Visualização de leitura

Berlin Ransomware Leak Exposes State Secrets

Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web.

When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out this exact threat against Berlin after local authorities refused to pay a thirty Bitcoin ransom.

At the end of August, Berlin’s state government confirmed it was dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.

Rhysida claimed it stole 5.79 TB of data, covering around 1.44 million files. The alleged dataset includes:

  • Personal data: 12,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs.
  • Sensitive records: more than 5,000 personnel files, more than 5,000 administrative-offence files, payroll data and leadership information.
  • Credentials: plaintext passwords and credentials for systems including GebäudAtlas, the ePayment PAYONE database and Z_ADMIN accounts.
  • Government and legal material: disciplinary proceedings, court cases, supervisory documents, NDA records and Bundesrat committee protocols.
  • Classified information: data related to classified-material handling and documents allegedly containing state secrets.
  • Critical infrastructure: vulnerability analyses concerning Berlin’s water supply.
  • Identity documents: passports and ID cards from personnel records.
  • Other material: contracts, financial documents, HR records, infrastructure files, health data, password stores and SQL/PST archives.

The group also claimed that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS/BSIG requirements. These are Rhysida’s claims and have not been independently verified.

The scale of the breach is staggering. Investigators are now looking at roughly 1.4 million files containing personal details of civil servants, internal infrastructure records, and critical government data.

The fallout goes far beyond routine data theft. Investigative journalist Lars Winkelsdorf pointed out the gravity of the situation on social media.

Die absolute Vollkatastrophe ist eingetreten

Dieses Datenleck ist schlimmer als alle bisherigen Terroranschläge zusammen 1/xhttps://t.co/epU4mCYgew

— Lars Winkelsdorf (@winkelsdorf) September 4, 2026

“In addition to LKA documents related to investigations, the files also include plans concerning national defense—ranging from the federal government’s secret communication channels in the event of an apocalypse to defense-related companies and emergency plans developed by government agencies,” Winkelsdorf wrote.

Exposing crisis response plans and secret communication channels turns a financial shakedown into a national security headache.

Worse still, the leaked material includes files concerning chemical, biological, radiological, and nuclear threats.

“Among the published files is a folder titled “AG CBRN-Rahmenplanung.” CBRN stands for chemical, biological, radiological and nuclear threats,” notes the Euronews report

Having that kind of operational data floating around public forums gives hostile actors a blueprint for disaster.

Refusing to pay ransoms is the right policy, but it rarely stops the bleeding once the network is compromised. Governments keep treating cybersecurity like an IT expense rather than an existential line of defense.

Until boards start treating network segmentation with the same seriousness as physical security, we will keep watching expensive countdown timers tick down to zero.

Berlin’s state government announced the launch of a crisis response after the threat actors published the stolen data.

“A ‌central ⁠crisis unit will oversee the review, verification and assessment of the leaked data and support efforts to inform affected citizens and ​businesses, said the ​city.” Reuters reports.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Berlin)

Dark Web Service Nexus Sells 153M+ Driver’s Licenses

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans.

A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada.

The FBI’s New Orleans field office opened a formal investigation the same day. Brian Krebs at KrebsOnSecurity, who broke the story, traced the source to idscan.net, a New Orleans-based identity verification company whose clients include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and the financial services firm Jack Henry.

“On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.” wrote Krebs. “The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.”

The record total was also increasing by roughly 400,000 per day at the time of publication, which the operators attributed to ongoing active exfiltration from a live breach they claim has been running for over a year.

Krebs found his own driver’s license in the database after a source alerted him to the service. The operators had posted his Virginia license as a free sample on the Russian cybercrime forum Exploit. Each record contains six images of the license, showing the front and back in visible, infrared, and ultraviolet light, with a timestamp. Krebs’ timestamp matched a June 2025 flight and car rental.

He then checked nine friends and relatives, and everyone who found their license confirmed traveling or renting a car around the same date. His license and his mother’s, who rented a Hertz car with him that day, had timestamps just seconds apart.

Security researcher Zach Edwards, whose license also appeared in Nexus, narrowed the source further. His timestamp matched a trip to Las Vegas for DEF CON in August. He hadn’t rented a car, but he had shown his license at a marijuana dispensary: Planet13, a multi-state chain. In 2022, idscan.net published a press release announcing an exclusive identity verification partnership with Planet13’s dispensaries nationally. The company now serves more than 1,000 marijuana dispensaries in 19 states, and its own documentation confirms that its technology scans IDs with both infrared and ultraviolet light, precisely the format of the images appearing in Nexus.

Idscan.net performs more than 21 million verifications per month at more than 20,000 locations globally. Its client list spans car rentals, retailers, hotels, financial services, and dispensaries, which explains both the volume and the geographic spread of the records. The dataset also includes marijuana dispensary cards and records marked with the notation “CAC,” which may refer to Common Access Cards, the government-issued credentials used to enter federal buildings and secure facilities. If confirmed, that would significantly expand the security implications beyond consumer identity theft.

The database reportedly contained the driver’s licenses of U.S. Defense Secretary Pete Hegseth and the FBI’s assistant director, but not FBI Director Kash Patel’s.

Idscan.net said Krebs’ findings would help its internal investigation but gave no further details. The company later said it was working with law enforcement and forensic experts. Soon after the story became public, the Nexus service went offline.

Identity verification systems that require driver’s licenses are spreading sensitive data across an expanding network of third-party vendors, and oversight mechanisms haven’t kept pace. Every bar, hotel, car rental counter, dispensary, and age-verification system that scans an ID is creating a copy of that image in a system whose security posture the cardholder has no way to assess.

The idscan.net incident, if confirmed at the reported scale, would be among the largest exposures of government-issued identity document images ever recorded.

Krebs reports that Nexus shut down after his article, while the FBI opened an investigation after learning that stolen IDs may include licenses belonging to FBI agents.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Nexus)

412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration.

A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. Ransomnews’s analysis confirms the sample is genuine ticket-buyer data from The Town 2025, the São Paulo music festival, though who actually lost the data and how remains unconfirmed.

“The listing is headed “SELLING NEW TICKETMASTER DATABASE” and describes a global ticketing platform, Latin America region, with an internal ticketing database as the source and a breach date of 28 August 2026. It advertises 412,192 rows across 34 columns.” reported Ransomnews. “The country breakdown is dominated by Brazil at 251,557 records, or 61%, with Argentina at 219, Chile 155, Colombia 144, Peru 123 and Paraguay 72, plus nine more countries not itemised.”

