🚨🇧🇷 Central dos Benefícios dataset allegedly offered for sale, 2.7M+ people claimed
⠀
Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named in a cybercrime forum post where a threat actor claims to be selling a 1 GB dataset containing millions of records.
⠀
Claimed exposure
⠀
• 2,734,282 people records
• 2,086,659 payment card records
• 784,045 application users
• 32,322 security group records
• 11,059 security users
• 1,119 operator records
• Names and email addresses
• CPF/CNPJ identifiers
• Payment card numbers, expiration dates and CVV data
• Account and credential-related information
⠀
The actor claims the dataset contains approximately 3.5 million lines and is provided in JSON format.
⠀
A sample of the allegedly exposed records was published in the forum post, and the dataset is being advertised for $5,000, with XMR or BTC accepted.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Central dos Benefícios, a Brazilian corporate benefits platform providing employee benefit services, is named in a cybercrime forum post where a threat actor claims to be selling a 1 GB dataset containing millions of records.
⠀
Claimed exposure
⠀
• 2,734,282 people records
• 2,086,659 payment card records
• 784,045 application users
• 32,322 security group records
• 11,059 security users
• 1,119 operator records
• Names and email addresses
• CPF/CNPJ identifiers
• Payment card numbers, expiration dates and CVV data
• Account and credential-related information
⠀
The actor claims the dataset contains approximately 3.5 million lines and is provided in JSON format.
⠀
A sample of the allegedly exposed records was published in the forum post, and the dataset is being advertised for $5,000, with XMR or BTC accepted.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Threat actor seeking to buy compromised cPanel, Plesk and WHM access on a cybercrime forum
⠀
A threat actor has posted a listing seeking to purchase cPanel, Plesk and WHM credentials obtained from stealer logs or other compromised sources.
⠀
Requested access
⠀
• cPanel, Plesk or WHM credentials
• Valid username and password combinations
• No 2FA enabled
• Website must be operational
• Access must allow file creation and modification
• Credentials supplied in link:login:password format
⠀
The listing also states that escrow is accepted for transactions.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A threat actor has posted a listing seeking to purchase cPanel, Plesk and WHM credentials obtained from stealer logs or other compromised sources.
⠀
Requested access
⠀
• cPanel, Plesk or WHM credentials
• Valid username and password combinations
• No 2FA enabled
• Website must be operational
• Access must allow file creation and modification
• Credentials supplied in link:login:password format
⠀
The listing also states that escrow is accepted for transactions.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A forum seller is offering an active VirusTotal Enterprise account with GTI access and a 30M quota, priced at $2,000 in XMR or BTC with a 6-month account guarantee.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
😈1
🚨🇺🇸🇨🇦 195M identity records allegedly offered for sale on a cybercrime forum, including 153M+ driver’s license records from the recent Nexus onion DL market.
⠀
A threat actor is advertising what they claim is a 195 million-record identity dataset containing information tied primarily to individuals in the United States and Canada.
⠀
Claimed exposure
⠀
• 153,347,439 driver’s license records
• 10,335,678 identification card records
• 5,092,107 uncategorized identity records
• 1,924,144 travel document records
• 1,379,886 international driver’s license/ID records
• 579,201 medical card records
• 429,314 common access card records
• 91,873 residence card records
• 77,155 employment authorization records
⠀
The actor claims the dataset contains extensive identity information and says it has been in their possession for years.
⠀
The listing names multiple organizations as allegedly affected and is being advertised for $90,000, reduced from a claimed previous price of $120,000.
⠀
The dataset claim, record counts, affected organizations and authenticity of the advertised data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
A threat actor is advertising what they claim is a 195 million-record identity dataset containing information tied primarily to individuals in the United States and Canada.
⠀
Claimed exposure
⠀
• 153,347,439 driver’s license records
• 10,335,678 identification card records
• 5,092,107 uncategorized identity records
• 1,924,144 travel document records
• 1,379,886 international driver’s license/ID records
• 579,201 medical card records
• 429,314 common access card records
• 91,873 residence card records
• 77,155 employment authorization records
⠀
The actor claims the dataset contains extensive identity information and says it has been in their possession for years.
⠀
The listing names multiple organizations as allegedly affected and is being advertised for $90,000, reduced from a claimed previous price of $120,000.
⠀
The dataset claim, record counts, affected organizations and authenticity of the advertised data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
❤1🤔1
🚨🇷🇺 Strezhevoy city portal allegedly breached, 54K+ user accounts exposed
⠀
The Strezhevoy city portal, serving the city of Strezhevoy in Russia’s Kemerovo Oblast (Kuzbass), is named in a cybercrime forum post where a threat actor claims to have breached the site and obtained data from 13 database tables containing 450,516 rows.
⠀
Claimed exposure
⠀
• 54,404 chat accounts
• 54,387 MD5 password hashes
• Registration and last-seen IP addresses
• Email addresses and account activity data
• 301,501 historical login events
• 18,638 unique IP addresses
• 3,932 dating profiles with dates of birth
• Names, phone numbers and gender information
• 870 extended user profiles
• VKontakte profile links
• MySQL credentials and database configuration data
• Raw SQL database dumps
⠀
The actor claims the login history spans from October 2010 through June 2026 and includes usernames, timestamps, IP addresses and browser user-agent information.
⠀
The forum post states the site was breached on September 5, 2026, with the allegedly stolen data being distributed as PII CSV files, JSONL exports and SQL dumps.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
The Strezhevoy city portal, serving the city of Strezhevoy in Russia’s Kemerovo Oblast (Kuzbass), is named in a cybercrime forum post where a threat actor claims to have breached the site and obtained data from 13 database tables containing 450,516 rows.
⠀
Claimed exposure
⠀
• 54,404 chat accounts
• 54,387 MD5 password hashes
• Registration and last-seen IP addresses
• Email addresses and account activity data
• 301,501 historical login events
• 18,638 unique IP addresses
• 3,932 dating profiles with dates of birth
• Names, phone numbers and gender information
• 870 extended user profiles
• VKontakte profile links
• MySQL credentials and database configuration data
• Raw SQL database dumps
⠀
The actor claims the login history spans from October 2010 through June 2026 and includes usernames, timestamps, IP addresses and browser user-agent information.
⠀
The forum post states the site was breached on September 5, 2026, with the allegedly stolen data being distributed as PII CSV files, JSONL exports and SQL dumps.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
🚨🇫🇷 Service National Universel portal allegedly breached, 275K+ user records claimed
⠀
Service National Universel (SNU), a French government youth engagement program, is named in a cybercrime forum post where a threat actor claims to have exploited an IDOR vulnerability in one of its portals and scraped user information.
⠀
Claimed exposure
⠀
• 275,083 total user records
• 270,021 general user IDs
• 5,062 staff member records
• First and last names
• Email addresses
• Phone and mobile numbers
• User roles and account status
• Regional and departmental information
• Cohort information
• Account creation and update timestamps
• Last activity information
⠀
The actor claims the vulnerability exposed information belonging to regular users and administrative/staff accounts, with poorly configured roles and permissions potentially providing additional access.
⠀
Samples of both user and staff records were published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
Service National Universel (SNU), a French government youth engagement program, is named in a cybercrime forum post where a threat actor claims to have exploited an IDOR vulnerability in one of its portals and scraped user information.
⠀
Claimed exposure
⠀
• 275,083 total user records
• 270,021 general user IDs
• 5,062 staff member records
• First and last names
• Email addresses
• Phone and mobile numbers
• User roles and account status
• Regional and departmental information
• Cohort information
• Account creation and update timestamps
• Last activity information
⠀
The actor claims the vulnerability exposed information belonging to regular users and administrative/staff accounts, with poorly configured roles and permissions potentially providing additional access.
