🔪 Slice For Life 🔪
Відкрити в Telegram
Backup: t.me/SliceForLifeee Website: darkwebinformer.com Website Pricing (Includes Crypto): darkwebinformer.com/pricing Socials: darkwebinformer.com/socials API Access: https://darkwebinformer.com/api-details
Показати більшеСША8 032Категорія не вказана
Немає даних
Підписники
+2924 години
+1807 днів
+84630 днів
Триває завантаження даних...
Схожі канали
Немає даних
Виникли проблеми? Будь ласка, оновіть сторінку або зверніться до нашого support-менеджера.
Хмара тегів
Вхідні та вихідні згадування
---
---
---
---
---
---
Залучення підписників
квітень '26
квітень '26
+237
в 7 каналах
березень '26
+940
в 4 каналах
Get PRO
лютий '26
+302
в 6 каналах
Get PRO
січень '26
+597
в 3 каналах
Get PRO
грудень '25
+1 527
в 1 каналах
| Дата | Залучення підписників | Згадування | Канали | |
| 10 квітня | +18 | |||
| 09 квітня | +29 | |||
| 08 квітня | +25 | |||
| 07 квітня | +21 | |||
| 06 квітня | +55 | |||
| 05 квітня | +33 | |||
| 04 квітня | +11 | |||
| 03 квітня | +9 | |||
| 02 квітня | +11 | |||
| 01 квітня | +25 |
Дописи каналу
Repost from FBI Watchdog Alerts by Dark Web Informer
⚠️ FBI Watchdog - WHOIS Change ⚠️
🔗 DarkWebInformer.com - Cyber Threat Intelligence
Domain: breachforums.ac
Record Type: WHOIS Change
Time Detected: 2026-04-10 17:09:12 UTC
Previous Records:
status: ['ok']New Records:
status: ['ok'] → ['serverdeleteprohibited', 'serverhold', 'servertransferprohibited']
| 2 | ‼️🇲🇽 A threat actor claims to have full access to the financial core of the Secretariat of Finance and General Treasury of the State of Nuevo Leon, Mexico. The data is allegedly being sold on a popular cybercrime forum.
Threat Actor: Z3r00
Category: Data Breach / Access
Victim: Secretaria de Finanzas y Tesoreria General del Estado de Nuevo Leon
Industry: Government / Finance
Country: Mexico
Total Records: 53,000
The data contains:
▪️ Municipio (Municipality)
▪️ Caja (Cash Register)
▪️ Folio
▪️ Fecha (Date)
▪️ Autorizacion del Banco (Bank Authorization)
▪️ Estado (Status)
▪️ Pago Realizado Mediante (Payment Method)
▪️ Nombre (Name)
▪️ RFC (Tax ID)
▪️ Detalle de Cuenta (Account Detail, Tax Type and Company ID)
▪️ Municipio de la Empresa (Company Municipality)
▪️ Importe (Amount)
▪️ Total a Pagar (Total to Pay)
▪️ Sistema (System)
▪️ Firma Electronica / Hash (Electronic Signature)
▪️ Folio Fiscal Digital (Digital Fiscal Folio)
Sample documents showing payment receipts with amounts were included in the post. | 59 |
| 3 | ‼️🇹🇷 The database of Baydoner, a Turkish restaurant chain, has allegedly been leaked on a popular cybercrime forum.
Threat Actor: anonmoose
Category: Data Breach
Victim: Baydoner (baydoner.com)
Industry: Food / Restaurant
Country: Turkey
Date: March 2026
Records: 2M + 1.5M + 201K (many duplicates)
Format: CSV (converted from original SQLite database)
The breach exposed over 1.2M unique email addresses along with names, phone numbers, cities of residence, and plaintext passwords. A small number of records also included Turkish national ID numbers and dates of birth. Baydoner stated that payment and financial data was not affected.