The seller is asking $10,000 for the full database, or $80 for every 1,000 records, with escrow available. The 251,557 Brazilian records make up about 61% of the database, meaning the seller is effectively asking around four cents per person.

The data includes names, email addresses, CPF numbers, phone numbers, neighborhoods, ticket types, and payment details. Together, these details provide a detailed profile that could be used for identity theft and fraud.

“The seller’s own notes are the part that should concern Brazilian readers most. Alongside the sales copy, the listing states that the CPF numbers work “for Brazilian bank fraud, loan apps and SIM registration”.” continues the report.”That is not our characterisation of the risk. It is the seller describing the intended use of the file.”

Ransomnews ran the kind of checks that usually expose fake listings within minutes, and this one kept passing. Purchase IDs across the sample rise in strict chronological order, exactly what an auto-incrementing database key produces and something close to statistically impossible to fake by chance. Every CPF number in the sample passes Brazil’s official check-digit validation, phone area codes correctly match the state listed on each row rather than defaulting to a single city, and neighborhood names map precisely onto their stated cities, the kind of granular accuracy a random data generator simply doesn’t produce.

The ticket prices provide another strong sign that the database is genuine. Full-price tickets cost exactly 975 reais, while discounted tickets cost 487.50 reais, matching Brazil’s legal student discount. The database also lists Pix and Elo as payment methods, both widely used in Brazil.

Even the incomplete records look realistic. Complimentary tickets issued by the festival’s back office contain no name or CPF, only the ticket type and date. These kinds of inconsistencies are common in real databases but would be unusual in fabricated data.

However, there is an important detail that challenges the claim of a direct Ticketmaster breach. Every record in the sample has exactly the same processing timestamp: October 1, 2025 at 23:05:41, about two weeks after the festival ended.

A live database dump would normally contain different timestamps. The identical timestamp instead suggests that the data may have been exported in a single batch after the event and then shared with a promoter, sponsor, payment provider, or another partner. Ransomnews therefore warns that blaming Ticketmaster directly would go beyond what the available evidence currently shows.

That distinction matters more than it might seem, because it points at an industry-wide blind spot rather than one company’s failure. Brazilian ticketing requires CPF collection to enforce discount eligibility rules, which means live-events companies routinely end up holding a national identity number, a verified phone, and a home neighborhood for hundreds of thousands of people, data with the sensitivity of a bank record sitting inside an industry with nothing like a bank’s security requirements. The moment that data gets exported into a spreadsheet to reconcile ticket sales with a partner, which happens constantly and rarely makes headlines, it becomes dramatically easier to lose.

“If you bought tickets to The Town 2025, treat your CPF as exposed.” concludes the report. “A CPF cannot be reissued the way a password can, and the seller is explicitly marketing these numbers for credit and telecoms fraud.”

If you bought tickets to The Town 2025, the practical response here isn’t panic, it’s specific vigilance. A CPF can’t be reissued the way a password gets reset, so treat it as permanently exposed and check your credit record through Brazil’s Central Bank registry or services like Serasa for accounts you didn’t open. Watch closely for SIM swap attempts given the seller’s explicit mention of telecom fraud, and be skeptical of any inbound call or message referencing your actual festival purchase, since whoever holds this file knows exactly which days you attended and how you paid, more than enough detail to make a scam call sound completely legitimate.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, The Town 2025)

10 Best Dark Web Monitoring Tools in 2026

Dark web monitoring involves tracking activities on the hidden internet, accessible only via specialized software and configurations.

This shadowy realm hosts illicit markets for stolen data, illegal drugs, weapons, hacking services, and other criminal enterprises.

By scraping intelligence from these anonymous forums, dark web monitoring uncovers emerging threats and vulnerabilities.

It equips organizations and individuals with critical insights into high-risk cyber undergrounds, enabling proactive threat detection, data protection, and safeguarding of brands and assets.

What Is A Dark Web Monitoring Tool?

Dark web monitoring tools track and monitor activity on the dark web, a hidden area of the internet. These technologies strive to cut ways for searching underground forums, markets, and other illicit venues for dangers and threats.

They gather information on data breaches, stolen credentials, unlawful activity, and new cyber dangers. Tools for dark web monitoring offer several options to improve security and shield private data.

They alert enterprises to suspected data breaches by continuously scanning for mentions of compromised data, stolen passwords, or leaking information.

Additionally, these products provide threat intelligence, which keeps businesses updated on new dangers and hackers’ hacking methods.

By proactively monitoring talks and activity on the dark web, organizations can spot hazards to their reputation, fake goods, or unlawful use of their brand.

10 Best Dark Web Monitoring Tools in 2026

  1. Cyble: Utilizes deep web harvesting technology and AI-driven threat intelligence to identify data leaks, compromised credentials, brand risks, and emerging cyber threats.
  2. Recorded Future: Offers real-time threat intelligence, dark web monitoring, and predictive analytics for proactive cyber threat mitigation.
  3. DarkOwl: Extensive dark web data collection and analysis, offering deep insights into cyber threats and illicit activities.
  4. Terbium Labs: Automated dark web monitoring with Matchlight technology to detect and mitigate data exposure and cyber threats.
  5. Flashpoint: Provides business risk intelligence, dark web monitoring, and comprehensive threat analysis to safeguard against cyber threats.
  6. Dark Web ID: Continuous monitoring of dark web activities to detect and respond to data breaches and identity theft.
  7. Cybersixgill: Real-time dark web monitoring and threat intelligence with advanced analytics and automated alerts for proactive defense.
  8. OwlDetect: Monitors the dark web for compromised data, offering alerts and recommendations for mitigating potential risks.
  9. Intel 471: Delivers threat intelligence from the dark web, focusing on cybercriminal activities and emerging threats.
  10. Digital Shadows: Provides comprehensive dark web monitoring, threat intelligence, and risk mitigation with automated alerts and detailed reporting.

