New Data Leak Site Uncovered Linked to Active Initial Access Broker on Underground Forums
On Sun, Mar 22, 2026, a new data leak site named "ALP-001" emerged on the dark web. Operating as a Tor-based platform, it markets itself as a "Data Leaks / Access Market."
On Sun, Mar 22, 2026, a new data leak site named "ALP-001" emerged on the dark web. Operating as a Tor-based platform, it markets itself as a "Data Leaks / Access Market."
The site signifies a shift in operations for threat actors traditionally involved in selling corporate network access. These actors appear to be moving towards extensive extortion practices by merging data theft with exposure.
Security researchers have identified ALP-001 as an extension of an organized threat actor present in dark web forums since at least July 2024. This group was initially known for selling unauthorized access to enterprise systems, focusing on perimeter devices and remote access gateways.
ReliaQuest analysts have linked ALP-001 to an active Initial Access Broker (IAB) operating on forums like Exploit and DarkForums. The group has been identified by matching Tox and Session IDs on the leak site with those on IAB forum accounts. Historically, this group was referred to as "Alpha Group" and "DGJT Group."
On Sun, Mar 22, 2026, a new data leak site named "ALP-001" emerged on the dark web.
The group's targets are primarily internet-facing technologies, such as FTP and SSH servers, Fortinet and FortiGate VPN appliances, Cisco equipment, Citrix, RDWeb gateways, and GlobalProtect systems. These targets provide significant access to corporate environments once compromised.
ALP-001 is connected to at least 10 IAB accounts across six dark web forums, with activity starting in July 2024. The group advertises unauthorized access through compromised technologies such as FTP servers, Fortinet/FortiGate VPNs, GlobalProtect, and Citrix environments.
Organizations should audit and patch all internet-facing devices, particularly Fortinet, Cisco, and Citrix solutions, which are frequently targeted. Security teams should monitor for unauthorized access, unusual data transfers, and irregular privileged account activity. Implementing multi-factor authentication on all remote access points and conducting privileged account audits are critical steps to reduce exposure.
For more updates, follow us on Google News , LinkedIn , and X .
Based on reporting by Cyber Security News.
