Cyberthreats/Incidents

Dead databases and live money: an investigation into database remonetization and dark web actor behavior

Streltsov Dmitry

Streltsov Dmitry

Analyst, International Analytics Group, PT Cyber Analytics

About the report

Every year, cybersecurity analysts observe hundreds of databases being leaked on dark web platforms. However, researchers rarely explore who continues to exploit this data, and how they do it, months or even years after the initial release.

In this research, we focused less on the secondary market for leaked data itself and more on the specific tactics of dark web community members. We tracked how older, previously published databases resurface for sale, how threat actors fabricate the illusion of a fresh breach, and the specific schemes used to remonetize data. Analyzing this secondary market and the behavior of its participants is crucial for predicting cyberthreats and mitigating organizational risks.

The report primarily focuses on cases involving the exploitation of high-profile brand names and the creation of affiliated account networks. We structured our research as a digital investigation, analyzing forum posts, contact information, overlapping threat actor accounts, and disputes between data brokers. Our team examined over 30 sources, including dark web forums, cybercrime-focused Telegram channels, and open-source intelligence.

This report is designed for cybersecurity professionals, threat intelligence analysts, and any organizations or individuals seeking to understand modern cyberthreats, the inner workings of the dark web market, and the risks associated with compromised databases.

Executive summary

  • One of the notable trends in 2025 was the mass public release of previously private databases, particularly those belonging to companies in Russia and the CIS region

  • The republication and resale of leaked data amplify threat actor interest in targeted companies, increasing the likelihood of subsequent attacks and complicating attribution

  • Threat actors frequently masquerade old, publicly available databases as fresh or private breaches

  • Selling old databases under the guise of new breaches allows threat actors to attract attention, boost their reputation within the cybercriminal underground, and remonetize old data without actually possessing access to the victim's infrastructure
  • Exploiting recognizable, high-profile names builds trust among dark web community members and accelerates data monetization. For instance, cybercriminals impersonate well-known entities like ShinyHunters or Babuk Locker1. To achieve this, they create networks of channels and accounts that mimic the communication style of established threat groups
  • While fake accounts do appear on dark web forums, built-in reputation systems and community moderation typically neutralize their activity quickly. Telegram has become the primary platform for this type of activity

1Babuk Locker is a ransomware group known for its highly targeted approach to attacks. Their ransom demands typically ranged from $60,000 to $85,000. In 2021, the source code for their ransomware was leaked to the public.

Introduction

The media landscape is saturated with reports of corporate data breaches and the emergence of new databases on the clear web or dark web forums. While these incidents initially generate significant attention, they quickly fade from the news cycle. The relentless pace of new breaches creates a false sense of security, leading to the misconception that once a database is made public, it loses its value to cybercriminals. For instance, a major trend in 2025 has been the mass public release of previously private databases, particularly those belonging to organizations in Russia and the CIS region. Data that was once traded exclusively within closed communities or sold to the highest bidder is now increasingly surfacing on public or semi-private Telegram channels and dark web forums.

However, the reality within the cybercriminal underground is quite different. Even older, formally "dead" databases2 continue to circulate, undergo resale, and be exploited for malicious purposes. Furthermore, an entirely separate shadow economy has emerged around this data, where value is dictated not by the novelty of the leak, but by the potential for remonetization. A key indicator of this trend is the frequent conflicts that arise between database vendors. Disputes and accusations regarding data exclusivity often expose the inner workings of the underground market, revealing exactly how older leaks continue to generate profit. Consequently, threat actors develop sophisticated remonetization schemes, which even include impersonating notorious cybercrime syndicates. By co-opting the recognizable names of established groups, these actors build trust in their offerings, successfully transforming dead databases into a lucrative revenue stream.

2In the context of this report, a "dead database" refers to a data leak that was published a significant time ago (for example, in 2022) and is no longer formally considered an active incident.

Risks to organizations

The availability of stolen data in public or semi-private domains means that the threat to an organization has not passed. On the contrary, the continuous circulation of old databases and their persistent reappearance on dark web resources often drive increased interest from threat actors. An organization whose data remains available for sale or public download effectively stays on the radar of cybercriminals for an extended period.

One significant risk is the weaponization of this data for phishing attacks. Even outdated databases enable threat actors to craft highly convincing social engineering lures by leveraging real customer and employee names, email addresses, phone numbers, and details regarding orders or financial transactions. Similarly, this data can be weaponized against the organization's contractors and supply chain partners, particularly if the leak exposes the contact details of key personnel, contract information, or internal communication workflows.

Furthermore, leaked datasets frequently expose sensitive information about a company's IT infrastructure.

This may include:

  • Internal domains and subdomains
  • Service names
  • System identifiers
  • User credentials
  • IP addresses
  • Email gateways or third-party platforms in use

Even if some of this information is outdated, it can still be leveraged for initial reconnaissance, allowing threat actors to map the target infrastructure and stage more sophisticated attacks. Consequently, this significantly increases the likelihood of successful compromises against both the organization and its supply chain.

The credentials contained within leaked databases pose a distinct threat. Even if a data breach occurred several years ago, a portion of the compromised usernames and passwords may remain valid. Experience shows that users frequently reuse passwords, make only minor modifications to them, or fail to update their credentials entirely following an incident. As a result, this legacy data is actively weaponized for credential stuffing and brute-force attacks, or to establish initial access to corporate networks.

Ultimately, these factors complicate threat forecasting for organizations. Cyberrisks are driven not only by active incidents. The residual risk from past data breaches is a significant factor, because the continuous circulation of this data on the dark web keeps the targeted company in the crosshairs of cybercriminals. Therefore, factoring in the secondary market for leaked data is a critical component of assessing current risks and developing robust threat models.

Is a leak a new incident?

Amid the widespread availability of leaked databases in the public domain, a trend has emerged where the mere publication of data is often perceived as a new security incident. Various threat actor groups and lone cybercriminals actively exploit this misconception, recycling previously compromised, publicly available data and presenting it as the result of recent breaches. Their primary goal is to garner attention and bolster their reputation within the cybercriminal underground. This deceptive practice complicates the threat landscape, blurring the lines between genuine, new compromises and the recycling of historical data.

A prime example of this tactic was recently demonstrated by the RED EYES threat group. On January 16, the threat actors posted a statement on their channel claiming to have breached Yamm, a Saudi Arabian company that provides automated returns, exchanges, and post-purchase service solutions for e-commerce platforms. The post included assertions that the company's infrastructure had been compromised and offered a database for sale, framing the data leak as the direct result of a brand-new cyberattack3.

3The post was subsequently edited to include an announcement that the database had been published in another channel operated by the group.

Figure 1. Post advertising the sale of the Yamm database
Figure 1. Post advertising the sale of the Yamm database

Shortly after the claim was made, a cyberthreat intelligence (CTI) researcher specializing in the Middle East published an analysis of the leak, noting that the data had previously surfaced on the dark web and should not be classified as a new incident. The analysis revealed that the circulated data actually stems from a data breach published back in July 2025. It was originally leaked by a threat actor operating under the alias 888 on underground forums. The database contains records related to customer inquiries and returns, including order IDs, refund amounts, and customer details. However, it lacks any indicators of recent unauthorized access or the addition of fresh data. The researcher's findings confirm that the threat actors are recycling the exact same datasets with an identical field structure.

Figure 2. Researcher's post analyzing the database
Figure 2. Researcher's post analyzing the database

Auto-translation of Figure 2

"The RED EYES account published a statement claiming to have breached the platform of Yamm, a Saudi Arabian company providing automated returns, exchanges, and post-purchase service solutions for e-commerce stores.

Verification and analysis revealed the following:

  • The claim is not new
  • The circulated data stems from an older data breach dating back to July 2025
  • The identical dataset was previously published on a dark web forum by a threat actor using the alias 888, containing approximately 46,000 records related to orders and returns (order ID, refund amount, customer info)
  • There are no indicators of a recent compromise or the addition of fresh data

Recurring pattern:

  • Republishing the exact same files
  • Utilizing the identical field structure and data samples, with only the name of the claiming party changing
  • Marketing an old data breach as a new cyberattack

Analytical note:

Recently, the RED EYES threat group has become known for recycling previously leaked data and presenting it as new compromises, falsely claiming credit for the attacks. However, the threat actors fail to provide any evidence of actual infrastructure access or any other operational impact on the targeted networks."

Another example is a claim made by the same RED EYES threat group on January 16, alleging the compromise of the Saudi Arabian company Baran.

Figure 3. Post claiming the compromise of Baran and the sale of its database
Figure 3. Post claiming the compromise of Baran and the sale of its database

The post claimed that the threat actors had successfully exfiltrated approximately 21 GB of data. The database itself was offered for sale for $600. However, further analysis revealed that the circulated data was neither unique nor recently compromised. The data had already been published by a different threat group in February 2025 and had remained publicly accessible ever since. Similar to the Yamm case, this was not a new cyberattack, but rather the recommercialization of previously exposed and well-known data.

Figure 4. Original publication of the Baran database
Figure 4. Original publication of the Baran database

The behavior exhibited by this threat group is not unique; it reflects a global trend across dark web markets, particularly outside of strictly moderated underground forums. Recycling old data breaches and presenting them as fresh compromises allows cybercriminals to achieve multiple objectives simultaneously:

  • Attract the attention of their target audience
  • Artificially inflate their reputation within the cybercriminal underground
  • Monetize historical data breaches without possessing actual access to the victim's infrastructure

Consequently, a distinct ecosystem has emerged around outdated data. However, the practice of passing off old data breaches as new compromises is frequently condemned even within the cybercriminal community itself.

Demand for leaked databases

At first glance, one might assume that once a database is publicly released, interest in it would naturally decline. The logic seems straightforward: if the data is already out in the open and accessible to anyone, its commercial value should theoretically be lost. However, real-world practice proves otherwise. The underlying issue is not whether the data is publicly available, but rather the level of awareness among the cybercriminals themselves. Are they aware that the database has already been leaked, and can they accurately assess its true origin? Consequently, the market will always have opportunistic sellers willing to peddle public data as exclusive, alongside buyers ready to purchase it without verifying the sources.

A prime example of this persistent interest in previously leaked databases can be seen in recent activity on underground forums. For instance, on January 5, 2026, a user posted a request seeking to purchase the database of Zaymer, a Russian microfinance company specializing in quick online loans. Based on the context of the discussion, the request specifically targeted datasets associated with the zaymer[.]ru and zaymer[.]kz domains. However, the announcement regarding the compromise of the service's data had already been published back in 2024.

Figure 5. Request to purchase the Zaymer database
Figure 5. Request to purchase the Zaymer database
Figure 6. Post sharing the Zaymer database
Figure 6. Post sharing the Zaymer database

Despite this, the mere existence of the request indicates that the database retains its perceived value. There could be various reasons for this: the buyer might have been unaware of the original leak, or they might have hoped the seller possessed a more comprehensive version of the dataset. The fact that threat actors continue to seek out and offer such databases for sale years after their initial release underscores a sustained demand for previously exposed data. Ultimately, this demonstrates that a publicly available data breach does not automatically render the information commercially worthless.

Internal conflicts in the database market

Occasionally, dark web market trends are revealed not through new data leaks, claims, or discussions, but rather through the behavior of the threat actors themselves. This is precisely the case with leaked databases: the fierce competition for profit and reputation, combined with the drive to prove data exclusivity, sometimes results in open conflicts among underground market participants. For cybersecurity analysts, these incidents are valuable not merely as news events, but as a window into the actual monetization mechanisms of exfiltrated data.

One such dispute erupted between two data brokers who frequently operate on Telegram and prominent underground forums. The confrontation was triggered by accusations regarding the sale of databases that, according to one party, had long been publicly available and previously shared for free, yet were being marketed by the opposing party as exclusive data breaches.

It all started when a threat actor in a chat attempted to sell a database, claiming it had been previously acquired by an associate. Other members of the cybercrime community quickly responded to the listing, stating that the data had been publicly available for a long time and lacked exclusivity. The commenters included the operator of a data leak distribution and sales channel, acting under the alias Nickname (name hidden), who corroborated these claims. In retaliation, the seller threatened the channel operator with doxxing4, warning that they could face consequences for distributing public databases.

4Doxxing (or doxing) refers to the unauthorized collection and public disclosure of an individual's personal or sensitive information. The objective is typically to intimidate, harass, or inflict other forms of harm.

Figure 7. Post offering a database for sale
Figure 7. Post offering a database for sale

Auto-translation of Figure 7

— swanbitcoin(.)com 230K+

 — And?

 — [reply to "And?"] interested?

 — Free?

 — -

 — It's a free base, brother.

 — where

 — Another question is, where did you get it?)) 

— my friend bought it a week ago 

— [reply to "my friend bought it a week ago"] So your friend is a fool, it's a free base.

— [reply to swanbitcoin(.)com 230K+"] This database was leaked on March 30, 2024 

— [reply to "they buy public databases"] u get doxxed by selling public db

The discussion subsequently shifted to the channel operated by the user Solonik (as he was the individual selling the database). According to other participants, this threat actor specializes in reselling previously leaked information.

Solonik was not a casual participant. Since January 2026, he has posted over 100 threads on a major dark web forum, framing them as fresh data breaches from various companies.

Notably, this forum activity served a secondary purpose. The posts were utilized as a lure to attract attention and generate interest, after which users were systematically redirected to a Telegram channel and chat. These platforms hosted the primary engagement with the audience and facilitated the actual monetization. The most significant reaction was triggered by a post advertising an allegedly new data breach involving a popular social network. The author claimed the database contained records for 17 million users, including names, email addresses, phone numbers, and other sensitive data. However, further analysis by StealthMole researchers revealed that this exposure was not the result of a recent compromise.

Thus, this case illustrates a common strategy: by presenting recycled data as a recent incident, the threat actor creates a false sense of novelty, attracts attention, and builds the visibility of their persona. The forum traffic is subsequently funneled into Telegram channels, which serve as the primary platforms for audience engagement and monetization.

To further verify that Solonik was peddling publicly available databases, we analyzed his posts on a prominent underground forum. Regarding the trudvsem.ru database posted on January 7, 2026, he offered the dataset for $8,000, despite the fact that it had been publicly accessible and widely circulated across Telegram channels since November 2025. This activity clearly demonstrates that even historical data breaches continue to be leveraged for financial gain.

Figure 8. Data sale listing
Figure 8. Data sale listing
Figure 9. Multiple posts regarding the distribution of the database
Figure 9. Multiple posts regarding the distribution of the database

Resorting to doxxing, Solonik exposed the personal information of the user Nickname, further alleging that this community member systematically sells public data.

Figure 10. Statement from Solonik's channel regarding another database channel operator
Figure 10. Statement from Solonik's channel regarding another database channel operator

The dispute escalated beyond hostile posts on both sides' channels. Solonik was ultimately banned from a prominent forum for peddling old databases as new ones.

Figure 11. User ban notification
Figure 11. User ban notification

In retaliation, he declared his intention to launch his own forum to host all databases scraped from underground platforms, including BreachForums, DarkForums, and LeakBase. However, no further activity materialized.

Figure 12. Post announcing the launch of Solonik's own forum
Figure 12. Post announcing the launch of Solonik's own forum

The channel administrator's claims regarding his revenue drew particular attention. He asserted that he had earned approximately $130,000 in a single month. This demonstrates that recycled databases continue to generate substantial profits, sustaining a robust secondary market economy for leaked data.

Figure 13. Post detailing potential earnings
Figure 13. Post detailing potential earnings

Disputes within underground communities serve as valuable intelligence sources, providing deeper insights into threat actor motivations and the broader mechanics of the cybercrime ecosystem. The resale of recycled data breaches is a particularly telling example in this context, as attempting to profit off underground peers is almost universally condemned and triggers backlash. Nevertheless, many threat actors are driven to generate revenue by any means necessary, often exploiting the limited awareness of certain underground community members. To maximize their profits, they attempt to rapidly build a reputation to make their offerings appear more credible.

Why private databases are published

Within the context of the cybercriminal underground, a private database refers to datasets that are not publicly accessible and have not been widely distributed across public channels or forums. These databases typically circulate within closed circles (such as private chats or directly between specific buyers and sellers) or are integrated into the backend infrastructure of lookup services and doxxing bots.

A prominent trend in 2025 was the mass leakage of these private databases. Threat actors may begin sharing restricted information for personal gain or simply due to poor operational security. For instance, one forum member recounted sharing a database with a restricted group of associates, only to see it leaked to the public shortly after. Furthermore, once a private database has been sold to multiple buyers, it is often released publicly if the data becomes outdated or loses its commercial value.

Figure 14. Post from a chat participant regarding the private sharing of a database
Figure 14. Post from a chat participant regarding the private sharing of a database

Auto-translation of Figure 14

— [redacted].ru [redacted].ru 

— for example 

— [reply to "for example"] a lot / heavily 

— did you send it anywhere? 

— [reply to "did you send it anywhere?"] privately to some people 

— [reply to "privately to some people"] well then the question is only for them, why did they leak it

Data shared within private chats or between trading partners can also result in a leak if an individual decides to sell or publish the dataset independently. Consequently, private databases, even those acquired by a small number of threat actors, eventually become publicly accessible, posing a potential cyberrisk to the organizations whose data they contain.

(Not)ShinyHunters

Activity in the underground data market is not limited to the resale of publicly available databases. Another tactic frequently employed is the exploitation of an established name and reputation. Threat actors impersonate notorious groups and publish information under their aliases to artificially boost the credibility of their claims and the data they are selling.

The ShinyHunters group, which first emerged in 2020, has held a prominent position within the cybercriminal hierarchy for years. The group is associated with massive data breaches, high-profile claims, and cyberattacks against major corporations (such as Tokopedia and Santander Bank). Furthermore, they have monetized stolen databases across various dark web forums, including RaidForums and BreachForums. Notably, the group operated on these platforms not just as a source of high-profile leaks, but also in an administrative capacity, further amplifying its influence and visibility.

Because the ShinyHunters name is highly recognizable both within the cybercriminal underground and beyond, any claims made on the group's behalf automatically draw the attention of security researchers, the media, and other underground community members. As its notoriety grew, the ShinyHunters moniker was co-opted by third-party threat actors in the underground market looking to capitalize on the group's established reputation.

ShinyHunters on forums

An analysis of the activities of user Solonik (a party to the conflict discussed above) revealed an interesting detail: on January 10, 2026, he published a post on a forum leaking a database belonging to the company Fuse.

Figure 15. Post regarding the publication of the Fuse database
Figure 15. Post regarding the publication of the Fuse database

A few days later, on January 14, 2026, a similar post appeared on a different forum from an account that appeared to be affiliated with ShinyHunters.

Figure 16. Post regarding the publication of the Fuse database on behalf of ShinyHunters
Figure 16. Post regarding the publication of the Fuse database on behalf of ShinyHunters

On January 12, the same account published a high-profile post containing a DELL database. Notably, the author claimed the post was a joint release by ShinyHunters and Lapsus$, which immediately caught the attention of both security researchers and the cybercriminal community.

Figure 17. Post regarding the publication of the DELL database on behalf of ShinyHunters
Figure 17. Post regarding the publication of the DELL database on behalf of ShinyHunters

However, following a detailed analysis, several security experts concluded that the leaked data was fabricated.

Figure 18. Post from researchers regarding the verification of the DELL database
Figure 18. Post from researchers regarding the verification of the DELL database

Furthermore, on January 12, 2026, the Lapsus$ group stated on one of its official channels that it was not currently collaborating with anyone.

Figure 19. Statement from the Lapsus$ group
Figure 19. Statement from the Lapsus$ group

Consequently, the account impersonating ShinyHunters was banned for publishing fake data and attempting to hijack another group's identity.

Figure 20. Post regarding the ban of the fake ShinyHunters account
Figure 20. Post regarding the ban of the fake ShinyHunters account

This incident demonstrates that while such impersonator accounts can emerge on dark web forums, the reputation and internal control systems enforced by administrators and community members function quite effectively. Following verification and public discussion, offending profiles can be banned. This practice highlights the platform's commitment to maintaining trust in its resource: reputation mechanisms and public scrutiny of disputed leaks serve as regulatory tools, helping to reduce fraud within underground communities.

ShinyHunters on Telegram

In addition to underground forums, Telegram plays a key role in the distribution and monetization of databases under the ShinyHunters brand, as such schemes achieve significantly broader reach and faster dissemination on the platform.

An analysis of the fake ShinyHunters activity on the forum also uncovered a Telegram channel claiming to be official. On January 15, this channel published a post regarding the previously mentioned Fuse database.

Figure 21. Post in the Telegram channel regarding the publication  of the Fuse database on behalf of ShinyHunters
Figure 21. Post in the Telegram channel regarding the publication of the Fuse database on behalf of ShinyHunters

The investigation revealed that the owner of this channel operates a personal account. It is set up and managed to create the illusion that it is the official profile of the original threat group.

Figure 22. Telegram account allegedly belonging to ShinyHunters
Figure 22. Telegram account allegedly belonging to ShinyHunters

In addition to the personal account, this threat actor operates several Telegram channels (both affiliated and ostensibly personal). One of these directly uses the name of the original Scattered Lapsus$ Hunters alliance, which can mislead the audience and create a false impression that the source is legitimate.

Figure 23. Telegram account allegedly belonging to Scattered Lapsus$ Hunters
Figure 23. Telegram account allegedly belonging to Scattered Lapsus$ Hunters

At first glance, this appears to be the authentic ShinyHunters group. However, further analysis reveals a network of Telegram channels systematically cross-promoted by the threat actor, a practice not previously associated with ShinyHunters.

Figure 24. List of affiliated channels
Figure 24. List of affiliated channels

Additionally, a channel using the moniker Babuk was discovered within this same network of linked communities. This specific instance warrants special attention and will be discussed in more detail later in this report.

Figure 25. Babuk Telegram channel affiliated with ShinyHunters
Figure 25. Babuk Telegram channel affiliated with ShinyHunters

The primary Telegram channel used for the systematic publication and sale of databases was [Part of the name redacted]V 4 F i l e s. In most posts, the leaks are attributed to ShinyHunters, citing the group as the original source of the data compromise.

During the investigation, a distinct pattern emerged: posts with identical structures and content were published across various channels operated by different threat actors. The only variation was the attribution of the leak. This tactic was observed, for instance, during the release of the iwinv[.]kr database.

Figure 26. Examples of identical posts
Figure 26. Examples of identical posts

Most importantly, the leaked data had already been published much earlier, dating back to at least September 2025.

Figure 27. Post sharing the leaked database
Figure 27. Post sharing the leaked database
Figure 28. Linked database publications across different channels
Figure 28. Linked database publications across different channels

The fake ShinyHunters not only release old databases under their own name but also attempt to sell publicly available information. For instance, the threat actors advertised the sale of the utair[.]ru database for $1,480, even though similar posts had appeared previously and the data was already in the public domain. The record count and content of this database match the version previously published in the threat actor's channel.

Figure 29. Evidence of the attempt to sell the database
Figure 29. Evidence of the attempt to sell the database

Beyond data leaks

It is well documented that the authentic ShinyHunters threat actors developed their own ransomware and used it to extort targeted organizations. On August 8, 2025, a new Telegram channel named Scattered Lapsus$ Hunters emerged, a moniker that references the ShinyHunters, Scattered Spider, and Lapsus$ groups. The channel operators announced the development of their own RaaS (ransomware-as-a-service) operation dubbed ShinySp1d3r.

Concurrently, the fake ShinyHunters operators began promoting their own ransomware builder, leveraging the established group's reputation to lend credibility to their offering.

Figure 30. Post advertising the ransomware for rent
Figure 30. Post advertising the ransomware for rent

However, a detailed analysis of the attached promotional video revealed that the showcased ransomware builder has been known and used since at least 2018, meaning it is an outdated and publicly available tool.

Figure 31. Post sharing the ransomware builder
Figure 31. Post sharing the ransomware builder

Notably, the Telegram channel operated by the fake ShinyHunters claimed that BreachForums is a honeypot. In contrast, the authentic ShinyHunters group hosted their leaked databases on a BreachForums subdomain after launching their new DLS5. The allegation that the forum is a trap serves a single purpose: to artificially boost the legitimacy of the fake channels and accounts.

5DLS (dedicated leak site) refers to a website used by threat actors to publish compromised corporate data.

