☑️ Weekly Darkweb – August Week 3, 2026
🔍 Trade Secrets and Employee Data of Danish Pharmaceutical Giant ‘N’ Leaked on Dark Web
• On August 12, a DLS link allegedly containing core trade secrets, unpublished drug-research data, and proprietary AI-model data belonging to global pharmaceutical company ‘N’ was posted on ‘BreachForums.’
✓ ‘N’: the company generated approximately USD 47 billion in revenue in 2025 with a market capitalization of roughly USD 400 billion. It is a leading player in the diabetes and obesity treatment markets.
• The threat actor ‘FulcrumSec’ claimed that, after negotiations following an initial 264 GB leak in June broke down, it published a further 1.05 TB of data through a dedicated DLS link. The actor claimed the combined 1.3 TB dataset includes next-generation obesity-treatment manufacturing methods, unpublished drug candidates, proprietary AI models, and clinical patient and employee information.
🔍 Indonesian Army Strategic Reserve Command Database Leaked on Dark Web
• On August 10, materials purported to be a database from the website content management system (CMS) of Indonesian Army Strategic Reserve Command (Kostrad) were identified in text form on the dark web forum ‘BreachForums.’
✓ Kostrad (Komando Cadangan Strategis Angkatan Darat): an Indonesian Army strategic reserve force and a major combat command involved in national defense and security operations.
• The posted material includes website management structures, administrator account and role information, and website access/request logs. The currently reviewed material does not contain any core military-sensitive information. Some standard SQL keywords also appear to have been rendered in Indonesian.
🔍 Cyprus Government Website File-Upload Vulnerability Offered for Sale
• On August 11, a post offering a file-upload vulnerability affecting a Cyprus government website was identified on the dark web hacking forum ‘PwnForums.’
• The user ‘Figure’ claimed that the vulnerability could be used to distribute malware. The seller promoted its potential use in phishing campaigns involving forged notifications or invoices sent from a government domain, claiming this could increase the likelihood of user interaction and facilitate the theft of sensitive information. The vulnerability was advertised for USD 300–750, with the price described as negotiable.
• The seller stated that detailed evidence could not be made public for security reasons but could be provided upon request. As supporting evidence, the seller shared one screenshot allegedly showing a successful test upload to the government site using a test account and a file containing the user's name.
*The full report is available upon request and for XARVIS subscribers.