☠ [LEAK] ACME Corp - Full Database Dump + Internal Documents (890 GB)
Posted by ShinyHunters - 2026-10-07 14:23 UTC - Views: 47,832 - Replies: 312
We are releasing the full database dump and internal documents from ACME Corporation. Access was maintained for 23 days through a compromised VPN endpoint (Fortinet CVE-2026-1847). Exfiltration completed before detection.
WHAT'S INCLUDED
● Full customer database (12.4M records) - names, emails, phones, addresses, SSNs
● Employee records (8,200+) - PII, salaries, performance reviews, medical claims
● Financial data - bank statements, wire transfers, tax filings 2022-2026
● Email archives - CEO, CFO, CTO, Legal Counsel (PST exports, 14 GB)
● Source code repositories - proprietary algorithms, API keys, credentials
● Active Directory dump - all user hashes, service accounts, GPO configs
● Network infrastructure - firewall rules, VPN configs, SSL private keys
● Board meeting minutes + M&A documents (Project Phoenix, $340M deal)
● GDPR compliance reports showing known vulnerabilities left unpatched
● Cyber insurance policy details including coverage limits and exclusions
⚠ NOTICE TO ACME CORP
We attempted to contact your security team via your responsible disclosure program. No response was received after 14 days. The full dataset will be published for free on October 14, 2026 if no agreement is reached. Contact us via the marketplace chat with your company domain as proof of identity. Clock is ticking.
Free sample data published as proof of breach. Redacted for preview - full records available to buyers.
--- CUSTOMER DATABASE SAMPLE (50 of 12,401,832 records) ---
========================================================================
ID |
FULL NAME |
EMAIL |
SSN
--------+------------------------+----------------------------------+-----------
1048201 | Robert M. Henderson | r.henderson@outlook.com | ***-**-4821
1048202 | Sarah K. Whitfield | s.whitfield.pro@gmail.com | ***-**-7734
1048203 | James T. O'Brien | jtobrien@yahoo.com | ***-**-2198
1048204 | Maria L. Gonzalez | mlgonzalez.work@gmail.com | ***-**-5543
1048205 | David Chen | d.chen.88@outlook.com | ***-**-9012
1048206 | Jennifer A. Williams | jaw.consulting@gmail.com | ***-**-3367
1048207 | Michael R. Patel | mpatel.dev@protonmail.com | ***-**-8845
... 12,401,825 more records ...
[FULL SSN/DOB/ADDRESS AVAILABLE IN PAID VERSION]
--- EMPLOYEE SALARY DATA SAMPLE ---
========================================================================
EMP_ID |
NAME |
DEPARTMENT |
SALARY |
BONUS
--------+------------------------+---------------+-------------+--------
E-00142 | Thomas Wright (CEO) | Executive | $892,000/yr | $340,000
E-00143 | Claire Dubois (CFO) | Executive | $745,000/yr | $285,000
E-00144 | Raj Krishnamurthy (CTO) | Executive | $698,000/yr | $260,000
E-00251 | Amanda Foster | Engineering | $185,000/yr | $42,000
E-00252 | Yuki Tanaka | Engineering | $172,000/yr | $38,000
E-00401 | Brian McAllister | Sales | $124,000/yr | $67,000
... 8,194 more records ...
--- ACTIVE DIRECTORY HASH DUMP (PARTIAL) ---
========================================================================
Administrator:500:aad3b435b51404eeaad3b435b51404ee:fc525c9683e8fe067095ba2ddc971889:::
t.wright:1104:aad3b435b51404eeaad3b435b51404ee:7a21990fcd3d759941e45c490f143d5f:::
c.dubois:1105:aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42:::
r.krishnamurthy:1106:aad3b435b51404eeaad3b435b51404ee:b4b9b02e6f09a9bd760f388b67351e2b:::
svc_backup:1201:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
svc_sql:1202:aad3b435b51404eeaad3b435b51404ee:a87f3a337d73085c45f9416be5787d86:::
... 4,891 more hashes ...
[NTLM HASHES - CRACKABLE WITH HASHCAT]
--- EMAIL EXCERPT - CEO INBOX (Project Phoenix M&A) ---
========================================================================
From: t.wright@acmecorp.com
To: c.dubois@acmecorp.com, legal@acmecorp.com
Date: 2026-09-12 09:14:22 UTC
Subject: RE: Project Phoenix - Final Offer
Claire,
Board approved the revised offer at $340M. We need to close before Q4 earnings
or the stock price impact will kill the deal. Legal is preparing the LOI for
signature by Friday.
DO NOT share this outside the exec team until the 8-K filing.
- Tom
... 23,891 more emails across 5 executive mailboxes ...
Aggregated threat intelligence related to this breach
⚠ CRITICAL - Active Data Breach in Progress
ACME Corporation has suffered a major data breach. Threat actor "ShinyHunters" (tracked as TA-4721) claims 890 GB of exfiltrated data including customer PII, financial records, and proprietary source code. Initial access via Fortinet VPN - CVE-2026-1847 (CVSS 9.8). Dwell time: 23 days. Data is actively being sold on BreachForums.
CVE-2026-1847
DATA BREACH
CRITICAL
Timeline of Events
Sep 14, 2026 - Initial access via compromised Fortinet VPN (CVE-2026-1847)
Sep 15-18 - Lateral movement, privilege escalation to Domain Admin
Sep 19-25 - Data exfiltration phase 1 (databases, email archives)
Sep 26 - Oct 02 - Data exfiltration phase 2 (source code, configs, documents)
Oct 05 - ACME SOC detects anomalous outbound traffic, begins investigation
Oct 06 - Threat actor loses access, exfiltration complete
Oct 07 - Data listed on BreachForums by ShinyHunters
Oct 08 - ACME engages incident response firm (Mandiant)
Oct 14 - Threatened full public release
TIMELINE
INCIDENT RESPONSE
Indicators of Compromise (IOCs)
C2 Infrastructure:
185.220.101.42 (Tor exit node - Netherlands)
91.243.44.156 (Bulletproof hosting - Moldova)
exfil-drop.onion:8443 (Exfiltration endpoint)
File Hashes (Tools):
SHA256: 3a7b9f2e8d1c4b6a5e0f7d9c2b4a6e8f1d3c5b7a9e0f2d4c6b8a0e1f3d5c7b - rclone.exe (modified)
SHA256: 9e8d7c6b5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6f5e4d3c2b1a0f9e - mimikatz_custom.exe
SHA256: 2b4c6d8e0f1a3b5c7d9e1f3a5b7c9d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b - procdump64.exe
Persistence:
Scheduled Task: \Microsoft\Windows\Maintenance\SysHealthCheck
Registry: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SysMonitor
Service: WinDefenderUpdate (masquerading)
IOC
C2
PERSISTENCE
Recommended Actions
1. Immediately patch Fortinet VPN - CVE-2026-1847
2. Reset ALL domain credentials and service account passwords
3. Revoke and rotate all SSL/TLS certificates and API keys
4. Engage legal counsel for GDPR/regulatory notification requirements
5. Notify affected customers within 72 hours (GDPR Article 33)
6. Block identified C2 IP addresses at perimeter firewall
7. Hunt for identified IOCs across all endpoints
8. Preserve forensic evidence - do not wipe systems until investigation complete
9. Engage cyber insurance carrier
10. Prepare SEC 8-K filing for material cybersecurity incident
REMEDIATION
COMPLIANCE