Back to Feed
Threat IntelligenceMay 12, 2026

Daily Dose of Dark Web Informer - May 12th, 2026

Dark Web Informer daily digest reports multiple breaches, ransomware claims, and threat actor activity.

Summary

This is a daily dark web threat intelligence digest aggregating multiple breach reports, ransomware claims, and threat actor activity from May 12, 2026. Notable incidents include alleged breaches of Kuwaiti government identity records (5.23M citizens), Egyptian e-commerce platform FutureShop, Brazilian betting platform MBet (200k+ KYC docs), Dubai fashion retailer SIVVI (300k+ records), and Indonesian government agency BPJS. The digest also tracks threat actor operations including ShinyHunters domain suspension, Nightmare-Eclipse GitHub releases, and various malware tools like Shai-Hulud being open-sourced.

Full text

Dark Web Informer β€” Daily Threat Intelligence Digest πŸ”‘ API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. Explore API β†’ πŸ” Follow across all official platforms β€” darkwebinformer.com/socials πŸ”₯ Advertising Opportunities Reach a highly engaged audience. View details 56.2k Unique Visitors 122.1k Pageviews Last 30 days as of May 11, 2026. Next update June 11th. πŸ”’ Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. View Plans & Subscribe β†’ πŸ“Œ Legend πŸ“°Law Enforcement β€” LEA updates, investigations ⚠️Dark Web Notices β€” forums, markets, announcements ❗️Urgent Threats β€” breaches, ransomware, vulnerabilities πŸ’‘Insights & Tools β€” guides, OSINT, learning resources 🧾 Today's Intelligence Threat Intelligence ❗️ Public Authority for Civil Information Allegedly Breached Exposing 5.23 Million Kuwaiti Citizen Records From the Kuwaiti Government Identity Authority FREE ❗️ FutureShop Egypt Allegedly Breached Exposing Thousands of Customer, Order, and Delivery Records From the Egyptian Grocery Delivery Platform FREE X/Twitter Updates πŸ’‘ Looks like Instructure made payment to ShinyHunters ❗️ MBet allegedly breached exposing 200,000+ KYC documents and 300,000+ PII records from the Brazilian online casino and sports betting platform ❗️ Nightmare-Eclipse has just released two new GitHub repositories... Same user behind RedSun, UnDefend, BlueHammer ❗️ SIVVI allegedly breached exposing approximately 300,000 customer records from the Dubai-based fashion e-commerce platform ❗️ BPJS Ketenagakerjaan Kota Metro allegedly leaked exposing personal data of RT, RW, and LPM neighborhood officials in Karangrejo, North Metro, Indonesia ❗️ ShinyHunters confirms their clearnet domain was suspended and it is no longer operated or owned by them anymore. πŸ’‘ How dumb can you be... ❗️ A threat actor is selling a private cloud-hosted collection of stealer logs totaling 988.7 GB across more than 10,080 files in URL:Login:Password format. ❗️ 313 Team is claiming to target Spotify ❗️ PGP Signed message and the repos now have information: ❗️ TeamPCP has open sourced Shai-Hulud ❗️ Note: This a repost from the leak by threat actor "breach3d." This actor is asking for a $20,000 ransom. It is not verified if anything in this leak differs from the previous leak in April. ❗️ OHNO allegedly breached exposing Telegram user IDs, crypto wallets, and private keys from the on-chain trading automation platform ❗️ AIM Smarter allegedly breached exposing 6,500+ business records from the UK promotional products and marketing distribution group πŸ’‘ Bruh

Indicators of Compromise

  • malware β€” Shai-Hulud
  • malware β€” RedSun
  • malware β€” UnDefend
  • malware β€” BlueHammer

Entities

ShinyHunters (threat_actor)Nightmare-Eclipse (threat_actor)313 Team (threat_actor)TeamPCP (threat_actor)OHNO (threat_actor)Instructure (product)