Dark Web Digest – September 2025 Edition

Dark Web Digest

The dark web is a hidden corner of the internet, as we know. Criminals use it to sell illegal drugs, stolen data, and harmful content. It’s a place where illegal activities can hide from regular law enforcement. In this month, the dark web was in the spotlight. Police took decisive action against crime. Massive data breaches exposed millions of users. Child abuse networks were dismantled. This digest covers eight major stories from August 2025 to September 2025.

Hacker offers to sell 15.8 million plain-text PayPal credentials on dark web forum

On August 18, 2025, a hacker named Chucky_BF offered 15.8 million PayPal credentials for sale. The data included email addresses and plain-text passwords. It was listed on a dark web forum for just $750. The credentials were linked to Gmail, Yahoo, and other email domains. They also included PayPal-specific URLs for web and mobile logins. The data likely originated from infostealer malware, rather than a direct PayPal breach.

This leak poses serious risks. Criminals could use the credentials for fraud, phishing, or account takeovers. PayPal urged users to change passwords and enable two-factor authentication (2FA). Using a password manager can help create strong, unique passwords. Regularly checking account activity is also key.

Germany is a prime target for dark web and ransomware attacks

Germany faced a surge in cyberattacks in August 2025. A SOCRadar report found that 20.68% of compromised data in stealer logs came from Germany. This is almost three times more than Brazil (6.55%) or India (5.62%). Stealer logs are bundles of data stolen by malware. They include sensitive information like passwords and financial details.

The dark web analysis showed 74.6% of threat posts targeted Germany alone. The rest included other countries. Ransomware hit Germany’s manufacturing sector hardest, with 18.15% of attacks. The information sector and IT services were also hit. Germany’s strong economy makes it a prime target. Companies need to prioritize cybersecurity.

Italy: Nearly 100,000 ID scans from hotel guests found on dark web

In August 2025, Italian authorities found 90,600 ID scans for sale on the dark web. The data included passports and ID cards from hotel guests. A hacker named “mydocs” stole the data from hotel systems between June and August 2025. The breach affected 10 hotels in Italy. More could be discovered later.

The Agency for Digital Italy (AgID) detected the sale with help from its cybersecurity team. Stolen IDs can be used for fake documents, bank fraud, or identity theft. The Italian Data Protection Authority has urged hotels to secure their data and inform guests. Hotels were told to use the state’s Alloggiati portal for guest registration.

UK data breach exposes Afghan allies to Taliban threat

In August 2025, a violation of the UK Ministry of Defence leaked data on 7,000 Afghan allies. The data included names, addresses, and photos. It was sold on the dark web. This put the Afghans at risk of Taliban attacks. The breach happened due to a poorly secured server.

The UK launched a secret evacuation plan. But many may not get help or compensation. This shows how dark web leaks can cause real-world harm. Governments must secure sensitive data.

Ex-childcare worker charged for filming explicit images; dark web footprint led to arrest

In August 2025, Australian police arrested David James, a 26-year-old childcare worker in Sydney. He was charged with filming explicit images of 10 children, aged 5 to 6, at six childcare centers from 2021 to 2024. The Australian Federal Police (AFP) found his dark web activity, leading to his arrest. James faces nine counts of producing child abuse material and other charges.

The case shocked Australia’s childcare sector. It followed other abuse scandals, raising calls for stricter rules. The AFP is identifying victims and notifying families. James also worked as a probationary constable, unknown to the police.

Hackers are selling police email accounts for just £4 on the dark web

In August 2025, hackers sold police and government email accounts on the dark web. Prices were as low as £4. Accounts included those from the U.S. Postal Service, the FBI, and the Italian police. Others came from Brazil, Mexico, and Thailand. The seller offered hundreds of accounts with access to investigative tools like license plate databases.

These accounts can be used to send fake legal requests or steal sensitive data. They bypass standard email security. The FBI warned about this trend last year. Governments need to limit account access and monitor connections.

Your kidneys for sale on the dark web! The DaVita ransomware attack affects 2.4 million patients

On March 24, 2025, DaVita, a US hemodialysis company, suffered a ransomware attack. It lasted until April 12. The attack affected 2.4 million patients. Hackers stole names, addresses, Social Security numbers, and health data. This included diagnoses and lab results. Some phone numbers and check images were also taken. The data was sold on the dark web.

The Interlock group claimed responsibility. They’ve hit healthcare before, like Kettering Health. DaVita offered free credit monitoring to victims. Patient care wasn’t disrupted, but the breach poses a risk of fraud.

Police bust dark web paedophile ring spanning three states, suspected mastermind allegedly exploited baby adoption process

On August 29, 2025, Malaysian police dismantled a dark web paedophile ring. The operation, Op Pedo, ran from July 19 to August 19. It spanned Johor, Selangor, and Penang. Police arrested 11 suspects, including a 29-year-old technician believed to be the mastermind. They rescued five children, aged two months to five years.

The main suspect used Facebook to source babies for adoption. He paid mothers RM1,500 to RM3,500 for their babies. He then sold child abuse images and videos on Telegram and the dark web. Police seized phones, hard drives, and documents. The children are now with the Social Welfare Department. This case shows how criminals exploit trust. It calls for better oversight of adoption processes.

August 2025 highlighted the serious threats posed by the dark web—the PayPal breach exposed 15.8 million credentials, risking fraud. Germany’s industries faced heavy ransomware and data theft. Italian hotel hacks leaked 100,000 guest IDs. The UK’s Afghan data breach endangered lives. A Sydney childcare worker was caught using evidence from the dark web. Police email accounts were sold for £4, threatening security. DaVita’s ransomware attack hit 2.4 million patients. A Malaysian paedophile ring was stopped, saving kids. These events prove that the dark web fuels crime. Global law enforcement is fighting back. Individuals must use strong passwords and 2FA. Businesses need audits and backups. Monitoring dark web forums can catch leaks early. The dark web continues to evolve, but robust cybersecurity can mitigate its harm. 

Dark Web Digest – August 2025 Edition

Dark Web Digest - August 2025

In July 2025, several significant events showed how dangerous the dark web can be. Law enforcement fought back with decisive actions. Data breaches exposed millions of people. Child abuse networks were undone. This August month’s 2025 digest will discuss the impact of dark web attacks and explore how to stay safe against them in the future. 

Justice Department shuts down dark web child abuse sites

On July 28, 2025, the U.S. Justice Department launched Operation Grayskull. This major operation targeted four dark websites sharing child abuse material. These sites had a combined 120,000 members. They hosted millions of illegal images and videos. The operation was a success. Authorities seized the sites’ servers. They arrested a key administrator, who was sentenced to 20 years in prison.

Justice Department

The FBI led the effort. They worked with Europol and police from other countries. Advanced tracking technology helped find these hidden sites. Operation Grayskull sent a clear message: child exploitation will not be tolerated. The dark web makes these crimes hard to trace. But global cooperation is making a difference. Parents, teachers, and communities must stay alert. Signs like secretive behavior or fear in children could point to online grooming. 

Leak Zone breach exposes 22 million user records

On July 18, 2025, cybersecurity firm UpGuard discovered a major breach at Leak Zone, a notorious dark web forum. An unprotected Elasticsearch database exposed 22 million web request records. About 95% of these were linked to leakzone[.]net, a platform for trading hacking tools and stolen accounts. The database included sensitive user data, such as IP addresses, geographic locations, and internet service provider details. This created a detailed map of user activity on the illegal site.

The breach covered three weeks of data, from June 25 to July 18, 2025. It logged about one million requests daily, with a median size of 2,862 bytes. The database revealed 185,000 unique IP addresses, far more than Leak Zone’s 109,000 registered users. This suggests users employed privacy tools like VPNs and proxies. About 5% of requests (1.37 million records) came through public proxies. Many others used VPN services, especially Cogent Communications. However, 39% of IPs appeared only once, likely unprotected users.

PayPal credentials leak sparks major security concerns

A massive data breach hit PayPal users on July 15, 2025. A hacker, known as Chucky_BF, claimed to sell 15.8 million PayPal credentials. The data included emails and plain-text passwords. It was listed for just $750 on a dark web forum. The leak likely came from infostealer malware. This software infects devices and steals sensitive information.

PayPal said its systems weren’t directly hacked. The data was linked to a 2022 breach. But the sale still poses a significant risk. Criminals can use these credentials to access accounts. 

PayPal Data Breach

Abacus Market shuts down in suspected exit scam

On July 24, 2025, Abacus Market went offline. It was the largest Western dark web marketplace. The site sold illegal drugs, stolen data, and hacking tools. It used Bitcoin for secure payments. Experts believe the shutdown was an exit scam. This means the site’s owners likely stole users’ funds and disappeared. Vendors and buyers lost millions of dollars.

The abacus was known for its strong security. It used PGP encryption and two-factor authentication. But even these couldn’t protect users from the scam. Exit scams are common on the dark web. They show how risky these markets are, even for criminals. When Abacus closed, other sites like Russian Market gained users.

UK data breach exposes Afghan allies to Taliban threat

In July 2025, a UK Ministry of Defence breach exposed sensitive data. It involved 7,000 Afghans who worked with British forces. The leaked information included names, addresses, and photos. This data was offered for sale on the dark web. The breach put these individuals at serious risk. The Taliban could target them for revenge.

The UK government acted quickly. They launched a secret evacuation plan to protect those affected. However, many may not receive help or compensation. The breach happened due to a poorly secured server. 

Qilin ransomware group escalates dark web attacks

The Qilin ransomware group stepped up attacks in July 2025. They targeted hospitals, media companies, and government agencies. They stole sensitive data and sold it on the dark web. Qilin also offered legal support to its affiliates. This helped them pressure victims to pay large ransoms. In April 2025, they hit 72 targets. In May, they attacked 55 more. Their activity grew in July.

qilin

Qilin took advantage of gaps left by other groups like LockBit. They used advanced malware bought on dark web markets. Their attacks caused chaos. For example, hospitals lost access to patient records. Businesses faced huge financial losses. For safety, companies need regular backups and strong security as well as Governments must track these groups closely.

Russian Market emerges as top cybercrime platform

On June 16, 2025, the Russian Market became a leading dark web platform. It specializes in selling stolen credentials. These come from social media, banking, and email accounts. The data is stolen by infostealer malware like RedLine and Vidar. Prices are very low. Credit card details sell for as little as $10. This makes the market popular among criminals.

The site organizes data by device and region. This helps buyers target specific victims. It fuels cybercrime across the globe. Police are monitoring the platform. But it’s hard to shut down.

Workday data breach linked to dark web sales

On July 15, 2025, Workday reported a data breach. Hackers accessed a third-party CRM system. They stole names, emails, and phone numbers. The data was put up for sale on the dark web. Workday provides HR services to many businesses. 

Workday alerted its customers. They advised monitoring accounts for suspicious activity. The breach highlights the risks of third-party systems. These can be weak links in a company’s security. Regular audits and strong protections are needed. This incident shows how dark web sales can harm businesses. Companies must act fast to secure their networks and prevent data leaks.

These events prove the dark web is a significant threat. Law enforcement is fighting back with global cooperation. But individuals and organizations must take action too. Strong, unique passwords are essential. Two-factor authentication adds extra protection. Companies need robust cybersecurity, including regular backups and audits. Monitoring accounts and dark web forums can catch problems early. 

Dark Web Digest – June 2025 Edition

Dark Web digest June 2025

In May 2025, several significant incidents highlighted the dark events in the online world and the steps taken by various countries to address these issues. This June 2025 digest provides a comprehensive report of recent news events, including police raids, data leaks, political decisions, and child security issues on the dark web. 

Violent online networks like 764 show how terrifying the Dark Web is for young children.

Thus, the dark web is a serious threat to kids, just as violent online networks like “764” are exploiting kids in unbelievable ways. The “764” network, which was born in 2020, is a gang of bullies who seek kids and teens on gaming platforms, social media, and self-help forums. With bullying methods, the members of the gang force their victims to do some evil actions like cutting occult signs or abuser names on their skins (which is the so-called “fansigning”), making porn videos, hurting pets, broadcasting their suicides, or even doing self-harm. 

The victims who decide to reject will be chased by doxing, swatting, blackmail, or extortion. This gang has been the subject of an incident of violence in the physical world. The violence includes school shootings. For example, a 17-year-old boy named Solomon Henderson, who was influenced by the 764 and nihilistic extremism, shot a student in Antioch, Tennessee, in January 2025. Or, another example is Natalie Rupnow, who, being connected to related online forums, killed two classmates in Madison, Wisconsin, in December 2024.

Child Porn

Other cases include a 13-year-old girl in Arizona who was exploited to force her to carve symbols and swastikas by a 764-member group, and minors in California who were blackmailed to commit torture rituals. A 15-year-old girl from Eastern Europe, who was a victim of the crime at first, then became its recruiter and got a man from Minnesota to convince her to do the self-immolation on a live stream. More than 500 cases have been uncovered in the past three years, which highlights the magnitude of this menace. The authorities reacted, with the FBI and NYPD arresting two suspects, one in North Carolina and the other in Greece, who are allegedly the leaders of the situation. A 764-member in Kentucky also admitted in court that he was planning to kill a minor. The FBI’s Joint Terrorism Task Force is operating worldwide to inform the authorities and train school officials in what to look out for, such as cutting, isolation, or the making of a bomb threat.

Case Location Details Outcome
Solomon Henderson Antioch, TN Killed a student, influenced by 764 Linked to nihilistic extremism
Natalie Rupnow Madison, WI Killed two classmates Connected to True Crime forums
Arizona Case Arizona 13-year-old forced to carve symbols Ongoing investigation
California Cases California Minors blackmailed into torture Ongoing investigation

Early intervention by parents, teachers, and friends is crucial to protect children and help victims recover, breaking the cycle of abuse.

Trump pardons drug kingpins even as he escalates the U.S. drug war.

In May 2025, former President Trump’s actions created a complex narrative around Dark Web-related drug crimes. He pardoned or commuted sentences for at least 13 individuals convicted of federal drug crimes, among them were high-profile figures such as Ross Ulbricht, who created Silk Road, a Dark Web marketplace for illegal drugs, and Larry Hoover, leader of the Gangster Disciples gang that was involved in drug trafficking. These pardons were in line with advocacy from figures like Ye (formerly Kanye West) for Hoover and Kim Kardashian for Alice Marie Johnson. This nonviolent drug offender was later named Trump’s “pardon czar”.

Ross Ulbricht

At the same time, Trump suggested that the penalties should be harsher in the US drug war and also wanted the death penalty for drug dealers, while calling for more decisive action against Mexican cartels. Opponents, such as Jeffrey Singer from the Cato Institute, maintained that these pardons equivocate and thus result in efforts to eliminate Dark Web drug markets being undermined effectively. Followers, however, interpret them as part of the reform of the criminal justice system, a re-entry for some offenders. The pardons, often seen as a token of political support, illustrate the paradox between law enforcement and leniency in the pursuit of combating Dark Web crimes.

Massive data breach exposes 184 million passwords, logins.

In May 2025, a massive data breach exposed 184 million account credentials, comprising email addresses, passwords, usernames, and URLs, from various platforms, including Google, Microsoft, Apple, Facebook, Snapchat, banking services, medical platforms, and government accounts. Cybersecurity researcher Jeremiah Fowler discovered a completely unprotected database, lacking encryption and access controls, and it was therefore freely available online. This information, likely obtained using infostealer malware, may have been sold on Dark Web forums or utilized by cyber attackers for targeted attacks. Consequently, the situation has worsened, with incidents of account hijacking, spamming, fake accounts, or identity theft becoming quite possible.

The breach serves as a reminder that digital systems are vulnerable, and this vulnerability is exacerbated by the fact that technologies like AI and quantum computing do not pose an obstacle for hackers. Users are advised to use different passwords and enable multifactor authentication, as well as to regularly monitor their digital footprints, to stay safer from threats. Meanwhile, companies must also step up their efforts and implement improved safeguards for data protection to prevent the leak of such data from fueling the dark market.

Data appeared on the Dark Web following the Nova Scotia Power breach

Nova Scotia Power users in Canada discovered that their private information was on the Dark Web after a security breach in May 2025. The exact nature of the leaked data has not been made public; however, the incident highlights the risk of cyberattacks on critical infrastructure. A breach like this can also lead to sensitive customer information being sold on illicit marketplaces on the Dark Web, thereby increasing the likelihood of fraud and identity theft. This incident highlights the need for utility companies to implement more robust cybersecurity measures to safeguard customer data effectively.

Nova Scotia Power breach

Dark Web child abuse network smashed in Multan raid, six kids rescued.

A raid by the National Cyber Crime Investigation Agency (NCCIA) in Multan, Pakistan, led to the breaking of a network of child pornography on the Dark Web. Two persons were arrested, including the head of the gang, Junaid Irfan, and six children aged 6-8 were saved. The operation additionally established that the network was using platforms such as Telegram and WhatsApp to produce and distribute illegal material. The network aimed at underprivileged children whom they bribed and forced through blackmail to be their partners in crime. The police seized the electronic devices and papers from the perpetrators, as well as the videos and a fully equipped video studio. The Child Protection Department is the place to which these children are being sent so that they can be rehabilitated. 

300 servers and 35M seized as Europol targets ransomware

Europol’s Operation Endgame, launched in May 2024, is ongoing as of May 2025. The authorities intervened between May 19 and 22, when they eliminated 300 servers and took €3.5 million in cryptocurrency from the criminals. The operation aimed to eliminate malware, including Bumblebee, QakBot, and TrickBot, which are distributed on the Dark Web to facilitate ransomware attacks. Operation Endgame has thus far confiscated more than €21.2 million, and as a result, it has played a crucial role in dismantling the ransomware network. Germany has taken legal action against 37 individuals, and six of them have been added to the EU’s Most Wanted list.

Operation Servers Seized Crypto Seized Malware Targeted
Endgame 300 €3.5M Bumblebee, QakBot

This operation shows law enforcement’s adaptability in targeting Dark Web cybercrime infrastructure.

270 arrested in global Dark Web crackdown targeting online drug and criminal networks

Operation RapTor, led by Europol, has culminated in the arrest of 270 people in ten countries in May 2025. The operation, which was aimed at the vendors and buyers of the dark web, has not only confiscated more than €184 million in cash and cryptocurrencies but has also seized two tons of drugs (such as amphetamines, cocaine, and opioids) and 180 firearms. The new operation, based on the previous takedown of the Nemesis and Tor2Door marketplaces, has utilized intelligence to identify suspects in the United States, Germany, the UK, and other locations. It is a clear indication that the criminals can no longer hide online.

Dark Web Digest – May 2025 Edition

May 2025 Edition

April saw big, threatening news on the dark web. The FBI arrested a money laundering operation called ElonmuskWHM. While other news reports circulated about the Kidflix child abuse network being taken down by the agency, 79 people were arrested in connection with the operation.

However, the dark web still holds serious threats. Login credentials from central Australian banks were leaked. A new Xanthorox AI hacking tool appeared, offering criminals a wide range of capabilities. Meanwhile, a Turkish man was arrested for his role in a dark web child abuse network. Ransomware groups continued to target government agencies, like one in Oregon.

The increasing danger of dark web crime and the ongoing efforts to tackle this crime wave are shown monthly. Let us discuss the major dark web incident that happened in April.

Germany Dismantles Major Dark Web “OP Stream” Operation

German authorities have successfully taken down one of the world’s largest darknet platforms for streaming child exploitation content. The operation involved 38 law enforcement agencies from 38 countries, including the US, the UK, and several EU nations. 

The platform, which had over 1.8 million users worldwide, contained tens of thousands of disturbing images and videos depicting severe child sexual abuse. The operation identified 1,393 suspects globally, including more than 100 persons in Germany alone, despite attempts by perpetrators to conceal their identities. A crucial part of the investigation involved tracking cryptocurrency transactions used by the platform’s operators and users to avoid detection. 

Germany Flag

Extensive searches were conducted between March 10 and 23, leading to the seizure of electronic devices such as mobile phones and computers. The investigation is ongoing in multiple countries as law enforcement agencies analyze confiscated materials and conduct further searches.

Turkish Man Arrested in Connection with Dark Web Child Abuse Network

A global network that served child abuse images to hundreds of thousands of members on the dark web was dismantled by US cybercrime experts. Eight individuals were arrested, and 1.2 million videos were banned. The leader of the gang, Mehmet Berk Bozüyük, was identified as “John De Vil.” The site, which could be accessed via special internet servers for $100, provided access to the illegal “Dark/Deep Web,” where child abuse content was made available. 

Agents identified 39-year-old Krunalkumar Modi as controlling the site’s database and granting access. During a raid on Modi’s home in New Jersey, authorities uncovered over 1.2 million videos, many involving babies, and millions of people were members of the site. The investigation revealed that Ximena Maqueda was the network’s financier. 

Eight people were arrested during searches conducted in Canada and other countries. Bozüyük, using stolen and forged identities, was found to be facilitating the global sale and distribution of child abuse material. Many of the abused children were migrants who were kidnapped at the borders and sought internationally by their families. 

The arrested people were charged with distributing child sexual abuse content across state lines, distributing obscene materials, and the illegal use of two-way communication devices. They were sent to prison, but Bozüyük and Maqueda remain at large. A Red Notice has been issued for Bozüyük’s arrest.

Over 26,000 Dark Web Forum Discussions Focused on Hacking Financial Institutions

A study of 46 deep-web hacker forums and over 26,000 threat actors‘ forum threads in 2024 revealed alarming trends in cyber threats targeting the financial services industry. 

The research revealed a thriving underground economy centered around information-stealing malware, with an average of 3-4 daily mentions of unique “infostealer-as-a-service” across each monitored forum. Developers target individual threat actors and more sophisticated APT groups, offering enhanced UIs, technical support, and specialized modules for stealing corporate credentials.

Radware researchers identified a concerning trend in how these attack tools are marketed and distributed. 

Infostealer developers increasingly offer tailored solutions with dedicated features specifically designed to target corporate accounts, such as Mystic Stealer, which provides specialized functionality to extract passwords from Outlook. The democratization of attack capabilities has reached unprecedented levels, making attribution and law enforcement intervention increasingly challenging.

The most significant development of 2024 has been the rise of “OTP (One-Time Password) bots,” underground services operated via Telegram that enable threat actors to automate social engineering attacks. 

These bots function by using credential stuffing attacks using previously leaked username-password combinations. When login attempts fail due to two-factor authentication requirements, attackers target these accounts using OTP bots that impersonate legitimate entities through pre-recorded or AI-generated voice calls and SMS messages.

Login Credentials of Four Major Australian Banks Leaked on Telegram and Dark Web

According to a report by the Australian Broadcasting Corporation, hackers have stolen Australian banking passwords and are selling them online. The login credentials for four major banks are being seen on Telegram and the dark web.

The credentials were stolen from personal devices via “info stealer” malware, with some compromised devices infected as early as 2021. Globally, over 31 million devices have been infected by info-stealing malware, with over 58,000 affected in Australia alone. Australian superannuation funds have also been targeted by cyberattacks, using stolen passwords to access accounts and commit fraud.

Leaked on Telegram

Xanthorox AI Emerges on Dark Web as All-in-One Hacking Tool

Cybersecurity firm SlashNext has identified a new AI platform, Xanthorox AI, designed for offensive cyber operations. Xanthorox AI, first appearing in late Q1 2025, is based on five distinct AI models optimized for specific cyber operations, hosted on private servers under the seller’s control. 

This sets Xanthorox AI apart from previous malicious tools, which often rely on existing large language models (LLMs). The platform is fully custom-built, using “fully custom-built language models” instead of established models like LLaMA or Claude. It is promoted as a modular system capable of code generation, vulnerability exploitation, data analysis, and integrated voice and image processing, enabling automated and interactive attacks.

The platform’s modular design allows for future updates or replacement of specific functionalities. It also features built-in voice and image handling modules, live internet search scraping using over 50 engines, and offline functionality. 

Xanthoox AI

The toolkit includes the Xanthorox Coder, which automates tasks like code creation and script development, Xanthorox Vision, which adds visual intelligence, and Reasoner Advanced, which aims to replicate human-like decision-making. Xanthorox AI facilitates voice-based interaction through real-time voice calls and asynchronous voice messaging, allowing hands-free command and control.

Threat Intelligence Firm Trades Cryptocurrency for Dark Web Accounts

Prodaft, a threat intelligence company, is offering users of Dark Web cybercrime forums a new deal: Prodaft will pay to take accounts off cybercriminals’ hands while guaranteeing the anonymity of the sellers. 

The SYS initiative will buy vetted accounts from five known cybercrime forums: XSS and Exploit, in RAMP4U, Verified, and BreachForums. Prodaft will pay extra for forum accounts with moderator or administrator roles. Users involved in these activities will not have to explain their past or answer any questions. 

The aim is to position for better threat intelligence gathering. The account will be analyzed and assessed, and Prodaft will provide details of the offer and payment method. All purchased forum accounts will be reported to the firm’s law enforcement partners for transparency, but the seller’s identity will be protected. 

To be viable for SYS, accounts must be registered before December 2022 and cannot be on the Most Wanted by the FBI or any other law enforcement list. Payment can be made in Bitcoin, Monero, or other cryptocurrency.

Ransomware Group Claims Oregon Agency’s Sensitive Data Leaked on Dark Web

Oregon Public Radio reported that Rhysida, a ransomware group responsible for a cyberattack on April 9, released 1.3 million files, containing 2.4 terabytes of data, allegedly stolen from the Oregon Department of Environmental Quality (DEQ). 

The files containing sensitive employee information were released after DEQ officials paused most services, including vehicle emissions testing. The agency spokesperson, Lauren Wirtis, provided little additional information. 

The department regulating air quality announced a potential cyberattack but denied any data breach. From April 9 to 11, employees were forced to work from their phones and could not receive emails. The department has enlisted a data forensics team to investigate the incident, but has not admitted to any data theft.

79 Arrested in Takedown of Dark Web’s Largest Child Abuse Network, ‘Kidflix’

Kidflix, one of the most significant known child sexual abuse material (CSAM) websites on the dark web, was dismantled on March 11, 2025, in a coordinated effort involving authorities from over 35 countries. With over 1.8 million registered users, the platform was designed to grow fast and allowed users to stream and download CSAM. It used a system that rewarded uploads and engagement with cryptocurrency-based tokens, which could be used to unlock higher-quality versions of the content. 

