🚨🇳🇬 Nestuge App user dataset allegedly offered for sale on a cybercrime forum, 326K+ records claimed
⠀
Nestuge App, described in the listing as a Nigerian job and earning platform, is named in a cybercrime forum post where a threat actor claims to be selling a Firebase Firestore export containing 326,578 user records.
⠀
The advertised dataset includes:
⠀
• 326,524 unique email addresses
• 324,900 records with names
• 12,006 records with phone numbers
• Full names
• Email addresses
• Phone numbers where available
⠀
The actor claims the dataset was extracted on August 24, 2026 from a live application user base and says re-extraction is available.
⠀
The data is advertised in JSON format, with Nigeria listed as the primary country alongside users in the global diaspora.
⠀
The listing is priced at $800–$1,000, with BTC and XMR accepted.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Nestuge App, described in the listing as a Nigerian job and earning platform, is named in a cybercrime forum post where a threat actor claims to be selling a Firebase Firestore export containing 326,578 user records.
⠀
The advertised dataset includes:
⠀
• 326,524 unique email addresses
• 324,900 records with names
• 12,006 records with phone numbers
• Full names
• Email addresses
• Phone numbers where available
⠀
The actor claims the dataset was extracted on August 24, 2026 from a live application user base and says re-extraction is available.
⠀
The data is advertised in JSON format, with Nigeria listed as the primary country alongside users in the global diaspora.
⠀
The listing is priced at $800–$1,000, with BTC and XMR accepted.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
🚨🇲🇽 SISEEMS student records allegedly leaked on a cybercrime forum
⠀
SISEEMS (Sistema de Servicios Escolares de la Educación Media Superior), Mexico’s upper-secondary education school services system, is named in a cybercrime forum post where a threat actor claims to have leaked student records associated with DGETI and DGETAyCM.
⠀
The advertised data includes:
⠀
• Full names
• Student IDs
• School names and codes
• Academic programs
• GPA information
• Credits completed
• Document status
• Official folio numbers
• Issuance dates
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
SISEEMS (Sistema de Servicios Escolares de la Educación Media Superior), Mexico’s upper-secondary education school services system, is named in a cybercrime forum post where a threat actor claims to have leaked student records associated with DGETI and DGETAyCM.
⠀
The advertised data includes:
⠀
• Full names
• Student IDs
• School names and codes
• Academic programs
• GPA information
• Credits completed
• Document status
• Official folio numbers
• Issuance dates
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇵🇪 Peruvian Air Force dataset allegedly leaked on a cybercrime forum, 13K+ files claimed
⠀
Fuerza Aérea del Perú (FAP), the Peruvian Air Force, is named in a cybercrime forum post where a threat actor claims to have leaked a database containing 13,037 images totaling approximately 1.3 GB.
⠀
The actor claims:
⠀
• 13,037 image files
• Approximately 1.3 GB of data
• The release represents the complete database
• Additional specific databases may also be available
⠀
The actor published a download for the allegedly exposed material and also named Argentina as a “next target.”
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Fuerza Aérea del Perú (FAP), the Peruvian Air Force, is named in a cybercrime forum post where a threat actor claims to have leaked a database containing 13,037 images totaling approximately 1.3 GB.
⠀
The actor claims:
⠀
• 13,037 image files
• Approximately 1.3 GB of data
• The release represents the complete database
• Additional specific databases may also be available
⠀
The actor published a download for the allegedly exposed material and also named Argentina as a “next target.”
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
🚨🇫🇷 Pass Pass dataset allegedly leaked on a cybercrime forum, 18K+ people claimed
⠀
Pass Pass, a regional public transport and mobility service in Hauts-de-France, France, is named in a cybercrime forum post where a threat actor claims to have leaked a partial dataset containing information tied to 18,861 people.
⠀
The advertised data includes:
⠀
• Customer names and email addresses
• Billing and delivery information
• Order and transaction records
• Invoice data
• Payment metadata
• Product and transport-related information
• Application and system logs
⠀
The actor claims the leak contains 92,178 lines of data totaling approximately 214 MB, provided in CSV and JSON formats.
⠀
Files shown in the post include datasets related to orders, invoices and historical application logs.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Pass Pass, a regional public transport and mobility service in Hauts-de-France, France, is named in a cybercrime forum post where a threat actor claims to have leaked a partial dataset containing information tied to 18,861 people.
⠀
The advertised data includes:
⠀
• Customer names and email addresses
• Billing and delivery information
• Order and transaction records
• Invoice data
• Payment metadata
• Product and transport-related information
• Application and system logs
⠀
The actor claims the leak contains 92,178 lines of data totaling approximately 214 MB, provided in CSV and JSON formats.
⠀
Files shown in the post include datasets related to orders, invoices and historical application logs.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 YouFID dataset allegedly leaked on a cybercrime forum, 7.8K people claimed
⠀
YouFID, a French customer loyalty and engagement platform that helps businesses manage digital loyalty programs and rewards, is named in a cybercrime forum post where a threat actor claims to have leaked a partial dataset containing information tied to 7,880 people.
