Ecuador Breaches and Cl0p Windchill Attacks Surge

Events tracked
266
Critical exposure
128

Summary

Public-sector compromise claims dominated the day's collection, with local administrations and sensitive government systems exposed alongside a shift toward industrial software exploitation. The combination raises immediate access-control and patching concerns across government and manufacturing networks.

Today's developments

Ecuadorian Government Under Siege. Actor azraelzer0d4y claims to have breached seven separate Ecuadorian parish government entities, including the Gobierno Parroquial de Manuel de Jesus Calle, GAD La Victoria Parish, and the Decentralized Autonomous Parish Government of Huertas. The actor also posted a mass dump of .gob.ec domains, suggesting a broad scanning or access campaign against the country's government infrastructure. Separately, actor BL33DR00T claimed access to gadnuevoparaiso.gob.ec, compounding the pressure on Ecuador's public sector.

UK Public Sector Data Allegedly for Sale. Actor exfilsquad claims to have breached the UK Department for Education and the Police National Legal Database. These are high-value targets: the DfE holds records on students, staff, and schools, while the police database contains sensitive law enforcement records. The claims, if verified, represent a significant compromise of UK government systems. Separately, actor Richard2002 alleged breaches of several UK businesses, including TOP RACE LTD, Fox Supplements, and PatientConnections, indicating a broader targeting of the UK economy.

Cl0p Affiliates Target Industrial Software. Industry researchers report that Cl0p (aka FIN11, Lace Tempest) affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments. The attack chain chains a pre-authentication information disclosure with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution. This marks a shift for Cl0p, which historically focused on file-transfer appliances, now targeting industrial and manufacturing software.

Critical Vulnerabilities Under Active Attack. Two unpatched or recently patched flaws are being exploited in the wild. A critical Fastjson 1.x RCE vulnerability (CVE-2026-16723, CVSS 9.0) is being targeted against Spring Boot applications, with no patch available. Separately, a researcher published a GitLab RCE exploit for a flaw patched on June 10, affecting self-managed GitLab 18.11.3 servers. Any authenticated user who can push to a project can execute commands as the git user.

DevMan RaaS Platform Detailed. Researchers at PRODAFT have detailed the DevMan ransomware-as-a-service operation, tracked as Funky Mantis. The platform centralizes payload builds, victim management, and affiliate payouts, lowering the barrier for entry-level cybercriminals. This operational efficiency is likely to drive an increase in ransomware incidents from smaller affiliates.

Threat landscape signals

The data reveals a pronounced clustering of attacks against government administration, with Ecuador, the UK, and Indonesia being the most targeted. Actor azraelzer0d4y alone accounts for 11 events, almost entirely against Ecuadorian government entities. This suggests a coordinated campaign rather than opportunistic targeting. The United States remains the top victim country overall, but the concentration of events in Ecuador (31) and France (23) indicates regional threat spikes.

The high volume of data breach events (102) compared to ransomware (18) suggests that data extortion without encryption remains a dominant tactic. The presence of multiple actors claiming access to police, education, and government databases underscores the value of personally identifiable information (PII) on dark web markets. Defenders should prioritize patching for Fastjson and GitLab, monitor for Cl0p activity against PTC Windchill deployments, and review access controls for any internet-exposed government systems.

All incidents are reported as alleged claims by threat actors and have not been independently verified by GrayscaleInsight.

Threat intelligence is reported for security awareness purposes only and does not constitute endorsement of any actor, group, or activity.

Recent editions