home.social

Search

50 results for “darkwebinformer”

  1. 🚨🇫🇷 France Travail Employee Dataset With 62,848 Records Offered for Sale

    An actor is selling what they claim is an internal France Travail employee dataset containing 62,848 records.

    This one is focused on staff rather than job seekers. The samples include employee names, work email addresses, phone numbers, job titles, departments, regions, internal identifiers, and links to profile photos hosted on France Travail's intranet.

    The seller published a portion of the data as proof and is taking offers privately.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  2. 🚨🇳🇬 Initial Access to Two Nigerian Companies Advertised

    A forum actor claims to have gained initial access to systems belonging to Liquid Telecommunications Ltd. and Eko Atlantic City Management Ltd.

    The actor says the compromised environments contain user credentials and PII, and published several screenshots as purported proof of access.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  3. 🚨🇩🇴 UNAPEC Allegedly Breached, Student Credentials and Personal Data Exposed

    An actor claims to have breached Universidad APEC (UNAPEC) in the Dominican Republic and obtained data from several university systems.

    The exposed information allegedly includes student names, email addresses, passwords, national or student ID numbers, and login records. The actor also claims to have access to email accounts associated with affected users.

    A screenshot shared as proof shows credentials tied to multiple UNAPEC services and subdomains.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  4. 🚨 Social Media Account and Profile Archive Marketplace Advertised on Forum

    IOC: akysos[.]market

    A marketplace called AKYSOS Market is being promoted for the sale of VK and Telegram accounts, profile archives, VPN accounts, and VPN configurations.

    The service claims users can search archived profiles by city or ID, with products starting at £5. The operator says the data and accounts are sourced from third-party suppliers.

    Payments are advertised through cryptocurrency and bank cards, with escrow also accepted.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  5. 🚨 New Ransomware Group: SCARLETTGROUP

    Dark Web: http://scarlettgugldabhgz3uertpnxglxytddxbd5vnoma5pihfk6k5q2sid[.]onion/

    Forum claim: x.com/DarkWebInformer/status/2

  6. 🚨 VirusTotal Enterprise API Key Offered for Sale for $350

    The seller advertises limits of 5,000 requests per day, 300,000 per hour, and 1 billion per month, and offers to demonstrate that the key works before purchase.

    Payment is accepted in BTC or LTC, with escrow also offered.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  7. 🚨🇺🇸 Yale University Press Allegedly Breached, 64,000+ Records Exposed

    A group calling itself "SCARLETTGROUP" claims it breached Yale University Press and obtained data on more than 64,000 students and employees.

    The group says the breach includes 28,000+ transaction records, personal information, Yale Books source code, course materials, exam answer keys, registration data, and other internal files.

    Screenshots showing apparent access to Yale Books systems were published as proof, with the group demanding contact before a negotiation deadline.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  8. 🚨🇹🇷 Okul Güvenliği Dataset With 2 Million+ Records Offered for Sale

    A dataset allegedly linked to Turkish school security platform Okul Güvenliği has been offered for sale for $2,000.

    The actor claims the data includes more than 2.1 million ID numbers and 1.9 million phone numbers, along with student and parent names, dates of birth, schools, classes, and other personal information.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  9. 🚨🇳🇵 This is what a bad supply-chain compromise looks like.
    ⠀
    One Nepalese technology provider.
    ⠀
    170+ client environments.
    ⠀
    Government ministries. Police. Municipalities. Universities. Hospitals.
    ⠀
    An actor claims their team compromised the provider, gained administrative access, achieved RCE, and obtained credentials for databases, APIs, SMTP services, and customer systems.
    ⠀
    Screenshots shared in the post show client administration panels, database backups, credentials, and access to government-related systems.
    ⠀
    Among the organizations named:
    ⠀
    • Nepal Police Headquarters
    • Department of National Personnel Records
    • Ministry of Home Affairs and Communication
    • Provincial Infrastructure Development Authority
    • Lumbini Technological University
    • Office of the Chief Minister and Council of Ministers
    • Bhaktapur Municipality
    • Tokha Municipality
    • Ratnanagar Municipality
    ⠀
    The actors also claim access to a Git repository and responsibility for the defacement of Lumbini Technological University.
    ⠀
    If legitimate, the dataset is only one part of the story.
    ⠀
    The access is the bigger problem.
    ⠀
    Claim is currently unverified.
    ⠀
    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  10. ‼️ New Dark Web Informer Blog Post!

    Title: Japan Hands Suspected Qilin Ransomware Member to Germany

    Link: darkwebinformer.com/japan-hand

    💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: darkwebinformer.com/pricing

  11. 🚨🇺🇸 480 GB of Metrea and Commuter Air Technology Data Allegedly Stolen

    An actor claims to have obtained 480 GB of data containing approximately 64,000 files from U.S. defense contractors Metrea and Commuter Air Technology.

    The actor claims the material includes SOCOM-related documents, military radio firmware, deployment information, contract data, employee records, cybersecurity assessments, and credentials associated with classified systems.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  12. ‼️ New Dark Web Informer Blog Post!

    Title: Spokane Man Accused of Running Dark Web Cocaine Operation Through U.S. Mail

    Link: darkwebinformer.com/spokane-ma

    💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: darkwebinformer.com/pricing

  13. ‼️ New Dark Web Informer Blog Post!

    Title: FLOCKER Ransomware Affiliate Program Returns With 90% Revenue Share and Cross-Platform Tooling

    Link: darkwebinformer.com/flocker-ra

    💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: darkwebinformer.com/pricing

  14. ‼️ New Dark Web Informer Blog Post!

    Title: MedCred Dataset Claim Lists 274,534 Users With Names, Email and Address Information

    Link: darkwebinformer.com/medcred-da

    💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: darkwebinformer.com/pricing

  15. 🚨 Initial Access Buyer Targets Healthcare, Logistics and Manufacturing Networks

    A forum actor is seeking to purchase initial access to corporate networks, specifically naming healthcare, logistics, and manufacturing as sectors of interest.

    The actor asks sellers to contact them before offering access elsewhere.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  16. 🚨 Windows 11 Zero-Day LPE and Pre-Auth RCE Exploits Offered for Sale

    A forum actor is advertising an alleged Windows 11 zero-day local privilege escalation exploit claimed to work across all versions.

    The seller also claims to have pre-auth RCE exploits for Ivanti Connect Secure SSLVPN and Zimbra, along with an RCE exploit targeting Switchvox SMB.

    Pricing is negotiable, with transactions offered through escrow.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  17. ‼️🇦🇪 Flydubai is named in a new Everest ransomware listing involving airline operational and personnel data.

    🇦🇪 Flydubai - A Dubai-based airline operating passenger and cargo services across the Middle East, Africa, Asia, and Europe.

    The listing claims 4.36 GB across 16,517 files, including flight-operations documentation, crew training materials, personnel exports, manufacturer technical publications, electronic flight-reference packages, and Boeing engineering software.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  18. 🚨 Initial Access Seller Advertises RDP and Fortinet VPN Access

    A forum actor is advertising corporate network access through RDP, FortiSSLVPN, and FortiGate.

    The seller says target revenue generally starts at $2 million, with some organizations reaching $30 million to $50 million, and transactions are available through escrow.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  19. 🚨 Initial Access Buyer Seeking Corporate Network Access Across U.S., Canada and Europe

    A forum actor is seeking to purchase access to corporate networks in the U.S., Canada, and several European countries, targeting organizations with revenue starting at $5 million.

    The buyer says the access method does not matter, with Domain User privileges listed as the minimum requirement. Schools, hospitals, government organizations, churches, and similar targets are excluded.

    The actor also offers above-market pricing and profit-sharing arrangements for suppliers with a consistent flow of access or large botnets.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  20. 🚨🇺🇸 Government Email Access Sought for Emergency Data Requests

    A forum actor is seeking to purchase access to a government email account capable of submitting Emergency Data Requests (EDRs).

    The actor says U.S. government access is preferred, but would consider other countries where the account could be used for EDRs and retain access for longer periods.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  21. 🚨🇺🇸 Initial Access: US Corporate Network

    A threat actor is advertising Domain Admin access to an unnamed U.S. company reportedly generating more than $35M in revenue.

    This claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  22. ‼️ New Dark Web Informer Blog Post!

    Title: Armurerie Douillet Data Sale Claim Includes 7,546 Files With Firearms Licence and Identity Documents

    Link: darkwebinformer.com/armurerie-

    💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: darkwebinformer.com/pricing

  23. 🚨🇵🇦 Panama's Caja de Seguro Social Appointment Data Allegedly Exposed

    Approximately 700,000 medical appointment records allegedly belonging to Panama's Caja de Seguro Social (CSS) have been shared on a forum.

    The actor claims access was obtained using default credentials, exposing patient names, national ID numbers, doctors, specialties, appointment dates, and clinic information.

    Claim is currently unverified.

    Infostealer data via @whiteintel_io (X)

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  24. 🚨🇯🇴 Daraghmeh Dataset With 45,000 Records Offered for Sale

    A dataset allegedly belonging to Jordanian clothing retailer Daraghmeh has been offered for sale for $200.

    The actor claims it contains 45,000 records, including names, email addresses, phone numbers, physical addresses, and payment method information.

    Claim is currently unverified.

    Infostealer data via @whiteintel_io (X)

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  25. 🚨🇨🇴 Motos del Oriente Dataset With 207,000 Records Offered for Sale

    A dataset allegedly belonging to Colombian motorcycle retailer Motos del Oriente has been offered for sale for $200.

    The actor claims it contains 207,000 user records, including names, phone numbers, email addresses, physical addresses, and bcrypt password hashes.

    Claim is currently unverified.

    💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  26. 🚨 🇺🇸 Cybersecurity expert charged in alleged $19 million ransomware remediation fraud scheme

    Zohar Pinhasi, 50, the owner of Florida based cybersecurity company MonsterCloud, has been charged with allegedly defrauding businesses seeking help after ransomware attacks.

    Prosecutors say Pinhasi, also known as “Zack Silver” and “Zack Green,” claimed his company could recover encrypted data using proprietary technology without paying attackers.

    Instead, he allegedly negotiated with the cybercriminals, secretly paid their ransom demands and charged clients substantially more.

    In one case, MonsterCloud allegedly paid an attacker about $8,200 before billing the victim approximately $150,000.

    The Justice Department says Pinhasi collected more than $19 million from clients while making over $8 million in ransom payments.

    He was arraigned in Brooklyn on October 7 after being indicted on two counts of wire fraud and one count of wire fraud conspiracy.

    Each count carries a maximum penalty of 20 years in prison if he is convicted.

    Source: justice.gov/opa/pr/known-cyber

  27. FBI Jobs: Opens tomorrow.
    FBI Director: Tomorrow!

    Bro, we get it. 😭

  28. 🚨 Dread admin confirms critical GoBalance zero-day vulnerability behind recent .onion hijackings

    Dread administrator "HugBunter" says a vulnerability in GoBalance allows attackers to derive Tor onion private keys from publicly available service descriptors, potentially enabling them to impersonate legitimate onion services.

    The vulnerability reportedly affects all released versions of GoBalance, with multiple darknet markets also impacted.

    Key points:

    • No Dread server or database compromise, according to the administrator.
    • Attackers can potentially recover onion identity signing capabilities without accessing the server.
    • The attacker reportedly used AI to discover the vulnerability.
    • Dread plans to release a patched version of GoBalance shortly.
    • Dread is working to recover affected onion addresses and redirect users to legitimate services.

    HugBunter also claims the attacker attempted extortion but provided no evidence of possessing Dread's database.

    https://dreadohblesmagfagqup24vw7catlvmqhhce5itz7wxr4vffgemjzaad[.]onion/post/f8c46a6418adcbbbd3da

  29. Verified. New Dread URL: https://dreadohblesmagfagqup24vw7catlvmqhhce5itz7wxr4vffgemjzaad[.]onion

  30. ⚠️ Dread is currently showing a PGP signed message from HugBunter

    "October 7th, 2026

    We are here. We have migrated, permanently, following onion private key exposure due to a vulnerability in third party software, other hidden services are also affected.

    dreadohblesmagfagqup24vw7catlv

    Dread has never been hacked.
    The servers are safe.
    We have not been doxxed.

    - -Hug"

Share on Mastodon

Enter the server where you have an account.