HomeSecurityByteToBreach traffics sensitive data from airlines, banks and government agencies

ByteToBreach traffics sensitive data from airlines, banks and government agencies

A cybercriminal using the alias ByteToBreach has emerged as a significant threat to the online underground economy, trafficking and publishing sensitive data from airlines, banks, universities and government organizations around the world.

See also: OpenAI: Data breach via third-party provider Mixpanel

ByteToBreach

It has been active since at least June 2025 and appears to operate a multi-platform network, combining technical expertise with heavy promotion on DarkForums, Dread, Telegram, and a public WordPress site. Its victims are located in many countries, including Ukraine, Kazakhstan, Cyprus, Poland, Chile, Uzbekistan, and the United States. The data that has been published includes airline passenger lists, bank employee records, healthcare databases, and government-related documents.

Some of the affected organizations have confirmed the incidents or have identified technical evidence that substantiates the validity of the claims. KELA researchers were able to identify and track ByteToBreach through extensive research.

The perpetrator is reportedly using a combination of methods, such as exploiting known vulnerabilities in corporate and cloud systems, leveraging stolen credentials from infostealers and phishing attacks, as well as access via brute force or incorrect security settings.

See also: Comcast to pay fine for customer data breach

ByteToBreach traffics sensitive data from airlines, banks and government agencies

Once he gains access to a system, ByteToBreach focuses on extracting data, targeting employee records, databases, backups, and other sensitive documents. In August 2025, he created a WordPress-based website called “Pentesting Ltd,” which presented itself as a legitimate service company. The website displayed logos of organizations he claimed to have breached, presenting them as “clients.”

The site's graphics included provocative slogans, such as "Let Me Harm Your Data" and "Industry-leading Threat Actor". The perpetrator maintains multiple communication channels, including ProtonMail, Tuta, Gmail, Telegram (@ByteToBreach), Signal and Session. KELA's analysis of data from infostealers linked the perpetrator to two infected computers in Algeria.

One was infected by Raccoon in September 2022 and the second by StealC in February 2024. His oldest Telegram username, “inesslopez”, was found in the bot files, as well as a phone number directly related to his current Telegram account.

See also: Dartmouth College: Data breach via Oracle EBS

ByteToBreach traffics sensitive data from airlines, banks and government agencies

This case demonstrates how modern cyber threat actors combine legitimate technical skills with criminal intent, leveraging marketing-like strategies to exploit stolen data on a global scale.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS