Data Theft Claims Converge on Banks and Government

Events tracked
209
Critical exposure
59

Summary

Data compromise cut across finance, public administration, healthcare and transport, leaving identity systems and internet-facing applications as the day's common pressure points. Reporting shows how initial access can move quickly from a reachable service or login flow into credential theft and extortion. Security teams should treat exposed identity infrastructure and delayed patching as connected risks, not separate workstreams.

Today's developments

Datacloud claims a breach against Bank Mandiri in Indonesia, while a separate listing says the bank is investigating an alleged customer-data leak. Market Exchange claims activity across Gulf finance, naming Emirates NBD in the United Arab Emirates and advertising three separate Saudi Arabian datasets tied to bank accounts, stocks and securities. LuckyRaku1 claims a Polish banking database, and sonalal claims a set of leads linked to hardware-wallet maker Trezor in the United States. These forum claims remain unverified, but their concentration around account holders, investors and financial institutions creates a consistent fraud and social-engineering risk.

Public-sector and infrastructure claims were geographically dispersed. GordonFreeman claims a breach against the Central Electoral Board of the Dominican Republic; 0xSec claims Docurba, a French public-sector service; MDGhost666 claims National Oil Ethiopia; UserSec claims Ukrainian financial-services company city24; and honeydutches claims the Edgewood Police Department in the United States. Other alleged victims include the Toledo Zoo and Aquarium, claimed by seraphims, and Quest Apartment Hotels in Australia, claimed by uawrongteam. Betway separately claims large datasets from US transport and logistics organizations CGETC and ABC Movers. Healthcare breach reports also named Premier Medical Group of the Hudson Valley, Genesis Medical Management, The Asthma Center, Psychiatric Wellness Center and Grafton City Hospital, although the feed did not attribute those reports to a named actor.

External security reporting added immediate exploitation context. CISA added CVE-2026-21962, a maximum-severity Oracle HTTP Server and WebLogic Server flaw, to its exploited-vulnerability catalog after reports of active attacks. Researchers also observed attempts against the miniOrange SAML 2.0 SSO WordPress plugin through CVE-2026-61979 and CVE-2026-15981, two unauthenticated authentication-bypass flaws that can lead to administrator access. Reporting on Mirage2FA said the phishing-as-a-service operation targeted 4,500 US and European companies through Microsoft 365 login flows, with researchers assessing that 48% of targeted email addresses were potentially compromised.

Software supply-chain and endpoint research widened the attack surface. Researchers found 24 npm packages being used to host ClickFix-style fake CAPTCHA pages through unpkg mirrors. Oasis Security reported that a malicious webpage could reach a local Ollama instance behind NVIDIA NemoClaw and plant hidden instructions, while Unit 42 described how behavioral controls can still detect AI-assisted malware by what it does at runtime. Interpol reporting counted 58 arrests in an international cybercrime operation and described infrastructure supporting fraud and money laundering. CISA red-team reporting provided a defensive contrast: a tested water-sector organization contained the simulated intrusion, while a government-sector target did not. Reporting on the Grand Theft Auto VI leaks also described a drip-release extortion model designed to sustain attention rather than deliver a single disclosure.

Threat landscape signals

The three most active named actors accounted for 44 of 209 tracked events, or about 21%: RBL LEVIATHAN GHOST recorded 25, MARKET DOMAIN 11 and K3LLLEAKERS 8. The United States led victim-country counts with 42, followed by Indonesia with 29 and Israel with 20. Government Administration and Government and Public Sector together represented 40 events, while healthcare contributed at least nine. This concentration means identity providers, citizen-facing portals and third-party administrative systems deserve priority review even when an organization is not named in a claim.

The category mix was nearly balanced between 56 DDoS events and 59 alleged breaches or leaks, with another 30 initial-access listings. That combination points to simultaneous availability, credential and data-loss pressure rather than a single dominant technique. Defenders can act on the pattern by checking Oracle and miniOrange exposure against current asset inventories, reviewing Microsoft 365 sign-in anomalies and phishing-resistant authentication coverage, and monitoring newly created administrator accounts. Claims involving banks and public agencies should also trigger fraud monitoring and credential-reset readiness, but no forum claim should be treated as confirmed without victim or independent-source verification.

All incidents are reported as alleged claims by threat actors and have not been independently verified by GrayscaleInsight.

Threat intelligence is reported for security awareness purposes only and does not constitute endorsement of any actor, group, or activity.

Recent editions