SOCRADAR’S Dark Web Team reported several underground listings, while stressing that the claims had not been independently verified. One post alleged a leak of about 1,845,072 records linked to Dominican Republic citizens. The sample appeared to contain document identifiers, names and birth information; email addresses, physical addresses, passwords and phone numbers were reportedly null in some records. If genuine, the data could support fraud, profiling, phishing and identity misuse.
Other advertisements included a claimed Money Network database containing approximately 1,037,245 lines, with sample fields including names, sanitised phone numbers, analysed email addresses, country information, SynapsePay IDs, credit ranges and account-alert data. A separate auction claimed to offer 1.9 million US CVV records, including card details, expiry dates, CVVs, names, addresses, phone numbers and email addresses. The seller set a $4,000 starting price, $250 minimum bid increase and $5,000 “blitz” price. The report said valid data could facilitate payment fraud, identity theft and card-not-present abuse.
The report also described an advert for “Celestial”, a malware suite marketed with HVNC, stealer, checker, wallet-injection and brute-force capabilities. Finally, an initial access broker claimed to be selling SSL VPN/Fortigate SSH access to a US industrial machinery and manufacturing organisation, said to have more than 200 hosts and around $1.5 billion in revenue. The asking price was $3,300.
SOCRadar said such access could enable lateral movement, data theft or ransomware, but did not confirm that the access or any of the advertised datasets was authentic or being actively exploited.