PULSE
FEED
ransomemperador reclama a SiteProRentals · Hospitalityransomemperador reclama a Electrolux 2... · SE · Manufacturingransompanzer reclama a SMCare · Healthcareransomincransom reclama a AHEAD · US · Not Foundransomincransom reclama a nsbsd.org · US · Government & Defenseransompanzer reclama a Asesoría FAR · Professional Servicesransompanzer reclama a Ressources Si · FR · Professional Servicesransomstorm reclama a First Secure Bank Group · US · Financial Servicesransomqilin reclama a XICO · MX · Not Foundransomqilin reclama a Island · CA · Technologyransomqilin reclama a Revenga Smart Solutions · ES · Technologyransomqilin reclama a Willatt & Flickinger · US · Not Foundransomarcusmedia reclama a Pantaneiro Capas · BR · Manufacturingransomemperador reclama a Car Service Abschlepp · DE · Transportationransomemperador reclama a SiteProRentals · Hospitalityransomemperador reclama a Electrolux 2... · SE · Manufacturingransompanzer reclama a SMCare · Healthcareransomincransom reclama a AHEAD · US · Not Foundransomincransom reclama a nsbsd.org · US · Government & Defenseransompanzer reclama a Asesoría FAR · Professional Servicesransompanzer reclama a Ressources Si · FR · Professional Servicesransomstorm reclama a First Secure Bank Group · US · Financial Servicesransomqilin reclama a XICO · MX · Not Foundransomqilin reclama a Island · CA · Technologyransomqilin reclama a Revenga Smart Solutions · ES · Technologyransomqilin reclama a Willatt & Flickinger · US · Not Foundransomarcusmedia reclama a Pantaneiro Capas · BR · Manufacturingransomemperador reclama a Car Service Abschlepp · DE · Transportation
Kalir Brief · Item28 September 2026 · 07:48 UTC
BRIEFAccess salehighP72

U.S. Department of Commerce data offered for sale

U.S. Department of Commerce

Detected28 September 2026 · 07:48 UTC
Why it matters

A seller on DarkForums is advertising data or access tied to the U.S. Department of Commerce, a high-value federal target. If genuine, such material could enable further intrusion, credential abuse or influence operations against a government body. It should be triaged as a validated government-target lead rather than dismissed as chatter.

MetadataRECORD
CategoryAccess sale
Severityhigh
Priority score72
Detected28 September 2026 · 07:48 UTC
Related items6
Access sale● 60
Credenciales de phpMyAdmin del ITESHU de México a la ventaCredentials for the phpMyAdmin panel of ITESHU, a Mexican higher-education institute, are being offered on a hacking forum. Access to phpMyAdmin usually means direct control over the institution's backend databases, risking exfiltration or tampering of student and administrative records. This is a timely lead for defenders at Mexican public education institutions.
1d
Access sale● 78
Venta de exploit RCE pre-autenticación para Oracle PeopleSoftShinyHunters is selling a pre-authentication RCE plus WAF bypass for Oracle PeopleSoft, an ERP widely deployed across government agencies, ministries, universities and banks. This kind of unauthenticated exploit enables initial access without credentials and is highly relevant to public-sector targets in Latin America. Defenders running PeopleSoft should urgently hunt for exposed internet-facing instances and review WAF/DB logs for exploitation attempts.
2d
Access sale● 50
Credenciales y cookies del Colegio Faraday (Perú) a la ventaCredentials and session cookies for the Peruvian school colegiofaraday.edu.pe are being offered on an underground forum. Such access lets an attacker log in as staff or students, pivot into internal portals and abuse institutional email. It is a fresh compromise of a Latin American education target worth monitoring for lateral movement.
2d
Access sale● 45
Venta de email gubernamental de la Policía Estatal italiana (poliziadistato.it)A user is selling a @poliziadistato.it government email account for over $500, posted minutes ago. A law-enforcement credential can enable phishing, internal access and impersonation of Italian authorities. Defenders should treat it as a possible initial-access vector even though it sits outside the AR-LATAM region.
2d
Access sale● 57
Lista de 6.938 servicios expuestos verificados (RDP/SQL/SMB)A threat actor is sharing a verified, live list of 6,938 exposed services including RDP, MongoDB, PostgreSQL, MySQL and SMB endpoints. It is effectively a ready-made target list for ransomware and intrusion crews. Defenders should treat it as an exposure-hunting checklist and confirm none of their assets appear.
3d
Access sale● 42
Venta de acceso web a la naviera Minnesota Freight ExpressAdmin access to the website of US shipping company minnesotafreightexpress.com is being offered for sale. Website or admin access to a logistics firm can enable data theft, defacement or supply-chain abuse. Verify the claim and notify the victim so access can be revoked.
3d