> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# RapidFort Allegedly Breached in CanisterWorm Campaign, 569GB Across 48 S3 Buckets Listed for $40,000
- URL: https://darkwebinformer.com/rapidfort-allegedly-breached-in-canisterworm-campaign-569gb-across-48-s3-buckets-listed-for-40-000/
- Published: 2026-07-21T21:07:37.000Z
- Updated: 2026-07-21T21:07:37.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Technology / Security Vendor Data for Sale 

## RapidFort Allegedly Breached in CanisterWorm Campaign, 569GB Across 48 S3 Buckets Listed for $40,000

A threat actor posting as **xpl0itrs** is advertising the sale of data they claim to have taken from **RapidFort**, a US container hardening and software supply chain security vendor. The listing attributes the intrusion to a campaign the poster calls **CanisterWorm**, carried out with a group named **TeamPCP**, and describes **569GB across 140,061 files extracted from 48 S3 buckets**. The seller publishes a detailed bucket-by-bucket manifest covering hardening pipelines, a vulnerability database pipeline said to account for roughly 235GB, scanner backends, DevOps infrastructure, and billing exports, and claims the set contains **plaintext cloud credentials, Kubernetes kubeconfigs, and private keys**. The actor further claims the data dates to **March** and that customers were never notified. The asking price is **$40,000, negotiable**. The claim is **unverified**.

Severity CRITICAL 

Data569GB

Files140,061

Price$40,000

Actorxpl0itrs

### ▣Post details

TargetRapidFort

Country![United States flag](https://flagcdn.com/w40/us.png)United States

SectorTechnology / Cybersecurity

ListingData for sale — $40k negotiable

Volume569GB / 140,061 files

Source48 S3 buckets

ObservedJul 21, 2026

CampaignCanisterWorm / TeamPCP

### !Allegedly included

- Vulnerability DB pipeline (\~235GB)
- Image hardening pipelines
- AWS credential pairs
- Kubernetes kubeconfigs (AKS)
- GitLab & PostgreSQL creds
- Azure storage account key
- RSA and encryption keys
- EC2 instance credentials
- DoD pipeline & deploy configs
- Customer CloudFormation templates
- Jenkins build server backups
- Redis scanner DB dumps
- CloudFront CDN access logs
- AWS billing & usage exports

### ◱Screenshots

[ ![RapidFort CanisterWorm data breach forum post screenshot, July 2026 (1 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723651.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723651.png) [ ![RapidFort CanisterWorm data breach forum post screenshot, July 2026 (2 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723652.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723652.png) [ ![RapidFort CanisterWorm data breach forum post screenshot, July 2026 (3 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723653.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723653.png) [ ![RapidFort CanisterWorm data breach forum post screenshot, July 2026 (4 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723654.png) Screenshot 4 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/1239785629873659872635987263589723654.png) 

### ⚠Potential impact

The concern with a claim like this is not the volume, it is the position the vendor occupies. RapidFort sits inside its customers' build and deployment pipelines, and the manifest describes **per-customer CloudFormation templates that provision cross-account IAM roles** so the platform can scan customer images, snapshots, and volumes. If that material is authentic, the exposure is not confined to one company: it maps trust relationships reaching into every environment that onboarded the scanner. The claimed presence of **plaintext AWS credential pairs, AKS kubeconfigs with service principal auth, database credentials, a full Azure storage account key, and RSA private keys** would compound that, since any still-valid secret is a live path rather than a historical record. The listing also advertises **Department of Defense pipeline automation and deployment manifests**, which would carry its own set of consequences. Separately, the manifest itself is a detailed map of internal architecture, useful to any actor planning a follow-on intrusion whether or not the data ever sells. The claim is unverified.

### iStatus

Unverified 

The post is a sale listing with an unusually granular manifest, offered at a fixed but negotiable price with cryptocurrency and encrypted messenger contact routes, which **Dark Web Informer has withheld**. The seller alleges the data dates to March 2026 and that **no breach notification or customer disclosure has been issued**. That allegation is the seller's own and should be treated as a claim rather than a finding. The claim is **unverified** and RapidFort has not publicly addressed it. Organisations using the platform may wish to review cross-account role trust policies and rotate any credentials shared with or generated for the service.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE