🚨🇲🇽 Root access to Mega Gas allegedly offered for sale on a cybercrime forum
⠀
Mega Gasolineras, S.A. de C.V. (Mega Gas), a Mexican fuel retailer and gas station operator, is named in a cybercrime forum post where a threat actor claims to be selling root-level access to its infrastructure.
⠀
Advertised access
⠀
• Root access
• Approximately 1.9 TB of data
• Access tied to Mega Gas infrastructure
• Asking price: $450
⠀
The seller claims the company generates approximately $122.9 million in annual revenue and employs between 501 and 1,000 people.
⠀
The access claim, data volume and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Mega Gasolineras, S.A. de C.V. (Mega Gas), a Mexican fuel retailer and gas station operator, is named in a cybercrime forum post where a threat actor claims to be selling root-level access to its infrastructure.
⠀
Advertised access
⠀
• Root access
• Approximately 1.9 TB of data
• Access tied to Mega Gas infrastructure
• Asking price: $450
⠀
The seller claims the company generates approximately $122.9 million in annual revenue and employs between 501 and 1,000 people.
⠀
The access claim, data volume and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: Admin Access to a Dubai Car Marketplace Advertised With Seller Data
Link: https://darkwebinformer.com/admin-access-to-a-dubai-car-marketplace-advertised-with-seller-data/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Admin Access to a Dubai Car Marketplace Advertised With Seller Data
Link: https://darkwebinformer.com/admin-access-to-a-dubai-car-marketplace-advertised-with-seller-data/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Admin Access to a Dubai Car Marketplace Advertised With Seller Data
A forum actor posting as Keishell, crediting two others, claims to have gained access to the administrative panel of ryxcars.com, a luxury vehicle marketplace based in Dubai.
‼️ New Dark Web Informer Blog Post!
Title: Jinko Patient Records Published With Diagnoses and Private Messages
Link: https://darkwebinformer.com/jinko-patient-records-published-with-diagnoses-and-private-messages/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Jinko Patient Records Published With Diagnoses and Private Messages
Link: https://darkwebinformer.com/jinko-patient-records-published-with-diagnoses-and-private-messages/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Jinko Patient Records Published With Diagnoses and Private Messages
A forum actor posting as DaOnlySpark has published 3.7 GB attributed to Jinko, a French cancer care support platform.
🚨🇧🇷 Municipality of Rincão allegedly compromised, administrative access claimed
⠀
Prefeitura Municipal de Rincão, the municipal government of Rincão in São Paulo, Brazil, is named in a cybercrime forum post where a threat actor claims to have compromised multiple administrative accounts and gained access to internal government systems.
⠀
Claimed access
⠀
• Government administrative accounts
• Full administrator access
• Municipal CRM access
• User management capabilities
• Government email accounts
• Confidential documents
• Access to a Strapi administrative dashboard
⠀
The actor claims they were able to identify and disable website categories and render portions of the municipal website inoperable.
⠀
Screenshots published in the forum post appear to show access to a Strapi administration panel containing municipal user accounts, email addresses, roles and account status information.
⠀
The access claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Prefeitura Municipal de Rincão, the municipal government of Rincão in São Paulo, Brazil, is named in a cybercrime forum post where a threat actor claims to have compromised multiple administrative accounts and gained access to internal government systems.
⠀
Claimed access
⠀
• Government administrative accounts
• Full administrator access
• Municipal CRM access
• User management capabilities
• Government email accounts
• Confidential documents
• Access to a Strapi administrative dashboard
⠀
The actor claims they were able to identify and disable website categories and render portions of the municipal website inoperable.
⠀
Screenshots published in the forum post appear to show access to a Strapi administration panel containing municipal user accounts, email addresses, roles and account status information.
⠀
The access claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: MSM Unify Extorted for 400,000 Dollars Over Student Passport and Visa Files
Link: https://darkwebinformer.com/msm-unify-extorted-for-400-000-dollars-over-student-passport-and-visa-files/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: MSM Unify Extorted for 400,000 Dollars Over Student Passport and Visa Files
Link: https://darkwebinformer.com/msm-unify-extorted-for-400-000-dollars-over-student-passport-and-visa-files/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
MSM Unify Extorted for 400,000 Dollars Over Student Passport and Visa Files
A forum actor posting as Kazu claims to hold 1.45 TB taken from MSM Unify, a Canadian education technology platform that helps students apply to universities abroad.
🔪 Slice For Life - Part 2 🔪
⚠️ A lot of talk on Dread about Dark Matter still being down and jokes on a possible exit scam. My private link is working fine. See response header date/time with the market loaded.
⚠️ Dark Matter has provided an update to it's downtime. Stay vigilant.
Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/3a4526d61445e3539680
There is also now a mega thread to keep everything in one place.
Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/62c85b0b9ee1a3030427
Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/3a4526d61445e3539680
There is also now a mega thread to keep everything in one place.
Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/62c85b0b9ee1a3030427
🚨 ExEngine AV/EDR killer advertised on a cybercrime forum, Ring-3 rootkit and UAC bypass claimed
⠀
ExEngine, a malware tool advertised as an AV/EDR killer for Windows systems, is being promoted on a cybercrime forum with claims that it can disable mainstream consumer antivirus products and allow additional payloads to execute with reduced interference.
⠀
Advertised capabilities
⠀
• AV/EDR termination
• UAC bypass for privilege escalation
• Ring-3 rootkit functionality
• Process, file and registry hiding
• Network connection concealment
• Discord webhook logging
• Persistence across reboots and logouts
• Anti-VM and anti-debug features
• Support for Windows 10 and 11
• Secondary decoy payload support
⠀
The seller specifically claims compatibility against products including Windows Defender, Malwarebytes, Bitdefender and Avast, while stating support for additional antivirus software.
⠀
ExEngine is advertised at $750 per month or $2,500 per year.
⠀
The functionality, effectiveness and compatibility claims have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
⠀
ExEngine, a malware tool advertised as an AV/EDR killer for Windows systems, is being promoted on a cybercrime forum with claims that it can disable mainstream consumer antivirus products and allow additional payloads to execute with reduced interference.
⠀
Advertised capabilities
⠀
• AV/EDR termination
• UAC bypass for privilege escalation
• Ring-3 rootkit functionality
• Process, file and registry hiding
• Network connection concealment
• Discord webhook logging
• Persistence across reboots and logouts
• Anti-VM and anti-debug features
• Support for Windows 10 and 11
• Secondary decoy payload support
⠀
The seller specifically claims compatibility against products including Windows Defender, Malwarebytes, Bitdefender and Avast, while stating support for additional antivirus software.
⠀
ExEngine is advertised at $750 per month or $2,500 per year.
⠀
The functionality, effectiveness and compatibility claims have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
🔥1😁1
‼️🇳🇱 Opsporing Verzocht will play the voice of a vishing suspect in the Odido hack case during its broadcast on Monday, September 7, at 9:15 p.m. on NPO 2. Police hope this will lead to tips about the suspect or encourage the suspect to come forward.
Source: https://www.politie.nl/nieuws/2026/september/7/11-stem-van-verdachte-odido-hack-te-horen-in-opsporing-verzocht.html
Source: https://www.politie.nl/nieuws/2026/september/7/11-stem-van-verdachte-odido-hack-te-horen-in-opsporing-verzocht.html
www.politie.nl
Stem van verdachte Odido-hack te horen in Opsporing Verzocht
Opsporing Verzocht laat in de uitzending van maandag 7 september (21:15 uur op NPO2) de stem van een verdachte in de zaak van de Odido-hack horen. Hiermee hoopt de politie tips over de verdachte te krijgen of dat de verdachte zichzelf meldt.
🔪 Slice For Life - Part 2 🔪
🚨‼️ Liquid Network was drained of approximately 4,000 BTC, worth around $320 million, over the past several hours. The hackers left the following on-chain message: “we are whitehats. contact us on chain” Blockstream responded on-chain with: “Please contact…
‼️The Liquid hackers return 3,400 BTC and kept $47M as a bounty.
😭3❤1
🚨🇻🇪 Venezuela’s Ministry of People’s Power for Culture allegedly breached, 26K+ confidential photos claimed
⠀
Ministerio del Poder Popular para la Cultura, Venezuela’s government ministry responsible for cultural policy and programs, is named in a cybercrime forum post where a threat actor claims to have obtained a collection of 26,360 confidential photographs.
⠀
Claimed exposure
⠀
• 26,360 photographs
• Approximately 4.7 GB of data
• Images provided in JPG format
• Large collection of individual portrait photographs
• Records allegedly sourced from ministry systems
⠀
The actor published a preview showing numerous individual portrait images and claims the complete collection contains more than 26,000 files.
⠀
A sample download is also advertised in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Ministerio del Poder Popular para la Cultura, Venezuela’s government ministry responsible for cultural policy and programs, is named in a cybercrime forum post where a threat actor claims to have obtained a collection of 26,360 confidential photographs.
⠀
Claimed exposure
⠀
• 26,360 photographs
• Approximately 4.7 GB of data
• Images provided in JPG format
• Large collection of individual portrait photographs
• Records allegedly sourced from ministry systems
⠀
The actor published a preview showing numerous individual portrait images and claims the complete collection contains more than 26,000 files.
⠀
A sample download is also advertised in the forum post.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 FitLab allegedly breached, data tied to 700K customers and 1.2M orders claimed
⠀
FitLab, a U.S. fitness and sports lifestyle company that operates a network of health, wellness and athletic brands, is named in a cybercrime forum post where a threat actor claims a third-party business intelligence platform was compromised using a zero-day vulnerability, providing access to FitLab data.
⠀
Claimed exposure
⠀
• 700,000 customer records
• 1.2 million order records
• 75,000 participant records
• Names and email addresses
• Phone numbers
• Billing and shipping addresses
• Order and transaction information
• Payment and fulfillment metadata
• Customer and brand identifiers
• Event, race and booking information
• Participant and team details
⠀
The actor claims the compromise occurred in August 2026 and resulted in access to multiple FitLab datasets containing customer, order and event participation information.
⠀
Samples of the allegedly exposed database structures were published in the forum post, with a download also advertised.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
FitLab, a U.S. fitness and sports lifestyle company that operates a network of health, wellness and athletic brands, is named in a cybercrime forum post where a threat actor claims a third-party business intelligence platform was compromised using a zero-day vulnerability, providing access to FitLab data.
⠀
Claimed exposure
⠀
• 700,000 customer records
• 1.2 million order records
• 75,000 participant records
• Names and email addresses
• Phone numbers
• Billing and shipping addresses
• Order and transaction information
• Payment and fulfillment metadata
• Customer and brand identifiers
• Event, race and booking information
• Participant and team details
⠀
The actor claims the compromise occurred in August 2026 and resulted in access to multiple FitLab datasets containing customer, order and event participation information.
⠀
Samples of the allegedly exposed database structures were published in the forum post, with a download also advertised.
⠀
The breach claim, exposed data and scope have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
‼️ Dark Project is now offering a RaaS affiliate program
Dark Web: http://darkprn3d3udnhpuxknsrhft3376lrz5tenhgkrxge5hxqe46pkbrwid[.]onion
Dark Web: http://darkprn3d3udnhpuxknsrhft3376lrz5tenhgkrxge5hxqe46pkbrwid[.]onion