Dark Web Monitoring Tools Features

Dark Web Monitoring ToolsFeaturesStand Alone FeatureFree Trial Demo
1. Cyble1. Darkweb & cybercrime monitoring.
2. Stealer log & credential intelligence.
3. Ransomware leak site tracking.
4. Threat actor chatter monitoring.
5. AI-powered risk scoring & compliance reporting.
350B+ darkweb records with analyst-verified, real-time threat intelligence across TOR, I2P, Telegram, and 10,000+ cybercrime forums.Yes
2. Recorded Future1. Real-time threat intelligence.
2. Indicators of compromise (IOCs).
3. Vulnerability management..
4. Attack Surface Monitoring
5. Threat Analysis and Prioritization.
Real-time threat intelligence with extensive dark web monitoring.Yes
3. DarkOwl1. Dark web data collection.
2. Data breach monitoring and alerting.
3. Deep and continuous dark web monitoring.
4. Dark web threat intelligence.
5. Dark web footprint analysis.
Automated dark web data collection and analysis.Yes
4. Terbium Labs1. Data intelligence and monitoring.
2. Data breach detection.
3. Stolen data recovery.
4. Incident Response Support.
5. Customizable Monitoring.
Automated dark web monitoring with data fingerprinting.Yes
5. BrightPlanet1. Deep and dark web monitoring.
2. Threat intelligence analysis.
3. Cybercrime and fraud detection.
4. Insider threat detection.
5. Supply Chain Risk Management.
Business risk intelligence with dark web insights.Yes
6. Intel 4711. Credential monitoring.
2. Stolen data detection.
3. Identity theft prevention.
4. Compromised Credential Detection.
5. Integration with Security Systems.
Continuous dark web monitoring for compromised credentials.Yes
7. OwlDetect1. Underground forums monitoring.
2. Cybercriminal activity tracking.
3. Data Leakage Prevention.
4. Credential Exposure Monitoring.
5. Integration with Security Tools.
Advanced threat intelligence with dark web focus.Yes
8. Cybersixgill1. Attack Surface Monitoring.
2. Cybercrime and fraud detection.
3. Vulnerability management.
4. Insider threat detection.
5. Data breach monitoring and alerting.
Real-time dark web monitoring for personal information.Yes
9. Dark Web ID1. Cybercrime tracking and attribution.
2. Malware analysis.
3. Hacking Group Analysis.
4. Customized Threat Reports.
5. Ransomware Tracking.
Adversary intelligence with dark web monitoring.Yes
10. Digital Shadows
1. Dark web monitoring.
2. Threat intelligence analysis.
3. Digital risk assessment.
4. Vulnerability management.
5. Data Exposure Monitoring.

Comprehensive threat intelligence and digital risk protection.
Yes

1. Cyble

Dark Web Monitoring Tools
Cyble

Cyble is a comprehensive darkweb and cybercrime monitoring platform that combines proprietary AI, NLP, and human intelligence to deliver real-time threat visibility across the deepest layers of the internet for enterprise and government organizations.

The platform continuously scans TOR, I2P, Telegram, Discord, paste sites, ransomware leak sites, and 10,000+ invite-only cybercrime forums to detect threats before they become incidents. It delivers analyst-verified, enriched alerts with risk tags, source screenshots, and remediation guidance — eliminating manual triage entirely.

Additionally, Cyble monitors stealer logs, credential marketplaces, and threat actor chatter, cross-referencing findings against your organization’s digital assets in real time. Compliance reporting is native, with audit-ready dashboards supporting GDPR, PCI-DSS, and HIPAA, requiring zero integration for onboarding.

Features

  • Monitors 350B+ darkweb records across forums, marketplaces, and ransomware leak sites.
  • Utilizes AI-powered NLP classifiers with multilingual threat parsing and contextual risk scoring.
  • Provides stealer log and credential intelligence verified against known breach corpora.
  • Features Telegram, Discord, and encrypted channel monitoring for real-time threat actor chatter.
  • Delivers a fully managed SaaS experience via Cyble Vision console, REST API, CSV, and PDF export.
What is Good?What Could Be Better?
350B+ record corpus depth.Interface has a learning curve.
Analyst-verified, low-noise alerts.Onboarding support varies by tier.
Native compliance reporting.
Broad source coverage across TOR, I2P, Telegram.

Cyble – Trial / Demo

2. Recorded Future

Dark Web Monitoring Tools
Recorded Future

Recorded Future is a comprehensive dark web monitoring tool that leverages machine learning and advanced analytics to provide real-time intelligence on emerging cyber threats.

Recorded Future continuously scans dark web forums, marketplaces, and other hidden networks to help organizations stay ahead of potential security risks.

It integrates with existing security systems, offering seamless threat intelligence and actionable insights.

Its user-friendly interface and robust reporting capabilities enable security teams to identify and respond to threats quickly.

The platform also provides context around the threats, helping to understand the tactics, techniques, and procedures malicious actors use.

Recorded Future’s extensive threat database and predictive capabilities make it an essential tool for proactive cyber defense.

Features

  • Provides real-time, actionable threat intelligence from open, dark, and technical web sources to reduce risk.
  • Uses machine learning and human expertise for context-rich threat analysis and prioritized risk scoring.
  • Offers attack surface monitoring, vulnerability intelligence, and brand protection features.
  • Integrates with security workflows for automated alerting and incident response.
  • Delivers tailored insights through an intuitive dashboard, browser extensions, and extensive third-party integrations.
What is Good?What Could Be Better?
Rich, real-time threat intelligence.Interface can feel complex.
Strong automation and integrations.Premium pricing for full features.
Context-rich risk scoring.Some alerts lack customization.
Wide data source coverage.Occasional false positives.

Recorded Future – Trial / Demo

3. DarkOwl

Dark Web Monitoring Tools
DarkOwl

DarkOwl is a comprehensive dark web monitoring tool that provides organizations with real-time intelligence on emerging threats and data breaches.

It continuously scans the dark, deep, and illicit forums to identify compromised data, including credentials, personal information, and sensitive documents.

DarkOwl’s advanced analytics and machine learning capabilities help detect and prioritize threats, enabling proactive security measures. Its user-friendly dashboard allows for easy access to detailed reports and actionable insights.

DarkOwl’s robust API integrations facilitate seamless incorporation into existing security infrastructures.

By offering continuous surveillance and in-depth analysis, DarkOwl helps organizations mitigate risks and protect their digital assets from dark web threats.

