🔪 Slice For Life - Part 2 🔪
4.69K subscribers
1.07K photos
59 videos
964 links
Download Telegram
There was an issue with crypto payments via XMR. Should be fixed. Anyone who made a purchase in the last 48 hours via Monero had their subscription updated to reflect what you recently paid for. So if you are new, you should have just received an email.
Fisher-Price presents: My First Bulletproof Hosting Setup
😁6
🚨🇫🇷 Atout France user dataset allegedly leaked on a cybercrime forum, 10K records claimed

Atout France, France’s national tourism development agency, is named in a cybercrime forum post where a threat actor claims to have exploited a vulnerability and scraped approximately 10,000 user records.

The advertised data includes:

• Full names
• Email addresses and login information
• Phone numbers
• Job functions and organizations
• Membership numbers
• SIRET identifiers
• Billing addresses
• Delivery addresses
• User and profile IDs
• Drupal user identifiers

The actor claims the vulnerability provided access to thousands of users and says they subsequently scraped the available records.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Ledger + Trezor cryptocurrency theft toolkit allegedly offered for sale on a cybercrime forum

A threat actor is advertising what they describe as an “unleaked” Ledger and Trezor exploit toolkit, claiming it can be used to trick cryptocurrency wallet users into authorizing malicious transactions.

The advertised capabilities include:

• Support for Ledger and Trezor devices
• Custom cryptocurrency and EVM chain selection
• Transaction signing workflows
• SMS-based victim interaction
• Multiple social-engineering flow templates
• Custom recipient addresses
• Claimed “one-click” transfer functionality

The actor shared a demonstration showing a Trezor Model T-themed transaction request for 5 ETH, designed to prompt a wallet user to review and sign a transaction.

The seller claims the toolkit is hosted on their infrastructure and says similar kits have been offered elsewhere for five-figure prices.

The claims and the functionality, effectiveness and authenticity of the advertised toolkit have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Spirit Cultural Exchange allegedly breached, 170 GB of data claimed

Spirit Cultural Exchange, a U.S.-based provider of international cultural exchange and J-1 visa programs, has been named in an extortion post on a cybercrime forum.

Claimed exposure

• 170 GB of data
• 136,817 files
• Passport files and face images
• Employment verification documents
• Degree diplomas
• Host school offers
• Letters of reference
• Criminal background checks
• Additional participant documents

Extortion demand: $100,000
Deadline: September 20, 2026

The actor claims the data will be offered for sale if the ransom is not paid.

The breach claim, exposed data and scope have not been independently verified.

💥 Get the intel threat actors see when they post it.
darkwebinformer.com/pricing
🚨🇮🇱 Yehud-Monosson Municipality allegedly breached, 836K+ rows of data claimed

Yehud-Monosson Municipality, a local government authority in Israel, is named in a cybercrime forum post where a threat actor claims to have obtained a full MariaDB dump from the municipality’s Social Welfare Office systems.

Claimed exposure

• 135 MB of data
• 114 database tables
• 836,672 rows
• 16 staff accounts with password hashes
• Administrative and editor accounts
• Active session tokens
• TOTP 2FA secret for a superuser account
• Google Site Kit OAuth credentials
• System logs containing usernames and IP addresses
• Social welfare intake records and case paperwork

The sample shown by the actor includes highly sensitive welfare-related records involving domestic violence, financial hardship and other social-service cases.

The actor claims the municipality was breached on September 4, 2026 and has published the allegedly stolen dataset on the forum.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️🇺🇸 Mission Pet Health has been claimed a victim to DireWolf Ransomware
🇩🇪 Berlin Launches Crisis Response After Rhysida Ransomware Publishes 5.79 TB of Stolen Government Data

https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/
😁1
🚨🇪🇸 Spain SIPS energy supply dataset allegedly leaked, 40M+ CUPS records claimed

SIPS (Sistema de Información de Puntos de Suministro), Spain’s electricity and gas supply-point information system, is named in a cybercrime forum post where a threat actor claims to have obtained a full dataset covering more than 40 million CUPS records.

Claimed exposure

• Customer names and NIF/CIF identifiers
• Dates of birth and customer addresses
• CUPS supply-point identifiers
• Electricity and gas supply information
• Supply addresses and municipalities
• Distribution companies and tariffs
• Contracted power and voltage data
• Meter information and access rights
• Consumption profiles and billing frequency
• Annual energy consumption figures
• Meter readings and BIE-related dates

The actor describes the dataset as fresh and claims it contains detailed information associated with electricity and gas supply points throughout Spain.

A sample record containing personal, address and supply information was also published in the forum post.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
😭1
🚨🇲🇽 Querétaro State Civil Protection Coordination allegedly breached, user dataset leaked

Coordinación Estatal de Protección Civil de Querétaro (CEPCQ), the state agency responsible for civil protection in Querétaro, Mexico, is named in a cybercrime forum post where a threat actor claims to have obtained the full user dataset from its online procedures platform.

Claimed exposure

• Full names
• CURP and RFC identifiers
• Phone numbers and email addresses
• Residential addresses and postal codes
• Business and commercial names
• Legal representative information
• Representative contact information
• User IDs and account-related fields
• Applicant type, position and status information
• Record update timestamps

The actor claims the dataset contains profiles belonging to individual applicants, businesses and legal entities that processed civil protection procedures in Querétaro.

