🚨🇫🇷 La Maison Pour Tous tenant dataset allegedly leaked on a cybercrime forum, 8K records claimed
⠀
La Maison Pour Tous, a French social housing cooperative, is named in a cybercrime forum post where a threat actor claims to have leaked a dataset containing information tied to approximately 8,000 tenants.
⠀
The advertised data includes:
⠀
• Tenant names
• Associated record identifiers
⠀
The actor claims the dataset totals approximately 275 KB and is provided in CSV format.
⠀
A sample of the allegedly exposed records was also published in the forum post.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
La Maison Pour Tous, a French social housing cooperative, is named in a cybercrime forum post where a threat actor claims to have leaked a dataset containing information tied to approximately 8,000 tenants.
⠀
The advertised data includes:
⠀
• Tenant names
• Associated record identifiers
⠀
The actor claims the dataset totals approximately 275 KB and is provided in CSV format.
⠀
A sample of the allegedly exposed records was also published in the forum post.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🔪 Slice For Life - Part 2 🔪
ASN: 53667 🇱🇺 Org: FranTech Solutions
This is a Luxembourg server. You can report any illegal content to https://stopline.bee-secure.lu/.
BEE SECURE works with Luxembourg police/prosecutors and international partners to handle qualifying reports.
BEE SECURE works with Luxembourg police/prosecutors and international partners to handle qualifying reports.
There was an issue with crypto payments via XMR. Should be fixed. Anyone who made a purchase in the last 48 hours via Monero had their subscription updated to reflect what you recently paid for. So if you are new, you should have just received an email.
🚨🇫🇷 Atout France user dataset allegedly leaked on a cybercrime forum, 10K records claimed
⠀
Atout France, France’s national tourism development agency, is named in a cybercrime forum post where a threat actor claims to have exploited a vulnerability and scraped approximately 10,000 user records.
⠀
The advertised data includes:
⠀
• Full names
• Email addresses and login information
• Phone numbers
• Job functions and organizations
• Membership numbers
• SIRET identifiers
• Billing addresses
• Delivery addresses
• User and profile IDs
• Drupal user identifiers
⠀
The actor claims the vulnerability provided access to thousands of users and says they subsequently scraped the available records.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Atout France, France’s national tourism development agency, is named in a cybercrime forum post where a threat actor claims to have exploited a vulnerability and scraped approximately 10,000 user records.
⠀
The advertised data includes:
⠀
• Full names
• Email addresses and login information
• Phone numbers
• Job functions and organizations
• Membership numbers
• SIRET identifiers
• Billing addresses
• Delivery addresses
• User and profile IDs
• Drupal user identifiers
⠀
The actor claims the vulnerability provided access to thousands of users and says they subsequently scraped the available records.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Ledger + Trezor cryptocurrency theft toolkit allegedly offered for sale on a cybercrime forum
⠀
A threat actor is advertising what they describe as an “unleaked” Ledger and Trezor exploit toolkit, claiming it can be used to trick cryptocurrency wallet users into authorizing malicious transactions.
⠀
The advertised capabilities include:
⠀
• Support for Ledger and Trezor devices
• Custom cryptocurrency and EVM chain selection
• Transaction signing workflows
• SMS-based victim interaction
• Multiple social-engineering flow templates
• Custom recipient addresses
• Claimed “one-click” transfer functionality
⠀
The actor shared a demonstration showing a Trezor Model T-themed transaction request for 5 ETH, designed to prompt a wallet user to review and sign a transaction.
⠀
The seller claims the toolkit is hosted on their infrastructure and says similar kits have been offered elsewhere for five-figure prices.
⠀
The claims and the functionality, effectiveness and authenticity of the advertised toolkit have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A threat actor is advertising what they describe as an “unleaked” Ledger and Trezor exploit toolkit, claiming it can be used to trick cryptocurrency wallet users into authorizing malicious transactions.
⠀
The advertised capabilities include:
⠀
• Support for Ledger and Trezor devices
• Custom cryptocurrency and EVM chain selection
• Transaction signing workflows
• SMS-based victim interaction
• Multiple social-engineering flow templates
• Custom recipient addresses
• Claimed “one-click” transfer functionality
⠀
The actor shared a demonstration showing a Trezor Model T-themed transaction request for 5 ETH, designed to prompt a wallet user to review and sign a transaction.
⠀
The seller claims the toolkit is hosted on their infrastructure and says similar kits have been offered elsewhere for five-figure prices.
⠀
The claims and the functionality, effectiveness and authenticity of the advertised toolkit have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Spirit Cultural Exchange allegedly breached, 170 GB of data claimed
Spirit Cultural Exchange, a U.S.-based provider of international cultural exchange and J-1 visa programs, has been named in an extortion post on a cybercrime forum.
Claimed exposure
• 170 GB of data
• 136,817 files
• Passport files and face images
• Employment verification documents
• Degree diplomas
• Host school offers
• Letters of reference
• Criminal background checks
• Additional participant documents
Extortion demand: $100,000
Deadline: September 20, 2026
The actor claims the data will be offered for sale if the ransom is not paid.
The breach claim, exposed data and scope have not been independently verified.
💥 Get the intel threat actors see when they post it.
darkwebinformer.com/pricing
Spirit Cultural Exchange, a U.S.-based provider of international cultural exchange and J-1 visa programs, has been named in an extortion post on a cybercrime forum.
Claimed exposure
• 170 GB of data
• 136,817 files
• Passport files and face images
• Employment verification documents
• Degree diplomas
• Host school offers
• Letters of reference
• Criminal background checks
• Additional participant documents
Extortion demand: $100,000
Deadline: September 20, 2026
The actor claims the data will be offered for sale if the ransom is not paid.
The breach claim, exposed data and scope have not been independently verified.
💥 Get the intel threat actors see when they post it.
darkwebinformer.com/pricing
🚨🇮🇱 Yehud-Monosson Municipality allegedly breached, 836K+ rows of data claimed
Yehud-Monosson Municipality, a local government authority in Israel, is named in a cybercrime forum post where a threat actor claims to have obtained a full MariaDB dump from the municipality’s Social Welfare Office systems.
Claimed exposure
• 135 MB of data
• 114 database tables
• 836,672 rows
• 16 staff accounts with password hashes
• Administrative and editor accounts
• Active session tokens
• TOTP 2FA secret for a superuser account
• Google Site Kit OAuth credentials
• System logs containing usernames and IP addresses
• Social welfare intake records and case paperwork
The sample shown by the actor includes highly sensitive welfare-related records involving domestic violence, financial hardship and other social-service cases.
The actor claims the municipality was breached on September 4, 2026 and has published the allegedly stolen dataset on the forum.
The breach claim, exposed data and scope have not been independently verified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Yehud-Monosson Municipality, a local government authority in Israel, is named in a cybercrime forum post where a threat actor claims to have obtained a full MariaDB dump from the municipality’s Social Welfare Office systems.
Claimed exposure
• 135 MB of data
• 114 database tables
• 836,672 rows
• 16 staff accounts with password hashes
• Administrative and editor accounts
• Active session tokens
• TOTP 2FA secret for a superuser account
• Google Site Kit OAuth credentials
• System logs containing usernames and IP addresses
• Social welfare intake records and case paperwork
The sample shown by the actor includes highly sensitive welfare-related records involving domestic violence, financial hardship and other social-service cases.
The actor claims the municipality was breached on September 4, 2026 and has published the allegedly stolen dataset on the forum.
The breach claim, exposed data and scope have not been independently verified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🇩🇪 Berlin Launches Crisis Response After Rhysida Ransomware Publishes 5.79 TB of Stolen Government Data
https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/
https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/
😁1
🚨🇪🇸 Spain SIPS energy supply dataset allegedly leaked, 40M+ CUPS records claimed
⠀
SIPS (Sistema de Información de Puntos de Suministro), Spain’s electricity and gas supply-point information system, is named in a cybercrime forum post where a threat actor claims to have obtained a full dataset covering more than 40 million CUPS records.
⠀
Claimed exposure
⠀
• Customer names and NIF/CIF identifiers
• Dates of birth and customer addresses
• CUPS supply-point identifiers
• Electricity and gas supply information
• Supply addresses and municipalities
• Distribution companies and tariffs
• Contracted power and voltage data
• Meter information and access rights
• Consumption profiles and billing frequency
• Annual energy consumption figures
• Meter readings and BIE-related dates
⠀
The actor describes the dataset as fresh and claims it contains detailed information associated with electricity and gas supply points throughout Spain.
⠀
A sample record containing personal, address and supply information was also published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
SIPS (Sistema de Información de Puntos de Suministro), Spain’s electricity and gas supply-point information system, is named in a cybercrime forum post where a threat actor claims to have obtained a full dataset covering more than 40 million CUPS records.
⠀
Claimed exposure
⠀
• Customer names and NIF/CIF identifiers
• Dates of birth and customer addresses
• CUPS supply-point identifiers
• Electricity and gas supply information
• Supply addresses and municipalities
• Distribution companies and tariffs
• Contracted power and voltage data
• Meter information and access rights
• Consumption profiles and billing frequency
• Annual energy consumption figures
• Meter readings and BIE-related dates
⠀
The actor describes the dataset as fresh and claims it contains detailed information associated with electricity and gas supply points throughout Spain.
⠀
A sample record containing personal, address and supply information was also published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
😭1
🚨🇲🇽 Querétaro State Civil Protection Coordination allegedly breached, user dataset leaked
⠀
Coordinación Estatal de Protección Civil de Querétaro (CEPCQ), the state agency responsible for civil protection in Querétaro, Mexico, is named in a cybercrime forum post where a threat actor claims to have obtained the full user dataset from its online procedures platform.