Features

  • Provides comprehensive darknet, deep web, and dark web data collection through automated and authenticated access to a wide range of sources.
  • Enables near real-time monitoring and search with safe, analyst-friendly interfaces and customizable alerts.
  • Supports actionable threat intelligence on credentials, corporate data, malware, and threat actor chatter, including from encrypted chat platforms and hacker forums.
  • Offers powerful querying, entity extraction, and exposure scoring, allowing targeted searches and automated risk assessment for organizations.
  • Seamlessly integrates with enterprise security environments via APIs and data feeds for enriched workflows and automated incident response.
What is Good?What Could Be Better?
Largest, in-depth darknet database.UI good but not outstanding.
Real-time, automated data collection.Learning curve for advanced searches.
Broad source coverage (encrypted chats etc.).Lacks glossy, modern interface features.
Easy integration via API/data feeds.Raw data can require extra analyst work.

DarkOwl – Trial / Demo

4. Terbium Labs

Dark Web Monitoring Tools
Terbium Labs

Terbium Labs is a cybersecurity company specializing in dark web monitoring and threat intelligence. Their flagship product, Matchlight, provides continuous, automated monitoring of the dark web to detect the exposure of sensitive data.

Using advanced data fingerprinting technology, Terbium Labs ensures that clients’ information is protected without ever needing to see the data itself, maintaining privacy and compliance.

The platform delivers real-time alerts and actionable insights, enabling organizations to respond swiftly to data breaches and mitigate risks.

With its user-friendly interface and comprehensive reporting capabilities, Terbium Labs helps businesses safeguard their digital assets against dark web threats.

The company’s innovative approach to dark web monitoring makes it a trusted partner for proactive cybersecurity.

Features

  • Uses patented digital fingerprinting technology to monitor data exposure privately, ensuring sensitive information stays confidential.
  • Provides continuous, automated monitoring across the open, deep, and dark web for signs of data loss, fraud, and misuse.
  • Delivers real-time alerts and actionable intelligence to enable rapid remediation of threats and digital risks.
  • Supports automated detection of compromised credentials, brand abuse, and sensitive data leaks—without requiring the client to reveal their data.
  • Offers a user-friendly platform with precise, low false-positive detection, enabling easy integration into digital risk protection workflows.
What is Good?What Could Be Better?
Unique, patented fingerprinting tech.Lacks experienced technical leadership.
Strong privacy: doesn’t see your data.Product relies heavily on manual analysis.
Near real-time alerting & detection.Leadership sometimes ignores feedback.
Friendly, diverse, flexible culture.Tech is less mature than competitors.

Terbium Labs – Trial / Demo

5. BrightPlanet

BrightPlanet

BrightPlanet is a dark web monitoring tool designed to provide comprehensive insights into the hidden corners of the internet.

Utilizing its Deep Web Harvester technology, BrightPlanet collects and indexes data from various dark web sources, allowing organizations to monitor and analyze potential threats in real time.

This tool offers advanced search capabilities, enabling users to track specific keywords, phrases, or patterns indicative of cyber threats, illicit activities, or sensitive data leaks.

BrightPlanet also integrates with other security platforms to enhance threat intelligence and response strategies.

By focusing on providing actionable insights and detailed reports, BrightPlanet helps organizations proactively protect their assets and mitigate risks associated with dark web activities.

Its robust data harvesting and analysis capabilities make it a valuable tool for cybersecurity professionals seeking to stay ahead of emerging threats.

Features

  • Harvests and structures data from the Surface Web and Deep Web, making unstructured content accessible for advanced research and analytics.
  • Provides customized monitoring and real-time alerts on targeted web sources, blogs, social media, and news feeds relevant to user-defined interests.
  • Enriches collected data with normalization and advanced analytics, enabling deeper insights and pattern recognition across multiple domains.
  • Offers configurable dashboards for visualization, filtering, and alerting, allowing users to synthesize and visualize key intelligence and security data.
  • Supports integration with enterprise workflows and security platforms through flexible deployment options and partnerships, ensuring broad compatibility and scalability for various industries.
What is Good?What Could Be Better?
Excellent surface/deep web coverage.Limited dark web focus.
Strong data structuring & analytics.UI feels outdated.
Custom alerting and monitoring.Initial setup can be complex.
Flexible integration options.Support/updates less frequent.
BrightPlanet– Trial / Demo

6. Intel 471

Intel 471

Intel 471 is a premier dark web monitoring tool that provides real-time cyber threat intelligence from deep and dark web sources.

It monitors cybercriminal activities, including threat actor groups, malware, and vulnerabilities, to deliver actionable insights.

The platform leverages human intelligence and automated data collection to stay ahead of emerging threats. Intel 471 offers detailed threat reports and alerts, helping organizations strengthen their security posture.

Its comprehensive database enables proactive defense strategies by identifying and mitigating potential threats before they impact the business.

Security teams widely use the tool to enhance their threat intelligence capabilities and improve cybersecurity resilience.

Features

  • Provides real-time cybercrime threat intelligence drawn from deep monitoring of the cyber underground to track threat actors and malware operations.
  • Delivers context-rich intelligence on malware, adversaries, compromised credentials, and high-risk vulnerabilities for proactive defense.
  • Offers continuous monitoring of underground marketplaces to identify mentions of your organization, leaked data, or third-party breaches.
  • Integrates via robust APIs and dashboards to operationalize intelligence within existing security workflows.
  • Supports custom reporting and guided threat hunts to address specific intelligence needs, uncover hidden threats, and streamline incident response.
What is Good?What Could Be Better?
Deep coverage of closed cyber sources.User interface needs improvement.
Real-time, actionable intelligence.Threat hunting process can be complex.
Strong, analyst-driven reporting.Learning curve for new users.
Proactive, guided threat hunts.Some manual effort still required.
Intel 471– Trial / Demo

7. OwlDetect

OwlDetect

OwlDetect is a comprehensive dark web monitoring tool designed to help organizations protect sensitive information from being exposed on the dark web.

It scans the dark web for compromised data, including personal information, credentials, and intellectual property.

OwlDetect provides real-time alerts when potential threats or breaches are detected, enabling quick response and mitigation.

The tool features an intuitive interface and detailed reporting, making it easy for users to understand and act on the findings.

OwlDetect helps organizations stay ahead of cyber threats with advanced threat intelligence and proactive monitoring capabilities.

