Daily Dark Web: French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating from the 2024 Blackout ransomware leak targeting Centre Hospitalier d'Armentières in France. According to the post, the dataset contains information on approximately 203,928 patients, covering records from 2004 through March 2018.2026-06-28
x-ctiransomwareFranceT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Ido Cohen: New Ransomware Group: Settra Settra has entered the ransomware landscape with 10+ published victims already listed on its leak site. Unlike groups that attempt to justify their actions, Settra openly states its motivation is simple: money. The group claims it does not target specific countries or industries—it targets organizations with exploitable security weaknesses.2026-06-27
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
MalwareHunterTeam: RT by @malwrhunterteam: This is some kind of IT security related recruiting ad from the University of Criminal Investigation and Police Studies of Serbia... What are they "analysing"? Looks top or something like that... 2026-06-27
malwrhunterteamcampaignSerbia
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
Ido Cohen: Two ransomware groups are showing a sharp increase in activity during 2026. SafePay Q1 2026: 22 victims Q2 2026: 59 victims (+168%) RALord (Nova) Q1 2026: 14 victims Q2 2026: 60 victims (+329%) Both groups have significantly accelerated their operations in recent months, making them two of the fastest-growing ransomware threats to watch. Track ransomware trends and emerging threat groups with DarkFeed.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
MalwareHunterTeam: List of names: "CamScanner 19-06-2026 16.49.accdr" "Adv Int Course (Rome).accdr" "Expression of Interest (EOI).accdr" "Security Orientation Course-41.accdr" "001210.accdr" "Proposal for Area Admin Meeting - SLNS Barana.accdr" "UN-System-wide-Strategy-on-SSC-2026-2029.accdr" 2026-06-26
malwrhunterteamcampaignUnknown
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
MalwareHunterTeam: A possible interesting, low detected sample that was seen from Italy has @ET_Labs "ET MALWARE Win32/Darkme Trojan Checkin M1" traffic match to that IP address. In case correct, that IP can be related to Evilnum APT... As soon as @smica83 has time, the sample will be uploaded to Bazaar and then anyone can look. cc @marsomx_ @G609309532026-06-26
malwrhunterteammalwareItaly
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
Hackmanac: Cyber Alert ‼ USA - 𝗣𝗼𝗹𝘆𝗺𝗮𝗿𝗸𝗲𝘁 Polymarket confirmed a third-party compromise that enabled attackers to inject malicious code into its website, leading to the theft of user funds. The company contained the incident and will refund affected users. Around the same time, researchers reported a phishing campaign targeting Polymarket users that allegedly stole about US$3 million in cryptocurrency.2026-06-26
H4ckmanacphishingUnited StatesT1566
Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures.
Clearview Eye Centre2026-06-25
interlockransomwareCanada
Un incidente de ciberseguridad ha afectado a Clearview Eye Centre, una clínica oftalmológica en Calgary, Alberta. Según informaciones recientes, el grupo malicioso "interlock" ha comprometid...
Delegal Poindexter & Underkofler, P.A.2026-06-25
morpheusransomwareUnited States
Se ha reportado un incidente de ciberataque relacionado con ransomware afectando a Delegal Poindexter & Underkofler, P.A., una organización especializada en servicios legales. El grupo Morph...
StealthMole: 𝗗𝗮𝘆 𝟮 𝗶𝘀 𝗶𝗻 𝗳𝘂𝗹𝗹 𝘀𝘄𝗶𝗻𝗴 𝗮𝘁 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗣𝗼𝗹𝗶𝗰𝗲 𝗘𝘅𝗽𝗼 𝟮𝟬𝟮𝟲! The best part of an event isn't the presentations. It's the conversations happening in between. Day 2 has been full of great discussions, new connections, and live demos at the StealthMole booth. Thank you to everyone who's stopped by so far! If you're at the expo today, come visit us at 𝗕𝗼𝗼𝘁𝗵 𝗔𝟮𝟯. There's still plenty of time to connect, exchange ideas, and see StealthMole in action.2026-06-25
stealthmole_intcampaignUnited States
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
StealthMole: One thing we've learned from 𝗗𝗮𝘆 𝟭 𝗮𝘁 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗣𝗼𝗹𝗶𝗰𝗲 𝗘𝘅𝗽𝗼 𝟮𝟬𝟮𝟲 The best part of any event isn't the booth. It's the people you meet. Today was filled with conversations, new perspectives, and plenty of great moments with visitors, partners, and friends from across the industry. Thank you to everyone who spent time with us at 𝗕𝗼𝗼𝘁𝗵 𝗔𝟮𝟯.2026-06-25
stealthmole_intcampaignUnited States
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
Ido Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Country Spotlight: Canada Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion attacks targeting Canada.2026-06-25
ido_cohen2ransomwareCanadaT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Group-IB Threat Intelligence: Group-IB telemetry has identified over 62,000 compromised endpoints across more than 160 countries infected with #MilleniumRAT (4.x). The infection velocity is alarming, with over 39,000 of these detections occurring in Q1 2026 alone, representing 64% of all infections. This demonstrates a rapidly accelerating global campaign.2026-06-25
x-cticampaignUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
StealthMole: RT by @stealthmole_int: Following the Money: Mapping KidBin's Cryptocurrency Infrastructure Across Darkweb Note: When visiting this blog, you may see a "Sensitive Content" warning from Blogger. This warning is automatically generated by Google's systems based on the topics discussed on the site and does not necessarily indicate the presence of graphic or inappropriate material.2026-06-24
stealthmole_intcampaignUnknown
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
Ido Cohen: We continue to monitor additional sources in the darknet. Here are some of the events that were added to our platform in the last week. 1 A major breach exposed over 500GB of sensitive personal information from job seekers, posing a high risk of identity theft and fraud. 2 Remote access to POS systems is being sold, threatening financial data and sensitive customer information across large retail businesses globally.2026-06-24
ido_cohen2breachUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.