Elektrine lite

← Feed

DarkWebSonar

darkwebsonar@infosec.exchange

<p>Advanced threat intelligence platform monitoring dark web activity, data breaches, and DDoS attacks.</p>

Posts

  • Post #4498915

    🇮🇹 We tracked a ransomware claim by BravoX listing Verona 83, a transportation and logistics operator in Italy. BravoX has logged 4 listings in the past 30 days, with recent activity spiking to 3 incidents in the last week. #Ransomware #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/bravox-mastodon

  • Post #4458335

    🇮🇶 We tracked a data breach claim by MrDarkRoot naming the Kurdistan Region Ministry of Justice, alleging unauthorized network access and exfiltration of approximately 120,300 personal records from the Ministry, Kurdistan Region Lawyers Foundation, and Khabat Organization. We&#39;ve logged 6 MrDarkRoot incidents in our tracking, with activity concentrated in government and defense sectors. #DataBreach #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/mrdarkroot-mastodon

  • Post #4441071

    🇷🇴 We tracked NoName057(16) claiming unauthorized access to CCTV surveillance at a Romanian nursing home, reporting real-time access to 15 camera feeds covering multiple facility areas. Actor attributes the access to weak security practices. We&#39;ve logged 80 incidents from this actor in the past 30 days. #InitialAccess #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/noname057-16-mastodon

  • Post #4434343

    🇺🇸 We tracked a ransomware claim by INSOMNIA listing Park Place Behavioral Health Care, a mental health and substance use services provider in Florida offering crisis intervention and telehealth services. We&#39;ve logged 2 INSOMNIA listings in the past 30 days. #Ransomware #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/insomnia-mastodon

  • Post #4426080

    We picked up a data-leak claim by Iron Atlas New Generation naming INTERPOL, the international law enforcement organization. The actor claims unauthorized access to an INTERPOL database. We&#39;ve tracked 2 Iron Atlas New Generation listings in the past 30 days across our monitoring. #DataLeak #ThreatIntel This entry + more → https://go.darkwebsonar.io/iron-atlas-new-generation-mastodon

  • Post #4416614

    🇺🇸 We tracked a ransomware claim by INC Ransom listing Virginia Peninsula Regional Jail, a regional correctional facility in Williamsburg, Virginia. We&#39;ve logged 34 INC Ransom listings in the past 30 days, with 12 in just the last week. #Ransomware #Government #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/inc-ransom-mastodon

  • Post #4410982

    🇺🇸 We tracked a ransomware claim by Global Secret Group listing Pavillon, a North Carolina-based substance abuse treatment facility with 100-200 employees. The actor alleges exfiltration of 646 GB of data across 47,950 files. We&#39;ve logged 13 Global Secret Group listings in the past 30 days, mostly targeting manufacturing and financial services. #Ransomware #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/global-secret-group-mastodon

  • Post #4374884

    🇮🇱 We tracked a data breach claim by Cyber Support Front naming IMCO Industries, an Israeli military-industrial company. The actor claims access to approximately 250TB of data, with 30TB exfiltrated including technical documents, production files, and defense contractor information. We&#39;ve logged 7 Cyber Support Front listings in the past 30 days, mostly targeting Israeli entities. #DataBreach #GovernmentDefense #ThreatIntel Details + live feed → https://go.darkwebsonar.io/cyber-support-front...

  • Post #4374445

    Threat actor spotlight: Miyako Here&#39;s an anomaly worth flagging in this initial access broker&#39;s data: China is their second most listed country, behind only the US. That rarely happens. Chinese organizations almost never surface on Western ransomware leak sites, so China ranking this high is a real divergence from the datasets most CTI teams calibrate on. It points to either opportunistic exposure of Chinese edge devices or deliberate inventory diversification, and either way it&#39;s...

