πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.99K subscribers
1.28K photos
71 videos
1.13K links
Download Telegram
‼️ New Darknet Market: Sentinel Market

Stay vigilant!

Market: http://sentunywvqvyqj6kvnrw5uo6tszg74glp46fsdnjf345f37zbui56dyd[.]onion

Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/69690d62a6869eee6b57
😈1
🚨 πŸ‡ΉπŸ‡· Initial Access: Turkish Import & Export Company

A threat actor is advertising RDP access to an unnamed Turkish import and export company with reported revenue below 5M.

The advertised access includes two domain user accounts. The environment reportedly contains 33 domain users, four domain computers, and one domain controller, with Windows Defender and Wazuh XDR/EDR deployed.

This claim is currently unverified.

πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 πŸ‡΅πŸ‡­ Initial Access: Major Philippine Telecom Company

A threat actor is advertising firewall access to an unnamed major telecommunications company in the Philippines reportedly generating more than $1B in revenue.

The advertised access is described as Firewall/RCE access and is listed for $1,200, negotiable. Payment is requested in XMR or BTC.

This claim is currently unverified.

πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
At some point when I moved all my repositories from GitHub to my Git server, the Telegram Scraper script didn't get moved. Unfortunately, I can't sync the original repository from GitHub because it no longer exists on my GitHub account.

Anyway, I've added the script back to my Git server, and I'm in the process of adding an IOC extractor and a global database search feature to it. I will add an updated Readme at that time. Soonβ„’

https://git.darkwebinformer.com/DarkWebInformer/Telegram_Scraper
πŸš¨πŸ‡©πŸ‡ͺ LANXESS internal data allegedly leaked following failed negotiations
β €
LANXESS is a German specialty chemicals company headquartered in Cologne, producing chemical intermediates, additives, and specialty products for industries worldwide.
β €
A forum actor using the handle sta6 claims to have released internal LANXESS data after what they describe as weeks of unsuccessful negotiations with the company.
β €
Claimed exposed data includes:
β €
β€’ 14,658 user records
β€’ 11,860 MD5 password hashes
β€’ Corporate and external business email addresses
β€’ Names, phone numbers, addresses, and job information
β€’ Internal account and login information
β€’ TLS/SSL private keys and certificate archives
β€’ Application and database credentials
β€’ Oracle-related user data and password hashes
β€’ Internal LANXESS contact-routing information
β€’ 12,249 customer and business enquiry emails
β€’ Names, corporate emails, phone numbers, and message content from external contacts
β€’ Configuration files and other internal system data
β €
The actor also claims the material contains historical TLS/SSL keys dating from 2011 through 2025, cleartext credentials from several internal configuration files, and information tied to approximately 12,000 external customers and business contacts.
β €
A sample archive was published as purported proof of the compromise.
β €
The breach claim, authenticity of the material, and full scope of the exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡¦πŸ‡Ί TIC Group source code allegedly leaked following September breach
β €
TIC Group is an Australian supply chain and retail logistics provider offering reverse logistics, product recovery, warehousing, and related services to retailers and brands.
β €
A forum moderator using the handle 888 claims to have published source code allegedly stolen from TIC Group during a breach in September 2026.
β €
Claimed exposed data includes:
β €
β€’ Internal source code
β€’ Application and project files
β€’ Repository directory structures
β€’ Other development-related material
β €
The actor states that TIC Group was breached and that its source code was taken, with a directory tree shared as purported proof. Access to the download is being distributed through the forum.
β €
The breach claim, origin of the source code, and full scope of the exposed material have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡¦πŸ‡΄ Angola’s SEPE e-government platform allegedly compromised, 179 GB of data claimed
β €
SEPE is Angola’s official electronic public services platform, allowing citizens and businesses to access government services online without visiting government offices.
β €
A forum actor using the handle Kazu claims to have obtained approximately 179 GB of data from SEPE, including 364,841 files and information tied to 110,021 users.
β €
Claimed exposed data includes:
β €
β€’ Copies of identity cards
β€’ NIF tax identification numbers
β€’ Full names and dates of birth
β€’ Gender and nationality
β€’ Home addresses, communes, and provinces
β€’ Phone numbers and email addresses
β€’ Countries of residence
β€’ Employment and occupation information
β€’ Education, courses, and work experience
β€’ Academic qualification certificates
β€’ Military service documents
β€’ Medical certificates
β€’ Curriculum vitae documents
β€’ Criminal record documents
β€’ Other government-related files
β €
The actor is demanding $100,000 and has set a deadline of September 27, 2026, claiming the data will be sold if payment is not made. Samples were also published alongside the claim.
β €
The breach claim, record counts, authenticity of the documents, and full scope of the exposure have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1
β€ΌοΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡Έ Global Ransomware claims 2 victims

πŸ‡ΊπŸ‡Έ Sutton Public Schools - A Massachusetts public school district serving students and families in Sutton.

πŸ‡ΊπŸ‡Έ Town of Sutton, Massachusetts - The municipal government of Sutton, Massachusetts, providing resident services, permits, payments, local news, and community programs.
πŸš¨πŸ‡¨πŸ‡± Chilean clinical database containing patient and medical imaging records allegedly leaked
β €
The leaked material appears to contain healthcare and diagnostic imaging records tied to Chilean medical institutions, including ClΓ­nica Universidad de los Andes in the published samples.
β €
A forum actor using the handle Synq1xxs claims to have obtained and released a full clinical database containing patient information and diagnostic examination records.
β €
Claimed exposed data includes:
β €
β€’ Patient IDs
β€’ Full names
β€’ Sex
β€’ Dates of birth
β€’ Patient identifiers
β€’ Medical examination details
β€’ Imaging modalities
β€’ Study descriptions
β€’ Examination dates and times
β€’ Accession numbers
β€’ Healthcare institution information
β€’ Diagnostic imaging metadata
β €
Published samples appear to contain records for mammography, radiography, and other medical imaging studies, along with patient information and associated clinical metadata.
β €
The breach claim, affected institutions, source of the database, and full scope of the exposed medical data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡¬πŸ‡§ Revolut confirms customer data breach after falling for fake government requests

Revolut has confirmed it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent information requests sent from a legitimate government agency email domain.
β €
Potentially exposed information includes:

β€’ Names and dates of birth
β€’ Postal and email addresses
β€’ Phone numbers
β€’ Passports and driver’s licenses
β€’ Verification selfies
β€’ IBANs
β€’ Account statements
β€’ Withdrawal records
β€’ Full transaction histories, including Bitcoin transactions
β €
Revolut says a limited number of customers were affected, but has not disclosed the exact number or identified the government agency whose email domain was used.
β €
After discovering the scam, Revolut blocked the email address and notified the affected government agency, law enforcement, data protection authorities, and financial regulators.
β €
Revolut says its systems were not compromised and customer funds remain unaffected.

Affected customers are being contacted directly.
πŸ”₯1
Superlist Darknet Market TorZon turned 4 years old today. That’s a longgg timeee.

https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/c8eb3febdc3ab3556279/?context=eed472f1fbcc7084ee#c-eed472f1fbcc7084ee
😁1
πŸš¨πŸ‡¨πŸ‡· Costa Rican credit reporting agency allegedly breached, massive nationwide dataset claimed
β €
The affected organization is described only as a Costa Rican credit reporting agency. Its name was not disclosed in the post.
β €
A forum actor using the handle jarol1488 claims to have compromised the agency and obtained multiple datasets containing financial, identity, legal, contact, vehicle, and civil-registry information tied to people across Costa Rica.
β €
Claimed exposed data includes:
β €
β€’ 21.8M+ address records
β€’ 3.9M+ email records
β€’ 3.3M+ photographs
β€’ 18.7M+ detailed court records
β€’ 8.1M+ additional legal records
β€’ 374.6M+ salary records
β€’ 9.9M+ individual identity records
β€’ 3.5M+ vehicle records
β€’ 3.3M+ vehicle ownership records
β€’ 13.4M+ telephone records
β€’ 1.9M+ marriage records
β €
The actor claims the dataset includes information covering Costa Rica’s population as well as foreign nationals, and published samples containing addresses, emails, legal records, salary information, identity details, vehicle data, phone numbers, civil-status records, and photographs.
β €
The breach claim, identity of the affected agency, record counts, and full scope of the exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 πŸ‡¨πŸ‡³ Initial Access: Chinese Luxury E-Commerce Company

A threat actor is advertising two firewall access points to an unnamed Chinese luxury e-commerce company.

The advertised access is described as Firewall/RCE with root privileges. Both access points are being offered together for $2,000, negotiable, with payment requested in XMR.

This claim is currently unverified.

πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€ΌοΈπŸ‡ΊπŸ‡Έ ShinyHunters names 1 new victim

πŸ‡ΊπŸ‡Έ Kimberly-Clark - A U.S.-based consumer products company best known for brands including Huggies, Kleenex, Kotex, Cottonelle, and Scott.
πŸš¨πŸ‡²πŸ‡½ UASLP student database containing 940 records and facial images allegedly leaked
β €
Universidad AutΓ³noma de San Luis PotosΓ­ (UASLP) is a public university in San Luis PotosΓ­, Mexico, offering undergraduate, graduate, research, and professional education programs.
β €
A forum actor using the handle zfo claims to have obtained and released a UASLP student dataset containing information on approximately 940 students, including what the actor describes as student facial images.
β €
Claimed exposed data includes:
β €
β€’ Student identification numbers
β€’ Full names
β€’ Academic programs / majors
β€’ Enrollment status
β€’ Gender
β€’ CURP identifiers
β€’ Dates of birth
β€’ Personal email addresses
β€’ UASLP institutional email addresses
β€’ Mobile and home phone numbers
β€’ Street addresses
β€’ Municipalities and states
β€’ Postal codes
β€’ Academic adviser information
β€’ Student photographs / facial images
β €
The actor published a sample containing detailed student records and is distributing the purported dataset through Telegram.
β €
The breach claim, record count, authenticity of the data, and claimed exposure of student facial images have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1