It is suitable for businesses of all sizes, ensuring robust protection of critical assets and data.

Features

  • Delivers threat intelligence on digital artifacts (files, IPs, domains) via a single scalable API for rapid enrichment.
  • Integrates with a wide range of OSINT and malware analysis tools to provide comprehensive, multi-source analysis.
  • Features a user-friendly dashboard and visualizations for efficient data exploration and threat investigation.
  • Enables automation with REST APIs and GUI, streamlining analyst workflows and saving investigation time.
  • Supports customized, real-time queries and analysis at scale for security teams needing detailed threat context.
What is Good?What Could Be Better?
Scans broad dark web sources.UK-centric, less global support.
Alerts for many data types.Manual input of data required.
Fast detection, action plans.No mobile app, only web access.
Simple, low-cost subscription.Limited customization in alerts.
OwlDetect– Trial / Demo

8. Cybersixgill

Cybersixgill

Cybersixgill is a leading dark web monitoring tool that provides real-time insights into underground cyber threats.

It utilizes advanced AI and machine learning algorithms to automatically collect and analyze data from dark web forums, marketplaces, and social media platforms.

Cybersixgill offers actionable intelligence that helps organizations identify and mitigate potential threats before they materialize.

Its comprehensive platform includes threat intelligence feeds, risk analysis, and incident response support.

The tool’s user-friendly interface and customizable alerts enable security teams to stay ahead of cybercriminals.

Cybersixgill helps protect sensitive information and maintain organizational security by continuously monitoring and analyzing dark web activity.

Features

  • Automatically collects and analyzes threat intelligence from clear, deep, and dark web sources in real time for early risk detection.
  • Delivers actionable intelligence covering compromised credentials, vulnerabilities, fraud, phishing, and threat actor activities.
  • Uses AI-driven analysis and reporting to provide context-rich insights and summarizations, including through an integrated 24/7 assistant.
  • Offers specialized modules for attack surface management, identity intelligence, and dynamic vulnerability exploit (DVE) intelligence, including open-source vulnerabilities.
  • Provides seamless integration via dashboards and APIs, supporting alerting, incident response, and workflow automation for security teams and MSSPs.
What is Good?What Could Be Better?
Real-time, comprehensive dark web intel.User interface can be complex/cluttered.
AI-enabled, automated alerting & search.Reporting tools need enhancement.
Wide coverage, including rare sources.More training & better user guidance.
Competitive pricing, strong ROI.Improve integration with 3rd party tools.
Cybersixgill – Trial / Demo

9. Dark Web ID

Dark Web ID

Dark Web ID is a comprehensive dark web monitoring tool designed to help organizations detect and respond to threats from the dark web.

Developed by ID Agent, it continuously scans dark web forums, marketplaces, and data dumps for compromised credentials and sensitive information related to your business.

By providing real-time alerts and detailed reports, Dark Web ID enables proactive threat management and immediate action to mitigate risks.

It integrates seamlessly with existing security frameworks and offers easy-to-use dashboards for efficient monitoring.

Focusing on protecting user identities and corporate data, Dark Web ID helps maintain a security posture and prevent potential breaches.

Suitable for businesses of all sizes, it enhances overall cybersecurity resilience by keeping a vigilant eye on the dark web.

Features

  • Provides 24/7 human and machine monitoring of the dark web for compromised credentials and sensitive data exposure.
  • Delivers real-time, analyst-validated intelligence to identify threats before they escalate and enable rapid response.
  • Covers a wide range of sources, including hidden chat rooms, unindexed sites, P2P networks, and black market sites for comprehensive risk detection.
  • Enables easy integration with SOC, ticketing, and CRM platforms via APIs for streamlined security operations.
  • Supports fast SaaS or API deployment, offering immediate protection and an early warning system for security teams.
What is Good?What Could Be Better?
Easy, fast setup & use.Reports lack customization.
Real-time alerts, quick response.Occasional false positives.
Broad dark web coverage.UI/reporting can be clunky.
Integrates with SOC/ticketing.Long contract terms, costly.
Dark Web ID– Trial / Demo

10. Digital Shadows

Dark Web Monitoring Tools
Digital Shadows

Digital Shadows is a comprehensive dark web monitoring tool that provides organizations with real-time threat intelligence and digital risk protection.

It continuously scans the dark web, deep web, and open sources to identify potential threats and data breaches affecting your organization.

With its extensive coverage and advanced analytics, Digital Shadows helps detect compromised credentials, data leaks, and other malicious activities.

The platform offers detailed reports and actionable insights, enabling security teams to respond promptly to emerging threats.

Digital Shadows integrates seamlessly with existing security systems, enhancing overall threat detection and mitigation capabilities.

Its user-friendly interface and customizable alerts make it a valuable tool for safeguarding digital assets and maintaining organizational security.

Features

  • Monitors and manages digital risk across open, deep, and dark web sources.
  • Provides attackers’ eye view of an organization’s online exposure to identify external threats.
  • Continuously detects data loss, brand impersonation, and sensitive data exposure.
  • Reduces attack surface by highlighting vulnerable assets and suggesting remediation.
  • Delivers actionable threat intelligence with contextual risk analysis for rapid incident response.
What is Good?What Could Be Better?
Easy to use, even for non-experts.Dark web monitoring not industry-leading.
Strong brand/digital risk protection.Take down/removal service can be slow.
Excellent customer support.Initial configuration not very easy.
Wide coverage of online sources.Lacks SMS alerting, reducing reactivity.

Digital Shadows – Trial / Demo

The post 10 Best Dark Web Monitoring Tools in 2026 appeared first on Cyber Security News.

Dark Web Corporate Access Prices Surge 4,055% as Stolen Credentials Flood Cybercrime Markets

Corporate network access is becoming both cheaper to obtain at scale and vastly more valuable at the top end of the criminal market. That contradiction defines the identity threat economy entering 2026: billions of stolen credentials have made basic logins disposable, while verified footholds into large enterprises are being marketed as premium assets for ransomware, […]

The post Dark Web Corporate Access Prices Surge 4,055% as Stolen Credentials Flood Cybercrime Markets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

PNLD Data Breach Exposes Police and Government Contact Details on Dark Web

PNLD data breach

The PNLD data breach has exposed contact information belonging to police officers, government partners, criminal justice professionals and customers after data from the Police National Legal Database (PNLD) was published on the dark web. The data breach at PNLD, identified on July 26, 2026, also affected some users of Ask the Police, raising concerns about targeted phishing attacks. 

PNLD Data Breach Exposes Police and Contact Details 

According to PNLD, the compromised data includes names, organizations and work email addresses of police officers, police staff, criminal justice professionals, government partners and customers. The incident also exposed the names and email addresses of some individuals who had previously submitted questions through Ask the Police. UK government guidance warns that such information could enable attackers to craft more convincing phishing emails targeting named officers and affected individuals.  In its official statement, PNLD said, "There is no evidence to suggest that passwords or other security credentials have been compromised." The organisation clarified that it provides legal information, products and services to UK police forces and criminal justice organisations. It also stressed that PNLD is not the Police National Computer or the Police National Database, is not a crime-recording system, and does not store confidential information relating to victims, witnesses or offenders. 

PNLD Notifies Authorities and Affected Users 

Following the PNLD data breach, the organization said it had contacted all affected organizations and provided additional guidance. Individuals impacted through Ask the Police have also received notification emails with further information PNLD confirmed that it has informed the Information Commissioner's Office (ICO) and is working with the National Crime Agency (NCA) and specialist cybersecurity organizations as the investigation continues.  Its statement noted: "We are continuing to investigate a data security incident affecting the Police National Legal Database (PNLD), which was identified on Sunday 26 July." It added that compromised information had been published on the dark web and reiterated that there is no evidence that passwords or other security credentials were accessed.  Regarding Ask the Police, PNLD said the platform was affected because it is hosted on the same infrastructure, resulting in the publication of some users' names and email addresses. 

Investigation Continues as Key Questions Remain 

As of August 3, 2026, PNLD had not disclosed how many people were affected by the data breach at PNLD, when the intrusion began, how long unauthorized access lasted or the total volume of data obtained. Its public breach notice lists the categories of exposed information but does not include a victim count.  PNLD's 2025-26 annual summary reported 108,429 police registrations and support for all 43 Home Office police forces. However, the organization emphasized that this figure represents its user base and should not be interpreted as the number of people affected by the breach.  The organization's 2023-24 annual summary stated that PNLD uses Microsoft Power Platform technology. On August 3, 2026, The Hacker News reported that the breach notification page referenced assets hosted on Microsoft's content.powerapps.com domain. While this supports the platform connection, it does not indicate how the attackers accessed or extracted the compromised data. 

PNLD Confirms Data Breach Affecting UK Police and Justice Staff

UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating.

The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a data breach exposed the contact details of police officers, staff, and criminal justice professionals and published them on the dark web. The breach also hit Ask the Police, a public Q&A service hosted on the same platform. The National Crime Agency is involved in the investigation.

“Information including the names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web.” reads the notice of data breach. “There is no evidence to suggest that passwords or other security credentials have been compromised.”

UK police is investigating the security breach with the help of the National Crime Agency (NCA) and private cybersecurity firms.

The PNLD reported 108,429 police registrations in its 2025-26 annual summary, which gives some sense of the potential user base affected, though PNLD has not disclosed how many individuals are actually in the breached dataset. No victim count, no timeline of when the intrusion began, no statement on how much data was taken.

“The data security incident primarily affected the Police National Legal Database (PNLD) which hosts the Ask the Police site.” continues the notice. “As a result, some names and email addresses of people who have previously submitted a question to Ask the Police have been published on the dark web.”

Ask the Police is a public-facing service where anyone can submit questions to the police. The exposure of those submitters’ names and emails alongside police officers’ work contact details creates two distinct risk categories: named officers are now more vulnerable to targeted phishing, and members of the public who contacted police services have had that fact made visible on criminal forums.

“PNLD also provides legal information, products and services to UK police forces and criminal justice organisations; it is not a crime recording system and does not hold confidential information relating to victims, witnesses, or offenders.” concludes the notice.

All affected organizations were promptly notified, provided guidance, and the incident was reported to the UK Information Commissioner’s Office (ICO).

The extortion group ExfilSquad listed PNLD on its leak site on July 26, though PNLD has not attributed the incident to the group.

Cybersecurity firm VenariX reviewed samples associated with 11 of ExfilSquad’s 15 claimed victims and found structures consistent with Microsoft Dataverse across all of them, pointing toward a likely campaign pattern involving misconfigured Microsoft Power Pages portals, public-facing sites where overly permissive table access settings can expose data to anyone who visits the page without logging in.

PNLD’s 2023-24 annual summary stated the database uses Microsoft Power Platform technology, and the breach notice page references assets on Microsoft’s content.powerapps.com domain, which corroborates the platform connection. That said, neither PNLD’s notice nor VenariX’s report has confirmed a PNLD-specific endpoint, permission setting, or access route, the Power Pages hypothesis remains exactly that: a hypothesis consistent with the evidence, not a confirmed root cause.

“The reviewed data is most consistent with extraction from public Microsoft Power Pages portals that were configured to allow anonymous users to read Dataverse records.” states VenariX. “Microsoft documents that Power Pages can expose Dataverse tables through its portal Web API using the /_api/<EntitySetName> route, and that access is governed by table permissions assigned through web roles.

A likely flow is:

Public Power Pages portal → Anonymous Users web role → Broad table permission → Power Pages Web API or legacy OData feed → Dataverse data export

For any organization running Microsoft Power Pages: VenariX recommends reviewing Anonymous Users table permissions, Web API settings, and legacy OData feeds, then validating access from an unauthenticated browser session. Microsoft provides a tenant-level control that blocks unauthenticated users from reading Dataverse data while still allowing public form submissions. That’s the kind of configuration that should have been validated before deployment, not after a breach.

Police officers and staff whose details were exposed should be alert to targeted phishing that uses their name, organization, and work email, the exact combination now available on the dark web.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, UK Police)

What&#8217;s your data worth on the dark web? (Lock and Code S07E15)

This week on the Lock and Code podcast…

Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.”

Pithy as the phrase sounds, it is undeniably true.

Data steers decisions at businesses of every size. Data created entirely new industries built around its capture. And, for a select number of companies, data has produced billions—if not trillions—of dollars in value.

So how is it that, on the dark web, your stolen identity can be purchased for just 95 cents?

