[November-25-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.

1. Alleged sale of unauthorized access to an unidentified IT company in Germany

2. Alleged Unauthorized Admin Access to Bayleaf Indian Restaurant

3. Kids & Company falls victim to Sinobi Ransomware

4. Money Mart falls victim to Everest Ransomware

5. Alleged Data Breach of DCDC Kidney Care

6. Columbia Medical Practice falls victim to Qilin Ransomware

7. Lake Superior State University falls victim to Qilin Ransomware

8. Paal falls victim to Qilin Ransomware

9. Inspire Communities falls victim to Qilin Ransomware

10. New England Tractor Trailer Training School falls victim to Qilin Ransomware

11. Christofle falls victim to Qilin Ransomware

12. Rochester Philharmonic Orchestra falls victim to Akira Ransomware

13. Alleged leak of login credentials of bitcoin

14. Cyber Islamic resistance-Axis claims to target Netivot Moshe schools

15. Iberia Airlines falls victim to Everest Ransomware

16. Alleged data breach of Police Tenant & Registration System Data OF Pakistan sindh

  • Category: Data Breach
  • Content: group claims to have leaked 5 GB of Data from Police Tenant & Registration System Data OF Pakistan Sindh. The compromised data reportedly includes officials name, identity card number, phone number, district, police station name, family members info, home address etc.
  • Date: 2025-11-25T16:39:05Z
  • Network: telegram
  • Published URL: https://t.me/IndianCyberForceTG/25
  • Screenshots:
  • Threat Actors: INDIAN CYBER FORCE
  • Victim Country: Pakistan
  • Victim Industry: Government Administration
  • Victim Organization: police tenant & registration system data of pakistan sindh
  • Victim Site: sindhpolice.gov.pk

17. INDIAN CYBER FORCE targets the website of University of Balochistan

18. Alleged data leak of TIM Brasil

  • Category: Data Breach
  • Content: The group claims to have leaked 32,138 database of TIM Brasil. The compromised data includes tdoc,doc,name,tp_log,lograd,number, compl,neighborhood, city,state, zipcode, area code, phone,operator etc
  • Date: 2025-11-25T14:22:37Z
  • Network: telegram
  • Published URL: https://t.me/c/3211040888/3
  • Screenshots:
  • Threat Actors: Chronus leaks
  • Victim Country: Brazil
  • Victim Industry: Network & Telecommunications
  • Victim Organization: tim brasil
  • Victim Site: tim.com.br

19. Alleged shell access to S2O Care Services

20. Alleged shell access to Al Hakeem International Contracting

  • Category: Initial Access
  • Content: The group claims to have unauthorized access to Al Hakeem International Contracting.NB: The authenticity of the post is yet to be verified.
  • Date: 2025-11-25T13:54:35Z
  • Network: telegram
  • Published URL: https://t.me/c/2758066065/362
  • Screenshots:
  • Threat Actors: HellR00ters Team
  • Victim Country: UAE
  • Victim Industry: Building and construction
  • Victim Organization: al hakeem international contracting
  • Victim Site: alhakeemcont.com

21. Nullsec Philippines targets the website of DILG Philippines

22. Alleged sale of access to Metal Design Inc Arts

23. Cryo Pur falls victim to INC RANSOM Ransomware

24. Alleged sale of access to Jelly Bean Learning Center

25. Alleged sale of webShell access to Government of Penajam Paser Utara Regency PPID

26. Alleged data breach of CIFP Los Gladiolos

  • Category: Data Breach
  • Content: The group claims to be leaked database of CIFP Los Gladiolos, compromised data contains Full name of the minor, Contact email address, etc.NB: Data leak by L0stex x Nayid
  • Date: 2025-11-25T13:15:31Z
  • Network: telegram
  • Published URL: https://t.me/c/3211040888/9
  • Screenshots:
  • Threat Actors: Chronus leaks
  • Victim Country: Spain
  • Victim Industry: Education
  • Victim Organization: cifp los gladiolos
  • Victim Site: losgladiolos.es

27. Alleged data breach of Government of Paraguay

  • Category: Data Breach
  • Content: The group claims to be leaked 1.52 GB database of Government of Paraguay, compromised data contains full name, age, diseases, date of birth, ID number, number, etc.
  • Date: 2025-11-25T13:03:43Z
  • Network: telegram
  • Published URL: https://t.me/c/3211040888/14
  • Screenshots:
  • Threat Actors: Chronus leaks
  • Victim Country: Paraguay
  • Victim Industry: Government Administration
  • Victim Organization: government of paraguay
  • Victim Site: paraguay.gov.py

28. Payouts King Ransomware group adds an unknown victim (V****l)

29. Alleged sale of webShell access to DPMPTSP Garut Regency

30. Alleged data breach of Declaranet

31. Chronus leaks targets the website of Gobierno De Coahuila

32. Schmidt’s Naturals falls victim to INC RANSOM Ransomware

33. KingSkrupellos targets the website of Ministry of Environment and Sustainable Development of Colombia

34. scattered LAPSUS$ hunters 7.0 claims to target Falconfeeds.io

35. Standing Chapter 13 Trustee District of Minnesota falls victim to Akira Ransomware

36. Rempe Construction falls victim to Sinobi Ransomware

37. Order-403 targets the website of YouCan

38. NONC falls victim to NightSpire Ransomware

39. Alleged unauthorized access to an industrial SCADA system in Spain

  • Category: Initial Access
  • Content: The group claims to have accessed the SCADA system of a water filtration facility in Spain, reportedly gaining control of pumps, filters, operating parameters, emergency settings, and admin access, allowing them to change passwords, alter runtimes, trigger shutdowns, disable alerts, and view resulting alarms.
  • Date: 2025-11-25T10:34:01Z
  • Network: telegram
  • Published URL: https://t.me/c/2787466017/654
  • Screenshots:
  • Threat Actors: NoName057(16)
  • Victim Country: Spain
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

40. D4LGH4CK_TM targets the website of JPL

41. Balkrishna Paper Mills Limited falls victim to NightSpire Ransomware

42. LAMAICA falls victim to NightSpire Ransomware

43. Alleged data breach of Cool Bangalore News

44. KingSkrupellos targets the website of Institute of Geological and Energy Research

45. KingSkrupellos targets the website of OAP agro

46. KingSkrupellos targets the website of Dirección Provincial de Vialidad de Entre Ríos.

47. KingSkrupellos targets the website of Municipalidad de Gral. San Martín

48. KingSkrupellos targets the website of Geoportal de San Carlos en mapas

49. KingSkrupellos targets the website of COPECO

50. KingSkrupellos targets the website of National Institute of Meteorology and Hydrology of Ecuador

51. KingSkrupellos targets the website of Asociación de Municipalidades Ecuatorianas

52. KingSkrupellos targets the website of Công Bố Dữ Liệu Viễn Thám

53. Alleged leak of admin login access to Udonpichairakpittaya School

54. StatMedPlus LLC falls victim to Sinobi Ransomware

55. Red wolf cyber claims to target Morocco and Algeria

56. KingSkrupellos targets the website of Government of the Province of Buenos Aires

57. scattered LAPSUS$ hunters 7.0 promoting ransomware

58. Alleged Data Breach of Maxon Computer

59. Alleged leak of admin login access to Blue Elephant Thailand Tours

60. Alleged Data Leak of Maxon.net

61. BABAYO EROR SYSTEM targets the website of Peeks Printing

62. Alleged data breach of Cred Auto Network

63. Zecher GmbH falls victim to Qilin Ransomware

64. BABAYO EROR SYSTEM targets the website of AIS Radio

65. Blue Projects falls victim to Qilin Ransomware

66. BABAYO EROR SYSTEM targets the website of Furbly

67. Nottingham Village falls victim to Qilin Ransomware

68. Alleged leak of malicious JavaScript exploit source code

69. Alleged leak of admin login access to YOORI-SpaGreen Creative

70. Alleged leak of admin login access to 24×7 Parcels

71. scattered LAPSUS$ hunters 7.0 claims to target National Security Agency

72. Alleged data breach of Amcor

73. Alleged Data Sale of My Monster Labs

74. Alleged Data Leak of 1.3 Billion Chinese Citizens Database

  • Category: Data Breach
  • Content: Threat Actor claims to have leaked 1.3 Billion records of Chinese Citizens Database which includes full name, gender, date of birth, citizen ID number, registered address, province, city, and district, phone number, last login IP, device IMEI or MAC address, real-name verification status, and face recognition result.
  • Date: 2025-11-25T02:28:53Z
  • Network: openweb
  • Published URL: https://leakbase.la/threads/big-leaks.46488/
  • Screenshots:
  • Threat Actors: hackoozz
  • Victim Country: China
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

75. Alleged Data Breach of 900 Million SSN Records in USA

76. Commercial WR falls victim to MEDUSA Ransomware

77. Alleged Data Breach of 850 Million HI-TEK’s Citizen Database in India

78. Alleged Data Breach of 608 MILLION CITIZEN CNIC NADRA DATABASE in Pakistan

79. Infrastructure Destruction Squad claims to target USA

80. Infrastructure Destruction Squad claims to target India

81. Alleged Data Leak of 608 MILLION CITIZEN CNIC NADRA DATABASE in Pakistan

82. Municipal University of Sao Caetano do Sul (USCS) falls victim to MEDUSA Ransomware

Conclusion The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Ransomware attacks are particularly prominent, with major groups like Qilin, Everest, and Sinobi targeting sectors ranging from education and healthcare to manufacturing and real estate across countries like the USA, Canada, Germany, and France. Data breaches and leaks remain a critical issue, with massive alleged exposures involving citizen databases in China, the USA, India, and Pakistan. Beyond data compromise, the report reveals significant activity in initial access sales and website defacements, affecting government bodies and private enterprises globally. The wide geographic spread—spanning North and South America, Europe, Asia, and the Middle East—demonstrates that organizations across all industries face persistent threats from sophisticated actors and opportunistic attacks. The nature of these incidents emphasizes the critical importance of robust cybersecurity measures, including strong access controls, data protection strategies, continuous vulnerability management, and proactive threat intelligence.