RapidFort Data Breach Allegedly Exposes AWS Credentials and Internal Assets

A threat actor claims to be selling 569 GB of data allegedly stolen from RapidFort, including cloud infrastructure, credentials, vulnerability intelligence, and development assets.
Cropped screenshot of a cybercrime forum post claiming to sell 569 GB of data allegedly stolen from RapidFort during the CanisterWorm campaign, describing the alleged breach, data size, pricing, and the first several Amazon S3 buckets. Contact details have been blurred.
Cropped version of a forum post in which a threat actor claims to be selling 569 GB of data allegedly stolen from RapidFort during the CanisterWorm campaign. The original post continues with a detailed inventory of the purported data, infrastructure assets, and credentials.

A threat actor has allegedly offered 569 GB of data purportedly stolen from cloud security company RapidFort, claiming the archive contains production and development infrastructure, vulnerability intelligence, cloud credentials, CI/CD assets, and Department of Defense-related deployment files.

The sale listing, posted on a cybercrime forum, attributes the alleged compromise to the CanisterWorm campaign and claims the data was obtained in collaboration with TeamPCP several months ago. According to the post, RapidFort allegedly failed to notify customers or publicly disclose the incident before the data was offered for sale.

BreachNews has not independently verified the authenticity of the data or the threat actor’s claims.

Threat actor claims archive spans 48 S3 buckets

According to the forum post, the archive allegedly contains approximately 140,061 files extracted from 48 Amazon S3 buckets totaling 569 GB. The threat actor is seeking $40,000 for the dataset.

According to the forum post, the alleged archive includes:

  • Production and development image hardening pipelines
  • Vulnerability intelligence databases and CVE enrichment data
  • RapidFort’s RFScan tooling and scanner infrastructure
  • CI/CD artifacts, Jenkins backups, and DevOps automation
  • Kubernetes deployment artifacts and Terraform state files
  • CloudFormation templates used for customer onboarding
  • Azure build artifacts and release pipelines
  • Redis backups, scanner outputs, and Amazon CloudFront logs
  • AWS billing exports and infrastructure metadata
  • Deployment manifests allegedly associated with Department of Defense environments

Credentials and infrastructure secrets allegedly exposed

The post further claims the archive includes numerous infrastructure secrets, including plaintext AWS credential pairs, Kubernetes kubeconfig files, Azure storage account keys, PostgreSQL credentials, GitLab registry credentials, RSA private keys, EC2 instance credentials, and encryption keys.

If authentic and still active, credentials of this nature could present immediate security risks by enabling unauthorized access to cloud infrastructure, CI/CD environments, source repositories, or production services.

The alleged exposure also reportedly includes customer onboarding CloudFormation templates, Terraform state files, scanner infrastructure, and deployment artifacts associated with RapidFort’s cloud security platform.

Post references Department of Defense deployments

Among the more notable claims, the threat actor alleges the archive contains deployment manifests and pipeline overrides associated with Department of Defense environments, including Helm chart overrides and automation files.

BreachNews has not independently verified these claims or confirmed whether any of the referenced files relate to active government systems.

Linked to the CanisterWorm campaign

The forum post explicitly attributes the alleged theft to the CanisterWorm campaign conducted alongside TeamPCP. Earlier this year, BreachNews published a profile examining TeamPCP and the group’s alleged involvement in a series of cloud-focused intrusions and data theft operations.

If accurate, the latest sale would represent one of the largest datasets publicly attributed to the campaign to date. However, RapidFort has not confirmed the alleged incident, and the origin of the purported data remains unverified.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site