[September-15-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


1. GARUDA ERROR SYSTEM targets the website of E-hinga


2. Alleged data sale of SmartTrader


3. Alleged data breach of Diia


4. Alleged data leak of Kulturkvarteret

  • Category: Data Breach
  • Content: The group claims to have leaked more than 20K data from Kulturkvarteret. The compromised data reportedly contain information such as names, addresses, phone numbers, contact emails, sender emails, places, cities, IP addresses, and hashed passwords.
  • Date: 2025-09-15T14:02:24Z
  • Network: telegram
  • Published URL: (https://t.me/bl4ckcyb3rofficial/1934)
  • Screenshots:
  • Threat Actors: BL4CK CYB3R
  • Victim Country: Sweden
  • Victim Industry: Recreational Facilities & Services
  • Victim Organization: kulturkvarteret
  • Victim Site: kulturkvarteret.se

5. Alleged data leak of Avatel Telecom

  • Category: Data Breach
  • Content: The threat actor claims to have leaked data from Avatel Telecom, including employee information exfiltrated from Active Directory and 380 GB of user and corporate data from the company’s Oracle Database. The leaked content allegedly contains sensitive infrastructure details, financial records, internal contracts, client data, and personal information of users.
  • Date: 2025-09-15T13:59:33Z
  • Network: openweb
  • Published URL: (https://darkforums.st/Thread-Selling-ES-Avatel-Telecom-Database)
  • Screenshots:
  • Threat Actors: ByteToBreach
  • Victim Country: Spain
  • Victim Industry: Network & Telecommunications
  • Victim Organization: avatel telecom
  • Victim Site: avatel.es

6. Alleged data sale of UAE Red Crescent


7. Alleged data leak of Office of the Basic Education Commission


8. Alleged data leak of Tickle me


9. Alleged data leak of Majlis Agama Islam Melaka (MAIM)


10. Alleged data leak of Ministry of Economy of Malaysia


11. Alleged data leak of Ministry of Home Affairs Malaysia


12. Alleged data leak of Bureau of Internal Revenue


13. Alleged leak of multiple login credentials from Abu Dhabi Judicial Department


14. Alleged unauthorized access to a Maroso autoclave controller system in the UK


15. Alleged data leak of Rational Solutions


16. Alleged data leak of CenTríto


17. Alleged data leak of Heyfood


18. Alleged data leak of Speedi


19. Alleged data leak of Urzza Charge Tech


20. Alleged leak from an unidentified Brazilian database


21. Alleged data leak of Oblige


22. Alleged data leak of Mitecnico


23. Alleged Data Breach of MobiVerse


24. Alleged Data Breach of Fabrice Claeys


25. Alleged leak of Admin access to Ministry of Education and Research

  • Category: Initial Access
  • Content: The group claims to have leaked the Romanian Ministry of Education’s administration system, gaining access to high school application data and the ability to alter statuses. They also modified the system to visibly demonstrate the breach to administrators
  • Date: 2025-09-15T06:06:13Z
  • Network: telegram
  • Published URL: (https://t.me/OverloadXTeam/161)
  • Screenshots:
  • Threat Actors: OverloadX Team Hacker
  • Victim Country: Romania
  • Victim Industry: Government Administration
  • Victim Organization: ministry of education and research
  • Victim Site: jobs.edu.ro

26. Alleged Data Breach of Ebay Accounts


27. Alleged data leak of Facebook


28. Alleged data leak of Netflix


29. Alleged Unauthorized Access to U.S. Oil & Gas Control System


30. Alleged data leak of LEDGER


31. Alleged Data breach of Gravatar


32. Alleged Data Breach of Mercado Libre


33. Alleged Data Leak of Pengadilan Agama Gunung Sitoli

  • Category: Data Breach
  • Content: A threat actor claims to have leaked a database pa-gunungsitoli.go.id, including personal details such as names, addresses, emails, phone numbers, and other metadata.
  • Date: 2025-09-15T04:47:56Z
  • Network: telegram
  • Published URL: (https://t.me/LenteraBawahOfc/204)
  • Screenshots:
  • Threat Actors: ResetIDN
  • Victim Country: Indonesia
  • Victim Industry: Government Administration
  • Victim Organization: pengadilan agama gunung sitoli
  • Victim Site: pa-gunungsitoli.go.id

34. Alleged sale of Google LLC 0day Redirection Vulnerability


35. Alleged unauthorized admin access to an unidentified Two Top Pakistani Government Websites


36. Alleged Data Breach of Magnus Marketing


37. Alleged Data Breach of Jacob Engineering and Education ME


38. Alleged Data Breach of Sangoma Technologies Corporation


39. Alleged leak of Unidentified Vulnerability in Department of Education -Cordillera Administrative Region

  • Category: Vulnerability
  • Content: threat actor claims to have discovered vulnerabilities on the DepEd Tayo Cordillera website that could potentially allow access to all accounts through a single login. The poster advises the organization to patch the site, implement stronger encrypted passwords, and train employees.
  • Date: 2025-09-15T03:17:57Z
  • Network: openweb
  • Published URL: (https://darkforums.st/Thread-deped-car-ph-DepEd-Tayo-Cordillera)
  • Screenshots:
  • Threat Actors: r00tXpLo1t
  • Victim Country: Philippines
  • Victim Industry: Education
  • Victim Organization: department of education -cordillera administrative region
  • Victim Site: depedcar.ph

40. Alleged Data Leak of Thailand Covid Study from Educational Institution

  • Category: Data Breach
  • Content: The threat actor claims to have leaked a COVID vaccination study database from a Thai educational institution, exposing highly sensitive personal data of what is claimed to be over 7.2 million individuals. The dataset includes Thai national ID numbers, full names, university student IDs, faculty information, and detailed COVID vaccination records such as vaccine types, dates, and dose history.
  • Date: 2025-09-15T03:16:44Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/266280/)
  • Screenshots:
  • Threat Actors: r57
  • Victim Country: Thailand
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

41. Alleged data breach of Balance Brand


42. Alleged Data Breach of Council of Ministers of Iraq


43. Alleged data breach of SELF U


44. Alleged Data Leak of USA Housekeeping Owners Data


45. Alleged data sale of Thailand car owners information


46. Alleged data breach of ALB Commercial Capital


47. Alleged data breach of Look

  • Category: Data Breach
  • Content: The threat actor claims to have leaked a database of Look.com.ua, a Ukrainian lifestyle platform that provides content on beauty, fashion, health, and interior design. The actor alleges that the dump contains 353,761 records, including email addresses, hashed passwords, usernames, IP addresses, and other user metadata.
  • Date: 2025-09-15T00:20:36Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/266270/)
  • Screenshots:
  • Threat Actors: r57
  • Victim Country: Ukraine
  • Victim Industry: Marketing, Advertising & Sales
  • Victim Organization: look
  • Victim Site: look.com.ua

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Data breaches and leaks are prominent, affecting various sectors from education and e-commerce to government and financial services. The compromised data ranges from personal user information and account details to sensitive organizational data and intellectual property.

Beyond data compromise, the report also reveals significant activity in initial access sales, with threat actors offering unauthorized access to various systems, including government infrastructure and a U.S. oil and gas control system. The sale of vulnerabilities and malicious tools, such as an alleged Google 0day and an SQL injection exploit, further underscores the availability of offensive capabilities in the cyber underground.

The incidents collectively demonstrate that organizations across various industries and geographies face persistent threats from data exfiltration, unauthorized network access, and the proliferation of malicious tools. The nature of these incidents emphasizes the critical importance of robust cybersecurity measures, including strong access controls, data protection strategies, continuous vulnerability management, and proactive threat intelligence to defend against a wide array of sophisticated and opportunistic attacks.