[August-18-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Alleged leak of Saudi Arabia military and Government internal documents

  1. Alleged data sale of Non-VBV credit cards

  1. Alleged sale of classified documents

  1. Alleged sale of international credit card records

  1. Alleged data breach Riskav

  1. Alleged data breach of Ministry of transport in Thailand

  1. Team Azrael Angel Of Death targets the website of Mahatma Gandhi College of Law

  1. Alleged data leak of Marriott International

  1. Alleged data breach of PrestaShop

  1. Alleged sale of an unknown USA database

  1. Alleged data leak of National Bank of Canada

  1. Alleged sale of a Twitter automation tool

  1. Alleged leak of L’Oréal and CeraVe API keys

  1. Alleged sale of Grafit data

  1. Alleged sale of Naga College Foundation data

  1. Alleged leak of Nissan CBI data of automotives design

  1. Alleged access sale to an unidentified U.S agriculture company

  1. Alleged data breach of SMA Muhammadiyah 1 Prambanan

  1. Alleged sale of UK loan records

  1. Alleged data leak of Emcan Group

  1. Alleged data leak of Ministry of Interior (MoI), Saudi Arabia
  • Category: Data Breach
  • Content: The group claims to have leaked database from Ministry of Interior (MoI), Saudi Arabia, containing 20,000 records, including user login credentials.
  • Date: 2025-08-18T08:29:49Z
  • Network: telegram
  • Published URL: https://t.me/liwaamohammad/715
  • Screenshots:
  • Threat Actors: Liwaa Muhammad
  • Victim Country: Saudi Arabia
  • Victim Industry: Government Administration
  • Victim Organization: ministry of interior (moi), saudi arabia
  • Victim Site: moi.gov.sa

  1. Alleged data leak of Ministry of Interior (MoI), Saudi Arabia

  1. Alleged data leak of Mobily

  1. Alleged data leak of Kirkpatrick Partners, LLC

  1. Alleged data breach of NATO

  1. Alleged data leak of Belgium IBAN Database

  1. Alleged leak of unauthorized access to Summit Computer Co., Ltd.
  • Category: Initial Access
  • Content: The group claims to have leaked unauthorized access to Summit Computer Co., Ltd.’s internal document archive and database system in Thailand.
  • Date: 2025-08-18T04:46:48Z
  • Network: telegram
  • Published URL: https://t.me/nxbbsec/2408
  • Screenshots:
  • Threat Actors: NXBB.SEC
  • Victim Country: Thailand
  • Victim Industry: Information Technology (IT) Services
  • Victim Organization: summit computer co., ltd.
  • Victim Site: summitcomputer.co.th

  1. Alleged leak of Cambodian government personnel database
  • Category: Data Leak
  • Content: The group claims to have leaked Cambodian government personnel database. The compromised data includes ID or user number, name in both Khmer and English, organization or position, affiliation or employer, possibly contact details or records.
  • Date: 2025-08-18T04:15:28Z
  • Network: telegram
  • Published URL: https://t.me/nxbbsec/2407
  • Screenshots:
  • Threat Actors: NXBB.SEC
  • Victim Country: Cambodia
  • Victim Industry: Government & Public Sector
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged leak of unauthorized admin access to Hugcode Company

  1. Alleged data breach of Bureau of Indian Standards

  1. Alleged data leak of unidentified Healthcare organization in Thailand

  1. Alleged data breach of Bank of Latvia

  1. Alleged data breach of SMK Negeri 1 Kaligondang

  1. Alleged data breach of SMK Negeri 1 Wonosobo

  1. Alleged leak of unauthorized access to Royal Irrigation Department (Thailand)

  1. Alleged sale of a multilingual keylogger

  1. WOLF CYBER ARMY V2 targets the website of Desa Pattedong Selatan

  1. Alleged leak of emails and passwords from MINISTRY OF PRIMARY AND SECONDARY EDUCATION

  1. Alleged sale of Cutlet Maker 1.0 F
  • Category: Malware
  • Content: The threat actor claims to be selling Cutlet Maker 1.0 F, an ATM jackpotting malware designed to exploit vulnerabilities in ATM controllers via USB access. The malware enables attackers to empty cash cassettes and includes a DIY kit with instructions, targeted ATM models, and operational guidance.
  • Date: 2025-08-18T01:14:35Z
  • Network: openweb
  • Published URL: https://darkforums.st/Thread-ATM-Jackpotting-Malware
  • Screenshots:
  • Threat Actors: majormotion
  • Victim Country: Unknown
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged data breach of Argentine Army

  1. Alleged data leak of Personal database

i need also conclusion

Incident Report: Analysis of Recent Cyber Events This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Alleged leak of Saudi Arabia military and Government internal documents

  1. Alleged data sale of Non-VBV credit cards

  1. Alleged sale of classified documents

  1. Alleged sale of international credit card records

  1. Alleged data breach Riskav

  1. Alleged data breach of Ministry of transport in Thailand

  1. Team Azrael Angel Of Death targets the website of Mahatma Gandhi College of Law

  1. Alleged data leak of Marriott International

  1. Alleged data breach of PrestaShop

  1. Alleged sale of an unknown USA database

  1. Alleged data leak of National Bank of Canada

  1. Alleged sale of a Twitter automation tool

  1. Alleged leak of L’Oréal and CeraVe API keys

  1. Alleged sale of Grafit data

  1. Alleged sale of Naga College Foundation data

  1. Alleged leak of Nissan CBI data of automotives design

  1. Alleged access sale to an unidentified U.S agriculture company

  1. Alleged data breach of SMA Muhammadiyah 1 Prambanan

  1. Alleged sale of UK loan records

  1. Alleged data leak of Emcan Group

  1. Alleged data leak of Ministry of Interior (MoI), Saudi Arabia
  • Category: Data Breach
  • Content: The group claims to have leaked database from Ministry of Interior (MoI), Saudi Arabia, containing 20,000 records, including user login credentials.
  • Date: 2025-08-18T08:29:49Z
  • Network: telegram
  • Published URL: https://t.me/liwaamohammad/715
  • Screenshots:
  • Threat Actors: Liwaa Muhammad
  • Victim Country: Saudi Arabia
  • Victim Industry: Government Administration
  • Victim Organization: ministry of interior (moi), saudi arabia
  • Victim Site: moi.gov.sa

  1. Alleged data leak of Ministry of Interior (MoI), Saudi Arabia

  1. Alleged data leak of Mobily

  1. Alleged data leak of Kirkpatrick Partners, LLC

  1. Alleged data breach of NATO

  1. Alleged data leak of Belgium IBAN Database

  1. Alleged leak of unauthorized access to Summit Computer Co., Ltd.
  • Category: Initial Access
  • Content: The group claims to have leaked unauthorized access to Summit Computer Co., Ltd.’s internal document archive and database system in Thailand.
  • Date: 2025-08-18T04:46:48Z
  • Network: telegram
  • Published URL: https://t.me/nxbbsec/2408
  • Screenshots:
  • Threat Actors: NXBB.SEC
  • Victim Country: Thailand
  • Victim Industry: Information Technology (IT) Services
  • Victim Organization: summit computer co., ltd.
  • Victim Site: summitcomputer.co.th

  1. Alleged leak of Cambodian government personnel database
  • Category: Data Leak
  • Content: The group claims to have leaked Cambodian government personnel database. The compromised data includes ID or user number, name in both Khmer and English, organization or position, affiliation or employer, possibly contact details or records.
  • Date: 2025-08-18T04:15:28Z
  • Network: telegram
  • Published URL: https://t.me/nxbbsec/2407
  • Screenshots:
  • Threat Actors: NXBB.SEC
  • Victim Country: Cambodia
  • Victim Industry: Government & Public Sector
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged leak of unauthorized admin access to Hugcode Company

  1. Alleged data breach of Bureau of Indian Standards

  1. Alleged data leak of unidentified Healthcare organization in Thailand

  1. Alleged data breach of Bank of Latvia

  1. Alleged data breach of SMK Negeri 1 Kaligondang

  1. Alleged data breach of SMK Negeri 1 Wonosobo

  1. Alleged leak of unauthorized access to Royal Irrigation Department (Thailand)

  1. Alleged sale of a multilingual keylogger

  1. WOLF CYBER ARMY V2 targets the website of Desa Pattedong Selatan

  1. Alleged leak of emails and passwords from MINISTRY OF PRIMARY AND SECONDARY EDUCATION

  1. Alleged sale of Cutlet Maker 1.0 F
  • Category: Malware
  • Content: The threat actor claims to be selling Cutlet Maker 1.0 F, an ATM jackpotting malware designed to exploit vulnerabilities in ATM controllers via USB access. The malware enables attackers to empty cash cassettes and includes a DIY kit with instructions, targeted ATM models, and operational guidance.
  • Date: 2025-08-18T01:14:35Z
  • Network: openweb
  • Published URL: https://darkforums.st/Thread-ATM-Jackpotting-Malware
  • Screenshots:
  • Threat Actors: majormotion
  • Victim Country: Unknown
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged data breach of Argentine Army

  1. Alleged data leak of Personal database

Conclusion The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Data breaches and leaks are prominent, affecting various sectors from government administration and education to financial services and automotive, and impacting countries including Saudi Arabia, UK, Iran, Thailand, India, USA, France, Canada, Belarus, Philippines, Japan, Belgium, Cambodia, Latvia, Indonesia, and Argentina. The compromised data ranges from personal user information and credit card details to sensitive military documents, confidential company designs, and large customer databases. Beyond data compromise, the report also reveals significant activity in initial access sales, with threat actors offering unauthorized access to internal document archives, databases, and company networks. The sale of malware, including a multilingual keylogger and an ATM jackpotting tool, further underscores the availability of offensive capabilities in the cyber underground. The incidents collectively demonstrate that organizations across various industries and geographies face persistent threats from data exfiltration, unauthorized network access, and the proliferation of malicious tools. The nature of these incidents emphasizes the critical importance of robust cybersecurity measures, including strong access controls, data protection strategies, continuous vulnerability management, and proactive threat intelligence to defend against a wide array of sophisticated and opportunistic attacks.