πͺ That Dark Web Guy - Part 3 πͺ
π¨ ALERT: A third-party email provider used by Trezor was breached and used to send a phishing email titled βCritical Security Alert: STM32 Entropy Vulnerability.β The message is not legitimate, and recipients should not click any links. The affected domainβ¦
X (formerly Twitter)
BitBox (@BitBoxSwiss) on X
Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised.
Multiple oβ¦
Multiple oβ¦
πͺ That Dark Web Guy - Part 3 πͺ
BitBox is also experiencing the same issue. https://x.com/BitBoxSwiss/status/2097793026336981079
Here is the phishing email in regards to Trezor.
π¨π¨π΄ Optic Networks administrative access and customer dataset allegedly compromised
β
Optic Networks S.A.S. is a Colombian internet service provider operating primarily in Santa Marta, providing connectivity and telecommunications services to residential and business customers.
β
Actors identifying themselves as ZentinelTeam, including Keishell and noname8173, claim to have obtained administrative access to the providerβs management systems, giving them the ability to view customer and network information and modify service settings.
β
Claimed exposed data includes:
β
β’ Customer names
β’ National / government ID numbers
β’ Mobile phone numbers
β’ Email addresses
β’ Home and service addresses
β’ Geographic and location information
β’ IP addresses
β’ PPP/Hotspot usernames
β’ Internet service plans
β’ Account status
β’ Payment dates
β’ Current debt and balances
β’ Amounts due and next payment dates
β’ Service types and customer IDs
β
The actors also claim they intend to disrupt the providerβs internet service and leak its customer dataset. Screenshots were published as purported proof of access to customer records and network-management systems.
β
The intrusion claim, level of administrative access, and full scope of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Optic Networks S.A.S. is a Colombian internet service provider operating primarily in Santa Marta, providing connectivity and telecommunications services to residential and business customers.
β
Actors identifying themselves as ZentinelTeam, including Keishell and noname8173, claim to have obtained administrative access to the providerβs management systems, giving them the ability to view customer and network information and modify service settings.
β
Claimed exposed data includes:
β
β’ Customer names
β’ National / government ID numbers
β’ Mobile phone numbers
β’ Email addresses
β’ Home and service addresses
β’ Geographic and location information
β’ IP addresses
β’ PPP/Hotspot usernames
β’ Internet service plans
β’ Account status
β’ Payment dates
β’ Current debt and balances
β’ Amounts due and next payment dates
β’ Service types and customer IDs
β
The actors also claim they intend to disrupt the providerβs internet service and leak its customer dataset. Screenshots were published as purported proof of access to customer records and network-management systems.
β
The intrusion claim, level of administrative access, and full scope of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΉπ Alizune database and source code allegedly leaked on a cybercrime forum
β
Alizune is a Thailand-based online marketplace selling digital accounts and other products.
β
Actors identifying themselves as ZentinelTeam, including Keishell and noname8173, claim to have obtained and leaked the platformβs database and website source code.
β
Claimed exposed data includes:
β
β’ Usernames and email addresses
β’ Phone numbers
β’ Password hashes
β’ Authentication and remember tokens
β’ Account and subscription information
β’ Customer addresses
β’ Customer GPS coordinates
β’ Customer notes
β’ Outstanding balances and amounts owed
β’ Supplier names, phone numbers, and addresses
β’ Transaction amounts
β’ Income and expense records
β’ Sales and purchase information
β’ Invoice numbers and references
β’ Payment-related information
β’ Admin account email and password hash
β’ Google Maps API key
β’ Payment account and mobile numbers
β’ System configuration and business settings
β
The actors published screenshots showing what they claim are database records and access to the websiteβs source-code files as proof of the intrusion.
β
The breach claim and full scope of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
β
Alizune is a Thailand-based online marketplace selling digital accounts and other products.
β
Actors identifying themselves as ZentinelTeam, including Keishell and noname8173, claim to have obtained and leaked the platformβs database and website source code.
β
Claimed exposed data includes:
β
β’ Usernames and email addresses
β’ Phone numbers
β’ Password hashes
β’ Authentication and remember tokens
β’ Account and subscription information
β’ Customer addresses
β’ Customer GPS coordinates
β’ Customer notes
β’ Outstanding balances and amounts owed
β’ Supplier names, phone numbers, and addresses
β’ Transaction amounts
β’ Income and expense records
β’ Sales and purchase information
β’ Invoice numbers and references
β’ Payment-related information
β’ Admin account email and password hash
β’ Google Maps API key
β’ Payment account and mobile numbers
β’ System configuration and business settings
β
The actors published screenshots showing what they claim are database records and access to the websiteβs source-code files as proof of the intrusion.
