The ExtortionLord Trail: How a KakaoTalk Sale Led Back to LockBit's Leaked Infrastructure

The underground data trade rarely revolves around a single forum or marketplace. Sellers and brokers move between dark web communities, encrypted messaging platforms, and private channels, offering everything from compromised databases and source code to network access and internal corporate data. The identities behind these operations can be equally fluid. Usernames change, accounts disappear, and communication shifts from public posts to private messengers, leaving investigators to piece together fragments scattered across different platforms and points in time.

One such figure is ExtortionLord, a threat actor whose activity surfaced through the sale and distribution of compromised data on underground forums. At first glance, the actor appeared to fit a familiar profile: an underground seller advertising access to valuable stolen material. But as we began following the identifiers and traces surrounding ExtortionLord through StealthMole, the investigation started moving beyond individual sales posts and into a wider network of forum activity, aliases, encrypted communication identifiers, Telegram accounts, channels, and leaked files.

This report follows that investigation as it unfolded. Starting with the activity that first brought ExtortionLord into view, we trace the actor's footprint across underground sources and follow each meaningful lead into the next. Along the way, the investigation reaches communication channels connected through shared identifiers, profiles that may offer additional context around the people involved.

The First Trace of ExtortionLord

The investigation began when StealthMole's Leaked Monitoring tool indexed a recent post from a user operating under the name ExtortionLord. The post appeared on DarkForums, where the actor claimed to be selling KakaoTalk's full source code, alongside network access and access to the company's databases.

  • https://darkforums.**/Thread-Selling-Kakao-Talk*************96

At this stage, ExtortionLord was simply an unfamiliar name attached to a potentially significant underground sale. There was little indication of who was behind the account or whether the identity had appeared elsewhere. Rather than stopping at the leak itself, we decided to use the information captured by StealthMole as the starting point for a deeper investigation into the seller.

The DarkForums link surfaced through Leaked Monitoring tool was examined further using StealthMole's Dark Web Tracker. Inside the thread, ExtortionLord had left a single direct contact point for anyone interested in reaching them:

  • TOX: 4DEBE**********************************************B55A9

Unlike a username, which can easily be copied or reused across unrelated platforms, this long-form identifier offers a much more specific artifact to work with. It gave the investigation two immediate directions: the ExtortionLord identity itself and the Tox ID the actor had chosen as their only listed contact point.

From there, the focus shifted away from the KakaoTalk sale itself. The question was no longer simply what ExtortionLord claimed to possess, but what traces the actor and their contact information might have left elsewhere across the underground ecosystem.

Following the Contact Point

With the Tox ID established as ExtortionLord's only listed contact method on the DarkForums thread, the next step was to determine whether the same identifier had surfaced elsewhere. A search for the full Tox ID through StealthMole produced a much broader trail than the original KakaoTalk listing suggested.

The identifier appeared in a post on XSS, but this time it was not attached to the ExtortionLord name. Instead, the post was associated with the alias Mansoryx. The overlap immediately stood out. The same Tox ID that ExtortionLord had provided as the sole contact point for the KakaoTalk offering was now connected to a different underground identity.

This did not, on its own, establish that ExtortionLord and Mansoryx were the same person. Communication identifiers can potentially be shared, transferred, or used by multiple individuals. However, the exact match provided a concrete connection between the two identities and gave us another lead to follow.

We then searched the Tox ID through StealthMole's Telegram Tracker, looking for any messages or channels where it had previously been mentioned.

That search led us to a telegram channel:

  • https://t.me/+NV5**********mI0

Inside the channel, we identified a message containing two encrypted-messaging identifiers. One was the same qTox ID already encountered in the DarkForums and XSS threads:

  • 4DEBEB************************************************DB55A9

Another was a Session ID:

  • 05a19***********************************************69c74917

At this point, the investigation had moved considerably beyond the original sale post. A Tox identifier first discovered as ExtortionLord's contact point on DarkForums had led to the Mansoryx alias on XSS, which in turn led to a Telegram channel where the same Tox ID appeared alongside a second encrypted communication identifier.

The repeated appearance of the exact Tox ID across these separate sources gave the investigation a more stable thread to follow than the usernames themselves. ExtortionLord and Mansoryx remained identities requiring careful attribution, but the communication infrastructure connecting the activity was beginning to form a clearer trail.

