Group-IB reported that several Chinese-language dark web forums and Telegram channels are advertising massive troves of supposedly stolen corporate data that often do not represent genuine new breaches. The company identified recurring sellers and channels including Exchange Market, Chang’An Sleepless Night, Aiqianjin, Yiqun Data, and Phoenix Overseas Resources, saying they promote high-volume datasets from organizations worldwide using repetitive formats, aggressive messaging, and breach-related keywords to attract buyers and attention.
According to the research, many of the advertised records appear to be recycled or recombined from older public leaks such as Facebook 2021, Eatigo 2020, and Truecaller 2022, rather than fresh exfiltration. Group-IB said sample data showed multiple signs of fabrication or poor recombination, including mistranslated Arabic field values, mismatched names, phone numbers, and password hashes, as well as implausible database structures. The firm warned that these "lead data" brokers create noise that can misdirect incident response and urged defenders to verify whether claimed records match an organization’s real schema and whether identifiers within each record are internally consistent before treating a post as evidence of compromise.
See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Group-IB recommended that defenders verify whether advertised records match an organization's internal data structure and whether identifiers within each record are internally consistent before treating marketplace claims as legitimate breaches. The guidance was issued to reduce analytical noise caused by fabricated or recombined datasets.
The analysis found that sample datasets promoted by these brokers were often compiled from older public leaks such as Facebook 2021, Eatigo 2020, and Truecaller 2022. Group-IB also documented repeated inconsistencies including mistranslated Arabic field values, mismatched names and phone numbers, incompatible password hashes, and implausible database structures.
Group-IB analyzed Chinese-language dark web forums and Telegram channels advertising large volumes of purportedly stolen data and concluded that many claims were low-credibility 'lead data' rather than evidence of genuine breaches. The research highlighted recurring sources including Exchange Market, Chang’An Sleepless Night, Aiqianjin, Yiqun Data, and Phoenix Overseas Resources.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.