A threat actor using the alias authentic claims to be selling a database of 35 million OkCupid users, saying it was scraped after gaining privileged access to the dating app's internal API.
A threat actor using the alias KLINZO007 claims to be selling the full user database of Tayara (tayara.tn), described as the largest online classifieds platform in Tunisia.
A threat actor using the alias an0bixz has publicly released what they claim is a full dataset stolen from BRPDV Ltda., a Brazilian company (brpdv.com.br), after an extortion deadline reportedly expired with no payment.
Live phishing & scam threat intelligence - a real-time mirror of the PhishDestroy blocklist. Scan any domain and browse 150k+ known-malicious sites across crypto, wallet, and brand-impersonation scams.
A federal judge has handed down a sentence of more than 26 years in prison to a California man who used one of the world's largest dark web marketplaces to ship methamphetamine and fentanyl across the country.
A threat actor using the alias macaroni claims to have exfiltrated the full customer CRM of Tradeify, an online trading platform, by abusing a Klaviyo private API key that was reportedly hardcoded in the site's client-side JavaScript.
A threat actor using the alias DNH ("DeathNoteHackersPH") claims to have leaked roughly 10 GB of internal data from Viva Communications, Inc. (Viva Entertainment), one of the largest entertainment conglomerates in the Philippines, via its site viva.com.ph.
CVE-2026-20230 is an unauthenticated, remote server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM SME).
A threat actor using the alias l1ghtSoulHem, posting for "SoulHemTeam," claims to have breached the IEEA (State Institute for Adult Education) in Campeche, Mexico, and leaked a database tied to campeche.inea.gob.mx.
A threat actor using the alias DumpsecV2 ("Dumpsec") claims to be selling a large dataset stolen from Carvivo, a French SaaS provider whose "Carvivo Contact" platform manages automotive sales leads for car dealerships across Europe.
A threat actor using the alias malconguerra2 claims to be selling a confidential dataset attributed to SUNACOOP, Venezuela's national superintendency of cooperatives.
A threat actor using the alias Hermes_Olymp, posting on behalf of "Olympus_Group," claims to have leaked 10,000+ records from the RPP Nayarit, the public property registry of Nayarit state, Mexico.
A threat actor using the alias spain claims to be selling a 109.79 GB customer database stolen from Iberdrola, one of the world's largest electricity utilities, and lists the domain iberdrola.es.
A threat actor using the alias malconguerra2 claims to be selling a 30 GB confidential dataset attributed to SENIAT, Venezuela's national tax and customs authority.
A threat actor using the alias sativa claims to have leaked a database dump attributed to INEGI, Mexico's national statistics institute, allegedly sourced from internal GOB.MX services.
A threat actor using the alias hackformetome claims to be selling persistent web-shell access and a related exploit to a compromised NASA .gov web application, advertising remote code execution and the ability to pivot into internal network ranges.
A threat actor using the alias 2019 claims to have leaked a database allegedly belonging to Hampr, an Australian workplace food and catering management platform used by businesses to organise office meals, corporate catering, pantry supplies, and workplace events.
CVE-2026-39987 is a critical pre-authentication remote code execution flaw in Marimo, a popular open-source reactive Python notebook framework and a modern alternative to Jupyter with roughly 19.6k GitHub stars.
Dark Web Informer
Checked
5 hours 50 minutes ago
A real-time cyber threat intelligence platform that monitors the dark web and clearnet for data breaches, ransomware campaigns, darknet market activity, leaked databases, and active threat actors.