The data includes:
▪️ Emails
▪️ Names/Usernames
▪️ Plaintext Passwords
▪️ Birthdates
▪️ Gender Information
▪️ Partial Addresses
▪️ National IDs
▪️ Phone Numbers
▪️ Purchase Info
Leaked CSV files include records.csv, customers.csv, orders.csv, and phone_counts.csv containing order history, branch details, payment methods, and phone-linked spending totals.
The breach is also listed on haveibeenpwned.com. | 54 |
| 4 | ‼️🇨🇴 The database and client platform access for ETB (Empresa de Telecomunicaciones de Bogota), a Colombian telecommunications company, is allegedly being sold on a popular cybercrime forum.
Threat Actor: Petro_Escobar (in collaboration with NyxarGroup)
Category: Data Breach / Access
Victim: ETB (etb.com.co)
Industry: Telecommunications
Country: Colombia
Price: $500
The data originates from ETB Manizales Colombia (Mobile Sales Data/Access) operated or outsourced by EmergiaCC Customer Case.
The sale includes:
▪️ 1,000,000 sales records
▪️ Full access to the ETB client platform
An attached sample file (Archivo20230602113006987564.xlsx) was included in the post. | 66 |
| 5 | ‼️🇨🇴 The database of Banco de Occidente, one of Colombia's largest and oldest financial institutions, is allegedly being sold on a popular cybercrime forum.
Threat Actor: Petro_Escobar (in collaboration with NyxarGroup)
Category: Data Breach
Victim: Banco de Occidente (bancodeoccidente.com.co)
Industry: Banking / Financial Services
Country: Colombia
Price: $200
The data is categorized as Collection/Penalty records, operated or outsourced by EmergiaCC Conalcreditos Collection Unit.
Databases included:
▪️ Management Universe - Banco de Occidente - OCCIDENTECASTIGOJULIO2021BOGOTA (dated 2026-03-24)
▪️ General Database - Banco de Occidente - OCCIDENTECASTIGOJULIO2021BOGOTA (dated 2026-03-24)
An attached sample file (Matriz-Acuerdos-Por-Cliente-5099.xls) was included in the post. | 66 |
| 6 | ‼️🇪🇸 The database of Helvetia.es (Caser Insurance), a Spanish insurance company, is allegedly being sold on a popular cybercrime forum.
Threat Actor: Jenk
Category: Data Breach
Victim: Helvetia.es / Caser Insurance (helvetia.es)
Industry: Insurance
Country: Spain
The threat actor claims to have been in negotiations with the company for days but they stopped responding. They state that AEPD (Spanish Data Protection Authority) will be notified, alleging the company broke the 72H AEPD notification law. The actor also claims this is not the first time the company has been breached and that they have proof.
The breach also includes all employee users, emails, and internal IDs.
Customer data includes:
▪️ Client Code (codcli)
▪️ NIF (National ID Number)
▪️ Full Names (nombre, apellido1, apellido2)
▪️ Date of Birth
▪️ Age
▪️ Gender
▪️ Marital Status
▪️ Phone Numbers
▪️ Email Addresses
▪️ Physical Addresses (direccion, portal, cp, poblacion, provincia)
▪️ IBAN / BIC (Banking Details)
▪️ Insurance Policy Status
▪️ Registration Dates | 79 |
| 7 | I am in the process of adding an additional 5 forums to the Threat Feed. They should all be implemented by the end of next week. | 112 |
| 8 | ‼️ CardioFit Medical Group, Inc. has submitted a breach notification sample to affected customers.
PDF: https://oag.ca.gov/system/files/4.10.26%20CardioFit%20Patient%20Notification%20Letter.pdf
CardioFit Medical Group is a full-service cardiac, venous, and longevity medicine practice dedicated to prevention, early detection, and patient-centered care. | 175 |
| 9 | ‼️ A new Rust-native info-stealer and post-exploitation framework called "Valkyrie" is being advertised on a popular cybercrime forum, featuring blockchain-anchored C2 and a decentralized log ingestion system.
