ZeroFox Daily Deep and Dark Web Intelligence - July 27, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - July 27, 2026
Product Serial: D-2026-07-27a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed in deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 72 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple groups posted new leak site entries, including Qilin, Nova, Akira, Play, The Gentlemen, and SETTRA; a new extortion leak site, "GLOBAL SECRET GROUP," also emerged, listing dozens of disclosed and undisclosed entries.
- Unauthorized Access Claims: Actors advertised credential and access sales, including alleged credentials for multiple geospatial and satellite imagery platforms, root-level CMS access purportedly tied to nine organizations across multiple sectors, and RDWeb access purportedly to a U.S.-based real estate company and a Sweden-based marine and industrial engines supplier.
- Tooling Commercialization: An actor advertised pre-configured Google Workspace Enterprise Plus email infrastructure packages.
- Data Dissemination and Telemetry: Forums hosted breach and data sale claims, including data purportedly tied to Timer Immobilier posted on PwnForums. Separately, credential intelligence systems ingested over 1.2 billion combined compromised account credentials (CAC) and botnet records between June 29 and July 26, 2026.
Tags: tlp:clear, dark web, data breach, threat actor