DreamChild
Aug 3, 2026
A data breach attributed to a target or platform named 'DreamChild', released or associated with the threat actor handle 'GoreTurbine'. The dataset contains user records including phone numbers, names, IP addresses, geographic information (country, region, city), device identifiers, device types, device family, carrier information, OS names and versions, platform data, app version names, and session/title metadata. The data appears to originate from a mobile analytics or user tracking backend.
Data found in this dataset
Source files
Expand any file to inspect its column headers and the LLM's field-mapping reasoning, recorded during ingestion.
DREAMCHILD_JSONLINES__records.csv5 columns64,002 rows
File structure
Format: CSV·Delimiter: Comma·Has header: yes·Quote: "
| Source column | Mapped field | Confidence | LLM assessment |
|---|---|---|---|
| 0 | phone | high | header "Phone" resolves to PII field "phone" |
| 3 | country | high | header "Country" resolves to PII field "country" |
| 5 | city | high | header "City" resolves to PII field "city" |
| 83 | phone | high | header "Phone.1" resolves to PII field "phone" |
| 84 | phone | high | header "Phone.2" resolves to PII field "phone" |
Notes: Heuristic auto-detection: header-named PII columns confirmed by data conformance
DREAMCHILD_PRETTYJSON__records.csv5 columns64,002 rows
File structure
Format: CSV·Delimiter: Comma·Has header: yes·Quote: "
| Source column | Mapped field | Confidence | LLM assessment |
|---|---|---|---|
| 0 | phone | high | header "Phone" resolves to PII field "phone" |
| 3 | country | high | header "Country" resolves to PII field "country" |
| 5 | city | high | header "City" resolves to PII field "city" |
| 83 | phone | high | header "Phone.1" resolves to PII field "phone" |
| 84 | phone | high | header "Phone.2" resolves to PII field "phone" |
Notes: Heuristic auto-detection: header-named PII columns confirmed by data conformance