RapTor

Dark Web News: The Current Stories, and Which Parts of Them Are Actually Confirmed

Most dark web news is one press release or one criminal's sales thread, rewritten by four outlets and stripped of the detail that would let you judge it. This desk works the other way round. Every story below carries the date it last changed, the primary document behind it, and a label saying whether its central claim is confirmed independently, acknowledged by the organisation involved, or simply a criminal describing their own inventory — which is where a surprising amount of published dark web reporting actually comes from. Sources were read and this page checked on .

The stories on the desk right now

Current stories, most recently changed first
StoryLast changeStatus
Xinbi Guarantee seized and sanctioned; scam-compound raids in Madagascar9 Sept 2026Confirmed by primary documents; the marketplace's total volume is one firm's estimate
153 million driver's licence scans sold via a service called Nexus; trail leads to IDScan.net8 Sept 2026Company has acknowledged a breach in narrower terms than the seller advertised; FBI investigation open
Tor Browser and Tails move to a two-week release cadence9 Sept 2026Confirmed by the projects themselves; ongoing
General-purpose markets contract while smaller specialised platforms multiply2026 assessment, covering 2025Confirmed by Europol's own reporting; a trend rather than an event

Xinbi Guarantee: a Telegram marketplace, not a Tor one

On 9 September 2026 the U.S. Attorney's office announced that the Department of Justice's Scam Center Strike Force, with the Secret Service and Treasury, had moved against Xinbi Guarantee — a Chinese-language marketplace where vendors sold scam-center operators everything from custom fake investment websites to money laundering to the recruitment of trafficking victims. A court authorised seizure of the Telegram channels hosting it on 7 September; two wallets holding roughly $12 million were seized, restraint was sought over 47 more, and about $52 million was restrained in a single day, bringing the Strike Force's cumulative total to roughly $938 million.U.S. Secret Service, 9 September 2026 OFAC designated Xinbi a significant transnational criminal organisation the same day.

The scale of what was hit comes from Elliptic, the blockchain-analytics firm whose multi-year tracking of Xinbi's wallets fed the action: it puts the marketplace's throughput since 2022 at a minimum of $24 billion, calls it the second-largest illicit online marketplace on record behind Huione Guarantee's $31 billion, and reports that Telegram deleted Xinbi's central channels and banned its usernames within hours of the sanctions — having previously declined to close it despite the evidence.Elliptic, 9 September 2026 Xinbi's own response is the part worth watching: it condemned the "arbitrary freezing", promised to compensate customers, and began moving off Tether's USDT — which can be frozen by its issuer — to USDD, swapping roughly $2.8 million within hours.Elliptic, 9 September 2026

Separately, the same announcement disclosed that a Strike Force team spent two weeks in Madagascar helping local authorities take down 13 Chinese-run scam compounds, processing more than 3,200 seized devices and interviewing nearly 400 arrestees, around 30 of them identified as Chinese leaders of the compounds and repatriated to China.U.S. Secret Service, 9 September 2026 For the size of the underlying problem: the FBI's complaint centre attributes almost 85% of all losses reported to it in 2025 to cyber-enabled fraud, with reported losses from crypto investment fraud alone rising from $4.57 billion in 2023 to $8.65 billion in 2025 — figures the announcement itself describes as probably well below the true total, because most victims never report.U.S. Secret Service, 9 September 2026 The row for this operation, alongside every earlier one, sits in the takedown ledger.

153 million driver's licences, and a name that collides with a market

Start with the disambiguation, because it will otherwise cost someone real money: the identity-theft service in this story called itself Nexus and has nothing whatsoever to do with the Nexus darknet market covered on its own page here. Anyone searching that name over the last fortnight has been getting two unrelated stories mixed into one set of results.

On 1 September 2026, Brian Krebs reported that a new user on the Russian-language cybercrime forum Exploit was advertising access to identity-document scans for more than 170 million people in North America, through a service that itself listed more than 153 million driver's licences, over 10 million ID cards, more than three million travel documents and around 579,000 medical cards.KrebsOnSecurity, 1 September 2026 He did not take the seller's word for the volume: a blank search returned roughly 11.5 million pages of results at about 15 results a page, and the record count rose by nearly 400,000 in 24 hours, indicating live exfiltration rather than a static old dump. Then he did the work that makes this story stand up. Of more than a dozen friends and family who gave permission, nine found their licences in the service, and every one confirmed having travelled on or near the date stamped on their images — the common thread being a rental-car counter or a Las Vegas dispensary, both of which scan licences through third-party identity-verification systems, with the trail pointing at the Louisiana firm IDScan.net.KrebsOnSecurity, 1 September 2026 The FBI's New Orleans field office opened an investigation the day the story ran, and the service went offline within hours of publication, its login page replaced with "This service is no longer available."

Two later developments change how the story should be read. IDScan.net published a notice around 8 September saying an unauthorised third party may have accessed or copied certain customer information "including full names and drivers license or other government-issued identification numbers", and that it is notifying affected individuals and offering credit protection.KrebsOnSecurity, updated 8 September 2026 That is an acknowledgement of names and numbers — narrower than what the seller advertised, which was image files including infrared and ultraviolet captures of each document. The gap between those two descriptions is the open question in this story, and no outside party can currently close it. Second, SecurityWeek's write-up two days later put the Canadian share at roughly 1.1 million licences and noted that some of the exposed licences belonged to FBI personnel.SecurityWeek, 3 September 2026

Tor Browser and Tails now ship every two weeks

Not a crime story, and the one on this page most likely to affect what you do today. Tails 7.12 shipped on 3 September 2026 as the first release on a two-week cadence, adopted because Firefox — which Tor Browser and therefore Tails are built on — moved to two-week releases in September; Tor Browser 15.0.22 followed on 9 September, the second stable release inside a fortnight.The Tor Project blog, September 2026 The practical consequence is that any guide naming a version number is now wrong within weeks rather than months, which is why the version claims on this site are written with the date they were checked and why the download page, not a screenshot in an article, is the only current answer. The same blog carried a 9 September post on what the Tor Project has learned building its own Android VPN, including per-app circuit isolation — worth reading before believing any commercial VPN comparison written before it existed.The Tor Project blog, September 2026 The cadence is already proving itself: Tor Browser 15.0.23 followed on 15 September with two backported high-severity Firefox fixes, and carries an unrelated wrinkle worth knowing before you update on Windows — the certificate Tor Project signs its Windows installer with expired on 1 September and was still not renewed at 15.0.23's release, so a fresh install on Windows can throw a "bad signature" warning that has nothing to do with the file being tampered with.The Tor Project blog, 15 September 2026

The market landscape: fewer big markets, more small ones

Europol's 2026 assessment describes general-purpose markets contracting while smaller, specialised platforms gain ground — average market lifespans shortening, administrators growing risk-averse after international operations, and markets no longer surviving long enough to build large userbases, which produces fragmentation, internal instability and widespread mistrust among users. Forums act as the migration hubs when a market dies, and when a forum dies its successor appears within weeks: DarkForums emerged during 2025 as the successor to BreachForums, carrying leaked-data trading, malware sales and hacking tools across both clearnet and Tor.Europol, IOCTA 2026 If you are trying to work out which markets that leaves standing, the dated directory is the page for it, and exit scams covers what happens to escrowed money when one of the short-lived ones ends.

Confirmed, acknowledged, claimed: what those labels mean here

The distinction does real work in this subject, because the loudest source in most dark web stories is the criminal selling something.

Confirmed
A primary document from an agency, court, or the organisation that did the thing — a seizure warrant, a sanctions designation, a project's own release announcement. The Xinbi seizure is confirmed in this sense: there is a government release naming the court, the date and the amounts.
Acknowledged
The organisation at the centre of the story has admitted it, usually in carefully drawn language. IDScan.net's notice is the example, and it shows why the label matters: the company acknowledged names and identification numbers, while the seller advertised full document images. Both statements can be true at once, and neither one confirms the other.
Claimed
A criminal describing their own inventory, which is marketing. The Nexus seller's "more than 170 million people" and its boast of "continuously exfiltrating new data for over a year" are sales copy from an anonymous vendor on a crime forum. They may be accurate. Nothing about their being widely republished makes them more so, and a headline that quotes the higher number without saying whose it is has taken a criminal's word for it.
Corroborated
Someone independent has checked a specific part of the claim. Krebs's nine verified licence records, each matched to a date the person confirmed, is corroboration of the dataset's authenticity and provenance; it is not corroboration of the seller's total.

Even two solid sources on the same action will not always agree to the digit, and that is worth seeing rather than smoothing over. The government release describes seizing two wallets and seeking restraint over 47 more, with about $52 million restrained; Elliptic, whose analysts identified the wallets, reports 52 wallets holding $52.8 million frozen from 08:00 UTC on 8 September.Elliptic, 9 September 2026 Different counting boundaries and a day's difference in framing, not a contradiction — but you only get to see that if both figures are attributed, which is the rule every page on this site is written under.

How the services in these stories are actually hosted, advertised and paid for

"Dark web" in a headline usually means one of four quite different arrangements, and knowing which one is in play tells you who could shut it down.

  • A Tor onion service. No registered domain, no hosting company to serve with a warrant, an address that is a cryptographic key rather than a name — the arrangement behind darknet markets and behind ransomware leak sites. The directory page explains what that means for reaching one safely.
  • A Telegram channel. Xinbi was not a Tor site at all. It ran on a mainstream messaging platform, which is why a platform decision could end it in hours once sanctions landedElliptic, 9 September 2026 — a vulnerability no onion service has. Europol describes exactly this hybrid drift, with marketplaces and forums intertwining with end-to-end-encrypted messaging platforms rather than staying on Tor.Europol, IOCTA 2026
  • A clearnet or hybrid service advertised on a crime forum. The licence-scan service was promoted on Exploit, a Russian-language forum, which is the standard pattern: forums are where leaked and breached data gets advertised, where new criminals are onboarded and vetted, and where everyone regroups when a platform is dismantled.Europol, IOCTA 2026
  • An escrow or "guarantee" layer sitting on top. Xinbi's merchants posted deposits so buyers could be compensated if defrauded — escrow substituting for the legal recourse criminals cannot use.Elliptic, 9 September 2026 It is the same trust problem darknet markets solve the same way, and the same single point of failure.

Payment is where these stories converge. Xinbi ran on Tether's USDT, mostly on the TRON blockchain — a stablecoin whose issuer can freeze wallets, which is precisely what happened and why Xinbi started migrating to one that cannot.Elliptic, 9 September 2026 Europol's own read of 2025 has ransomware crews moving toward high-opacity coins that resist tracing tools, favouring exchanges in loose-AML jurisdictions, and increasingly chain-hopping through blockchain bridges to break the trail — bridges being ordinary interoperability infrastructure that laundering simply borrows.Europol, IOCTA 2026 The mechanics of what a blockchain does and does not reveal about an ordinary person are on the cryptocurrency privacy page; the short version is that the transparency which makes these freezes possible does not stop at criminals.

Whether your own data is in one of these datasets

For email addresses, there is a real answer. Have I Been Pwned lets you search an address against breaches that have been loaded into it, and its own FAQ is unusually straight about the limit: the service "contains but a small subset of all the records that have been breached over the years", many breaches never result in public data release, many go undetected entirely, and so — in its own words — "absence of evidence is not evidence of absence."Have I Been Pwned, FAQ A clean result means nothing was found, not that nothing happened.

For the story on this page, the answer is worse, and no article you find will say so plainly. A dataset of scanned driver's licences is not searchable by email address, the service selling it went offline within hours of the reporting, and nobody outside law enforcement now holds a copy anyone can query. IDScan.net says it is notifying affected individuals directlyKrebsOnSecurity, updated 8 September 2026 — which makes waiting for a letter the only check available to an ordinary person, and it will reach you only if the company's own records say you were affected. Anyone offering to search that dataset for you is either lying or has bought a copy.

So the useful move is not searching, it is assuming. If you handed a licence to a rental counter, a dispensary, a hotel or an age-verification screen in the past couple of years, treat the scan as potentially circulating and act on what actually changes your exposure: a credit freeze rather than a monitoring subscription, scepticism toward anyone quoting your licence number as proof they are legitimate, and knowing that document images are exactly what account-recovery fraud runs on. The general version of this reasoning — deciding what you are protecting and from whom, instead of buying products aimed at a threat you may not have — is the OPSEC guide.

Which of the past year's stories are still open

"Open" here means the central question has no answer yet, not that nobody is working on it.

Status of the past year's significant stories, and what would close each one
StoryOpen or closedWhat would close it
IDScan.net breach and the licence-scan serviceOpenAn FBI charging document, or a fuller disclosure saying whether document images were taken as well as names and numbers
Xinbi GuaranteePartly closedChannels seized, wallets frozen and sanctions in place; no arrests were announced in this action, and the operators are still publishing
Abacus Market going dark, July 2025Open, probably permanentlyEuropol's own account leaves it as law-enforcement pressure "potentially" prompting an exit scam rather than a seizureEuropol, IOCTA 2026 — only a prosecution or a seizure notice would settle it
Archetyp Market, June 2025ClosedInfrastructure dismantled across five countries and the administrator, a 30-year-old German national, arrested in BarcelonaEuropol, IOCTA 2026
Earlier market prosecutionsMostly closedConvictions and guilty pleas, with the primary documents collected in the takedown ledger

The reason a market going dark so often stays unresolved is that a covert seizure and an exit scam look identical from outside, sometimes for months, and law enforcement has reasons to prefer the ambiguity. That case is made properly on the exit scam page.

Where darknet market news ends and ransomware news begins

They get filed together and they are different beats with different audiences. Ransomware is an enterprise problem: initial access brokers, supply-chain compromise, affiliate programmes, incident response, insurance. Europol counted more than 120 active ransomware brands in 2025, with operations short-lived and prone to rebranding, overlapping administrators and affiliates, and extortion that has shifted from encrypting data to threatening to publish it — because modern organisations can survive losing data and not survive it being released.Europol, IOCTA 2026

This desk covers exactly one part of that: the point where extortion touches Tor. Leak sites — where a crew publishes stolen data to pressure a victim — are onion services, and the reason they are hard to remove is the same reason a market address cannot be taken away by a registrar. That is a genuine overlap and it belongs here. Everything else about ransomware belongs to enterprise security publications with defenders as their readers, and if that is your job, this is not your page. Saying so is more useful than pretending a site written for individual privacy readers can also brief a security operations centre.

The primary sources worth following directly

Almost every dark web story you will read is a rewrite of one of these. Going to the source costs nothing and removes a layer of telephone — each one has a bias, so they are listed with it.

Europol's Internet Organised Crime Threat Assessment
The annual European picture, and the best single document on how markets and forums are structured. Written from law-enforcement visibility, so it sees what investigations see and reports trends rather than dated events. The PDF is the reliable artefact; Europol's newsroom pages often will not load without JavaScript.
U.S. Secret Service and Justice Department releases
Where seizures, sanctions and indictments appear first, with dates, courts and amounts. They are prosecution announcements: strongest on what was done, silent on what was not achieved.
KrebsOnSecurity
Original reporting rather than aggregation, and the rare outlet that verifies a criminal claim before printing the number. The licence-scan story existed at all because someone checked nine records against nine people's travel dates.
Chainalysis and Elliptic
On-chain measurement with a stated method — the only sources that can size this ecosystem without asking a criminal. Both sell blockchain analytics to governments and banks, which is worth holding in mind when a report concludes that blockchain analytics work.
The Tor Project blog
Releases, security fixes and the Tails announcements, dated and authoritative. It is also the correct answer to "which version is current", now that the answer changes fortnightly.
Have I Been Pwned
For checking an email address against known breaches, and for its own documentation of what such a check cannot tell you.

What you will not find here is a story built on an anonymous vendor's sales thread, a screenshot of a marketplace offered as evidence of its size, or a service described as online when nobody has looked recently. Everything above decays, and quickly: the version numbers in this month's releases will be superseded within a fortnight, an open case can close with a single unsealed indictment, and a market running today may be gone by the time you read this. The date attached to a line here is part of the claim, not decoration — read it before you act on the sentence it belongs to.