ZeroFox Daily Deep and Dark Web Intelligence - September 30, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - September 30, 2026
Product Serial: D-2026-09-30a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple threat groups posted new leak site entries, including ThreeAM Ransomware, Storm Ransomware, CHAOS Ransomware, Play Ransomware, and Wallstreet Ransomware, while The Gentlemen Ransomware added 26 new victims in a notable activity surge.
- Unauthorized Access Marketplace: A threat actor advertised PMS access allegedly tied to an unnamed Japan-based hotel company on deep and dark web (DDW) Exploit.
- Hacktivism: Pro-Iran group "GORZ ROSTAM" claimed a web defacement and unauthorized access targeting Appeal House, while pro-Palestinian group "313 Team" claimed a DDoS attack against Google Design, both via Telegram.
- Data Dissemination and Telemetry: Threat actors posted several data sale claims, including alleged data tied to Transfast, HUB24, and Bangladesh Air Force, alongside smaller processed breach data sets. Credential systems ingested over 1.59 billion combined compromised account credentials (CAC) and botnet CAC records between September 2 and September 29, 2026.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor