← RapidFort

2026 RapidFort — CanisterWorm / TeamPCP S3 sale claim; 569GB across 48 buckets (unverified)

2026 Unknown records affected Share on X

Data compromised

Actor-claimed ~569GB / 140,061 files from 48 S3 buckets (~$40k asking price): vulnerability-DB and image-hardening pipelines, plaintext cloud credentials, AKS kubeconfigs, GitLab/PostgreSQL creds, Azure storage key, RSA/private keys, customer CloudFormation templates, Jenkins backups, billing exports — unverified; no individual victim headcount cited

Technical writeup

Unverified leak-site / forum sale claim — observed July 21, 2026 by Dark Web Informer. Actor “xpl0itrs” advertised alleged RapidFort data from a campaign labeled CanisterWorm (with TeamPCP), describing 569GB across 140,061 files taken from 48 S3 buckets and priced around $40,000 negotiable. The listing’s bucket-level manifest allegedly covers hardening and vulnerability-database pipelines, DevOps infrastructure, billing exports, and secrets including AWS credential pairs, Kubernetes kubeconfigs, database credentials, and private keys, plus claimed per-customer CloudFormation / cross-account IAM material. Seller alleged data dated to March 2026 and that customers had not been notified—those statements are the actor’s alone. RapidFort had not publicly confirmed the claim in sources reviewed. BreachHistory indexes recordsAffected 0 (no individual count cited) and labels the row unverified.

Root cause

Unverified underground sale listing by actor “xpl0itrs” attributing intrusion to CanisterWorm campaign with TeamPCP; alleged extraction from 48 S3 buckets — RapidFort had not confirmed at indexing time

References