ZeroFox Daily Deep and Dark Web Intelligence - July 28, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - July 28, 2026
Product Serial: D-2026-07-28a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed in deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple digital extortion groups posted new leak-site entries, including ShinyHunters, Qilin, BLACKWATER, Triple X, Kairos, Insomnia, and BravoX, with CRPx0 alone listing 29 new entries.
- Unauthorized Access Marketplace: Threat actors advertised network and administrative access allegedly tied to a South Korea-based software company, an undisclosed telecommunications company (AWS STS), a U.S.-based hospitality company (Fortinet VPN), and the Saudi Arabia government web ecosystem (.gov.sa domain), across multiple deep and dark web forums.
- Leak Site and Marketplace Emergence: Three new dark web sites surfaced—ExfilSquad (15 entries), SECTION9 (25 undisclosed entries), and SHIBA (no entries listed yet).
- Data Dissemination and Telemetry: Forums hosted several breach and data-sale claims referencing government and private-sector organizations, including alleged leaks tied to NúcleoGov and a UAE federal identity and customs authority. Separately, credential intelligence systems ingested over 1.29 billion combined compromised account (CAC) and botnet records between June 30 and July 27, 2026.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor