[August-8-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Alleged data breach of Ministry of State Secretariat, Indonesia

  1. Alleged Sale of European Partner Access
  • Category: Initial Access
  • Content: The threat actor claims to be selling full admin access to a large European partner’s online store office. The access reportedly allows replacing payment requests with the buyer’s own details, and includes the user database and CMS. The data was allegedly obtained via SQL, and the admin panel comes with the reported error.
  • Date: 2025-08-08T14:07:14Z
  • Network: openweb
  • Published URL: https://forum.exploit.in/topic/263934/
  • Screenshots:
  • Threat Actors: Forbs
  • Victim Country: Unknown
  • Victim Industry: E-commerce & Online Stores
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged Sale of Mixed Mail Access Data

  1. Alleged data breach of OfficeMust

  1. Alleged data breach of PT Bank Danamon Indonesia

  1. Alleged Data Breach of Ukrainian State System IPC Local Budget

  1. Alleged Sale of 42K Valid Email Access from Mixed Domains

  1. Alleged Sale of 1.4K Mixed Email Account Access

  1. Alleged sale of national identities and residency proofs of Iraq

  1. EAGLE7 targets the website of Bangladesh Madrasah Education Board

  1. Alleged Data Leak of SME Bank Cambodia
  • Category: Data Leak
  • Content: The group claims to have leaked data from SME Bank Cambodia. The exposed content reportedly includes a publicly accessible PHP information page revealing detailed server configuration data, software versions, and enabled modules, which could potentially be exploited for further compromise.
  • Date: 2025-08-08T11:25:41Z
  • Network: telegram
  • Published URL: https://t.me/YourAnonSRVN/1528
  • Screenshots:
  • Threat Actors: Anonymous SRVN
  • Victim Country: Cambodia
  • Victim Industry: Financial Services
  • Victim Organization: sme bank cambodia
  • Victim Site: smebankcambodia.com.kh’

  1. Alleged Data Leak of National Election Authority of Cambodia
  • Category: Data Leak
  • Content: The group claims to have leaked data from the National Election Authority of Cambodia. The exposed content reportedly includes web application source files, configuration files, and a 2.7 GB compressed archive, all accessible from a subdomain of the organisation’s official website.
  • Date: 2025-08-08T11:23:40Z
  • Network: telegram
  • Published URL: https://t.me/YourAnonSRVN/1527
  • Screenshots:
  • Threat Actors: Anonymous SRVN
  • Victim Country: Cambodia
  • Victim Industry: Government Administration
  • Victim Organization: national election authority of cambodia
  • Victim Site: nea.gov.kh

  1. Alleged data leak of One Window Service Office (OWSO)

  1. Alleged sale of EITI Indonesia report form

  1. Alleged data leak of Home of English International School

  1. Alleged data leak of Nissan Cambodia.

  1. Alleged data leak of National Center for Parasitology, Entomology, and Malaria Control (CNM) in Cambodia

  1. Alleged sale of Twitter legacy admin gold verified

  1. Alleged data breach of Police of the Province of Córdoba

  1. Alleged data leak of United Arab Emirates

  1. Alleged sale of access to Telecom Argentina

  1. AKATSUKI CYBER TEAM claims to target Israel

  1. Alleged data breach of Systematize
  • Category: Data Breach
  • Content: The threat actor claims to be selling a 1.37 GB SQL database allegedly stolen from Systematize,Allegedly leaked on October 31, 2022. The dataset reportedly contains over 12.6 million records and includes sensitive data from various tables, such as client records, student details, guardian and employee information, financial transactions, audit logs, and admin credentials.
  • Date: 2025-08-08T10:09:17Z
  • Network: openweb
  • Published URL: https://darkforums.st/Thread-COLOMBIA-Siacolweb-com
  • Screenshots:
  • Threat Actors: giorggios
  • Victim Country: Colombia
  • Victim Industry: Information Technology (IT) Services
  • Victim Organization: systematize
  • Victim Site: siacolweb.com

  1. Anonymous SRVN targets the website of Harbor Property

  1. Alleged data breach of DyalCom

  1. Alleged data breach of Montalvo Institute

  1. Alleged data breach of Pakistan Petroleum Limited

  1. Alleged sale of Thailand president and military

  1. Alleged Unauthorized access to an Unidentified Organization in Netherlands

  1. Alleged data breach of The Housing and Development Bank Egypt

  1. Alleged data breach of Ministry of Foreign Affairs, Republic of China (Taiwan)

  1. Alleged data breach of Haha – Graby World

  1. Alleged unauthorised access to U.S. Department of Labor
  • Category: Initial Access
  • Content: The threat actor claims to have successfully hacked the U.S. Department of Labor, gaining undetected access to internal systems and corporate email accounts. They report exfiltrating a large volume of sensitive U.S. government data, including confidential employee records, internal email lists, interdepartmental communications, case files, and lawyer information.
  • Date: 2025-08-08T04:03:39Z
  • Network: telegram
  • Published URL: https://t.me/n2LP_wVf79c2YzM0/783
  • Screenshots:
  • Threat Actors: Infrastructure Destruction Squad
  • Victim Country: USA
  • Victim Industry: Government Administration
  • Victim Organization: u.s. department of labor
  • Victim Site: dol.gov

  1. Alleged data breach of swarovski

  1. Alleged data leak of Italian Database

  1. Alleged data breach of Experia USA
  • Category: Data Breach
  • Content: The Threat actor claims to be selling a dataset allegedly stolen from Experia USA (experia-usa.com), a U.S.-based data and marketing platform. The leaked data reportedly contains personal and demographic details of 10 million individuals, including names, addresses, phone numbers, email addresses, dates of birth, income levels, credit scores, household composition, ethnicity, interests, and IP addresses.
  • Date: 2025-08-08T02:37:06Z
  • Network: openweb
  • Published URL: https://darkforums.st/Thread-10-Million-USA-experia-usa-com-2025-Database
  • Screenshots:
  • Threat Actors: DigitalGhostt
  • Victim Country: USA
  • Victim Industry: Electrical & Electronic Manufacturing
  • Victim Organization: experia usa
  • Victim Site: experia-usa.com

  1. Alleged data breach of Rumah Sakit Polri Kramat Jati

  1. Alleged Data breach of Bank of America Records
  • Category: Data Breach
  • Content: The threat actor claims to have leaked a 1 million-record Bank of America database containing sensitive personal and financial information, including names, SSNs, addresses, email, phone numbers, dates of birth, driver’s license details, income type, occupation, employer, bank account numbers, routing numbers, and passwords.
  • Date: 2025-08-08T00:44:16Z
  • Network: telegram
  • Published URL: https://t.me/c/2490485755/15322
  • Screenshots:
  • Threat Actors: DigitalGhost
  • Victim Country: USA
  • Victim Industry: Banking & Mortgage
  • Victim Organization: bank of america
  • Victim Site: bankofamerica.com

  1. Alleged sale of RDP access to an unidentified France company

  1. Alleged unauthorized access to General Administration of Health Services

  1. Alleged data breach of truCSR

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Data breaches and leaks are prominent, affecting various sectors from government and education to retail and banking, and impacting countries including Indonesia, Greece, Ukraine, Iraq, Bangladesh, Cambodia, Philippines, Poland, Pakistan, Thailand, Netherlands, Egypt, Taiwan, Malaysia, Australia, Italy, USA, France, Saudi Arabia, and India. The compromised data ranges from personal user information, financial details, and confidential government documents to sensitive patient records and large customer databases.

Beyond data compromise, the report also reveals significant activity in initial access sales, with threat actors offering unauthorized access to online stores, email accounts, and corporate networks (including RDP and shell access to a French company and the U.S. Department of Labor). The sale of combo lists and alerts for planned attacks further underscores the availability of offensive capabilities in the cyber underground.

The incidents collectively demonstrate that organizations across various industries and geographies face persistent threats from data exfiltration, unauthorized network access, and the proliferation of malicious tools. The nature of these incidents emphasizes the critical importance of robust cybersecurity measures, including strong access controls, data protection strategies, continuous vulnerability management, and proactive threat intelligence to defend against a wide array of sophisticated and opportunistic attacks.