Exfilsquad and Ecuador Claims Drive Breach Surge

Events tracked
175
Critical exposure
60

Summary

Public-sector exposure set the operational tone, with municipal systems, education networks, transport bodies, and national agencies appearing across the alleged breach feed. The breadth of sectors suggests opportunistic access is being converted into disclosure claims quickly, while concentrated campaigns against related organizations create a separate risk of shared-vulnerability exploitation.

Today's developments

Actor exfilsquad claims breaches against 12 organizations spanning six countries. In the United States, the actor alleges access involving Microsoft, Allstate, Frontier Airlines, Analog Devices, TaylorMade Golf, Viavi Solutions, District of Columbia Public Schools, the City of Atlanta, and a Houston target categorized as IT services. It also claims breaches against Newcastle University in the United Kingdom, Bonava in Sweden, and Zenith Bank in Nigeria. These remain unverified actor claims; the clustering across software, insurance, aviation, electronics, education, local government, real estate, and banking gives potentially affected defenders a concrete list for access-log review and third-party credential checks.

Actor azraelzer0d4y claims a concentrated series against Ecuadorian local-government organizations. The listings name the parish governments of Shimpis, Pacto, Tumbaco, Yangana, San Pablo de Atenas, Zambi, and Guayusa, plus the municipalities of La Libertad del Oro and Sabiango and the La Libertad public transport enterprise. Ten related claims in one national and administrative cluster raise the possibility of reused software, shared hosting, or common credentials, although the forum posts do not independently establish the entry path.

Other alleged disclosures widen the public-sector and education footprint. PulseSec claims a breach of France Travail; 0wnzS3c claims Argentina's National Seed Institute; DR4K7H CYBER TEAM ( D C T ) claims Indonesia's Ministry of Transportation and the Sumedang village e-office; and 313team claims a leak involving Iraqi traffic directorates. Data Hoarder alleges a Bangladesh Navy database leak, while yoruwithstrike claims documents connected to Pakistan Air Force and Navy deals. In education, homercracker claims employee-data exposure at SEP Tlaxcala, K27 DEV claims Vinh University, lefshaaa claims Cizim Okulu, and JundAlNabi Official claims Materne Training.

Financial and commercial claims were dispersed across several sellers. Exchange Markets alleges incidents involving Bolero Online Securities, the Indian Council of Medical Research, and an insurance-related database. Carm1nPe claims data connected to Libelula Soft and Nuvem services; Sensitive2025 claims Iris Mega in Serbia and PASDE in Greece; WSdatabase claims datasets tied to Indian stock traders and Czech messaging users. PandaPixel claims credential exposure involving Libero and Fastweb in Italy, while QwErTyYyY advertises alleged identity-document images from Italy and the United States. These listings should be treated as claims, not proof that the named organizations were compromised.

Threat landscape signals

The feed contained 175 non-excluded events, including 60 Data Breach or Data Leak claims. Data Breach led with 44 entries, followed by Defacement at 38, Ransomware at 35, DDoS at 22, Data Leak at 16, and Initial Access at 15. The three most active named actors accounted for 44 events, or 25.1% of the daily total, so activity was concentrated enough to make campaign-level monitoring useful without reducing the day to a single actor.

Government Administration was the largest victim vertical with 36 events, ahead of Education at 10, Financial Services at 9, and IT Services at 8. The United States led country counts with 31, followed by France with 17 and Iran with 16. Ransomware still exceeded DDoS by 13 events, but the 60 breach-or-leak claims show that exposure and resale activity were at least as important as disruption. No security-media RSS article fell inside this Eastern-day window, so the brief does not attach outside confirmation to the forum claims. Defenders in municipal and education environments should compare identity-provider sign-ins, remote-access creation, and privileged-account changes across peer systems before treating each named victim as an isolated case.

All incidents are reported as alleged claims by threat actors and have not been independently verified by GrayscaleInsight.

Threat intelligence is reported for security awareness purposes only and does not constitute endorsement of any actor, group, or activity.

Recent editions