βΌοΈ New Dark Web Informer Blog Post!
Title: Citya Immobilier Dataset Claim Covers 2.2M+ Records and ~50K Digicodes
Link: https://darkwebinformer.com/citya-immobilier-dataset-claim-covers-2-2m-records-and-50k-digicodes/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Citya Immobilier Dataset Claim Covers 2.2M+ Records and ~50K Digicodes
Link: https://darkwebinformer.com/citya-immobilier-dataset-claim-covers-2-2m-records-and-50k-digicodes/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Citya Immobilier Dataset Claim Covers 2.2M+ Records and ~50K Digicodes
A forum actor posting as ChimeraZ is selling what they claim is a database belonging to Citya Immobilier, a French real estate company providing property management, rental, sales and co-ownership services.
π¨π¦πͺ ECC Group database containing 52K+ records allegedly leaked by AnkaTeam
β
ECC Group is a Dubai-based group of companies operating across construction, engineering, fit-out, manufacturing, building materials, facilities, and real estate development.
β
An actor using the handle SALDIRGAN, identifying with AnkaTeam, claims to have leaked a database associated with ECC Groupβs official website.
β
Claimed exposed data includes:
β
β’ 52,444 database records
β’ WordPress user accounts
β’ Usernames and display names
β’ Email addresses
β’ Password hashes
β’ User registration dates
β’ Account activation data
β’ Other WordPress database records
β
The actor identifies the backend as MariaDB and the affected CMS as WordPress, describing the incident as a database dump exposure. A sample administrator record was published alongside the claim.
β
The breach claim, record count, and full scope of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
ECC Group is a Dubai-based group of companies operating across construction, engineering, fit-out, manufacturing, building materials, facilities, and real estate development.
β
An actor using the handle SALDIRGAN, identifying with AnkaTeam, claims to have leaked a database associated with ECC Groupβs official website.
β
Claimed exposed data includes:
β
β’ 52,444 database records
β’ WordPress user accounts
β’ Usernames and display names
β’ Email addresses
β’ Password hashes
β’ User registration dates
β’ Account activation data
β’ Other WordPress database records
β
The actor identifies the backend as MariaDB and the affected CMS as WordPress, describing the incident as a database dump exposure. A sample administrator record was published alongside the claim.
β
The breach claim, record count, and full scope of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Media is too big
VIEW IN TELEGRAM
Dangerous apps - In the web of data brokers
What many smartphone users know: the apps on their phones collect detailed location data. What few people know: the information often ends up with a global network of data brokers and advertising companies.
Video Credit: youtube.com/@DWDocumentary
What many smartphone users know: the apps on their phones collect detailed location data. What few people know: the information often ends up with a global network of data brokers and advertising companies.
Video Credit: youtube.com/@DWDocumentary
Forwarded from Dark Web Informer - Private
βΌοΈ DOJ Press Release
βββββββββββββββββββββ
California Man Sentenced to Over 12 Years in Prison for Distributing Sadistic Child Sexual Abuse Material Over the Dark Web
Full Press Release β justice.gov
βββββββββββββββββββββ
π΅οΈ Dark Web Informer β’ DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
βββββββββββββββββββββ
California Man Sentenced to Over 12 Years in Prison for Distributing Sadistic Child Sexual Abuse Material Over the Dark Web
Full Press Release β justice.gov
βββββββββββββββββββββ
π΅οΈ Dark Web Informer β’ DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
Department of Justice
California Man Sentenced to Over 12 Years in Prison for Distributing Sadistic Child Sexual Abuse Material Over the Dark Web
James David Johnson, 58, of Santee, California, was sentenced today to 151 months in prison and 10 years of supervised release for distributing images and videos over the dark web that depicted the sexual abuse of children.
β€1
π¨ πͺπΈ Initial Access: Spanish Government Entity
A threat actor is advertising RDP access to an unnamed Spanish government entity with approximately 150 hosts and reported revenue of 20M.
The advertised access includes Local Admin privileges, Dell Unisphere, and several NAS servers containing more than 500TB of data. Kaspersky is reportedly installed but disabled.
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A threat actor is advertising RDP access to an unnamed Spanish government entity with approximately 150 hosts and reported revenue of 20M.
The advertised access includes Local Admin privileges, Dell Unisphere, and several NAS servers containing more than 500TB of data. Kaspersky is reportedly installed but disabled.
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ CVE-2026-89094: Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
CVSS: 9.9
Foregejo Update/Notes: https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md
CVSS: 9.9
Foregejo Update/Notes: https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md
Florida confirms DMV database breach after police account compromised
https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/
https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/
BleepingComputer
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee.
πͺ That Dark Web Guy - Part 3 πͺ
I will do top 2 for now. Voting ends sometime in the next 24 hours. Yes I realize the telegram scraper is missing from my Git, I will add it back sometime later today. https://git.darkwebinformer.com
β€3
π¨π²π½ YucatΓ‘n government documents allegedly leaked, 30 GB archive claimed
β
The Government of YucatΓ‘n is the state administration responsible for public services, civil records, education, and other government functions across YucatΓ‘n, Mexico.
β
A forum actor using the handle vansel claims to have obtained approximately 30 GB of documents, totaling around 50,000 files, from the state of YucatΓ‘n.
β
Claimed exposed data includes:
β
β’ CURP identity records
β’ Birth certificates
β’ Official state documents
β’ School-related records
β’ Names and dates of birth
β’ Civil registry information
β’ Family and parental information
β’ Government-issued identifiers
β’ Other personal information contained in official documents
β
The actor states that roughly 10% of the claimed archive has been released so far, consisting of approximately 5,000 PDF files totaling 2.91 GB.
β
Sample documents published with the post appear to include Mexican birth certificates and CURP-related records.
β
The breach claim, source of the documents, total file count, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
The Government of YucatΓ‘n is the state administration responsible for public services, civil records, education, and other government functions across YucatΓ‘n, Mexico.
β
A forum actor using the handle vansel claims to have obtained approximately 30 GB of documents, totaling around 50,000 files, from the state of YucatΓ‘n.
β
Claimed exposed data includes:
β
β’ CURP identity records
β’ Birth certificates
β’ Official state documents
β’ School-related records
β’ Names and dates of birth
β’ Civil registry information
β’ Family and parental information
β’ Government-issued identifiers
β’ Other personal information contained in official documents
β
The actor states that roughly 10% of the claimed archive has been released so far, consisting of approximately 5,000 PDF files totaling 2.91 GB.
β
Sample documents published with the post appear to include Mexican birth certificates and CURP-related records.
β
The breach claim, source of the documents, total file count, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π¦πͺ Initial Access to Dubai-based IT company allegedly offered for sale
β
The affected organization is described only as an IT company in Dubai that works with Capgemini and Digital Dubai. Its identity was not disclosed in the listing.
β
A forum actor using the handle jorisbernard77 claims to be selling access to the companyβs environment, including remote desktop access and several internal business services.
β
Claimed access includes:
β
β’ Full RDP access
β’ Microsoft Teams
β’ Microsoft Outlook
β’ Password-protected company files
β’ Tally Prime Gold accounting software
β’ Bank account access
β’ Other internal systems accessible through the compromised environment
β
The access claim, affected company, and extent of the alleged compromise have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
The affected organization is described only as an IT company in Dubai that works with Capgemini and Digital Dubai. Its identity was not disclosed in the listing.
β
A forum actor using the handle jorisbernard77 claims to be selling access to the companyβs environment, including remote desktop access and several internal business services.
β
Claimed access includes:
β
β’ Full RDP access
β’ Microsoft Teams
β’ Microsoft Outlook
β’ Password-protected company files
β’ Tally Prime Gold accounting software
β’ Bank account access
β’ Other internal systems accessible through the compromised environment
β
The access claim, affected company, and extent of the alleged compromise have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΊπΈ Tiny Rituals dataset containing 227K+ records allegedly breached and sold
β
Tiny Rituals is a U.S.-based jewelry retailer offering gemstone, crystal, spiritual, and wellness-focused jewelry and accessories.
β
A forum actor using the handle JSON09 claims to have obtained a dataset containing 227,843 records associated with Tiny Rituals, with the breach reportedly occurring on September 10, 2026.
β
Claimed exposed data includes:
β
β’ First and last names
β’ Email addresses
β’ Phone numbers
β’ Street addresses
β’ Cities
β’ ZIP/postal codes
β’ Countries
β
The dataset was advertised for $250.
β
The breach claim, record count, and authenticity of the dataset have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Tiny Rituals is a U.S.-based jewelry retailer offering gemstone, crystal, spiritual, and wellness-focused jewelry and accessories.
β
A forum actor using the handle JSON09 claims to have obtained a dataset containing 227,843 records associated with Tiny Rituals, with the breach reportedly occurring on September 10, 2026.
β
Claimed exposed data includes:
β
β’ First and last names
β’ Email addresses
β’ Phone numbers
β’ Street addresses
β’ Cities
β’ ZIP/postal codes
β’ Countries
β
The dataset was advertised for $250.
β
The breach claim, record count, and authenticity of the dataset have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Please open Telegram to view this post
VIEW IN TELEGRAM
π¨π«π· Ekolis data leak allegedly exposes driver, vehicle, and logistics information
β
Ekolis is a French company specializing in telematics and connected-device solutions for the trucking and logistics industry.
β
An underground forum member using the handle 4me44 claims to have leaked data associated with Ekolis following an alleged breach on September 5, 2026.
β
Claimed exposed data includes:
β
β’ Driver information
β’ Vehicle and trailer records
β’ Fleet identifiers
β’ Customer and company names
β’ Phone numbers
β’ Street and service addresses
β’ Vehicle registration details
β’ Equipment types
β’ Location and logistics information
β’ Operational timestamps
β’ Additional telematics-related records
β
The actor states the leak contains 8 separate files and published sample records showing vehicle, customer, and location-related information.
β
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Ekolis is a French company specializing in telematics and connected-device solutions for the trucking and logistics industry.
β
An underground forum member using the handle 4me44 claims to have leaked data associated with Ekolis following an alleged breach on September 5, 2026.
β
Claimed exposed data includes:
β
β’ Driver information
β’ Vehicle and trailer records
β’ Fleet identifiers
β’ Customer and company names
β’ Phone numbers
β’ Street and service addresses
β’ Vehicle registration details
β’ Equipment types
β’ Location and logistics information
β’ Operational timestamps
β’ Additional telematics-related records
β
The actor states the leak contains 8 separate files and published sample records showing vehicle, customer, and location-related information.
β
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Darknet Market: Sentinel Market
Stay vigilant!
Market: http://sentunywvqvyqj6kvnrw5uo6tszg74glp46fsdnjf345f37zbui56dyd[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/69690d62a6869eee6b57
Stay vigilant!
Market: http://sentunywvqvyqj6kvnrw5uo6tszg74glp46fsdnjf345f37zbui56dyd[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/69690d62a6869eee6b57
π1