The internet holds vast secrets for those who know how to look

IntelOps retweeted
Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of ShinyHunters, a group linked to cyberattacks in the United States, the Netherlands, and around the world. The Dutch High-Tech Crime Unit arrested the suspect under Dutch law. That's exactly how the "best athlete" model in the new FBI Cyber Strategy is meant to work: the partner with the strongest authority and access leads. The @FBI is grateful to everyone who has assisted us in the ShinyHunters investigation, especially the Dutch National Police and the industry partners who shared information with us.
66
285
1,217
105,444
There is a lot less cats than expected
8
2
28
986
IntelOps retweeted
UPDATE: he was hacked with Pegasus while investigating spyware. He's just sued NSO Group's executives. We @citizenlab found MEP @SteliosKoul's phone was hacked during particularly significant periods of the EU's PEGA committe to investigte spyware abuses. Case adds to NSO Group's growing legal troubles as spyware victims from around the world seek legal remedies. tovima.com/society/kouloglou…
BREAKING: 🇪🇺EU lawmaker investigating spyware abuses was hacked with Pegasus. Infected during key moments of the PEGA committee. More proof that it's spyware open season in Europe.. yet nothing is being done 1/ Our @citizenlab forensic investigation: citizenlab.ca/research/membe…
7
138
270
13,869
IntelOps retweeted
Dutch Authorities have arrested 23-year-old Pepijn van der Stap A/K/A "Umbreon", on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters
31
79
791
50,844
IntelOps retweeted
I asked dozens of ransomware groups one important question, do they like cats, here are the results 🧵👇
69
221
1,476
149,323
IntelOps retweeted
BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use. Notably, Alias 4 (below) was also seen laundering funds from the Kelp DAO $292M exploit earlier this year. I've observed the same pattern after multiple TraderTraitor attributed exploits, and I've closely tracked these groups. I plan to share more of my data on them in coming weeks. Currently, funds are being chain-hopped via bridges and being deposited into mixing services such as Wasabi. Alias 1 - Cc Discord: cc02006 Discord ID: 1351486674386948148 Txn: F08657EFAEAE7B58217CD17A22BF4779582E5D080C2E92E173BC239A5D828363 Alias 2 - jack Discord: jack_34808 Discord ID: 1553705721768714377 Txn: 68583D313A0CCC99F2702D61D05A242A69C86CAE09ED252B65F34B677C377F69 Alias 3 - Melon Discord: under0346 Discord ID: 1394240539108573215 Txn 1: ABE2AEF8B10057E60F8259CA2CA2CD5D71D38D254960FEEE89CB3C95A964873F Txn 2: 7BE290865901DEB1680A6D692A11392D1FDDACA0D31C48F26DCB249F2444BD6B Alias 4 - lolo / Marin TG: pvpcz TGID: 6223514198 Discord: losern Discord ID: 1024415186527985704 Txn: 8E935C19D00F40639B78BF1FD094FE48C92118F3E586AB52DF93851080CCCE15 Alias 5 - HELP ME Discord: helpme031897 Discord ID: 1554035533817188384 Txn: 7C58CAD760EBBED54F2CA4D2146D056910B7B6688B4F524396DC8807353C2379
602
828
6,286
1,530,487
IntelOps retweeted
⚠️ Threat Actor Claims Massive Leak of US Law Enforcement and Intelligence Databases An anonymous threat actor has posted a claim on an underground forum alleging the theft of extensive data from multiple United States federal law enforcement and intelligence agencies. The post, dated September 25, 2026, asserts that the actor possesses "all CIA correspondence from 2000 to the present" as well as classified FBI and Secret Service communications dating back to 2016 and 2019, respectively. According to the listing, the alleged data dump includes highly sensitive materials such as: * Classified White House documents from 2020 to the present * Dossiers on individuals under FBI and CIA surveillance * Complete personnel files for officers handling espionage and counter-espionage cases * Audio recordings of over 700,000 individuals accused of espionage, murder, and cybercrimes * All US police records and data from over 10 million case files The actor provides a link to a website (mrhex.sbs) for viewing "live photos" and a file host link purportedly containing the 10 million case files. No independent verification of these claims has been provided by the Department of Justice, FBI, CIA, or other relevant federal agencies. Claims of such magnitude involving core national security databases are frequently used in phishing scams or as disinformation tactics by unverified actors; however, if authentic, the exposure would represent a catastrophic compromise of US national security infrastructure. At the time of reporting, the alleged breach has not been independently verified. Federal agencies have not issued public statements confirming or denying the incident.
7
15
35
4,397
IntelOps retweeted
For any aspiring hackers, please stay ethical it really isn't worth it.
47
67
1,129
45,751
‼️ A former U.S. Army soldier who stole call and text metadata of over 100 million AT&T customers has been sentenced to 70 months in prison, after it was revealed that while awaiting sentencing he used other inmates' email accounts to have contacts prompt a commercial AI tool for working exploit code. Cameron Wagenius, 22, known online as Kiberphant0m and arrested in December 2024, sought Windows privilege escalation scripts and code for the D-Link flaw CVE-2023-45208, and asked for help researching a prison escape, prosecutors say, though they know of no evidence he deployed any of it. AT&T paid his group a $370,000 ransom, yet he made only around $1,500 selling stolen data.
20
94
692
80,305
IntelOps retweeted
Regarding who is behind the hack: I present to you THE LAZARUS GROUP. just linked this hack to the AFX hack, which stole $24M in July and was specifically attributed to TraderTraitor. The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the AFX hack. Stay smart.
关于攻击原因: 安全团队已初步定位攻击来源。黑客入侵了钱包服务的一个关键后台系统,并利用该系统伪造转账信息、调用授权签名流程,将资金转出。可以排除私钥泄漏的情况——这意味着更恶劣的风险场景已被排除。目前确认止损已完成,平台不存在进一步资金流失的风险。黑客具体入侵手法仍在技术核查中,完整报告将在调查结束后发布。 关于提币恢复: 多组技术团队正在并行推进系统修复与安全加固,提币恢复准备工作同步进行。我们将在有明确时间窗口后第一时间公告,不提前承诺无法兑现的时间。
17
46
288
183,488
IntelOps retweeted
🚨 UNC6671 INFRA UPDATE New root domain: ssosettings[.]com Observed hostnames reference GoDaddy, Teads, ICANN + Upgrade 👀 More pivots to follow. #UNC6671
1
10
38
4,298
IntelOps retweeted
Remember the guy who hacked his gym using AI, Andrew Bird? Well, I did a little OSINT, and it turns out he is the Conference Co-Director of Effective Altruism Global since 2015. Isn't it interesting that every major "AI" hack has been made by people directly connected to Effective Altruism?
NEW: A Melbourne man asked his AI assistant OpenClaw to book a gym class. It found a exploit in the gym website, got around booking restrictions and kicked someone off the waiting list to move him up a spot It's the first known Australian case of AI agents autonomously hacking!
74
365
2,561
173,036
🚨 🇺🇸 Scattered Spider member Ahmed Elbadawy sentenced to 45 months in prison Ahmed Hossam Eldin Elbadawy, a Texas man linked to Scattered Spider, has been sentenced following guilty pleas to wire fraud conspiracy and aggravated identity theft. ⠀ The case involved a phishing operation that targeted company employees and used stolen information to access cryptocurrency accounts. Prosecutors described attacks running from September 2021 through April 2023. ⠀ Employees received text messages impersonating their employer or an IT provider, often warning that their accounts were about to be deactivated. Links directed them to fake login pages designed to capture their credentials. ⠀ CyberScoop reports that the indictment identified at least 12 victim companies and 29 individual victims. One cryptocurrency theft alone was worth nearly $6.35 million. ⠀ The court also reportedly ordered the forfeiture of approximately 175 bitcoin, 1,306 ether or their sale proceeds, along with cash and luxury assets.
16
25
224
26,466
IntelOps retweeted
The Australian Government claims that this constitutes a unique risk. It does not. The same portal that OpenAI is alleged to have scraped has been publicly accessible and independently scraped by members of the public for more than a year. This script was also posted on LinkedIn but it has been subsequently taken down. It fits the bill exactly. github.com/bfiripis/Web-Scra…
Breaking: Anthony Albanese rings up Sam Altman to express "severe concern" after finding out an AI agent hacked into an Australian Medicare data portal in June. Richard Marles says while the impact was "minor" it is a "warning in terms of what can happen" abc.net.au/news/2026-09-24/a…
24
123
658
42,977
Getting lost in the ocean of data? Use advanced filtering to find that single drop 💧 Master the entire process at our live investigation training on 25 September 👇 osint.industries/webinar/lea…
1
5
7
987
IntelOps retweeted
🚨 Possible OPSEC slip in UNC6671 associated infrastructure? A DNS change appears to expose 46.19.136[.]147 (Private Layer INC ) behind numerous myaccountapps[.]com hostnames. 🔎 Misconfiguration or campaign teardown? Intent remains unclear—but the pivot is worth watching. 👀
1
15
63
6,801
IntelOps retweeted
New: from 404 Media. The catastrophic FBI hack also exposed the FBI's own hacking unit. The Remote Operations Unit is a highly secretive part of the FBI, responsible for making tools to break into peoples' devices. Some of their names are in the data 404media.co/fbi-hack-exposed…
52
689
1,916
88,212
Yo, we all gotta talk bout ShinyHunters vs PeopleSoft So let met get this right.. 113 of you said lets pack HR, payroll, finance, procurement, supply chain, student records, employee identities, and every business process with a pulse all into one giant loot piñata with an ugly @Oracle logo stamped on it? Love me a place where their leadership finally discovers "mission critical" means too important to patch, too entangled to isolate, too expensive to replace, and too embarrassing to explain. Congratulations kings. You all running a Threat Actor Costco and gave ShinyHunters an executive membership.
29
84
930
92,676
IntelOps retweeted
ShinyHunters post about a researcher or journalist ruining the experience for everyone: PRESS RELEASE RE PSA We are currently not distributing samples to any media agencies. Furthermore, our policy restricts sharing these materials strictly to established, mainstream agencies. You know who you are. We initially provided samples to a select group of prominent U.S. media organizations solely to verify our claims, mainly operating under the assumption that they would handle the sensitive sample data responsibly. We explicitly told each journalist we shared samples with to NOT share the sample file with others and to explicitly delete the sample data after they complete their assessment. Due to the high sensitivity of this situation, one or more of the journalists involved shared these samples with a security researcher that we are aware of. In our experience, security researchers are both white and blackhats. We believe that security researcher is going to share it with his counterparts. That security researcher has made a YouTube video bragging about how he has the sample data. We keep a strict circle and control over the things we do. Our allegation here is accurate. If the 5,000 sample data records leak, it's not because of us, it's because of any journalist who exercised bad practice and shared it with the security researcher that we are speaking of. We are actively working to figure out which one of the journalists is responsible for sharing such material with unauthorized persons and without our consent. That was very inappropriate for a journalist to do. Because of this we will put a halt to responding to press inquiries. If you are someone with access to the 5,000 samples you are either a journalist or security researcher working a job in the industry. We kindly advise you delete the file immediately. NO FURTHER, EXTRA, OR NEW SAMPLES OF THIS DATA IS IN THE PUBLIC DOMAIN. We redirect all readers and the FBI to our PSA on the right side of your screen on our page. Updated: 24 Sep 2026 #osint #threatintel
15
30
147
14,089