⠀
Samples of both user and staff records were published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🚨🇷🇸🇧🇬 PHOENIX Pharma Serbia & Bulgaria allegedly breached, 293 MB of internal B2B data claimed
⠀
PHOENIX Pharma Serbia & Bulgaria, part of Germany-based PHOENIX group, is named in a cybercrime forum post where a threat actor claims to have obtained internal business-to-business data from the pharmaceutical wholesaler and healthcare services company.
⠀
Claimed exposure
⠀
• Usernames
• Pharmacy names
• Passwords
• Email addresses
• Order information
• Internal B2B account data
⠀
The actor claims the dataset totals approximately 293 MB and is provided in CSV, XLS and JSON formats.
⠀
A sample published in the forum post appears to contain pharmacy account records, employee or operator information, email addresses and related business data.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
PHOENIX Pharma Serbia & Bulgaria, part of Germany-based PHOENIX group, is named in a cybercrime forum post where a threat actor claims to have obtained internal business-to-business data from the pharmaceutical wholesaler and healthcare services company.
⠀
Claimed exposure
⠀
• Usernames
• Pharmacy names
• Passwords
• Email addresses
• Order information
• Internal B2B account data
⠀
The actor claims the dataset totals approximately 293 MB and is provided in CSV, XLS and JSON formats.
⠀
A sample published in the forum post appears to contain pharmacy account records, employee or operator information, email addresses and related business data.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
Telegram 0-Click Crash Exploit
https://x.com/0x6rss/status/2096695379299377321
https://x.com/0x6rss/status/2096695379299377321
X (formerly Twitter)
0x6rss (@0x6rss) on X
⚠️Telegram 0-Click Crash Exploit @telegram
This vulnerability can make Telegram unusable regardless of the version or platform. Sending just a single malicious sticker to the target chat is enoug…
This vulnerability can make Telegram unusable regardless of the version or platform. Sending just a single malicious sticker to the target chat is enoug…
Lul, someone sends a message and is like is this Dark Webie guy? you should join this Telegram channel it has big new data breach... HAHA good one.
😁4
🔪 Slice For Life - Part 2 🔪
⚠️ A lot of talk on Dread about Dark Matter still being down and jokes on a possible exit scam. My private link is working fine. See response header date/time with the market loaded.
Dear feds, I have a private link on all of the top darknet marketplaces... for reasons like this one. It's no deeper than that.
😁3😈1
🔪 Slice For Life - Part 2 🔪
🚨‼️ Liquid Network was drained of approximately 4,000 BTC, worth around $320 million, over the past several hours. The hackers left the following on-chain message: “we are whitehats. contact us on chain” Blockstream responded on-chain with: “Please contact…
X (formerly Twitter)
Liquid Network 🌊 (@Liquid_BTC) on X
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on con…
🚨 🇺🇸 Initial Access: US Software Company
A threat actor is advertising access to an unnamed U.S. software company reportedly generating $450M in revenue.
The advertised access includes GitHub, CI/CD infrastructure, a Snyk key, and a Databricks token. Payment is requested in XMR.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A threat actor is advertising access to an unnamed U.S. software company reportedly generating $450M in revenue.
The advertised access includes GitHub, CI/CD infrastructure, a Snyk key, and a Databricks token. Payment is requested in XMR.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ ShinyHunters claims a Swiss medical technology company
🇨🇭 Medela - A Swiss medical technology company specializing in breast pumps, breastfeeding products, and healthcare solutions for mothers, infants, and hospitals.
The listing includes a September 8, 2026 deadline, but does not specify the claimed data volume or types of information compromised.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
🇨🇭 Medela - A Swiss medical technology company specializing in breast pumps, breastfeeding products, and healthcare solutions for mothers, infants, and hospitals.
The listing includes a September 8, 2026 deadline, but does not specify the claimed data volume or types of information compromised.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
OSINTsearch is a live data search engine that helps individuals, investigators, and security teams explore social profiles and available breach exposure data from supported sources and third-party providers.
