π¨πΈπ¦ Saudi Arabia Ministry of Education database containing 600K records allegedly offered on a cybercrime forum
β
The Ministry of Education of Saudi Arabia is the government authority responsible for overseeing the countryβs public education system, schools, universities, and education-sector personnel.
β
A cybercrime forum actor using the handle saotome claims to be selling a Ministry of Education dataset containing approximately 600,000 records, with a sample reportedly containing information associated with Hail.
β
Claimed exposed data includes:
β
β’ Civil registry IDs
β’ Ministry identification numbers
β’ Full names
β’ Nationality and nationality codes
β’ Residency information
β’ Dates of birth and ages
β’ Email addresses
β’ Mobile numbers
β’ Job titles and employment types
β’ Current workplace information
β’ Employee status
β’ Education regions
β’ School names and Noor school IDs
β’ Assigned classes
β’ University information
β’ Qualifications and majors
β’ GPA and graduation information
β’ Ministry employment start dates
β’ Years of service
β
The actor is asking $300 in cryptocurrency for the purported dataset and published a CSV sample as proof of the claim.
β
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
The Ministry of Education of Saudi Arabia is the government authority responsible for overseeing the countryβs public education system, schools, universities, and education-sector personnel.
β
A cybercrime forum actor using the handle saotome claims to be selling a Ministry of Education dataset containing approximately 600,000 records, with a sample reportedly containing information associated with Hail.
β
Claimed exposed data includes:
β
β’ Civil registry IDs
β’ Ministry identification numbers
β’ Full names
β’ Nationality and nationality codes
β’ Residency information
β’ Dates of birth and ages
β’ Email addresses
β’ Mobile numbers
β’ Job titles and employment types
β’ Current workplace information
β’ Employee status
β’ Education regions
β’ School names and Noor school IDs
β’ Assigned classes
β’ University information
β’ Qualifications and majors
β’ GPA and graduation information
β’ Ministry employment start dates
β’ Years of service
β
The actor is asking $300 in cryptocurrency for the purported dataset and published a CSV sample as proof of the claim.
β
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Good thread if you just want to read and understand.
"How does law enforcement (in this case, the BKA)muse DoS attacks to deanonymize marketplaces?"
Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/76fa6c805d7aca2ca3a9/?context=e903ed28c6c3961df1#c-c40688d965ebe87ec0
"How does law enforcement (in this case, the BKA)muse DoS attacks to deanonymize marketplaces?"
Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/76fa6c805d7aca2ca3a9/?context=e903ed28c6c3961df1#c-c40688d965ebe87ec0
π¨π¨π³ China Housing Provident Fund dataset containing 280M records allegedly offered on a cybercrime forum
β
Chinaβs Housing Provident Fund is a mandatory housing savings system funded through employee and employer contributions, used to support housing purchases and related expenses.
β
A cybercrime forum actor using the handle feijo claims to be selling a dataset associated with the system containing approximately 280 million records.
β
Claimed exposed data includes:
β
β’ Names and identification numbers
β’ Gender and dates of birth
β’ Ages and mobile numbers
β’ Registration provinces
β’ Fund provinces and cities
β’ Employer information
β’ Account status
β’ Contribution bases
β’ Employee and employer contribution amounts
β’ Contribution ratios
β’ Monthly contribution totals
β’ Account balances
β’ Account opening dates
β’ Latest contribution dates
β
The actor is asking $450 for the purported dataset and published sample records as proof of the claim.
β
The source, record count, and authenticity of the dataset have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Chinaβs Housing Provident Fund is a mandatory housing savings system funded through employee and employer contributions, used to support housing purchases and related expenses.
β
A cybercrime forum actor using the handle feijo claims to be selling a dataset associated with the system containing approximately 280 million records.
β
Claimed exposed data includes:
β
β’ Names and identification numbers
β’ Gender and dates of birth
β’ Ages and mobile numbers
β’ Registration provinces
β’ Fund provinces and cities
β’ Employer information
β’ Account status
β’ Contribution bases
β’ Employee and employer contribution amounts
β’ Contribution ratios
β’ Monthly contribution totals
β’ Account balances
β’ Account opening dates
β’ Latest contribution dates
β
The actor is asking $450 for the purported dataset and published sample records as proof of the claim.
β
The source, record count, and authenticity of the dataset have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯1
π¨ TerraMaster pre-auth RCE 0-day exploit allegedly offered on a cybercrime forum
β
TerraMaster is a network-attached storage (NAS) vendor that develops storage appliances and operating systems for home, business, and enterprise environments.
β
A cybercrime forum actor using the handle LazaKNOXGroup claims to be selling an exclusive, unpatched pre-authentication remote code execution exploit affecting TerraMaster systems.
β
Claimed exploit details include:
β
β’ Affects TerraMaster V4 and V5
β’ Pre-authentication RCE
β’ Claimed code execution as root
β’ Described as a logical vulnerability
β’ Actor claims 100% reliability in testing
β’ Single-buyer exclusivity
β’ Full rights reportedly transferred to the buyer
β
The actor states that Deal Over Escrow is accepted and is marketing the exploit as an exclusive sale.
β
The vulnerability, affected versions, exploit reliability, and 0-day status have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
TerraMaster is a network-attached storage (NAS) vendor that develops storage appliances and operating systems for home, business, and enterprise environments.
β
A cybercrime forum actor using the handle LazaKNOXGroup claims to be selling an exclusive, unpatched pre-authentication remote code execution exploit affecting TerraMaster systems.
β
Claimed exploit details include:
β
β’ Affects TerraMaster V4 and V5
β’ Pre-authentication RCE
β’ Claimed code execution as root
β’ Described as a logical vulnerability
β’ Actor claims 100% reliability in testing
β’ Single-buyer exclusivity
β’ Full rights reportedly transferred to the buyer
β
The actor states that Deal Over Escrow is accepted and is marketing the exploit as an exclusive sale.
β
The vulnerability, affected versions, exploit reliability, and 0-day status have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π§π· FUSVE and Medgrupo confidential data allegedly offered on a cybercrime forum
Hi Jack!
β
Medgrupo is a Brazilian medical education company, while FUSVE operates educational and healthcare institutions in Rio de Janeiro state, including Vassouras University Hospital.
β
A cybercrime forum actor using the handle jackswastedlife claims to possess hundreds of thousands of sensitive and financial records associated with Medgrupo clients and students, along with 70,963 PDF medical imaging reports tied to patients of Vassouras University Hospital.
β
Claimed exposed data includes:
β
β’ Client and student financial records
β’ Patient names
β’ Patient ages
β’ Referring physician information
β’ Medical imaging reports
β’ Examination dates
β’ Clinical indications
β’ Other sensitive medical information
β
The actor also published several files as purported samples and is directing interested parties to contact them through Tox or email.
β
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Hi Jack!
β
Medgrupo is a Brazilian medical education company, while FUSVE operates educational and healthcare institutions in Rio de Janeiro state, including Vassouras University Hospital.
β
A cybercrime forum actor using the handle jackswastedlife claims to possess hundreds of thousands of sensitive and financial records associated with Medgrupo clients and students, along with 70,963 PDF medical imaging reports tied to patients of Vassouras University Hospital.
β
Claimed exposed data includes:
β
β’ Client and student financial records
β’ Patient names
β’ Patient ages
β’ Referring physician information
β’ Medical imaging reports
β’ Examination dates
β’ Clinical indications
β’ Other sensitive medical information
β
The actor also published several files as purported samples and is directing interested parties to contact them through Tox or email.
β
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ A threat actor claims to be selling a Remote Code Execution (RCE) and Blind SQL Injection vulnerability affecting an undisclosed Moroccan government university website.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π2
βΌοΈ New Dark Web Informer Blog Post!
Title: PT Betiri Cipta Media Core Database Access Offered for $25K
Link: https://darkwebinformer.com/pt-betiri-cipta-media-core-database-access-offered-for-25k/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: PT Betiri Cipta Media Core Database Access Offered for $25K
Link: https://darkwebinformer.com/pt-betiri-cipta-media-core-database-access-offered-for-25k/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
PT Betiri Cipta Media Core Database Access Offered for $25K
A forum actor posting as TheTrueWorldCreator is offering what they claim is full access to the core money database of PT Betiri Cipta Media, an Indonesian aggregator and distributor of digital goods operating as a PPOB business.
βΌοΈπΉπ An actor on a forum is offering webmail access allegedly belonging to Police Thailand, claiming it provides access to law enforcement portals and the ability to retrieve documents and legal information about individuals.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
βΌοΈπ¦π· A seller is offering root-level database access to an unnamed Argentine university for $200 in XMR/BTC, claiming the database includes user records with emails, passwords, full names, city, and state information.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
π¨πΊπΈ Phoenix woman pleads guilty to running dark web drug operation
Brejea Wrigley, 30, pleaded guilty to two federal counts of distributing methamphetamine after prosecutors say she took over the dark web vendor account βBlackCoconutβ in August 2025.
β
The operation offered methamphetamine, fentanyl marketed as βChina White,β pressed oxycodone pills, and mushrooms, with drugs shipped to customers nationwide through USPS.
β
Undercover investigators placed two orders that were shipped from Phoenix to a law enforcement-controlled P.O. Box in New Hampshire.
The shipments contained nearly 450 grams and more than 800 grams of methamphetamine.
β
Investigators later identified Wrigley as the person operating the account following additional investigation and search warrants.
β
She faces up to life in federal prison, at least five years of supervised release, and a fine of up to $10 million.
Sentencing is scheduled for December 17.
Source: https://www.azfamily.com/2026/09/09/phoenix-woman-who-sold-meth-dark-web-could-face-up-life-prison/
Brejea Wrigley, 30, pleaded guilty to two federal counts of distributing methamphetamine after prosecutors say she took over the dark web vendor account βBlackCoconutβ in August 2025.
β
The operation offered methamphetamine, fentanyl marketed as βChina White,β pressed oxycodone pills, and mushrooms, with drugs shipped to customers nationwide through USPS.
β
Undercover investigators placed two orders that were shipped from Phoenix to a law enforcement-controlled P.O. Box in New Hampshire.
The shipments contained nearly 450 grams and more than 800 grams of methamphetamine.
β
Investigators later identified Wrigley as the person operating the account following additional investigation and search warrants.
β
She faces up to life in federal prison, at least five years of supervised release, and a fine of up to $10 million.
Sentencing is scheduled for December 17.
Source: https://www.azfamily.com/2026/09/09/phoenix-woman-who-sold-meth-dark-web-could-face-up-life-prison/
βΌοΈ New Dark Web Informer Blog Post!
Title: FairMoney Dataset Claim Covers ~335,505 User Accounts
Link: https://darkwebinformer.com/fairmoney-dataset-claim-covers-335-505-user-accounts/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: FairMoney Dataset Claim Covers ~335,505 User Accounts
Link: https://darkwebinformer.com/fairmoney-dataset-claim-covers-335-505-user-accounts/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
FairMoney Dataset Claim Covers ~335,505 User Accounts
A forum actor posting as GoreTerminal has released what they claim is a filtered dataset belonging to FairMoney, a licensed digital bank in Nigeria that provides personal loans and mobile financial services.
βΌοΈπΊπΈπΊπΈπΊπΈπ¨π¦ Cl0p Ransomware claims and leaks 4 victims
πΊπΈ Harley-Davidson - A U.S.-based motorcycle manufacturer known for heavyweight motorcycles, parts, accessories, apparel, and related financial services.
πΊπΈ Henry Pratt Company - A U.S.-based manufacturer of valves and flow-control products used in water, wastewater, power, and industrial infrastructure.
πΊπΈ GE - A U.S.-based industrial and aerospace company with major operations in aircraft engines, aviation systems, and related technologies.
π¨π¦ ALDO Group - A Canadian footwear and accessories company operating the ALDO brand and other retail businesses internationally.
πΊπΈ Harley-Davidson - A U.S.-based motorcycle manufacturer known for heavyweight motorcycles, parts, accessories, apparel, and related financial services.
πΊπΈ Henry Pratt Company - A U.S.-based manufacturer of valves and flow-control products used in water, wastewater, power, and industrial infrastructure.
πΊπΈ GE - A U.S.-based industrial and aerospace company with major operations in aircraft engines, aviation systems, and related technologies.
π¨π¦ ALDO Group - A Canadian footwear and accessories company operating the ALDO brand and other retail businesses internationally.
Media is too big
VIEW IN TELEGRAM
Another good banger.
KSHMR - House Of Cards (feat. Sidnie Tipton)
KSHMR - House Of Cards (feat. Sidnie Tipton)
π₯1
Forwarded from Dark Web Informer - Private
βΌοΈ DOJ Press Release
βββββββββββββββββββββ
Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware
Full Press Release β justice.gov
βββββββββββββββββββββ
π΅οΈ Dark Web Informer β’ DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
βββββββββββββββββββββ
Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware
Full Press Release β justice.gov
βββββββββββββββββββββ
π΅οΈ Dark Web Informer β’ DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
Department of Justice
Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware
Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000β¦
β€1
βΌοΈπΊπΈπ΅π Rhysida Ransomware claims a retail services company and a hospital
πΊπΈ Professional Retail Services - A U.S.-based retail services company providing facilities maintenance, construction, project management, and related support for commercial and retail clients.
The listing claims employee evaluations, salary and bonus information, job offers, family documents, client credit reports, bankruptcy and tax records, medical records, corporate financial documents, tax returns, credit applications, signed checks, corporate credit card information, drug tests, and employee health insurance data. The dataset is being offered for 8 BTC.
π΅π General Santos Doctors Hospital - A Philippine hospital providing medical, surgical, diagnostic, and specialist healthcare services.
The listing claims approximately 3.5 million files totaling 2.44 TB, including patient PHI, pathology and hemodialysis records, admission records, cancer-treatment files, laboratory data, PhilHealth information, neonatal/NICU data, physician records, payroll workbooks, HR files, passport scans, drug-test records, audited financial statements, banking information, internal audit documents, payroll batches, and leadership contact information. The dataset is being offered for 8 BTC.
πΊπΈ Professional Retail Services - A U.S.-based retail services company providing facilities maintenance, construction, project management, and related support for commercial and retail clients.
The listing claims employee evaluations, salary and bonus information, job offers, family documents, client credit reports, bankruptcy and tax records, medical records, corporate financial documents, tax returns, credit applications, signed checks, corporate credit card information, drug tests, and employee health insurance data. The dataset is being offered for 8 BTC.
π΅π General Santos Doctors Hospital - A Philippine hospital providing medical, surgical, diagnostic, and specialist healthcare services.
The listing claims approximately 3.5 million files totaling 2.44 TB, including patient PHI, pathology and hemodialysis records, admission records, cancer-treatment files, laboratory data, PhilHealth information, neonatal/NICU data, physician records, payroll workbooks, HR files, passport scans, drug-test records, audited financial statements, banking information, internal audit documents, payroll batches, and leadership contact information. The dataset is being offered for 8 BTC.
Media is too big
VIEW IN TELEGRAM
The Dark Webβs New Deadliest Drug
These are Nitazenes. Nitazenes are a highly potent and still relatively little-known class of synthetic opioids that are increasingly making their way into Europeβs illicit drug supply.
Video Credit: youtube.com/@fern-tv
These are Nitazenes. Nitazenes are a highly potent and still relatively little-known class of synthetic opioids that are increasingly making their way into Europeβs illicit drug supply.
Video Credit: youtube.com/@fern-tv
βΌοΈπΊπΈπ RansomHouse Ransomware claims California School Employees Association (CSEA)
πΊπΈ California School Employees Association (CSEA) - A California-based labor organization representing classified public school employees and advocating for employee rights, benefits, and public education.
The listing claims the organizationβs systems were encrypted on August 21, 2026 and references 35 evidence items, with the actor threatening to leak confidential data, project documents, and other internal information.
πΊπΈ California School Employees Association (CSEA) - A California-based labor organization representing classified public school employees and advocating for employee rights, benefits, and public education.
The listing claims the organizationβs systems were encrypted on August 21, 2026 and references 35 evidence items, with the actor threatening to leak confidential data, project documents, and other internal information.
π¨ Surfshark discloses security incident after internal test server was exposed to the internet
Surfshark says human error resulted in an internal engineering test server being misconfigured and publicly reachable, allowing an unauthorized third party to gain access.
β
The exposed environment contained limited internal engineering material, including parts of system binaries and configurations for certain services. Some build-related credentials had also previously been committed to the companyβs code history.
β
Surfshark says:
β’ No customer data was accessed
β’ No VPN traffic or browsing activity was exposed
β’ No production systems were compromised
β’ No encryption keys or user IP addresses were accessible
β’ Apps and browser extensions were not altered
β
Access was also gained to an isolated content accessibility optimization server, but Surfshark says it had no access to user identities, browsing traffic, encryption keys, or IP addresses.
β
The first suspicious activity was detected on August 31. The incident was confirmed and contained on September 2, with additional remediation completed by September 5.
β
Surfshark rotated or retired potentially affected internal credentials and says it found no malicious activity in the available access logs.
The company is now strengthening security around test environments and plans to conduct an additional independent security audit.
Source: https://surfshark.com/blog/security-update-september-2026-incident-report
Surfshark says human error resulted in an internal engineering test server being misconfigured and publicly reachable, allowing an unauthorized third party to gain access.
β
The exposed environment contained limited internal engineering material, including parts of system binaries and configurations for certain services. Some build-related credentials had also previously been committed to the companyβs code history.
β
Surfshark says:
β’ No customer data was accessed
β’ No VPN traffic or browsing activity was exposed
β’ No production systems were compromised
β’ No encryption keys or user IP addresses were accessible
β’ Apps and browser extensions were not altered
β
Access was also gained to an isolated content accessibility optimization server, but Surfshark says it had no access to user identities, browsing traffic, encryption keys, or IP addresses.
β
The first suspicious activity was detected on August 31. The incident was confirmed and contained on September 2, with additional remediation completed by September 5.
β
Surfshark rotated or retired potentially affected internal credentials and says it found no malicious activity in the available access logs.
The company is now strengthening security around test environments and plans to conduct an additional independent security audit.
Source: https://surfshark.com/blog/security-update-september-2026-incident-report