The scale of the abuse is massive, with the platform hosting around 91,000 unique videos, totaling more than 6,200 hours of CSAM. On average, 3.5 new videos were uploaded every hour, many of which had never been seen by investigators. Seventy-nine people have been arrested in connection with the site, including some who were directly involved in abusing children. 

Law enforcement has identified nearly 1,400 suspects, and the investigation is still ongoing. Officials also blocked over 3,000 electronic devices and rescued 39 children from dangerous situations. Kidflix was a highly organized and profitable operation, with users earning tokens by uploading CSAM, tagging content, and verifying video descriptions. The site’s infrastructure supported low, medium, and high-quality video, making it even more attractive to predators. 

The operation’s success relied heavily on international teamwork, with agencies from the United States, the United Kingdom, Australia, Canada, Germany, and others helping to track suspects, secure digital evidence, and identify victims.

FBI Takes Control of Dark Web Money Laundering Operation ‘ElonmuskWHM’

The FBI has been increasingly infiltrating cybercrime, using its agents to embed with and even fully operate digital criminal organizations. A case in point is the FBI’s operation of “ElonmuskWHM,” a dark web money laundering operation that allowed cybercriminals to cash out cryptocurrency elicited via criminal schemes. Customers, including drug traffickers and hackers, would send the business their crypto, and the operator would mail them cash. Elon Musk would take a 20% fee for his services. 

The FBI began investigating the service in 2021, recruiting the Postal Service to help it probe cash shipments between cybercriminals and the operator. Investigation showed that nearly $90 million worth of cryptocurrency traveled through Elon Musk’s network, and at one point, the operator boasted of making as much as $30 million from his business. Eventually, police found and arrested the conspirator, a 30-year-old Indian national named Anurag Pramod Murarka, and took over the site. 

The feds operated ElonmuskWHM for approximately 11 months, allowing the feds to understand ties between the service and drug trafficking prosecutions, robbery at knife point investigations, and numerous computer hacking investigations. 

The FBI also took extreme steps to unmask the operator of ElonmuskWHM, including demanding Google turn over identifying information about everyone who watched a specific YouTube video over eight days. Murarka was sentenced to 121 months in prison in January. 

This is the latest example of the government clandestinely infiltrating cybercriminal operations to understand their structure and probe customers. The FBI’s “Trojan Shield” operation allowed the bureau to monitor 11,800 devices in 90 countries, providing a window into high-level criminal activity by as many as 300 transnational crime organizations. 

Dark Web Digest – April 2025 Edition

Dark web Digest - April 2025 edition

March was no quiet month on the dark web. Criminal activities varied, from millions of stolen bankcards and malware-infected devices to drug deals and secret Bitcoin movements, and the underground network has been a crazy place of crime.

We have seen the return of a long-dead dark marketplace, a crackdown on shady adult content remittances, and even a chilling child exploitation ring busted overseas. Closer to home, Kerala police uncovered tech-savvy youth trading drugs online.

 There is a lot more to explore in this digest.

2.3 Million Stolen Credit & Debit Cards Dumped on Dark Web

From 2023-2024, over 2.3 million bank cards became exposed through info stealer malware, affecting 26 million Windows devices. According to the cybersecurity company, users’ card data is stolen in 1 of 14 infections caused by an infostealer of that kind. Nevertheless, there is a likely significantly more significant number of devices infected by infosteal malware as data files taken from one victim by the attackers are primarily years later or a few months after the initial infection was released. 

Redline is well known as the most common info stealer malware, accounting for 34% of the total infections in 2024. An info stealer known as Risepro spread very quickly and targeted banking card details and passwords. 

The Risepro info stealer, apart from the theft of cryptocurrency wallet data, is going it’s way with software cracks, game mods, and key generators. Moreover, Kaspersky recommends that the public and corporations watch over bank notifications, implement two-factor authentication, and make all devices undergo full security scanners to be alert in the face of malware.

Feds Crack Down on Dark Web Cash Moves

The Enforcement Directorate (ED) is investigating Subdigi Ventures Private Limited, administered by a Noida-based married couple after they found a large spider web of unauthorized money remittances from abroad and a link to the companies engaged in streaming adult content.

The search operations, which were carried out under the provisions of Section 37 of the Foreign Exchange Management Act (FEMA) and Section 132 of the Income Tax Act, extended to various locations connected with the company and its directors.

The investigation being conducted by ED found that Subdigi Ventures Private Limited was being sent a significant amount of foreign remittances from Technius Limited, a company in Cyprus that operates adult content websites such as Xhamster and Stripchat. The remittances, under the pretext of services like advertising, market research, and public opinion polling, ostensibly were the proceeds of adult content being streamed on the specified platforms. The Foreign

During the raids, the ED officials identified a high-tech studio set up to create adult content. The couple used models from social media platforms to perform in these adult content streams. Apart from these transactions, the bank accounts of Subdigi Ventures and its directors were credited with an illegal remittance of Rs 15.6 crores.

Moreover, a bank account in an undisclosed location in the company’s home country had also been the recipient of around Rs 7 crores from Technius Limited. Subsequently, these funds from foreign sources were withdrawn in cash in India with the help of international debit cards, thus remaining unnoticed by the Indian authorities. The pair were keeping about 75% of the proceeds from the porn site and, at the same time, sharing only a tiny amount of the money with the performers therein. This issue of model exploitation and illicit money transfers was a significant part of the current probe. The ED is looking for the whole network of operations through cooperation with global organizations.

Dead Dark Web Portal Reborn as Whale Moves $77.5M in Untraceable BTC.

The Nucleus Marketplace, an infamous criminal marketplace on the internet’s darknet, has resurfaced after a nine-year downtime. It sold a variety of things, including drugs, fake IDs, and computer hacking services. The point is that the site disappeared in 2016, and it was assumed that either the police had found and stopped it, another criminal had stolen it, or that the same owners were the ones who had pretended to go. No one has given an official explanation for the money’s untouched status up to date.

Per a publication by the blockchain analysts at Arkham Intelligence, the resource is back and has just moved $77.5 million worth of Bitcoin into three fresh wallets. That way, the guilty party of the Nucleus Market is playing a long game, and they still have only $365 million in Bitcoin to deal with. Most probably, the analysts of Arkham’s intelligence and law enforcement officers will keep a close eye on the space to secure the rest of the stolen funds.

CA Man Gets Prison for Washing $Millions in Dark Net Drug Coin.

John Khuu, 29, has been charged with not less than 87 counts of federal prison sentence in San Francisco, California, for being part of the way to money laundering using Bitcoin to cover the proceeds of a dark web operation that sold MDMA. John Khuu, a person from San Francisco, was a significant contributor to the mythology that included the shipment of MDMA from Germany and the sale in various dark web markets. 

A man whom Khuu dealt with then paid his Bitcoin to third-party accounts. The man exchanged the Bitcoin for U.S. dollars and formed a complete money laundering system consisting of a few transactions through vast numbers of financial accounts. Furthermore, he was separately charged in the Northern District of California in connection with unlawfully importing a Schedule I controlled substance. The arrest was part of the ongoing three-agency Operation Crypt Run, which resulted from a joint investigation of the Department of Justice (DOJ), the U.S. Secret Service, and the U.S. Postal Inspection Service

The federal government is using a combination of methods to combat Bitcoin money laundering as Chainalysis, a blockchain data company, predicts that 2024 will be the year with the most significant amount of money laundered through cryptocurrency, up to $40 billion. A 2024 money laundering risk assessment from the U.S. Treasury discovered that besides the fact that traditional drug dealers still use the conventional way to launder their money, digital currency is becoming more and more popular and, thus, more effective.

Child Porn Ring Smashed in US-Thai Cops

Thai law enforcement, in collaboration with the US Department of Homeland Security (DHS), seized 36 pieces of evidence, including hard disk storage with 140,000 pages and 5,000 video files, while conducting a joint operation against the criminal. The alleged offender was detained in Chonburi province and is currently facing various charges. 

The man has also been staying in the country on an overstay visa. He was involved in the sale of paedophilic sex porn through the dark web as well as in the provision of various kinds of spyware services to online businesses.

At a press conference hosted by Police Major Athip Pongsiwapai and Aaron Mercelus, the US Embassy Attaché for HSI, the TCSD officially announced a significant achievement in their operation. Speaking at a press conference in Bangkok, the US Homeland Security agency underlines its role of safeguarding the citizens and addressing national security threats. The US authorities first communicated with the Thai police unit in December 2024 on the suspicion that a few dark websites were serving as dens for these criminals and, at the same time, conducted the spyware service with no regard to the law. Mr. Steffen’s place was broken into by the Royal Thai Police and the US Embassy in Bangkok on March 5th after several months of inquiry.

