StealthMole: RT by @stealthmole_int: We traced the threat actor behind the defacement of Malaysia's Ministry of Health (MOH) website. Our investigation found that the actor has been active on Telegram since 2024, participating in multiple channels related to hacking forums, web shells, spam, hacking tools, and data leaks.2026-06-29
stealthmole_intbreachMalaysia
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
Daily Dark Web: French Municipal Police Data Allegedly Leaked A threat actor claims to have leaked approximately 4,900 "mains courantes" (police incident reports/logs) belonging to the Municipal Police of Joinville-le-Pont, France. * According to the listing, the actor states the dataset was personally extracted and is offering access through a paid forum.2026-06-28
x-cticampaignFrance
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Clearview Eye Centre2026-06-25
interlockransomwareCanada
Un incidente de ciberseguridad ha afectado a Clearview Eye Centre, una clínica oftalmológica en Calgary, Alberta. Según informaciones recientes, el grupo malicioso "interlock" ha comprometid...
Ido Cohen: We continue to monitor additional sources in the darknet. Here are some of the events that were added to our platform in the last week. 1 A major breach exposed over 500GB of sensitive personal information from job seekers, posing a high risk of identity theft and fraud. 2 Remote access to POS systems is being sold, threatening financial data and sensitive customer information across large retail businesses globally.2026-06-24
ido_cohen2breachUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
CHIFENG GOLD SEPON2026-06-24
thegentlemenransomwareLaos
Una alerta de ransomware ha sido reportada contra CHIFENG GOLD SEPON, una empresa minera líder en Laos que opera en la provincia de Savannakhet. El ataque, atribuido al grupo cybercriminal "...
Coldstat Refrigeration2026-06-23
cmdorganizationransomwareUnited Kingdom
Una empresa de refrigeración industrial, Coldstat Refrigeration, ha sido afectada por un ataque cibernético atribuido al grupo cmdorganization. El incidente ocurrió el 23 de junio de 2026 y ...
Ido Cohen: The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this supply chain incident? And are we witnessing the emergence of a serious competitor to CLOP in the supply chain extortion arena? We'll know more soon.2026-06-23
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: APT73 continues to expand its operations. The group has added 3 new victims to its leak site, including a government entity in South America and a major international airport operator in Central Europe serving tens of millions of passengers annually. APT73 was added to the DarkFeed platform in mid-2024 and has since claimed 110+ victims.2026-06-23
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.