DarkFeed: Cyber Threat Intelligence Platform

DarkFeed: Cyber Threat Intelligence Platform DarkFeed is a Tel Aviv-based cybersecurity startup providing real-time threat intelligence on ransomware, cyber extortion, and dark web activity.

Our platform offers affordable monitoring solutions for businesses of all sizes. Learn more: DarkFeed.io 🚀

🚨 Threat Actor Claims Major Payment Platform Breach — Customer Data & API Keys Allegedly CompromisedDarkFeed has identif...
19/08/2026

🚨 Threat Actor Claims Major Payment Platform Breach — Customer Data & API Keys Allegedly Compromised

DarkFeed has identified a newly published post on an underground cybercrime forum claiming a significant breach involving one of the world's largest online payment infrastructure providers.

According to the threat actor's post, the alleged compromise occurred on August 17, 2026, with the actor describing the release as “Part 1” — potentially indicating that additional data may follow.

The actor claims to possess:

🔹 662 compromised databases
🔹 1,033 API keys
🔹 Approximately 33 GB of data
🔹 688,000 unique customer records

The advertised customer dataset allegedly contains fields including email addresses, full names, first/last names, phone numbers, registration dates, and IP addresses.

The presence of allegedly compromised API keys makes this claim particularly noteworthy, as exposed credentials could potentially create risks beyond the disclosure of customer information depending on their validity, permissions, and associated systems.

At this stage, these claims originate from an underground forum post and should be treated as unverified until independently confirmed.

DarkFeed continues to monitor underground forums, ransomware infrastructure, leak sites, and cybercriminal communities for emerging threats before they become widely reported.

🔎 Want visibility into what threat actors are discussing and selling underground? Track emerging threats with DarkFeed:
darkfeed.io

🚨 ShinyHunters Issues Warning as New High-Profile Victims AppearShinyHunters has published a new warning on its leak sit...
13/08/2026

🚨 ShinyHunters Issues Warning as New High-Profile Victims Appear

ShinyHunters has published a new warning on its leak site, stating that the group is currently experiencing an “influx of volume” and that more leaks are expected to follow.

The message appears primarily directed at organizations currently communicating or negotiating with the threat actors. ShinyHunters warns against delaying negotiations, claims that it holds the leverage, and threatens to immediately publish stolen data when organizations do not cooperate with its demands.

The timing of the message is particularly noteworthy.

Alongside the warning, ShinyHunters has added several high-profile claimed victims spanning healthcare, technology, digital health, and retail/manufacturing.

Among the organizations recently listed are:

🔹 A major privately held U.S. medical device manufacturer headquartered in Indiana, with more than 12,000 employees across its group and medical products distributed in approximately 135 countries.

🔹 A major U.S. global MedTech company providing essential healthcare products, including IV solutions, infusion systems, pharmaceuticals, surgical technologies, patient monitoring and other hospital technologies. Its products are sold across more than 100 countries.

🔹 A widely adopted open-source business intelligence and analytics technology provider. Its platform allows organizations to connect directly to databases, query and visualize information, create dashboards and embed analytics into applications.

🔹 An Atlanta-based digital health company whose technology connects millions of people across the healthcare ecosystem, working with health plans, employers, providers, public-sector organizations and other healthcare stakeholders.

🔹 A well-established American workwear and apparel manufacturer headquartered in Michigan. Founded in 1889, the family-owned company employs thousands of people and has built one of the most recognizable workwear brands in the United States.

The combination of multiple high-profile claimed victims and the group's latest warning may indicate that ShinyHunters is preparing for a broader wave of disclosures.

As always, victim listings and statements published by threat actors should be treated as claims until independently verified.

🔎 Follow ShinyHunters, emerging extortion campaigns, new victims and threat-actor activity in real time with DarkFeed.

darkfeed.io

🔍 **Introducing Ethics — a newly tracked cyber extortion group on the DarkFeed platform.**Our analysts have added **Ethi...
11/08/2026

🔍 **Introducing Ethics — a newly tracked cyber extortion group on the DarkFeed platform.**

Our analysts have added **Ethics** to the platform after identifying activity on its leak site.

At the moment, the group lists **three victims** across **Germany and the United States**, targeting organizations from different industry sectors.

One of the most interesting aspects of Ethics isn't its victim count, but the way it presents itself. Unlike the vast majority of ransomware leak sites, which typically feature polished branding, countdown timers, negotiation portals, and complex layouts, the Ethics website is remarkably minimalistic and simplistic. This unusual presentation makes it stand out from most ransomware and cyber extortion groups currently operating.

Whether this reflects an early-stage operation, a deliberate design choice, or a different operational approach remains to be seen, and we'll continue monitoring the group's activity closely.

🚀 Want to stay ahead of emerging ransomware and cyber extortion groups?

Join us at **https://darkfeed.io**

🚨 Another cyber extortion group joins the DarkFeed intelligence platform.This time, we're tracking SovCali, a newly obse...
09/08/2026

🚨 Another cyber extortion group joins the DarkFeed intelligence platform.

This time, we're tracking SovCali, a newly observed cyber extortion operation.

One aspect that immediately stands out is the group's communication style. Rather than simply listing victims, SovCali publishes unusually detailed summaries describing the categories of information they claim to possess, the scale of the data, and additional contextual details for each victim.

Whether these claims are fully accurate or not, this level of disclosure is relatively uncommon among extortion groups and appears intended to strengthen negotiation leverage by demonstrating familiarity with the allegedly compromised environment.

As always, these claims should be treated as unverified until independently confirmed.

📈 Since the beginning of this month, 8 new ransomware and cyber extortion groups have already been added to the DarkFeed platform.

Want to stay ahead of emerging threat actors?

🔗 https://darkfeed.io

🚨 **CLOP may be entering another large-scale disclosure campaign.**The ransomware group has added **44 new victim entrie...
08/08/2026

🚨 **CLOP may be entering another large-scale disclosure campaign.**

The ransomware group has added **44 new victim entries** to its leak site, with many organization names still partially redacted—an indication that negotiations with several victims are likely still in progress.

According to the group's claims, the affected organizations represent:

• **44 organizations**
• **Approximately $2.87 trillion in combined annual revenue**
• Large volumes of allegedly exfiltrated data, including databases, engineering documentation, CAD files, project repositories, backups, software, blueprints, and internal corporate records.

The sheer number of newly listed organizations, combined with the use of partially concealed identities, may indicate the early phase of a broader disclosure campaign. It is also possible that this activity is linked to a previously undisclosed supply chain compromise, although that has not been confirmed.

If negotiations break down, we may soon see a significant wave of newly identified victims published by the group.

Stay ahead of ransomware activity with real-time intelligence:
🔗 https://darkfeed.io

🚨 Negotiation pressure appears to be increasing.The ShinyHunters threat group has published a new message on its darknet...
08/08/2026

🚨 Negotiation pressure appears to be increasing.

The ShinyHunters threat group has published a new message on its darknet leak site targeting an undisclosed organization, suggesting that negotiations may currently be underway.

According to the group's statement, the alleged compromise includes:

• More than 11.5 million records stored across Salesforce, ServiceNow, and Microsoft Entra, reportedly containing customer and employee personally identifiable information (PII).

• More than 3.1TB of internal corporate data.

The operators have given the organization until August 10, 2026 to establish contact, warning that failure to do so will result in the publication of the stolen data along with additional "digital problems."

While the victim's identity has not yet been disclosed and the group's claims remain unverified, this type of public messaging is a common tactic used by ransomware and cyber extortion groups to increase pressure during ongoing negotiations and encourage payment before data is released.

We'll be closely monitoring this case to see whether the organization reaches an agreement, whether the deadline is extended, or whether the data is ultimately published.

Want to monitor ransomware groups, darknet negotiations, and emerging cyber extortion campaigns as they happen?

Join the DarkFeed Intelligence Platform for real-time threat intelligence.

🌐 https://darkfeed.io

🚨 Ransomware and cyber extortion activity continues to accelerate.Since the beginning of this month alone, the DarkFeed ...
07/08/2026

🚨 Ransomware and cyber extortion activity continues to accelerate.

Since the beginning of this month alone, the DarkFeed Intelligence Team has added seven new ransomware and cyber extortion groups to our intelligence platform.

That's one new threat group every single day—a pace that highlights just how rapidly the cyber extortion ecosystem continues to evolve.

This time, meet Helix.

At the time of analysis, the group's darknet leak site lists approximately six victims, all located in the United States and Canada.

One of the published victims is a global transportation and mobility technology company with annual revenue measured in the tens of billions of dollars, operating one of the world's largest ride-sharing and delivery platforms and serving millions of customers across dozens of countries.

While our analysts continue to monitor Helix's activity, its early victim selection suggests an interest in targeting large, well-established organizations rather than smaller enterprises.

The ransomware landscape is evolving faster than ever—and staying informed has never been more important.

Want to monitor Helix and hundreds of ransomware and cyber extortion groups in real time?

Join the DarkFeed Intelligence Platform for live ransomware tracking, darknet monitoring, and actionable cyber threat intelligence.

🌐 https://darkfeed.io

🚨 The attackers aren't slowing down... and neither are we.Another emerging cyber threat has been added to the DarkFeed I...
06/08/2026

🚨 The attackers aren't slowing down... and neither are we.

Another emerging cyber threat has been added to the DarkFeed Intelligence Platform.

Meet L Group.

At the time of analysis, the group's leak site already lists more than 25 victims spanning multiple countries and a wide range of industries. While our analysts are still in the process of validating and assessing the group's activity, one characteristic immediately caught our attention.

Every organization currently published on the group's leak site reportedly generates annual revenue exceeding $500 million.

That is a highly unusual pattern for a newly emerged ransomware operation. Most new groups initially target organizations of varying sizes while building their reputation. L Group, however, appears to be focusing almost exclusively on large enterprises from the very beginning.

Whether this reflects a sophisticated and capable operation—or simply an ambitious victim selection strategy—remains to be seen. Either way, L Group is certainly a threat actor worth watching closely.

Want to track L Group and hundreds of ransomware and cyber extortion groups in real time?

Join the DarkFeed Intelligence Platform and stay ahead of emerging threats.

🌐 https://darkfeed.io

🚨 More than 100 new ransomware and cyber extortion victims were published in just the last 72 hours.The DarkFeed Intelli...
06/08/2026

🚨 More than 100 new ransomware and cyber extortion victims were published in just the last 72 hours.

The DarkFeed Intelligence Platform tracked over 100 newly published victims across multiple ransomware and cyber extortion operations during the past three days.

The affected organizations span a wide range of industries, including major enterprises, financial institutions, and several government entities.

Among the newly identified government-related victims were:

• A county emergency services agency in the United States responsible for coordinating emergency response, disaster management, and public safety operations.

• A Brazilian federal government organization, highlighting that public sector institutions continue to face persistent cyber extortion activity.

• Two municipal governments in the United States, responsible for delivering local government services and managing city operations for their communities.

• A regional correctional facility in Virginia that provides detention services for multiple jurisdictions, demonstrating that critical public safety organizations remain attractive targets for cybercriminals.

The continued targeting of both public and private sector organizations demonstrates that ransomware operators remain highly active and continue to pursue a broad range of high-value victims worldwide.

Want to monitor ransomware activity in real time and never miss an emerging threat?

Join the DarkFeed Intelligence Platform for live ransomware tracking, darknet monitoring, threat intelligence, and free dashboards.

🌐 https://darkfeed.io

🚨 The day is still far from over for the DarkFeed Intelligence Team.As ransomware groups continue to emerge, we've added...
06/08/2026

🚨 The day is still far from over for the DarkFeed Intelligence Team.

As ransomware groups continue to emerge, we've added another operation to the DarkFeed Intelligence Platform.

Meet Storm.

At the time of analysis, the group's leak site lists approximately six victims, and their targeting pattern is already becoming apparent. Every published victim is located in the United States, indicating that Storm is currently concentrating its operations on a single geographic region.

Beyond the victim list, the group has also launched an affiliate program designed to recruit new operators. In its recruitment material, Storm presents itself as a professional organization offering "global strategic partnerships," claiming to focus exclusively on targets outside CIS countries.

The operators emphasize:

• Expansion of an international affiliate network.
• Strong operational security and confidentiality.
• A professional, service-oriented approach for affiliates.
• Recruitment of experienced operators through direct TOX contact.

While these claims are part of the group's own marketing and should be viewed critically, they illustrate how modern ransomware operations increasingly present themselves as structured businesses in an effort to attract experienced affiliates.

It is still too early to assess Storm's long-term impact, but it is certainly a threat actor worth monitoring closely as its activity develops.

Want to monitor Storm and hundreds of ransomware and cyber extortion groups in real time?

Join the DarkFeed Intelligence Platform and gain access to live threat intelligence, ransomware tracking, darknet monitoring, and free intelligence dashboards.

🌐 https://darkfeed.io

Address

Tel Aviv

Alerts

Be the first to know and let us send you an email when DarkFeed: Cyber Threat Intelligence Platform posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share