⠀
The advertised data includes:
⠀
• Full names
• Email addresses
• Phone numbers
• Associated date fields
⠀
The actor claims the dataset contains 7,880 lines of data totaling approximately 805 KB, provided in JSON format.
⠀
A sample of the allegedly exposed records was also published in the forum post.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
YouFID, a French customer loyalty and engagement platform that helps businesses manage digital loyalty programs and rewards, is named in a cybercrime forum post where a threat actor claims to have leaked a partial dataset containing information tied to 7,880 people.
⠀
The advertised data includes:
⠀
• Full names
• Email addresses
• Phone numbers
• Associated date fields
⠀
The actor claims the dataset contains 7,880 lines of data totaling approximately 805 KB, provided in JSON format.
⠀
A sample of the allegedly exposed records was also published in the forum post.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🔪 Slice For Life - Part 2 🔪
https://x.com/DarkWebInformer/status/2096267679044649190
ASN: 53667 🇱🇺
Org: FranTech Solutions
Org: FranTech Solutions
🚨🇬🇧 Initial access to a UK IT consulting company allegedly offered for sale on a cybercrime forum
⠀
An unnamed UK IT consulting company operating in the finance sector is referenced in a cybercrime forum post where a threat actor claims to be selling privileged access to its environment.
⠀
The advertised access includes:
⠀
• Personal Access Token (PAT)
• Administrative access to GitLab
• Access associated with a company reportedly generating $225M in revenue
⠀
The actor did not publicly identify the affected company in the listing.
⠀
The claims and the authenticity, scope and validity of the advertised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
An unnamed UK IT consulting company operating in the finance sector is referenced in a cybercrime forum post where a threat actor claims to be selling privileged access to its environment.
⠀
The advertised access includes:
⠀
• Personal Access Token (PAT)
• Administrative access to GitLab
• Access associated with a company reportedly generating $225M in revenue
⠀
The actor did not publicly identify the affected company in the listing.
⠀
The claims and the authenticity, scope and validity of the advertised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 La Maison Pour Tous tenant dataset allegedly leaked on a cybercrime forum, 8K records claimed
⠀
La Maison Pour Tous, a French social housing cooperative, is named in a cybercrime forum post where a threat actor claims to have leaked a dataset containing information tied to approximately 8,000 tenants.
⠀
The advertised data includes:
⠀
• Tenant names
• Associated record identifiers
⠀
The actor claims the dataset totals approximately 275 KB and is provided in CSV format.
⠀
A sample of the allegedly exposed records was also published in the forum post.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
La Maison Pour Tous, a French social housing cooperative, is named in a cybercrime forum post where a threat actor claims to have leaked a dataset containing information tied to approximately 8,000 tenants.
⠀
The advertised data includes:
⠀
• Tenant names
• Associated record identifiers
⠀
The actor claims the dataset totals approximately 275 KB and is provided in CSV format.
⠀
A sample of the allegedly exposed records was also published in the forum post.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🔪 Slice For Life - Part 2 🔪
ASN: 53667 🇱🇺 Org: FranTech Solutions
This is a Luxembourg server. You can report any illegal content to https://stopline.bee-secure.lu/.
BEE SECURE works with Luxembourg police/prosecutors and international partners to handle qualifying reports.
BEE SECURE works with Luxembourg police/prosecutors and international partners to handle qualifying reports.
There was an issue with crypto payments via XMR. Should be fixed. Anyone who made a purchase in the last 48 hours via Monero had their subscription updated to reflect what you recently paid for. So if you are new, you should have just received an email.
🚨🇫🇷 Atout France user dataset allegedly leaked on a cybercrime forum, 10K records claimed
⠀
Atout France, France’s national tourism development agency, is named in a cybercrime forum post where a threat actor claims to have exploited a vulnerability and scraped approximately 10,000 user records.
⠀
The advertised data includes:
⠀
• Full names
• Email addresses and login information
• Phone numbers
• Job functions and organizations
• Membership numbers
• SIRET identifiers
• Billing addresses
• Delivery addresses
• User and profile IDs
• Drupal user identifiers
⠀
The actor claims the vulnerability provided access to thousands of users and says they subsequently scraped the available records.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Atout France, France’s national tourism development agency, is named in a cybercrime forum post where a threat actor claims to have exploited a vulnerability and scraped approximately 10,000 user records.
⠀
The advertised data includes:
⠀
• Full names
• Email addresses and login information
• Phone numbers
• Job functions and organizations
• Membership numbers
• SIRET identifiers
• Billing addresses
• Delivery addresses
• User and profile IDs
• Drupal user identifiers
⠀
The actor claims the vulnerability provided access to thousands of users and says they subsequently scraped the available records.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Ledger + Trezor cryptocurrency theft toolkit allegedly offered for sale on a cybercrime forum
⠀
A threat actor is advertising what they describe as an “unleaked” Ledger and Trezor exploit toolkit, claiming it can be used to trick cryptocurrency wallet users into authorizing malicious transactions.
