[November-6-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Studio Corvo Parma falls victim to Qilin ransomware
  1. Washington Post falls victim to CL0P ransomware
  1. Alleged data leak of PAKISTANI/PUNJAB POLICE DATABASE
  1. Zanaco falls victim to CL0P ransomware
  1. Alleged data breach of Turkish Higher Education Quality Council
  1. Alleged data leak of ISIS
  1. Alleged sale of unauthorized WordPress admin access to an unidentified Kuwait e-commerce site (credit-card redirect)
  • Category: Initial Access
  • Content: The threat actor claims to be selling unauthorized WordPress admin access For an unidentified e-commerce website Located in Kuwait (KW). The listing indicates the site uses a credit-card redirect payment method and provides recent transaction volumes: October — 104 COD, 51 credit-card orders; September — 125 COD, 69 credit-card orders.
  • Date: 2025-11-06T21:17:24Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/269788/)
  • Screenshots:
  • Threat Actors: Fancy.Bear
  • Victim Country: Kuwait
  • Victim Industry: E-commerce & Online Stores
  • Victim Organization: Unknown
  • Victim Site: Unknown
  1. Alleged sale of unauthorized WordPress admin access to an unidentified US e-commerce website
  1. Alleged sale of unauthorized access to an unidentified Peruvian bakery website
  • Category: Initial Access
  • Content: The threat actor is allegedly offering unauthorized access to an unidentified e-commerce website based in Peru, identified as a bakery or pastry shop operating on the WordPress/WooCommerce Platform. The listing claims the website has processed a total of 14,518 Orders, with 69 Orders in October and 18 of those involving card payments. The payment system reportedly uses an iframe-based payment form, which may indicate potential interception or manipulation risk if compromised.
  • Date: 2025-11-06T21:04:15Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/269771/)
  • Screenshots:
  • Threat Actors: SammyWalt
  • Victim Country: Peru
  • Victim Industry: E-commerce & Online Stores
  • Victim Organization: Unknown
  • Victim Site: Unknown
  1. falls victim to INC RANSOM Ransomware
  1. Prutsch-Lang & Damitner Lawyers falls victim to INC RANSOM Ransomware
  1. Meyer & Vögele Elektroanlagen GmbH falls victim to INC RANSOM Ransomware
  1. Ketat Grundstücksverwertungs GmbH falls victim to INC RANSOM Ransomware
  1. Alleged data breach of ItzEazy
  1. Alleged leak of admin access to neatchapter
  1. Provincial Department of Health Services falls victim to Kryptos Ransomware
  1. Alleged data sale of USER PERSONAL DATA INFORMATION PAYTM
  1. Alleged sale of unauthorized Spanish and EU identity dossiers (DNI, IBAN, business documents)
  • Category: Data Breach
  • Content: The threat actor claim to be selling unauthorized Spanish and EU identity dossiers containing extensive personal and business information. The listing advertises Spain DNI (National ID) scans along with IBAN details, business registration documents, professional certificates, notarized rental forms, and insurance policies.
  • Date: 2025-11-06T18:54:37Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/269765/)
  • Screenshots:
  • Threat Actors: boto
  • Victim Country: Spain
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown
  1. Piaty Müller-Mezin Schoeller Partner falls victim to INC RANSOM Ransomware
  1. Alleged sale of online trade personal information from Russia
  1. ZEBRA falls victim to INC RANSOM Ransomware
  1. UScraft falls victim to Qilin ransomware
  1. Alleged sale of unauthorized root access to sigmadomain.com
  1. PCB Funeral Care falls victim to Qilin ransomware
  1. Alleged sale of unauthorized access to an unidentified UK-based online store
  1. Alleged sale of unauthorized domain admin access to an unidentified Belgian agricultural organization
  1. Sai Mai Hospital falls victim to Qilin ransomware
  1. Systems Integrated falls victim to Qilin Ransomware
  1. Alleged data breach of MYM
  1. Tass Meister Patent Firm falls victim to Qilin ransomware
  1. Cyb3r Drag0nz targets the website of Rangala General Trading LTD
  1. Ville de Mont-Laurie falls victim to Qilin ransomware
  1. Dermatology Associates falls victim to ANUBIS Ransomware
  1. Alleged data leak of Mymoneytimes
  1. Alleged sale of admin access to costless.ae
  1. Pharaoh’s Team targets the website of Kağan Şimşek
  1. Alleged leak of login access of Cambodia Journal of Basic and Applied Research ​(CJBAR)
  1. Cyb3r Drag0nz targets the website of Nawshirwan Mustafa
  1. Alleged sale of unauthorized access to BELTEI International School
  1. Black Hills Bentonite LLC falls victim to Nitrogen ransomware
  1. Alleged data breach of Health Dimensions Group
  1. Cyb3r Drag0nz targets the website of Azadbun Organization
  1. Alleged data breach of Horst Realty
  1. E-First Aid Supplies falls victim to Akira Ransomware
  1. Secretaria Municipal de Saúde de Fortaleza falls victim to Nova Ransomware
  1. Alleged data sale of Dubai Police Academy
  1. Noble Compañía de Seguros falls victim to Qilin ransomware
  1. Advanced Technology Group falls victim to Warlock Ransomware
