🔪 Slice For Life - Part 2 🔪
4.69K subscribers
1.07K photos
59 videos
964 links
Download Telegram
🚨🇬🇧 Initial access to a UK IT consulting company allegedly offered for sale on a cybercrime forum

An unnamed UK IT consulting company operating in the finance sector is referenced in a cybercrime forum post where a threat actor claims to be selling privileged access to its environment.

The advertised access includes:

• Personal Access Token (PAT)
• Administrative access to GitLab
• Access associated with a company reportedly generating $225M in revenue

The actor did not publicly identify the affected company in the listing.

The claims and the authenticity, scope and validity of the advertised access have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 La Maison Pour Tous tenant dataset allegedly leaked on a cybercrime forum, 8K records claimed

La Maison Pour Tous, a French social housing cooperative, is named in a cybercrime forum post where a threat actor claims to have leaked a dataset containing information tied to approximately 8,000 tenants.

The advertised data includes:

• Tenant names
• Associated record identifiers

The actor claims the dataset totals approximately 275 KB and is provided in CSV format.

A sample of the allegedly exposed records was also published in the forum post.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🔪 Slice For Life - Part 2 🔪
ASN: 53667 🇱🇺 Org: FranTech Solutions
This is a Luxembourg server. You can report any illegal content to https://stopline.bee-secure.lu/.

BEE SECURE works with Luxembourg police/prosecutors and international partners to handle qualifying reports.
Media is too big
VIEW IN TELEGRAM
Kid Cudi - Pursuit Of Happiness ft. MGMT
🤔4
⚠️ Dark Matter Market public links are currently down. Private links are working, but some are complaining that their private links aren't. Treat with caution.

Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/598f789643cae0d3f573
1
There was an issue with crypto payments via XMR. Should be fixed. Anyone who made a purchase in the last 48 hours via Monero had their subscription updated to reflect what you recently paid for. So if you are new, you should have just received an email.
Fisher-Price presents: My First Bulletproof Hosting Setup
😁6
🚨🇫🇷 Atout France user dataset allegedly leaked on a cybercrime forum, 10K records claimed

Atout France, France’s national tourism development agency, is named in a cybercrime forum post where a threat actor claims to have exploited a vulnerability and scraped approximately 10,000 user records.

The advertised data includes:

• Full names
• Email addresses and login information
• Phone numbers
• Job functions and organizations
• Membership numbers
• SIRET identifiers
• Billing addresses
• Delivery addresses
• User and profile IDs
• Drupal user identifiers

The actor claims the vulnerability provided access to thousands of users and says they subsequently scraped the available records.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Ledger + Trezor cryptocurrency theft toolkit allegedly offered for sale on a cybercrime forum

A threat actor is advertising what they describe as an “unleaked” Ledger and Trezor exploit toolkit, claiming it can be used to trick cryptocurrency wallet users into authorizing malicious transactions.

The advertised capabilities include:

• Support for Ledger and Trezor devices
• Custom cryptocurrency and EVM chain selection
• Transaction signing workflows
• SMS-based victim interaction
• Multiple social-engineering flow templates
• Custom recipient addresses
• Claimed “one-click” transfer functionality

The actor shared a demonstration showing a Trezor Model T-themed transaction request for 5 ETH, designed to prompt a wallet user to review and sign a transaction.

The seller claims the toolkit is hosted on their infrastructure and says similar kits have been offered elsewhere for five-figure prices.

The claims and the functionality, effectiveness and authenticity of the advertised toolkit have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Spirit Cultural Exchange allegedly breached, 170 GB of data claimed

Spirit Cultural Exchange, a U.S.-based provider of international cultural exchange and J-1 visa programs, has been named in an extortion post on a cybercrime forum.

Claimed exposure

• 170 GB of data
• 136,817 files
• Passport files and face images
• Employment verification documents
• Degree diplomas
• Host school offers
• Letters of reference
• Criminal background checks
• Additional participant documents

Extortion demand: $100,000
Deadline: September 20, 2026

The actor claims the data will be offered for sale if the ransom is not paid.

The breach claim, exposed data and scope have not been independently verified.

