🔪 Slice For Life - Part 2 🔪
4.79K subscribers
1.1K photos
62 videos
980 links
Download Telegram
🚨🇧🇷 Central dos Benefícios dataset allegedly offered for sale, 2.7M+ people claimed

Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named in a cybercrime forum post where a threat actor claims to be selling a 1 GB dataset containing millions of records.

Claimed exposure

• 2,734,282 people records
• 2,086,659 payment card records
• 784,045 application users
• 32,322 security group records
• 11,059 security users
• 1,119 operator records
• Names and email addresses
• CPF/CNPJ identifiers
• Payment card numbers, expiration dates and CVV data
• Account and credential-related information

The actor claims the dataset contains approximately 3.5 million lines and is provided in JSON format.

A sample of the allegedly exposed records was published in the forum post, and the dataset is being advertised for $5,000, with XMR or BTC accepted.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Threat actor seeking to buy compromised cPanel, Plesk and WHM access on a cybercrime forum

A threat actor has posted a listing seeking to purchase cPanel, Plesk and WHM credentials obtained from stealer logs or other compromised sources.

Requested access

• cPanel, Plesk or WHM credentials
• Valid username and password combinations
• No 2FA enabled
• Website must be operational
• Access must allow file creation and modification
• Credentials supplied in link:login:password format

The listing also states that escrow is accepted for transactions.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A forum seller is offering an active VirusTotal Enterprise account with GTI access and a 30M quota, priced at $2,000 in XMR or BTC with a 6-month account guarantee.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
😈1
🚨🇺🇸🇨🇦 195M identity records allegedly offered for sale on a cybercrime forum, including 153M+ driver’s license records from the recent Nexus onion DL market.

A threat actor is advertising what they claim is a 195 million-record identity dataset containing information tied primarily to individuals in the United States and Canada.

Claimed exposure

• 153,347,439 driver’s license records
• 10,335,678 identification card records
• 5,092,107 uncategorized identity records
• 1,924,144 travel document records
• 1,379,886 international driver’s license/ID records
• 579,201 medical card records
• 429,314 common access card records
• 91,873 residence card records
• 77,155 employment authorization records

The actor claims the dataset contains extensive identity information and says it has been in their possession for years.

The listing names multiple organizations as allegedly affected and is being advertised for $90,000, reduced from a claimed previous price of $120,000.

The dataset claim, record counts, affected organizations and authenticity of the advertised data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🤔1
🚨🇷🇺 Strezhevoy city portal allegedly breached, 54K+ user accounts exposed

The Strezhevoy city portal, serving the city of Strezhevoy in Russia’s Kemerovo Oblast (Kuzbass), is named in a cybercrime forum post where a threat actor claims to have breached the site and obtained data from 13 database tables containing 450,516 rows.

Claimed exposure

• 54,404 chat accounts
• 54,387 MD5 password hashes
• Registration and last-seen IP addresses
• Email addresses and account activity data
• 301,501 historical login events
• 18,638 unique IP addresses
• 3,932 dating profiles with dates of birth
• Names, phone numbers and gender information
• 870 extended user profiles
• VKontakte profile links
• MySQL credentials and database configuration data
• Raw SQL database dumps

The actor claims the login history spans from October 2010 through June 2026 and includes usernames, timestamps, IP addresses and browser user-agent information.

The forum post states the site was breached on September 5, 2026, with the allegedly stolen data being distributed as PII CSV files, JSONL exports and SQL dumps.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
1
🚨🇫🇷 Service National Universel portal allegedly breached, 275K+ user records claimed

Service National Universel (SNU), a French government youth engagement program, is named in a cybercrime forum post where a threat actor claims to have exploited an IDOR vulnerability in one of its portals and scraped user information.

Claimed exposure

• 275,083 total user records
• 270,021 general user IDs
• 5,062 staff member records
• First and last names
• Email addresses
• Phone and mobile numbers
• User roles and account status
• Regional and departmental information
• Cohort information
• Account creation and update timestamps
• Last activity information

The actor claims the vulnerability exposed information belonging to regular users and administrative/staff accounts, with poorly configured roles and permissions potentially providing additional access.

