[October-13-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Mercante Tubos e Aços falls victim to Mydata/Alphalocker Ransomware

  1. Bank3 falls victim to Qilin Ransomware

  1. Alleged data leak of Royal Bank of Scotland

  1. BHI Co., Ltd. falls victim to Qilin Ransomware

  1. Pharaoh’s Team targets the website of Peak Performance Hiking

  1. San Bernard Electric Coop.,Inc. falls victim to Qilin Ransomware

  1. Pharaoh’s Team targets the website of Namaste Tech

  1. Pharaoh’s Team targets the website of Hind Era Properties

  1. Pharaoh’s Team targets the website hostingersite.com

  1. Pharaoh’s Team targets the website of Grandeur Net Academy

  1. Pharaoh’s Team targets the website darkgoldenrod-pigeon-466926.hostingersite.com

  1. Bun falls victim to ThreeAM Ransomware

  1. Pharaoh’s Team targets the website bookingsupport.in

  1. Pharaoh’s Team targets the website of AMOREVO

  1. PT. INDACO WARNA DUNIA falls victim to Nova Ransomware

  1. Alleged leak of sensitive documents from Palestine and Egypt

  1. Fountains Condominium Operations falls victim to DragonForce Ransomware

  1. Arabian Ghosts targets the website of Front Blink

  1. Arabian Ghosts targets the website of Hackberry Softech Private Limited

  1. Alleged data breach of Bienvenue à Paris

  1. HellR00ters Team targets the website of Shiv Shakti International

  1. HellR00ters Team targets the website of Shiv Gaushala Charitable Trust Miyani

  1. HellR00ters Team targets the website of M/s M. R. Overseas Pvt. Ltd

  1. Alleged data sale of personally identifiable information

  1. HellR00ters Team targets the website of Smileshot Photography

  1. The group claims to have deface the website of MindWhiz

  1. HellR00ters Team targets the website of Ziran

  1. HellR00ters Team targets the website of Kuldevi Brass

  1. HellR00ters Team targets the website of Truenam Global

  1. HellR00ters Team targets the website of K9HR Solutions

  1. SourceOne Corp. falls victim to Qilin Ransomware

  1. HellR00ters Team targets the website of Tulsi Precision Product LLP

  1. HellR00ters Team targets the website of JK Tech

  1. HellR00ters Team targets the website of HTF Tools

  1. HellR00ters Team targets the website of snap2shoot photography

  1. HellR00ters Team targets the website of GujcoMart

  1. HellR00ters Team targets the website of Goldcoin Group

  1. HellR00ters Team targets the website of Shree Gayatri Refrigeration

  1. HellR00ters Team targets the website of Gatral Trading

  1. HellR00ters Team targets the website of Cromix Cab

  1. Alleged sale of access to unidentified Telecom company from Peru

  1. Alleged data sale of Companies and Intellectual Property Commission

  1. Hauts-de-France Region falls victim to Qilin Ransomware

  1. Alleged Sale of Merged Credit-Card Database
  • Category: Data Breach
  • Content: The threat actor claims to be selling a merged database of stolen credit card records from 2022\u20132025, totaling approximately 9.8 million cards (claimed 80% U.S.) the listing and its contents have not been independently verified.
  • Date: 2025-10-13T17:03:10Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/268143/) Screenshots:
  • https://d34iuop8pidsy8.cloudfront.net/0a13f72a-5e9b-451e-a60c-7b55a998ddb5.png
  • Threat Actors: cashmoneycard
  • Victim Country: USA
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged sale of Thailand ID Card Database

  1. Alleged sale of Playtech Gambling Database

  1. Alleged gain of access to IT networking monitoring system and 403 network devices

  1. Alleged data leak of Italian Mobile Number Data with Email

  1. Alleged data sale of Companies and Intellectual Property Commission – eServices

  1. Alleged sale of Indian Aadhaar database

  1. InDoM1nu’s targets the website gemista.store

  1. InDoM1nu’s targets the website of Meta Nxt Solutions Private Limited

  1. InDoM1nu’s targets the website of Gift Corporate India

  1. Alleged data leak of multiple US banks

  1. Alleged sale of Android Spyware 2025

  1. Undefasa falls victim to Black Nevas Ransomware

  1. Alleged data leak of multiple royal palaces in Morocco

  1. BABAYO EROR SYSTEM targets the website of ADES-Nord

  1. North Stonington Public Schools falls victim to INTERLOCK Ransomware

  1. Alleged breach of MAYA Technologies Ltd
  • Category: Data Breach
  • Content: The group claims to have breached MAYA Technologies Ltd. They allege that they obtained access to a network of defense-related companies and accessed sensitive ideas and plans related to military equipment development.\n\nNB: The authenticity of the claim is yet\u00a0to\u00a0be\u00a0verified
  • Date: 2025-10-13T12:56:05Z
  • Network: telegram
  • Published URL: (https://t.me/CyberIsnaadFront1/758) Screenshots:
  • https://d34iuop8pidsy8.cloudfront.net/0b3e29f8-e638-4640-9e90-6241bb030139.png
  • Threat Actors: Cyber Isnaad Front
  • Victim Country: Israel
  • Victim Industry: Machinery Manufacturing
  • Victim Organization: maya technologies ltd
  • Victim Site: maya-il.com

