zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - October 2, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - October 2, 2026

Product Serial: D-2026-10-02a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple threat groups posted new leak site entries, including GENESIS Ransomware, REDACT, INC Ransomware, and n0n Ransomware.
  • Unauthorized Access Marketplace: Threat actors advertised SSH and FortiGate access allegedly tied to a Mexico-based telecommunications company, web shell access allegedly tied to a Thailand-based retail and hospitality company, and Tailscale access allegedly tied to an Asia-based aerospace technology company, on deep and dark web (DDW) forums Exploit, RehubCom, and DarkForums.
  • Law Enforcement Action: An international operation dubbed "Operation KillSwitch," led by German authorities, reportedly seized the KillSec ransomware group's dark web leak site and servers.
  • Data Dissemination and Telemetry: Forums hosted several data sale claims, including alleged data tied to Cisco Systems, over 2,690 alleged Google Cloud and Firebase credential files, and over 102 million scraped B2B records allegedly sourced from RevenueBase, on DDW forums DarkForums, XSS, and PwnForums. Credential systems ingested over 1.56 billion combined compromised account credentials (CAC) and botnet CAC records between September 4 and October 1, 2026.

Tags: tlp:clear,  dark web,  vulnerability/exploit,  data breach,  threat actor