πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.97K subscribers
1.23K photos
68 videos
1.09K links
Download Telegram
β€ΌοΈπŸ‡ΊπŸ‡ΈπŸ‡΅πŸ‡­ Rhysida Ransomware claims a retail services company and a hospital

πŸ‡ΊπŸ‡Έ Professional Retail Services - A U.S.-based retail services company providing facilities maintenance, construction, project management, and related support for commercial and retail clients.

The listing claims employee evaluations, salary and bonus information, job offers, family documents, client credit reports, bankruptcy and tax records, medical records, corporate financial documents, tax returns, credit applications, signed checks, corporate credit card information, drug tests, and employee health insurance data. The dataset is being offered for 8 BTC.

πŸ‡΅πŸ‡­ General Santos Doctors Hospital - A Philippine hospital providing medical, surgical, diagnostic, and specialist healthcare services.

The listing claims approximately 3.5 million files totaling 2.44 TB, including patient PHI, pathology and hemodialysis records, admission records, cancer-treatment files, laboratory data, PhilHealth information, neonatal/NICU data, physician records, payroll workbooks, HR files, passport scans, drug-test records, audited financial statements, banking information, internal audit documents, payroll batches, and leadership contact information. The dataset is being offered for 8 BTC.
Media is too big
VIEW IN TELEGRAM
The Dark Web’s New Deadliest Drug

These are Nitazenes. Nitazenes are a highly potent and still relatively little-known class of synthetic opioids that are increasingly making their way into Europe’s illicit drug supply.

Video Credit: youtube.com/@fern-tv
β€ΌοΈπŸ‡ΊπŸ‡ΈπŸ”’ RansomHouse Ransomware claims California School Employees Association (CSEA)

πŸ‡ΊπŸ‡Έ California School Employees Association (CSEA) - A California-based labor organization representing classified public school employees and advocating for employee rights, benefits, and public education.

The listing claims the organization’s systems were encrypted on August 21, 2026 and references 35 evidence items, with the actor threatening to leak confidential data, project documents, and other internal information.
🚨 Surfshark discloses security incident after internal test server was exposed to the internet

Surfshark says human error resulted in an internal engineering test server being misconfigured and publicly reachable, allowing an unauthorized third party to gain access.
β €
The exposed environment contained limited internal engineering material, including parts of system binaries and configurations for certain services. Some build-related credentials had also previously been committed to the company’s code history.
β €
Surfshark says:

β€’ No customer data was accessed
β€’ No VPN traffic or browsing activity was exposed
β€’ No production systems were compromised
β€’ No encryption keys or user IP addresses were accessible
β€’ Apps and browser extensions were not altered
β €
Access was also gained to an isolated content accessibility optimization server, but Surfshark says it had no access to user identities, browsing traffic, encryption keys, or IP addresses.
β €
The first suspicious activity was detected on August 31. The incident was confirmed and contained on September 2, with additional remediation completed by September 5.
β €
Surfshark rotated or retired potentially affected internal credentials and says it found no malicious activity in the available access logs.

The company is now strengthening security around test environments and plans to conduct an additional independent security audit.

Source: https://surfshark.com/blog/security-update-september-2026-incident-report
Hot take, imagine SH releasing a dataset tomorrow related to NYπŸ‡ΊπŸ‡Έ licenses. It's a hot take chat.
πŸ”₯3
‼️ CVE-2026-11387: A critical improper-authentication flaw in the WordPress plugin SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery.

GitHub: https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP
πŸš¨πŸ‡ΉπŸ‡· Threat actor seeks partner after claiming access to a Turkish company’s SMTP credentials
β €
The targeted organization is described only as a medium-sized Turkish company, with its name and industry not disclosed in the forum post.
β €
An actor claims to possess the company’s SMTP credentials and is seeking a partner to help operationalize the access.
β €
The actor claims experience obtaining access through:
β €
β€’ RDP
β€’ Fortinet infrastructure
β€’ VPN services
β€’ Other remote-access environments
β €
The actor states that developing or configuring command-and-control infrastructure to evade detection is outside their area of expertise and says they are looking for someone to work with.
β €
The access claim, affected company, and validity of the credentials have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Gotta love the real talk on Dread every once and awhile.
❀5πŸ”₯1
πŸš¨πŸ‡«πŸ‡· WiziShop and Dropizi dataset containing 511K+ records allegedly leaked on a cybercrime forum
β €
WiziShop and Dropizi are French e-commerce platforms that help businesses create and manage online stores, with Dropizi focused on dropshipping.
β €
A cybercrime forum actor using the handle ChimeraZ claims to have leaked a dataset associated with stores operating through WiziShop and Dropizi, containing 511,661 records across 21,402 stores.
β €
Claimed exposed data includes:
β €
β€’ Invoice IDs and numbers
β€’ Supplier information
β€’ Customer identifiers
β€’ Store names
β€’ Billing and delivery addresses
β€’ Cities and postal information
β€’ Countries
β€’ Transaction and invoice dates
β€’ Other store and order-related records
β €
The actor states the dataset is approximately 127 MB in JSON format and published multiple download mirrors along with a sample of the purported data.
β €
The source, record count, and authenticity of the dataset have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡°πŸ‡Ό Jazeera Airways partial dataset containing 54K+ individuals allegedly leaked
β €
Jazeera Airways is a Kuwait-based low-cost airline serving destinations across the Middle East, Asia, Europe, and Africa.
β €
A forum actor using the handle ChimeraZ claims to have leaked a partial Jazeera Airways dataset containing information tied to 54,375 people, with approximately 154,310 lines of data.
β €
Claimed exposed data includes:
β €
β€’ Customer names
β€’ Email addresses
β€’ Mobile numbers
β€’ Insurance policy information
β€’ Policy and insurance certificate numbers
β€’ Coverage levels
β€’ Policy issue, start, and end dates
β€’ Insurer information
β€’ Premium amounts
β€’ Benefit schedules
β€’ Policy notes
β€’ Travel agency invoices
β€’ Invoice and payment-related information
β €
The actor states the leak is approximately 400 MB in JSON and PDF formats and includes 3,711 agency invoices totaling around 335 MB, along with tens of thousands of policy notes and insurance certificates.
β €
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡«πŸ‡· Aqualter contact dataset containing 273K+ individuals allegedly leaked
β €
Aqualter is a French water-management company providing services and infrastructure related to drinking water, wastewater treatment, and environmental management.
β €
A forum actor using the handle ChimeraZ claims to have leaked contact information associated with 273,229 individuals, totaling more than 320,000 records.
β €
Claimed exposed data includes:
β €
β€’ 187,073 phone numbers
β€’ 86,156 email addresses
β€’ Associated record identifiers
β €
The actor states the dataset is approximately 7 MB in CSV format and published samples showing email addresses and phone numbers.
β €
The source, record count, and authenticity of the dataset have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
πŸš¨πŸ‡ΊπŸ‡Έ Booking.com-linked payment card dataset containing 2.3K+ records allegedly offered for sale
β €
Booking.com is a global online travel platform used to book accommodations, flights, car rentals, and other travel services.
β €
A forum actor using the handle ChimeraZ claims to be selling a dataset containing 2,348 records allegedly associated with Booking.com customers.
β €
Claimed exposed data includes:
β €
β€’ Customer names
β€’ Street addresses
β€’ ZIP/postal codes
β€’ Payment card numbers
β€’ Card expiration dates
β€’ Record identifiers
β €
The actor states the dataset is approximately 350 KB in JSON format and does not include CVV codes. Several sample records were published alongside the listing.
β €
The dataset is being offered for $40 in XMR.
β €
The source of the data, its connection to Booking.com, and the authenticity of the records have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀2πŸ”₯1
🚨 DarkMatter Market is likely gone after exit scamming. That doesn't mean the feds stop chasing though. If admin got spooked on something, then things may just be heating up.

Name: DarkMatter Market
Launch Date: September 22nd, 2022
Exit Start: September 7th, 2026
Dread Superlist: September 24th, 2023
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸš¨πŸ‡ΊπŸ‡Έ Forum actor solicits U.S. tax forms for refund filing operation
β €
U.S. tax forms such as 1040s, 1065s, 1099s, W-2s, and W-9s can contain sensitive taxpayer, income, employment, and business information used for federal tax reporting.
β €
A forum actor using the handle Elkmann is seeking partners who can provide tax-form data from compromised targets, claiming they can process the information and file for refunds throughout the year.
β €
Forms being requested include:
β €
β€’ Form 1040 individual tax returns
β€’ Form 1065 partnership returns
β€’ Form 1099 information returns
β€’ W-2 wage and tax statements
β€’ W-9 taxpayer identification forms
β€’ W-9 records accompanied by email access
β €
The actor states they can process as many forms as partners can provide and is actively seeking partnerships ahead of the next tax season.
β €
Minimum quantities are reportedly discussed privately, with initial contact requested through forum messages.
β €
The legitimacy, scale, and success of the claimed refund operation have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Kicksecure: Kicksecure is a hardened Linux operating system designed for security-sensitive computing. It includes protections against malware and exploits, stronger system isolation, hardened defaults, and physical-security features such as a panic-key emergency shutdown that can quickly power off the system if it is at risk of being physically compromised.

Link: https://www.kicksecure.com/
❀2