💥 Get the intel threat actors see when they post it.
darkwebinformer.com/pricing
🚨🇮🇱 Yehud-Monosson Municipality allegedly breached, 836K+ rows of data claimed

Yehud-Monosson Municipality, a local government authority in Israel, is named in a cybercrime forum post where a threat actor claims to have obtained a full MariaDB dump from the municipality’s Social Welfare Office systems.

Claimed exposure

• 135 MB of data
• 114 database tables
• 836,672 rows
• 16 staff accounts with password hashes
• Administrative and editor accounts
• Active session tokens
• TOTP 2FA secret for a superuser account
• Google Site Kit OAuth credentials
• System logs containing usernames and IP addresses
• Social welfare intake records and case paperwork

The sample shown by the actor includes highly sensitive welfare-related records involving domestic violence, financial hardship and other social-service cases.

The actor claims the municipality was breached on September 4, 2026 and has published the allegedly stolen dataset on the forum.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️🇺🇸 Mission Pet Health has been claimed a victim to DireWolf Ransomware
🇩🇪 Berlin Launches Crisis Response After Rhysida Ransomware Publishes 5.79 TB of Stolen Government Data

https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/
😁1
🚨🇪🇸 Spain SIPS energy supply dataset allegedly leaked, 40M+ CUPS records claimed

SIPS (Sistema de Información de Puntos de Suministro), Spain’s electricity and gas supply-point information system, is named in a cybercrime forum post where a threat actor claims to have obtained a full dataset covering more than 40 million CUPS records.

Claimed exposure

• Customer names and NIF/CIF identifiers
• Dates of birth and customer addresses
• CUPS supply-point identifiers
• Electricity and gas supply information
• Supply addresses and municipalities
• Distribution companies and tariffs
• Contracted power and voltage data
• Meter information and access rights
• Consumption profiles and billing frequency
• Annual energy consumption figures
• Meter readings and BIE-related dates

The actor describes the dataset as fresh and claims it contains detailed information associated with electricity and gas supply points throughout Spain.

A sample record containing personal, address and supply information was also published in the forum post.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
😭1
🚨🇲🇽 Querétaro State Civil Protection Coordination allegedly breached, user dataset leaked

Coordinación Estatal de Protección Civil de Querétaro (CEPCQ), the state agency responsible for civil protection in Querétaro, Mexico, is named in a cybercrime forum post where a threat actor claims to have obtained the full user dataset from its online procedures platform.

Claimed exposure

• Full names
• CURP and RFC identifiers
• Phone numbers and email addresses
• Residential addresses and postal codes
• Business and commercial names
• Legal representative information
• Representative contact information
• User IDs and account-related fields
• Applicant type, position and status information
• Record update timestamps

The actor claims the dataset contains profiles belonging to individual applicants, businesses and legal entities that processed civil protection procedures in Querétaro.

The data is advertised in CSV format, and a sample containing personal, business and contact information was published in the forum post.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇨🇦 Bitbuy super-admin support portal access allegedly offered for sale on a cybercrime forum

Bitbuy, a Canadian cryptocurrency trading platform, is named in a cybercrime forum post where a threat actor claims to have access to an internal super-admin/support portal and is offering the access for sale.

Claimed exposure

• User IDs and email addresses
• Account risk scores
• Investigation status information
• Last account activity
• Risky transaction volumes
• Transfer volumes
• Country information
• Account activity status

The actor published screenshots that appear to show an administrative dashboard containing customer risk and transaction information, along with a sample export of allegedly accessible records.

The seller also claims additional details can be discussed privately with interested buyers.

The access claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇧🇷 Central dos Benefícios dataset allegedly offered for sale, 2.7M+ people claimed

Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named in a cybercrime forum post where a threat actor claims to be selling a 1 GB dataset containing millions of records.

Claimed exposure

• 2,734,282 people records
• 2,086,659 payment card records
• 784,045 application users
• 32,322 security group records
• 11,059 security users
• 1,119 operator records
• Names and email addresses
• CPF/CNPJ identifiers
• Payment card numbers, expiration dates and CVV data
• Account and credential-related information

The actor claims the dataset contains approximately 3.5 million lines and is provided in JSON format.

A sample of the allegedly exposed records was published in the forum post, and the dataset is being advertised for $5,000, with XMR or BTC accepted.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing