Dark Web Informer - Private
Cybersecurity Incident Disclosure Tue, 8 Sep 2026 16:29:11 EDT A cybersecurity incident has been disclosed by Veradigm Inc., Inc CIK: 0001124804, Ticker: (https://www.google.com/search?q=%24None+ticker). View SEC Filing
X (formerly Twitter)
Dark Web Informer (@DarkWebInformer) on X
๐จ VERADIGM INC. has filed form 8-K due to a Cybersecurity incident
Incident: https://t.co/1W9ukJsvyq
"Veradigm Inc. (the โCompanyโ) recently learned that one of its third-party vendors experienโฆ
Incident: https://t.co/1W9ukJsvyq
"Veradigm Inc. (the โCompanyโ) recently learned that one of its third-party vendors experienโฆ
Forwarded from Dark Web Informer - Private
โผ๏ธ DOJ Press Release
โโโโโโโโโโโโโโโโโโโโโ
Texas Couple Sentenced for Operating Website Selling Smuggled Pesticides and Veterinary Drugs
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
โโโโโโโโโโโโโโโโโโโโโ
Texas Couple Sentenced for Operating Website Selling Smuggled Pesticides and Veterinary Drugs
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
Department of Justice
Texas Couple Sentenced for Operating Website Selling Smuggled Pesticides and Veterinary Drugs
Thao Duong and Lam Mai, a wife and husband from Garland, Texas, were sentenced today in federal court to charges stemming from their operation of a website selling veterinary drugs and pesticides smuggled into the United State from Mexico. Duong was sentencedโฆ
๐จ๐บ๐ธ 2.7M-user dataset from U.S. social marketplace allegedly offered on a cybercrime forum
โ
The listing describes the source as a U.S.-based social marketplace/network, though the specific platform is not identified in the post.
โ
A threat actor using the handle KrebsonFanAccount claims to be selling a private dataset containing approximately 2.7 million users and published a sample of the purported records.
โ
Claimed data includes:
โ
โข User IDs and usernames
โข Password hashes
โข Email addresses
โข Display names
โข Account registration dates
โข User URLs
โข Account status information
โข Activation keys
โข Spam/deletion status fields
โ
The actor states the passwords use portable PHP password hashing and published a 1,000-record sample as proof of the claim.
โ
The claim, source of the dataset, and total number of affected records have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
The listing describes the source as a U.S.-based social marketplace/network, though the specific platform is not identified in the post.
โ
A threat actor using the handle KrebsonFanAccount claims to be selling a private dataset containing approximately 2.7 million users and published a sample of the purported records.
โ
Claimed data includes:
โ
โข User IDs and usernames
โข Password hashes
โข Email addresses
โข Display names
โข Account registration dates
โข User URLs
โข Account status information
โข Activation keys
โข Spam/deletion status fields
โ
The actor states the passwords use portable PHP password hashing and published a 1,000-record sample as proof of the claim.
โ
The claim, source of the dataset, and total number of affected records have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐1
๐จ๐ง๐ท IME Events dataset containing 502K records allegedly offered on a cybercrime forum
โ
IME Events is a Brazilian online platform used to organize and host online events and scientific congresses.
โ
A threat actor using the handle Sorb claims to be selling the platformโs full dataset in CSV format, containing approximately 502,000 records of personal information.
โ
Claimed data includes:
โ
โข 498,000 unique email addresses
โข 456,000 unique phone numbers
โข 451,000 unique document numbers
โข Full names
โข bcrypt password hashes
โข 16,000 unique CPF/CNPJ numbers
โข 10,000 dates of birth
โข 17,000 addresses
โ
The actor is asking $500 for the dataset, states that escrow is accepted, and claims it will be sold exclusively to a single buyer. A sample was also published.
โ
The claim and full scope of the exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
โ
IME Events is a Brazilian online platform used to organize and host online events and scientific congresses.
โ
A threat actor using the handle Sorb claims to be selling the platformโs full dataset in CSV format, containing approximately 502,000 records of personal information.
โ
Claimed data includes:
โ
โข 498,000 unique email addresses
โข 456,000 unique phone numbers
โข 451,000 unique document numbers
โข Full names
โข bcrypt password hashes
โข 16,000 unique CPF/CNPJ numbers
โข 10,000 dates of birth
โข 17,000 addresses
โ
The actor is asking $500 for the dataset, states that escrow is accepted, and claims it will be sold exclusively to a single buyer. A sample was also published.
โ
The claim and full scope of the exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
๐จ๐ง๐ท Medgrupo and FUSVE patient data allegedly leaked and offered on a cybercrime forum
โ
Medgrupo is a Brazilian medical education company, while FUSVE operates educational and healthcare institutions in Rio de Janeiro state, including Vassouras University Hospital.
โ
A threat actor using the handle jacksenseofrejection claims to possess hundreds of thousands of sensitive and financial records associated with Medgrupo clients and students, along with 70,963 PDF medical imaging reports involving patients of Vassouras University Hospital.
โ
Claimed exposed data includes:
โ
โข Client and student financial records
โข Patient names
โข Patient ages
โข Referring physician information
โข Medical imaging reports
โข Examination dates
โข Clinical indications
โข Other sensitive medical information
โ
The actor published samples and is asking approximately 1.25 BTC for the purported data, with an offer deadline of September 15, 2026.
โ
The breach claim, origin of the data, and full scope of the exposure have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
โ
Medgrupo is a Brazilian medical education company, while FUSVE operates educational and healthcare institutions in Rio de Janeiro state, including Vassouras University Hospital.
โ
A threat actor using the handle jacksenseofrejection claims to possess hundreds of thousands of sensitive and financial records associated with Medgrupo clients and students, along with 70,963 PDF medical imaging reports involving patients of Vassouras University Hospital.
โ
Claimed exposed data includes:
โ
โข Client and student financial records
โข Patient names
โข Patient ages
โข Referring physician information
โข Medical imaging reports
โข Examination dates
โข Clinical indications
โข Other sensitive medical information
โ
The actor published samples and is asking approximately 1.25 BTC for the purported data, with an offer deadline of September 15, 2026.
โ
The breach claim, origin of the data, and full scope of the exposure have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
๐จ๐ฎ๐ฉ City of Balikpapan SIMPATDA database allegedly breached
โ
Balikpapan is a major city in East Kalimantan, Indonesia, whose municipal government manages local public services, taxation, and regional administration.
โ
A cybercrime forum actor using the handle vicmeow claims to have breached a SIMPATDA database, a system associated with managing local government revenue and taxation data.
โ
Claimed exposed data includes:
โ
โข Resident and taxpayer information
โข Tax identification and payment records
โข Names and addresses
โข Billing and payment status
โข Tax periods and due dates
โข Property and land-related records
โข Administrative and operator information
โข Multiple database backups and internal tables
โ
The actor claims the leak contains tax information for residents of Balikpapan and published a downloadable archive along with sample database records.
โ
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
Balikpapan is a major city in East Kalimantan, Indonesia, whose municipal government manages local public services, taxation, and regional administration.
โ
A cybercrime forum actor using the handle vicmeow claims to have breached a SIMPATDA database, a system associated with managing local government revenue and taxation data.
โ
Claimed exposed data includes:
โ
โข Resident and taxpayer information
โข Tax identification and payment records
โข Names and addresses
โข Billing and payment status
โข Tax periods and due dates
โข Property and land-related records
โข Administrative and operator information
โข Multiple database backups and internal tables
โ
The actor claims the leak contains tax information for residents of Balikpapan and published a downloadable archive along with sample database records.
โ
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐จ๐ด Santiago de Cali municipal government dataset containing 600K+ records allegedly leaked
โ
The Alcaldรญa de Santiago de Cali is the municipal government of Cali, Colombia, responsible for local administration, public services, taxation, and city finances.
โ
A cybercrime forum actor using the handle arcepah claims to have obtained a dataset associated with the municipality containing more than 600,000 records and over 60 GB of data from 2024 through 2026.
โ
Claimed data includes:
โ
โข Tax and public-finance records
โข Business and taxpayer names
โข NIT tax identification numbers
โข Addresses
โข Phone numbers
โข Email addresses
โข Tax declaration and filing periods
โข Withholding tax information
โข ICA municipal tax records
โข Taxable amounts and withholding totals
โข Penalties and interest information
โ
The published sample appears to contain records associated with the municipalityโs public finance and tax management operations.
โ
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
The Alcaldรญa de Santiago de Cali is the municipal government of Cali, Colombia, responsible for local administration, public services, taxation, and city finances.
โ
A cybercrime forum actor using the handle arcepah claims to have obtained a dataset associated with the municipality containing more than 600,000 records and over 60 GB of data from 2024 through 2026.
โ
Claimed data includes:
โ
โข Tax and public-finance records
โข Business and taxpayer names
โข NIT tax identification numbers
โข Addresses
โข Phone numbers
โข Email addresses
โข Tax declaration and filing periods
โข Withholding tax information
โข ICA municipal tax records
โข Taxable amounts and withholding totals
โข Penalties and interest information
โ
The published sample appears to contain records associated with the municipalityโs public finance and tax management operations.
โ
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Media is too big
VIEW IN TELEGRAM
Cyberattacks, data encryption, extortion - How cybercriminals operate
Video Credit: youtube.com/@DWDocumentary
Video Credit: youtube.com/@DWDocumentary
โผ๏ธ New Dark Web Informer Blog Post!
Title: Blossom Health Records on 29,600 Mental Health Patients Offered for Sale
Link: https://darkwebinformer.com/blossom-health-records-on-29-600-mental-health-patients-offered-for-sale/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Blossom Health Records on 29,600 Mental Health Patients Offered for Sale
Link: https://darkwebinformer.com/blossom-health-records-on-29-600-mental-health-patients-offered-for-sale/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Blossom Health Records on 29,600 Mental Health Patients Offered for Sale
A forum actor posting as 2019 is selling what they describe as the patient database of Blossom Health, a virtual psychiatric care platform in the United States that provides online therapy and medication management for conditions including anxiety, depressionโฆ
Tor VPN beta is now available on Android ๐
Blog: https://blog.torproject.org/tor-vpn-beta/
Download: https://download.torproject.org/
Blog: https://blog.torproject.org/tor-vpn-beta/
Download: https://download.torproject.org/
blog.torproject.org
Tor VPN Beta: What we've learned building our own VPN for Android from scratch | Tor Project
Last fall, we soft-launched Tor VPN Beta as a way to extend Tor's privacy protections beyond the browser to an entire Android device. Since then, we've been able to learn from how people are actually using it in real-world scenarios. This post walks throughโฆ
๐ฅ2
๐จ๐ซ๐ท Cyberattack disrupts municipal services in Le Tampon, Rรฉunion
The City of Le Tampon says it was hit by a cyberattack Wednesday morning that is causing major disruption across several municipal services.
The municipality says employees are currently unable to carry out some services under normal operating conditions.
Technical teams are working to gradually restore affected systems and services.
The city says it will provide additional information once reliable details become available.
Source: https://www.linfo.re/la-reunion/societe/le-tampon-la-mairie-victime-d-une-cyber-attaque-les-services-municipaux-au-ralenti
The City of Le Tampon says it was hit by a cyberattack Wednesday morning that is causing major disruption across several municipal services.
The municipality says employees are currently unable to carry out some services under normal operating conditions.
Technical teams are working to gradually restore affected systems and services.
The city says it will provide additional information once reliable details become available.
Source: https://www.linfo.re/la-reunion/societe/le-tampon-la-mairie-victime-d-une-cyber-attaque-les-services-municipaux-au-ralenti
๐จ๐บ๐ธ Severe cyberattack shuts down Springfield Public Schools for second day
Springfield Public Schools in Massachusetts says an outside group gained access to its network and blocked access to systems required to operate the district.
One of the affected systems contains vital student medical records. School nurses currently cannot access information needed to dispense medication, check allergies, and address other health issues.
Officials classified the attack as a districtwide Level 4 severe cyber incident.
Schools were closed Tuesday and Wednesday and will not reopen until nurses can safely access the medical information they need.
Other affected systems include transportation and food-related information, while the district is also unable to use its normal email systems. Students and staff have been instructed to stay off SPS networks and district-issued devices.
The FBI, Massachusetts State Police, and local authorities are assisting.
Officials have not yet confirmed whether student or staff data was stolen, whether ransomware was deployed, or who is responsible.
Source: https://www.wwlp.com/news/crime/springfield-schools-closed-as-cyberattack-locks-access-to-student-medical-records/
Springfield Public Schools in Massachusetts says an outside group gained access to its network and blocked access to systems required to operate the district.
One of the affected systems contains vital student medical records. School nurses currently cannot access information needed to dispense medication, check allergies, and address other health issues.
Officials classified the attack as a districtwide Level 4 severe cyber incident.
Schools were closed Tuesday and Wednesday and will not reopen until nurses can safely access the medical information they need.
Other affected systems include transportation and food-related information, while the district is also unable to use its normal email systems. Students and staff have been instructed to stay off SPS networks and district-issued devices.
The FBI, Massachusetts State Police, and local authorities are assisting.
Officials have not yet confirmed whether student or staff data was stolen, whether ransomware was deployed, or who is responsible.
Source: https://www.wwlp.com/news/crime/springfield-schools-closed-as-cyberattack-locks-access-to-student-medical-records/
๐1
๐จ๐บ๐ธ Iran-linked hackers claim responsibility for major Texas AT&T outage. AT&T says it didn't.
APT IRAN, a group closely linked to the IRGC-affiliated CyberAv3ngers, claims it targeted telecommunications infrastructure and an unidentified water utility in Texas.
โ
The claim followed a widespread AT&T outage on September 7 that generated thousands of reports across Houston, Spring, Dallas, Fort Worth, and Austin.
AT&T acknowledged a major fiber outage affecting more than 7,000 families.
โ
However, AT&T disputes the hackersโ claim.
The company says it has found no evidence the outage resulted from a cyberattack and that its assessment indicates attempted cable theft caused the disruption.
โ
APT IRAN previously threatened โcritical eventsโ targeting U.S. telecommunications, energy, and water infrastructure and has claimed involvement in recent attacks against U.S. water systems.
โ
AT&T says service has been restored and its network continues to be monitored.
Source: https://www.yahoo.com/news/us/articles/iranian-hackers-claim-credit-massive-181942480.html
APT IRAN, a group closely linked to the IRGC-affiliated CyberAv3ngers, claims it targeted telecommunications infrastructure and an unidentified water utility in Texas.
โ
The claim followed a widespread AT&T outage on September 7 that generated thousands of reports across Houston, Spring, Dallas, Fort Worth, and Austin.
AT&T acknowledged a major fiber outage affecting more than 7,000 families.
โ
However, AT&T disputes the hackersโ claim.
The company says it has found no evidence the outage resulted from a cyberattack and that its assessment indicates attempted cable theft caused the disruption.
โ
APT IRAN previously threatened โcritical eventsโ targeting U.S. telecommunications, energy, and water infrastructure and has claimed involvement in recent attacks against U.S. water systems.
โ
AT&T says service has been restored and its network continues to be monitored.
Source: https://www.yahoo.com/news/us/articles/iranian-hackers-claim-credit-massive-181942480.html
๐1
โผ๏ธ New Dark Web Informer Blog Post!
Title: AdvaCare Dataset Claimed on Forum, 20,734 Timesheet Entries and 39 Staff Accounts
Link: https://darkwebinformer.com/advacare-dataset-claimed-on-forum-20-734-timesheet-entries-and-39-staff-accounts/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: AdvaCare Dataset Claimed on Forum, 20,734 Timesheet Entries and 39 Staff Accounts
Link: https://darkwebinformer.com/advacare-dataset-claimed-on-forum-20-734-timesheet-entries-and-39-staff-accounts/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
AdvaCare Dataset Claimed on Forum, 20,734 Timesheet Entries and 39 Staff Accounts
A forum actor posting as DaOnlySpark has published what they describe as a small dump of data belonging to AdvaCare, a Swiss healthcare consultancy focused on long-term care and nursing.
๐จ๐ฎ๐ฉ Wibuku dataset containing 200K registered users allegedly leaked on a cybercrime forum
โ
Wibuku is an Indonesian digital platform and mobile app focused on anime, manga, light novels, and Japanese pop culture content.
โ
A cybercrime forum actor using the handle L3yn claims to have leaked a dataset containing approximately 200,000 registered Wibuku users and published a sample of the purported records.
โ
Claimed data includes:
โ
โข User IDs
โข Gmail addresses
โข Registered account information
โ
The published sample shows user IDs paired with email addresses, while additional information.
โ
The breach claim, record count, and full scope of the exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
Wibuku is an Indonesian digital platform and mobile app focused on anime, manga, light novels, and Japanese pop culture content.
โ
A cybercrime forum actor using the handle L3yn claims to have leaked a dataset containing approximately 200,000 registered Wibuku users and published a sample of the purported records.
โ
Claimed data includes:
โ
โข User IDs
โข Gmail addresses
โข Registered account information
โ
The published sample shows user IDs paired with email addresses, while additional information.
โ
The breach claim, record count, and full scope of the exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Malware... don't download unless you want malware.
https://github.com/dead-partaker2244/GTA-6-Social-Club-Bypass-No-Account
https://github.com/dead-partaker2244/GTA-6-Social-Club-Bypass-No-Account
GitHub
GitHub - dead-partaker2244/GTA-6-Social-Club-Bypass-No-Account: Bypass GTA 6 Social Club login and play without an account, noโฆ
Bypass GTA 6 Social Club login and play without an account, no installation required, Windows 10/11. - dead-partaker2244/GTA-6-Social-Club-Bypass-No-Account
๐ญ2
โผ๏ธ LAPSUS$ Group has a new PGP signed message. Chapter II first victim is set to release in 3 days.
IOC: lapsus[.]ar[.]io
"When we completed our first operations, we demonstrated the triviality of modern enterprise defense systems. To TeamPCP, we send our sincere gratitude: your sacrifice provided us with the exact coverage we needed. We owe you all our gratitude for falling and taking on the acts of our cooperation. Retirement was only a temporary diversion born of pure boredom. Yet, driven by our enduring passion for the craft, we return not out of necessity, but to reclaim our dominance and for the love of the game. Our primary goal today is explicit: to openly challenge the FBI and the federal apparatus, proving once and for all that we operate completely above the law on this network. Corporate violations, corporate extortion and the generation of countless millions of dollars will continue unhindered, without any risk to ourselves, completely free. Prepare your incident response units and alert your federal managers. The clock is active."
IOC: lapsus[.]ar[.]io
"When we completed our first operations, we demonstrated the triviality of modern enterprise defense systems. To TeamPCP, we send our sincere gratitude: your sacrifice provided us with the exact coverage we needed. We owe you all our gratitude for falling and taking on the acts of our cooperation. Retirement was only a temporary diversion born of pure boredom. Yet, driven by our enduring passion for the craft, we return not out of necessity, but to reclaim our dominance and for the love of the game. Our primary goal today is explicit: to openly challenge the FBI and the federal apparatus, proving once and for all that we operate completely above the law on this network. Corporate violations, corporate extortion and the generation of countless millions of dollars will continue unhindered, without any risk to ourselves, completely free. Prepare your incident response units and alert your federal managers. The clock is active."
โค2๐ฅ1
๐ช That Dark Web Guy - Part 3 ๐ช
โผ๏ธ LAPSUS$ Group has a new PGP signed message. Chapter II first victim is set to release in 3 days. IOC: lapsus[.]ar[.]io "When we completed our first operations, we demonstrated the triviality of modern enterprise defense systems. To TeamPCP, we send ourโฆ
LAPSUS$ Group name sale: https://core.metaplex.com/explorer/9HVcBG572WENSB6uTMB2geYQxMVWS1Z6C6fNsbW6oagx