The data is advertised in CSV format, and a sample containing personal, business and contact information was published in the forum post.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇨🇦 Bitbuy super-admin support portal access allegedly offered for sale on a cybercrime forum

Bitbuy, a Canadian cryptocurrency trading platform, is named in a cybercrime forum post where a threat actor claims to have access to an internal super-admin/support portal and is offering the access for sale.

Claimed exposure

• User IDs and email addresses
• Account risk scores
• Investigation status information
• Last account activity
• Risky transaction volumes
• Transfer volumes
• Country information
• Account activity status

The actor published screenshots that appear to show an administrative dashboard containing customer risk and transaction information, along with a sample export of allegedly accessible records.

The seller also claims additional details can be discussed privately with interested buyers.

The access claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇧🇷 Central dos Benefícios dataset allegedly offered for sale, 2.7M+ people claimed

Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named in a cybercrime forum post where a threat actor claims to be selling a 1 GB dataset containing millions of records.

Claimed exposure

• 2,734,282 people records
• 2,086,659 payment card records
• 784,045 application users
• 32,322 security group records
• 11,059 security users
• 1,119 operator records
• Names and email addresses
• CPF/CNPJ identifiers
• Payment card numbers, expiration dates and CVV data
• Account and credential-related information

The actor claims the dataset contains approximately 3.5 million lines and is provided in JSON format.

A sample of the allegedly exposed records was published in the forum post, and the dataset is being advertised for $5,000, with XMR or BTC accepted.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Threat actor seeking to buy compromised cPanel, Plesk and WHM access on a cybercrime forum

A threat actor has posted a listing seeking to purchase cPanel, Plesk and WHM credentials obtained from stealer logs or other compromised sources.

Requested access

• cPanel, Plesk or WHM credentials
• Valid username and password combinations
• No 2FA enabled
• Website must be operational
• Access must allow file creation and modification
• Credentials supplied in link:login:password format

The listing also states that escrow is accepted for transactions.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A forum seller is offering an active VirusTotal Enterprise account with GTI access and a 30M quota, priced at $2,000 in XMR or BTC with a 6-month account guarantee.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
😈1
🚨🇺🇸🇨🇦 195M identity records allegedly offered for sale on a cybercrime forum, including 153M+ driver’s license records from the recent Nexus onion DL market.

A threat actor is advertising what they claim is a 195 million-record identity dataset containing information tied primarily to individuals in the United States and Canada.

Claimed exposure

• 153,347,439 driver’s license records
• 10,335,678 identification card records
• 5,092,107 uncategorized identity records
• 1,924,144 travel document records
• 1,379,886 international driver’s license/ID records
• 579,201 medical card records
• 429,314 common access card records
• 91,873 residence card records
• 77,155 employment authorization records

The actor claims the dataset contains extensive identity information and says it has been in their possession for years.

The listing names multiple organizations as allegedly affected and is being advertised for $90,000, reduced from a claimed previous price of $120,000.

The dataset claim, record counts, affected organizations and authenticity of the advertised data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🤔1
🚨🇷🇺 Strezhevoy city portal allegedly breached, 54K+ user accounts exposed

The Strezhevoy city portal, serving the city of Strezhevoy in Russia’s Kemerovo Oblast (Kuzbass), is named in a cybercrime forum post where a threat actor claims to have breached the site and obtained data from 13 database tables containing 450,516 rows.

Claimed exposure

• 54,404 chat accounts
• 54,387 MD5 password hashes
• Registration and last-seen IP addresses
• Email addresses and account activity data
• 301,501 historical login events
• 18,638 unique IP addresses
• 3,932 dating profiles with dates of birth
• Names, phone numbers and gender information
• 870 extended user profiles
• VKontakte profile links
• MySQL credentials and database configuration data
• Raw SQL database dumps

The actor claims the login history spans from October 2010 through June 2026 and includes usernames, timestamps, IP addresses and browser user-agent information.

The forum post states the site was breached on September 5, 2026, with the allegedly stolen data being distributed as PII CSV files, JSONL exports and SQL dumps.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
1
🚨🇫🇷 Service National Universel portal allegedly breached, 275K+ user records claimed

Service National Universel (SNU), a French government youth engagement program, is named in a cybercrime forum post where a threat actor claims to have exploited an IDOR vulnerability in one of its portals and scraped user information.

Claimed exposure

• 275,083 total user records
• 270,021 general user IDs
• 5,062 staff member records
• First and last names
• Email addresses
• Phone and mobile numbers
• User roles and account status
• Regional and departmental information
• Cohort information
• Account creation and update timestamps
• Last activity information

The actor claims the vulnerability exposed information belonging to regular users and administrative/staff accounts, with poorly configured roles and permissions potentially providing additional access.

Samples of both user and staff records were published in the forum post.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🚨🇷🇸🇧🇬 PHOENIX Pharma Serbia & Bulgaria allegedly breached, 293 MB of internal B2B data claimed

PHOENIX Pharma Serbia & Bulgaria, part of Germany-based PHOENIX group, is named in a cybercrime forum post where a threat actor claims to have obtained internal business-to-business data from the pharmaceutical wholesaler and healthcare services company.

Claimed exposure

• Usernames
• Pharmacy names
• Passwords
• Email addresses
• Order information
• Internal B2B account data

The actor claims the dataset totals approximately 293 MB and is provided in CSV, XLS and JSON formats.

A sample published in the forum post appears to contain pharmacy account records, employee or operator information, email addresses and related business data.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials