Skywalk Group Allegedly Breached as WordPress Database and Source Code Leaked

A threat actor claims to have stolen Skywalk Group's WordPress database and website source code, publishing a directory tree as purported evidence of the alleged breach.
Screenshot of a cybercrime forum post alleging a breach of Skywalk Group, claiming the theft of the company’s WordPress database and website source code, with the Skywalk Group logo shown prominently.
Screenshot of the forum post in which a threat actor claims to have breached Skywalk Group and stolen its WordPress database and website source code.

A threat actor claims to have breached Skywalk Group, a manufacturer of equipment for action and wind sports, and is offering what they describe as the company’s WordPress website database alongside the site’s source code. At the time of publication, Skywalk Group had not issued any public statement regarding the alleged incident.

WordPress site allegedly compromised

According to a post published on a cybercrime forum, the threat actor claims the breach occurred in August 2026 and resulted in the theft of the WordPress website database and full website source code. The post includes a directory tree as purported proof of access and states the leaked archive contains both the SQL database and website files.

The shared directory listing appears to include a WordPress installation with the primary database dump (wp_skywalkgroup.sql), standard WordPress core files, and directories such as wp-content, themes, plugins, cache folders, and configuration files.

Part of a broader series of alleged website breaches

This claim follows several recent forum posts alleging compromises of WordPress-powered websites in which source code and databases were purportedly obtained. BreachNews previously reported on a similar claim involving Go-Flare, where a directory tree was also published as purported evidence.

In this case, no customer records or database contents were publicly previewed beyond the directory listing. As a result, it is not currently possible to independently verify what information, if any, may have been exposed.

Potential impact

If authentic, a WordPress database and corresponding website source code could expose administrator accounts, hashed passwords, customer or subscriber information stored by the site, configuration details, and proprietary web assets. Access to both the database and source code could also provide insight into the site’s underlying infrastructure and custom functionality.

The forum post includes a directory tree that appears consistent with a WordPress installation and advertises a downloadable archive containing the purported database and source code. BreachNews has not independently accessed or verified the contents of the archive, and Skywalk Group had not issued any public statement regarding the alleged incident at the time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site