  1. Alleged data breach of IAS – Industrial Application Software

  1. Alleged data breach of PLC TRANS

  1. Alleged data breach of Kuehne+Nagel

  1. Alleged data breach of CareWell

  1. Alleged data breach of DSV – Global Transport and Logistics

  1. Alleged data breach of Legal Boutique

  1. Alleged data breach of Borrowell

  1. Alleged sale of access to an unidentified Internet Service Provider In Brazil

  1. Alleged Unauthorized Access to Irrigation Control System in New Zealand

  1. Alleged data breach of Bank Central Asia

  1. Alleged data breach of SMBT Sevabhavi Trust

  1. Alleged leak of multiple login credentials in Indonesia

  1. Alleged sale of USA/EU Corporate Mail Credentials

  1. The City of Michigan City falls victim to Obscura Ransomware

  1. Alleged leak of Principal Accountant General (Audit) Haryana
  • Category: Data Breach
  • Content: The group claims to have obtained 1,900+ Excel databases from India\u2019s Principal Accountant General , comprising a wide range of sensitive governmental data.
  • Date: 2025-10-13T06:15:39Z
  • Network: telegram
  • Published URL: (https://t.me/c/3088972502/61) Screenshots:
  • https://d34iuop8pidsy8.cloudfront.net/0b9375af-9b7b-491d-b9cc-f550ed898072.png
  • Threat Actors: HIME666
  • Victim Country: India
  • Victim Industry: Government & Public Sector
  • Victim Organization: principal accountant general (audit)
  • Victim Site: cag.gov.in

  1. Alleged Sale of VPN Access to Unidentified Shop in West Africa

  1. Alleged sale of Discord leak

  1. Cemtrex Inc. falls victim to MEDUSA Ransomware

  1. Alleged data breach of Berkeley Lab

  1. Alleged data breach of Discord Inc

  1. Alleged leak of BrightTech Solutions’ Amazon Enterprise Management System
  • Category: Data Breach
  • Content: Group claims to have leaked the enterprise management platform developed and operated by BrightTech Solutions for Amazon. The compromised system reportedly manages HR, finance, and operational data for large-scale administrative operations. Exposed information is said to include detailed employee records, personal and work contact details, and sensitive payroll and financial data. The incident, if verified, could raise serious concerns about data protection and corporate confidentiality within Amazon\u2019s management infrastructure.
  • Date: 2025-10-13T02:17:00Z
  • Network: telegram
  • Published URL: (https://t.me/n2LP_wVf79c2YzM0/1902) Screenshots:
  • https://d34iuop8pidsy8.cloudfront.net/1a2deddc-1a76-4e50-8b28-fd6c623ee8bf.png
  • https://d34iuop8pidsy8.cloudfront.net/e2fe2ba1-e99d-4e98-b5f2-44e8f5e1de00.png
  • Threat Actors: Infrastructure Destruction Squad
  • Victim Country: Unknown
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged sale of 12K Indian investors database

  1. Alleged data breach of TFUEL

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats, ranging from Ransomware attacks and Data Breaches to Initial Access sales and Defacements. Ransomware groups like Qilin, Mydata/Alphalocker, and Black Nevas continue to target diverse organizations, including finance (Bank3), manufacturing (BHI Co., Ltd.), and public services (San Bernard Electric Coop.,Inc., Hauts-de-France Region). Data compromise remains prominent, affecting sectors from education (North Stonington Public Schools, SMBT Sevabhavi Trust) and financial services (Royal Bank of Scotland, Bank Central Asia) to government entities (Principal Accountant General (Audit) Haryana, The City of Michigan City, Companies and Intellectual Property Commission – eServices) and large tech platforms (Discord Inc.). Initial Access sales are also evident, with threat actors offering access to telecommunications infrastructure in Peru and irrigation control systems in New Zealand. The significant number of defacements, primarily targeting organizations in India by groups like HellR00ters Team and Pharaoh’s Team, underscores a high volume of opportunistic web attacks. This persistent activity across multiple threat categories and global regions emphasizes the critical need for robust and multi-layered cybersecurity defenses.