pwshub.com

Cyber-crook leaks 20GB of data 'stolen' from Capgemini

A miscreant claims to have broken into Capgemini and leaked a large amount of sensitive data stolen from the technology services giant – including source code, credentials, and T-Mobile's virtual machine logs.

The French multinational IT and consulting firm did not immediately respond to The Register's request for comment, and has yet to formally confirm or deny the cyber-criminal's claims. We will update this story if and when a spokesperson replies to our inquiries. We had heard rumblings of a recent security breach at Capgemini, which earlier declined to comment on those rumors.

According to a BreachForums post today announcing the leak, a crook who goes by "grep" said they allegedly compromised Capgemini this month and swiped 20GB of data from the biz. This is said to include some databases, source code, private keys, credentials, API keys, projects, employee data, and other information.

In portions of the leaked information reviewed by The Register we could see lists of Capgemini employees with what looks like their names, email addresses, usernames, and password hashes. There were also what appeared to backup archives, and files related to Capgemini clients, including internal configuration details for their cloud infrastructure.

"They had more data but I decided to exfiltrate only big files, company confidential, Terraform, and many more," the thief wrote. As well as offering the stolen data to fellow forum users, grep also shared some select samples, including what's said to be T-Mobile VM logs. Screenshots of the allegedly stolen data posted on X appear to show customer info.

Capgemini generated more than €22 billion (about $24 billion) in revenue in 2023.

  • Capgemini wins deal with UK tax collector worth up to £574M
  • Capgemini to keep the legacy lights on at HMRC for £245.5M
  • Transport for London confirms 5,000 users' bank data exposed, pulls large chunks of IT infra offline
  • So you paid a ransom demand … and now the decryptor doesn't work

In July, the consultancy won a controversial UK government contract worth up to £574 million.

Under the lucrative deal, valued between £403 million and £574 million, Capgemini will run legacy tax management systems for His Majesty's Revenue and Customs until 2029.

Both of the services in the contract, Enterprise Tax Management Platform (ETMP) and Enterprise Operations (EOPS), run SAP ECC 6.0, a legacy system from the German software giant that exits mainstream support at the end of 2027. ®

Source: theregister.com

Related stories
1 month ago - Whether attack slowdown continues downward trend is the million dollar question that security researchers can't answer Critical industrial organizations continued to be hammered by ransomware skids in July, while experts suggest the perps...
1 month ago - Names, addresses, Social Security numbers, more all out there A Florida firm has all but confirmed that millions of people's sensitive personal info was stolen from it by cybercriminals and publicly leaked.…
1 month ago - They say crime doesn't pay. They're right – it's the victims doing the paying An unnamed Fortune 50 corporation paid a stonking $75 million to a ransomware gang to stop it leaking terabytes of stolen data.…
1 month ago - Anydesk is its access tool of choice A new extortion gang called Mad Liberator uses social engineering and the remote-access tool Anydesk to steal organizations' data and then demand a ransom payment, according to Sophos X-Ops.…
3 weeks ago - The government-backed crew also enjoys ransomware as a side hustle Iranian government-backed cybercriminals have been hacking into US and foreign networks as recently as this month to steal sensitive data and deploy ransomware, and...
Other stories
7 minutes ago - After California passed laws cracking down on AI-generated deepfakes of election-related content, a popular conservative influencer promptly sued,...
30 minutes ago - Act fast to grab this high-performing mesh router for less than $500, keeping you connected while saving some cash too.
30 minutes ago - If the old-school PlayStation is dear to your heart, you can soon relive those totally sweet 1990s memories. Sony is releasing a series of products...
31 minutes ago - If you've got an old phone to part with, T-Mobile is offering both new and existing customers the brand-new Apple iPhone 16 Pro for free with this trade-in deal.
31 minutes ago - Who doesn't want the best for their beloved pooch? Grab some of these tasty treats to make your dog feel special.