β
The breach claim and full scope of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
π¨πΈπ¦ Saudi Arabia Ministry of Education database containing 600K records allegedly offered on a cybercrime forum
β
The Ministry of Education of Saudi Arabia is the government authority responsible for overseeing the countryβs public education system, schools, universities, and education-sector personnel.
β
A cybercrime forum actor using the handle saotome claims to be selling a Ministry of Education dataset containing approximately 600,000 records, with a sample reportedly containing information associated with Hail.
β
Claimed exposed data includes:
β
β’ Civil registry IDs
β’ Ministry identification numbers
β’ Full names
β’ Nationality and nationality codes
β’ Residency information
β’ Dates of birth and ages
β’ Email addresses
β’ Mobile numbers
β’ Job titles and employment types
β’ Current workplace information
β’ Employee status
β’ Education regions
β’ School names and Noor school IDs
β’ Assigned classes
β’ University information
β’ Qualifications and majors
β’ GPA and graduation information
β’ Ministry employment start dates
β’ Years of service
β
The actor is asking $300 in cryptocurrency for the purported dataset and published a CSV sample as proof of the claim.
β
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
The Ministry of Education of Saudi Arabia is the government authority responsible for overseeing the countryβs public education system, schools, universities, and education-sector personnel.
β
A cybercrime forum actor using the handle saotome claims to be selling a Ministry of Education dataset containing approximately 600,000 records, with a sample reportedly containing information associated with Hail.
β
Claimed exposed data includes:
β
β’ Civil registry IDs
β’ Ministry identification numbers
β’ Full names
β’ Nationality and nationality codes
β’ Residency information
β’ Dates of birth and ages
β’ Email addresses
β’ Mobile numbers
β’ Job titles and employment types
β’ Current workplace information
β’ Employee status
β’ Education regions
β’ School names and Noor school IDs
β’ Assigned classes
β’ University information
β’ Qualifications and majors
β’ GPA and graduation information
β’ Ministry employment start dates
β’ Years of service
β
The actor is asking $300 in cryptocurrency for the purported dataset and published a CSV sample as proof of the claim.
β
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Good thread if you just want to read and understand.
"How does law enforcement (in this case, the BKA)muse DoS attacks to deanonymize marketplaces?"
Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/76fa6c805d7aca2ca3a9/?context=e903ed28c6c3961df1#c-c40688d965ebe87ec0
"How does law enforcement (in this case, the BKA)muse DoS attacks to deanonymize marketplaces?"
Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/76fa6c805d7aca2ca3a9/?context=e903ed28c6c3961df1#c-c40688d965ebe87ec0
π¨π¨π³ China Housing Provident Fund dataset containing 280M records allegedly offered on a cybercrime forum
β
Chinaβs Housing Provident Fund is a mandatory housing savings system funded through employee and employer contributions, used to support housing purchases and related expenses.
β
A cybercrime forum actor using the handle feijo claims to be selling a dataset associated with the system containing approximately 280 million records.
β
Claimed exposed data includes:
β
β’ Names and identification numbers
β’ Gender and dates of birth
β’ Ages and mobile numbers
β’ Registration provinces
β’ Fund provinces and cities
β’ Employer information
β’ Account status
β’ Contribution bases
β’ Employee and employer contribution amounts
β’ Contribution ratios
β’ Monthly contribution totals
β’ Account balances
β’ Account opening dates
β’ Latest contribution dates
β
The actor is asking $450 for the purported dataset and published sample records as proof of the claim.
β
The source, record count, and authenticity of the dataset have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Chinaβs Housing Provident Fund is a mandatory housing savings system funded through employee and employer contributions, used to support housing purchases and related expenses.
β
A cybercrime forum actor using the handle feijo claims to be selling a dataset associated with the system containing approximately 280 million records.
β
Claimed exposed data includes:
β
β’ Names and identification numbers
β’ Gender and dates of birth
β’ Ages and mobile numbers
β’ Registration provinces
β’ Fund provinces and cities
β’ Employer information
β’ Account status
β’ Contribution bases
β’ Employee and employer contribution amounts
β’ Contribution ratios
β’ Monthly contribution totals
β’ Account balances
β’ Account opening dates
β’ Latest contribution dates
β
The actor is asking $450 for the purported dataset and published sample records as proof of the claim.
β
The source, record count, and authenticity of the dataset have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯1
π¨ TerraMaster pre-auth RCE 0-day exploit allegedly offered on a cybercrime forum
β
TerraMaster is a network-attached storage (NAS) vendor that develops storage appliances and operating systems for home, business, and enterprise environments.
β
A cybercrime forum actor using the handle LazaKNOXGroup claims to be selling an exclusive, unpatched pre-authentication remote code execution exploit affecting TerraMaster systems.
β
Claimed exploit details include:
β
β’ Affects TerraMaster V4 and V5
β’ Pre-authentication RCE
β’ Claimed code execution as root
β’ Described as a logical vulnerability
β’ Actor claims 100% reliability in testing
β’ Single-buyer exclusivity
β’ Full rights reportedly transferred to the buyer
β
The actor states that Deal Over Escrow is accepted and is marketing the exploit as an exclusive sale.
β
The vulnerability, affected versions, exploit reliability, and 0-day status have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
TerraMaster is a network-attached storage (NAS) vendor that develops storage appliances and operating systems for home, business, and enterprise environments.
β
A cybercrime forum actor using the handle LazaKNOXGroup claims to be selling an exclusive, unpatched pre-authentication remote code execution exploit affecting TerraMaster systems.
β
Claimed exploit details include:
β
β’ Affects TerraMaster V4 and V5
β’ Pre-authentication RCE
β’ Claimed code execution as root
β’ Described as a logical vulnerability
β’ Actor claims 100% reliability in testing
β’ Single-buyer exclusivity
β’ Full rights reportedly transferred to the buyer
β
The actor states that Deal Over Escrow is accepted and is marketing the exploit as an exclusive sale.
β
The vulnerability, affected versions, exploit reliability, and 0-day status have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π§π· FUSVE and Medgrupo confidential data allegedly offered on a cybercrime forum
Hi Jack!
β
Medgrupo is a Brazilian medical education company, while FUSVE operates educational and healthcare institutions in Rio de Janeiro state, including Vassouras University Hospital.
β
A cybercrime forum actor using the handle jackswastedlife claims to possess hundreds of thousands of sensitive and financial records associated with Medgrupo clients and students, along with 70,963 PDF medical imaging reports tied to patients of Vassouras University Hospital.
β
Claimed exposed data includes:
β
β’ Client and student financial records
β’ Patient names
β’ Patient ages
β’ Referring physician information
β’ Medical imaging reports
β’ Examination dates
β’ Clinical indications
β’ Other sensitive medical information
β
The actor also published several files as purported samples and is directing interested parties to contact them through Tox or email.
β
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Hi Jack!
β
Medgrupo is a Brazilian medical education company, while FUSVE operates educational and healthcare institutions in Rio de Janeiro state, including Vassouras University Hospital.
β
A cybercrime forum actor using the handle jackswastedlife claims to possess hundreds of thousands of sensitive and financial records associated with Medgrupo clients and students, along with 70,963 PDF medical imaging reports tied to patients of Vassouras University Hospital.
β
Claimed exposed data includes:
β
β’ Client and student financial records
β’ Patient names
β’ Patient ages
β’ Referring physician information
β’ Medical imaging reports
β’ Examination dates
β’ Clinical indications
β’ Other sensitive medical information
β
The actor also published several files as purported samples and is directing interested parties to contact them through Tox or email.
β
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ A threat actor claims to be selling a Remote Code Execution (RCE) and Blind SQL Injection vulnerability affecting an undisclosed Moroccan government university website.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π2
βΌοΈ New Dark Web Informer Blog Post!
Title: PT Betiri Cipta Media Core Database Access Offered for $25K
Link: https://darkwebinformer.com/pt-betiri-cipta-media-core-database-access-offered-for-25k/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: PT Betiri Cipta Media Core Database Access Offered for $25K
Link: https://darkwebinformer.com/pt-betiri-cipta-media-core-database-access-offered-for-25k/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
PT Betiri Cipta Media Core Database Access Offered for $25K
A forum actor posting as TheTrueWorldCreator is offering what they claim is full access to the core money database of PT Betiri Cipta Media, an Indonesian aggregator and distributor of digital goods operating as a PPOB business.
βΌοΈπΉπ An actor on a forum is offering webmail access allegedly belonging to Police Thailand, claiming it provides access to law enforcement portals and the ability to retrieve documents and legal information about individuals.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
βΌοΈπ¦π· A seller is offering root-level database access to an unnamed Argentine university for $200 in XMR/BTC, claiming the database includes user records with emails, passwords, full names, city, and state information.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
π¨πΊπΈ Phoenix woman pleads guilty to running dark web drug operation
Brejea Wrigley, 30, pleaded guilty to two federal counts of distributing methamphetamine after prosecutors say she took over the dark web vendor account βBlackCoconutβ in August 2025.
β
The operation offered methamphetamine, fentanyl marketed as βChina White,β pressed oxycodone pills, and mushrooms, with drugs shipped to customers nationwide through USPS.
β
Undercover investigators placed two orders that were shipped from Phoenix to a law enforcement-controlled P.O. Box in New Hampshire.
The shipments contained nearly 450 grams and more than 800 grams of methamphetamine.
β
Investigators later identified Wrigley as the person operating the account following additional investigation and search warrants.
β
She faces up to life in federal prison, at least five years of supervised release, and a fine of up to $10 million.
Sentencing is scheduled for December 17.
Source: https://www.azfamily.com/2026/09/09/phoenix-woman-who-sold-meth-dark-web-could-face-up-life-prison/
Brejea Wrigley, 30, pleaded guilty to two federal counts of distributing methamphetamine after prosecutors say she took over the dark web vendor account βBlackCoconutβ in August 2025.
β
The operation offered methamphetamine, fentanyl marketed as βChina White,β pressed oxycodone pills, and mushrooms, with drugs shipped to customers nationwide through USPS.
β
Undercover investigators placed two orders that were shipped from Phoenix to a law enforcement-controlled P.O. Box in New Hampshire.
The shipments contained nearly 450 grams and more than 800 grams of methamphetamine.
β
Investigators later identified Wrigley as the person operating the account following additional investigation and search warrants.
β
She faces up to life in federal prison, at least five years of supervised release, and a fine of up to $10 million.
Sentencing is scheduled for December 17.
Source: https://www.azfamily.com/2026/09/09/phoenix-woman-who-sold-meth-dark-web-could-face-up-life-prison/
βΌοΈ New Dark Web Informer Blog Post!
Title: FairMoney Dataset Claim Covers ~335,505 User Accounts
Link: https://darkwebinformer.com/fairmoney-dataset-claim-covers-335-505-user-accounts/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: FairMoney Dataset Claim Covers ~335,505 User Accounts
Link: https://darkwebinformer.com/fairmoney-dataset-claim-covers-335-505-user-accounts/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
FairMoney Dataset Claim Covers ~335,505 User Accounts
A forum actor posting as GoreTerminal has released what they claim is a filtered dataset belonging to FairMoney, a licensed digital bank in Nigeria that provides personal loans and mobile financial services.
βΌοΈπΊπΈπΊπΈπΊπΈπ¨π¦ Cl0p Ransomware claims and leaks 4 victims
πΊπΈ Harley-Davidson - A U.S.-based motorcycle manufacturer known for heavyweight motorcycles, parts, accessories, apparel, and related financial services.
πΊπΈ Henry Pratt Company - A U.S.-based manufacturer of valves and flow-control products used in water, wastewater, power, and industrial infrastructure.
πΊπΈ GE - A U.S.-based industrial and aerospace company with major operations in aircraft engines, aviation systems, and related technologies.
π¨π¦ ALDO Group - A Canadian footwear and accessories company operating the ALDO brand and other retail businesses internationally.
πΊπΈ Harley-Davidson - A U.S.-based motorcycle manufacturer known for heavyweight motorcycles, parts, accessories, apparel, and related financial services.
πΊπΈ Henry Pratt Company - A U.S.-based manufacturer of valves and flow-control products used in water, wastewater, power, and industrial infrastructure.
πΊπΈ GE - A U.S.-based industrial and aerospace company with major operations in aircraft engines, aviation systems, and related technologies.
π¨π¦ ALDO Group - A Canadian footwear and accessories company operating the ALDO brand and other retail businesses internationally.