[October-10-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. M.S Security Group falls victim to Kairos Ransomware

  1. Forestry Department falls victim to DEVMAN 2.0 Ransomware

  1. DEVMAN 2.0 ransomware group adds an unknown victim (r******urology.com)

  1. HIME666 targets the website of Policy Advisor

  1. Alleged sale of sensitive documents from CIA

  1. Paleontological Research Institution falls victim to Sinobi Ransomware

  1. Complete Milling Lab falls victim to Sinobi Ransomware

  1. krne.com falls victim to SAFEPAY Ransomware

  1. Sunbulah Group falls victim to Sinobi Ransomware

  1. glatten.de falls victim to SAFEPAY Ransomware

  1. Alleged data breach of Centre for Distance and Online Education

  1. Central Jersey Medical Center falls victim to Sinobi Ransomware

  1. Porto Funeral Homes falls victim to SAFEPAY Ransomware

  1. Glenn Graydon Wright LLP falls victim to SAFEPAY Ransomware

  1. Alleged data leak of Venezuelan Military

  1. CML Machinery Inc. falls victim to SAFEPAY Ransomware

  1. Empirico Research falls victim to SAFEPAY Ransomware

  1. Tango De Mayo Hotel falls victim to SAFEPAY Ransomware

  1. BridgeNet Communications, LLC falls victim to SAFEPAY Ransomware

  1. ClawSec Team targets the website of InfinityFree

  1. Brevard Skin and Cancer Center falls victim to PEAR Ransomware

  1. M A D G H O S T targets the website heshoo.com

  1. M A D G H O S T targets the website saghebi.ir

  1. Arabian Ghosts targets the website of Cilimiao

  1. Alleged sale of unauthorized access to an unidentified manufacturing company in Spain

  1. Arabian Ghosts targets the website of Webempresa Europa

  1. Arabian Ghosts targets the website of Tutorial.com

  1. Alleged leak of Vietnamese online shopping data

  1. Alleged leak of random documents from a military base

  1. InDoM1nu’s targets the website of emplolio

  1. Caparrós Nature, SL. falls victim to Qilin Ransomware

  1. InDoM1nu’s targets the website of teamclue

  1. Alleged data leak of Bank Leumi

  1. Artan Holding falls victim to Qilin Ransomware

  1. Alleged sale of unauthorized access to an unidentified hotel in Uruguay

  1. Alleged data breach of Russian Post
  • Category: Data Breach
  • Content: The threat actor claims to be selling 94.7 MB of Russian Post database (TXT) containing 61 pages of records with full names, registered and actual addresses, SNILS/TIN, and passport series/numbers
  • Date: 2025-10-10T17:11:17Z
  • Network: openweb
  • Published URL: (https://xss.pro/threads/143702/)
  • Screenshots: https://d34iuop8pidsy8.cloudfront.net/c3ebe43a-8ee9-4baa-befa-4b4b607a59d8.png
  • Threat Actors: SilentRoot
  • Victim Country: Russia
  • Victim Industry: Transportation & Logistics
  • Victim Organization: russian post
  • Victim Site: ruspost.eu

  1. Royal Den Hartogh Logistics falls victim to ANUBIS Ransomware

  1. Alleged sale of turnkey malware

  1. Alleged data breach of LEJE – Leilão Judicial Eletrônico

  1. Alleged data breach of Searchhub

  1. Friendly Gus falls victim to Sinobi Ransomware

  1. Alleged data sale of Inland Revenue Department (IRD)

  1. Alleged data breach of Attiva Medical

  1. American Home Furniture and Mattress falls victim to LYNX Ransomware

  1. Alleged data breach of Brightannica Pty Ltd

  1. Alleged data sale of Job-Kleidung GmbH

  1. HMEI7 targets the website of Gilgal Christian Assembly

  1. Alleged data leak of Orange

  1. Alleged data sale of the Grenoble Academy

  1. HMEI7 targets the website of GBCT World

  1. Five Star Mechanical falls victim to akira Ransomware

  1. Carlson Building Maintenance falls victim to Akira Ransomware
  • Category: Ransomware
  • Content: The group claims to have obtained 20 GB of the organization’s data. The compromised data includes essential corporate documents such as: financial data (audit, payment details, financial reports, invoices), employees and customers information (passports, driver’s licenses, emails, phones), confidential information and other documents with personal information.
  • Date: 2025-10-10T12:54:43Z
  • Network: tor
  • Published URL: (https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion/)
  • Screenshots: https://d34iuop8pidsy8.cloudfront.net/f853e7c5-db33-48d3-9d45-3f13e7abc401.png
  • Threat Actors: akira
  • Victim Country: USA
  • Victim Industry: Facilities Services
  • Victim Organization: carlson building maintenance
  • Victim Site: carlsonbuilding.com

  1. Alleged data breach of the Drought Management Centre for Southeastern Europe

  1. Alleged data breach of Ticketmaster

  1. Alleged data breach of the Ministry of Welfare and Social Affairs, Israel

  1. Alleged access sale of Indian software company
  • Category: Initial Access
  • Content: The treat actor claims to be selling access to an Indian software development company. The actor mentions RDP and Domain Admin privileges across around 350 hosts, indicating potential full network-level access to the organization’s infrastructure.
  • Date: 2025-10-10T12:08:43Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/267938/)
  • Screenshots: https://d34iuop8pidsy8.cloudfront.net/5256e13c-c139-4700-8be0-5c9ab0f1be2e.png
  • Threat Actors: Big-Bro
  • Victim Country: India
  • Victim Industry: Software Development
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged leak of Chinese overseas data in France

  1. Alleged data breach of MyRepublic Indonesia

  1. Alleged leak of admin access to Bangladesh Power Development Board (BPDB)

  1. Alleged leak of access to Bangladesh Nursing and Midwifery Council

  1. Alleged data breach of Delek Group

  1. Alleged data breach of TraxNYC

  1. Alleged leak of COLOMBIA Immigration Database

  1. Alleged leak of admin access to Romanian Intelligence Service

  1. Alleged leak of admin access to JDIH Legal Department of the West Halmahera Regency Government
  • Category: Initial Access
  • Content: The threat actor claims to have leaked admin-level access to the JDIH Legal Department of the West Halmahera Regency Government’s administration system.
  • Date: 2025-10-10T07:11:58Z
  • Network: telegram
  • Published URL: (https://t.me/c/2532663346/224)
  • Screenshots: https://d34iuop8pidsy8.cloudfront.net/335fd5b9-b59a-4371-9560-6e4b1ecaf2cb.png
  • Threat Actors: BABAYO EROR SYSTEM
  • Victim Country: Indonesia
  • Victim Industry: Government Administration
  • Victim Organization: west halmahera district
  • Victim Site: jdih.halbarkab.go.id

  1. Alleged unauthorized access to the Solar System from Italy.

  1. Alleged sale of U.S. Bank Data and Personal Information

  1. Alleged data breach of Ministry of Defense of Venezuela

  1. Churchill Claims Services falls victim to SECUROTROP Ransomware

  1. Alleged sale of admin access to an unidentified wordpress shop from

  1. Alleged data breach of PT Tempo Scan Group

  1. Falco Electronics falls victim to BlackShrantac Ransomware

  1. CyberToufan claims to target MAYA Technologies Ltd.

  1. Pharaoh’s Team Channel claims to target India

  1. Alleged data breach of San Nicolás municipal government

  1. Benedict Industries falls victim to INC RANSOM Ransomware

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Ransomware attacks, notably from groups like SAFEPAY, Sinobi, akira, Qilin, and Kairos, are the most prominent threat category, affecting sectors like Hospital & Health Care, Manufacturing, Government & Public Sector, and Financial Services across the USA, Canada, Germany, and others.

Data breaches remain a significant risk, targeting sensitive data from organizations such as the Ministry of Welfare and Social Affairs (Israel), Ticketmaster (USA), and Orange (France), with data ranging from personal information and customer records to classified military documents.

Activity in Initial Access sales also underscores the availability of network entry points, with threat actors offering access to an Indian software development company, the Romanian Intelligence Service, and the Bangladesh Power Development Board.

The incidents collectively demonstrate that organizations across various industries and geographies face persistent threats from data exfiltration, unauthorized network access, and the proliferation of malicious tools, emphasizing the critical importance of robust cybersecurity measures.