling privileged access to its environment.
β
The advertised access includes:
β
β’ Personal Access Token (PAT)
β’ Administrative access to GitLab
β’ Access associated with a company reportedly generating $225M in revenue
β
The actor did not publicly identify the affected company in the listing.
β
The claims and the authenticity, scope and validity of the advertised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing