[September-22-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Alleged Sale of USA citizens data

  1. Alleged Sale of Hotmail Checker tool

  1. Alleged unauthorized access to greenhouse climate control system in Poland

  1. Alleged sale of USA insurance data

  1. Alleged data leak of airports in Europe

  1. Infinite Cyber Team targets the website of Universidad Paccioli de Córdoba

  1. HellR00ters Team targets the website of [suspicious link removed]

  1. HellR00ters Team targets the website of Shaden Arabian Contracting

  1. HellR00ters Team targets the website of Media House

  1. HellR00ters Team targets the website of Baasim Advertising

  1. Alleged data breach of Forex World Pty Ltd

  1. Alleged data breach of Interteach

  1. Alleged Unauthorized Access to Unidentified Heat Control System in Poland

  1. Alleged Sale of access to Government of Romania

  1. Alleged unauthorized access to unidentified U.S. gas station control system
  • Category: Initial Access
  • Content: The group claims to have gained access to a gas station control system in the United States. The alleged breach reportedly enables monitoring of pipeline pressure, gas flow, temperature, and operational status, as well as management of emergency shut-off valves and alarm signals.
  • Date: 2025-09-22T10:49:25Z
  • Network: telegram
  • Published URL: https://t.me/n2LP_wVf79c2YzM0/1704
  • Screenshots:
  • Threat Actors: Infrastructure Destruction Squad
  • Victim Country: USA
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged data breach of Sultan Qaboos Comprehensive Cancer Center

  1. Alleged sale of corporate SMTP

  1. Alleged Unauthorized Access to Irrigation and Fertigation Control System, Italy

  1. Alleged unauthorized access to dairy plant control systems in Italy

  1. Alleged data breach of Pakistan Military Account Department

  1. Alleged leak of All-In-One Checker

  1. Alleged data breach of Italian State Police

  1. Alleged sale of Civil Aviation Authority of Nepal
  • Category: Initial Access
  • Content: The threat actor claims to be selling the entire server of the Civil Aviation Authority of Nepal, including internal airport databases and sensitive files.
  • Date: 2025-09-22T06:11:13Z
  • Network: telegram
  • Published URL: https://t.me/ctrl_nepal/114
  • Screenshots:
  • Threat Actors: GenZRisingNepal
  • Victim Country: Nepal
  • Victim Industry: Aviation & Aerospace
  • Victim Organization: civil aviation authority
  • Victim Site: caanepal.gov.np

  1. Alleged admin access to World Aviation Services in Egypt

  1. Alleged data breach of Tokopedia

  1. Alleged sale of Knck Clip Crypto Clipper C-Sharp2025

  1. Alleged sale of admin access to an unidentified private NAS server in China

  1. Alleged data leak of Norway B2B/B2C Data

  1. Alleged data sale of Binance.US

  1. Alleged sale of global crypto database

  1. Alleged data breach of ePardoseli

  1. Alleged data leak of Norway Buyer Records
  • Category: Data Breach
  • Content: Threat actor claims to be selling a database containing 76,250 personal entries. Sample data includes full names, phone numbers, and residential addresses of individuals across various Norwegian cities such as Oslo, Bergen, Trondheim, and Kristiansand.
  • Date: 2025-09-22T02:11:48Z
  • Network: openweb
  • Published URL: https://forum.exploit.in/topic/266749/
  • Screenshots:
  • Threat Actors: r57
  • Victim Country: Norway
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged data breach of Bouygues Telecom

  1. Alleged sale of RDP and VPN access to Industrial Machinery & Equipment company in Malaysia
  • Category: Initial Access
  • Content: Threat actor claims to be selling VPN-RDP access to an industrial machinery and equipment company based in Malaysia, allegedly with domain admin privileges. The compromised network reportedly includes 213 hosts, over 20 domain-joined machines, and approximately 4TB of data.
  • Date: 2025-09-22T02:01:26Z
  • Network: openweb
  • Published URL: https://forum.exploit.in/topic/266753/
  • Screenshots:
  • Threat Actors: decider
  • Victim Country: Malaysia
  • Victim Industry: Machinery
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged data leak of Norway Consumer Luxury Shop

  1. Alleged data breach of France Titres – Agence Nationale Des Titres Sécurisé

  1. Alleged sale of RDP and VPN access to an unidentified education firm in Colombia

  1. Alleged sale of RDP and VPN access to an unidentified Commercial & Residential Construction company in Philippines

  1. Alleged sale of VPN access to an unidentified business service company in Philippines
  • Category: Initial Access
  • Content: Threat actor claims to be selling VPN-RDP access to a business services company based in the Philippines, allegedly with domain admin privileges. The compromised infrastructure reportedly includes 186 hosts and over 35 machines joined to the domain.
  • Date: 2025-09-22T01:43:44Z
  • Network: openweb
  • Published URL: https://forum.exploit.in/topic/266751/
  • Screenshots:
  • Threat Actors: decider
  • Victim Country: Philippines
  • Victim Industry: Business and Economic Development
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged data leak of documents from Indonesia

Conclusion The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Data breaches and leaks are prominent, affecting various sectors from education and gaming to healthcare and automotive, and impacting countries including Bangladesh, Mexico, Malaysia, India, Indonesia, France, Brazil, and Israel. The compromised data ranges from personal user information and credit card details to sensitive patient records, classified military components, and large customer databases. Beyond data compromise, the report also reveals significant activity in initial access sales, with threat actors offering unauthorized access to banking systems, corporate networks (including RDWeb access to Canadian and UK firms), and even government and military infrastructure like the Royal Thai Air Force and Madrid’s irrigation system. The sale of malware, including penetration testing tools and DDoS tools, further underscores the availability of offensive capabilities in the cyber underground. The incidents collectively demonstrate that organizations across various industries and geographies face persistent threats from data exfiltration, unauthorized network access, and the proliferation of malicious tools. The nature of these incidents emphasizes the critical importance of robust cybersecurity measures, including strong access controls, data protection strategies, continuous vulnerability management, and proactive threat intelligence to defend against a wide array of sophisticated and opportunistic attacks.