Imobiliare.ro, Klark.ai, Fortinet VPN, E-Commerce Skimming, and Solimut SQLi
SOCRadar Dark Web Team identified several new underground posts involving alleged database leaks, exposed remote access, and access-for-sale activity. The findings include an alleged Imobiliare.ro user database sale, administrative Fortinet SSL-VPN access tied to a UAE hotel reservation firm, an alleged Klark.ai data leak, a U.S. e-commerce iframe skimming operation, and alleged SQL injection access affecting Solimut Mutuelle de France.
Receive a Free Dark Web Report for Your Organization:
Alleged Imobiliare.ro User Database Sale is Detected

SOCRadar Dark Web Team detected a threat actor post advertising an alleged database from Imobiliare.ro, a Romanian real estate platform. The seller claimed the dataset contains 1.2 million user records and said the access was obtained through an exposed ASP.NET debug configuration in the production environment.
According to the listing, the actor claimed that customErrors=Off and debug=True allowed them to trigger a verbose error page through a non-existent URL. The error page allegedly exposed the production SQL Server cluster connection string, enabling access to backend data.
The alleged database reportedly includes user emails, phone numbers, property listings, and transaction history. If authentic, this exposure could support phishing, real estate fraud, and highly targeted scams using property and transaction context.
Alleged UAE Fortinet SSL-VPN Access is Detected

SOCRadar Dark Web Team detected an initial access broker post advertising administrative access to a UAE-based hotel reservation company. The listing claimed the access was obtained through Fortinet SSL-VPN and included admin rights over an environment with approximately 1,450 network hosts.
The actor described the target as a hotel reservation firm with reported revenue of $17 million and listed the access for $700. The post also included a Tox contact for purchase discussions.
Alleged Klark.ai Data Leak is Detected

SOCRadar Dark Web Team detected a post claiming that data from Klark.ai, an AI customer service platform, was leaked on an underground forum. The actor claimed the leak includes 140 GB of data across 162 CSV files, with some files allegedly exceeding two million lines.
The claimed data types include names, emails, phone numbers, hashed passwords, customer service conversations, exchange logs, API keys, secret API tokens, and IBANs. The presence of API credentials is especially important, because exposed tokens can create risk not only for the platform but also for connected customer environments.
Alleged U.S. E-Commerce Iframe Access is Detected

SOCRadar Dark Web Team detected a post auctioning alleged access to a network of U.S.-based e-commerce shops. The actor claimed to have shell access across a grid of 60 shops, with 10 active sites currently redirecting customers to the same payment form through a malicious iframe.
The listing described the payment form as Braintree-themed and claimed that 1,030 card transactions were captured from the active shops during May. The auction started at $2,000, with a $5,000 blitz price.
This activity resembles digital skimming operations, where attackers modify checkout flows to steal payment data before it reaches the legitimate processor. E-commerce operators should review checkout pages, iframe behavior, server-side file changes, and Content Security Policy rules for signs of unauthorized modification.
Alleged Solimut SQL Injection Access is Detected

SOCRadar Dark Web Team detected a post advertising alleged database access for Solimut Mutuelle de France. The actor claimed the access was obtained through an error-based SQL injection vulnerability in a web portal and said the database uses Sybase.
The listing claimed the main database contains more than 1,000 tables and information on approximately 770,000 members. The sample reportedly included names, IBANs, BICs, and internal IDs, while the actor stated they were selling access rather than dumping the full database due to size and network limitations.
Powered by DarkMirror™
Gaining visibility into deep and dark web threats can be extremely useful from an actionable threat intelligence and digital risk protection perspective. However, monitoring all sources is simply not feasible, which can be time-consuming and challenging. One click-by-mistake can result in malware bot infection. To tackle these challenges, SOCRadar’s DarkMirror™ screen empowers your SOC team to follow up with the latest posts of threat actors and groups filtered by the targeted country or industry.

