zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - August 3, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - August 3, 2026

Product Serial: D-2026-08-03a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 72 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Several threat actor groups, including Qilin, Orion Leaks, CoinbaseCartel, Cl0p, FALCON, and PEAR, posted new leak site entries; The Gentlemen added 27 new entries to its site in a single posting spree.
  • Unauthorized Access Marketplace: Threat actors "Trim" and "Big-Bro" auctioned administrator-level web panel and RDWeb access allegedly tied to unnamed travel and software organizations on the deep and dark web (DDW) forum Exploit.
  • New Extortion Infrastructure: ZeroFox observed a new Tor-based leak site operating as "FALCON" with its first entry already posted.
  • Data Dissemination and Telemetry: Threat actors posted multiple breach and data sale claims on DDW forums, including XSS, DarkForums, and PwnForums, targeting financial services, including Bank of America, "Citigroup Securities," and South African Reserve Bank. Separately, credential intelligence systems ingested over 1.3 billion combined compromised account credentials (CAC) and botnet records between July 6 and August 2, 2026.

Tags: tlp:clear dark web vulnerability/exploit data breach threat actor