United States
Technology / Security Vendor
Data for Sale
RapidFort Allegedly Breached in CanisterWorm Campaign, 569GB Across 48 S3 Buckets Listed for $40,000
A threat actor posting as xpl0itrs is advertising the sale of data they claim to have taken from RapidFort, a US container hardening and software supply chain security vendor. The listing attributes the intrusion to a campaign the poster calls CanisterWorm, carried out with a group named TeamPCP, and describes 569GB across 140,061 files extracted from 48 S3 buckets. The seller publishes a detailed bucket-by-bucket manifest covering hardening pipelines, a vulnerability database pipeline said to account for roughly 235GB, scanner backends, DevOps infrastructure, and billing exports, and claims the set contains plaintext cloud credentials, Kubernetes kubeconfigs, and private keys. The actor further claims the data dates to March and that customers were never notified. The asking price is $40,000, negotiable. The claim is unverified.
▣Post details
United States!Allegedly included
- Vulnerability DB pipeline (~235GB)
- Image hardening pipelines
- AWS credential pairs
- Kubernetes kubeconfigs (AKS)
- GitLab & PostgreSQL creds
- Azure storage account key
- RSA and encryption keys
- EC2 instance credentials
- DoD pipeline & deploy configs
- Customer CloudFormation templates
- Jenkins build server backups
- Redis scanner DB dumps
- CloudFront CDN access logs
- AWS billing & usage exports
◱Screenshots
⚠Potential impact
The concern with a claim like this is not the volume, it is the position the vendor occupies. RapidFort sits inside its customers' build and deployment pipelines, and the manifest describes per-customer CloudFormation templates that provision cross-account IAM roles so the platform can scan customer images, snapshots, and volumes. If that material is authentic, the exposure is not confined to one company: it maps trust relationships reaching into every environment that onboarded the scanner. The claimed presence of plaintext AWS credential pairs, AKS kubeconfigs with service principal auth, database credentials, a full Azure storage account key, and RSA private keys would compound that, since any still-valid secret is a live path rather than a historical record. The listing also advertises Department of Defense pipeline automation and deployment manifests, which would carry its own set of consequences. Separately, the manifest itself is a detailed map of internal architecture, useful to any actor planning a follow-on intrusion whether or not the data ever sells. The claim is unverified.
iStatus
UnverifiedThe post is a sale listing with an unusually granular manifest, offered at a fixed but negotiable price with cryptocurrency and encrypted messenger contact routes, which Dark Web Informer has withheld. The seller alleges the data dates to March 2026 and that no breach notification or customer disclosure has been issued. That allegation is the seller's own and should be treated as a claim rather than a finding. The claim is unverified and RapidFort has not publicly addressed it. Organisations using the platform may wish to review cross-account role trust policies and rotate any credentials shared with or generated for the service.
DARK WEB INFORMER - THREAT INTELLIGENCE