Samples of both user and staff records were published in the forum post.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🚨🇷🇸🇧🇬 PHOENIX Pharma Serbia & Bulgaria allegedly breached, 293 MB of internal B2B data claimed

PHOENIX Pharma Serbia & Bulgaria, part of Germany-based PHOENIX group, is named in a cybercrime forum post where a threat actor claims to have obtained internal business-to-business data from the pharmaceutical wholesaler and healthcare services company.

Claimed exposure

• Usernames
• Pharmacy names
• Passwords
• Email addresses
• Order information
• Internal B2B account data

The actor claims the dataset totals approximately 293 MB and is provided in CSV, XLS and JSON formats.

A sample published in the forum post appears to contain pharmacy account records, employee or operator information, email addresses and related business data.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
‼️ New DragonForce Ransomware Mirror:

http://xjhmtitnrdrgzw4vmsghirdoo2fk35a3tzj4enlmah4pvehdspydsiyd[.]onion
1
Lul, someone sends a message and is like is this Dark Webie guy? you should join this Telegram channel it has big new data breach... HAHA good one.
😁4
⚠️ A lot of talk on Dread about Dark Matter still being down and jokes on a possible exit scam. My private link is working fine. See response header date/time with the market loaded.
🚨‼️ Liquid Network was drained of approximately 4,000 BTC, worth around $320 million, over the past several hours.

The hackers left the following on-chain message: “we are whitehats. contact us on chain”

Blockstream responded on-chain with: “Please contact security@blockstream.com.”
🚨 🇺🇸 Initial Access: US Software Company

A threat actor is advertising access to an unnamed U.S. software company reportedly generating $450M in revenue.

The advertised access includes GitHub, CI/CD infrastructure, a Snyk key, and a Databricks token. Payment is requested in XMR.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ ShinyHunters claims a Swiss medical technology company

🇨🇭 Medela - A Swiss medical technology company specializing in breast pumps, breastfeeding products, and healthcare solutions for mothers, infants, and hospitals.

The listing includes a September 8, 2026 deadline, but does not specify the claimed data volume or types of information compromised.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
OSINTsearch is a live data search engine that helps individuals, investigators, and security teams explore social profiles and available breach exposure data from supported sources and third-party providers.

Link: https://osintsearch.org

Credit: @weezerOSINT (X)
🚨🇧🇷 Claro Brasil allegedly breached, 46M+ phone numbers linked to CPF claimed

Claro Brasil, one of Brazil’s largest telecommunications providers, is named in a cybercrime forum post where a threat actor claims to have compromised an exposed API and extracted 46,033,380 telephone numbers linked to Brazilian CPF identifiers.

Claimed exposure

• 46,033,380 phone numbers
• CPF identifiers linked to telephone numbers
• Historical records reportedly dating from 2004 to early 2026
• Approximately 2 million records released as proof of concept
• 6.1 GB dataset
• Database provided in .DB format

The actor claims Claro has approximately 90.8 million existing phone numbers in Brazil, but says only slightly more than half could be extracted before the activity was detected.

The actor also claims the 2 million-record proof of concept contains phone numbers linked to CPF data, with some records dating through 2019.

The breach claim, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇦🇷 Hospital Alemán and OSDEPYM allegedly breached, sensitive medical and customer data leaked

Hospital Alemán and OSDEPYM, two Argentine healthcare organizations, are named in a cybercrime forum post where a threat actor claims negotiations failed and data belonging to both organizations is now being released.

Hospital Alemán claimed exposure

• Approximately 84,000 prescription records
• Patient names and dates of birth
• DNI identification numbers
• Medical coverage information
• Diagnoses and treatment details
• Prescription and medication information
• Physician and electronic prescription data

The actor published a sample containing highly sensitive medical information and claims the prescription data was converted into CSV format for release.

OSDEPYM claimed exposure

• Approximately 7,000 customer records
• Names and dates of birth
• DNI and affiliate identifiers
• Email addresses and phone numbers
• Residential addresses
• Health plan and coverage information
• Account and registration-related data

Samples of the allegedly exposed OSDEPYM customer data were also published in the forum post.

The breach claims, exposed data and scope have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing