🇩🇪 Berlin Launches Crisis Response After Rhysida Ransomware Publishes 5.79 TB of Stolen Government Data
https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/
https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/
😁1
🚨🇪🇸 Spain SIPS energy supply dataset allegedly leaked, 40M+ CUPS records claimed
⠀
SIPS (Sistema de Información de Puntos de Suministro), Spain’s electricity and gas supply-point information system, is named in a cybercrime forum post where a threat actor claims to have obtained a full dataset covering more than 40 million CUPS records.
⠀
Claimed exposure
⠀
• Customer names and NIF/CIF identifiers
• Dates of birth and customer addresses
• CUPS supply-point identifiers
• Electricity and gas supply information
• Supply addresses and municipalities
• Distribution companies and tariffs
• Contracted power and voltage data
• Meter information and access rights
• Consumption profiles and billing frequency
• Annual energy consumption figures
• Meter readings and BIE-related dates
⠀
The actor describes the dataset as fresh and claims it contains detailed information associated with electricity and gas supply points throughout Spain.
⠀
A sample record containing personal, address and supply information was also published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
SIPS (Sistema de Información de Puntos de Suministro), Spain’s electricity and gas supply-point information system, is named in a cybercrime forum post where a threat actor claims to have obtained a full dataset covering more than 40 million CUPS records.
⠀
Claimed exposure
⠀
• Customer names and NIF/CIF identifiers
• Dates of birth and customer addresses
• CUPS supply-point identifiers
• Electricity and gas supply information
• Supply addresses and municipalities
• Distribution companies and tariffs
• Contracted power and voltage data
• Meter information and access rights
• Consumption profiles and billing frequency
• Annual energy consumption figures
• Meter readings and BIE-related dates
⠀
The actor describes the dataset as fresh and claims it contains detailed information associated with electricity and gas supply points throughout Spain.
⠀
A sample record containing personal, address and supply information was also published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
😭1
🚨🇲🇽 Querétaro State Civil Protection Coordination allegedly breached, user dataset leaked
⠀
Coordinación Estatal de Protección Civil de Querétaro (CEPCQ), the state agency responsible for civil protection in Querétaro, Mexico, is named in a cybercrime forum post where a threat actor claims to have obtained the full user dataset from its online procedures platform.
⠀
Claimed exposure
⠀
• Full names
• CURP and RFC identifiers
• Phone numbers and email addresses
• Residential addresses and postal codes
• Business and commercial names
• Legal representative information
• Representative contact information
• User IDs and account-related fields
• Applicant type, position and status information
• Record update timestamps
⠀
The actor claims the dataset contains profiles belonging to individual applicants, businesses and legal entities that processed civil protection procedures in Querétaro.
⠀
The data is advertised in CSV format, and a sample containing personal, business and contact information was published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Coordinación Estatal de Protección Civil de Querétaro (CEPCQ), the state agency responsible for civil protection in Querétaro, Mexico, is named in a cybercrime forum post where a threat actor claims to have obtained the full user dataset from its online procedures platform.
⠀
Claimed exposure
⠀
• Full names
• CURP and RFC identifiers
• Phone numbers and email addresses
• Residential addresses and postal codes
• Business and commercial names
• Legal representative information
• Representative contact information
• User IDs and account-related fields
• Applicant type, position and status information
• Record update timestamps
⠀
The actor claims the dataset contains profiles belonging to individual applicants, businesses and legal entities that processed civil protection procedures in Querétaro.
⠀
The data is advertised in CSV format, and a sample containing personal, business and contact information was published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇨🇦 Bitbuy super-admin support portal access allegedly offered for sale on a cybercrime forum
⠀
Bitbuy, a Canadian cryptocurrency trading platform, is named in a cybercrime forum post where a threat actor claims to have access to an internal super-admin/support portal and is offering the access for sale.
⠀
Claimed exposure
⠀
• User IDs and email addresses
• Account risk scores
• Investigation status information
• Last account activity
• Risky transaction volumes
• Transfer volumes
• Country information
• Account activity status
⠀
The actor published screenshots that appear to show an administrative dashboard containing customer risk and transaction information, along with a sample export of allegedly accessible records.
⠀
The seller also claims additional details can be discussed privately with interested buyers.
⠀
The access claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Bitbuy, a Canadian cryptocurrency trading platform, is named in a cybercrime forum post where a threat actor claims to have access to an internal super-admin/support portal and is offering the access for sale.
⠀
Claimed exposure
⠀
• User IDs and email addresses
• Account risk scores
• Investigation status information
• Last account activity
• Risky transaction volumes
• Transfer volumes
• Country information
• Account activity status
⠀
The actor published screenshots that appear to show an administrative dashboard containing customer risk and transaction information, along with a sample export of allegedly accessible records.
⠀
The seller also claims additional details can be discussed privately with interested buyers.
⠀
The access claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇧🇷 Central dos Benefícios dataset allegedly offered for sale, 2.7M+ people claimed
⠀
Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named in a cybercrime forum post where a threat actor claims to be selling a 1 GB dataset containing millions of records.
⠀
Claimed exposure
⠀
• 2,734,282 people records
• 2,086,659 payment card records
• 784,045 application users
• 32,322 security group records
• 11,059 security users
• 1,119 operator records
• Names and email addresses
• CPF/CNPJ identifiers
• Payment card numbers, expiration dates and CVV data
• Account and credential-related information
⠀
The actor claims the dataset contains approximately 3.5 million lines and is provided in JSON format.
⠀
A sample of the allegedly exposed records was published in the forum post, and the dataset is being advertised for $5,000, with XMR or BTC accepted.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named in a cybercrime forum post where a threat actor claims to be selling a 1 GB dataset containing millions of records.
⠀
Claimed exposure
⠀
• 2,734,282 people records
• 2,086,659 payment card records
• 784,045 application users
• 32,322 security group records
• 11,059 security users
• 1,119 operator records
• Names and email addresses
• CPF/CNPJ identifiers
• Payment card numbers, expiration dates and CVV data
• Account and credential-related information
⠀
The actor claims the dataset contains approximately 3.5 million lines and is provided in JSON format.
⠀
A sample of the allegedly exposed records was published in the forum post, and the dataset is being advertised for $5,000, with XMR or BTC accepted.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Threat actor seeking to buy compromised cPanel, Plesk and WHM access on a cybercrime forum
⠀
A threat actor has posted a listing seeking to purchase cPanel, Plesk and WHM credentials obtained from stealer logs or other compromised sources.
⠀
Requested access
⠀
• cPanel, Plesk or WHM credentials
• Valid username and password combinations
• No 2FA enabled
• Website must be operational
• Access must allow file creation and modification
• Credentials supplied in link:login:password format
⠀
The listing also states that escrow is accepted for transactions.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A threat actor has posted a listing seeking to purchase cPanel, Plesk and WHM credentials obtained from stealer logs or other compromised sources.
⠀
Requested access
⠀
• cPanel, Plesk or WHM credentials
• Valid username and password combinations
• No 2FA enabled
• Website must be operational
• Access must allow file creation and modification
• Credentials supplied in link:login:password format
⠀
The listing also states that escrow is accepted for transactions.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A forum seller is offering an active VirusTotal Enterprise account with GTI access and a 30M quota, priced at $2,000 in XMR or BTC with a 6-month account guarantee.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
😈1
🚨🇺🇸🇨🇦 195M identity records allegedly offered for sale on a cybercrime forum, including 153M+ driver’s license records from the recent Nexus onion DL market.
⠀
A threat actor is advertising what they claim is a 195 million-record identity dataset containing information tied primarily to individuals in the United States and Canada.
⠀
Claimed exposure
⠀
• 153,347,439 driver’s license records
• 10,335,678 identification card records
• 5,092,107 uncategorized identity records
• 1,924,144 travel document records
• 1,379,886 international driver’s license/ID records
• 579,201 medical card records
• 429,314 common access card records
• 91,873 residence card records
• 77,155 employment authorization records
⠀
The actor claims the dataset contains extensive identity information and says it has been in their possession for years.
⠀
The listing names multiple organizations as allegedly affected and is being advertised for $90,000, reduced from a claimed previous price of $120,000.
⠀
The dataset claim, record counts, affected organizations and authenticity of the advertised data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
A threat actor is advertising what they claim is a 195 million-record identity dataset containing information tied primarily to individuals in the United States and Canada.
⠀
Claimed exposure
⠀
• 153,347,439 driver’s license records
• 10,335,678 identification card records
• 5,092,107 uncategorized identity records
• 1,924,144 travel document records
• 1,379,886 international driver’s license/ID records
• 579,201 medical card records
• 429,314 common access card records
• 91,873 residence card records
• 77,155 employment authorization records
⠀
The actor claims the dataset contains extensive identity information and says it has been in their possession for years.
⠀
The listing names multiple organizations as allegedly affected and is being advertised for $90,000, reduced from a claimed previous price of $120,000.
⠀
The dataset claim, record counts, affected organizations and authenticity of the advertised data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🤔1
🚨🇷🇺 Strezhevoy city portal allegedly breached, 54K+ user accounts exposed
⠀
The Strezhevoy city portal, serving the city of Strezhevoy in Russia’s Kemerovo Oblast (Kuzbass), is named in a cybercrime forum post where a threat actor claims to have breached the site and obtained data from 13 database tables containing 450,516 rows.
⠀
Claimed exposure
⠀
• 54,404 chat accounts
• 54,387 MD5 password hashes
• Registration and last-seen IP addresses
• Email addresses and account activity data
• 301,501 historical login events
• 18,638 unique IP addresses
• 3,932 dating profiles with dates of birth
• Names, phone numbers and gender information
• 870 extended user profiles
• VKontakte profile links
• MySQL credentials and database configuration data
• Raw SQL database dumps
⠀
The actor claims the login history spans from October 2010 through June 2026 and includes usernames, timestamps, IP addresses and browser user-agent information.
⠀
The forum post states the site was breached on September 5, 2026, with the allegedly stolen data being distributed as PII CSV files, JSONL exports and SQL dumps.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
The Strezhevoy city portal, serving the city of Strezhevoy in Russia’s Kemerovo Oblast (Kuzbass), is named in a cybercrime forum post where a threat actor claims to have breached the site and obtained data from 13 database tables containing 450,516 rows.
⠀
Claimed exposure
⠀
• 54,404 chat accounts
• 54,387 MD5 password hashes
• Registration and last-seen IP addresses
• Email addresses and account activity data
• 301,501 historical login events
• 18,638 unique IP addresses
• 3,932 dating profiles with dates of birth
• Names, phone numbers and gender information
• 870 extended user profiles
• VKontakte profile links
• MySQL credentials and database configuration data
• Raw SQL database dumps
⠀
The actor claims the login history spans from October 2010 through June 2026 and includes usernames, timestamps, IP addresses and browser user-agent information.
⠀
The forum post states the site was breached on September 5, 2026, with the allegedly stolen data being distributed as PII CSV files, JSONL exports and SQL dumps.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
🚨🇫🇷 Service National Universel portal allegedly breached, 275K+ user records claimed
⠀
Service National Universel (SNU), a French government youth engagement program, is named in a cybercrime forum post where a threat actor claims to have exploited an IDOR vulnerability in one of its portals and scraped user information.
⠀
Claimed exposure
⠀
• 275,083 total user records
• 270,021 general user IDs
• 5,062 staff member records
• First and last names
• Email addresses
• Phone and mobile numbers
• User roles and account status
• Regional and departmental information
• Cohort information
• Account creation and update timestamps
• Last activity information
⠀
The actor claims the vulnerability exposed information belonging to regular users and administrative/staff accounts, with poorly configured roles and permissions potentially providing additional access.
⠀
Samples of both user and staff records were published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
Service National Universel (SNU), a French government youth engagement program, is named in a cybercrime forum post where a threat actor claims to have exploited an IDOR vulnerability in one of its portals and scraped user information.
⠀
Claimed exposure
⠀
• 275,083 total user records
• 270,021 general user IDs
• 5,062 staff member records
• First and last names
• Email addresses
• Phone and mobile numbers
• User roles and account status
• Regional and departmental information
• Cohort information
• Account creation and update timestamps
• Last activity information
⠀
The actor claims the vulnerability exposed information belonging to regular users and administrative/staff accounts, with poorly configured roles and permissions potentially providing additional access.
⠀
Samples of both user and staff records were published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🚨🇷🇸🇧🇬 PHOENIX Pharma Serbia & Bulgaria allegedly breached, 293 MB of internal B2B data claimed
⠀
PHOENIX Pharma Serbia & Bulgaria, part of Germany-based PHOENIX group, is named in a cybercrime forum post where a threat actor claims to have obtained internal business-to-business data from the pharmaceutical wholesaler and healthcare services company.
⠀
Claimed exposure
⠀
• Usernames
• Pharmacy names
• Passwords
• Email addresses
• Order information
• Internal B2B account data
⠀
The actor claims the dataset totals approximately 293 MB and is provided in CSV, XLS and JSON formats.
⠀
A sample published in the forum post appears to contain pharmacy account records, employee or operator information, email addresses and related business data.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
PHOENIX Pharma Serbia & Bulgaria, part of Germany-based PHOENIX group, is named in a cybercrime forum post where a threat actor claims to have obtained internal business-to-business data from the pharmaceutical wholesaler and healthcare services company.
⠀
Claimed exposure
⠀
• Usernames
• Pharmacy names
• Passwords
• Email addresses
• Order information
• Internal B2B account data
⠀
The actor claims the dataset totals approximately 293 MB and is provided in CSV, XLS and JSON formats.
⠀
A sample published in the forum post appears to contain pharmacy account records, employee or operator information, email addresses and related business data.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
Telegram 0-Click Crash Exploit
https://x.com/0x6rss/status/2096695379299377321
https://x.com/0x6rss/status/2096695379299377321
X (formerly Twitter)
0x6rss (@0x6rss) on X
⚠️Telegram 0-Click Crash Exploit @telegram
This vulnerability can make Telegram unusable regardless of the version or platform. Sending just a single malicious sticker to the target chat is enoug…
This vulnerability can make Telegram unusable regardless of the version or platform. Sending just a single malicious sticker to the target chat is enoug…
Lul, someone sends a message and is like is this Dark Webie guy? you should join this Telegram channel it has big new data breach... HAHA good one.
😁4
🔪 Slice For Life - Part 2 🔪
⚠️ A lot of talk on Dread about Dark Matter still being down and jokes on a possible exit scam. My private link is working fine. See response header date/time with the market loaded.
Dear feds, I have a private link on all of the top darknet marketplaces... for reasons like this one. It's no deeper than that.
😁3😈1