[weglot_switcher]
Cybercrime update graphic showing ShinyHunters and criminal forums trends.

The SECTION9 Hoax, Forum Wars, & Phishing Kits Built to Beat MFA

Table of Contents

Check your exposure

As we countdown the final days of summer, we look back on a busy July for the dark web.

Last month brought a fake RaaS, a new episode in the ongoing ‘Forum Wars’ series, new phishing kits, and a notable rise in breaches impacting Latin America. In this month’s wrap-up we cover:

Plus, in case you missed it, we also link to our deep dives on:

Let’s get into it!

Someone made a fake RaaS to embarrass cybersecurity vendors

In early July, a previously unknown ransomware group calling themselves SECTION9 launched a new dataleak site on Tor. The site listed a few dozen partially redacted victims, each with a country, sector, partially redacted website domain, and a countdown clock to when their stolen data would be released. Many threat intelligence monitoring firms were quick to report on the site and add SECTION9 to their ransomware trackers. Some even made more significant claims about their knowledge of SECTION9, such as enumerating their TTPs and even advertising ransomware file decryption services for SECTION9. 

A few weeks later, SECTION9 revealed that the whole thing was fake. They stated that their aim in creating the site was to expose “ambulance chasing” by cybersecurity vendors and “test the credibility of vendors and service providers in the sector.” They also linked to some of the offending cybersecurity blogs and informational pages on SECTOR9 in an effort to call out their deceitful advertising practices.

Analysis of ransomware and phishing kits used to bypass MFA security measures.

Full text of the SECTION9 post revealing the entire site to be a ruse

While we at SpyCloud will refrain from calling out any vendors that were duped by this scheme, it should shock absolutely no one that it worked. 

Latest Dispatch From the Forum Wars

In April 2025, BreachForums (the largest English-language data breach forum) went dark. Since then, there have been quite a number of new forums popping up – many of them short lived, and a few of them even named after BreachForums and its predecessor RaidForums. However, no clear successor has emerged in over a year since BreachForums went down. Some of the most interesting updates to this landscape from July include: 

Screenshot of SpyCloud dashboard showing cybersecurity threats and user activity.

Homepage for Leak Society

Cybersecurity concept with anime-style characters and digital security elements.

Website banner for Hasan’s newest BreachForums copycat site – the third currently active forum calling itself BreachForums

RaidBin logo with a sinister skull and spider design in red and black.

Telegram message announcing the new RaidBin website

Cybersecurity alert with phishing and hacking themes for SEO.

Website banner for Hasan’s newest BreachForums copycat site – the third currently active forum calling itself BreachForums

Jalisco and OmegaLord: Phishing Kits Built to Beat MFA

Device code phishing has been somewhat in vogue with bad actors lately, with several top-tier kits including Kali365 massively leveraging this mechanism to bypass MFA in Microsoft 365 environments. In a July 14 report, ReliaQuest pulled two phishing kits out of active campaigns against Microsoft 365 tenants and named them from their own command-and-control panels: Jalisco and OmegaLord.

Device code phishing usually carries a built-in weakness for the attacker, since the codes Microsoft issues expire after 15 minutes and a lure that sits in an inbox too long stops working. Jalisco removes that limit by calling a backend API to mint a fresh OAuth device code the moment a victim opens the page, so the clock never runs down. After the victim signs in and clears MFA, the operator enrolls attacker-controlled devices into the victim’s Entra ID tenant and picks up a Primary Refresh Token, which keeps access alive even after a password reset. ReliaQuest watched operators register five or more devices per compromised account, named to blend in with entries like “microsoft-” and “WINDOWS-“.

Microsoft sign-in page and Dropbox file sharing verification screenshot.

 Example of a device code phishing attempt, showing the device code lure which prompts the user to enter the code after logging into their account on the legitimate login.microsoftonline.com portal

OmegaLord is the blunter tool: a JavaScript credential harvester disguised as a PDF reader login that grabs the victim’s phone number along with the password, most likely to help intercept MFA prompts later. 

 

One aside before the next section: Jalisco is also the name of a Mexican state. The name seems like a coincidence and no relation to our next update from what we’re seeing in Latin American underground activity.

Emerging Trend: Rise in Latin American Data Breaches

So far in 2026, we’ve ingested roughly 2.9 times as many individual breaches from Latin American organizations, across both government and private industry, as our historical yearly average. That’s a big enough jump to ask whether something real is happening or whether we’re just watching our own collection get faster.

Graph showing LATAM breach activity and share of catalog from 2021 to 2026.

Chart showing YoY growth of SpyCloud-recaptured data breaches from Latin America, which shows a noticeable uptick in 2025 and the first two quarters of 2026

Bar chart showing breach mechanism distribution with exfiltrated data most common.

Chart showing the mechanism of breach for LATAM breaches collected so far in 2026. “Exfiltrated” means someone compromised something that was secure (or at least that someone made an effort to secure it), while “exposed” and “scraped” both indicate the data was at least publicly available (whether intentionally or unintentionally)

The obvious question: is this just a byproduct of how much more data we’ve ingested from this region since 2024?

Short answer: no. 

Our LATAM collection rides along with our broader global collection effort. Until recently, the emerging Latin American ecosystem has been less of a focus for recapturing breaches due to the low volume in comparison to the ever-present activity coming from the Russian or Chinese sources.

It’s also not the exposed-database phenomenon, the low-effort scraped and AI-coded databases that keep surfacing on the open internet. Most of these breaches were exfiltrated, meaning someone broke into a system that was at least nominally secured, rather than scraped or left sitting on an open server.

The industry split tells a similar story. Top sectors – government and education – account for most of the volume, which is what you’d expect if actors are hitting organizations that hold real data rather than harvesting whatever’s already public. The large “Unclassified” share reflects source data that doesn’t map cleanly to a primary industry, not an absence of victims.

Bar chart showing LATAM breach entries by industry since August 2025.

Chart showing the industry breakdown of breaches collected from LATAM since August 2025. Industry is automatically determined by SpyCloud based on available source data and is labeled “Unclassified” when no specific primary industry can be identified

Over the last few years, we have also noticed more and more Latin American-based actors engaging in English-language breach spaces. For example, USDoD (a very prominent actor on BreachForums in the 2023-2024 time frame) was revealed to be a Brazilian national and was arrested in late 2024. We have also recently noticed a lot of Spanish-language posts popping up on primarily English-speaking forums. On some of these forums – such as pwnforums – moderators still tend to enforce a primarily English-speaking space. We have observed pwnforums moderators actually instructing users who post in Spanish to add English translations to any posts made in foreign languages. 

Cybersecurity data breach illustration with SpyCloud branding.
Cybersecurity threat analysis featuring SpyCloud data and phishing kit visuals.

Screenshots from a Spanish-language post to pwnforums about an alleged breach of a local government body in Chiapas Mexico. A forum moderator responded to the post, advising that they must post in English, and stating that they edited the post to add an English translation

Taken together, these signals point in one direction. The rise in LATAM breach data reflects a real expansion of the region’s cybercrime activity rather than an artifact of how we collect. Most of what we recaptured was exfiltrated, not scraped or left exposed, which means actors are breaking into organizations, not just harvesting what’s already public. And the people behind these breaches are increasingly at home in English-language forums, moving out of Portuguese- and Spanish-speaking corners of the ecosystem and into the same spaces where BreachForums-era actors like USDoD made their names. We’ll keep watching both, and we expect LATAM’s share of our breach ingest to keep climbing through the rest of 2026.

Other research insights from SpyCloud Labs

On June 24, 2026, an international law enforcement coalition seized the infrastructure behind StealC, one of the more widely used information stealers of the past three years. 

Attackers are finding new ways to make MFA irrelevant, and device code phishing is their latest weapon. This adversary-in-the-middle (AiTM) technique exploits the legitimate OAuth 2.0 Device Authorization Grant flow, tricking users into entering an attacker-generated code that issues active session tokens directly to the attacker’s device. Here’s what you need to know.

Recaptured data numbers for July 2026

July monthly total

Total New Recaptured Data Records for July:
1,957,804,104

New third-party breach data this month

Third-Party Breaches Parsed and Ingested:
3,271
New Data Records from Third-Party Breaches:
1,304,859,434

New recaptured phished data this month

New Phished Data Records:
6,373,022

New infostealer malware data this month

Stealer Logs Parsed and Ingested:
4,372,142
New Data Records from Stealer Infections:
130,428,609
New Stolen Cookie Records:
522,516,061

Discover what cybercriminals know about your business and your customers – and how to prevent targeted attacks with SpyCloud.

Keep reading

Analysis of Stealc malware takedown by SpyCloud for cybersecurity.
Peers Held, StealC Didn’t: Analyzing the June 24 Takedown in SpyCloud’s Data
SpyCloud Labs data shows StealC fell 90% before the June 24 Operation Endgame takedown. See what our post-takedown analysis reveals.
Cybercrime update graphic showing ShinyHunters and criminal forums trends.
The Klue Breach, SocGholish Cleanup, and AI Cybercrime Slop
Read on for the latest from the criminal underground, including details of the Klue breach, Operation Endgame’s latest malware disruption, and trends in AI cybercrime slop.
SpyCloud logo with FortiBleed threat actor infrastructure background.
More Than a Leak: What SpyCloud Found Inside the FortiBleed Threat Actor Infrastructure
SpyCloud Labs analyzed the media-dubbed “FortiBleed” leak and found that initial reports left some key information out. See what we found after parsing and analyzing the data to understand the full impact.

Check Your Company's Exposure

See your real-time exposure details powered by SpyCloud.

X