Alleged Fullz, PrestaShop Access, RGT Source Code, and Database Leaks
SOCRadar Dark Web Team identified several new underground posts, including an alleged U.S. fullz sale, administrative access to a Czech Prestashop store, and a claimed source code leak affecting South Korean robotics company RGT. Other posts involved an alleged Brazilian healthcare data leak and a DLH.NET credential database claim, showing continued underground interest in identity data, e-commerce access, source code, and exposed user credentials.
Receive a Free Dark Web Report for Your Organization:
Alleged U.S. Fullz Data Sale is Detected

SOCRadar Dark Web Team detected a threat actor post advertising an alleged batch of 153,000+ U.S. fullz records. The seller described the data as fresh, unused, and not previously sold, positioning it as exclusive identity data for fraud-focused buyers.
The listing claimed the records include names, dates of birth, addresses, driver’s license information, phone numbers, Social Security numbers, bank account and routing numbers, and email addresses. If authentic, this type of dataset can support identity theft, account opening fraud, phishing, and financial abuse because it combines identity, contact, and banking details in one package.
Alleged Prestashop Admin Access is Detected

SOCRadar Dark Web Team detected a threat actor post auctioning alleged administrative access to a Czech Republic Prestashop store. The seller claimed the access provided full rights to the admin panel and referenced 3,045 credit card orders processed through redirection in the last 90 days.
The listing started at $500, with a $100 step and a $1,500 flash price. Access to an e-commerce admin panel can allow attackers to alter store content, review customer order data, modify payment flows, or deploy skimming logic, making this type of access valuable for payment fraud and follow-on compromise.
Alleged RGT Source Code Leak is Detected

SOCRadar Dark Web Team detected a post claiming a source code leak from RGT, also known as Robot Global Team, a South Korean robotics company focused on autonomous service robots. The actor claimed the leaked material came from RGT.kr and included stolen source code.
The exposure of source code can create long-term risk beyond the initial leak. If authentic, attackers or competitors could review proprietary logic, identify security weaknesses, or search for vulnerabilities in software used for robot integration and logistics automation. For technology manufacturers, source code leaks can affect both intellectual property and downstream product security.
Alleged Hospital Di Camp Data Leak is Detected

SOCRadar Dark Web Team detected a post claiming that Hospital Di Camp, a healthcare facility in Campo Grande, Brazil, was affected by a data leak. The post was linked to the threat actor group Doommageddon, which reportedly listed the hospital as a victim.
The visible listing did not clearly confirm the exact volume or full data scope, but healthcare-related exposure can carry high privacy risk if patient records, appointment data, internal files, or administrative documents are involved. If confirmed, the incident could create regulatory, reputational, and patient safety concerns due to the sensitivity of medical information.
Alleged DLH.NET User Database Exposure is Detected

SOCRadar Dark Web Team detected a threat actor post advertising an alleged DLH.NET user database. The seller claimed the dataset had expanded from 3.2 million to 4.7 million records, with 4.4 million reportedly dehashed into email and plain-password format.
The listing included samples containing email addresses, password hashes, and related account metadata. If authentic, the exposure creates a high risk of credential stuffing, especially for users who reused passwords across gaming, email, social media, or work accounts. Dehashed credentials are especially dangerous because attackers can immediately test them against other services without needing to crack the hashes themselves.
Powered by DarkMirror™
Gaining visibility into deep and dark web threats can be extremely useful from an actionable threat intelligence and digital risk protection perspective. However, monitoring all sources is simply not feasible, which can be time-consuming and challenging. One click-by-mistake can result in malware bot infection. To tackle these challenges, SOCRadar’s DarkMirror™ screen empowers your SOC team to follow up with the latest posts of threat actors and groups filtered by the targeted country or industry.