Threat Actor: thesystemowner
Category: Malware / Stealer / Tool
Name: Valkyrie Stealer Panel
Price: $250 for 3 months
Core Technology:
▪️ 100% Rust (memory-safe, low detection surface, native Windows execution)
▪️ ABE bypass (extracts credentials from browsers and Discord even with Application Bound Encryption)
▪️ Crypter-agnostic (compatible with external crypters)
▪️ Loader recommended for extended campaign longevity
Data Recovery Categories:
▪️ Authentication and Sessions (passwords, cookies, autofill, cards, browser profiles, Discord tokens, Google tokens)
▪️ Wallets and Financials (crypto wallets, FTP/SSH/RDP/VPN credentials)
▪️ Cloud and DevOps (AWS/Azure/GCloud creds, GitHub tokens, Postman, DBeaver, .env files)
▪️ Messaging and Artifacts (Telegram, WhatsApp, Signal, Discord)
▪️ Local Security and Databases (KeePass, Bitwarden, installed apps, running processes, file stealer)
▪️ System Intelligence (history, bookmarks, system info)
Panel Features:
▪️ Multi-language UI (English, Russian, Chinese)
▪️ Tabbed log inspector with advanced filters
▪️ Professional log exporter (forensics-ready)
▪️ Worker role system with scoped panel access
▪️ Real-time notifications via Telegram/Discord webhooks
Infrastructure:
▪️ Decentralized log ingestion (no single point of failure)
▪️ No geolocation blocks
▪️ Blockchain-backed C2 (resistant to domain seizures, DNS takedowns, and hosting bans)
Panel dashboard shows 4,188 total samples, 52 in the last 24 hours, 33,926 credentials, 166 wallets, and 93 unique origins.
Logs from victims across multiple countries including The Netherlands, India, Brazil, Turkey, Poland, Bangladesh, and France are visible. | 179 |
| 10 | ‼️🇬🇧 A dataset allegedly originating from The Student Room (thestudentroom.co.uk), a major UK student community platform, is being sold on a popular cybercrime forum.
Threat Actor: TelephoneHooliganism
Category: Data Breach
Victim: The Student Room (thestudentroom.co.uk)
Industry: Education
Country: United Kingdom
Total Records: 427K
Price: $1,150
The data is organized across 3 main sections:
1. Contacts (student and user contact details):
▪️ Full Names
▪️ Email Addresses
▪️ Phone Numbers
▪️ Dates of Birth
▪️ Physical Addresses
▪️ Nationality
▪️ Social Media Profiles (LinkedIn, Facebook, Twitter)
▪️ Lead Source and Account Tier
▪️ Marketing Opt-in and Contact Preferences
2. Student Enrollment (academic context and enrollment status):
▪️ Faculty, Year of Study, University Name
▪️ Subscription/Payment Plan Details
▪️ GPA, Course Completion Percentage
▪️ Scholarship Details
▪️ Enrollment Channel and Status
3. Subscription and Payment (transactions and billing):
▪️ Payment Method and Transaction IDs
▪️ Billing Addresses
▪️ Invoice Numbers
▪️ Refund Status and Chargeback Flags
▪️ Coupon Codes and Discounts | 147 |
| 11 | Немає тексту... | 127 |
| 12 | ‼️🇰🇪 The database of AfyaRekod, a Kenyan health-tech startup, has allegedly been breached and is being held for $150,000 ransom on a popular cybercrime forum.
Threat Actor: XP95
Category: Data Breach / Ransom
Victim: AfyaRekod (afyarekod.com)
Industry: Healthcare / Health-Tech
Country: Kenya
Total Records: 258,459 patients PII
Ransom: $150,000
Deadline: 30/4/2026
AfyaRekod is a digital health platform that provides patients and healthcare providers secure, real-time access to medical records through a universal electronic health record system using AI and blockchain.
The threat actor states that if the ransom is not paid by the deadline, the data will be edited into a sale listing. | 158 |
| 13 | ‼️ On April 9–10, 2026, attackers compromised a backend API on the CPUID website and replaced the download links for the popular CPU-Z and HWMonitor utilities with trojanized installers.
Users who clicked the official HWMonitor 1.63 download received a suspiciously named file, "HWiNFO_Monitor_Setup.exe," which was flagged by Windows Defender and over 30 VirusTotal vendors as a trojan.
Analysis by @vxunderground revealed that the malware was multi-staged, operated almost entirely in memory, used DLL hijacking via a fake CRYPTBASE.dll, and leveraged PowerShell to fetch additional payloads from command-and-control servers, with evidence it targeted browser credentials stored in Chrome.
CPUID confirmed the breach lasted roughly six hours, stating that a side API was compromised but that their original signed binaries were not tampered with, and that the issue has since been fixed.
Researchers linked the same threat group to a similar campaign targeting FileZilla users in March 2026, suggesting an ongoing pattern of hijacking trusted software distribution channels.
Users who downloaded either tool during this window are advised to scan their systems immediately and rotate any potentially exposed credentials.
https://www.bleepingcomputer.com/news/security/supply-chain-attack-at-cpuid-pushes-malware-with-cpu-z-hwmonitor/ | 145 |
| 14 | ‼️ DOJ Press Release
━━━━━━━━━━━━━━━━━━━━━
Justice Department Settles Lawsuit Challenging Biden State Department’s Alleged Social Media Censorship
Full Press Release → justice.gov
━━━━━━━━━━━━━━━━━━━━━
🕵️ Dark Web Informer • DOJ Monitor | 2 |
| 15 | ‼️🇫🇷 The database of Academie de Nice (ac-nice.fr), a French public education authority, has allegedly been leaked on a popular cybercrime forum.
Threat Actor: ChimeraZ
Category: Data Breach
Victim: Academie de Nice (ac-nice.fr)
Industry: Education / Government
Total Records: 23,850
Size: 8.66 MB
Format: json/jsonl
Breach contains:
▪️ 13,244 fiches (personnel/student records)
▪️ 4,582 agents (staff records) | 161 |
| 16 | Proxy testing creates a temporary Telethon client using your proxy settings and tries to actually connect to Telegram's servers through it, if it connects and can pull your account info, the proxy works. | 187 |
| 17 | 💥 Telegram Scraper with Forwarding has been updated with Proxy Support and Database Search within the script.
https://github.com/DarkWebInformer/telegram-scraper | 181 |
| 18 | ‼️🇲🇽 Actor Z3r00 shared a database containing personal information from Universidad Politecnica de Tapachula including full names, phone numbers, emails, addresses, postal codes, CURP identifiers, and other personal details. | 192 |
| 19 | Cyberattack News Alert
━━━━━━━━━━━━━━━━━━━━━━━━━
Victim: Saver
Domain: saver.nl
Country: 🇳🇱 NL
Date: Apr 9th, 2026
Summary:
L'entreprise de gestion des déchets Saver a été victime d'une cyberattaque dans la nuit du 9 avril, entraînant la mise hors ligne de certains de ses systèmes. Bien que la collecte des déchets se poursuive, l'entreprise subit des restrictions de service, notamment une impossibilité de répondre par téléphone et un accès limité à certaines données. Un groupe de crise a été constitué pour enquêter sur l'ampleur de l'incident en collaboration avec une société de cybersécurité.
Source: https://www.internetbode.nl/bergen-op-zoom/472401/afvalverwerker-saver-getroffen-door-cyberaanval | 221 |
| 20 | ‼️ DOJ Press Release
━━━━━━━━━━━━━━━━━━━━━
Three Family Members Plead Guilty to Smuggling Drugs into Prison
Full Press Release → justice.gov
━━━━━━━━━━━━━━━━━━━━━
🕵️ Dark Web Informer • DOJ Monitor | 93 |
