A threat actor has allegedly offered 569 GB of data purportedly stolen from cloud security company RapidFort, claiming the archive contains production and development infrastructure, vulnerability intelligence, cloud credentials, CI/CD assets, and Department of Defense-related deployment files.
The sale listing, posted on a cybercrime forum, attributes the alleged compromise to the CanisterWorm campaign and claims the data was obtained in collaboration with TeamPCP several months ago. According to the post, RapidFort allegedly failed to notify customers or publicly disclose the incident before the data was offered for sale.
BreachNews has not independently verified the authenticity of the data or the threat actor’s claims.
Threat actor claims archive spans 48 S3 buckets
According to the forum post, the archive allegedly contains approximately 140,061 files extracted from 48 Amazon S3 buckets totaling 569 GB. The threat actor is seeking $40,000 for the dataset.
According to the forum post, the alleged archive includes:
- Production and development image hardening pipelines
- Vulnerability intelligence databases and CVE enrichment data
- RapidFort’s RFScan tooling and scanner infrastructure
- CI/CD artifacts, Jenkins backups, and DevOps automation
- Kubernetes deployment artifacts and Terraform state files
- CloudFormation templates used for customer onboarding
- Azure build artifacts and release pipelines
- Redis backups, scanner outputs, and Amazon CloudFront logs
- AWS billing exports and infrastructure metadata
- Deployment manifests allegedly associated with Department of Defense environments
Credentials and infrastructure secrets allegedly exposed
The post further claims the archive includes numerous infrastructure secrets, including plaintext AWS credential pairs, Kubernetes kubeconfig files, Azure storage account keys, PostgreSQL credentials, GitLab registry credentials, RSA private keys, EC2 instance credentials, and encryption keys.
If authentic and still active, credentials of this nature could present immediate security risks by enabling unauthorized access to cloud infrastructure, CI/CD environments, source repositories, or production services.
The alleged exposure also reportedly includes customer onboarding CloudFormation templates, Terraform state files, scanner infrastructure, and deployment artifacts associated with RapidFort’s cloud security platform.
Post references Department of Defense deployments
Among the more notable claims, the threat actor alleges the archive contains deployment manifests and pipeline overrides associated with Department of Defense environments, including Helm chart overrides and automation files.
BreachNews has not independently verified these claims or confirmed whether any of the referenced files relate to active government systems.
Linked to the CanisterWorm campaign
The forum post explicitly attributes the alleged theft to the CanisterWorm campaign conducted alongside TeamPCP. Earlier this year, BreachNews published a profile examining TeamPCP and the group’s alleged involvement in a series of cloud-focused intrusions and data theft operations.
If accurate, the latest sale would represent one of the largest datasets publicly attributed to the campaign to date. However, RapidFort has not confirmed the alleged incident, and the origin of the purported data remains unverified.












