[September-8-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.

1.

Alleged Sale of RDWeb Access to Dutch Home Improvement & Hardware Retail Firm

  • Category: Initial Access
  • Content: The threat actor claims to be selling RDWeb access to a Netherlands-based home improvement and hardware retail company with reported revenue of $5.9 million. According to the listing, the access includes around 200 Active Directory accounts and Datto RMM integration.
  • Date: 2025-09-08T13:46:09Z
  • Network: openweb
  • Published URL: https://forum.exploit.in/topic/265795/
  • Screenshots:
  • Threat Actors: gadji
  • Victim Country: Netherlands
  • Victim Industry: Retail Industry
  • Victim Organization: Unknown
  • Victim Site: Unknown

2.

Alleged data leak of Kraken

3.

Alleged unauthorized access to Palazzo Raja Hotel, Italy

4.

Z-ALLIANCE targets the website of Agrohills Nut

5.

Alleged access to unidentified CCTV cameras in Turkey

6.

Alleged access sale to OJSC Multiregional TransitTelecom

7.

Alleged Sale of HizeAero PDM Data

8.

Alleged unauthorised access to multiple unidentified organizations

9.

Alleged sale of financial data from Vietnam

  • Category: Data Breach
  • Content: The threat actor claims to be selling a comprehensive financial database from Vietnam, reportedly containing sensitive information such as personal identification details, credit payment histories, risk analyses, credit card data, military and government IDs, tax IDs, income statements, and debt records.
  • Date: 2025-09-08T11:02:28Z
  • Network: telegram
  • Published URL: https://t.me/c/2976044031/2242
  • Screenshots:
  • Threat Actors: Scattered Lapsus$
  • Victim Country: Vietnam
  • Victim Industry: Financial Services
  • Victim Organization: Unknown
  • Victim Site: Unknown

10.

Alleged Sale of WooCommerce Canada Access

  • Category: Initial Access
  • Content: The threat actor claims to be selling access to a WooCommerce-based platform in Canada, which includes both a webshell and database. The system reportedly processes 400-450 card transactions per month via iframe, while the admin panel reflects 550-600 transactions per month.
  • Date: 2025-09-08T10:27:57Z
  • Network: openweb
  • Published URL: https://forum.exploit.in/topic/265774/
  • Screenshots:
  • Threat Actors: bonafire
  • Victim Country: Canada
  • Victim Industry: E-commerce & Online Stores
  • Victim Organization: Unknown
  • Victim Site: Unknown

11.

Alleged sale of admin access to Svedala Municipality

12.

Alleged sale of admin access to Skolinspektionen

13.

Alleged sale of admin access to Oskarshamn Municipality

14.

Alleged sale of admin access to Öckerö Municipality

15.

Alleged sale of admin access to Lund Municipality

16.

Alleged sale of admin access to Gällivare Municipality

17.

Alleged sale of admin access to Kommuninvest

18.

Alleged sale of admin access to Falun Municipality

19.

Alleged unauthorized access to unidentified Advanced Metering Infrastructure (AMI) in Ukraine

20.

Alleged unathorized access to NM India Biotech

21.

Alleged data leak of 10 Design

22.

GenZRisingNepal claims to target Federal Parliament of Nepal

23.

GenZRisingNepal targets the website of Hotel Association Nepal

24.

Alleged data breach of NCC Alumni Association

25.

Alleged data breach of National Academy of Science and Technology, Philippines

26.

UNDERGROUND-NET targets the website of Mak Pet

27.

Alleged data breach of Watertec India Pvt Ltd

28.

Alleged sale of 161 Credit Card from USA

Conclusion

The cyber incidents detailed in this report indicate a varied and active threat landscape. Data breaches and the sale of access are prominent, affecting sectors such as government administration, retail, financial services, and manufacturing, across countries including Sweden, Ukraine, India, and the Philippines. The compromised data ranges from highly sensitive financial information and personal user data to intellectual property and operational system access. The sale of administrative access to government and corporate systems highlights the ongoing risk of unauthorized access. These events collectively underscore the persistent and diverse nature of cyber threats, emphasizing the need for robust security measures to protect against data exfiltration and unauthorized network access. Sources