🚨🇫🇷 Service National Universel portal allegedly breached, 275K+ user records claimed
⠀
Service National Universel (SNU), a French government youth engagement program, is named in a cybercrime forum post where a threat actor claims to have exploited an IDOR vulnerability in one of its portals and scraped user information.
⠀
Claimed exposure
⠀
• 275,083 total user records
• 270,021 general user IDs
• 5,062 staff member records
• First and last names
• Email addresses
• Phone and mobile numbers
• User roles and account status
• Regional and departmental information
• Cohort information
• Account creation and update timestamps
• Last activity information
⠀
The actor claims the vulnerability exposed information belonging to regular users and administrative/staff accounts, with poorly configured roles and permissions potentially providing additional access.
⠀
Samples of both user and staff records were published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
Service National Universel (SNU), a French government youth engagement program, is named in a cybercrime forum post where a threat actor claims to have exploited an IDOR vulnerability in one of its portals and scraped user information.
⠀
Claimed exposure
⠀
• 275,083 total user records
• 270,021 general user IDs
• 5,062 staff member records
• First and last names
• Email addresses
• Phone and mobile numbers
• User roles and account status
• Regional and departmental information
• Cohort information
• Account creation and update timestamps
• Last activity information
⠀
The actor claims the vulnerability exposed information belonging to regular users and administrative/staff accounts, with poorly configured roles and permissions potentially providing additional access.
⠀
Samples of both user and staff records were published in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🚨🇷🇸🇧🇬 PHOENIX Pharma Serbia & Bulgaria allegedly breached, 293 MB of internal B2B data claimed
⠀
PHOENIX Pharma Serbia & Bulgaria, part of Germany-based PHOENIX group, is named in a cybercrime forum post where a threat actor claims to have obtained internal business-to-business data from the pharmaceutical wholesaler and healthcare services company.
⠀
Claimed exposure
⠀
• Usernames
• Pharmacy names
• Passwords
• Email addresses
• Order information
• Internal B2B account data
⠀
The actor claims the dataset totals approximately 293 MB and is provided in CSV, XLS and JSON formats.
⠀
A sample published in the forum post appears to contain pharmacy account records, employee or operator information, email addresses and related business data.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
⠀
PHOENIX Pharma Serbia & Bulgaria, part of Germany-based PHOENIX group, is named in a cybercrime forum post where a threat actor claims to have obtained internal business-to-business data from the pharmaceutical wholesaler and healthcare services company.
⠀
Claimed exposure
⠀
• Usernames
• Pharmacy names
• Passwords
• Email addresses
• Order information
• Internal B2B account data
⠀
The actor claims the dataset totals approximately 293 MB and is provided in CSV, XLS and JSON formats.
⠀
A sample published in the forum post appears to contain pharmacy account records, employee or operator information, email addresses and related business data.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
Telegram 0-Click Crash Exploit
https://x.com/0x6rss/status/2096695379299377321
https://x.com/0x6rss/status/2096695379299377321
X (formerly Twitter)
0x6rss (@0x6rss) on X
⚠️Telegram 0-Click Crash Exploit @telegram
This vulnerability can make Telegram unusable regardless of the version or platform. Sending just a single malicious sticker to the target chat is enoug…
This vulnerability can make Telegram unusable regardless of the version or platform. Sending just a single malicious sticker to the target chat is enoug…
Lul, someone sends a message and is like is this Dark Webie guy? you should join this Telegram channel it has big new data breach... HAHA good one.
😁4
🔪 Slice For Life - Part 2 🔪
⚠️ A lot of talk on Dread about Dark Matter still being down and jokes on a possible exit scam. My private link is working fine. See response header date/time with the market loaded.
Dear feds, I have a private link on all of the top darknet marketplaces... for reasons like this one. It's no deeper than that.
