Skip to content

Hungarian State Treasury Allegedly Compromised, Actor Claims vCenter and Identity Vault Access

Intrusion Claim Hungary flagHungary Government / Treasury Selective Sale

Hungarian State Treasury Allegedly Compromised, Actor Claims vCenter and Identity Vault Access

A threat actor posting as bytetobreach claims to have compromised the Magyar Államkincstár, Hungary's State Treasury, which administers state payments, pensions, family benefits, and EU funding. Rather than publishing records, the post presents 13 screenshots documenting a claimed intrusion chain, with captions describing initial foothold, persistence, exposed JDWP and Oracle WebLogic services, movement across an Active Directory forest trust, access to an Oracle Identity Manager vault, endpoint security evasion, and finally VMware vCenter takeover. The actor states the data is not for open sale and that no ransom has been demanded. The claim is unverified.

Evidence13 screenshots
Claimed depthvCenter
CountryHungary flagHungary
Actorbytetobreach

Post details

TargetMagyar Államkincstár
CountryHungary flagHungary
SectorGovernment / Public finance
ListingNot for open sale, no ransom
Entry pointSubdomain via forest trust
EvidenceScreenshots, no data sample
Observed
Actorbytetobreach

!Claimed access

  • Initial foothold
  • Persistence established
  • Exposed JDWP service
  • Oracle WebLogic
  • AD forest trust crossing
  • Identity system access
  • Oracle Identity Manager vault
  • Service principal evaluation
  • Storage systems
  • Endpoint security evasion
  • VMware vCenter takeover
  • Historical records

Screenshot

Potential impact

This is an intrusion claim rather than a data leak, and the depth described is what matters. vCenter controls the virtualisation layer, meaning every hosted system rather than any single server, while an identity manager vault governs credentials across the estate. If accurate, remediation is not patching but rebuilding trust in the environment. The Treasury administers pensions, family benefits, and EU funds, so the affected population is effectively national. The claimed forest trust crossing also raises whether connected government domains were reachable. The claim is unverified.

iStatus

Unverified

Evidence is 13 captioned screenshots and no data sample, so scale cannot be assessed. The stated position, no ransom and no open sale, is unusual and leaves the motive unclear. This is the same actor behind a claimed breach of Georgia's judiciary weeks earlier. Mirrors and contact routes are withheld. The claim is unverified and the Treasury has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest