🇯🇵 Japan - Keio University & University of Tokyo Student Databases
1,739 Student Records Allegedly Offered for Sale
A threat actor is advertising the sale of two allegedly compromised databases associated with Japanese university-focused platforms, claiming to contain personal information, photographs, and account credentials belonging to students from some of Japan's most prestigious academic institutions.
According to the forum post, the dataset allegedly includes records from:
* https://t.co/TlsuDEvtP1 (Keio University community platform)
* UTopia / https://t.co/ypw5izg3Il (University of Tokyo student platform)
The actor claims the combined dataset contains:
* 1,739 user accounts
* Email addresses
* Plaintext passwords
* Profile photographs
* Personal profile information
* Student-related identity information
Alleged Keio University Dataset Details:
* Approximately 1,600 users
* 1,596 email addresses
* 1,356 plaintext passwords
* 484 Gmail accounts
* 1,587 profile photographs
* Name, gender, date of birth, school, company, biography, city, and photo data
Alleged University of Tokyo Dataset Details:
* 139 users
* KYC-related identity verification information
* Student identification data
* Profile photographs
* Email addresses
* Names
* Gender and age information
* University affiliation
* Additional personal profile attributes
Potential Risks:
* Credential stuffing attacks against university and personal accounts
* Identity theft targeting students and alumni
* Social engineering and spear-phishing campaigns
* Exposure of student photographs and sensitive personal information
* Reputational harm and privacy violations
* Long-term intelligence collection against future government, academic, and business leaders
Analyst Note: Although the total number of records is relatively small compared to large commercial breaches, the alleged presence of plaintext passwords, student identity information, and profiles linked to elite academic institutions significantly increases the intelligence value of the dataset. Such records can be leveraged for targeted recruitment, espionage, social engineering, and long-term profiling activities.
#DDW #Intelligence #DarkWeb #Japan
‼️🚨 BREAKING: 320,000 Fortinet firewall devices have been targeted in a campaign that has been dubbed 'FortiBleed'. Attackers were able to confirm 75,000 working credentials against the admin and SSL VPN interfaces.
The victims include really big names like Samsung, Oracle, Spotify, Sony, and more.
The data was first surfaced by researcher Volodymyr "Bob" Diachenko and analyzed by Hudson Rock and SOCRadar. The operation runs as a self-feeding loop. Attackers scan the internet for exposed Fortinet devices, then test each one against a curated list of passwords leaked from earlier Fortinet breaches and infostealer logs. Every successful login gets recorded into a verified database. They then turn each compromised box into a listening post, sniffing the traffic passing through the firewall to harvest fresh credentials, which go straight back into the scanner.
The scale is large. The group ran an estimated 1.16 billion credential attempts against more than 320,000 FortiGate targets, plus 2.1 billion brute-force tries against 160,000 MSSQL servers. In the deeper intrusions they intercept SSL VPN authentication hashes, crack them on a dedicated 45-GPU cluster, and move into internal Active Directory.
Diachenko confirmed full network compromises in Japan, Taiwan, Vietnam, Iraq, and Turkey, including a Turkish NATO defense contractor that had classified defense documents stolen.
If you run Fortinet, act now: rotate every VPN and admin credential, enforce MFA on all external gateways, restrict management access to approved sources, segment internal networks, and audit gateway logs for unusual logins. Hudson Rock has a free domain lookup at https://t.co/KLv2YiMtpm.
Data surfaced via the Hunt Intelligence, Inc. feed.
‼️FortiBleed Leak Linked to Massive Fortinet Credential Harvesting Campaign
Security researcher Bob Diachenko discovered the FortiBleed leak, exposing Fortinet/FortiGate VPN credentials for 73,932 firewall URLs across 21,632 domains in 194 countries.
A Russian-speaking threat actor allegedly conducted a large-scale credential harvesting campaign involving 1.16 billion attacks against 320,777 FortiGate devices and 2.1 billion attempts against 163,650 Microsoft SQL Server systems.
Source: https://t.co/qXnFd7sx7y