Public-Sector Breach Claims Span Three Regions
Summary
Public agencies and identity-rich services faced a broad mix of alleged intrusion, leak, and access activity across several regions. The overlap between exposed public-facing applications and claims against telecom, healthcare, and financial organizations increases the chance that stolen credentials will be reused across sectors. Immediate risk reduction depends on patching internet-facing software and separating privileged access from credentials used in customer and citizen services.
Today's developments
Forum claims were concentrated in government and public-service targets. Arcepahs channel claims an alleged breach of the Supreme Court of Justice of the State of Jalisco in Mexico. Neffex THe BlackHat claims an alleged breach of Belitung Regency in Indonesia, while gerome99 claims the alleged sale of access associated with Australia's Department of Foreign Affairs and Trade. BlackHatSect0r claims an alleged breach of the Labour Commissionerate of Kerala in India. Disrupt0r claims alleged breaches of the Karnataka Skill Development Corporation and Brihanmumbai Municipal Corporation, also in India. l1ghtSoulHem claims alleged leaks involving Argentina's Cordoba Provincial Police, Neuquen Judicial Branch, and Municipality of Formosa. cutzinger claims an alleged breach of Mexican telecom provider Telcel, HACKSAW claims an alleged breach of France's SFR, and Edric claims an alleged leak involving India's Airtel. Keishell separately claims alleged breaches of OpenStreetMap in the United Kingdom and AFLIT in Malawi.
Security reporting showed how software exploitation could compound those access claims. A GitLab GraphQL flaw, CVE-2026-19478 with a reported CVSS score of 9.4, could let unauthenticated attackers delete public projects. Forminator's CVE-2026-15748, scored 9.8, could enable unauthenticated remote code execution through a malicious upload. Reporting on SafePal said a breach affected nearly 40,000 users, while Polish authorities were examining a MyDr healthcare software incident that could affect 19 million people. France's tax authority disclosed an incident affecting 680,000 people. Kaspersky researchers described Cavern C2 using DNS and Google Apps Script to disguise command traffic in operations attributed to Iranian actors against Israeli targets. Ukraine's military intelligence also claimed that a cyberattack disrupted Russia's Wildberries marketplace during the same period.
Threat landscape signals
The dataset recorded 252 events, down 27.2% from 346 on the prior day. Alleged breach and leak exposures fell from 93 to 64, but they still represented 25.4% of the day's activity. Trenggalek Cyber Army, Learn Exploit, and Meduza Locker accounted for 82 events, or 32.5% of the total. Defacement remained the largest category at 74 events, while ransomware declined from 41 to 35 and DDoS activity edged down from 27 to 25.
Government Administration led the industry distribution with 34 events. The United States and Iran each recorded 30 events, followed by India with 25 and Indonesia with 15. The operational priority is therefore narrower than the geographic spread suggests: inventory exposed GitLab and WordPress instances, patch the two high-severity flaws, rotate credentials used by telecom and public-service portals, and monitor for the same accounts appearing across government, healthcare, and financial systems.