Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden (5.4M+), Chrysler/Salesforce (1TB+, Everest Ransomware), and Crypto-Platform Lead Lists — Threadlinqs Intelligence
As of 2026-06-15, Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden (5.4M+), Chrysler/Salesforce (1TB+, Everest Ransomware), and Crypto-Platform Lead Lists is a high-severity data breach threat attributed to Everest ransomware group (North Korea (APT43/Kimsuky claim, unverified); Unknown (data brokers)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0803 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Attribution: Everest ransomware group · North Korea (APT43/Kimsuky claim, unverified); Unknown (data brokers) · FINANCIAL
SOCRadar DarkMirror dark-web monitoring surfaced multiple high-volume data-leak and breach claims in June 2026: ~168M records (1984-2024) allegedly from Iran's Hajj and Pilgrimage Organization sold
This threat record tracks a SOCRadar dark-web monitoring roundup published 2026-06-15 documenting four distinct high-volume data-exposure events plus a set of unverified advanced-persistent-threat tooling claims. It is a DATA_BREACH intelligence aggregation, not a single CVE-bound vulnerability; no CVE or CVSS is stated by the source.
1) IRAN HAJJ AND PILGRIMAGE ORGANIZATION (~168M records, 1984-2024). An unnamed actor advertised a dataset spanning four decades of pilgrim records. Exposed fields reportedly include full names, birth dates and places, national ID numbers, national codes, passport details, contact information, travel/pilgrimage records, insurance data, banking and payment information, and security-deposit documents. The seller additionally claimed possession of Hajj-application source code and asserted the records include government officials, NAJA (police) forces, Basij paramilitary forces, and clerics. Asking price: $80,000 USD payable in Bitcoin. Primary SOC risk: large-scale identity theft, targeted phishing/spear-phishing of named officials, financial fraud, and foreign-intelligence collection against a sensitive population.
2) ADRESSFAKTA / SUPEReROI AB, SWEDEN (5,452,000+ unique users). A contact/marketing dataset from the Swedish service AdressFakta (operator SUPEReROI AB) was offered for a $3,800 base-plus-access price. Exposed fields include names, gender, mobile and landline numbers, street addresses, ZIP codes, towns, birthdates, and housing-type information. Primary SOC risk: smishing, vishing, identity profiling, and social-engineering of Swedish consumers.
3) CHRYSLER / SALESFORCE (1+ TB; 105+ GB Salesforce records, 2021-2025) - EVEREST RANSOMWARE. The Everest extortion group claimed exfiltration of more than 1 TB of Chrysler (Stellantis) data, including over 105 GB of Salesforce CRM records covering 2021-2025. Exposed data reportedly includes customer, dealer, and agent records; interaction/call logs; names, phone numbers, emails, and addresses; vehicle details; recall notes; and call outcomes. Everest (active since December 2020) has evolved into a hybrid ransomware/initial-access-broker operation; documented TTPs include initial access via exposed RDP, purchased credentials, and an insider-recruitment program (running since October 2023), lateral movement over RDP with valid accounts, and data exfiltration using rclone.exe, winscp.exe, and custom PowerShell scripts to bulletproof C2 infrastructure. Primary SOC risk: dealer-impersonation phishing, recall scams, and double-extortion.
4) CRYPTOCURRENCY-PLATFORM LEAD LISTS (millions aggregated). Combined lead lists referencing users of Binance.US, Coinbase, Crypto.com (1.8M lines), Gemini (930k+ lines), Kraken, Robinhood, Ledger, and Paxful were advertised. Exposed fields are names, emails, and phone numbers, reportedly aggregated using a 'crypto checker' tool. Primary SOC risk: targeted phishing, SIM-swapping, and credential stuffing against crypto holders.
5) UNVERIFIED APT43 / KIMSUKY CLAIMS. A separate dark-web post attributed to APT43 (Kimsuky, North-Korea-linked) advertised a C++ backdoor with encryption/anti-forensic capabilities, Android kernel attack tools, a server-takeover rootkit, and three alleged zero-days including a Linux root privilege-escalation. SOCRadar explicitly flags these as unverified and notes such APT claims are frequently exaggerated. APT43/Kimsuky is a documented espionage actor (MITRE G0094) whose real, sourced tooling includes the BabyShark/LATEOP VBScript backdoor and off-the-shelf RATs such as XenoRAT, QuasarRAT, and Gh0st RAT; the specific tools advertised here are not independently confirmed.
Defensive priority: breach response and credential-exposure monitoring for affected populations, anti-phishing and anti-fraud controls, and Everest-ransomware hardening (RDP exposure reduction, exfil-tool detection).
Weaknesses (CWE)
CWE-200, CWE-359, CWE-522
Target sectors: government, religious-pilgrimage, automotive, retail-consumer, cryptocurrency, financial, marketing-data
Target regions: Middle East, Iran, Europe, Sweden, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1587, T1588, T1608, T1650, T1133, T1078, T1190, T1566, T1199, T1059