// CRIMINAL ECONOMY
Cybercrime
Ransomware operations, threat-actor profiles, breach economics, and the criminal markets that fund all of it.
- Telegram 120M leak: we counted 63M, most from 2020A forum listing advertises 120 million Telegram records. Ransomnews parsed the 3.7GB file: 63.1 million rows, 74% Iranian, and most of it dates to 2020.
- Condé Nast: 32.8M user records for sale, sample verifiedA 32.8M-record Condé Nast user database is on sale for $15,000 on a Russian-language hacker forum. We tested the sample: genuine account data, and the rest of the December WIRED hack.
- The Town 2025 ticketing data sold as a Ticketmaster breachA seller is offering 412,192 Latin American ticket-buyer records from The Town 2025, including 250,000 Brazilian CPFs, at about four cents a head. We tested the sample.
- Micro-Comm hack is separate from the US water attacksThe FBI water-sector PLC alert and the Barracuda ransomware breach at supplier Micro-Comm landed a day apart. The evidence says they are not the same story.
- Love Electric driver data for sale: NI, licence numbersA seller is offering 877,000 driver records from UK EV salary sacrifice broker Love Electric, including National Insurance and driving licence numbers. We checked the sample.
- Live Stripe keys for 659 merchants, published for freeStripe was not breached. A forum dataset holds live API keys for 659 of its merchants, plus 35GB pulled from them. We told Stripe before publishing this.
- Verified.ru: inside the archive of a cybercrime bureaucracyA 152,973-message archive of the Verified forum shows how Russian-speaking cybercrime governed itself between 2005 and 2010, using rules, penalty points and bans.
- McDonald’s employee data listed for sale in wider Entra campaignA forum seller claims 1.7 million McDonald’s employee records pulled from its Azure tenant. We analysed the sample, and the four other brands listed alongside it.
- 7.3M chess.com records leaked, and the data is realA 15.5 GB file of 7.3 million chess.com user records is circulating free on two leak forums. We verified it: the data is genuine and days old, but the shape points to scraping, not a breach.
- Quake3 and morgot: tracing REvil’s source-code developerQuake3, a moderator on the XSS.is cybercrime forum, is the persona DEF CON 33 research placed at REvil’s source-code development, and the man the German BKA named in April 2026. We trace the forum record that ties the handles together.
- Pokémon Center vending ‘breach’ is old 2016 dataA seller is marketing a ‘live’ breach of automated-retail vendor SwyftStore across 28 brands including Pokémon Center. The sample is genuine Zoom/Swyft data, but every record dates from 2016.
- Israeli population registry for sale, but the data is oldA vendor is selling what they call Israel’s current 9.22M-record population registry. Our analysis of the 100k sample says the data is genuine, but every date in it stops in 2005.
- Żabka confirms breach via supplier account, data for saleŻabka has confirmed unauthorized access through an external provider’s account after a dataset was listed for €5,000. We reviewed the sample; the company has not confirmed its scale.
- 5socks.net: 20 years of proxy crime, 2004 to seizure5socks.net sold access to hacked residential IPs from 2004 until the FBI seized it in May 2025. Dancho Danchev traces the service back to its Russian origins.
- Deadlock: ransomware that hides its C2 on the blockchainDeadlock ransomware uses Polygon smart contracts for takedown-resistant command and control and a vulnerable driver to kill EDR. A profile of 2026’s most technically novel new group.
- Clover Health discloses social-engineering breach in 8-KClover Health disclosed in a July 17 SEC filing that three employee accounts were compromised via social engineering, risking protected health data.
- DragonForce: the cartel that absorbed its rivalsDragonForce rebranded as a ransomware cartel offering white-label infrastructure, absorbed RansomHub affiliates, and hit UK retail. A profile of its model, decline, and tactics.
- ShinyHunters’ Salesforce extortion wave hits Fluke, IngramShinyHunters listed Fluke (21M Salesforce records claimed) and Ingram Content on its leak site, extending a 2026 Salesforce extortion campaign now drawing class-action lawyers.
- LockBit 5.0: the comeback nobody wantedLockBit relaunched as version 5.0 in September 2025 and surged to 7% of June 2026 attacks. A profile of the disrupted brand’s resurgence, new encryptor, and affiliate model.
- Deutsche Bank breached via supplier as Unsafe gang leaks dataA ransomware group called Unsafe posted Deutsche Bank employee data samples from a third-party supplier. The bank confirms a supplier breach but denies any internal compromise.
- Scattered Spider duo jailed 5.5 years over £29M TfL hackTwo Scattered Spider members were jailed 5.5 years each on July 16 over the 2024 Transport for London hack, the UK’s first conviction under Computer Misuse Act Section 3ZA.
- World Leaks dumps 19,000 files tied to India nuclear plantWorld Leaks published 19,000 files (14.3GB) tied to India’s Kudankulam nuclear plant after Reliance Infrastructure refused to pay. The data leaked via a third-party server.
- Akira: the edge-VPN ransomware that never slowed downAkira has stayed a top-tier ransomware operation into 2026 by hammering SonicWall SSL-VPNs via CVE-2024-40766, deploying within an hour and using BYOVD to bypass EDR.
- Coca-Cola’s Fairlife halts US production after ransomwareCoca-Cola disclosed a ransomware attack on its Fairlife dairy subsidiary in a July 16 SEC filing, suspending all US production. No group has claimed it.