Figure 32. Statement claiming BreachForums is a honeypot
Figure 32. Statement claiming BreachForums is a honeypot
Figure 33. Database publication on a BreachForums subdomain
Figure 33. Database publication on a BreachForums subdomain

Linked accounts

During the investigation into the fake ShinyHunters activity, several Telegram accounts frequently mentioned in the posts were identified. These include:

  • [Part of the username redacted]psss

  • [Part of the username redacted]berserker

  • [Part of the username redacted]coins

To better understand their roles and affiliations, the investigation expanded beyond Telegram. The next step involved searching underground forums to find mentions of these accounts and correlate their activities.

These searches yielded positive results. Notably, on December 11, 2025, a threat actor was observed selling a Malaysian bank database on a dark web forum. 

Figure 34. Sale of a Malaysian bank database on an underground forum
Figure 34. Sale of a Malaysian bank database on an underground forum

The contact details provided in the database sales thread matched the Telegram accounts identified earlier. This finding connects the Telegram channels to illicit forum trading and highlights the involvement of these accounts in a broader data distribution and resale operation.

Figure 35. Contact details provided for direct messaging
Figure 35. Contact details provided for direct messaging

Notably, this exact database had already been sold previously. In 2025, fake representatives of the Babuk group posted about it. The descriptions of the data leak in both instances are almost identical. 

Figure 36. Post advertising the sale of the Malaysian bank database in the Babuk Telegram channel
Figure 36. Post advertising the sale of the Malaysian bank database in the Babuk Telegram channel

An examination of the AkiraHunters profile revealed another interesting detail: on January 15, 2025, the user posted a request to purchase a database of the National Credit Information Centre (CIC) of Vietnam, referring to the victim as the "Credit Institute of Vietnam." This is the same database that had already been sold on dark web forums on behalf of the authentic ShinyHunters group.

Figure 37. Request to purchase the CIC database
Figure 37. Request to purchase the CIC database

This raises a logical question: why would these threat actors search for a database they supposedly already possess? Furthermore, the fake ShinyHunters channel also listed this database for sale on January 20.

Figure 38. Post advertising the sale of the CIC database in the Telegram channel
Figure 38. Post advertising the sale of the CIC database in the Telegram channel

It is worth noting that the account [Part of the username redacted]berserker, which is affiliated with the fake ShinyHunters, attempted to buy the database from another seller. This again begs the question: why would the group buy data they already claim to possess?

During the transaction, the seller requested proof of funds, which subsequently led to accusations against the buyer. The seller alleged that [Part of the username redacted]berserker provided forged financial proof, labeled the buyer a scammer, and exposed their alt account6.

6An alt account (or multi-account) is the practice where a single individual creates and operates multiple user profiles on the same platform or service.

Figure 39. Post regarding an attempted scam
Figure 39. Post regarding an attempted scam

Furthermore, a post in another threat group's channel claimed that actors masquerading as ShinyHunters were attempting to resell previously leaked databases.

Figure 40. Threat group statement regarding the repackaging of databases by the fake ShinyHunters
Figure 40. Threat group statement regarding the repackaging of databases by the fake ShinyHunters

Notably, the authentic ShinyHunters launched a new data leak site (DLS) on January 22. However, the contact details listed on the site differ from those provided in the Telegram channel. This discrepancy serves as further clear evidence that the Telegram posts were published by impostors.

Figure 41. ShinyHunters data leak site
Figure 41. ShinyHunters data leak site
Figure 42. ShinyHunters contact details listed on the DLS
Figure 42. ShinyHunters contact details listed on the DLS

The fake Telegram channel listed the following contact details:

  • XMPP: [Part of the contact redacted] psss@xmpp[.]jp

  • Email: [Part of the contact redacted] pssss@dnmx[.]cc

For further verification, we consulted web archives. On a forum where the authentic ShinyHunters officially published stolen data, the listed contacts once again differ from those in the Telegram channel. A similar discrepancy was observed on their previously accessible DLS.

Figure 43. ShinyHunters contact details listed on a forum
Figure 43. ShinyHunters contact details listed on a forum
Figure 44. ShinyHunters contact details listed on the previously accessible DLS
Figure 44. ShinyHunters contact details listed on the previously accessible DLS

In short, the scheme operates as follows:

  • The threat actors exploit the high-profile and recognizable name of a well-known group
  • They aggregate previously leaked data from open and semi-open sources
  • This is followed by the active publication of this information alongside bold claims, creating the illusion of high operational efficiency and continuous activity
  • Once trust is established, the threat actors either sell individual databases or offer paid access to private channels

In the case of the fake ShinyHunters, the cost of such access ranges from $200 to $1,200.

Babuk Locker 2.0

A similar scheme involving the Babuk moniker was mentioned earlier in this report. This case is highly illustrative, as it demonstrates that exploiting a high-profile name is not an isolated incident.

Activity surrounding Babuk (or Babuk Locker 2.0) was observed as recently as 2025, even though the original group ceased operations in 2021. Over a short period, threat actors posing as Babuk published data from dozens of compromised companies. However, researchers estimate that up to 90% of the claimed victims had actually been compromised by other ransomware groups.

Notably, representatives of these other groups accused Babuk 2.0 of stealing their published databases. Furthermore, the authentic Babuk group publicly denied any affiliation with this new activity. Other researchers shared similar assessments, highlighting contradictory statements and a lack of evidence indicating any actual compromise of the victims' infrastructure.

Consequently, the Babuk Locker 2.0 scheme closely mirrors the situation involving the fake ShinyHunters. In both instances, we observe:

  • Exploitation of a recognizable and reputable name

  • Appropriation of third-party or previously leaked databases

  • Fabrication of operational activity

  • Monetization through the sale of data or access to a private channel
Figure 45. Post advertising the sale of access to the private Babuk channel
Figure 45. Post advertising the sale of access to the private Babuk channel

Confirmed instances of Babuk-related scams on Telegram warrant special attention. For example, one user reported falling victim to a scam, losing $4,000 in the process.

Figure 46. Confirmation of the scam by a chat participant
Figure 46. Confirmation of the scam by a chat participant

Auto-translation of Figure 46

— [reply to "Telegram fakes were from Serbia"] funny enough, one of them scammed me 

— 4k dollars 

— why does he have a WikiLeaks link 

— [reply to "why does he have a WikiLeaks link"] Because they [redacted]

— I messed up and sent it to Telegram Babuk 

— [reply to "funny enough, one of them scammed me"] [redacted] Babuk 

— And there was some other tag

In January 2026, a threat actor operating under the Babuk moniker resurfaced on a dark web forum. This activity immediately caught the attention of other community members. For instance, a representative of the Vect group asked why this user was continuing to impersonate Babuk.

Figure 47. Message from a Vect group representative
Figure 47. Message from a Vect group representative

Exploiting established names within underground communities for fraudulent purposes is a recognized trend. In many cases, multiple independent threat groups operate simultaneously under the same name.

Key takeaways

Even ostensibly obsolete databases continue to circulate, be resold, and be utilized, which makes them an ongoing potential threat to organizations. This report demonstrates that threat actors can indeed monetize relatively old data, and that exploiting high-profile, recognizable names attracts the attention of other cybercriminals.

The analysis also uncovered an operational scheme involving multiple interconnected accounts, which helps maintain the illusion of activity and bolsters the credibility of the posts. However, attempts to impersonate notorious threat groups are actively thwarted on several dark web forums, where administrators may ban accounts as part of their reputation control mechanisms.

Such data leaks heighten the interest of cybercriminal groups in various companies, increasing the likelihood of these organizations being targeted in future attacks. Analyzing data leak posts is one of many critical factors for successful threat forecasting, alongside monitoring group activity, initial access broker sales, the emergence of new exploits, and other indicators. Furthermore, tracking the behavior of threat actors on the dark web is essential. It enables researchers to uncover their operational tactics, understand their monetization strategies, and attribute database leaks to specific groups or individual threat actors. Because cybercriminals often recycle previously leaked data, attribution becomes increasingly complex; only by cross-referencing information from multiple sources is it possible to accurately identify the perpetrators.

This comprehensive and proactive approach makes it possible to identify potential targets, prevent successful cyberattacks, and mitigate the risk of non-tolerable events.