Resources
  • Newsletter
  • News Highlights
Weekly Darkweb: July 2026, Week 3
2026.07.23

☑️ Weekly Darkweb – July Week 3, 2026



🔍 Philippines Telecom Regulator Data Sale on Dark Web


• On July 13, confidential data of the Philippine government's telecommunications regulator ‘N’ was posted for sale on the dark web hacking forum BreachForums.


✓ ‘N’: the national regulatory authority overseeing the country's telecommunications infrastructure.


• The user ‘DNH’ presented a screenshot of a file properties window showing the agency's domain, claiming to have obtained approximately 126GB of data (over 200,000 documents) that includes employees' personally identifiable information (PII).


➢ The attacker states that the leak is an act of protest against the government's alleged negligence in handling a mass shooting incident in June. This incident represents a textbook case of hacktivism, in which indiscriminate exposure of government secrets encourages follow-on attacks by other threat actors and fuels wider social unrest.



🔍 Saudi Chemical and Trading Firm ‘S’ Attacked by DragonForce Ransomware


• On July 12, the ransomware group DragonForce listed Saudi chemical and logistics company ‘S’ on its leak site as a new victim, claiming to have stolen approximately 115.54GB of data and threatening to publish it within two days.


✓ ‘S’: a chemical and trading firm headquartered in Dammam, Saudi Arabia that provides logistics and manufacturing services to the petrochemical sector.


• DragonForce operates as a ransomware collective with a cartel-style structure, providing affiliate attackers with white-label ransomware builders. After exfiltrating data, the group uses the threat of public disclosure as leverage while simultaneously encrypting internal systems to demand restoration payments, employing a classic double-extortion tactic.



🔍 Japan Taxi and Transport Company ‘N’ Target of AiLock's Data Breach


• On July 15, the ransomware group ‘AiLock’ uploaded a post on its leak site claiming to have exfiltrated 2.9TB of data from Japanese taxi and transport company ‘N.’


✓ ‘N’: Japan's largest taxi operator, with a reported fleet of approximately 4,000 taxis and 2,700 limousine vehicles.


• According to S2W's analytic tools, AiLock is a double-extortion ransomware group that uses a dedicated negotiation portal to pressure victims into direct talks.


➢ The attack is the first known case of the group specifically targeting a Japanese company since its emergence in 2025. However, on the same day, AiLock posted a separate claim of data leakage involving Japanese CRM tool provider ‘S,’ indicating a broadening of its victim profile within Japan's corporate ecosystem.



👉 Subscribe to <Weekly Darkweb> and get the latest newsletter every week.
Subscribe on LinkedIn
This newsletter is based on news derived from big data collected from over 400 million encrypted pages and channels, including those on the dark web and Telegram.

☎️ Contact us: Contact S2W

*The full report is available upon request and for XARVIS subscribers.


S2W XARVIS platform subscription banner

List