[November-17-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Alleged Data Breach of Robinhood Markets

  1. Alleged Data Breach of Bybit

  1. Alleged Data Breach of Japan Financial Investment Education Association

  1. Alleged Data Breach of Internal Revenue Service

  1. Alleged Data Breach of BitBox

  1. Alleged Data Breach of Uttar Pradesh Power Corporation Limited (UPPCL)

  1. Alleged Data Breach of Robinhood Markets, Inc

  1. Alleged Data Breach of Brsk ISP Limited

  1. Alleged Sale of USA citizens Data

  1. Air Design Systems, Inc. falls victim to Sinobi Ransomware

  1. Alleged data breach of Silver Falcon Group

  1. LincolnIT falls victim to Sinobi Ransomware

  1. H.G. Reynolds Company falls victim to Sinobi Ransomware

  1. KDR Real Estate Svc falls victim to Qilin Ransomware

  1. Alleged sale of unauthorized access to an online store in UK

  1. Alleged unauthorized sale of E-Commerce admin panel with credit card payment access

  1. Alleged data breach of die.co.il

  1. Alleged Sale of Microsoft-Signed Vulnerable Driver Capable of Disabling EDR/XDR Systems

  1. Alleged data breach of Physiothletics

  1. Alleged data breach of liatgallery.co.il

  1. Alleged unauthorized RDP access to U.S. Healthcare Networks

  1. Payouts King Ransomware group adds an unknown victim(l****.com)

  1. Alleged data breach of clipim.co.il

  1. Alleged data breach of Mishan

  1. Alleged data breach of Qprint Digital

  1. Alleged sale of credit cards from various European Countries

  1. Poe’s Accounting Services falls victim to PEAR Ransomware

  1. Quinn Jay Patent falls victim to PEAR Ransomware

  1. Law Office of Ronald W. Hillberg falls victim to PEAR Ransomware

  1. Alleged leak of admin access to Khalifa International Award for Date Palm and Agricultural Innovation (KIAAI) website

  1. Alleged unauthorized access to Al Ain University

  1. Charles Rutenberg Realty Inc. falls victim to Akira Ransomware
  • Category: Ransomware
  • Content: The group claims to have obtained 91GB of organization’s data. The compromised data includes many personal docs (more than 1,5gb of just scanned docs), (passports, driver licenses, SSNs, phones, addresses, email addresses, credit card details, employee headshots), financials, contracts and agreements, NDA, clients’ information, projects, etc.
  • Date: 2025-11-17T17:03:46Z
  • Network: tor
  • Published URL: (https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion/)
  • Screenshots: https://d34iuop8pidsy8.cloudfront.net/ba85c100-d8aa-4ef6-97c8-b5a4ad883086.png
  • Threat Actors: akira
  • Victim Country: USA
  • Victim Industry: Real Estate
  • Victim Organization: charles rutenberg realty inc.
  • Victim Site: charlesrutenberginc.com

  1. Alleged sale of unauthorized access to an unidentified retail company in Germany

  1. Alleged leak of login credentials from UNIQLO

  1. Alleged Sale of 6,000 Fortinet VPN Network Accesses

  1. jokeir 07x claims to target UAE

  1. Alleged Sale of 3,000 Fortinet VPN Network Accesses

  1. ARH Associates, Inc. falls victim to Akira Ransomware

  1. Petrobras falls victim to Everest Ransomware

  1. UNDER ARMOUR falls victim to Everest Ransomware

  1. Alleged sale of RDweb access to an unidentified Organization in UK

  1. Eagle Oil & Gas, LLC falls victim to Akira Ransomware

  1. LG Energy Solution falls victim to Akira Ransomware
  • Category: Ransomware
  • Content: The group claims to have obtained 1.67 TB of organization’s data. The compromised data includes employee personal information (visas, US and Korean passports, medical documents, Korean ID cards, addresses, phones, emails and so on), confidential projects, NDAs, confidentiality agreements, detailed financials, information about clients and partners, lots of contracts, etc.
  • Date: 2025-11-17T14:42:46Z
  • Network: tor
  • Published URL: (https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion/)
  • Screenshots: https://d34iuop8pidsy8.cloudfront.net/40f54791-d270-4195-a953-bbfe0b0906c8.png
  • Threat Actors: akira
  • Victim Country: South Korea
  • Victim Industry: Chemical Manufacturing
  • Victim Organization: lg energy solution
  • Victim Site: lgensol.com

  1. Alleged data breach of ADNOC Group
  • Category: Data Breach
  • Content: The group claims to have compromised the ADNOC website and obtained the VPN access and exfiltrated sensitive internal data, including email addresses, usernames, passwords, files, and operational plans.
  • Date: 2025-11-17T14:26:36Z
  • Network: telegram
  • Published URL: (https://t.me/LulzS1/3)
  • Screenshots: https://d34iuop8pidsy8.cloudfront.net/f2d6ae03-a8ba-43ef-81c7-50cd0c4ada3b.png
  • Threat Actors: LulzSec Hackers
  • Victim Country: UAE
  • Victim Industry: Oil & Gas
  • Victim Organization: adnoc group
  • Victim Site: adnoc.ae

  1. AkroStar falls victim to The Gentlemen Ransomware

  1. UNDERGROUND-NET targets the website of Bilkent University

  1. Pharaoh’s Team targets the website of Haraj Syria

  1. The Gentlemen Ransomware group adds an unknown victim (A***-****.com)

  1. HellR00ters Team targets the website of Journal of Buddhist Educational Administration

  1. MOBI falls victim to Akira Ransomware

  1. Bold+ falls victim to Akira Ransomware

  1. Alleged data breach of an unidentified Germany organization

  1. NOT-CTBER targets the website of ThinkView

  1. Alleged sale of access to an unidentified Casino gaming company

  1. DEVMAN 2.0 ransomware group adds an unknown victim (****clinic.com.**)

  1. Alleged data breach of PT Brantas Abipraya Persero

  1. TRUTH LEGION 707 targets the website of Top Clinique

  1. Alleged leak of Moroccan citizens database

  1. Youngster Nepal targets the website of CG Electronics

  1. Alleged Data Leak of Malwarebytes Forum User Records

  1. Alleged sale of unauthorized access to an unidentified shop in USA

  1. Alleged data leak of Japan Advance Create Insurance Product

  1. Alleged data breach of Information Communication Board (ICB SCAC)

  1. Alleged data leak of Russian Tupolev Tu-160

  1. Alleged Data Leak of Advance Create Co., Ltd..

  1. Alleged Data Leak of Hoken Ichiba Information Services Ltd.

  1. Alleged data breach of District One Medical Examiner Support, Inc. (D1MEO)

  1. Lotus Powergear Pvt Ltd., falls victim to NightSpire

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Data breaches and leaks are prominent, affecting various sectors from Financial Services, Education, and Healthcare to E-commerce, Oil & Gas, and Building and construction, and impacting countries including USA, Japan, Switzerland, India, UK, UAE, Israel, Brazil, South Korea, China, Turkey, Syria, Thailand, Vietnam, Morocco, Nepal, and Russia. The compromised data ranges from customer records, personal user information, and financial details to confidential operational documents, government records, and classified technical data. Beyond data compromise, the report also reveals significant activity in Initial Access sales, with threat actors offering unauthorized access to E-commerce sites, healthcare networks, corporate VPNs (Fortinet), and an unidentified casino gaming company. The proliferation of Ransomware attacks by groups like Sinobi, Qilin, PEAR, Payouts King, Akira, Everest, The Gentlemen, and DEVMAN 2.0 targeting industries like Real Estate, Accounting, Legal Services, and Manufacturing further underscores the constant threat landscape. The inclusion of Malware (vulnerable driver) and Defacement activities targeting various websites demonstrates the wide array of malicious capabilities available in the cyber underground. The incidents collectively demonstrate that organizations across various industries and geographies face persistent threats from data exfiltration, unauthorized network access, and the proliferation of malicious tools. The nature of these incidents emphasizes the critical importance of robust cybersecurity measures, including strong access controls, data protection strategies, continuous vulnerability management, and proactive threat intelligence to defend against a wide array of sophisticated and opportunistic attacks.