LockBit 5.0 threatens to publish identity documents tied to more than 100,000 job candidates from French staffing group Actua, spread across ten storage locations at once. What the claim-versus-reality gap looks like, and why scattered leaks change the takedown math.
A hacker using the alias ZeroBytes advertised a stolen DGFiP database on PwnForums, claiming live access to French tax systems. France's economy ministry confirmed illegitimate access affecting about 678,000 individuals and organizations; the seller's larger claims remain unverified.
After Abacus went offline in July 2025 amid withdrawal failures and exit-scam suspicions, its buyers scattered toward Torzon and Black Ops Market - while newer platforms rebuilt the payment stack around built-in coin swapping.
After BreachForums fell apart in April 2025, Darkforums absorbed its displaced user base and surged 600 percent in two months, now counting over 12,700 members under admins AnonOne and Knox.
The 2025 disruptions of Lumma and Rhadamanthys barely slowed the infostealer economy. Russian Market now lists 180,000+ logs per half-year, and the data inside them is fueling intrusions within days.
SOCRadar analysts spotted an underground post selling an alleged SCHUFA database of 70 million Germans with IBANs and credit scores, weeks after revelations of a secret shadow database at the credit bureau. The sale remains unverified.
A single cybercrime vendor known as TheHatman listed roughly 3.64 million Azure and Entra directory records from McDonald's, TCS, Vodafone, and six other large companies between July 31 and August 16, 2026. Hudson Rock assesses the dumps as highly likely authentic, while TCS denies any credible breach.
Mandiant tracks UNC6671, a voice-phishing and extortion operation tied to The Com that has run at least four victim-facing brands on shared infrastructure since January 2026, hitting financial firms including Apollo and Moody's with demands starting near $3 million.
The Silent Ransom Group's leak site has grown from 38 listed law firms in April to 64 by August 21, 2026, with Troutman Pepper Locke client records including tens of thousands of Social Security numbers now posted after the firm reportedly stayed silent.
ShinyHunters listed threat-intelligence firm ReliaQuest on its leak site on August 23 with screenshots but no verifiable evidence, days after the firm published research into the group's campaigns. The claim remains unconfirmed.
Initial access brokers now advertise corporate VPN, RDP and admin credentials alongside active recruitment of employees on messaging apps. Flashpoint's latest insider threat data shows a market that has professionalized faster than most defenses.
CISA, the FBI and HHS now count more than 500 Medusa victims, over 200 of them in the past year alone. A look at how the group's Tor-hosted leak site works and what it says about the wider 2026 extortion ecosystem.