  • Post #4348935

    🇦🇷 We tracked a data breach claim by APT IRAN مرکز تحقیقاتی naming six organizations across Argentina, Thailand, France, Indonesia, and Brazil. Stolen data ranges from PII and medical insurance records to government retiree information and municipal records. We&#39;ve logged 2 incidents from this actor in our tracking. #DataBreach #Healthcare #ThreatIntel This entry + more → https://go.darkwebsonar.io/apt-iran-mastodon

  • Post #4270528

    🇺🇸 We tracked a data breach claim by expl0itwastaken listing AdvancedHealth, a Tennessee-based physician group. The actor claims access to over 1.5 million patient records, with a 10,000-line sample posted. We&#39;ve logged 1 incident from this actor in the past 7 days across our monitoring. #DataBreach #Healthcare #ThreatIntel Details + live feed → https://go.darkwebsonar.io/expl0itwastaken-mastodon

  • Post #4246465

    🇪🇸 We tracked a data breach claim by mor3nako listing Instituto Nacional de la Seguridad Social (INSS), Spain&#39;s social security administration. The actor claims a database of over 3.1 million pensioner records in JSON format. We&#39;ve logged 2 mor3nako incidents in the past 30 days across our monitoring. #DataBreach #Government #ThreatIntel This entry + more → https://go.darkwebsonar.io/mor3nako-mastodon

  • Post #4233482

    🇬🇧 We tracked a ransomware claim by CHAOS naming Craneware Group, a UK health-tech firm. CHAOS alleges the breach exposed sensitive data contrary to the company&#39;s public characterization of the stolen information. We&#39;ve logged 4 CHAOS listings in the United Kingdom in our tracking. #Ransomware #Healthcare #ThreatIntel Details + live feed → https://go.darkwebsonar.io/chaos-mastodon

  • Post #4226173

    Carding incidents surged to 388 this week, up 557.6% from the previous 7 days. Financial Services saw the sharpest pressure, climbing to 395 incidents with a 226.4% increase. #Carding #FinancialServices #ThreatIntel

  • Post #4182364

    🇺🇸 We tracked a ransomware claim by SAFEPAY listing BNP Distributing Company, a New York-based distributor serving the restaurant, hotel, and retail sectors. We&#39;ve logged 33 SAFEPAY listings in the past 30 days across our monitoring. #Ransomware #ThreatIntel Details + live feed → https://go.darkwebsonar.io/safepay-mastodon

  • Post #4158253

    🇺🇸 We tracked a ransomware claim by CHAOS naming Vit-Best Nutrition, a US-based nutrition supplier. The actor alleges complete data exfiltration with 3% of data already published and threatens to release the remaining 97% within 48 hours. We&#39;ve logged 14 CHAOS listings in the past 30 days across our monitoring. #Ransomware #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/chaos-mastodon

  • Post #4154232

    We picked up forum user Rici144 allegedly offering webshell access to multiple .edu domain institutions, providing initial access into educational networks. We&#39;ve tracked Rici144 across 12 incidents, mostly in the education and government sectors, with activity spiking recently. #InitialAccess #Education #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/rici144-mastodon

  • Post #4142255

    🇲🇽 We tracked a data leak claim by sc4r_0x00 listing Mexico&#39;s Hidalgo Health Secretariat. The actor claims 14,050 employee records including full names, CURP national ID numbers, tax IDs, positions, and salary information. We&#39;ve logged 5 sc4r_0x00 listings in the last 30 days, mostly targeting government and defense sectors across Mexico and Central America. #DataLeak #Government #ThreatIntel Details + live feed → https://go.darkwebsonar.io/sc4r-0x00-mastodon

  • Post #4132128

    🇮🇩 We tracked a data breach claim by ERROR SYSTEM listing Kudus Regency Government in Indonesia. The actor claims access to a population database and is soliciting $2,500 USD in Bitcoin via Telegram. We&#39;ve logged 11 ERROR SYSTEM listings in the last 30 days across our monitoring. #DataBreach #Government #ThreatIntel This entry + more → https://go.darkwebsonar.io/error-system-mastodon

  • Post #4129072

    🇵🇭 We tracked a data breach claim by XPLOITZ targeting the Philippine Mines and Geosciences Bureau, part of the Department of Environment and Natural Resources. The actor claims to have external documentation of the exploit. We&#39;ve logged 114 XPLOITZ listings in the past 30 days across our monitoring. #DataBreach #Government #ThreatIntel Details + live feed → https://go.darkwebsonar.io/xploitz-mastodon

  • Post #4082940

    🇬🇹 We tracked a data leak claim by sc4r_0x00 listing AUXPMAG, an education organization in Guatemala. The claimed exposure includes debt collection records with national ID numbers, payment data, and location information for over 100,000 teachers. We&#39;ve logged 4 sc4r_0x00 listings in the past 30 days across our monitoring. #DataLeak #Education #ThreatIntel Details + live feed → https://go.darkwebsonar.io/sc4r-0x00-mastodon

  • Post #4079743

    🇺🇸 We tracked a data-leak claim by Golden falcon naming the U.S. Department of Defense. The actor alleges coordinates of multiple U.S. defense systems in the Middle East have been shared with Iranian entities. We&#39;ve logged 1 Golden falcon listing in the past 7 days across our monitoring. #DataLeak #Defense #ThreatIntel Details + live feed → https://go.darkwebsonar.io/golden-falcon-mastodon

  • Post #4068021

    🇲🇽 We tracked a data leak claim by cenfecracked naming Poder Judicial de Michoacán, the judicial branch of Mexico&#39;s Michoacán state. The actor distributed 135 GB via Telegram rather than selling it. We&#39;ve logged 17 cenfecracked incidents in the past 30 days, concentrated in Mexican government and defense sectors. #DataLeak #Government #ThreatIntel This entry + more → https://go.darkwebsonar.io/cenfecracked-mastodon

  • Post #4063257

    🇲🇽 We tracked a data breach claim by homercracker listing CADPE, the Michoacán State Government&#39;s procurement portal in Mexico. The actor claims 58GB+ of data including INE national IDs, fiscal records, and documents tied to government suppliers and contractors. We&#39;ve logged 5 homercracker listings in the past 30 days, all government sector. #DataBreach #Government #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/homercracker-mastodon

  • Post #4057346

    🇮🇩 We tracked a data breach claim by BABAYO EROR SYSTEM targeting sipraja.kuduskab.go.id, the population information system operated by Kudus Regency Government in Indonesia. The actor alleges resident and personal data has been exfiltrated from the regional government entity. We&#39;ve logged 14 incidents from BABAYO EROR SYSTEM in the past 30 days across our monitoring. #DataBreach #Government #ThreatIntel Details + live feed → https://go.darkwebsonar.io/babayo-eror-system-mastodon

  • Post #4054634

    🇵🇭 We tracked a data leak claim by hhhhhaplus naming eight Philippine government agencies including AFP, BFP, PNP, NaPolCom, and SSS. The actor claims access to personnel and pension database records. We&#39;ve logged 12 hhhhhaplus incidents since tracking began, with 2 in the past week. #DataLeak #Government #ThreatIntel Details + live feed → https://go.darkwebsonar.io/hhhhhaplus-mastodon

  • Post #4026370

    Combo List incidents climbed to 2838 this week, up 20.6% from the previous 7 days. The category now accounts for over three quarters of all monitored events. #ComboList #DataBreach #ThreatIntel

  • Post #4011521

    🇧🇴 We tracked a data-leak claim by &#39;SALDIRGAN listing Utepsa University, a higher education institution in Bolivia. The actor claims to have leaked a database containing 67,027 records. We&#39;ve logged 3 &#39;SALDIRGAN listings in the past 30 days across our monitoring. #DataLeak #Education #ThreatIntel Details + live feed → https://go.darkwebsonar.io/saldirgan-mastodon

  • Post #4007149

    🇲🇽 We tracked a data leak claim by homercracker listing SEPyC, the Secretaría de Educación Pública y Cultura in Sinaloa, Mexico. The alleged dataset includes employee personal details, addresses, CURPs, and RFCs distributed via Telegram. homercracker has 4 tracked incidents, all targeting Mexican government entities. #DataLeak #Government #ThreatIntel This entry + more → https://go.darkwebsonar.io/homercracker-mastodon

  • Post #4003472

    🇷🇺 We tracked a data leak claim by BENABDELOHZZ listing an aggregated dataset of 238 million Russian personal records. The data is claimed to include names and dates of birth from FSSP, traffic police, mobile operator, and residency databases covering 1990–2022. We&#39;ve logged 3 BENABDELOHZZ listings in the past 30 days. #DataLeak #Government #ThreatIntel Details + live feed → https://go.darkwebsonar.io/benabdelohzz-mastodon