Stolen Bank Data from 26M Devices Sold in Underground Forums

The Kaspersky threat intelligence team discovered that infostealer malware and bank card theft are closely related. Approximately 26 million devices suffered from the infostealer malware between 2023 and 2024; however, 2 million bank card details were exposed due to many lost devices. It must be pointed out that Infostealers, besides stealing debit or credit card information, can also look for and pinch every possible data helpful to hackers. Windows devices were the only ones affected, with 26 million during 2023-2024.

Further, it is said that cybercriminals use dark web log files to dump data months or even years after the initial infection. We still come across many of the formerly forgotten compromised accounts and data today. However, due to the lateness of the date, there is an increase in the number of remnants from previous years. Kaspersky avers that, at most, an additional 25 million devices shall be tainted with infostealer malware in 2024 and an additional 22 million devices tainted with infostealer malware in 2023. Thus, infection estimates forecast the worm’s spread for the year.

Indian Police Track 25 Dark Web Drug Suppliers

The state police in Kerala have traced the roots of a drug trafficking group consisting of twenty-five people. These people are mainly Kerala natives who are using the dark web for malicious activities. It was a joint operation by the cybercrime division and the technical intelligence wing that was launched to weed out those who are initiating the network and doing business on the dark web, the secret part of the internet that cannot be indexed by search engines and requires special software and tools to access. The Kerala police concluded that traffickers utilized dark websites to get buyers. It was interesting to find out that the criminals were in the astronautics or IT sectors, and some were from the affluent segments who were very good at their work. They were identified as the majority.

The police have made some arrests of the 25 identified traffickers through their dark web patrols. Almost all the identified people deal with banking transactions. In cases in which the criminals are outside the home state, the details have been sent to the concerned police units for further action.

Dark web sales are considered more straightforward than usual because there are no face-to-face meetings between sellers and buyers, making it impossible to recognize the violators. The producers and consumers will post to share information about the availability and requirement of the drugs, and in a short time, the products are shipped to home. Of the 25 people involved in the operation, only one person used methods other than their bank account, and most used cryptocurrency.

Drug peddlers might have imported the substances from foreign countries or procured them from local networks that have stockpiles of the banned substances. Nevertheless, the active online peddlers were involved in the distribution of a category of drugs in a smaller quantity.

Dark Web Digest – March 2025 Edition

Dark Web Digest - March 2025 Edition

The dark web is still where online criminals and law enforcement are caught up in a heated exchange. In the meantime, the darknet’s criminals generated a mixture of odious acts and many notable victories in combating dark web-related activities. Through this monthly digest, we will take you into the significant happenings and attempts for growth that are forced due to the use of the dark web and the ways it would be a threat that needs to be taken into more significant consideration.

Dark Web Child Exploitation Case Shocks the U.S.

On August 31, 2011, one of the most upsetting stories to come out was about a man from the United States who allegedly raped a 7-year-old boy and then uploaded the attack videos to the dark web. This awful case, according to NDTV and People, shows the use of the dark web to commit such terrible crimes. The dark network also has benefits, such as becoming a safe place for lawless people who distribute such illegal content without any authorities overlooking them. They evade the eyes of law enforcement and get away with it because the hidden web guarantees their anonymity.

Since the dark web is a place where people can protect their identities and be free from the authorities, the police forces are doing their best to search for and close platforms like that, but the fact that the article is dedicated to addressing the challenges they face has prompted legislators to advocate for stronger legislation and closer monitoring of the dark web and its activities. 

IVF Patient Data Leaked in Major Dark Web Breach

A fertility clinic, Genea, was affected by a massive data breach, as a result of which the particulars of the IVF patients were revealed. The report stated that the stolen data was shared on the dark web, showing a risk of cybersecurity hacks and privacy breaches in the health sector. An event like this included personal data, medical records, and financial information, thus putting the patients at a greater risk of identity theft and fraud.

This infected file and its current state regarding Ransomware attack crimes are clear evidence of the need for strong and reliable data security. The highly sensitive input observably demonstrates healthcare facilities’ vulnerability to digital attacks. The leakage incident has implications for network vulnerability.

Genea - IVF Patients Data Leak

The hacker had spread a message on the dark web, offering to sell the patient’s data for USD 300, and the Albania drug cartel was carrying out the whole operation for laundering money. Research conducted by the RUC would produce the results regarding those responsible for this data breach.

Police Dismantle 8Base Ransomware Gang

The NATO Alliance has achieved its goal of dismantling the dark web servers of the 8Base ransomware group. According to Hackread and TechCrunch, the action stopped the gang, and they cannot continue extorting and leaking sensitive data. 8Base was one of the groups that held their victims up to ransom and shared whatever data they had. Nevertheless, these guys brought sophistication by deploying ransomware in businesses, homes, government entities, and other institutions, and they demanded huge sums of money.

8base - Arrest in Thailand

This operation is proof of the stronger bond between international law enforcement agencies to tackle the dark web, a gateway for criminal activities. Policemen from several different nations, namely all those active campaign sites, were simultaneously knocking out hiding hackers to ruin their rackets on the gaming platform.  

TikToker Exposes Dark Web Chat Room Dangers

A TikTok user shared an experience in a dark web chat room that went viral and revealed the platform’s dangers. Unilad reported on the story, igniting a discourse about the dangers of the dark web. The user described experiencing horrible content, such as illegal actions and sexually explicit things, while trying to learn about the dark web only for a short period.

The video turned out to be a warning for people who are not well-versed in the internet. It showed the scary side of searching the dark web. The dark web is often depicted as an intriguing, enigmatic space; however, the reality is more ominous. The experience of TikTok proves that apart from letting the public know, young people need to be educated about the dark web threats and cautious while browsing the internet.

Dark Web Drug Dealer Sentenced to 8 Years

A man from King County was sentenced to 8 years in prison for distributing hard drugs over the dark web and hoarding a stockpile of weapons. The case, which the U.S. Department of Justice reported, emphasizes the connection between drug trafficking on the dark web and illegal firearms. Police also confiscated $ 287,000 more in crypto from the seller, which is what KOMO News informs us.

The incident, however, serves as a powerful pointer to the dark web’s involvement in the illegal drug trade and the difficult path that law enforcement needs to overcome in the fight against such activities. Using cryptocurrency for trade dealings creates further confusion, making identifying and confiscating black money cumbersome. The court verdict gives a signal to the dark web drug sellers. Nonetheless, it also brings to the front the need for intervention on this ramp. Therefore, the police have to take measures to stifle the mafia networks and prevent the infiltration of illegal drugs and weapons.

Georgia Man Indicted for Attempting to Sell Teen on Dark Web

A man from Georgia was accused of attempting to sell a teenage girl on the dark web, and this was highlighted by Atlanta News First, which also said that the case, in a big way, leaves the point of human trafficking in the dark web uncovered. This case, in which a man has been indicted, indicates the dark web’s role as a medium for human trafficking. The man is alleged to have employed the dark web platforms as a medium for advertising the live girl, causing the sinister aspect of human trafficking, which occurs on the online network, to emerge.

Man Arrested

This case signals the worst part of the dark web as it has now been transformed into a platform facilitating modern-day slavery, thus calling for the enforcement of stringent measures to fight human trafficking. Criminals use the dark web to conduct their illicit activities by selling exploitation material to the public. On their part, law enforcement agencies are busy with the activities of the dark web so that they can recognize and save the trafficking victims.

Toronto Zoo Cyberattack: Guest Data Leaked on Dark Web

During the recent cyberattack at the Toronto Zoo, transaction data, including those of the members and visitors, was stolen and subsequently leaked on the dark web. CBC News was the first to break the news, focusing on the vulnerability of public institutions’ cybersecurity, which is evident from the incident. The hackers accessed guests’ and members’ private data, including payment and residence information. 

It is essential to remember that such an incident brings out the ever-increasing risk of cyberattacks on public enterprises and the critical role played by the security apparatus in this sense. It also highlights the value of an open and prompt dialogue between the authorities and those impacted by such breaches to minimize their impact. The Toronto Zoo has enhanced its security systems to avoid similar attacks in the future. However, the incident is a heads-up that cybercriminals are unyielding in their quest to undermine security.

Medusa Ransomware Group Targets Healthcare Sector

The Medusa ransomware group has targeted the healthcare sector, exposing confidential data on the dark web. The Register reports on the attacks and draws attention to the alarming ransomware trend that increasingly imperils critical areas. “They (Healthcare companies) were asked to pay a huge amount of money for not circulating the stolen data by pressuring them with increased healthcare systems with already strained systems” was their ransom scenario.

With the recent ransomware invasion, the healthcare industry again finds itself on a knife edge due to cybersecurity-related attacks and demands for additional, more effective cybersecurity measures. Healthcare facilities must get their safe and secure patient data by putting them at the top of the list and investing in protective measures that will help prevent future attacks.

Conclusion

Even though February 2025 witnessed both alarming dark web activities and significant law enforcement victories, the dark web remains a complex and dangerous space, with threats ranging from child exploitation and data breaches to ransomware takedowns. The past month’s events emphasize the still fraught situation of dark web threats, indicating the necessity for constant vigilance and proactive measures.

Dark Web Digest – February 2025 Edition

Dark Web Digest - February 2025

The dark web continues to be a hidden and curious place. It is a mysterious part of the internet where anonymity reigns supreme, letting users browse hidden websites and engage in activities beyond the reach of traditional search engines.

This month’s Dark Web Digest explores the latest thoughts and incidents from January 2025. Our dark web analysis uncovers growing trends, incidents, and threats.

Dark Web Forum Tempted Our Son – 50 Days Later, He Was Gone

A 15-year-old boy named Cristoforo Nicolaou, who died just 50 days after being blackmailed and psychologically tortured by an anonymous predator on a dark web forum, has been warned about the hidden dangers of online gaming. The family discovered the blackmail after reading through his son’s online chat, which led to the creation of the Christoforos Charity Foundation (CCF) in his memory. The foundation raises awareness about the dangers of the internet and cyberbullying, stating that children can stumble into these dangers unknowingly and become drawn deeper into the dark dimensions of the web.

The challenges began with small tasks like eating cereal within a specific timeframe or running backward up the stairs, but they soon grew more sinister and degrading. Christoforos was prohibited from sleeping and forced to watch horror films all night. He also found pictures of knives sent to him on the forum. The family has never been able to trace the perpetrator who threatened their son, but they now work to educate others about online dangers for children through their charity, CCF.

The organization aims to raise awareness about protecting kids from online predators through presentations and activities days away from social media. They recommend parents be constantly aware of who their children are speaking to or playing games with online and ensure they are “tangible people” their children know personally. They also urge parents and children to avoid clicking on unfamiliar content and restrict social media use to encourage real-life connections.

Canadian Sentenced for Importing Fake Xanax via Dark Web

Arden McCann is a Canadian gentleman and a 37-year-old native of Quebec who was given a 30-year imprisonment term in federal prison for heading an international narcotics network that used the dark web. The book containing the story was imported from China and had been bound with Ed Tsunami Neblett in collaboration with multiple others. Even though McCann was never mentioned in the document and personally endorsed by a prosecutor because of his work dismantling the gang, Nason is mentioned 32 times.

The DEA Atlanta Division’s Jae Chung pointed out the fact that research into counterfeit pill production and distribution, along with drug trafficking via the dark web, is an issue that must be addressed. At the same time, buyers are produced with counterfeit LSD. The FBI Atlanta Division’s Sean Burke expressed his happiness by saying that McCann’s conviction is a good result of the excellent law enforcement cooperation between agencies in Georgia and internationally.

Man sold Drugs

Investigating the case, the Laval Police (Quebec, Canada) arrested McCann in October 2015 due to the drug sale on the dark web under the pseudonym “DRXanax.” As a result of the investigation done on the left pro radical of fentanyl analogs, 15 weapons, bulletproof vests, and narcotics ledgers were found by Canadian officials. McCann, undeterred by his imprisonment, was involved in the drug trade, even distributing fentanyl analogs on the dark web. He was handed over to the United States on June 9, 2022, and given a 30-year imprisonment sentence followed by 10 years of supervised release.

Ross Ulbricht was released from prison after 11 years by Trump.

Ross Ulbricht, the founder of the first dark web drug market, was captured over 11 years ago in San Francisco and condemned to a lifetime in prison. However, with the help of Donald Trump and his strong influence in the American cryptocurrency world, he will be a free man. Trump signed a full and unconditional pardon of Ulbricht’s mother, expressing his pleasure in supporting her and the Libertarian Movement. The Silk Road, created by Ulbricht under the pseudonym Dread Pirate Roberts, facilitated the sale of vast amounts of narcotics, counterfeit documents, money laundering services, and guns for hundreds of millions of dollars i

Silk Road Founder Released

n Bitcoin payments.

After the FBI located the Silk Road’s server in Iceland in 2013 and arrested Ulbricht in San Francisco, he was convicted on seven charges relating to the distribution of narcotics, money laundering, and computer hacking. In 2015, he was sentenced to life in prison, a punishment beyond the 20-plus years that prosecutors in the case requested.

A Free Ross movement has steadily pressed for Ulbricht’s release, first in a failed appeal and then in petitions for clemency. Many of Ulbricht’s supporters contend that the Silk Road was a free-trade experiment based on libertarian principles that only permitted “victimless crime.” Perhaps due to its support for the libertarian cryptocurrency community, the Trump administration has changed its position on Ulbricht’s case.

2 Arrested in Lucknow for Stealing Shoppers’ Data via Dark Web

Lucknow police have arrested two individuals involved in a fraud operation targeting Amazon Pay and Amazon Pay Later customers. Dhairya Verma and Maruf Asif Kasmani accessed customer data through the dark web and the Telegram app, committing fraud worth crores by exploiting their accounts for online shopping. They used a Telegram bot to bypass account security measures and made unauthorized purchases on various e-commerce platforms.

 Dhairya Verma and Maruf Asif Kasmani

Recovered items include protein powders, mobile phones, debit and credit cards, and cash. The fraudulent schemes, executed undetected for months, used Amazon Pay and Pay Later services. Investigations are being conducted to find other gang members and their methods of operation, and a case has been filed against the accused.

Hacker Spared Jail for Selling Unreleased Coldplay, Mendes Songs on Dark Web

Skylar Dalziel, a 22-year-old hacker from Luton, has been sentenced to 21 months in prison, suspended for two years, for 14 counts related to trading copyrighted music without the consent of the recording artists or label. In a raid of her home in January, police discovered hard drives containing up to 291,941 music tracks, including unreleased songs by Coldplay, Shawn Mendes, Melanie Martinez, Taylor Upsahl, and Bebe Rexha. Dalziel obtained the music illegally, accessing several cloud storage accounts linked to the artists. A spreadsheet also showed she had sold the tracks to several customers. An investigation was launched the previous year after the Recording Industry Association of America supplied evidence showing that Dalziel had purchased six unreleased music tracks on the dark web using Bitcoin.

At Luton Crown Court, she was handed the suspended sentence after pleading guilty to nine copyright offenses and four computer misuse offenses. She was ordered to complete 180 hours of unpaid work and 10 rehabilitative activity days. The court also ordered the forfeiture and destruction of hard drives and other equipment associated with the offense.

Detective Constable Daryl Fryatt from the Police Intellectual Property Crime Unit (PIPCU) at City of London Police said that theft of copyrighted material is illegal and jeopardizes the work of artists and the livelihoods of those who work with them to create and release their music.

15,000 Fortinet Firewall Configs Exposed on Dark Web

Fortinet has released data and VPN credentials for 15,474 devices, including configuration data, to the Dark Web due to a vulnerability, CVE-2024-55591, discovered on January 14. This vulnerability allowed an unauthenticated attacker to perform administrative operations via specially crafted HTTP requests on vulnerable devices. Security researchers developed a proof-of-concept exploit to scan for vulnerable devices and observed escalating exploitation attempts.

Fortinet

The same day CVE-2024-55591 was disclosed, the “Belsen Group” released data belonging to over 15,000 Fortinet devices. CloudSEK researchers assessed that the data had been stolen due to CVE-2022-40684, likely when the bug was still a zero-day. They concluded that the threat actor(s) decided to leak the data in 2025 after exhausting its use for themselves. The Belsen Group has released a 1.6GB file detailing a cybercrime attack on Fortinet devices, which appears to have spread across every continent.

The highest concentration of affected devices is in Belgium, Poland, the US, and the UK, with over 20 victims. The leaked listings contain two folders: “config.conf,” which contains device configurations, IP addresses, usernames and passwords, device management certificates, and firewall rules stolen via CVE-2022-40684, and “vpn-password.txt,” which contains SSL-VPN credentials sourced from devices via CVE-2018-13379.

7-fold increase in drug seizure… drones, dark web challenge

Indian Union Home Minister Amit Shah has called on states and agencies to take legal action against illegal labs. He stated that narcotics worth Rs 16,914 crore were seized in 2024, the highest recorded since Independence. He emphasized the need for strict measures against the dark web, cryptocurrency, online marketplaces, and drones. Shah also highlighted the seven-fold increase in drug seizures in the last decade and the government’s success in eliminating drug networks and terrorism linked to them.

He launched a drug disposal fortnight from January 11 to 25, with a target of destroying 1 lakh kg of narcotics worth Rs 8,600 crore. The Home Ministry is implementing a three-pronged strategy to achieve a drug-free India by 2047. Shah noted that drugs worth `8,150 crore were destroyed in 2004-14 and `54,851 crore in 2014-24.

Nepal’s Ministerial Data Hacked on Dark Web for $50

South Asian hacking collective FunkSec has released data from Nepal’s Ministry of Federal Affairs and General Administration for sale on the dark web, priced at $50. FunkSec, a self-proclaimed cybercrime group, has claimed 11 victims and promotes a free Distributed Denial-of-Service (DDoS) tool. The group has targeted victims across various sectors, including media, IT, retail, education, automotive, professional services, and NGOs, across countries like the United States, Tunisia, India, France, Thailand, Peru, Jordan, and the United Arab Emirates. FunkSec’s dark web platform features a “RANSOM” page, suggesting a double extortion strategy, encrypting and exfiltrating files from victims’ devices.

The group also advertised access to the super admin panels of four government websites, including Nepal’s ministry’s portal, which oversees sensitive information. Nepal’s media confirmed that Ministry spokesperson Kali Prasad Parajuli was unaware of the breach. Still, cybersecurity platforms like Ransomware Live and Onju.com confirmed that the ministry’s website had been compromised last August, with Bangladeshi hacker group Anonymous Bangladesh taking responsibility.

Dark Web Digest – January 2025 Edition

Dark Web Digest - January 2025

2024 has ended, and it is evident that the dark web is the most significant danger that threatens the digital world. 2025, awaits with actions on the security measures requirements and the what can we learn from our mistakes. In this month’s digest, we see the dark web attacks reaching dangerous levels, such as the exploitation of sophisticated ransomware attacks and the explosion of unfair tools like crypto drainers. Even at the end of the year, the dark web is still with us as it evolves, and new tactics and technologies are being developed to counter cybersecurity efforts worldwide.

Michael Schumacher’s former assistant is charged £12 million to post private images on the dark web

The family of Michael Schumacher faced accusations of a $12 million blackmail scheme committed against him. A proper plan, reflected by a former associate of the F1 maestro, included threats to publish highly personal dark web pictures. Markus Fritsche employed the guy as a bodyguard for the family, and he worked for the family for 18 months, even before Schumacher’s accident.

Internet trolls often argue over who got it right, but the truth might be understood after extended access to a family is gained via friendship. After the family had Fritsche… where Fritsche became annoyed that he created it, he made a nice scheme to get his revenge on days when someone discovered his missing USB device instead of simply giving it back.

Michael Schumacher

German prosecution accuses Fritsche of including Yilmaz Tozturkan, a long-time friend, and Tozturkan’s son, an IT specialist, as his allies in this criminal activity. The supposed framework implicated around that time unofficially included some 1,500 pictures, 200 recordings, and a series of documentation on Michael Schumacher’s illness was published.

Russia seizes a large amount of drugs and sentences the Hydra dark web kingpin to life in prison

The Russian court announced a lifetime sentence for the leader of the widespread criminal group Hydra. The group is famous for drugs online and arrested 15 of his aides. They were engaged in the production and trafficking of psychotropic substances and medicines. The Moscow Regional Court brought a guilty verdict after the decision of a group of jurors. Hydra was established in 2015 as a drugs market and was taken down by international police action in 2022 when its servers were seized. 

An information-sharing system was established at the regional level. Information on the gang’s activity of illegal trafficking of drugs was conveyed to the Russian State established through actual raids both in Russia and Belarus, and that caused a significant seizure of almost a ton of narcotic substances, cars, homes, and other assets belonging to the gang. The site carried out transactions of about one billion rubles ($9300,000) annually. Dmitry Olegovich Pavlov, whom we indicted for being Hydra’s IT administrator, is already in custody after his arrest in 2022. 

Hundreds of UK Ministry of Defence passwords leaked on the dark web

In the last four years, more than 600 military email login codes of Ministry of Defence (MOD) employees have been discovered and used in some cases of dark web data breaches that even reached the sections providing HR, email, collaboration, education, and training services. The thefts were repeated, with 124 stolen logins discovered during the past year. Those affected by these mischiefs are the people of countries like Iraq, Qatar, Cyprus, Europe, and the UK. It is challenging to say if the stolen entrance data was ever utilized since the perpetrator could obtain access to other private information by doing so. The portal uses multi-faceted authentication (MFA), an additional security layer that all public government websites are mandated to have now.

UK Defence

Should Russian intelligence services benefit logically? They must have been incompetent by allowing the credentials to be distributed on a dark website, which would ultimately be discovered. The gadgets engaged either were personal or had been awarded by the military. In either scenario, a higher risk of divulgence exists. Graham Cluley, the cybersecurity expert whose opinion is in the article, claims that the fact that 2FA stands as an obstacle does not mean it is sadly possible to smash into the system. Still, anybody who comes to such a task must master the details of a 2FA code thoroughly or, for instance, get a 2FA code from a user along with the user’s name and password.

At least 20% of cybercrimes involve attackers using the dark web

Lisianthus, the cyber security agency, has recently released a report pointing out that a minimum of 20% of cybercrimes in India involve attackers using the dark web. It is difficult to pin down the dark web as it is a platform that can be accessed via special tools and is also difficult to trace. The study was conducted within two months and relied on crime data from state police, the National Crime Records Bureau, and other relevant portals. The report also mentioned that some hackers had exploited it to launch ransomware attacks on AIIMS in Delhi last year.

Indeed, the dark web has witnessed a two-time hike in the past decade. According to a warning from a recent cybersecurity expert, web users should never give in to any ad of software asking them to grant permission to see their phone book and use other applications. Cybersecurity specialists at Cyber Tech, located in Gurugram, execute cybersecurity audits and security assessments for businesses.

Man goes jail after police found dark web drugs raid

Mr. Andrew’s rival, who is 34 years old and resides in Fe Atherstone, Staffordshire, has been arrested for offenses of selling harmful substances and involving in illegal money transfers. After a thorough examination, local police identified various classes of illicit drugs, including class B and class C drugs such as amphetamines, barbiturates, and anabolic steroids, worth approximately that equates to a kilogram of Class A drugs valued at over £10,000. Moreover, border control officers at Heathrow Airport were quick to identify this criminal network and managed to dice and apprehend the culprit, who had a drug parcel.

RI data leaked on the dark web by hackers

The health and benefits portal RIBridges in Rhode Island has been attacked by unidentified cybercriminals who have stolen an unknown amount of private information. The state’s worker, Deloitte, is communicating with the hackers, but Gov. Dan McKee has stated that no social welfare member should suffer any financial loss because of the data breach. Rhode Island will charge Deloitte for any additional costs incurred due to the hack and recommended that those whose data might be at risk should take security measures, such as freezing their credit with multi-factor authentication. Their goal is to have RIBridges back up and running by the middle of January, stated Brian Tardiff, the state’s top digital officer. He meanwhile cautioned residents of Rhode Island that other cybercriminals are always ready to exploit such events to conduct targeted attacks such as phishing. A phishing attack is perpetrated when the attacker tricks the victim into providing sensitive information (e.g., credit card numbers and bank account passwords) using realistic-looking emails, websites, or fake text messages.

Boxphish snaps up a dark web platform by dealing

Located in Leeds, Boxphish—a company known for managing human risk—has taken over Trillion, a high-tech threat intelligence service that follows up on the arguments on the dark web about credentials. Clients use Trillion’s technology to learn about the leaked credentials related to their business, which further helps them take necessary measures to reduce risks. With this acquisition, security technology company Boxphish has extended its range of products, including phishing simulations, data analytics, and cyber security training courses. In 2020, when Boxphish was founded by serial entrepreneurs Henry Doyle and Dan Bailey, they never would have dreamed that it would grow this quickly; it now has a customer list and even an in-house training course library for sectors of different sizes. 

BGF had put in £3.25m in April, which is an encouraging indication. By looking at all account credentials transmitted across dark markets and criminal forums, Trillion can quickly detect risk and notify the users to act according to the expected measures. The company that took over Trillion (Crossword) was glad to have found a new owner (Boxphish) for its technology and clients in Boxphish. Some customers already buy services from both companies, like Leeds United FC and New College Worcester, and now the deal brings long-term customer security.

Russian Supreme Court Punished Hydra Dark Web Kingpin

The Hydra leader, Stanislav Moiseev, was sentenced to life in prison and fined four million roubles (about $37,500) by a Russian court. The group was communicating through the internet in an encrypted form and, at the same time, also using covert drop-offs to deliver drugs of the size of a factory. Police officers could apprehend those participating in their operations thanks to a successful raid. Besides that, they confiscated a considerable amount of drugs, lab equipment, and smuggling-optimized autos. On 6th April 2022, US and German authorities destroyed Hydra’s German-based servers and caught its virtual currency worth. Produced by Meta, the platform had been used as the longest-running dark web marketplace and was estimated to be $1.3 billion, checked on a report by its closing.

Hydra Russia

After Hydra, dark web proceeds diminished to $1.5 billion, which was way less than in 2021 and a near count of $3.1 billion. Former users and retailers are alone on new platforms like OMG! Blacksprut and Mega Darknet Market have the upper hand. OMG saw its initial rise after Hydra’s downfall but received no additional users after a cyber-attack in June 2022. The court’s decision was the takeover of the group’s vehicles, properties, and land for the state’s benefit. The abilities are to be used in strict-regime penal colonies, and appeals could be made as planned.

 

Dark Web Digest – December 2024 Edition

Dark Web Digest - December 2024

This month, we’re looking at the newest and most concerning issues coming from the hidden parts of the internet, known as the dark web. We’ll explore complex ransomware attacks and the growing popularity of dangerous marketplaces like Abacus. The risks are more significant than ever. Cybercriminals are using clever tricks and new AI tools to trick people and organizations. Let’s explore some hot news and events from last month’s dark web world and see how these can be alarming for everyone!

Millions of records from the MOVEIT hack were made public on the dark web

A threat actor known as “Nam3L3ss” has posted at least 25 CSV datasets on the Breach Forums hacking site. These datasets contain millions of records from leading companies, likely stolen during last year’s MOVEit transfer vulnerability case. Hackers exploiting a zero-day vulnerability in Progress Software’s MOVEit transfer software caused the MOVEit hack, the most significant breach in 2023.

Israeli cybersecurity firm Hudson Rock reported that the stolen data includes employee directories from 25 major organizations, including Amazon, MetLife, Cardinal Health, HSBC, Fidelity, and US Bank. The directories contain detailed employee information, including names, email addresses, phone numbers, cost center codes, and sometimes entire organizational structures. Amazon received the most negative press due to 2.8 million Amazon records being exposed. However, Amazon spokesperson Adam Montgomery stated that Amazon and Amazon Web Services systems remain secure and that the company had not experienced a security incident.

The case highlights the weaknesses of third-party apps

Third-party software remains one of the most significant and least manageable cybersecurity risks organizations face, as well as massive and technically sophisticated enterprises. When companies react to these risks and vulnerabilities, they are already being actively exploited while being publicly disclosed. It is crucial for CISOs and their teams to focus on a proactive approach to their third-party software by shifting left and leveraging data to enable quick, accurate, and actionable risk assessments before they are exploited. New CVEs in other managed file transfer solutions, such as SolarWinds SERV-U and CRUSHFTP, can lead to data theft as severe as last year’s MoveIT incident. Security teams often need to be made aware of who uses these tools, how they are configured, or whether they are exposed to the public. This can lead to slow responses to vulnerabilities when they are disclosed.

Companies can avoid these blind spots by continuously analyzing their attack surface from the outside to understand what is exposed comprehensively and what needs to be protected. Effective third-party risk management should not be a “nice-to-have” but a “must-have,” according to Nick Mistry, senior vice president and CISO at Lineaje. Businesses must implement thorough procedures to proactively detect and address risks, such as frequent security audits, assessments, and ongoing third-party software monitoring. In today’s threat landscape, the security of an ecosystem extends far beyond the reach of an organization’s systems and infrastructure.

Prison layouts were leaked on the dark web

The Ministry of Justice (MoJ) has confirmed a data breach affecting prisons in England and Wales. Confidential prison layouts were leaked onto the dark web in the past two weeks, with a former prison governor stating that organized crime groups could potentially use the information to smuggle drugs or weapons into prisons or plan escapes. The leak is believed to be linked to organized crime groups using drones to smuggle drugs into prisons, while the blueprints could be used to evade security measures. The leaks include key security features, such as cameras and sensors, making it easier for criminals to bypass security or exploit vulnerabilities.

The Cabinet Office and the Prison Service are working to identify the source of the breach and assess who might benefit from the information. The National Crime Agency provided advisory support but is not investigating the incident. The MoJ has taken immediate action to ensure prisons remain secure.

490 million Instagram accounts listed for sale on the dark web

A threat actor on a popular Dark Web forum has claimed to have scraped a massive dataset containing over 489 million Instagram user records, allegedly accessing both public and hidden information. The data was obtained within the last three months through the Instagram API, and the post has gained attention across the cybersecurity community, questioning the potential privacy impacts on Instagram users worldwide. The dataset includes a wide range of user information, including usernames, full names, email addresses, first names, biographies, external URLs, account categories, targeted usernames, follower and following counts, location information, account creation dates, and user ID and scrape ID.

The threat actor provided a sample of over 100 records, offering a glimpse into the details they allegedly obtained, including email addresses and location data, alongside the usual public information such as usernames and follower counts. Such a mix of public and potentially private information could expose Instagram users to numerous security and privacy threats.

A dark web cryptocurrency laundering leader has been sent to 12.5 years in prison

Bitcoin Fog, the longest-running money laundering machine in dark web history, has been sentenced to 12 years and six months in US prison. The operator, Roman Sterlingov, was ordered to repay over half a billion dollars from the cryptocurrency mixing service he ran for a decade between 2011 and 2021. Bitcoin Fog processed 1.2 million Bitcoins during that time, worth roughly $400 million when shuttered. Sterling was ordered to repay $395,563,025.39 in restitution, forfeit approximately $1.76 million in seized assets, and relinquish control of Bitcoin Fog’s wallet containing more than $100 million in Bitcoin. Most of Sterlingov’s wealth came from the proceeds of crime, which he and his online service helped criminals hide from law enforcement.

The crimes associated with this activity included the sale of drugs, computer misuse offenses, identity theft, and child sexual abuse material (CSAM). The downfall of Bitcoin Fog won’t significantly dent criminals’ use of cryptocurrency mixers. However, investigators will be pleased that a service as relied upon as Sterlingov’s could be scuppered and distrust sowed throughout the community of criminals who use them. Mixers make investigators’ jobs more difficult by pooling all users’ funds together and redistributing them back to the users after taking a cut for the trouble. While mixers are not illegal in most places, they are widely abused and should be ended to prevent their widespread abuse.

Kaspersky predicts a nearly 25% increase in retail-related cyber threats ahead of Black Friday

In 2024, cybercriminals launched over 38 million phishing attacks, impersonating major marketplaces, banks, and tech retailers. Stolen payment card data is traded on dark web forums, with prices ranging from $70 to $315 per set. Between January and November 2024, Kaspersky Solutions blocked 38,473,274 phishing attacks related to online shopping, payment systems, and banking institutions.

Of these, 44% involved using banking services as bait, representing an increase of almost a quarter compared to the 30,803,840 million phishing attempts recorded during the same period last year. Scammers often impersonate major retailers like Amazon, Walmart, and Etsy, sending deceptive emails claiming to offer exclusive discounts. These emails link to fake websites designed to mimic legitimate ones, often with subtle errors like misspellings or slightly altered domain names. Victims attempting to shop on these sites typically lose money. Another widespread scam exploits consumers’ desire to win prizes by sending messages promoting limited-time surveys with prize draws, offering valuable rewards like a free iPhone 14. Kaspersky experts have traced the pathways of fraudulent activity, revealing that stolen data is exploited directly by scammers or sold on dark web marketplaces. The value of the data determines its price.

8,100 banks and financial institutions brace for fallout as hackers reveal a significant data breach on the dark web

Thousands of banks and financial institutions worldwide are preparing for new developments following a third-party data breach. Finastra, a financial services giant, has confirmed the discovery of suspicious activity in an internal file transfer system. The breach, first reported by cybersecurity journalist Brian Krebs, was discovered after someone claimed to have 400 gigabytes of compressed information from the firm. Finastra works with 8,100 financial institutions, including 45 of the world’s 50 largest banks. Early findings suggest the breach may involve sensitive data from significant banking clients, including financial records and transaction details. Confidential information on Finastra’s operations and services may also be at risk. The company has sent a letter to clients alerting them to its ongoing investigation, stating that the affected system remains isolated while the investigation continues. The source of the compromise is a priority aspect of the investigation.

A man who live-streamed a child sex assault was jailed

Wooly Spencer, a 34-year-old man from Exeter, has been sentenced to up to 25 years in jail after livestreaming himself on the dark web sexually assaulting a young girl. Spencer was arrested in March after the Australian Federal Police alerted the National Crime Agency (NCA) to the video, which contained 163 indecent images of children. He was previously found guilty of numerous offenses, including assault of a child under 13, sexual assault of a child under 13, causing a child under 13 to engage in sexual activity, attempted rape, engaging in sexual activity in the presence of a child, causing a child to watch sexual activity, and making and distributing indecent images of children. The NCA identified Spencer by examining the video and identifying the room he was in and his tattoos.

The prosecution, Nigel Wraith, stated that there had been no evidence of severe psychological harm to the victim and that Spencer had no previous sexual offense convictions. Judge James Adkin described the case as “repugnant” and described Spencer as “a hazardous man.” NCA operations manager Holly Triggs said the victims in the case suffered the most abhorrent sexual abuse, purely for his sexual gratification and others like him online. Spencer will spend 13 years in jail before he is eligible to apply for parole and will remain on the sex offenders register for life.