Eurail says stolen traveler data now up for sale on dark web

Eurail B.V. confirmed that customer data stolen in a breach earlier this year is being offered for sale on the dark web and a sample of the data was published on Telegram. The company is investigating which records and how many customers were affected, has notified data protection authorities under the GDPR, and advises customers to change Rail Planner passwords, reset reused credentials, and monitor bank accounts. #Eurail #Telegram #GDPR #RailPlanner #DiscoverEU

Read More

The intrusion began with a valid RDP login using pre-compromised credentials and progressed through rapid discovery, lateral movement, and persistent account creation before data exfiltration and a final ransomware deployment. The actor exfiltrated archives to temp.sh and deployed Lynx ransomware, leveraging infrastructure tied to Railnet LLC/Virtualine. #Lynx #RailnetLLC

Read More
Major US Debt Collection Agency Radius Global Solutions Allegedly Breached, Employee HR Data and Client Information Exposed

ResPublica claims it breached Radius Global Solutions LLC in January 2026, compromising one of the company’s contact center branches. The actor’s listing alleges exposure of employee HR records and client information, and Radius was reportedly notified in January but had not publicly disclosed the breach by February 2026. #RadiusGlobalSolutions #ResPublica…

Read More
Major US Debt Collection Agency Radius Global Solutions Allegedly Breached, Employee HR Data and Client Information Exposed

A threat actor using the handle Reve posted an auction offering full unauthorized access — WordPress admin panel, web shell, and database — to an unidentified US-based e-commerce shop. The site runs on WordPress with native Authorize.net payments and logged 952 orders between November 2025 and February 2026, with the actor…

Read More
Threat Actor Offers FTP Server Access to Unidentified France-Based Software Corporation

Anon-WMG posted a forum listing claiming unauthorized FTP server access to an unidentified France-based Content & Collaboration Software company, asserting access to over 2,000 files totaling more than 150 GB. Exposed data reportedly includes VPN configurations, server and database files, backups, and contracts, and the actor is offering the FTP access…

Read More
Inside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker | CloudSEK

CloudSEK researchers infiltrated a newly launched Gunra affiliate program in January 2026, obtaining RaaS management panel credentials and a live ransomware sample for detailed technical analysis. The Gunra locker is an offline-capable, multi-threaded encryptor that uses per-file ChaCha20 keys protected with RSA-4096, selective system exclusions, .ENCRT renaming, and a Tor-based payment portal. #Gunra #CloudSEK

Read More
Dark Web Profile: The Gentlemen Ransomware

The Gentlemen is an operationally disciplined ransomware group first observed in mid-to-late 2025 that conducts double‑extortion attacks across Windows, Linux, NAS, BSD, and ESXi environments using password‑protected, operator-driven builds. Their campaigns leverage exposed internet-facing services and compromised administrative credentials, and victims have been publicly listed on a Dark Web leak site. #TheGentlemen #ESXi

Read More
UK Fast Food Chain Pepe’s Piri Piri Allegedly Breached After Refusing Ransom, 2.1 Million Customer Records Leaked

A threat actor using the handle outcaaaast claims to have leaked Pepe’s Piri Piri’s complete customer database, posting 2,142,234 records allegedly exported from the company’s production database. The listing was published on the open web and the incident is recorded with medium severity in the report. #outcaaaast #PepesPiriPiri…

Read More
Killings, Torturing, and Smuggling: How an Infostealer Exposed an ISIS Cell’s XMPP Network

A single InfoStealer infection on a Lebanon-based machine likely owned by ISIS cell commander Qasura exposed years of encrypted XMPP chat logs, explosive synthesis manuals, and operational files that confirm IED attacks and cross-border logistics. The compromise allowed full mapping of the cell’s hierarchy, finances, smuggling routes, and sharia-sanctioned violence, showing how endpoint compromise can defeat messaging encryption. #InfoStealer #Qasura

Read More
Romania’s Oil Pipeline Operator Hacked: How an Infostealer Infection Paved the Way for Qilin’s Ransomware Attack

Conpet, Romania’s national oil pipeline operator, confirmed a major cyberattack after the Qilin ransomware group claimed to have stolen nearly 1TB of sensitive data. Hudson Rock traced the breach to a single Infostealer infection on an IT employee’s personal computer on January 11, 2026, which leaked credentials (including WSUS and Cacti access) that enabled a likely full network takeover. #Qilin #Infostealer #Conpet #WSUS

Read More
Threat Actor Offers FTP Server Access to Unidentified France-Based Software Corporation

A threat actor using the handle “GordonFreeman” posted a listing claiming to sell access to a vulnerability in Air France that allows entry to an administrative panel. The listing alleges a data extraction method that could expose roughly 2 million customer purchase records and includes samples referencing the Flying Blue frequent…

Read More