⠀
The advertised capabilities include:
⠀
• Support for Ledger and Trezor devices
• Custom cryptocurrency and EVM chain selection
• Transaction signing workflows
• SMS-based victim interaction
• Multiple social-engineering flow templates
• Custom recipient addresses
• Claimed “one-click” transfer functionality
⠀
The actor shared a demonstration showing a Trezor Model T-themed transaction request for 5 ETH, designed to prompt a wallet user to review and sign a transaction.
⠀
The seller claims the toolkit is hosted on their infrastructure and says similar kits have been offered elsewhere for five-figure prices.
⠀
The claims and the functionality, effectiveness and authenticity of the advertised toolkit have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A threat actor is advertising what they describe as an “unleaked” Ledger and Trezor exploit toolkit, claiming it can be used to trick cryptocurrency wallet users into authorizing malicious transactions.
⠀
The advertised capabilities include:
⠀
• Support for Ledger and Trezor devices
• Custom cryptocurrency and EVM chain selection
• Transaction signing workflows
• SMS-based victim interaction
• Multiple social-engineering flow templates
• Custom recipient addresses
• Claimed “one-click” transfer functionality
⠀
The actor shared a demonstration showing a Trezor Model T-themed transaction request for 5 ETH, designed to prompt a wallet user to review and sign a transaction.
⠀
The seller claims the toolkit is hosted on their infrastructure and says similar kits have been offered elsewhere for five-figure prices.
⠀
The claims and the functionality, effectiveness and authenticity of the advertised toolkit have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Spirit Cultural Exchange allegedly breached, 170 GB of data claimed
Spirit Cultural Exchange, a U.S.-based provider of international cultural exchange and J-1 visa programs, has been named in an extortion post on a cybercrime forum.
Claimed exposure
• 170 GB of data
• 136,817 files
• Passport files and face images
• Employment verification documents
• Degree diplomas
• Host school offers
• Letters of reference
• Criminal background checks
• Additional participant documents
Extortion demand: $100,000
Deadline: September 20, 2026
The actor claims the data will be offered for sale if the ransom is not paid.
The breach claim, exposed data and scope have not been independently verified.
💥 Get the intel threat actors see when they post it.
darkwebinformer.com/pricing
Spirit Cultural Exchange, a U.S.-based provider of international cultural exchange and J-1 visa programs, has been named in an extortion post on a cybercrime forum.
Claimed exposure
• 170 GB of data
• 136,817 files
• Passport files and face images
• Employment verification documents
• Degree diplomas
• Host school offers
• Letters of reference
• Criminal background checks
• Additional participant documents
Extortion demand: $100,000
Deadline: September 20, 2026
The actor claims the data will be offered for sale if the ransom is not paid.
The breach claim, exposed data and scope have not been independently verified.
💥 Get the intel threat actors see when they post it.
darkwebinformer.com/pricing
🚨🇮🇱 Yehud-Monosson Municipality allegedly breached, 836K+ rows of data claimed
Yehud-Monosson Municipality, a local government authority in Israel, is named in a cybercrime forum post where a threat actor claims to have obtained a full MariaDB dump from the municipality’s Social Welfare Office systems.
Claimed exposure
• 135 MB of data
• 114 database tables
• 836,672 rows
• 16 staff accounts with password hashes
• Administrative and editor accounts
• Active session tokens
• TOTP 2FA secret for a superuser account
• Google Site Kit OAuth credentials
• System logs containing usernames and IP addresses
• Social welfare intake records and case paperwork
The sample shown by the actor includes highly sensitive welfare-related records involving domestic violence, financial hardship and other social-service cases.
The actor claims the municipality was breached on September 4, 2026 and has published the allegedly stolen dataset on the forum.
The breach claim, exposed data and scope have not been independently verified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Yehud-Monosson Municipality, a local government authority in Israel, is named in a cybercrime forum post where a threat actor claims to have obtained a full MariaDB dump from the municipality’s Social Welfare Office systems.
Claimed exposure
• 135 MB of data
• 114 database tables
• 836,672 rows
• 16 staff accounts with password hashes
• Administrative and editor accounts
• Active session tokens
• TOTP 2FA secret for a superuser account
• Google Site Kit OAuth credentials
• System logs containing usernames and IP addresses
• Social welfare intake records and case paperwork
The sample shown by the actor includes highly sensitive welfare-related records involving domestic violence, financial hardship and other social-service cases.
The actor claims the municipality was breached on September 4, 2026 and has published the allegedly stolen dataset on the forum.
The breach claim, exposed data and scope have not been independently verified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing