π¨π¨π· Costa Rican credit reporting agency allegedly breached, massive nationwide dataset claimed
β
The affected organization is described only as a Costa Rican credit reporting agency. Its name was not disclosed in the post.
β
A forum actor using the handle jarol1488 claims to have compromised the agency and obtained multiple datasets containing financial, identity, legal, contact, vehicle, and civil-registry information tied to people across Costa Rica.
β
Claimed exposed data includes:
β
β’ 21.8M+ address records
β’ 3.9M+ email records
β’ 3.3M+ photographs
β’ 18.7M+ detailed court records
β’ 8.1M+ additional legal records
β’ 374.6M+ salary records
β’ 9.9M+ individual identity records
β’ 3.5M+ vehicle records
β’ 3.3M+ vehicle ownership records
β’ 13.4M+ telephone records
β’ 1.9M+ marriage records
β
The actor claims the dataset includes information covering Costa Ricaβs population as well as foreign nationals, and published samples containing addresses, emails, legal records, salary information, identity details, vehicle data, phone numbers, civil-status records, and photographs.
β
The breach claim, identity of the affected agency, record counts, and full scope of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
The affected organization is described only as a Costa Rican credit reporting agency. Its name was not disclosed in the post.
β
A forum actor using the handle jarol1488 claims to have compromised the agency and obtained multiple datasets containing financial, identity, legal, contact, vehicle, and civil-registry information tied to people across Costa Rica.
β
Claimed exposed data includes:
β
β’ 21.8M+ address records
β’ 3.9M+ email records
β’ 3.3M+ photographs
β’ 18.7M+ detailed court records
β’ 8.1M+ additional legal records
β’ 374.6M+ salary records
β’ 9.9M+ individual identity records
β’ 3.5M+ vehicle records
β’ 3.3M+ vehicle ownership records
β’ 13.4M+ telephone records
β’ 1.9M+ marriage records
β
The actor claims the dataset includes information covering Costa Ricaβs population as well as foreign nationals, and published samples containing addresses, emails, legal records, salary information, identity details, vehicle data, phone numbers, civil-status records, and photographs.
β
The breach claim, identity of the affected agency, record counts, and full scope of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ π¨π³ Initial Access: Chinese Luxury E-Commerce Company
A threat actor is advertising two firewall access points to an unnamed Chinese luxury e-commerce company.
The advertised access is described as Firewall/RCE with root privileges. Both access points are being offered together for $2,000, negotiable, with payment requested in XMR.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A threat actor is advertising two firewall access points to an unnamed Chinese luxury e-commerce company.
The advertised access is described as Firewall/RCE with root privileges. Both access points are being offered together for $2,000, negotiable, with payment requested in XMR.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π²π½ UASLP student database containing 940 records and facial images allegedly leaked
β
Universidad AutΓ³noma de San Luis PotosΓ (UASLP) is a public university in San Luis PotosΓ, Mexico, offering undergraduate, graduate, research, and professional education programs.
β
A forum actor using the handle zfo claims to have obtained and released a UASLP student dataset containing information on approximately 940 students, including what the actor describes as student facial images.
β
Claimed exposed data includes:
β
β’ Student identification numbers
β’ Full names
β’ Academic programs / majors
β’ Enrollment status
β’ Gender
β’ CURP identifiers
β’ Dates of birth
β’ Personal email addresses
β’ UASLP institutional email addresses
β’ Mobile and home phone numbers
β’ Street addresses
β’ Municipalities and states
β’ Postal codes
β’ Academic adviser information
β’ Student photographs / facial images
β
The actor published a sample containing detailed student records and is distributing the purported dataset through Telegram.
β
The breach claim, record count, authenticity of the data, and claimed exposure of student facial images have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Universidad AutΓ³noma de San Luis PotosΓ (UASLP) is a public university in San Luis PotosΓ, Mexico, offering undergraduate, graduate, research, and professional education programs.
β
A forum actor using the handle zfo claims to have obtained and released a UASLP student dataset containing information on approximately 940 students, including what the actor describes as student facial images.
β
Claimed exposed data includes:
β
β’ Student identification numbers
β’ Full names
β’ Academic programs / majors
β’ Enrollment status
β’ Gender
β’ CURP identifiers
β’ Dates of birth
β’ Personal email addresses
β’ UASLP institutional email addresses
β’ Mobile and home phone numbers
β’ Street addresses
β’ Municipalities and states
β’ Postal codes
β’ Academic adviser information
β’ Student photographs / facial images
β
The actor published a sample containing detailed student records and is distributing the purported dataset through Telegram.
β
The breach claim, record count, authenticity of the data, and claimed exposure of student facial images have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨π«π· Groupe MGEL databases allegedly offered for sale, 38.8M+ rows and 450K IBANs claimed
β
Groupe MGEL is a French organization historically associated with student mutual services and support for young people, including students, apprentices, and young workers.
β
A forum actor using the handle RedStone claims to be selling 16 databases containing 387 tables and more than 38.8 million rows associated with Groupe MGEL.
β
Claimed exposed data includes:
β
β’ 603,845 unique email addresses
β’ 685,676 unique phone numbers
β’ 1,122,168 unique full names
β’ 450,806 unique IBANs
β’ 594,414 member records
β’ 5.7M+ billing records
β’ 9.2M+ bank transfer records
β’ 204,480 identity records
β’ Names, addresses, and contact information
β’ Bank and account details
β’ SHA-256 password hashes
β’ Plaintext passwords in some student records
β’ School and education information
β’ Treating physician information
β’ Social security and diagnostic records
β’ Dates of birth and family-related information
β
The actor also claims to have 349,371 combined records containing names, phone numbers, and IBAN information, and published a 1,000-row sample drawn from five tables containing personal information.
β
The databases are being offered on a make-an-offer basis with a $500 minimum.
β
The breach claim, record counts, authenticity of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Groupe MGEL is a French organization historically associated with student mutual services and support for young people, including students, apprentices, and young workers.
β
A forum actor using the handle RedStone claims to be selling 16 databases containing 387 tables and more than 38.8 million rows associated with Groupe MGEL.
β
Claimed exposed data includes:
β
β’ 603,845 unique email addresses
β’ 685,676 unique phone numbers
β’ 1,122,168 unique full names
β’ 450,806 unique IBANs
β’ 594,414 member records
β’ 5.7M+ billing records
β’ 9.2M+ bank transfer records
β’ 204,480 identity records
β’ Names, addresses, and contact information
β’ Bank and account details
β’ SHA-256 password hashes
β’ Plaintext passwords in some student records
β’ School and education information
β’ Treating physician information
β’ Social security and diagnostic records
β’ Dates of birth and family-related information
β
The actor also claims to have 349,371 combined records containing names, phone numbers, and IBAN information, and published a 1,000-row sample drawn from five tables containing personal information.
β
The databases are being offered on a make-an-offer basis with a $500 minimum.
β
The breach claim, record counts, authenticity of the data, and full scope of the exposure have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΈπ¦ Waselni database allegedly leaked, driver, passenger, trip, and location data exposed
β
Waselni is a Saudi Arabia-based ride-hailing and taxi platform that connects passengers with drivers through its mobile applications.
β
A threat actor operating under the name UWAYS QARANI claims to have compromised Waselni and publicly released its database, alleging access to data tied to drivers, passengers, trips, transactions, and service locations.
β
Claimed exposed data includes:
β
β’ User names and account identifiers
β’ Email addresses
β’ Mobile phone numbers
β’ Password hashes
β’ Gender and profile information
β’ Driver and passenger records
β’ Trip-related information
β’ Vehicle makes, models, years, colors, and plate details
β’ Service-location identifiers
β’ Latitude and longitude coordinates
β’ Saved places and location descriptions
β’ Account and application metadata
β
The published samples appear to contain user-account records, vehicle information, and location data with geographic coordinates, alongside additional application-related fields.
β
The actor also claims the breach disrupted Waselniβs service and says the leaked information can be used to correlate individuals with their movements and locations.
β
The breach claim, extent of the alleged service disruption, authenticity of the database, and full scope of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Waselni is a Saudi Arabia-based ride-hailing and taxi platform that connects passengers with drivers through its mobile applications.
β
A threat actor operating under the name UWAYS QARANI claims to have compromised Waselni and publicly released its database, alleging access to data tied to drivers, passengers, trips, transactions, and service locations.
β
Claimed exposed data includes:
β
β’ User names and account identifiers
β’ Email addresses
β’ Mobile phone numbers
β’ Password hashes
β’ Gender and profile information
β’ Driver and passenger records
β’ Trip-related information
β’ Vehicle makes, models, years, colors, and plate details
β’ Service-location identifiers
β’ Latitude and longitude coordinates
β’ Saved places and location descriptions
β’ Account and application metadata
β
The published samples appear to contain user-account records, vehicle information, and location data with geographic coordinates, alongside additional application-related fields.
β
The actor also claims the breach disrupted Waselniβs service and says the leaked information can be used to correlate individuals with their movements and locations.
β
The breach claim, extent of the alleged service disruption, authenticity of the database, and full scope of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1
π¨ πΊπΈπ¨π¦ Initial Access Buyer Seeking Corporate Network Access
A threat actor is seeking suppliers of corporate access targeting organizations primarily in the U.S. and Canada.
Requested access types include VPN, Citrix, corporate RDP, HVNC, shells, bots, and similar access. The actor lists minimum revenue thresholds of $20M+ for U.S. targets and $30M+ for Canadian targets.
Other countries may also be considered, while .edu and .gov targets are excluded.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A threat actor is seeking suppliers of corporate access targeting organizations primarily in the U.S. and Canada.
Requested access types include VPN, Citrix, corporate RDP, HVNC, shells, bots, and similar access. The actor lists minimum revenue thresholds of $20M+ for U.S. targets and $30M+ for Canadian targets.
Other countries may also be considered, while .edu and .gov targets are excluded.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π«π· Sushi&Cie dataset containing 6K customer records allegedly leaked
β
Sushi&Cie is a Japanese restaurant in Houdan, France, specializing in sushi, maki, sashimi, and other freshly prepared Japanese dishes.
β
An underground forum member using the handle 4me44 claims to have obtained and released a Sushi&Cie dataset containing approximately 74,867 lines tied to around 6,000 users, with the breach reportedly occurring on September 13, 2026.
β
Claimed exposed data includes:
β
β’ Customer IDs
β’ Full names
β’ Email addresses
β’ Customer groups
β’ Account status information
β’ Approval status
β’ IP addresses
β’ Account creation dates
β’ Phone numbers
β
The actor published sample records containing customer names, email addresses, IP addresses, timestamps, and telephone numbers, with access to the purported full dataset shared through the forum.
β
The breach claim, record count, and authenticity of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Sushi&Cie is a Japanese restaurant in Houdan, France, specializing in sushi, maki, sashimi, and other freshly prepared Japanese dishes.
β
An underground forum member using the handle 4me44 claims to have obtained and released a Sushi&Cie dataset containing approximately 74,867 lines tied to around 6,000 users, with the breach reportedly occurring on September 13, 2026.
β
Claimed exposed data includes:
β
β’ Customer IDs
β’ Full names
β’ Email addresses
β’ Customer groups
β’ Account status information
β’ Approval status
β’ IP addresses
β’ Account creation dates
β’ Phone numbers
β
The actor published sample records containing customer names, email addresses, IP addresses, timestamps, and telephone numbers, with access to the purported full dataset shared through the forum.
β
The breach claim, record count, and authenticity of the exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ A forum actor is seeking to buy SS7 telecom access, preferably in the US, offering payment in Monero on a recurring or upfront basis.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΈπ¦ SMSA Express VPN access allegedly offered for sale
β
SMSA Express is a Saudi Arabian courier and logistics company providing express delivery, freight transportation, customs clearance, e-commerce logistics, cold-chain services, and healthcare logistics.
β
A forum actor using the handle alina20 claims to be selling VPN access to SMSA Express.
β
Claimed access details include:
β
β’ VPN access to the company environment
β’ Organization based in Saudi Arabia
β’ Logistics and transportation sector
β’ Company reportedly employs more than 8,000 people
β’ Access allegedly tied to SMSA Express internal systems
β
The actor is directing interested buyers to contact them privately through Signal.
β
The access claim, level of privileges, and current validity of the alleged VPN access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
SMSA Express is a Saudi Arabian courier and logistics company providing express delivery, freight transportation, customs clearance, e-commerce logistics, cold-chain services, and healthcare logistics.
β
A forum actor using the handle alina20 claims to be selling VPN access to SMSA Express.
β
Claimed access details include:
β
β’ VPN access to the company environment
β’ Organization based in Saudi Arabia
β’ Logistics and transportation sector
β’ Company reportedly employs more than 8,000 people
β’ Access allegedly tied to SMSA Express internal systems
β
The actor is directing interested buyers to contact them privately through Signal.
β
The access claim, level of privileges, and current validity of the alleged VPN access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π§πͺ FΓ©dΓ©ration francophone de Gymnastique dataset containing 209K+ member records allegedly breached
β
The FΓ©dΓ©ration francophone de Gymnastique is a Belgian sports federation that promotes and organizes gymnastics across French-speaking communities and affiliated clubs.
β
A forum actor using the handle Venus1337 claims to have obtained data associated with ffgym.be, along with access to an administrative panel.
β
Claimed exposed data includes:
β
β’ 209,818 member / subscriber records
β’ 764 staff user accounts with password hashes
β’ 5,858 accident records
β’ 26,058 invoices
β’ 10,335 affiliation records
β’ Names and licence numbers
β’ Dates of birth and gender
β’ Email addresses and phone numbers
β’ Postal addresses and localities
β’ Club and affiliation information
β’ Usernames and account status
β’ Accident dates and associated club information
β’ Invoice totals, payment status, balances, and references
β’ Nationality and membership information
β
The actor published samples from several JSON files showing member, staff, accident, invoice, and affiliation records, and also claims to be providing access to the organizationβs panel.
β
The breach claim, record counts, authenticity of the data, and claimed administrative access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
The FΓ©dΓ©ration francophone de Gymnastique is a Belgian sports federation that promotes and organizes gymnastics across French-speaking communities and affiliated clubs.
β
A forum actor using the handle Venus1337 claims to have obtained data associated with ffgym.be, along with access to an administrative panel.
β
Claimed exposed data includes:
β
β’ 209,818 member / subscriber records
β’ 764 staff user accounts with password hashes
β’ 5,858 accident records
β’ 26,058 invoices
β’ 10,335 affiliation records
β’ Names and licence numbers
β’ Dates of birth and gender
β’ Email addresses and phone numbers
β’ Postal addresses and localities
β’ Club and affiliation information
β’ Usernames and account status
β’ Accident dates and associated club information
β’ Invoice totals, payment status, balances, and references
β’ Nationality and membership information
β
The actor published samples from several JSON files showing member, staff, accident, invoice, and affiliation records, and also claims to be providing access to the organizationβs panel.
β
The breach claim, record counts, authenticity of the data, and claimed administrative access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΈπ¦ Almarai internal dataset access allegedly offered for sale
β
Almarai is a Saudi multinational food and beverage company headquartered in Riyadh, producing and distributing dairy products, juice, bakery goods, poultry, and other consumer foods across the region.
β
A forum actor using the handle alina20 claims to be offering access associated with Almarai, with the listing referencing August 20, 2026.
β
Claimed access includes:
β
β’ Internal dataset / database access
β’ Access allegedly tied to Almarai systems
β’ Saudi Arabia-based corporate environment
β’ Private sale through direct contact
β
The listing does not disclose the underlying tables, exposed record types, access privileges, or volume of data available through the alleged compromise.
β
The access claim, current validity, level of privileges, and extent of any exposed Almarai data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Almarai is a Saudi multinational food and beverage company headquartered in Riyadh, producing and distributing dairy products, juice, bakery goods, poultry, and other consumer foods across the region.
β
A forum actor using the handle alina20 claims to be offering access associated with Almarai, with the listing referencing August 20, 2026.
β
Claimed access includes:
β
β’ Internal dataset / database access
β’ Access allegedly tied to Almarai systems
β’ Saudi Arabia-based corporate environment
β’ Private sale through direct contact
β
The listing does not disclose the underlying tables, exposed record types, access privileges, or volume of data available through the alleged compromise.
β
The access claim, current validity, level of privileges, and extent of any exposed Almarai data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈπ¨π΄ Emperador claims a Colombian distributor
π¨π΄ Navitrans - A Colombian distributor and service provider specializing in commercial trucks and heavy machinery, including vehicle sales, spare parts, maintenance, and repair services.
The listing claims 223.2 MB of data containing sensitive information related to pricing, financing, inventory, warehouses, historical sales, transactions, product catalogs, distribution, and other operational data.
π¨π΄ Navitrans - A Colombian distributor and service provider specializing in commercial trucks and heavy machinery, including vehicle sales, spare parts, maintenance, and repair services.
The listing claims 223.2 MB of data containing sensitive information related to pricing, financing, inventory, warehouses, historical sales, transactions, product catalogs, distribution, and other operational data.
π¨π©π΄ Claro Dominican Republic dataset containing 2.8M+ customer records allegedly leaked
β
Claro is a major telecommunications provider in the Dominican Republic, offering mobile, internet, television, and other communications services to consumers and businesses.
β
A forum actor using the handle jarol1488 claims to have breached Claroβs systems in the Dominican Republic and obtained a dataset containing information tied to 2,889,256 customers.
β
Claimed exposed data includes:
β
β’ Customer identification numbers
β’ Mobile phone numbers
β’ Subscription records
β’ SIM / ICCID identifiers
β’ Service and account status
β’ Plan categories and descriptions
β’ Activation dates
β’ Billing cycle information
β’ Release dates
β’ Mobile validation status
β’ Internal subscription and plan identifiers
β
The actor published sample records showing customer identifiers alongside multiple mobile subscriptions, phone numbers, SIM-related data, account status, and prepaid plan information.
β
The breach claim, record count, authenticity of the dataset, and full scope of the exposed customer information have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Claro is a major telecommunications provider in the Dominican Republic, offering mobile, internet, television, and other communications services to consumers and businesses.
β
A forum actor using the handle jarol1488 claims to have breached Claroβs systems in the Dominican Republic and obtained a dataset containing information tied to 2,889,256 customers.
β
Claimed exposed data includes:
β
β’ Customer identification numbers
β’ Mobile phone numbers
β’ Subscription records
β’ SIM / ICCID identifiers
β’ Service and account status
β’ Plan categories and descriptions
β’ Activation dates
β’ Billing cycle information
β’ Release dates
β’ Mobile validation status
β’ Internal subscription and plan identifiers
β
The actor published sample records showing customer identifiers alongside multiple mobile subscriptions, phone numbers, SIM-related data, account status, and prepaid plan information.
β
The breach claim, record count, authenticity of the dataset, and full scope of the exposed customer information have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π¬π§ MyNewTerm dataset containing 142K unique users allegedly leaked
β
MyNewTerm is a UK-based online recruitment and applicant tracking platform used by schools and education organizations to advertise vacancies and manage candidates.
β
A forum moderator using the handle 888 claims to have breached MyNewTerm in August 2026 and released a dataset containing information tied to approximately 142,000 unique users.
β
Claimed exposed data includes:
β
β’ Applicant email addresses
β’ Job and appointment identifiers
β’ Job positions and vacancy references
β’ Application and recruitment status
β’ Onboarding information
β’ Job start and expiry dates
β’ School and trust identifiers
β’ School names and locations
β’ Job titles and descriptions
β’ Salary ranges
β’ Contract and employment types
β’ Subject and department information
β’ Visa sponsorship availability
β’ Vacancy posting and closing dates
β’ Internal recruitment metadata
β
Published samples appear to contain applicant records alongside detailed education-sector vacancy information, including school names, job descriptions, salary information, and recruitment status data.
β
The breach claim, record count, authenticity of the dataset, and full scope of the exposed information have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
MyNewTerm is a UK-based online recruitment and applicant tracking platform used by schools and education organizations to advertise vacancies and manage candidates.
β
A forum moderator using the handle 888 claims to have breached MyNewTerm in August 2026 and released a dataset containing information tied to approximately 142,000 unique users.
β
Claimed exposed data includes:
β
β’ Applicant email addresses
β’ Job and appointment identifiers
β’ Job positions and vacancy references
β’ Application and recruitment status
β’ Onboarding information
β’ Job start and expiry dates
β’ School and trust identifiers
β’ School names and locations
β’ Job titles and descriptions
β’ Salary ranges
β’ Contract and employment types
β’ Subject and department information
β’ Visa sponsorship availability
β’ Vacancy posting and closing dates
β’ Internal recruitment metadata
β
Published samples appear to contain applicant records alongside detailed education-sector vacancy information, including school names, job descriptions, salary information, and recruitment status data.
β
The breach claim, record count, authenticity of the dataset, and full scope of the exposed information have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€1