  1. Speedmais falls victim to NightSpire Ransomware
  1. Vrata Tech Solutions falls victim to NightSpire Ransomware
  1. Brihta falls victim to NightSpire Ransomware
  1. Silanos falls victim to Warlock Ransomware
  1. TEIN, INC. falls victim to Warlock Ransomware
  1. NARTIS Plant LLC falls victim to Warlock Ransomware
  1. miltech.local falls victim to Warlock Ransomware
  1. Alleged data sale of Prisoner’s Legal Services of Massachusetts
  1. Alleged sale of unauthorized access to unidentified shop in France
  1. Alleged sale of DHARAHARA TICKETING SYSTEM PANEL
  1. Alleged Shell Access to Multiple Argentine Organizations
  1. Alleged leak of passport, ID card from Romania
  1. Alleged Data Sale of Ferrovial Database
  1. Alleged data breach of Padel Mates
  1. Alleged sale of Bolivia E-Commerce user database
  1. Alleged data leak Chile telecom directory
  1. Alleged sale of Chilean Utility Customer Database
  1. Alleged leak of Australian consumer mobile database
  1. Alleged sale of Australian Manufacturer Contact Database
  1. Alleged sale of Australian Online Retail Customer Database
  1. Alleged sale of data from an unidentified China-based recruitment platform
  1. Alleged data sale of tourism booking records from Canada
  1. Alleged data leak of Cameroon E-Commerce Platform
  1. Alleged data leak of records from a Canada-based mapping service
  1. Alleged leak of personal data from Brazil
  1. ELSEWEDY ELECTRIC falls victim to CL0P Ransomware
  1. Alleged data leak of unidentified Holiday rentals in Austria
  1. Alleged data leak of unidentified Australian E-commerce platform
  1. Alleged data leak of course registration and payment platform Brazil
  1. Alleged data breach of Shaparak
  1. Logitech falls victim to CL0P Ransomware
  1. Alleged data leak of Argentina e-commerce records
  1. Alleged leak of Argentina Comprehensive Data
  1. Kirby Corporation falls victim to CL0P Ransomware
  1. Trimble Inc. falls victim to CL0P Ransomware
  1. Alleged leak of Bangladeshi job seekers database
  1. MKS Inc. falls victim to CL0P Ransomware
  1. Alleged leak of Austria Business Directory
  1. International Motors, LLC falls victim to CL0P Ransomware
  1. Informa PLC falls victim to CL0P Ransomware
  1. Kier Group falls victim to CL0P Ransomware
  1. John Wood Group PLC falls victim to CL0P Ransomware
  1. Rheem Manufacturing falls victim to CL0P Ransomware
  1. Alleged data breach of Cumilla City Corporation
  1. The Union League of Philadelphia falls victim to INC RANSOM Ransomware
  1. Alleged Unauthorized Access to Taiwanese Smart Home Automation System
  • Category: Initial Access
  • Content: The group claims to have gained access to an intelligent home control system in Taiwan that manages lighting, air conditioning, floor heating, and audio-video equipment. They allege that the compromised network allows centralized and room-specific control—including full lighting activation with a single command indicating a breach within a modern, high-end home automation infrastructure.
  • Date: 2025-11-06T00:25:05Z
  • Network: telegram
  • Published URL: (https://t.me/n2LP_wVf79c2YzM0/2302)
  • Screenshots:
  • Threat Actors: Infrastructure Destruction Squad
  • Victim Country: Taiwan
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown
  1. Alleged Unauthorized Access to Greek Heating Control System (ALFA THERM)
  • Category: Initial Access
  • Content: The group claims to have gained access to a system in Greece belonging to ALFA THERM, a company specializing in intelligent heating solutions. The compromised system allegedly manages central heating boilers, temperature regulation, and automated control of pumps, valves, and fans, enabling real-time monitoring and adjustments within residential or industrial energy networks.
  • Date: 2025-11-06T00:16:29Z
  • Network: telegram
  • Published URL: (https://t.me/n2LP_wVf79c2YzM0/2301)
  • Screenshots:
  • Threat Actors: Infrastructure Destruction Squad
  • Victim Country: Greece
  • Victim Industry: Energy & Utilities
  • Victim Organization: alfa therm
  • Victim Site: alphatherm.com.gr

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Ransomware and Data Breaches are prominent, affecting sectors from E-commerce and Financial Services to Government Administration and Healthcare, and impacting countries including the USA, Austria, India, and Canada. The compromised data ranges from personal user information and credit card details to sensitive patient records and corporate data.

The report also reveals significant activity in Initial Access sales, with threat actors offering unauthorized access to e-commerce platforms, educational systems, and domain admin accounts. Defacement attacks were also observed against organizations in Iraq and Turkey.

The nature of these incidents emphasizes the critical importance of robust cybersecurity measures, including strong access controls, data protection strategies, continuous vulnerability management, and proactive threat intelligence to defend against a wide array of sophisticated and opportunistic attacks.