3.1 Million Armenian Citizens' Data Allegedly for Sale on Dark Web

Share
3.1 Million Armenian Citizens' Data Allegedly for Sale on Dark Web

A threat actor using the alias "datsell_alld" claims to be selling a database containing approximately 3.1 million records of Armenian citizens on a dark web forum.

With Armenia's population estimated at just over 3 million, the claimed size suggests this could represent a near-complete national dataset.

What's Allegedly Exposed

The dataset reportedly includes:

  • Social Security Numbers (SSN)
  • Passport numbers
  • Full names (first, last, and patronymic)
  • Dates of birth
  • Document issuance or registration dates
  • Full residential addresses

Sample data has allegedly been provided to potential buyers to demonstrate authenticity.

Why This Matters

If legitimate, this breach would be one of the most significant data exposures in Armenia's history. Core identity data like SSNs and passport numbers cannot be easily changed, creating long-term risks including:

  • Identity theft and financial fraud
  • Document forgery and passport abuse
  • Targeted phishing and social engineering campaigns

The listing was posted by a relatively new forum account, which may indicate either a newly established actor or an attempt to minimize traceability.

Official Response

Armenian authorities have not publicly commented on the alleged breach. The original source of the data - whether government systems, a third-party contractor, or aggregated legacy databases - remains unknown.

Read more

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

A compromised version of the Nx Console extension — a popular VS Code plugin with over 2.2 million installations — was published to the Visual Studio Code Marketplace after an attacker leveraged stolen developer credentials to inject a multi-stage credential stealer into the official nrwl/nx GitHub repository. The malicious version

By Zero Day Wire
Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Symantec and Carbon Black have published a definitive analysis confirming that Fast16, a Lua-based malware framework first surfaced by SentinelOne weeks ago, was purpose-built to sabotage nuclear weapons testing simulations. The findings establish Fast16 as the earliest known cyber sabotage tool targeting nuclear weapons research — predating the first known version

By Zero Day Wire