Link: https://osintsearch.org
Credit: @weezerOSINT (X)
Link: https://osintsearch.org
Credit: @weezerOSINT (X)
🚨🇧🇷 Claro Brasil allegedly breached, 46M+ phone numbers linked to CPF claimed
⠀
Claro Brasil, one of Brazil’s largest telecommunications providers, is named in a cybercrime forum post where a threat actor claims to have compromised an exposed API and extracted 46,033,380 telephone numbers linked to Brazilian CPF identifiers.
⠀
Claimed exposure
⠀
• 46,033,380 phone numbers
• CPF identifiers linked to telephone numbers
• Historical records reportedly dating from 2004 to early 2026
• Approximately 2 million records released as proof of concept
• 6.1 GB dataset
• Database provided in .DB format
⠀
The actor claims Claro has approximately 90.8 million existing phone numbers in Brazil, but says only slightly more than half could be extracted before the activity was detected.
⠀
The actor also claims the 2 million-record proof of concept contains phone numbers linked to CPF data, with some records dating through 2019.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Claro Brasil, one of Brazil’s largest telecommunications providers, is named in a cybercrime forum post where a threat actor claims to have compromised an exposed API and extracted 46,033,380 telephone numbers linked to Brazilian CPF identifiers.
⠀
Claimed exposure
⠀
• 46,033,380 phone numbers
• CPF identifiers linked to telephone numbers
• Historical records reportedly dating from 2004 to early 2026
• Approximately 2 million records released as proof of concept
• 6.1 GB dataset
• Database provided in .DB format
⠀
The actor claims Claro has approximately 90.8 million existing phone numbers in Brazil, but says only slightly more than half could be extracted before the activity was detected.
⠀
The actor also claims the 2 million-record proof of concept contains phone numbers linked to CPF data, with some records dating through 2019.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇦🇷 Hospital Alemán and OSDEPYM allegedly breached, sensitive medical and customer data leaked
⠀
Hospital Alemán and OSDEPYM, two Argentine healthcare organizations, are named in a cybercrime forum post where a threat actor claims negotiations failed and data belonging to both organizations is now being released.
⠀
Hospital Alemán claimed exposure
⠀
• Approximately 84,000 prescription records
• Patient names and dates of birth
• DNI identification numbers
• Medical coverage information
• Diagnoses and treatment details
• Prescription and medication information
• Physician and electronic prescription data
⠀
The actor published a sample containing highly sensitive medical information and claims the prescription data was converted into CSV format for release.
⠀
OSDEPYM claimed exposure
⠀
• Approximately 7,000 customer records
• Names and dates of birth
• DNI and affiliate identifiers
• Email addresses and phone numbers
• Residential addresses
• Health plan and coverage information
• Account and registration-related data
⠀
Samples of the allegedly exposed OSDEPYM customer data were also published in the forum post.
⠀
The breach claims, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Hospital Alemán and OSDEPYM, two Argentine healthcare organizations, are named in a cybercrime forum post where a threat actor claims negotiations failed and data belonging to both organizations is now being released.
⠀
Hospital Alemán claimed exposure
⠀
• Approximately 84,000 prescription records
• Patient names and dates of birth
• DNI identification numbers
• Medical coverage information
• Diagnoses and treatment details
• Prescription and medication information
• Physician and electronic prescription data
⠀
The actor published a sample containing highly sensitive medical information and claims the prescription data was converted into CSV format for release.
⠀
OSDEPYM claimed exposure
⠀
• Approximately 7,000 customer records
• Names and dates of birth
• DNI and affiliate identifiers
• Email addresses and phone numbers
• Residential addresses
• Health plan and coverage information
• Account and registration-related data
⠀
Samples of the allegedly exposed OSDEPYM customer data were also published in the forum post.
⠀
The breach claims, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing