Finnish Kennel Club, Shell Access, UK Iframe, Salt Mobile, and Brazil SERPRO Claims
SOCRadar Dark Web Team identified several new underground posts, including an alleged Finnish Kennel Club and Showlink dog-show database leak, and a separate initial access listing offering shell and WordPress access to websites in Indonesia and Romania. Other posts advertised alleged shell access to a UK site with an iframe-based payment form, an alleged Salt Mobile customer database, and a large Brazil citizen database allegedly linked to SERPRO.
Receive a Free Dark Web Report for Your Organization:
Alleged Finnish Kennel Club Dog Show Database Leak is Detected

SOCRadar Dark Web Team detected a threat actor post on a dark web forum sharing an alleged database linked to Showlink and the Finnish Kennel Club. The listing claimed the dataset contains 105,000+ dog-show records associated with Finnish dog-show activities. The exposed fields reportedly include show identifiers, entry references, entry fees, dog registration numbers, breed, class, sex, dog names, titles, birth dates, color, sire and dam details, breeder information, race numbers, timestamps, results, scheduling data, and handler or owner fields.
The dataset is sensitive because it appears to combine participant information with animal registration and event-management records. If authentic, the exposure could support targeted phishing, identity profiling, and scams against owners, breeders, handlers, and dog-show participants. The source also noted that the data appears structured and includes fields such as owner names, addresses, emails, phone numbers, timestamps, and invoice IDs, suggesting it may have come from a backend management system.
Alleged Shell and WordPress Access to Indonesian and Romanian Websites is Detected

SOCRadar Dark Web Team detected a threat actor post advertising unauthorized access to three websites across Indonesia and Romania. The listing offered shell access for two Indonesian websites and a WordPress admin login for a Romanian website, with the actor pricing each access separately and offering a bundle deal for all three.
The post is notable because shell access and WordPress administrator access can give attackers control over site files, plugins, user data, and hosted content. If valid, this type of access could be used for phishing page hosting, malware delivery, web skimming, data theft, or further compromise of the underlying hosting environment. The presence of proof links in the post increased the likelihood that the actor had active unauthorized access.
Alleged UK Web Shell Access With Iframe Payment Form is Detected

SOCRadar Dark Web Team detected a threat actor post auctioning alleged shell access to a UK-based website using a custom CMS. The actor claimed the site included an iframe-based payment form and listed payment activity for May, June, and July, seemingly to market the access to buyers interested in monetizing payment flows.
This type of listing is concerning because web shell access can allow file modification, command execution, and persistent server access. The mention of an iframe payment form may indicate possible value for payment card theft or Magecart-style skimming if attackers can inject or alter scripts in the checkout flow. The victim was not named, so the claim remains limited to the actor’s description and should be treated as unverified.
Alleged Salt Mobile Customer Database Sale is Detected

SOCRadar Dark Web Team detected a post advertising an alleged Salt Mobile database containing more than 1.09 million customer records. The actor claimed the dataset includes names, dates of birth, full physical addresses, email addresses, and multiple telephone numbers.
This exposure could create significant risk for Salt Mobile customers because telecom-related PII can support SIM swap attempts, impersonation, targeted phishing, and identity theft. The claim has not been independently confirmed by the company in the source material, but the volume and type of data described make it a high-impact telecom exposure if validated.
Alleged Brazil SERPRO Citizen Database Leak is Detected

SOCRadar Dark Web Team detected a threat actor post claiming to leak a massive Brazil citizen database allegedly sourced from SERPRO, Brazil’s federal data processing service. The actor claimed the dataset contains approximately 214 million records, with exposed data including full names, CPF tax identification numbers, gender, and dates of birth.
The claimed scale makes this one of the most severe posts in the set. CPF numbers combined with identity attributes can be highly valuable for financial fraud, identity theft, account verification abuse, and social engineering campaigns targeting Brazilian citizens. The source notes that the actor provided a sample and database file as evidence, but the full origin and scope still require further validation.
Powered by DarkMirror™
Gaining visibility into deep and dark web threats can be extremely useful from an actionable threat intelligence and digital risk protection perspective. However, monitoring all sources is simply not feasible, which can be time-consuming and challenging. One click-by-mistake can result in malware bot infection. To tackle these challenges, SOCRadar’s DarkMirror™ screen empowers your SOC team to follow up with the latest posts of threat actors and groups filtered by the targeted country or industry.