That’s what a Malwarebytes researcher found last month after spending 48 hours inside the dark web to investigate cybercrime. Across a variety of forums and directories, he found subscription plans for malware that steals information once implanted on a device. He found guides for deploying social engineering scams. He found people selling their services to build fake websites that trick people into handing over their usernames and passwords. And he found one of the dark web’s most traded commodities—personal data, packaged together about individual people, to help a cybercriminal commit identity fraud.

These packages are called “fullz.” For victims in the United States, a fullz contains a full name, Social Security Number, date of birth, address, and other personal details. That is enough, on its own, for a cybercriminal to potentially open a bogus line of credit, file a fake tax return, access financial accounts, or obtain medical services under someone else’s name.

As we wrote on Malwarebytes Labs:

“For less than the cost of a cup of coffee, a cybercriminal can buy enough information to devastate someone’s financial life.”

It’s the kind of risk that could scare anyone, especially considering the scale behind it. In just the first six months of 2026, Malwarebytes found more than 7,500 compromised data sets on the dark web containing more than 8.4 billion records.

And yet, even today, cybersecurity professionals still get asked why anyone should bother protecting their data.

The public, understandably, are exhausted. With data breaches happening every week—if not every day—cybersecurity can start to feel pointless. With young people unable to build financial security, they start believing that they have nothing worth stealing. And with Big Tech already collecting our every movement, behavior, click, and concern, people understandably feel powerless to fight any kind of data abuse, be it corporate or criminal.

So today’s episode approaches the question from a different direction. This isn’t about why you should protect yourself—plenty of company websites will tell you that, and most of them rely on fear. This is about why hackers want your data in the first place.

Today, on the Lock and Code podcast, host David Ruiz explains how cybercriminals turn a single repeated password into account takeover, how a screenshot of your house from Google Maps became a tool in extortion emails, and why the most benign information about you—an address, an age, one public photo—is often the most useful data a stranger can buy.

Tune in today to listen to the full episode.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)


Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.

UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests

What Happened

Nemesis Dark Web Drug Dealers Arrested

  • On 14 May 2026, two Cambridgeshire drug dealers were sentenced after being arrested in July 2024 by the Eastern Region Special Operations Unit (ERSOU).
  • ERSOU officers recovered Royal Mail parcel labels, order lists, Gorgonites-branded packaging, and a USB memory stick containing login credentials for multiple dark web marketplace accounts.
  • The dealers reportedly used the dark web to supply heroin, cocaine, and amphetamine to hundreds of users across the UK.
  • The drug deals were initially arranged via a Telegram channel under the handle Gorgonites, which was linked to at least 570 individual sales on Nemesis Market since September 2023.

AEGIS Dark Web Drug Market Seizure

  • On 17 March 2026, the London Metropolitan Police’s Cyber Crime Unit announced the seizure of AEGIS Marketplace.
  • In June 2025, the Met Cyber Crime Unit became aware of AEGIS Marketplace, which was a site where individual sellers could market drugs for sale to users who could make purchases using cryptocurrency.
  • By March 2026, the website had 30 active sellers and was estimated to have generated 10,000 drug sales in ten months, leading to an estimated annual turnover of almost £2 million.
  • Officers from the Met managed to infiltrate the site, retrieving server data that led to the identification of administrators, sellers and customers.

Online Killers Marketplace (OKM) Admins Arrested

  • On 19 January 2026, two suspects were arrested in Romania as part of an ERSOU investigation into a bogus ‘harm-for-hire’ website which offered services including murder.
  • The arrests were connected to a dark web scam website called Online Killers Marketplace (OKM), which purported to facilitate criminal activities including the hiring of hitmen and extortion.
  • ERSOU noted that even though none of the services OKM offered were genuine, successful prosecutions have previously been pursued by police forces of individuals attempting to use it to cause harm to others.
  • The investigation led to the seizure of US crypto currency worth at least $600,000, as well as cash which included almost €50,000 Euros, and around £48,000 worth of Romanian Leu.

Analyst Comment

The anonymity and connectivity of encrypted messaging apps, the Tor network, cryptocurrency, and online marketplaces makes it nearly impossible to prevent such crime. However, law enforcement can achieve strategic containment by targeting specific infrastructure for seizure and individuals for arrest. These activities support the overall strategy for national law enforcement agencies is to deter criminals from being active in their country.

Telegram is increasingly used as a front-end service for all sorts of cybercrime activities. As seen in the Nemesis investigation, the dealers operated a Telegram channel under the handle Gorgonites to coordinate and funnel buyers toward more secure transactions. It is an easy-to-use mobile application that makes access to such illicit services simple for buyers. It is more accessible than having to download the Tor browser and use a desktop or laptop browser. Many of these illicit services also would not exist without cryptocurrency. The ability to send funds via peer-to-peer networks and obfuscate transactions continues to be the main enabling factor for most cybercrime operations. 

Interestingly, the sole administrator of Nemesis Market was sanctioned in March 2025 by the US Treasury OFAC department. The admin was an Iran-based individual named Behrouz Parsarad. Prior to its takedown by law enforcement in March 2024, Nemesis had over 30,000 active users and 1,000 vendors and facilitated the sale of nearly $30 million USD worth of drugs around the world between 2021 and 2024.

Defensive Takeaways

  • Blockchain Analytics: While cryptocurrency provides a layer of perceived anonymity for illicit markets it also leaves a permanent, public ledger. Law enforcement and threat intelligence firms, such as TRM Labs and Chainalysis, can leverage blockchain analytics to follow the money and deanonymise the administrators. By mapping transaction inputs and outputs, investigators can trace mixed funds, identify exchanges used to cash out into fiat currency, and map the financial infrastructure of a marketplace.
  • Breach Data Pivoting: To catch these cybercriminals, threat intelligence analysts can use historical breach data repositories to pivot from a known dark web alias or leaked credential to find a real-world identity. If an administrator used the same password or a variation of a username on a compromised gaming forum ten years ago, that footprint can blow their operational security (OPSEC).
  • Profile Scraping: Dark web vendors and market admins often leave massive digital footprints across forums, marketplaces, and messaging apps like Telegram. Continuous profile scraping can be achieve via automated bots to collect vendor profiles, feedback ratings, PGP keys, styles of writing (stylometry), and active hours. By aggregating this data over time, defenders can create a comprehensive profile of a target and identify them.
  • Dark Web Market Sock Puppet Accounts: Law enforcement and threat intelligence analysts can deploy sock puppets accounts, which are undercover, synthetic personas, into these dark web ecosystems. These accounts are kept for long periods of time and actively posting in an attempt to build trust within the cybercrime underground. Investigators can use them to buy products, interact with admins, and gain access to private vendor portals or escrow systems to support evidence gathering for a takedown.
  • Infrastructure Analysis: As dark web markets rely on servers, hosting providers, DNS, and Tor is is possible to analyse these attributes and look for configuration mistakes. This can include exposed IP addresses, trackable X509 certificates, or open port banners that reveal the true location of a hidden service. Once a server's true IP is uncovered, law enforcement can issue subpoenas to hosting providers or execute physical raids to seize the hardware and unmask administrators, vendors, and buyer databases.

Relevant Sources

  1. https://www.rocu.police.uk/news/2026/may/dark-web-was-used-to-supply-heroin-and-cocaine-to-hundreds-of-users-across-uk/
  2. https://web.archive.org/web/20260320135505/https://news.met.police.uk/news/met-seizes-website-making-millions-in-drug-sales-507234
  3. https://www.rocu.police.uk/news/2026/january/dark-web-arrests-in-romania-linked-to-portal-which-offered-services-including-murder/

Related CTI Sources

  1. https://home.treasury.gov/news/press-releases/sb0040
  2. https://www.tripwire.com/state-of-security/notorious-nemesis-market-zapped-video-game-loving-german-police

The Dark Web Explained with John Hammond

The dark web is often misunderstood, but it plays an important role in both privacy technology and cybercrime activity. In this episode, Tom Eston speaks with cybersecurity researcher and educator John Hammond about what the dark web actually is and how it has evolved in recent years. The discussion covers underground marketplaces, ransomware leak sites, […]

The post The Dark Web Explained with John Hammond appeared first on Shared Security Podcast.

The post The Dark Web Explained with John Hammond appeared first on Security Boulevard.

💾

Eurail Confirms Security Breach Affecting Over 300,000 U.S. Individuals

Eurail data breach

The Eurail data breach has exposed personal information of approximately 308,777 individuals in the United States, according to a disclosure by Eurail B.V., the Netherlands-based company that manages the official online sales platform for Eurail and Interrail rail passes. Among those affected are 242 residents of New Hampshire. The Eurail data breach occurred between late December 2025 and early January 2026, when an unauthorized actor gained access to Eurail’s network and transferred files. The company identified the issue after detecting unusual activity within its systems and later confirmed the exposure of personal data.

Eurail Data Breach Timeline and Response

Following the detection of suspicious activity, Eurail activated its incident response procedures and initiated an investigation with third-party cybersecurity experts. Law enforcement was also notified and is continuing to investigate the incident. According to the company, the unauthorized access took place on December 26, 2025, when files were transferred from its network. The investigation concluded that these files contained personal information, with the final determination made on February 25, 2026. Eurail began notifying affected individuals and state authorities on March 27, 2026, reporting the breach to attorneys general in California, New Hampshire, Oregon, and Vermont. A public notice was also issued on the European Youth Portal.

Information Compromised in the Eurail Data Breach

The company confirmed that the Eurail data breach involved sensitive personal information, including:
  • Names
  • Passport numbers
While this represents the confirmed data for U.S. individuals, earlier findings suggest that the broader impact may be more extensive. Previous disclosures linked to the incident indicated that additional data types were compromised, including financial and health-related information.

Broader Exposure Linked to Eurail Data Breach

Earlier this year, Eurail confirmed that data from a prior breach was being offered for sale on the dark web, with samples appearing on Telegram. This development suggested that the incident extended beyond initial containment and had evolved into a wider data exposure situation. The earlier dataset reportedly included passport details, bank account IBANs, email addresses, phone numbers, and health information, in addition to names. The combination of such data increases the risk of identity theft, financial fraud, and long-term misuse. The breach is also believed to have affected customers who purchased Eurail or Interrail passes through partner channels, as well as participants in the DiscoverEU program, which issued its own warning that sensitive personal details, including passport copies and financial information, may have been exposed.

Company Measures and Security Actions

In response to the Eurail data breach, the company has taken several steps, including terminating unauthorized access, strengthening internal security measures, and continuing its cooperation with law enforcement and cybersecurity experts. Eurail stated that it takes the protection of customer information seriously and is working to prevent similar incidents in the future. The investigation into the full scope of the breach is ongoing.

What Affected Individuals Should Do

Eurail has advised customers to stay alert to suspicious communications, especially any requests for personal information. Individuals are encouraged not to share sensitive data with unknown or unsolicited contacts claiming to represent the company. The company also recommends that users monitor their financial accounts and review credit reports regularly for any unauthorized activity. In the United States, consumers can obtain a free annual credit report from each of the three major credit bureaus. Those who suspect misuse of their information are advised to contact the Federal Trade Commission, reach out to their state’s attorney general office, and report the matter to local law enforcement.

A Growing Risk Around Travel Data

The Eurail data breach highlights the risks associated with large-scale travel platforms that handle sensitive identity and financial information. With passport numbers and other personal identifiers involved, the exposure can lead to long-term consequences for affected individuals. As investigations continue, the incident reinforces the need for stronger data protection measures and constant monitoring across systems that manage sensitive traveler information.

Google will end dark web reports that alerted users to leaked data

Google began offering "dark web reports" a while back, but the company has just announced the feature will be going away very soon. In an email to users of the service, Google says it will stop telling you about dark web data leaks in February. This probably won't negatively impact your security or privacy because, as Google points out in its latest email, there's really nothing you can do about the dark web.

The dark web reports launched in March 2023 as a perk for Google One subscribers. The reports were expanded to general access in 2024. Now, barely a year later, Google has decided it doesn't see the value in this type of alert for users. Dark web reports provide a list of partially redacted user data retrieved from shadowy forums and sites where such information is bought and sold. However, that's all it is—a list.

The dark web consists of so-called hidden services hosted inside the Tor network. You need a special browser or connection tools in order to access Tor hidden services, and its largely anonymous nature has made it a favorite hangout for online criminals. If a company with your personal data has been hacked, that data probably lives somewhere on the dark web.

Read full article

Comments

© Getty Images | 400tmax

❌