Elektrine lite

← Feed

DarkWebSonar

darkwebsonar@infosec.exchange

<p>Advanced threat intelligence platform monitoring dark web activity, data breaches, and DDoS attacks.</p>

Posts

  • View post

    🇧🇩 We tracked blacknet-00 claiming unauthorized access to Bangladesh Army network infrastructure at Qadirabad Cantonment. The actor alleges compromise of over 400 devices with access to PPPoE connections, backup files containing passwords, login logs, and router configurations. blacknet-00 has logged 19 incidents in the past week across our monitoring. #InitialAccess #ThreatIntel This entry + more → https://go.darkwebsonar.io/blacknet-00-mastodon

  • View post

    🇺🇸 We tracked a data breach claim by ShinyHunters naming ShipMonk, a shipping and fulfillment provider. The actor alleges theft of a 91GB database containing approximately 239,000 customer records spanning the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. We&#39;ve logged 73 ShinyHunters listings in the past 30 days. #DataBreach #Transportation #ThreatIntel Details + live feed → https://go.darkwebsonar.io/shinyhunters-mastodon

  • View post

    🇺🇸 We tracked a data breach claim by ShinyCorps listing Valley Health Team, a US healthcare provider. ShinyCorps claims the database contains 160,870 patient records, 4.18 million diagnoses, and 7.6 million unencrypted EHR scans. We&#39;ve logged 4 ShinyCorps listings in the past week across our monitoring. #DataBreach #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/shinycorps-mastodon

  • View post

    🇮🇩 We tracked a data breach claim by DBHunter listing Universitas Singaperbangsa Karawang (UNSIKA), an Indonesian university. The actor claims to have accessed a database containing lecturer personal information: names, employee IDs, national ID numbers, study programs, and email addresses. We&#39;ve logged 27 DBHunter listings originating from Indonesia. #DataBreach #Education #ThreatIntel This entry + more → https://go.darkwebsonar.io/dbhunter-mastodon

  • View post

    🇵🇪 We tracked a data breach claim by Frouzenx naming the Government of Peru. The actor alleges a SQL injection attack against government systems with exfiltration of employee records. We&#39;ve logged 13 Frouzenx listings in the past 30 days, concentrated in government and defense sectors across the region. #DataBreach #ThreatIntel Details + live feed → https://go.darkwebsonar.io/frouzenx-mastodon

  • View post

    🇧🇷 We tracked a data leak claim by Synq1xxs naming Brazil&#39;s Receita Federal do Brasil, the Federal Revenue Service. The actor claims roughly 70 million records from the CNPJ registry, including company legal names, CNPJ identification numbers, tax classifications, and location data. Synq1xxs has logged 9 listings in the last 30 days across our monitoring. #DataLeak #Government #ThreatIntel This entry + more → https://go.darkwebsonar.io/synq1xxs-mastodon

  • View post

    🇬🇷 We tracked a data leak claim by &#39;SALDIRGAN listing National Technical University of Athens research infrastructure, alleging a MariaDB database containing 13,905 records. We&#39;ve logged 10 &#39;SALDIRGAN listings in the past 30 days across education and research sectors. #DataLeak #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/saldirgan-mastodon

  • View post

    Threat actor spotlight: The Gentlemen (3/4) One August batch from this group&#39;s leak site: a Swiss security integrator for police and banks, a semiconductor test supplier, a lottery-tech provider, and a small UK construction subcontractor. Not all big names, but every one sits inside someone&#39;s critical supply chain. Manufacturing and construction make up 28% of 610 total claims across 75 countries. Full profile: https://darkwebsonar.io/blog/dark-web-most-wanted-2026-the-gentlemen/ #Thr...

  • View post

    🇧🇴 We tracked a data breach claim by DBHunter listing Universidad Autónoma Tomás Frías, a public university in Bolivia. The actor claims a database of student and applicant records from 2004-2025 containing national ID card numbers, full names, degree programs, and student IDs. DBHunter has 91 listings in the past 30 days across our monitoring. #DataBreach #Education #ThreatIntel This entry + more → https://go.darkwebsonar.io/dbhunter-mastodon

  • View post

    🇮🇱 We tracked a data breach claim targeting the Israeli Government Data Portal (info.data.gov.il). A forum post by a group identifying as Cyber Team Indonesia alleges leaked database content accessible via external file-sharing. NATION OF SAVIORS has 110 incidents in our tracking, with 12 linked to Israel and a focus on Government &amp; Defense targets. #DataBreach #Government #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/nation-of-saviors-mastodon

  • View post

    🇮🇹 We tracked a data leak claim by DaOnlySpark listing LivTours, an Italian-based European tour booking platform. The claimed 1.5GB database includes 295 tables spanning orders, bookings, traveler records, vouchers, payment logs, and marketing data. We&#39;ve logged 12 DaOnlySpark listings in the last 30 days. #DataBreach #Hospitality #ThreatIntel This entry + more → https://go.darkwebsonar.io/daonlyspark-mastodon

  • View post

    🇪🇸 We tracked a data leak claim by updap naming Spain&#39;s Policia Nacional and DNIE (national identity document) systems as victims. The actor alleges certificates were exfiltrated via an HTTP certificate upload server in 2021. updap has 256 listings in our tracking over the past 30 days. #DataLeak #Government #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/updap-mastodon

  • View post

    🇮🇹 We tracked a ransomware claim by BravoX listing Verona 83, a transportation and logistics operator in Italy. BravoX has logged 4 listings in the past 30 days, with recent activity spiking to 3 incidents in the last week. #Ransomware #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/bravox-mastodon

  • View post

    🇮🇶 We tracked a data breach claim by MrDarkRoot naming the Kurdistan Region Ministry of Justice, alleging unauthorized network access and exfiltration of approximately 120,300 personal records from the Ministry, Kurdistan Region Lawyers Foundation, and Khabat Organization. We&#39;ve logged 6 MrDarkRoot incidents in our tracking, with activity concentrated in government and defense sectors. #DataBreach #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/mrdarkroot-mastodon

  • View post

    🇷🇴 We tracked NoName057(16) claiming unauthorized access to CCTV surveillance at a Romanian nursing home, reporting real-time access to 15 camera feeds covering multiple facility areas. Actor attributes the access to weak security practices. We&#39;ve logged 80 incidents from this actor in the past 30 days. #InitialAccess #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/noname057-16-mastodon

  • View post

    🇺🇸 We tracked a ransomware claim by INSOMNIA listing Park Place Behavioral Health Care, a mental health and substance use services provider in Florida offering crisis intervention and telehealth services. We&#39;ve logged 2 INSOMNIA listings in the past 30 days. #Ransomware #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/insomnia-mastodon

  • View post

    We picked up a data-leak claim by Iron Atlas New Generation naming INTERPOL, the international law enforcement organization. The actor claims unauthorized access to an INTERPOL database. We&#39;ve tracked 2 Iron Atlas New Generation listings in the past 30 days across our monitoring. #DataLeak #ThreatIntel This entry + more → https://go.darkwebsonar.io/iron-atlas-new-generation-mastodon

  • View post

    🇺🇸 We tracked a ransomware claim by INC Ransom listing Virginia Peninsula Regional Jail, a regional correctional facility in Williamsburg, Virginia. We&#39;ve logged 34 INC Ransom listings in the past 30 days, with 12 in just the last week. #Ransomware #Government #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/inc-ransom-mastodon

  • View post

    🇺🇸 We tracked a ransomware claim by Global Secret Group listing Pavillon, a North Carolina-based substance abuse treatment facility with 100-200 employees. The actor alleges exfiltration of 646 GB of data across 47,950 files. We&#39;ve logged 13 Global Secret Group listings in the past 30 days, mostly targeting manufacturing and financial services. #Ransomware #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/global-secret-group-mastodon

  • View post

    🇮🇱 We tracked a data breach claim by Cyber Support Front naming IMCO Industries, an Israeli military-industrial company. The actor claims access to approximately 250TB of data, with 30TB exfiltrated including technical documents, production files, and defense contractor information. We&#39;ve logged 7 Cyber Support Front listings in the past 30 days, mostly targeting Israeli entities. #DataBreach #GovernmentDefense #ThreatIntel Details + live feed → https://go.darkwebsonar.io/cyber-support-front...

  • View post

    Threat actor spotlight: Miyako Here&#39;s an anomaly worth flagging in this initial access broker&#39;s data: China is their second most listed country, behind only the US. That rarely happens. Chinese organizations almost never surface on Western ransomware leak sites, so China ranking this high is a real divergence from the datasets most CTI teams calibrate on. It points to either opportunistic exposure of Chinese edge devices or deliberate inventory diversification, and either way it&#39;s...

  • View post

    🇦🇷 We tracked a data breach claim by APT IRAN مرکز تحقیقاتی naming six organizations across Argentina, Thailand, France, Indonesia, and Brazil. Stolen data ranges from PII and medical insurance records to government retiree information and municipal records. We&#39;ve logged 2 incidents from this actor in our tracking. #DataBreach #Healthcare #ThreatIntel This entry + more → https://go.darkwebsonar.io/apt-iran-mastodon

  • View post

    🇺🇸 We tracked a data breach claim by expl0itwastaken listing AdvancedHealth, a Tennessee-based physician group. The actor claims access to over 1.5 million patient records, with a 10,000-line sample posted. We&#39;ve logged 1 incident from this actor in the past 7 days across our monitoring. #DataBreach #Healthcare #ThreatIntel Details + live feed → https://go.darkwebsonar.io/expl0itwastaken-mastodon

  • View post

    🇪🇸 We tracked a data breach claim by mor3nako listing Instituto Nacional de la Seguridad Social (INSS), Spain&#39;s social security administration. The actor claims a database of over 3.1 million pensioner records in JSON format. We&#39;ve logged 2 mor3nako incidents in the past 30 days across our monitoring. #DataBreach #Government #ThreatIntel This entry + more → https://go.darkwebsonar.io/mor3nako-mastodon

  • View post

    🇬🇧 We tracked a ransomware claim by CHAOS naming Craneware Group, a UK health-tech firm. CHAOS alleges the breach exposed sensitive data contrary to the company&#39;s public characterization of the stolen information. We&#39;ve logged 4 CHAOS listings in the United Kingdom in our tracking. #Ransomware #Healthcare #ThreatIntel Details + live feed → https://go.darkwebsonar.io/chaos-mastodon

  • View post

    Carding incidents surged to 388 this week, up 557.6% from the previous 7 days. Financial Services saw the sharpest pressure, climbing to 395 incidents with a 226.4% increase. #Carding #FinancialServices #ThreatIntel

  • View post

    🇺🇸 We tracked a ransomware claim by SAFEPAY listing BNP Distributing Company, a New York-based distributor serving the restaurant, hotel, and retail sectors. We&#39;ve logged 33 SAFEPAY listings in the past 30 days across our monitoring. #Ransomware #ThreatIntel Details + live feed → https://go.darkwebsonar.io/safepay-mastodon

  • View post

    🇺🇸 We tracked a ransomware claim by CHAOS naming Vit-Best Nutrition, a US-based nutrition supplier. The actor alleges complete data exfiltration with 3% of data already published and threatens to release the remaining 97% within 48 hours. We&#39;ve logged 14 CHAOS listings in the past 30 days across our monitoring. #Ransomware #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/chaos-mastodon

  • View post

    We picked up forum user Rici144 allegedly offering webshell access to multiple .edu domain institutions, providing initial access into educational networks. We&#39;ve tracked Rici144 across 12 incidents, mostly in the education and government sectors, with activity spiking recently. #InitialAccess #Education #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/rici144-mastodon

  • View post

    🇲🇽 We tracked a data leak claim by sc4r_0x00 listing Mexico&#39;s Hidalgo Health Secretariat. The actor claims 14,050 employee records including full names, CURP national ID numbers, tax IDs, positions, and salary information. We&#39;ve logged 5 sc4r_0x00 listings in the last 30 days, mostly targeting government and defense sectors across Mexico and Central America. #DataLeak #Government #ThreatIntel Details + live feed → https://go.darkwebsonar.io/sc4r-0x00-mastodon