[August-11-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Alleged Sale of HQ Free Combolist

  1. Alleged Sale of Mixed Mail Access Combolist

  1. Alleged data leak of Indonesian IP addresses

  1. Alleged Sale of Valid Mail Access Combolist

  1. Alleged Data Leak of French Football Federation – Haute-Savoie Referees

  1. Alleged Sale of Magento Shop Admin Access (USA)

  1. Alleged Sale of WordPress Admin Access Containing Authorize.Net Credit Card Data (USA)
  • Category: Initial Access
  • Content: The threat actor claims to be selling WordPress admin panel access with full rights and installed plugins for a US-based site using the Authorize.Net payment gateway. The data includes 332 Authorize.Net credit card records for August (in 11 days) and 729 records for July (31 days).
  • Date: 2025-08-11T13:25:45Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/264079/)
  • Screenshots:
  • Threat Actors: black18
  • Victim Country: USA
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged Network Access Sale of Unidentified Danish Office Products Retail & Distribution Organisation
  • Category: Initial Access
  • Content: The threat actor claims to be selling network access to an unidentified organisation in Denmark operating in the office products retail and distribution industry. The access level is Domain Admin, with 11 PCs in the domain (visible via Fortinet VPN) and 78 domain users. The listing also mentions the presence of ESET, Acronis Cyber Protect, and Defender security solutions.
  • Date: 2025-08-11T13:22:27Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/264077/)
  • Screenshots:
  • Threat Actors: p0wershe11
  • Victim Country: Unknown
  • Victim Industry: Retail Industry
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged Data Leak of Unidentified Digital Banking Organisation

  1. Alleged Leak of USA Travelers and Visa Approvals Data
  • Category: Data Leak
  • Content: The threat actor claims to be leaking a database containing over 700,000 records related to USA travelers and visa approvals. The exposed data contains full personal details, including passport information and other sensitive data.
  • Date: 2025-08-11T13:11:13Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/264096/)
  • Screenshots:
  • Threat Actors: 0kb
  • Victim Country: USA
  • Victim Industry: Government Relations
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged data breach of Cartier

  1. Alleged Data Leak of Lookinsure.com
  • Category: Data Breach
  • Content: The threat actor claims to have leaked data from Lookinsure.com, an AI-powered insurance comparison platform based in Dubai, United Arab Emirates. The exposed data contains full names, phone numbers, email addresses, nationalities, vehicle details, payment transaction data, insurance policy specifics, and driver history.
  • Date: 2025-08-11T13:07:43Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/264095/)
  • Screenshots:
  • Threat Actors: 0kb
  • Victim Country: UAE
  • Victim Industry: Insurance
  • Victim Organization: lookinsure.com
  • Victim Site: lookinsure.com

  1. Allged data sale of Pintogogo

  1. Alleged Data Leak of PKO Bank Polski S.A
  • Category: Data Breach
  • Content: The threat actor claims to have leaked a database allegedly belonging to PKO Bank Polski S.A. The exposed data appears to include customer names, phone numbers, email addresses, gender, trading verification details, handling fees, and timestamps. The post suggests the dataset is from August and is related to financial investments, reportedly involving 800,000 entries.
  • Date: 2025-08-11T12:57:54Z
  • Network: telegram
  • Published URL: (https://t.me/aqj986/6660)
  • Screenshots:
  • Threat Actors: Aiqianjin
  • Victim Country: Poland
  • Victim Industry: Financial Services
  • Victim Organization: pko bank polski s.a.
  • Victim Site: pkobp.pl

  1. YOGJASEC-XTEAM targets the website of Tramt Technology Private Limited

  1. Alleged unauthorized access to CÁRNICAS CAZANI SL

  1. Alleged leak of Arab investor database

  1. Alleged data breach of Marcolin

  1. Alleged sale of admin access of National University of Callao

  1. Alleged data leak of Allianz Life Insurance Company of North America
  • Category: Data Breach
  • Content: The group claims to have leaked data from Allianz Life Insurance Company of North America. The compromised data reportedly include all personally identifiable information, including Social Security Numbers.
  • Date: 2025-08-11T09:14:34Z
  • Network: telegram
  • Published URL: (https://t.me/scatteredlapsusp1d3rhunters/972)
  • Screenshots:
  • Threat Actors: scattered lapsu$ hunters
  • Victim Country: USA
  • Victim Industry: Insurance
  • Victim Organization: allianz life insurance company of north america
  • Victim Site: allianzlife.com

  1. Akatsuki cyber team targets multiple Bolivian websites

  1. Alleged Unauthorized Access of WALKO HMI/SCADA System
  • Category: Initial Access
  • Content: The group claims to have gained unauthorized access to the WALKO HMI/SCADA panel controlling a large facility. They allege to have disabled automatic control of critical subsystems including heating, ventilation, dehumidification, the boiler house, and warehouse operations. The threat actor state they made setpoints, readings, and control elements unavailable, disrupted event and acknowledgement logs, and caused potential risks such as equipment failures, breaches in temperature regulation, warehouse logistics issues, and possible emergencies if manual intervention is attempted.
  • Date: 2025-08-11T06:59:53Z
  • Network: telegram
  • Published URL: (https://t.me/Z_alliance_ru/847)
  • Screenshots:
  • Threat Actors: Z-ALLIANCE
  • Victim Country: Unknown
  • Victim Industry: Industrial Automation
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged data breach of Mass-Zone

  1. Alleged Data Leak of Japan

  1. Alleged data sale of NKFI Office – National Research, Development and Innovation Office (NRDIO)

  1. Alleged data breach of Italian National Professional Registry

  1. Alleged Data Leak of Ministry of Education

  1. Alleged data breach of ELCA Online Shop

  1. Alleged Data Leak from Unidentified Organization in the Czech Republic

  1. Alleged Data Leak of Education Ministry Records

  1. Alleged data leak of Croatian business customer contact database

  1. Alleged data breach of Zeelab Pharmacy

  1. Alleged data breach of ChemtronRiverbend

  1. Alleged data breach of Kementerian Pendidikan Tinggi, Sains, dan Teknologi Republik Indonesia
  • Category: Data Breach
  • Content: A threat actor claims to have leaked a large database from INDONESIA BIMA KEMDIKTISAITEK.GO.ID, containing detailed personal and academic information of lecturers, including full names, identifiers, study programs, universities, contact details, and academic positions.
  • Date: 2025-08-11T02:35:05Z
  • Network: openweb
  • Published URL: (https://leakbase.la/threads/indonesia-bima-kemdiktisaitek-go-id.41361/)
  • Screenshots:
  • Threat Actors: Dhxlcfrwtch
  • Victim Country: Indonesia
  • Victim Industry: Government Relations
  • Victim Organization: kementerian pendidikan tinggi, sains, dan teknologi republik indonesia
  • Victim Site: kemdiktisaintek.go.id

  1. Alleged data breach of Community Services of Missouri

  1. Alleged data breach of Bolivian Military Social Security Corporation

  1. Alleged data breach of Guitar Zoom

  1. Alleged Data Leak of Indian Citizen Data

  1. Alleged unauthorized access to an unidentified Nuclear Training and Security Systems in the USA
  • Category: Initial Access
  • Content: A threat actor claims to have obtained highly sensitive U.S. nuclear-related data, including maps of training facilities, classified course materials, and technical specs of radiation systems. The leak allegedly includes details on the DIAMONDS system, nuclear incident response plans, and personnel involved in nuclear programs. It also mentions cooperation with international agencies and data on EMP/HEMP modeling and surety programs.
  • Date: 2025-08-11T00:56:14Z
  • Network: telegram
  • Published URL: (https://t.me/n2LP_wVf79c2YzM0/795)
  • Screenshots:
  • Threat Actors: Infrastructure Destruction Squad
  • Victim Country: USA
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged data breach of UseRH

  1. YOGJASEC-XTEAM targets the website of Pagarav Hospital and ICU

  1. YOGJASEC-XTEAM targets the website of Tramt Technology Pvt Ltd

  1. Alleged data breach of Archinect

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Data breaches and leaks are prominent, affecting various sectors from education and gaming to healthcare and automotive, and impacting countries including Bangladesh, Mexico, Malaysia, India, Indonesia, France, Brazil, and Israel. The compromised data ranges from personal user information and credit card details to sensitive patient records, classified military components, and large customer databases. Beyond data compromise, the report also reveals significant activity in initial access sales, with threat actors offering unauthorized access to banking systems, corporate networks (including RDWeb access to Canadian and UK firms), and even government and military infrastructure like the Royal Thai Air Force and Madrid’s irrigation system. The sale of malware, including penetration testing tools and DDoS tools, further underscores the availability of offensive capabilities in the cyber underground. The incidents collectively demonstrate that organizations across various industries and geographies face persistent threats from data exfiltration, unauthorized network access, and the proliferation of malicious tools. The nature of these incidents emphasizes the critical importance of robust cybersecurity measures, including strong access controls, data protection strategies, continuous vulnerability management, and proactive threat intelligence to defend against a wide array of sophisticated and opportunistic attacks.