😁3😈1
🔪 Slice For Life - Part 2 🔪
🚨‼️ Liquid Network was drained of approximately 4,000 BTC, worth around $320 million, over the past several hours. The hackers left the following on-chain message: “we are whitehats. contact us on chain” Blockstream responded on-chain with: “Please contact…
X (formerly Twitter)
Liquid Network 🌊 (@Liquid_BTC) on X
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on con…
🚨 🇺🇸 Initial Access: US Software Company
A threat actor is advertising access to an unnamed U.S. software company reportedly generating $450M in revenue.
The advertised access includes GitHub, CI/CD infrastructure, a Snyk key, and a Databricks token. Payment is requested in XMR.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A threat actor is advertising access to an unnamed U.S. software company reportedly generating $450M in revenue.
The advertised access includes GitHub, CI/CD infrastructure, a Snyk key, and a Databricks token. Payment is requested in XMR.
This claim is currently unverified.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ ShinyHunters claims a Swiss medical technology company
🇨🇭 Medela - A Swiss medical technology company specializing in breast pumps, breastfeeding products, and healthcare solutions for mothers, infants, and hospitals.
The listing includes a September 8, 2026 deadline, but does not specify the claimed data volume or types of information compromised.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
🇨🇭 Medela - A Swiss medical technology company specializing in breast pumps, breastfeeding products, and healthcare solutions for mothers, infants, and hospitals.
The listing includes a September 8, 2026 deadline, but does not specify the claimed data volume or types of information compromised.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
OSINTsearch is a live data search engine that helps individuals, investigators, and security teams explore social profiles and available breach exposure data from supported sources and third-party providers.
Link: https://osintsearch.org
Credit: @weezerOSINT (X)
Link: https://osintsearch.org
Credit: @weezerOSINT (X)
🚨🇧🇷 Claro Brasil allegedly breached, 46M+ phone numbers linked to CPF claimed
⠀
Claro Brasil, one of Brazil’s largest telecommunications providers, is named in a cybercrime forum post where a threat actor claims to have compromised an exposed API and extracted 46,033,380 telephone numbers linked to Brazilian CPF identifiers.
⠀
Claimed exposure
⠀
• 46,033,380 phone numbers
• CPF identifiers linked to telephone numbers
• Historical records reportedly dating from 2004 to early 2026
• Approximately 2 million records released as proof of concept
• 6.1 GB dataset
• Database provided in .DB format
⠀
The actor claims Claro has approximately 90.8 million existing phone numbers in Brazil, but says only slightly more than half could be extracted before the activity was detected.
⠀
The actor also claims the 2 million-record proof of concept contains phone numbers linked to CPF data, with some records dating through 2019.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Claro Brasil, one of Brazil’s largest telecommunications providers, is named in a cybercrime forum post where a threat actor claims to have compromised an exposed API and extracted 46,033,380 telephone numbers linked to Brazilian CPF identifiers.
⠀
Claimed exposure
⠀
• 46,033,380 phone numbers
• CPF identifiers linked to telephone numbers
• Historical records reportedly dating from 2004 to early 2026
• Approximately 2 million records released as proof of concept
• 6.1 GB dataset
• Database provided in .DB format
⠀
The actor claims Claro has approximately 90.8 million existing phone numbers in Brazil, but says only slightly more than half could be extracted before the activity was detected.
⠀
The actor also claims the 2 million-record proof of concept contains phone numbers linked to CPF data, with some records dating through 2019.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇦🇷 Hospital Alemán and OSDEPYM allegedly breached, sensitive medical and customer data leaked
⠀
Hospital Alemán and OSDEPYM, two Argentine healthcare organizations, are named in a cybercrime forum post where a threat actor claims negotiations failed and data belonging to both organizations is now being released.
⠀
Hospital Alemán claimed exposure
⠀
• Approximately 84,000 prescription records
• Patient names and dates of birth
• DNI identification numbers
• Medical coverage information
• Diagnoses and treatment details
• Prescription and medication information
• Physician and electronic prescription data
⠀
The actor published a sample containing highly sensitive medical information and claims the prescription data was converted into CSV format for release.
⠀
OSDEPYM claimed exposure
⠀
• Approximately 7,000 customer records
• Names and dates of birth
• DNI and affiliate identifiers
• Email addresses and phone numbers
• Residential addresses
• Health plan and coverage information
• Account and registration-related data
⠀
Samples of the allegedly exposed OSDEPYM customer data were also published in the forum post.
⠀
The breach claims, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Hospital Alemán and OSDEPYM, two Argentine healthcare organizations, are named in a cybercrime forum post where a threat actor claims negotiations failed and data belonging to both organizations is now being released.
⠀
Hospital Alemán claimed exposure
⠀
• Approximately 84,000 prescription records
• Patient names and dates of birth
• DNI identification numbers
• Medical coverage information
• Diagnoses and treatment details
• Prescription and medication information
• Physician and electronic prescription data
⠀
The actor published a sample containing highly sensitive medical information and claims the prescription data was converted into CSV format for release.
⠀
OSDEPYM claimed exposure
⠀
• Approximately 7,000 customer records
• Names and dates of birth
• DNI and affiliate identifiers
• Email addresses and phone numbers
• Residential addresses
• Health plan and coverage information
• Account and registration-related data
⠀
Samples of the allegedly exposed OSDEPYM customer data were also published in the forum post.
⠀
The breach claims, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Malone Lam is expected to plead guilty tomorrow in connection with the $263 million social engineering heist.
Lam had been scheduled for a “status hearing,” which was later changed to a “change of plea hearing,” indicating he is expected to enter a guilty plea.
He is one of 18 people charged in connection with the case.
Lam had been scheduled for a “status hearing,” which was later changed to a “change of plea hearing,” indicating he is expected to enter a guilty plea.
He is one of 18 people charged in connection with the case.
😭2
🔪 Slice For Life - Part 2 🔪
Malone Lam is expected to plead guilty tomorrow in connection with the $263 million social engineering heist. Lam had been scheduled for a “status hearing,” which was later changed to a “change of plea hearing,” indicating he is expected to enter a guilty…
Source: https://apnews.com/article/cryptocurrency-scam-malone-lam-guilty-3d40f81fd3ba0b5e28d6b962ca6b343d
AP News
Party's over for crypto scammers who went on a spending spree after a $240 million bitcoin theft
A 22-year-old man from Singapore is expected to plead guilty this week in Washington to orchestrating one of the largest cryptocurrency thefts in U.S. history, duping a stranger out of bitcoin worth over $240 million.
🚨🇲🇽 Root access to Mega Gas allegedly offered for sale on a cybercrime forum
⠀
Mega Gasolineras, S.A. de C.V. (Mega Gas), a Mexican fuel retailer and gas station operator, is named in a cybercrime forum post where a threat actor claims to be selling root-level access to its infrastructure.
⠀
Advertised access
⠀
• Root access
• Approximately 1.9 TB of data
• Access tied to Mega Gas infrastructure
• Asking price: $450
⠀
The seller claims the company generates approximately $122.9 million in annual revenue and employs between 501 and 1,000 people.
⠀
The access claim, data volume and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Mega Gasolineras, S.A. de C.V. (Mega Gas), a Mexican fuel retailer and gas station operator, is named in a cybercrime forum post where a threat actor claims to be selling root-level access to its infrastructure.
⠀
Advertised access
⠀
• Root access
• Approximately 1.9 TB of data
• Access tied to Mega Gas infrastructure
• Asking price: $450
⠀
The seller claims the company generates approximately $122.9 million in annual revenue and employs between 501 and 1,000 people.
⠀
The access claim, data volume and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: Admin Access to a Dubai Car Marketplace Advertised With Seller Data
Link: https://darkwebinformer.com/admin-access-to-a-dubai-car-marketplace-advertised-with-seller-data/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Admin Access to a Dubai Car Marketplace Advertised With Seller Data
Link: https://darkwebinformer.com/admin-access-to-a-dubai-car-marketplace-advertised-with-seller-data/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Admin Access to a Dubai Car Marketplace Advertised With Seller Data
A forum actor posting as Keishell, crediting two others, claims to have gained access to the administrative panel of ryxcars.com, a luxury vehicle marketplace based in Dubai.