⠀
Claimed exposure
⠀
• Full names
• CURP and RFC identifiers
• Phone numbers and email addresses
• Residential addresses and postal codes
• Business and commercial names
• Legal representative information
• Representative contact information
• User IDs and account-related fields
• Applicant type, position and status information
• Record update timestamps
⠀
The actor claims the dataset contains profiles belonging to individual applicants, businesses and legal entities that processed civil protection procedures in Querétaro.
⠀
The data is advertised in CSV format, and a sample containing personal, business and contact information was published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Coordinación Estatal de Protección Civil de Querétaro (CEPCQ), the state agency responsible for civil protection in Querétaro, Mexico, is named in a cybercrime forum post where a threat actor claims to have obtained the full user dataset from its online procedures platform.
⠀
Claimed exposure
⠀
• Full names
• CURP and RFC identifiers
• Phone numbers and email addresses
• Residential addresses and postal codes
• Business and commercial names
• Legal representative information
• Representative contact information
• User IDs and account-related fields
• Applicant type, position and status information
• Record update timestamps
⠀
The actor claims the dataset contains profiles belonging to individual applicants, businesses and legal entities that processed civil protection procedures in Querétaro.
⠀
The data is advertised in CSV format, and a sample containing personal, business and contact information was published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇨🇦 Bitbuy super-admin support portal access allegedly offered for sale on a cybercrime forum
⠀
Bitbuy, a Canadian cryptocurrency trading platform, is named in a cybercrime forum post where a threat actor claims to have access to an internal super-admin/support portal and is offering the access for sale.
⠀
Claimed exposure
⠀
• User IDs and email addresses
• Account risk scores
• Investigation status information
• Last account activity
• Risky transaction volumes
• Transfer volumes
• Country information
• Account activity status
⠀
The actor published screenshots that appear to show an administrative dashboard containing customer risk and transaction information, along with a sample export of allegedly accessible records.
⠀
The seller also claims additional details can be discussed privately with interested buyers.
⠀
The access claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Bitbuy, a Canadian cryptocurrency trading platform, is named in a cybercrime forum post where a threat actor claims to have access to an internal super-admin/support portal and is offering the access for sale.
⠀
Claimed exposure
⠀
• User IDs and email addresses
• Account risk scores
• Investigation status information
• Last account activity
• Risky transaction volumes
• Transfer volumes
• Country information
• Account activity status
⠀
The actor published screenshots that appear to show an administrative dashboard containing customer risk and transaction information, along with a sample export of allegedly accessible records.
⠀
The seller also claims additional details can be discussed privately with interested buyers.
⠀
The access claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇧🇷 Central dos Benefícios dataset allegedly offered for sale, 2.7M+ people claimed
⠀
Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named in a cybercrime forum post where a threat actor claims to be selling a 1 GB dataset containing millions of records.
⠀
Claimed exposure
⠀
• 2,734,282 people records
• 2,086,659 payment card records
• 784,045 application users
• 32,322 security group records
• 11,059 security users
• 1,119 operator records
• Names and email addresses
• CPF/CNPJ identifiers
• Payment card numbers, expiration dates and CVV data
• Account and credential-related information
⠀
The actor claims the dataset contains approximately 3.5 million lines and is provided in JSON format.
⠀
A sample of the allegedly exposed records was published in the forum post, and the dataset is being advertised for $5,000, with XMR or BTC accepted.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named in a cybercrime forum post where a threat actor claims to be selling a 1 GB dataset containing millions of records.
⠀
Claimed exposure
⠀
• 2,734,282 people records
• 2,086,659 payment card records
• 784,045 application users
• 32,322 security group records
• 11,059 security users
• 1,119 operator records
• Names and email addresses
• CPF/CNPJ identifiers
• Payment card numbers, expiration dates and CVV data
• Account and credential-related information
⠀
The actor claims the dataset contains approximately 3.5 million lines and is provided in JSON format.
⠀
A sample of the allegedly exposed records was published in the forum post, and the dataset is being advertised for $5,000, with XMR or BTC accepted.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Threat actor seeking to buy compromised cPanel, Plesk and WHM access on a cybercrime forum
⠀
A threat actor has posted a listing seeking to purchase cPanel, Plesk and WHM credentials obtained from stealer logs or other compromised sources.
⠀
Requested access
⠀
• cPanel, Plesk or WHM credentials
• Valid username and password combinations
• No 2FA enabled
• Website must be operational
• Access must allow file creation and modification
• Credentials supplied in link:login:password format
⠀
The listing also states that escrow is accepted for transactions.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A threat actor has posted a listing seeking to purchase cPanel, Plesk and WHM credentials obtained from stealer logs or other compromised sources.
⠀
Requested access
⠀
• cPanel, Plesk or WHM credentials
• Valid username and password combinations
• No 2FA enabled
• Website must be operational
• Access must allow file creation and modification
• Credentials supplied in link:login:password format
⠀
The listing also states that escrow is accepted for transactions.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing