As we countdown the final days of summer, we look back on a busy July for the dark web.
Last month brought a fake RaaS, a new episode in the ongoing ‘Forum Wars’ series, new phishing kits, and a notable rise in breaches impacting Latin America. In this month’s wrap-up we cover:
- The SECTION9 data-leak site that wasn’t
- Leak Society makes its debut into the cadre of forums vying for attention following the post-BreachForums shakeup
- A new doxxing site connected to RaidForums (no, not that version!) began operation
- Jalisco, a new PhaaS service, takes aim at Microsoft 365’s device token grant
Plus, in case you missed it, we also link to our deep dives on:
- SpyCloud Labs analysis of the law enforcement takedown of StealC: what we observed pre- and post-takedown, based on our recaptured data.
Let’s get into it!
Someone made a fake RaaS to embarrass cybersecurity vendors
In early July, a previously unknown ransomware group calling themselves SECTION9 launched a new dataleak site on Tor. The site listed a few dozen partially redacted victims, each with a country, sector, partially redacted website domain, and a countdown clock to when their stolen data would be released. Many threat intelligence monitoring firms were quick to report on the site and add SECTION9 to their ransomware trackers. Some even made more significant claims about their knowledge of SECTION9, such as enumerating their TTPs and even advertising ransomware file decryption services for SECTION9.
A few weeks later, SECTION9 revealed that the whole thing was fake. They stated that their aim in creating the site was to expose “ambulance chasing” by cybersecurity vendors and “test the credibility of vendors and service providers in the sector.” They also linked to some of the offending cybersecurity blogs and informational pages on SECTOR9 in an effort to call out their deceitful advertising practices.
Full text of the SECTION9 post revealing the entire site to be a ruse
While we at SpyCloud will refrain from calling out any vendors that were duped by this scheme, it should shock absolutely no one that it worked.
Latest Dispatch From the Forum Wars
In April 2025, BreachForums (the largest English-language data breach forum) went dark. Since then, there have been quite a number of new forums popping up – many of them short lived, and a few of them even named after BreachForums and its predecessor RaidForums. However, no clear successor has emerged in over a year since BreachForums went down. Some of the most interesting updates to this landscape from July include:
- Leak Society launched: A new data breach forum, which we have seen referred to as both Leak Society and Leaked recently came online. We first came across this forum being advertised on Spear Forums (a criminal forum with a particular focus on vishing that has some links to the Com).
Homepage for Leak Society
- A third BreachForums copycat enters the fray: In May, some of the forum administrators for Hasan’s BreachForums clone site took over the forum in a sort of coup d'état, ousting Hasan who had been the forum owner. At this point, this was one of two different sites calling themselves BreachForums and claiming to be the true BreachForums successor. Now – Hasan is back with a new BreachForums – adding a third separate BreachForums site to the mix.
Website banner for Hasan’s newest BreachForums copycat site – the third currently active forum calling itself BreachForums
- RaidForums makes their own doxbin – RaidBin: RaidForums, another new data breach forum that is named after an older and significantly more popular data breach forum, launched an offshoot website focused on doxxing. Doxxing is the act of posting personal information about someone online without their consent, with the intent of harassing or intimidating them. This is not the first recent forum to launch a separate affiliated doxxing site – in May we observed Hasan launch a site called DoxByte that was separate from – but still affiliated with – his version of BreachForums.
Telegram message announcing the new RaidBin website
- Fake LAPSUS$ retires: LAPSUS$ is a data theft extortion group that – like many of the examples above – chose to name themselves after a more famous past threat actor which they have no affiliation with. In July, they posted a message to their data leak site announcing that they would be retiring. In the post, LAPSUS$ stated that they had achieved their “financial objectives” and were going to let TeamPCP “take all the heat” so that they could “walk away clean with the money.” The Scattered LAPSUS$ Hunters collective, formed from Scattered Spider, LAPSUS$, and ShinyHunters, has spent the past year running one of the largest data-theft extortion sprees on record, including a Salesforce campaign that hit more than 1,000 organizations.
Website banner for Hasan’s newest BreachForums copycat site – the third currently active forum calling itself BreachForums
Jalisco and OmegaLord: Phishing Kits Built to Beat MFA
Device code phishing has been somewhat in vogue with bad actors lately, with several top-tier kits including Kali365 massively leveraging this mechanism to bypass MFA in Microsoft 365 environments. In a July 14 report, ReliaQuest pulled two phishing kits out of active campaigns against Microsoft 365 tenants and named them from their own command-and-control panels: Jalisco and OmegaLord.
Device code phishing usually carries a built-in weakness for the attacker, since the codes Microsoft issues expire after 15 minutes and a lure that sits in an inbox too long stops working. Jalisco removes that limit by calling a backend API to mint a fresh OAuth device code the moment a victim opens the page, so the clock never runs down. After the victim signs in and clears MFA, the operator enrolls attacker-controlled devices into the victim’s Entra ID tenant and picks up a Primary Refresh Token, which keeps access alive even after a password reset. ReliaQuest watched operators register five or more devices per compromised account, named to blend in with entries like “microsoft-” and “WINDOWS-“.
Example of a device code phishing attempt, showing the device code lure which prompts the user to enter the code after logging into their account on the legitimate login.microsoftonline.com portal
OmegaLord is the blunter tool: a JavaScript credential harvester disguised as a PDF reader login that grabs the victim’s phone number along with the password, most likely to help intercept MFA prompts later.
One aside before the next section: Jalisco is also the name of a Mexican state. The name seems like a coincidence and no relation to our next update from what we’re seeing in Latin American underground activity.
Emerging Trend: Rise in Latin American Data Breaches
So far in 2026, we’ve ingested roughly 2.9 times as many individual breaches from Latin American organizations, across both government and private industry, as our historical yearly average. That’s a big enough jump to ask whether something real is happening or whether we’re just watching our own collection get faster.
Chart showing YoY growth of SpyCloud-recaptured data breaches from Latin America, which shows a noticeable uptick in 2025 and the first two quarters of 2026
Chart showing the mechanism of breach for LATAM breaches collected so far in 2026. “Exfiltrated” means someone compromised something that was secure (or at least that someone made an effort to secure it), while “exposed” and “scraped” both indicate the data was at least publicly available (whether intentionally or unintentionally)
The obvious question: is this just a byproduct of how much more data we’ve ingested from this region since 2024?
Short answer: no.
Our LATAM collection rides along with our broader global collection effort. Until recently, the emerging Latin American ecosystem has been less of a focus for recapturing breaches due to the low volume in comparison to the ever-present activity coming from the Russian or Chinese sources.
It’s also not the exposed-database phenomenon, the low-effort scraped and AI-coded databases that keep surfacing on the open internet. Most of these breaches were exfiltrated, meaning someone broke into a system that was at least nominally secured, rather than scraped or left sitting on an open server.
The industry split tells a similar story. Top sectors – government and education – account for most of the volume, which is what you’d expect if actors are hitting organizations that hold real data rather than harvesting whatever’s already public. The large “Unclassified” share reflects source data that doesn’t map cleanly to a primary industry, not an absence of victims.
Chart showing the industry breakdown of breaches collected from LATAM since August 2025. Industry is automatically determined by SpyCloud based on available source data and is labeled “Unclassified” when no specific primary industry can be identified
Over the last few years, we have also noticed more and more Latin American-based actors engaging in English-language breach spaces. For example, USDoD (a very prominent actor on BreachForums in the 2023-2024 time frame) was revealed to be a Brazilian national and was arrested in late 2024. We have also recently noticed a lot of Spanish-language posts popping up on primarily English-speaking forums. On some of these forums – such as pwnforums – moderators still tend to enforce a primarily English-speaking space. We have observed pwnforums moderators actually instructing users who post in Spanish to add English translations to any posts made in foreign languages.
Screenshots from a Spanish-language post to pwnforums about an alleged breach of a local government body in Chiapas Mexico. A forum moderator responded to the post, advising that they must post in English, and stating that they edited the post to add an English translation
Taken together, these signals point in one direction. The rise in LATAM breach data reflects a real expansion of the region’s cybercrime activity rather than an artifact of how we collect. Most of what we recaptured was exfiltrated, not scraped or left exposed, which means actors are breaking into organizations, not just harvesting what’s already public. And the people behind these breaches are increasingly at home in English-language forums, moving out of Portuguese- and Spanish-speaking corners of the ecosystem and into the same spaces where BreachForums-era actors like USDoD made their names. We’ll keep watching both, and we expect LATAM’s share of our breach ingest to keep climbing through the rest of 2026.
Other research insights from SpyCloud Labs
On June 24, 2026, an international law enforcement coalition seized the infrastructure behind StealC, one of the more widely used information stealers of the past three years.
Attackers are finding new ways to make MFA irrelevant, and device code phishing is their latest weapon. This adversary-in-the-middle (AiTM) technique exploits the legitimate OAuth 2.0 Device Authorization Grant flow, tricking users into entering an attacker-generated code that issues active session tokens directly to the attacker’s device. Here’s what you need to know.