Threat actors using the aliases PescobarLegado and NyxarGroup claim to be selling internal access and employee data allegedly belonging to ContactMaster BPO, described as a strategic partner of Claro Móvil Colombia.
A threat actor using the alias henrymartin claims to have leaked a database allegedly belonging to La Redoute, a major French multichannel retailer specializing in ready-to-wear apparel and home decor.
A threat actor using the alias yeblan claims to be selling private customer data from an unnamed AI chatting platform, offered in a structured format containing user and customer emails, the last four digits of payment cards, and subscription IDs.
A threat actor using the alias EbonCherub claims to be selling sensitive internal documentation allegedly belonging to MCI, Iran's largest mobile operator, covering systems described as mymci, ewano, shop mci and Developer_asset.
A threat actor using the alias MagoSpeak claims to have leaked a database allegedly belonging to Universidad Tecnológica de la Sierra Hidalguense, a public technological university in Hidalgo, Mexico.
A threat actor using the alias somewhere claims to have leaked a full database allegedly belonging to EduSal, described as a Romanian national educational platform used by teachers, school inspectors, and county education authorities to manage academic records and user accounts.
A threat actor using the alias giorggios claims to be selling 2.8 million records allegedly belonging to Parkingpay, described as the official digital platform widely used for paying and managing parking across Switzerland.
A threat actor using the alias zSenior claims that Ramen Kuroda, a Japanese ramen restaurant chain in the Philippines, suffered a cyber intrusion in May 2026 resulting in the full compromise of its customer database.
A threat actor using the alias sta6 claims to be selling a full source-code and database leak allegedly belonging to Sisplan Sistemas, a Brazilian ERP software house based in Indaial/SC operating since 1996.
A ransomware group is claiming to have collected data allegedly belonging to Mecanizados y Montajes Aeronáuticos, a Spanish aerospace manufacturing company serving major Tier 1 and OEM programs.
A threat actor on an underground forum is claiming to leak databases allegedly belonging to Avea Vacances, a French organization offering holiday camps and educational stays for children and teenagers.
A threat actor on an underground forum is claiming to have leaked a database allegedly belonging to Optic 2000, a French optical retail and eyewear brand.
A threat actor on an underground forum is claiming to have compromised VIPER, an integrated management platform allegedly used by Chilean fire departments.
A threat actor on an underground forum is claiming to auction a customer database allegedly belonging to WisERP, a smart ERP solutions provider for modern businesses.
LiteSpeed User-End cPanel Plugin privilege-escalation vulnerability reportedly exploited in the wild, with potential root-level impact on affected hosting servers.
A threat actor on an underground forum is claiming to leak customer and employee data allegedly belonging to Hillpointe, a U.S. housing development and property management company.
ATOA has been named in a forum leak post involving an alleged database exposure with user, wallet, transaction, instalment, KYC, contact, and invoice records.
Dark Web Informer
Checked
4 hours 47 minutes ago
A real-time cyber threat intelligence platform that monitors the dark web and clearnet for data breaches, ransomware campaigns, darknet market activity, leaked databases, and active threat actors.