> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Hungarian State Treasury Allegedly Compromised, Actor Claims vCenter and Identity Vault Access
- URL: https://darkwebinformer.com/hungarian-state-treasury-allegedly-compromised-actor-claims-vcenter-and-identity-vault-access/
- Published: 2026-07-31T15:10:20.000Z
- Updated: 2026-07-31T15:10:20.000Z
- Author: Dark Web Informer
- Tags: Initial Access

Intrusion Claim ![Hungary flag](https://flagcdn.com/w40/hu.png)Hungary Government / Treasury Selective Sale 

## Hungarian State Treasury Allegedly Compromised, Actor Claims vCenter and Identity Vault Access

A threat actor posting as **bytetobreach** claims to have compromised the **Magyar Államkincstár**, Hungary's State Treasury, which administers state payments, pensions, family benefits, and EU funding. Rather than publishing records, the post presents **13 screenshots documenting a claimed intrusion chain**, with captions describing initial foothold, persistence, exposed **JDWP** and **Oracle WebLogic** services, movement across an **Active Directory forest trust**, access to an **Oracle Identity Manager vault**, endpoint security evasion, and finally **VMware vCenter takeover**. The actor states the data is **not for open sale and that no ransom has been demanded**. The claim is **unverified**.

Severity CRITICAL 

Evidence13 screenshots

Claimed depthvCenter

Country![Hungary flag](https://flagcdn.com/w40/hu.png)Hungary

Actorbytetobreach

### ▣Post details

TargetMagyar Államkincstár

Country![Hungary flag](https://flagcdn.com/w40/hu.png)Hungary

SectorGovernment / Public finance

ListingNot for open sale, no ransom

Entry pointSubdomain via forest trust

EvidenceScreenshots, no data sample

ObservedJul 31, 2026

Actorbytetobreach

### !Claimed access

- Initial foothold
- Persistence established
- Exposed JDWP service
- Oracle WebLogic
- AD forest trust crossing
- Identity system access
- Oracle Identity Manager vault
- Service principal evaluation
- Storage systems
- Endpoint security evasion
- VMware vCenter takeover
- Historical records

### ◱Screenshot

[ ![Hungarian State Treasury intrusion claim forum post screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/12937854692876359287656189764589712.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/12937854692876359287656189764589712.png) 

### ⚠Potential impact

This is an **intrusion claim rather than a data leak**, and the depth described is what matters. **vCenter controls the virtualisation layer**, meaning every hosted system rather than any single server, while an **identity manager vault** governs credentials across the estate. If accurate, remediation is not patching but rebuilding trust in the environment. The Treasury administers pensions, family benefits, and EU funds, so the affected population is effectively national. The claimed **forest trust crossing** also raises whether connected government domains were reachable. The claim is unverified.

### iStatus

Unverified 

Evidence is **13 captioned screenshots and no data sample**, so scale cannot be assessed. The stated position, no ransom and no open sale, is unusual and leaves the motive unclear. This is the same actor behind a claimed breach of **Georgia's judiciary** weeks earlier. Mirrors and contact routes are withheld. The claim is **unverified** and the Treasury has not publicly addressed it.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE