One guy. Global cybercrime. Tracked so you don't have to. Ransomware, data breaches, dark web activity, darknet markets, IOCs & emerging threats. Stay informed!

The Dark Web
‼️ Footage of the LeakBase domain administrator getting arrested in Taganrog, Russia. techcrunch.com/2026/03/25/ru…
35
118
1,111
458,609
Dark Web Informer retweeted
🚨 🇺🇸 Former U.S. soldier "kiberphant0m" sentenced to 70 months for telecom hacking and extortion Cameron John Wagenius, 22, has been sentenced to 5 years and 10 months in federal prison and ordered to pay $294,978 in restitution. ⠀ The Justice Department says Wagenius and his co-conspirators targeted at least 10 organizations and attempted to extort at least $1 million. The activity occurred while he was serving on active duty in the U.S. Army. ⠀ Investigators say the group obtained network credentials using several methods, including a tool called SSH Brute that Wagenius helped develop. They coordinated through Telegram and threatened to publish stolen datasets on BreachForums and XSS. ⠀ In November 2024, Wagenius posted confidential call records belonging to a government official and relatives of another former official, then threatened further disclosures unless a ransom was paid. The records contained call details, not the contents of conversations. ⠀ Some stolen data was also sold and used in other fraud, including SIM-swapping.
7
23
137
15,068
🚨 ShinyHunters resumes mass exploitation of critical Oracle PeopleSoft flaw using simple WAF bypass. Mandiant and Google Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240, also known as ShinyHunters. ⠀ The critical vulnerability allows unauthenticated remote code execution in Oracle PeopleSoft PeopleTools and carries a CVSS score of 9.8. Oracle released an emergency patch on June 10. ⠀ The new campaign targets organizations that attempted to mitigate the flaw using web application firewall rules but did not install the patch. ShinyHunters bypassed rules blocking the vulnerable /PSEMHUB/ endpoint by encoding a single character and sending requests to /%50SEMHUB/. ⠀ Google says web shells were deployed on dozens of systems worldwide across: • Higher education • Technology • IT services • Healthcare • Agriculture • Transportation • Government ⠀ The actors deployed web shells, the SIDEEYE backdoor, Neo-reGeorg tunneling tools and MeshAgent for persistent remote access. Around one-quarter of the observed commands executed with root or SYSTEM privileges. ⠀ Organizations running PeopleSoft should patch immediately, disable or remove the Environment Management Hub where possible and investigate encoded variants of /PSEMHUB/ in access logs. WAF rules alone are not sufficient.
3
8
53
5,468
We good. Added an English speaking carding forum E******. Waiting on a screenshot in the feed for final verification. Update the feed to get updated filters and updated status.
For the next hour you may see shoutbox alerts a little back to back, while I integrate the 30th forum.
1
3,682
Common Dread thread. Dread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/abc1a4a32bff6b39044f
2
8
3,921
For the next hour you may see shoutbox alerts a little back to back, while I integrate the 30th forum.
1
7
5,408
🚨 🇺🇸 Former U.S. soldier "kiberphant0m" sentenced to 70 months for telecom hacking and extortion Cameron John Wagenius, 22, has been sentenced to 5 years and 10 months in federal prison and ordered to pay $294,978 in restitution. ⠀ The Justice Department says Wagenius and his co-conspirators targeted at least 10 organizations and attempted to extort at least $1 million. The activity occurred while he was serving on active duty in the U.S. Army. ⠀ Investigators say the group obtained network credentials using several methods, including a tool called SSH Brute that Wagenius helped develop. They coordinated through Telegram and threatened to publish stolen datasets on BreachForums and XSS. ⠀ In November 2024, Wagenius posted confidential call records belonging to a government official and relatives of another former official, then threatened further disclosures unless a ransom was paid. The records contained call details, not the contents of conversations. ⠀ Some stolen data was also sold and used in other fraud, including SIM-swapping.
7
23
137
15,068
⚠️ HugBunter provides an update on DarkMatter Market, Prime Market, and Torqon/OM vendor shops. Dread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/6a2dd86978003f73c22e
1
3
18
4,802
I'm looking for some PAID OSINT tools. They need to accept crypto as payment. I'm working on some projects (people). Will share any information when it gets to that point. Submit via: darkwebinformer.com/tips/.
5
4,813
🚨 🇺🇸 Kentucky man sentenced to 13 years and 4 months for distributing child sexual abuse material Jacob Murphy, 27, of Harrodsburg, received a 160-month federal prison sentence on September 23. ⠀ The investigation began after Kik reported an account sharing child sexual abuse material in January 2025. Investigators traced the account to Murphy and found additional evidence on his cellphone. ⠀ Murphy admitted knowingly distributing the material, according to the Justice Department.
5
4
29
7,772
🚨 Roundcube SQL injection flaw actively exploited months after patches were released The Canadian Centre for Cyber Security has warned that CVE-2026-48842, a high-severity vulnerability in Roundcube Webmail, is being exploited in the wild. ⠀ Roundcube is an open-source webmail application that lets people access email through a browser. The flaw affects its virtuser_query plugin and allows SQL injection before authentication. ⠀ Key details: • CVSS score: 8.1 • No attacker credentials required • No user interaction required • Affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1 ⠀ Roundcube released the original fixes on May 24, 2026. Canada added the exploitation warning to its advisory on September 21, citing open-source reporting. The advisory does not identify the attackers, victims or scale of exploitation. ⠀ Administrators should update affected installations promptly. Newer security releases, 1.6.19 and 1.7.4, also address additional vulnerabilities.
1
8
35
7,320
🚨 Another actor selling the same VMware vCenter exploit for $40K
👀 🚨 VMware vCenter exploit advertised for $55,000 ⠀ VMware vCenter is used to centrally manage virtual machines and ESXi hosts. ⠀ An actor using the handle "Lalo" is selling a claimed one-day exploit that can reset a vCenter administrator account’s password. The seller claims no public exploit code is available. ⠀ Advertised capabilities include: ⠀ • Python-based vulnerability checking and exploitation • Administrator account takeover with network access • Instructions for resetting ESXi root passwords after compromise ⠀ The asking price is $55,000 plus escrow fees. No CVE identifier or affected versions are provided. ⠀ This claim is currently unverified. ⠀ 💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
3
22
8,124
🚨 🇧🇪 Royal Belgian Chess Federation dataset offered for sale ⠀ The Royal Belgian Chess Federation oversees organized chess and affiliated clubs across Belgium. ⠀ The actor "RedStone" is offering a 2.4 MB JSONL dataset allegedly containing records for 5,914 players across 210 chess clubs. The seller is accepting offers. ⠀ Some of the advertised data includes: ⠀ • Player names, birth years, sex, and federation membership • FIDE and federation identification numbers • Standard, rapid, and blitz ELO rankings • Club contacts, email addresses, and physical addresses • 174 club IBANs ⠀ The post does not explain how the data was obtained. ⠀ This claim is currently unverified. ⠀ 💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
1
5
4,678
Would love to see it obviously, but won't happen. monero:native Dread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/0686f45a5eba45aa71ad
1
14
6,179
🚨 🇺🇸 Approximately 2.56 million SpotAngels records allegedly leaked ⠀ SpotAngels is a crowdsourced parking app that helps drivers locate parking and avoid tickets. ⠀ The actor "GoreTerminal" claims to have breached SpotAngels on September 25, 2026, and released the data for free without demanding a ransom. ⠀ The dataset is advertised as 2.25 GB uncompressed and contains 2,559,907 JSONL records. Some of the claimed data includes: ⠀ • Names and email addresses • IP addresses and device information • Locations and parking activity • Vehicle and booking information • Account preferences and permissions ⠀ The record count does not establish the number of unique people affected. ⠀ This claim is currently unverified. ⠀ 💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
2
8
5,070
A couple updates for the OpSec Failures page... images are being added and adding social links if the person has one so if you want to follow them you can. Still have some things I'm working on.
I still think the OpSec Failures page will be ready sometime next week. Here is an updated look.
1
9
6,113