ZeroFox Daily Deep and Dark Web Intelligence - September 16, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - September 16, 2026
Product Serial: D-2026-09-16a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple threat actor groups posted new leak site entries, including Akira, SafePay, Dire Wolf, CHAOS, and ShadowByt3$, while The Gentlemen listed 32 new entries. Unauthorized Access Marketplace: Threat actors auctioned privileged access to unnamed organizations on deep and dark web (DDW) forum Exploit, including network access purportedly tied to a Saudi Arabia-based engineering company and malware bot access tied to a U.S.-based organization. Vulnerability and Tooling Commercialization: Threat actors advertised offensive capabilities, including iOS exploit kits and attack chains, a one-day RCE exploit targeting Fortinet FortiWeb, and recruitment for a new Ransomware-as-a-Service affiliate program, "Dark Project." Hacktivist Operations: Two politically motivated actors claimed operations via Telegram, "Golden Falcon" warned that U.S. water facilities were under its surveillance, and a pro-Palestinian group "313 Team" claimed a DDoS attack against Saudi Arabia's General Directorate of Civil Defense. Data Dissemination and Telemetry: Threat actors advertised data allegedly tied to named commercial entities, including UAE oil-and-gas supplier Oil & Gas International FZC and Castleton Commodities Japan. Separately, credential intelligence systems ingested over 1.2 billion combined compromised account credentials (CAC) and botnet CAC between the August 19 and September 15, 2026 reporting period.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor