We breached A-Plus Software Limited in the UK (GB) via a SQL injection vulnerability, accessed their backend on 08/18/2026, and downloaded backend and website content, including administrative user data with SHA-1 password hashes and internal account metadata, plus marketing/public web datasets (products, product content, news, and categories). The threat actor involved is ShadowByt3$ and the impacted country is #UnitedKingdom.
Incident Details
- Victim: A-Plus Software Limited
- Sector: Technology
- Country: GB
- Actor: ShadowByt3$
- Source: https://transfer.it/t/Ek7m9dkzhZ6Y
- Discovered: 2026-08-25T14:25:27.547858+00:00
- Published: 2026-08-25T14:25:11.616150+00:00
Information
- Access was gained through an SQL injection vulnerability, with backend data downloaded after entry.
- System access was obtained on 08/18/2026.
- The stolen website user data exposed 10 internal accounts, including admin, debuger, camby, asuka, jimmy, ricole, and green.
- Password hashes in SHA-1 format showed that nearly all administrative users shared the same password.
- Internal access metadata was also included in the compromised user data.
- The public website content included the master list of software solutions and mobile apps sold by the company, such as SalesAnywhere.
- Detailed product-page marketing text, features, specifications, and other content modules were taken.
- Historical corporate announcements, updates, and press releases were among the stolen files.
- News section category tags used for organizing website content were also exposed.
- The full dataset contained 211 records with an uncompressed size of 2,787,292 bytes, or 2.6582 MB.

Disclaimer: This post is based on public claims made by the ransomware group "ShadowByt3$". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.