New Names Begin to Surface

With the Tox and Session identifiers now appearing together in the same Telegram message, we continued investigating the Tox ID beyond the underground sources already uncovered. This led us to a security research report published by Trellix examining the leak of LockBit's administrative panel.

The report contained the same Tox ID we had been following since the original ExtortionLord post. More importantly, it provided additional context around the communication trail that had started to emerge through our own investigation.

Among the information documented in the research was a Telegram account:

  • https://t.me/INFO********l

The report also referenced activity involving the moniker flex, which had reportedly been used in connection with efforts to recruit pentesters on the XSS forum.

These findings introduced new names into the investigation, but they also required caution. The presence of the same Tox ID created a reason to examine the surrounding accounts and aliases, but it was not enough to conclude that ExtortionLord, flex, or the operator behind @INFO*******l were necessarily the same individual. Each would need to be investigated independently before any stronger connection could be made.

The Telegram account provided the most immediate next step. We searched @INFO*********l through StealthMole's Telegram Tracker, where the account surfaced under the name Molot.

The profile contained a particularly interesting detail. In its bio, Molot had included the following message:

Не ответил? проигнорировал? продублируй https://t.me/+NV51*********mI0

The link pointed to the same Telegram channel we had already reached by tracing ExtortionLord's Tox ID, the channel where the Tox and Session identifiers had appeared together.

This created a more meaningful connection than a shared username or alias. The investigation had reached the channel independently through ExtortionLord's Tox identifier, while the @INFO*********l account surfaced through a separate research trail and directly referenced that same channel in its profile.

We then examined Molot's wider Telegram activity through StealthMole. The account was found participating in another Telegram community:

  • https://t.me/user****forum

StealthMole's indexed data showed at least 24 messages associated with Molot in the channel, opening another avenue for examining the account's historical activity.

By this stage, the investigation had begun to move from isolated identifiers toward a more interconnected picture. Yet the relationships between the names remained unresolved. ExtortionLord, Mansoryx, flex, and Molot had now surfaced at different points along the same broader investigative trail, but the available evidence did not justify treating them as a single actor. What it did provide was a growing collection of connections that could now be examined against another source of evidence waiting in StealthMole's indexed data.

A Familiar Name Inside a Leaked Database

With the communication trail beginning to take shape, we returned to the other investigative direction created at the start of the case: the ExtortionLord username itself.

Searching ExtortionLord through StealthMole's Dark Web Tracker produced a result inside a leaked SQL file labelled Panel_DB. Unlike the earlier forum posts, this was not another public appearance of the alias. The username appeared as a record within a database dump.

To understand what the result contained, we analyzed the file using StealthMole's MoleChat. The analysis surfaced several values associated with the ExtortionLord record:

Username: ExtortionLord 

Password/value: gRh************i5 

Token/session-like value: eqnd*******************6ik2

At this point, however, the presence of the username raised more questions than it answered. A record labelled ExtortionLord inside an unidentified panel database did not tell us who operated the panel, what purpose it served, or what the actor's presence within the database actually represented. Even the additional values associated with the record could not be assigned a definitive function without understanding the underlying database structure.

The name of the file provided the next clue. We searched for references to paneldb_dump through StealthMole's Telegram Tracker and found the term appearing across several messages and shared files. One of those results came from a private Telegram channel, where copies of paneldb_dump and a corresponding torrent file had been circulated.

The accompanying message provided crucial context around what we had found. The material was described as originating from a compromise of LockBit's administrative infrastructure, with the leak attributed in the circulated material to an actor referred to as "xoxo from Prague."

This also brought the earlier Trellix report back into focus. The report we had initially reached while tracing ExtortionLord's Tox ID was examining the same broader event: the leak of LockBit's admin panel. What had previously served as a source of additional identifiers now provided context for understanding the unexplained SQL record surfaced through StealthMole.

The Panel_DB result was therefore not evidence of a database operated by ExtortionLord. Instead, the investigation indicated that the record had surfaced within data associated with the leaked LockBit admin panel.

That distinction was critical. It prevented an unrelated infrastructure attribution while opening a much more important question: why did a record carrying the ExtortionLord identity appear inside data from LockBit's leaked panel?

The answer could not be established from the username alone. But the database itself offered considerably more material to examine. Additional searches through StealthMole surfaced three more files associated with paneldb_dump, giving us an opportunity to look beyond a single ExtortionLord record and examine the structure and contents of the leaked panel in greater detail.

Looking Inside the LockBit Panel Leak

With the origin of paneldb_dump now clearer, the investigation shifted from identifying the database to understanding what it actually contained. StealthMole had surfaced three additional leaked files associated with paneldb_dump, which we analyzed using MoleChat to examine their structure and contents without manually navigating thousands of database records.

The files appeared to contain data from the backend of a ransomware operation. MoleChat identified records associated with victim and operator negotiations, including messages exchanged during ransom discussions and corresponding timestamps. Other records related to Bitcoin payment addresses, providing insight into how cryptocurrency addresses were managed within the panel.

The database also contained traces of the operational processes surrounding an extortion case. These included references to uploaded files and attachments, as well as records associated with test-decryption workflows, a process commonly used during ransomware negotiations to demonstrate that encrypted files can be recovered.

Additional tables and entries pointed to API-related activity and operational identifiers, while the records visible in the analyzed material covered activity from at least December 2024 through April 2025. Taken together, the files provided a glimpse into the administrative machinery behind the panel rather than simply a collection of leaked usernames.

This context helped us better understand the significance, and the limitations, of the earlier ExtortionLord record. Finding a username inside such a database could indicate that the identity existed somewhere within the panel's operational environment, but it did not, by itself, explain the individual's role. Without establishing precisely what table the record originated from and what that table represented, it would be premature to label ExtortionLord as a LockBit affiliate, administrator, or operator.

What made the finding more difficult to dismiss as a simple username collision, however, was the wider trail already uncovered during the investigation. The ExtortionLord identity found in the leaked panel data was being examined alongside a highly specific Tox identifier that had independently surfaced across the actor's 2026 DarkForums activity, XSS, Telegram, and external research connected to the LockBit panel leak.

The database therefore added an important historical layer to the investigation, but not a definitive attribution. Rather than providing a simple answer to who ExtortionLord was, it placed the identity within a much larger operational dataset and raised a more focused question about the nature of that connection.

With the LockBit panel data examined, one unresolved lead remained particularly interesting: Mansoryx, the alias encountered earlier on XSS using the same Tox contact point as ExtortionLord. We therefore returned to that identity to see whether StealthMole could uncover a historical footprint beyond the forum post where the name first appeared.

Conclusion

What began with StealthMole detecting an underground offer involving KakaoTalk ultimately became an investigation into the digital footprint surrounding the seller behind it. ExtortionLord initially appeared as a newly surfaced actor with little context beyond a DarkForums account and a Tox contact point. It was that contact point, rather than the username, that proved to be the most valuable lead.

Following the identifier across different sources uncovered traces that predated the KakaoTalk offering and crossed several corners of the underground ecosystem. The investigation encountered Mansoryx on XSS, a corresponding Session identifier in historical Telegram data, and the @INFO*********l account associated with Molot, whose profile pointed back to the same Telegram channel already uncovered through the Tox search. Separately, the ExtortionLord username surfaced within the leaked LockBit panel data, adding another potentially significant connection while leaving the actor's precise role within that environment unresolved.

Not every lead produced a definitive identity, and the investigation does not establish that ExtortionLord, Mansoryx, Molot, or flex are necessarily the same individual. The evidence instead shows how a single communication identifier can persist across platforms and over time, connecting activity that would otherwise appear unrelated. In this case, a Tox ID attached to a 2026 data sale opened a window into a much older and more complex trail.

The identity behind ExtortionLord therefore remains an open question. But the actor who appeared on DarkForums was not surrounded by an entirely new digital footprint. The identifiers attached to that identity had a history, and by following those traces across StealthMole's indexed dark web, leaked-data, and Telegram sources, it became possible to reconstruct parts of that history without forcing uncertain correlations into definitive attribution.

Editorial Note

Attribution in cybercrime and underground investigations is rarely absolute. Aliases can be reused, accounts can change hands, and communication identifiers may connect individuals without proving they are the same person.

The case also demonstrates the value of StealthMole in navigating these fragmented environments, allowing investigators to move between current activity and historical records, follow persistent identifiers across different sources, and distinguish meaningful connections from coincidences without overstating what the available evidence can prove.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: , , ,

P4R4ZYT3 and DEFCOMX64 Escalation: From Government Data Breach to Public Campaign

Brazil’s cyber threat landscape has evolved rapidly over the past few years. What was once dominated by financially motivated fraud schemes and banking malware has expanded into a more complex ecosystem: blending hacktivism, data leaks, politically motivated disruption, and reputational campaigns conducted through Telegram and underground forums.

State-level institutions, regional government departments, and public service agencies have increasingly appeared in defacement claims, breach announcements, and coordinated messaging campaigns. In many cases, the operational impact is difficult to measure immediately. What is easier to observe, however, is the shift in posture.

Actors are no longer operating solely for quiet monetization. They are signaling.

Telegram, in particular, has become the staging ground for these narratives. Channels emerge, disappear, rebrand, and resurface. Profile identities change. Symbols rotate. Messages escalate from cryptic commentary to declarative threats. In this environment, disruption does not always mean disappearance, it often signals reorganization.

It was within this broader context that a cluster of activity began to stand out.

What initially appeared to be routine underground interaction gradually aligned with more assertive messaging tied to government-linked targets. The trajectory did not unfold overnight. It evolved in fragments.

This report examines that evolution.

By tracing identity shifts, channel migrations, rhetorical changes, and platform behavior, we move from environmental context to actor-specific escalation. The objective is not only to document what has occurred but to understand how public signaling, post-disruption regrouping, and narrative framing intersect within Brazil’s current cyber threat environment.

Incident Trigger and Initial Investigation

The investigation began with a keyword search for “Brazil” within StealthMole’s Government Monitoring tool. The query returned 152 results, all linked to Brazilian government-related data breach references. Rather than reviewing each entry individually, the focus shifted toward identifying actors showing repeated activity against Brazilian public-sector entities.

One name surfaced prominently: P4R4ZYT3.

To understand the scope of this actor’s involvement, the next step was to examine their most recent indexed activity. The latest breach attributed to this alias was recorded on 10 February 2026, referencing an attack against F********H. However, further investigation revealed that this breach actually happened on 09 January 2026.

The breach was originally announced on DarkForums at:

  • https://darkforums.**/Thread-DATABASE-BRAZIL-HTTPS****DATA-BREACH

Visiting the thread revealed that the post was made under the username P4R4ZYT3, accompanied by the DEFCOMX64 logo as the profile image. The message was written in a declarative tone and framed as a collective action, stating that the operation was conducted by the DEFCOMX64 group.

The thread included:

  • Claims of full database compromise
  • Stated extraction size of approximately 8.6 GB
  • Politically framed commentary directed at state governance
  • A recruitment-style “join us” message
  • Embedded links referencing DEFCOMX64 Telegram infrastructure
  • Sample datasets allegedly belonging to F*****H personnel

Two bio-style datasets were visible within the thread, containing structured personal information such as names, CPF numbers, contact details, and associated identifiers. These were presented as evidence of database access.

The consistent presence of DEFCOMX64 branding, recruitment language, and cross-platform references suggested that this was not an isolated leak post but part of a broader identity ecosystem.

At this point, the investigation shifted from a single breach thread to the actor’s broader footprint.

Using StealthMole’s Defacement Alert tool, the username P4R4ZYT3 was queried to determine whether the actor had conducted website defacements in addition to database breaches. The search returned 12 defacement records, with victims primarily located in Brazil and Germany.

The visual consistency between the DarkForums thread and the defaced website, particularly the repeated DEFCOMX64 insignia, indicated coordinated branding across breach announcements and defacement operations.

Actor Attribution and Cross-Platform Identity Mapping

With the F*******H breach and associated defacement activity linked to the alias P4R4ZYT3, the next step was to determine whether this identity existed beyond a single forum post.

Using StealthMole’s Dark Web Tracker, the username P4R4ZYT3 was queried across indexed underground platforms. The search revealed multiple profiles associated with the same alias across mirrored and related domains:

  • https://umbra.**/P******3
  • https://darkforums.**/U******3
  • https://darkforums.**/U*****3
  • https://darkforums.**/U******3
  • https://hellofhackers.com/members/p*******7/

The DarkForums mirrors reflected consistent account metadata, including identical join dates and user ID references. The profile image matched the DEFCOMX64 logo observed in the F******H breach thread. This consistency suggested that the activity was not an impersonation across unrelated forums, but a unified identity replicated across mirrored infrastructure.

The Umbra profile added a critical layer of linkage. It referenced:

  • Telegram channel: https://t.me/d*******
  • Telegram username: P*******c
  • Signature reference: DEFCOMX64

This connection bridged the forum identity to Telegram infrastructure.

Further review of the Hell of Hackers platform revealed an earlier thread titled “DATABASE DUMPED IN BRAZIL.” In that post, P4R4ZYT3 claimed responsibility for compromising a Brazilian company via SQL injection and releasing customer and employee data. The message explicitly stated that the actor’s language was Portuguese and referenced Brazilian-specific identifiers such as CPF numbers. This activity predates the February 2026 F*****H breach, indicating that Brazil-focused data exposure was not a one-time occurrence.

At this stage, three consistent elements emerged:

  • The alias P4R4ZYT3
  • The DEFCOMX64 branding
  • The Telegram handle P*******c

Telegram Infrastructure and Identity Consolidation

With the forum footprint established, attention shifted to Telegram, where several references linked directly to the alias.

Using StealthMole’s Telegram Tracker, the username was examined. The account displayed clear alignment with the previously identified alias P4R4ZYT3. The bio referenced DEFCOMX64, and the profile imagery evolved over time before stabilizing around the group’s branding.

  • https://t.me/P**********c

StealthMole’s historical indexing revealed five distinct profile changes during 2024. In June 2024, the profile used an anonymous-style mask. By August, the image shifted to a “Wizard Society” graphic. In December 2024, the bio incorporated different flag markers and new visual messaging. Over time, the profile transitioned toward consolidated DEFCOMX64 branding, accompanied by the Brazilian, pirate, and Russian flag emojis.

Archived Telegram group activity further strengthened attribution.

In a June 2024 discussion within the “Azzasec Chat,” the user explicitly stated that they were from Brazil. In separate conversations within the “Jacuzzi” channel, the alias referenced having made a Brazilian database publicly available on a forum and directed users to search for the name P4R4ZYT3.

The account was also observed requesting access to XWorm, a commercially distributed remote access tool frequently discussed in underground channels. While this does not confirm operational deployment, it demonstrates awareness of and interest in offensive tooling.

Beyond the personal account, Telegram infrastructure extended to a channel:

  • https://t.me/de********s

This channel was created on 14 January 2026, shortly after the F*******H breach announcement. Its first message stated that the group’s primary Telegram account had been taken down following the breach activity and that this new channel would serve as its continuation. The message was signed “Att. P4R4ZYT3.”

At the time of review, the channel contained eight messages and 95 members. The branding, tone, and signature matched the forum identity.

Unlike the earlier Telegram interactions, the channel messaging shifted from conversational to declarative. Statements referenced intensifying actions against the state government and announced a specific timeline for renewed activity.

At this point, Telegram was no longer a peripheral communication platform. It had become the central hub for identity consolidation, escalation messaging, and public signaling.

Escalation Messaging and Campaign Signaling

The creation of the de********s Telegram channel marked a visible transition in tone.

Earlier activity linked to P4R4ZYT3 largely centered on breach announcements, forum promotions, and participation in underground discussions. The messaging was reactive, reporting past actions or directing attention to previously released datasets.

That posture shifted in February 2026.

On 20 February 2026, the DEFCOMX64 Telegram channel published a message declaring that actions against the state government would be intensified. The statement referenced a “wave of attacks” targeting government employees in Roraima and specified a time for the start of renewed activity. The message was signed “Att. P4R4ZYT3.”

This marked a change in operational posture.

Rather than announcing completed breaches, the messaging projected forward intent. The tone moved from disclosure to declaration. The language adopted ideological framing, referencing governance and positioning actions as retaliatory or corrective.

It is important to distinguish between declared intent and confirmed impact. The Telegram statements represent public signaling, not independently verified technical outcomes. However, in underground ecosystems, such declarations serve a strategic purpose. They build reputation, attract attention, and frame subsequent activity within a narrative of escalation.

The timing is also notable. The channel itself was created on 14 January 2026, shortly after the F*******H breach announcement and the reported takedown of a previous Telegram presence. Within days of re-establishing communication infrastructure, escalation rhetoric appeared.

This sequence suggests three observable behaviors:

  • Rapid reconstitution after platform disruption
  • Consolidation of identity under DEFCOMX64 branding
  • Transition from breach reporting to campaign-oriented messaging

When combined with earlier defacement activity and prior Brazil-focused database releases, the February declaration does not appear isolated. Instead, it aligns with a trajectory moving from opportunistic breach exposure toward publicly framed, state-directed confrontation.

Whether such messaging translates into sustained operational capability remains subject to continued monitoring. What is clear, however, is that the actor has adopted a posture of escalation and is communicating that posture openly.

Conclusion

What began as a routine keyword search within StealthMole’s Government Monitoring tool ultimately revealed a structured pattern of activity centered around the alias P4R4ZYT3 and the DEFCOMX64 identity.

The progression was not abrupt. It unfolded across platforms, from forum-based database disclosures to visually branded defacements, from informal Telegram participation to consolidated channel creation, and finally to public declarations of intensified action against state-linked targets. The consistency of branding, repeated self-attribution, and cross-platform alignment demonstrate persistence rather than coincidence.

The February 2026 transition marks a notable inflection point. The creation of a new Telegram channel following reported account disruption, combined with forward-looking escalation messaging, indicates an attempt to shift from retrospective breach announcements to campaign-oriented signaling. Whether this shift translates into sustained operational capability remains subject to continued monitoring. However, the trajectory reflects deliberate identity consolidation and increasingly public positioning.

At present, observable behavior aligns with a visibility-driven, hacktivist-style posture focused on Brazilian government-linked entities. The actor openly claims affiliation, publishes branding consistently, and frames activity within ideological language. The absence of ransom demands or structured monetization channels suggests reputation and narrative influence may be primary motivators.

Continued monitoring of defacement indexing, Telegram messaging, and new breach disclosures will be essential to determine whether this escalation rhetoric evolves into sustained, coordinated activity or remains primarily declarative.

Editorial Note

Attribution and capability assessment in cyber investigations are rarely absolute. Online identities can be replicated, exaggerated, or strategically framed for visibility. This case demonstrates how fragmented signals can be methodically assembled to identify patterns without overextending conclusions using StealthMole.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Old Data, New Actor: Investigating Solonik’s Alleged Instagram 17 M Leak

In early January 2026, a threat actor operating under the name Solonik began gaining attention across dark web forums and Telegram channels after advertising a large-scale Instagram data leak allegedly tied to a “2024 API breach.” The dataset was marketed as containing 17 million Instagram user records, including usernames, emails, phone numbers, and internal IDs. Given Instagram’s global footprint and the scale claimed, the leak quickly drew interest from buyers and researchers alike.

At first glance, Solonik appeared to be a rapidly emerging actor. StealthMole monitoring showed a sharp spike in activity associated with his handle, with dozens of leaks posted in a short time frame and multiple distribution channels emerging almost simultaneously. The pace, volume, and confidence of Solonik’s claims suggested either privileged access to new data sources or a coordinated effort to appear established.

However, as the investigation progressed, inconsistencies began to surface. While the dataset was promoted as new and tied to a 2024–2026 breach window, early indicators suggested that identical data samples had circulated years earlier. This raised the possibility that the “new” Instagram leak was not a fresh compromise but a recycled dataset being reintroduced under a different narrative.

This report documents how StealthMole was used to trace the origins, movement, and rebranding of this dataset across forums, Telegram channels, and domains, ultimately challenging Solonik’s claims and highlighting the growing trend of breach recirculation under false timelines.

Incident Trigger and Initial Investigation

The investigation began when Solonik published a thread titled “INSTAGRAM.COM 17M USERS — 2024 API LEAK (USERNAMES, EMAILS, PHONES, IDS)” on Dark Forums.

  • https://darkforums.****/Thread-INSTAGRAM-COM-17M****Solonik-****

To assess the actor’s credibility and scale, the identifier Solonik was queried through StealthMole’s Leaked Monitoring module. This revealed that between 7 January 2026 and 20 January 2026, Solonik had been associated with leaks affecting approximately 105 distinct victims, ranging from social media datasets to regional institutional records. This level of activity suggested either a highly active reseller or a coordinated operation.

One of the earliest corroborating signals came from Solonik’s Telegram presence. Using StealthMole’s Telegram Tracker, the channel https://t.me/solonik_*****s was identified as a public-facing vouch and transaction channel. From there, StealthMole uncovered an additional invite-only Telegram group at https://t.me/+iS5*******k, where screenshots showed buyers negotiating prices, confirming cryptocurrency transactions, and receiving CSV database files.

Notably, this Telegram infrastructure had already been indexed by StealthMole under CVE-2025-14847 and CVE-2026-21858 linking Solonik’s ecosystem to previously flagged malicious distribution activity. This connection established that the actor was not operating in isolation and had already intersected with known high-risk Telegram clusters.

Expansion of Infrastructure and the “BAPHOMET” Reference

Further investigation into Solonik’s online footprint revealed the domain solonik.***, which was queried through StealthMole’s Darkweb Tracker. The results were significant: StealthMole indexed 999+ leaked files associated with this domain, many labeled with Instagram-related filenames such as Instagram@Solonik_BF.json.

Among these results, a second Instagram-related leak surfaced on 14 January 2026, tied to a BreachForums thread advertising 45K Korean Hospital Patient & System Records. In Solonik’s forum bio on this thread, he included the phrase blessed by BAPHOMET.

This phrase prompted a deeper investigation. Through Telegram tracking, StealthMole identified a video circulating in one of Solonik’s channels in which he screen-recorded a BreachForums interaction. In the video, a user identified as BAPHOMET thanked Solonik for previously disclosing information about an SQL vulnerability in the forum’s structure, specifically referencing the my tabs column.

The video also displayed BAPHOMET’s BreachForums profile, showing the account as permanently banned, but historically influential. The message claimed that Solonik had “saved” the forum from a breach years earlier and framed their interaction as proof of legitimacy and insider status. While the claim itself could not be independently verified, its inclusion served as a credibility signal aimed at potential buyers.

This was a critical turning point. The narrative was no longer just about a dataset, but about lineage, reputation, and implied authority within the breach ecosystem.

Data Lineage Analysis: Tracing the Instagram Dataset Backward

To validate Solonik’s claim that the Instagram data originated from a 2024 API breach, the dataset itself was examined. Using StealthMole’s Telegram Tracker, the keyword “Instagram Leak 17M Lines ⭐ ️” was queried across historical Telegram messages. This surfaced a forwarded message dated 2023-11-28, originating from the channel The Jacuzzi.

That forwarded message led directly to a LeakBase thread posted in March 2023 by a user named Chucky. The LeakBase snapshot showed the thread title “Json No Pass Cloud Instagram Leak 17M Lines”, with sample JSON entries containing usernames, emails, phone numbers, and IDs, structurally identical to the samples advertised by Solonik in 2026.

  • https://leakbase.la/threads/instagram-leak-17*************/

Further comparison confirmed that the raw data fields, ordering, and sample values matched across the 2023 LeakBase post and Solonik’s 2026 offering. No new columns, timestamps, or indicators suggested that the dataset had been refreshed or expanded.

This same dataset appeared again in 2024 on Hydra Forums, posted by administrator Pavlov under the title “Instagram Leak 17M Lines ⭐️”:

  • https://hydraforums.io/Threads-*****************************8F

The Hydra Forums snapshot showed the same JSON samples, confirming that the data had circulated unchanged for at least three years.

These findings directly contradicted Solonik’s framing of the leak as a “2024 API breach” and strongly indicated dataset recycling rather than a new compromise.

Chucky, Chucky_lucky, and Identity Overlap

Solonik later claimed in Telegram messages that his previous BreachForums account, “Chucky_lucky,” had been taken down by a moderator named L****i. To assess this claim, Chucky_lucky was queried in StealthMole’s Leaked Monitoring module. The results showed five victims, including a global jewellery brand breach from 2023.

This activity aligned temporally with the original LeakBase Instagram post by Chucky, strengthening the hypothesis that Chucky, Chucky_lucky, and Solonik may be connected. Additional Telegram channels reinforced this pattern, including https://t.me/chucky***f and https://t.me/chucky_*******a, where screenshots showed Chucky listed among the “richest users” on a forum consistent with BreachForums.

These overlaps do not conclusively prove shared ownership, but they demonstrate continuity in datasets, platforms, and monetization strategies. The repeated appearance of the same Instagram data under different aliases across years suggests deliberate rebranding rather than independent rediscovery.

Telegram Attribution and Iranian Infrastructure

The investigation expanded further when the Telegram channel https://t.me/solonik***t was analyzed. StealthMole identified a user Solonik BF. From this channel, a phone number was extracted: +98 9*********8. While usernames on Telegram are easily changed, user IDs are persistent, making this identifier particularly valuable for further analysis.

The country code +98 indicates Iran. When this number was queried through StealthMole’s Darkweb Tracker, it appeared in a file labeled Iran_Telegram.json, part of previously leaked Iranian Telegram datasets. This does not confirm Solonik’s physical location, but it provides a rare infrastructural linkage between his Telegram presence and known leaked data repositories.

This file is part of a broader collection of leaked Iranian Telegram user data and contains structured records linking phone numbers to Telegram usernames and internal user IDs. Within this dataset, the number is explicitly associated with the username Sa*****n, once again tied to user ID 46******7, conclusively linking the Iranian Telegram leak data to the same account now operating as @Solonik*****F.

Historical analysis of this Telegram user ID provided additional context. When user ID 4********7 was pivoted through StealthMole’s Telegram Tracker, earlier activity associated with the same identifier was identified. Records dating back to October 2022 show the account operating under the username @Sa*****n, with display names recorded as S**** / T***t. This confirms that the identity linked to Solonik predates the 2026 Instagram leak claims by several years, suggesting a long-standing Telegram presence rather than a newly created persona.

Further examination of historical Telegram data showed that this account had been active as early as October 2020, based on StealthMole’s historical indexing. This timeline places the operator well before the emergence of the Instagram dataset later circulated in 2023, 2024, and 2026. The persistence of the same user ID across multiple usernames reinforces the continuity of control over the account, even as outward-facing identities evolved over time.

Additional contextual signals emerged when this Telegram identity was traced across group interactions. The same user ID was referenced within a Persian-speaking Telegram group titled Tavern Club, accessible at https://t.me/g*******b. While participation in such groups does not independently confirm attribution, it further situated the account within an Iranian-language Telegram ecosystem.

Taken together, these findings strengthen the infrastructural linkage between Solonik’s Telegram presence and Iranian-linked Telegram data exposure. The reuse of the same Telegram user ID across multiple usernames, its appearance in leaked Iranian Telegram datasets, and its interaction within regionally aligned Telegram groups suggest operational continuity rather than coincidence. This infrastructure-level overlap does not definitively attribute Solonik to a specific individual or location, but it provides a consistent and traceable framework that aligns with other elements observed throughout the investigation.

Conclusion

The investigation demonstrates that the Instagram “17M users” dataset advertised by Solonik in January 2026 is not new. Through StealthMole’s historical indexing and cross-platform tracking, the data can be traced back to at least March 2023, with confirmed appearances in 2023 (LeakBase) and 2024 (Hydra Forums) before resurfacing in 2026.

Instagram has publicly denied any 2026 breach, further undermining Solonik’s claims. While Solonik has successfully leveraged volume, presentation, and reputation signaling to attract buyers, the underlying data tells a different story, one of recirculation rather than compromise.

Whether Solonik is the same individual as Chucky or Chucky_lucky cannot be stated with certainty. However, the continuity of datasets, platforms, Telegram infrastructure, and monetization patterns strongly suggests either direct identity overlap or close operational alignment.

Editorial Note

Attribution in dark web investigations is rarely absolute. Actors reuse data, identities fragments, and narratives are intentionally blurred. This case underscores how easily old breaches can be reframed as new incidents and how critical longitudinal visibility is in cutting through those claims. By correlating historical leaks, Telegram activity, and infrastructure signals, StealthMole enabled a clearer understanding of what was genuinely new, what was recycled, and where uncertainty still remains.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report