zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - September 30, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - September 30, 2026

Product Serial: D-2026-09-30a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple threat groups posted new leak site entries, including ThreeAM Ransomware, Storm Ransomware, CHAOS Ransomware, Play Ransomware, and Wallstreet Ransomware, while The Gentlemen Ransomware added 26 new victims in a notable activity surge.
  • Unauthorized Access Marketplace: A threat actor advertised PMS access allegedly tied to an unnamed Japan-based hotel company on deep and dark web (DDW) Exploit.
  • Hacktivism: Pro-Iran group "GORZ ROSTAM" claimed a web defacement and unauthorized access targeting Appeal House, while pro-Palestinian group "313 Team" claimed a DDoS attack against Google Design, both via Telegram.
  • Data Dissemination and Telemetry: Threat actors posted several data sale claims, including alleged data tied to Transfast, HUB24, and Bangladesh Air Force, alongside smaller processed breach data sets. Credential systems ingested over 1.59 billion combined compromised account credentials (CAC) and botnet CAC records between September 2 and September 29, 2026.

Tags: tlp:clear,  dark web,  vulnerability/exploit,  data breach,  threat actor