A newly created forum account is claiming access to portions of Wickr Enterprise infrastructure, publishing what it describes as evidence from an internal administrative API associated with Amazon Web Services.
The post, published on June 10, alleges access to a Wickr Enterprise Admin API and includes a partial HTTP response containing references to internal service operations, administrative infrastructure, and what the actor claims are production related credentials.
While the disclosure contains more technical detail than many low credibility forum posts, the available evidence does not independently confirm a broader compromise of Wickr Enterprise systems or customer environments.
Actor publishes alleged internal API response
The threat actor, operating under the name Orcinus orca, published a brief proof-of-access post claiming visibility into Wickr Enterprise administrative systems.
According to the post, the actor obtained access to an internal administrative API operating behind AWS infrastructure. The published response contains references to an internal AWS administrative console domain and an Envoy service operation identified as an administrative API endpoint.
The actor also claims the response exposed internal API information and production payment processing credentials. BreachNews is not reproducing the alleged credentials contained in the post.
The forum account described the disclosure as evidence of deep access into Wickr Enterprise infrastructure. However, no additional screenshots, internal documents, source code, databases, or administrative console access were provided to support the broader claim.
Claim lacks evidence of customer impact
The information published by the actor appears to show interaction with a backend service, but it does not demonstrate administrative control of Wickr systems, access to enterprise tenants, access to user communications, or compromise of customer data.
The post also fails to explain how the alleged access was obtained, whether the information originated from a current production environment, or whether any credentials remain active.
Notably, the forum account behind the claim appears to have little established history. As a result, independent verification is especially important before drawing conclusions about the scope or significance of the alleged access.
The claim follows a growing number of incidents involving internal infrastructure, administrative systems, and development environments, including Vercel’s confirmed breach of internal systems and Trellix’s source code repository breach following unauthorized access.
No public statement issued
Amazon had not issued any public statement regarding the alleged Wickr Enterprise Admin API access at time of publication.
BreachNews could not independently verify the authenticity of the claim. The available evidence does not currently establish whether any customer information, enterprise environments, or production systems were compromised.











