[November-12-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Alleged data breach of ESPORT
  • Category: Data Breach
  • Content: The threat actor claims to be selling a database dump from esport.gov.kz (Kazakhstan’s e-sports authority) containing 286,000 records. The compromised fields reportedly include 12-digit national ID (IIN), full name, date of birth, ethnicity, region (province/city), role (athlete/coach), sport discipline, phone number, and email.
  • Date: 2025-11-12T23:14:32Z
  • Network: openweb
  • Published URL: (https://darkforums.st/Thread-DATABASE-kz-leak-esport-gov-kz-280k)
  • Screenshots:
  • Threat Actors: dump5ter
  • Victim Country: Kazakhstan
  • Victim Industry: Government Administration
  • Victim Organization: esport
  • Victim Site: esport.gov.kz

  1. Alleged data breach of GoldenGate Technolabs

  1. Alleged sale of admin access to an unidentified consulting company in Pakistan

  1. Alleged leak of admin access of Satun College of Agriculture and Technology

  1. Alleged data sale of Israeli Air system

  1. Alleged sale of unauthorized access to an unidentified organization in Spain

  1. Alleged sale of admin access to an unidentified store in Spain

  1. Alleged leak of admin access to Tuf pak Sports

  1. Legion targets the website of Artrans Mass Enthusiasm

  1. ICON International, Inc. falls victim to CHAOS Ransomware

  1. Alleged sale of admin access to an unidentified telecommunication Company in Germany

  1. Alleged data breach of NOWNodes

  1. Dover Area School District falls victim to SAFEPAY Ransomware

  1. Glendale Obstetrics and Gynecology falls victim to SAFEPAY Ransomware

  1. BABAYO EROR SYSTEM targets the website of Billerica family dental

  1. Alleged data breach of Leboncoin

  1. Alleged data sale of Local Place Database

  1. Alleged data sale of Taiwan Cyber security department

  1. Alleged sale of access to an unidentified organization in USA

  1. Alleged data sale of River

  1. Alleged sale of documents related to cybersecurity department of Taiwan

  1. Alleged sale of admin access to an unidentified store in Spain

  1. Alleged sale of admin access to an unidentified store in France

  1. PARANOIDSQUAD targets the website indianshooting.com

  1. Alleged unauthorized admin panel access to Armed Forces Medical Science Research Institute

  1. lxrdk1773n targets the website of Mahasarakham University Thailand

  1. City of Znojmo falls victim to INC RANSOM Ransomware

  1. LatamLex Abogados falls victim to INC RANSOM Ransomware

  1. Alleged leak of login access to Nakhon Ratchasima Rajabhat University

  1. BRIDGE Housing Corporation falls victim to INC RANSOM Ransomware

  1. Alleged leak of login access of Theos Seminary

  1. Alleged unauthorized access to Chiang Rai Rajabhat University

  1. Galileo Financial Technologies, LLC falls victim to INC RANSOM Ransomware

  1. Grupo Vía falls victim to INC RANSOM Ransomware

  1. Alleged leak of login access of ThreeNow

  1. Forensic Medical Management Services PLC falls victim to INC RANSOM Ransomware

  1. Koha Foods falls victim to INC RANSOM Ransomware

  1. Kxichixxsec targets the website of Nakhonratchasima Provincial Industrial Office

  1. Vennerhus Weine AG falls victim to RansomHouse Ransomware

  1. Alleged unauthorized access to mis.thachanapalmoil.co.th

  1. lxrdk1773n targets the websites of Samut Prakan Hospital

  1. Alleged leak of login access of Thrustmaster

  1. Alleged leak of login access to KidDiary

  1. Alleged Unauthorized Access to Department of Livestock Development

  1. Alleged leak of login access to Chaiyaphum Rajabhat University

  1. Alleged leak of login access of Electronic Document Management System, Royal Thai Army

  1. Alleged data sale of COSMOTE

  1. Alleged data breach of Taos Leather

  1. lxrdk1773n targets the websites of ITSMYMART Synergy Private Limited

  1. lxrdk1773n targets the websites of WideCare

  1. lxrdk1773n targets the websites of Shri Rukmani Dwarkadhish University of Science and Technology

  1. lxrdk1773n targets the websites of Event Pillow Private Limited

  1. lxrdk1773n targets the websites of Admissionwala® Education Technologies Private Limited

  1. Alleged unauthorized CCTV Access to multiple Thailand domains

  1. General Distributing Company falls victim to MEDUSA Ransomware

  1. lxrdk1773n targets the websites of Dadi Institute of Engineering & Technology (DIET)

  1. lxrdk1773n targets the websites of Al-Falah University

  1. Treetop Companies falls victim to Akira ransomware

  1. Forest Science and Technology Center of Catalonia falls victim to DEVMAN 2.0 Ransomware

  1. Asahi Kasei Microdevices Corporation falls victim to CRYPTO24 Ransomware

  1. Alleged data sale of CCWBET

  1. Alleged sale of admin access to Rata.id

  1. Alleged data sale of the Ministry of Parliamentary Affairs and Governance, Guyana

  1. Alleged leak of unauthorized access to RabbitMQ

  1. Alleged leak of Russian Ministry of Defense C-70 UCAV Documents

  1. Alleged Data sale of Mediterranean Shipping Company

  1. title Alleged data breach of Tuxum Secure Systems

  1. Alleged Unauthorized Access to Cox Communications Operational Systems

  1. Alleged data breach of Computer Society of India
  • Category: Data Breach
  • Content: The group claims to have leaked an internal database from the Computer Society of India (CSI).Note: Computer Society of India was previously breached on May 06, 2025.
  • Date: 2025-11-12T02:45:11Z
  • Network: telegram
  • Published URL: (https://t.me/c/2326263047/543)
  • Screenshots:
  • Threat Actors: LEAKS DATABASE CYBER TEAM INDONESIA
  • Victim Country: India
  • Victim Industry: Non-profit & Social Organizations
  • Victim Organization: computer society of india
  • Victim Site: csi-india.org

  1. PT Wiraswasta Gemilang Indonesia falls victim to INC RANSOM Ransomware

  1. Alleged sale of Multi-X Cracked v1.5
  • Category: Malware
  • Content: A threat actor is allegedly distributing Multi-X Cracked v1.5, a multi-tool launcher that consolidates various checkers, parsers, and quick-run utilities into a single interface. The tool provides one-click access to modules targeting platforms such as Netflix, Fortnite, Steam, Spotify, eBay, Instagram, and PSN.Its centralized UI allows users to launch, log, and compare results from different modules quickly, offering exportable summaries and consistent workflows. While marketed for convenience, the toolkit’s structure and included modules suggest potential use in credential validation, automation, and data-parsing activities across multiple platforms.
  • Date: 2025-11-12T00:07:42Z
  • Network: openweb
  • Published URL: (https://demonforums.net/Thread-Multi-X-Cracked-v1-5)
  • Screenshots:
  • Threat Actors: Starip
  • Victim Country: Unknown
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Data Breaches and Initial Access sales are prominent, impacting sectors from Government Administration and Information Technology (IT) Services to Education, Financial Services, and Hospital & Health Care across numerous countries, with a notable concentration in the USA, Thailand, and India.

The nature of the compromised data is extensive, including national IDs, personal information, customer databases, source code, classified military documents, and unauthorized administrative access to critical systems like ticketing portals and telecommunication infrastructure.

The recurring themes of ransomware attacks (e.g., CHAOS, SAFEPAY, INC RANSOM, MEDUSA, CRYPTO24, akira, DEVMAN 2.0, RansomHouse), defacements (often by lxrdk1773n and Kxichixxsec), and the trade of initial access point to persistent threats. Organizations across various industries and geographies face continuous risks from data exfiltration, unauthorized network access, and the availability of malicious tools like Multi-X Cracked v1.5, underscoring the critical need for robust cybersecurity measures.