[November-14-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. BROTHERHOOD CAPUNG INDONESIA targets the website of Children of Life
  • Category: Defacement
  • Content: The group claims to have defaced these domains: weezy.childrenoflife.top, up.childrenoflife.top, test.childrenoflife.top, new.childrenoflife.top, last.childrenoflife.top, inv.childrenoflife.top, badran.childrenoflife.top, 30.childrenoflife.top, 2023.childrenoflife.top.
  • Date: 2025-11-14T22:04:22Z
  • Network: openweb
  • Published URL: (https://defacer.id/mirror/id/209663)
  • Screenshots:
  • Threat Actors: BROTHERHOOD CAPUNG INDONESIA
  • Victim Country: India
  • Victim Industry: Non-profit & Social Organizations
  • Victim Organization: children of life
  • Victim Site: weezy.childrenoflife.top
  1. Eakas Corporation falls victim to INC RANSOM Ransomware
  1. Killingly High School falls victim to SAFEPAY Ransomware
  1. Sol Trading falls victim to Qilin Ransomware
  1. Payouts King Ransomware group adds an unknown victim (a****.com)
  1. Alleged sale of China ID cards
  1. dream hack targets the website of Sureman Financial Services Private Limited.
  1. Alleged data breach of Platinum Healthcare Staffing
  1. dream hack targets the website of Wealth Creators Private Limited
  1. Alleged data breach of Jefferson Enterprises , LLC
  1. 911Team targets the website of AMPRO BIO
  1. Alleged data breach of UNOde50
  1. Alleged data breach of Herman & Chamow
  1. Alleged sale of unauthorized admin access to an unidentified Swedish Magento shop
  1. 404 crew cyber team targets the website of AIRVISION INFINITY
  1. Alleged data breach of National Council of Municipal Health Secretariats (Brazil)
  1. XmrAnonye.id targets the website of MTs NEGERI 4 BOJONEGORO
  1. dream hack targets the website of Fintech Wealth
  1. Alleged data breach of BMW India
  1. Alleged data breach of Kaener Personal
  1. dream hack targets the website of Triangle Wealth
  1. dream hack targets the website of Ramah Finserv Private Limited
  1. Alleged data breach of Millicom
  1. Barbizon Lighting Company falls victim to Akira Ransomware
  1. Banyumas cyber team targets the website of Banyumas Regency government
  1. Alleged sale of a 1-day exploit for SAP NetWeaver
  1. Alleged sale of a 1-day exploit for multiple Microsoft Windows Server versions
  1. Alleged Sale of 72 Million Japan Citizen’s Data
  1. Alleged sale of unauthorized admin access to an unidentified US Magento shop
  1. Trigg Labs falls victim to Qilin Ransomware
  1. Alleged sale of unauthorized RDWeb access to an unidentified Canadian organization
  1. Alleged sale of medical records from USA
  1. RSVP falls victim to PLAY ransomware
  1. Alleged sale of F-16 fighter jet documentation
  1. B&K Precision Corporation falls victim to PLAY ransomware
  1. Alleged data breach of Franklin County Engineer’s Office
  1. Valley Plains Equipment falls victim to PLAY ransomware
  1. J00Nz targets the website of Fountain University Islamic Cooperative Investment and Credit Society
  1. 404 crew cyber team targets the website of Wesley Stoss
  1. Aero Precision, LLC falls victim to Akira Ransomware
  1. Alleged leak of login access of Cambodia Asia Bank
  1. Valley Bank falls victim to Akira Ransomware
  1. NULLSEC PHILIPPINES targets the website of DENR Forest Management Bureau
  1. NULLSEC PHILIPPINES targets the website of Province of Laguna Employment and Information System
  1. Alleged sale of unauthorized access to unidentified oraginsation in multiple countries
  1. CYBER TEAM INDONESIA targets the website of LATEEFAH MODUPEOLA OKUNNU FOUNDATION
  1. A-B Communications falls victim to akira ransomware
  1. BROTHERHOOD CAPUNG INDONESIA targets the website of AVC Marketing Agency
  1. Alleged database sale of Eurofiber Cloud Infra
  1. BROTHERHOOD CAPUNG INDONESIA targets the website of Lankava luxe
  1. BROTHERHOOD CAPUNG INDONESIA targets the websites of World Cup Betting Entrance (China) Co., Ltd.
  1. Alleged Sale of Romanian Database
  1. BROTHERHOOD CAPUNG INDONESIA targets the website of Pexus Digital
  1. 7 Proxies targets the website of Certificate/Authentication Management System, Karnaphuli Upazila
  1. 404 crew cyber team targets the website of University of the Republic
  1. BROTHERHOOD CAPUNG INDONESIA targets the website of gampahaapi.lk
  1. Kaan Cronenberg & Partner Rechtsanwälte GmbH falls victim to INC RANSOM Ransomware
  1. BROTHERHOOD CAPUNG INDONESIA targets the websites of hoopoedesign.lk
  1. BROTHERHOOD CAPUNG INDONESIA targets the websites of hmjtraders.lk
  1. BROTHERHOOD CAPUNG INDONESIA targets the websites of jworld.lk
  1. TEAM BD CYBER NINJA targets the website of Imprenta Sevilla
  1. TEAM BD CYBER NINJA targets the website of Radius Beauty Clinic Fukuoka
  1. 404 crew cyber team targets the website of Easy Tour Brazil
  1. TEAM BD CYBER NINJA targets the website of Hunde-Versandhaus
  1. 404 crew cyber team targets the website of Easy Tour Brazil
  1. lxrdk1773n targets the website of Halal India PVT LTD.
  1. Swiss Rose Company falls victim to Nova Ransomware
  1. Alleged data breach of Excel Educational Institution
  1. Bali Blackhat targets the website of International Union of Radioecology (IUR)
  1. Bali Blackhat targets the website of Institute of Innovative Development and Technology
  1. Alleged unauthorized access to Elikatni Products checkout system
  1. Alleged unauthorized access to unidentified control system of a hydroelectric power plant in France
  1. Alleged leak of Instagram usernames
  1. Barnhart Group falls victim to akira ransomware
  • Category: Ransomware
  • Content: The group claims to have obtained the organization’s corporate data. The compromised data includes financial data such as audit, payment details, invoices, detailed employees and customers information, Passports, driver’s license, Social Security Numbers, medical information, emails, phones, confidential information, NDAs and other documents with detailed personal information.
  • Date: 2025-11-14T11:05:10Z
  • Network: tor
  • Published URL: (https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion/)
  • Screenshots:
  • Threat Actors: akira
  • Victim Country: USA
  • Victim Industry: Transportation & Logistics
  • Victim Organization: barnhart group inc.
  • Victim Site: barnhartinc.com
  1. Alleged leak of login access of ROYAL CAMBODIAN ARMY
  1. Waukegan Steel falls victim to Akira ransomware
  • Category: Ransomware
  • Content: The group claims to have obtained 15GB of corporate data from Waukegan Steel, including scanned personal documents such as passports, Social Security numbers, driver’s licenses, W-9 forms, and other identity records, as well as project information, NDAs, contracts and agreements, financial documents, client information, drawings of ongoing projects, and additional sensitive corporate files.
  • Date: 2025-11-14T11:03:06Z
  • Network: tor
  • Published URL: (https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion/)
  • Screenshots:
  • Threat Actors: akira
  • Victim Country: USA
  • Victim Industry: Manufacturing
  • Victim Organization: waukegan steel
  • Victim Site: waukegansteel.com
  1. Bali Blackhat targets the website of FINMONITOR
  1. General Micro Systems falls victim to Akira ransomware
  1. Basin Harbor falls victim to akira ransomware
  1. Sarcoma ransomware group has added an unidentified victim
  1. Z-BL4CX-H4T targets the website of ARAS GROUP
  1. Alleged data sale of CoinMarketCap
  1. Alleged data breach of American Public University System
  1. Alleged data leak of Airlines from India
  1. The Foot Doctor, P.C. falls victim to Space Bears Ransomware
  1. Alleged sale of unauthorized vpn access in Singapore
  1. Alleged sale of unauthorized access to unidentified shop in Greece
  1. Alleged data breach of General Department of Immigration (GDI)
  1. Alleged leak of Login access of General Department of Immigration (GDI)
  1. Alleged data breach of AIESEC Canada
  1. Alleged data leak of ALRO Online Land Management System
  1. Alleged leak of Login access of Digital Research Information Center
  1. Metropolitan Adjustment Bureau falls victim to CHAOS Ransomware
  1. Alleged leak of admin access of JBSofts
  1. Rosemont Exposition Services, Inc. falls victim to INC RANSOM Ransomware
  1. Actor LEAKS DATABASE CYBER TEAM INDONESIA targets the website of Lateefah Modupeola Okunnu Foundation (LMOF)
  1. Grinding and Dicing Services Inc falls victim to INC RANSOM Ransomware
  1. Dubois Wood Products, Inc. falls victim to INC RANSOM Ransomware
  1. Facade Innovations Pty Ltd falls victim to INC RANSOM Ransomware
  1. Kelly Legal falls victim to INC RANSOM Ransomware
  1. Northcroft Middle East LLC falls victim to INC RANSOM Ransomware
  1. ANG BROTHERS (M&E) PTE. LTD. falls victim to Nova Ransomware

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats, strictly based on the provided data. Ransomware attacks are frequent, notably involving groups like INC RANSOM, akira, and PLAY, targeting various sectors globally, from Automotive and Education to Manufacturing and Financial Services. There is also significant activity in Data Breach incidents, with claims ranging from the leakage of individual customer and citizen records in countries like China, Japan, and Romania, to the alleged sale of large-scale databases from organizations in Telecommunications (Millicom) and Information Services (CoinMarketCap). Furthermore, the trade in Initial Access remains active, with threat actors claiming to sell network access to organizations in countries like Sweden, Canada, Cambodia, and access to critical systems, including a hydroelectric power plant in France. The prevalence of Defacement against websites in India, Sri Lanka, and Indonesia underscores the widespread nature of hacktivism and less-sophisticated attacks. Finally, the alleged sale of malware, including exploits for major platforms like SAP NetWeaver and Microsoft Windows Server, indicates the continued proliferation of offensive capabilities. The collection of these events demonstrates persistent and varied cyber risks across numerous industries and geographies.