BRIEFAccess salehighP78
Verified access to French government infrastructure for sale
Gobierno de Francia
Detected19 September 2026 · 16:23 UTC
A threat actor is offering verified access to one of the French government's infrastructures, a high-value initial-access sale. Such access enables lateral movement into public-sector networks, data theft or ransomware staging. A confirmed government intrusion is a strategic target demanding urgent validation and attribution.
CategoryAccess sale
Severityhigh
Priority score78
Detected19 September 2026 · 16:23 UTC
Access sale● 62
Acceso al portal gubernamental turco its.gov.tr a la ventaA seller is advertising access to the Turkish government subdomain paydas.its.gov.tr, posted on 2026-09-16. Government portal access can enable data theft, service abuse or lateral movement into other public-sector systems. It is a named high-value government target, so defenders tracking state-sector exposure should note it even though it is outside Latin America.Access sale● 30
Venta de acceso de administrador a hadiahmisteri.onlineA poster is trading administrator access to the Indonesian website hadiahmisteri.online, giving full control of the site and its backend. Admin access enables defacement, data theft or use as a foothold for further attacks. It is older (March 2026) and outside the region, so it ranks lower priority.Access sale● 78
Venta de acceso Domain Admin a empresa de IndonesiaA seller is offering Active Directory Domain Admin access to an Indonesian food & beverage company with over $5B in revenue. Domain Admin grants full control of the corporate network, enabling ransomware staging, lateral movement and mass data exfiltration. This is a high-value access listing that defenders at large enterprises should treat as a priority and monitor for related IOCs.Access sale● 48
Credenciales de administrador de WordPress en venta (Cloud9Base)Stealer logs advertised as valid WordPress administrator credentials were posted by the actor Cloud9Base. Valid CMS admin access allows attackers to deface sites, plant webshells and pivot into hosting infrastructure. Organizations running WordPress should check for compromised admin accounts and force password resets immediately.Access sale● 48
Venta de acceso admin a sitios WordPressSeller CLOUD9BASE is advertising valid WordPress administrator credentials in bulk, the kind of access that lets an intruder deploy webshells, deface sites or pivot into hosting. It is cross-posted across several forums, signalling an active broker, and any organisation running unpatched WordPress should treat it as a live risk.Access sale● 38
Venta de accesos de administrador de WordPress (URL y credenciales)A dump of WordPress administrator URLs paired with username and password credentials is being circulated, giving buyers ready access to web control panels. Sites running unpatched plugins are the usual victims, and such access is frequently the entry point for defacement, SEO spam or webshell deployment. No specific targets are named, so immediate relevance is limited, but it is a live access-sale listing.