[October-25-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


1. Alleged sale of CIA Intelligence data

2. PAP SUD falls victim to Nova Ransomware

3. Alleged leak of confidential intelligence data from multiple countries

4. Alleged data breach of Bahia Park

5. Alleged leak of unauthorized access to Wintale

6. Alleged leak of unauthorized access to Carbonia Musei

7. Alleged leak of unauthorized access to Divyan Properties

8. Precision Machined Products falls victim to akira ransomware

9. Alleged gain of access to the FTP server of MB “Gripitas IT”

10. Essential Cabinetry Group falls victim to Qilin Ransomware

11. Red wolf cyber claims to target India

12. Alleged Sale of Italian Credit Card Dumps

13. Alleged data breach of Sensory

14. Alleged data breach of Central Military Hospital

15. Alleged data sale of Royal Thai Army

16. Alleged sale of citizens’ data from Spain

17. Alleged leak of PII data from Indonesia

18. Svenska kraftnät falls victim to Everest Ransomware

19. Alleged Sale of 200K Credential Combo

20. Omrin falls victim to Qilin Ransomware

21. Kaufman & Stigger, PLLC Injury Lawyers falls victim to Qilin Ransomware

22. Zacho-Lind falls victim to Qilin Ransomware

23. City of Sugar Land, TX falls victim to Qilin Ransomware

24. HEZI RASH targets the website of Syrian Financial Analysts Society

25. MetroWest Community FCU falls victim to akira Ransomware

26. Alleged data breach of Siraj Finance

27. Alleged sale of a compact web-shell system

28. GHOST’S OF GAZA targets the website of Feni District Council

29. Alleged data sale of M-TIBA

30. Alleged sale of Admin access to Brazilian Police System

31. BABAYO EROR SYSTEM targets the website of Purbalingga Regency Government

32. Alleged leak of 5 Million unique Spanish passwords

33. David Yurman falls victim to CL0P Ransomware

34. HEZI RASH targets the website of bluediamondresearch.com


Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats, strictly based on the provided data. Ransomware attacks were notably frequent, with groups like Qilin and akira impacting organizations in the USA, Denmark, and the Netherlands. Data Breaches continued to be prominent, with incidents exposing large datasets from various countries, including Spain (38 million rows of citizen data) , Indonesia (4 billion PII data) , and a mobile healthcare platform in Kenya (17 million records). Sensitive intelligence data was also allegedly offered for sale by the actor jrintel.

Significant activity in Initial Access sales was observed, with threat actors offering unauthorized administrative access to websites and networks in Italy, India, Lithuania, and a Brazilian police system. Defacement attacks primarily targeted websites in the Middle East and South Asia.

These incidents collectively demonstrate that organizations across various industries and geographies face persistent threats from data exfiltration, ransomware, unauthorized network access, and the proliferation of malicious tools like the compact web-shell system offered by DieNet.