[October-27-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. France Travail falls victim to STORMOUS ransomware

  1. Alleged sale of unauthorized access to Americana de Colchones

  1. Alleged sale of unauthorized admin access to an unidentified e-commerce shop in Italy

  1. Alleged sale of Israeli Phone Numbers

  1. Alleged data breach of Dhaka Water Supply & Sewerage Authority

  1. Alleged data breach of University of Tlemcen

  1. Navigator Business Solutions falls victim to LYNX ransomware

  1. Trojan General Contracting LLC falls victim to Black Nevas ransomware

  1. Alleged sale of VPN access to Canadian automotive service company

  1. Alleged sale of unauthorized RDP access to German IT and Consumer Services companies

  1. MedImpact Healthcare Systems, Inc falls victim to Qilin ransomware

  1. Unique Data Center falls victim to Sinobi ransomware

  1. Luis Garratón, LLC falls victim to Sinobi ransomware

  1. SanDiego Automotive Museum falls victim to Sinobi ransomware

  1. Alleged data leak of Okaz

  1. Zulfiqar Electronic Brigade targets the website of The Heritage Portal of Imam Al-Albani

  1. Glawitsch Sutter Rechtsanwälte GmbH. falls victim to Sinobi ransomware

  1. Alleged sale of life insurance data from USA

  1. Cavalry Consulting LLC falls victim to Sinobi ransomware

  1. Zulfiqar Electronic Brigade targets the website of Aqeedah Association

  1. Alleged sale of unauthorized VPN and domain access to unidentified Indonesian aviation and logistics firms

  1. Double Oak Construction, Inc falls victim to Qilin ransomware

  1. Izaki Group Investments falls victim to Qilin ransomware

  1. Henrietta Ezeoke Law Firm falls victim to Qilin ransomware

  1. Alleged Data Leak of Oz Aviation Ltd

  1. Micke Stridh Maskin falls

  1. Tim Hortons UK & Ireland Ltd. falls victim to Akira ransomware

  1. Alleged unauthorized access to usa bms system

  1. Alleged data breach of SymbolTransport

  1. Alleged sale of Mexican bank debtors database

  1. Domy falls victim to Qilin ransomware

  1. Engineered Profiles LLC falls victim to akira ransomware

  1. Maki Building Centers victim falls victim to INTERLOCK Ransomware

  1. Alleged sale of unauthorized WHMCS access to unidentified organizations

  1. MotorsportMarkt.de falls victim to Everest Ransomware

  1. Ania Kruk falls victim to Everest Ransomware

  1. NCT [NTB CYBER TEAM] targets multiple Japanese websites

  1. Alleged unauthorized access to unidentified Hajj and Umrah company management system in Saudi Arabia

  1. ToxicJ claims to target Israel

  1. Alleged unauthorized access to Suphan Buri Provincial Education Office

  1. Miami Management, INC. falls victim to PEAR ransomware

  1. Flegenheimer International falls victim to akira ransomware

  1. Malgor & Co. falls victim to Qilin Ransomware

  1. GeBePro falls victim to BEAST Ransomware

  1. Bolt Group falls victim to BEAST Ransomware

  1. Alleged data breach of Fregat
  • Category: Data Breach
  • Content: The group claims to have leaked the data from Fregat. The compromised data reportedly include users, addresses, phone numbers, and house coordinates and other data.
  • Date: 2025-10-27T08:35:19Z
  • Network: telegram
  • Published URL: https://t.me/perunswaroga/644
  • Screenshots:
  • Threat Actors: Perun Svaroga
  • Victim Country: Ukraine
  • Victim Industry: Information Technology (IT) Services
  • Victim Organization: fregat
  • Victim Site: fregat.com

  1. Alleged leak of USA, China and Vietnam database

  1. Pharaoh’s Team targets multiple websites

  1. Alleged unauthorized login access to Illinois Cremation Centers

  1. Alleged unauthorized login access to American Pistachio Growers

  1. Alleged data breach of Secretaría de Educación Pública (SEP)
  • Category: Data Breach
  • Content: Threat actor claims to have breached data from Secretaría de Educación Pública (SEP). The compromised data includes highly sensitive personal and academic information of scholarship students. Exposed details include unique identifiers such as UID and CURP, full names, dates of birth, gender, nationality, and contact information including email addresses and phone numbers. NB: The organization was previously breached on October 07, 2025 by the same threat actor.
  • Date: 2025-10-27T05:47:18Z
  • Network: openweb
  • Published URL: https://darkforums.st/Thread-DATABASE-450k-SCHOLARSHIP-STUDENTS-DATA-OF-SEP
  • Screenshots:
  • Threat Actors: Alz_157s
  • Victim Country: Mexico
  • Victim Industry: Government Administration
  • Victim Organization: secretaría de educación pública (sep)
  • Victim Site: gob.mx

  1. Alleged leak of Casino User database

  1. Alleged leak of USA Trezor Database

  1. Alleged data breach of Net54Baseball

  1. Alleged Leak of Ledger 2025 DB Orders

  1. Alleged leak of Coinbase database of USA

  1. Meinhardt Group falls victim to CRYPTO24 Ransomware

  1. Alleged leak of USA Forex Database

  1. Pharaoh’s Team targets multiple websites

  1. Bayu Buana Travel Services falls victim to CRYPTO24 Ransomware

  1. Alleged leak of Top Secret RAYETHON LOCKHEED F-15 Document

  1. Farebi inteliigence agency targets the website of United High School

  1. Alleged sale of VPN access to an unidentified organisaton in Malaysia
  • Category: Initial Access
  • Content: The threat actor is offering to sell VPN access to a Malaysian engineering company with approximately 300 employees. The access is reportedly through the organization’s corporate domain via Fortinet VPN, potentially exposing internal systems and confidential project data.
  • Date: 2025-10-27T01:50:44Z
  • Network: openweb
  • Published URL: https://forum.exploit.in/topic/269012/
  • Screenshots:
  • Threat Actors: setvik
  • Victim Country: Malaysia
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged unauthorized access to a unauthorized access to a unidentified system in France

  1. KAL EGY 319 targets the website of Abiya Ceramics

  1. Alleged data breach of SpaceX

  1. D. W. Gould Realty Advisors Inc., Brokerage falls victim to INC RANSOM Ransomware

  1. Partitio falls victim to INC RANSOM Ransomware

  1. Alleged data breach od Irias Informatiemanagement B.V

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats.

Data breaches and leaks are prominent, affecting various sectors from education and gambling & casinos to healthcare and defense & space, and impacting countries including USA, Mexico, Israel, France, and Bangladesh. The compromised data ranges from personal user information and phone numbers to highly sensitive academic data, classified military documents, and large corporate data volumes.

Beyond data compromise, the report also reveals significant activity in initial access sales and ransomware attacks, with threat actors offering unauthorized access to e-commerce platforms, corporate networks (including VPN and RDP access to Canadian, Italian, German, and Indonesian firms), and government systems like the Suphan Buri Provincial Education Office. The prolific use of ransomware groups like Sinobi, Qilin, Akira, Everest, and BEAST further underscores the persistent threat of data theft and disruption.

The nature of these incidents emphasizes the critical importance of robust cybersecurity measures, including strong access controls, data protection strategies, continuous vulnerability management, and proactive threat intelligence to defend against a wide array of sophisticated and opportunistic attacks.