A threat actor has potentially compromised SignitOnline, a UK-based digital signature provider, and is attempting to sell sensitive user data on the dark web. The breach, claimed to affect 5,000 users with 36.5 GB of signatures, poses significant risks of identity theft and fraud. #SignitOnline #DataBreach
Keypoints
- The breach was allegedly carried out in July 2025 by a threat actor on SignitOnline.
- The stolen data includes email addresses, plaintext passwords, and SQL dumps.
- The attacker is selling the data for $500 USD with sample credentials provided.
- The compromised data contains highly sensitive user details and signature files.
- This breach could enable identity theft, fraud, and advanced phishing attacks against users.