A cybercriminal using the alias ByteToBreach has emerged as a significant threat to the online underground economy, trafficking and publishing sensitive data from airlines, banks, universities and government organizations around the world.
See also: OpenAI: Data breach via third-party provider Mixpanel

It has been active since at least June 2025 and appears to operate a multi-platform network, combining technical expertise with heavy promotion on DarkForums, Dread, Telegram, and a public WordPress site. Its victims are located in many countries, including Ukraine, Kazakhstan, Cyprus, Poland, Chile, Uzbekistan, and the United States. The data that has been published includes airline passenger lists, bank employee records, healthcare databases, and government-related documents.
Some of the affected organizations have confirmed the incidents or have identified technical evidence that substantiates the validity of the claims. KELA researchers were able to identify and track ByteToBreach through extensive research.
The perpetrator is reportedly using a combination of methods, such as exploiting known vulnerabilities in corporate and cloud systems, leveraging stolen credentials from infostealers and phishing attacks, as well as access via brute force or incorrect security settings.
See also: Comcast to pay fine for customer data breach

Once he gains access to a system, ByteToBreach focuses on extracting data, targeting employee records, databases, backups, and other sensitive documents. In August 2025, he created a WordPress-based website called “Pentesting Ltd,” which presented itself as a legitimate service company. The website displayed logos of organizations he claimed to have breached, presenting them as “clients.”
The site's graphics included provocative slogans, such as "Let Me Harm Your Data" and "Industry-leading Threat Actor". The perpetrator maintains multiple communication channels, including ProtonMail, Tuta, Gmail, Telegram (@ByteToBreach), Signal and Session. KELA's analysis of data from infostealers linked the perpetrator to two infected computers in Algeria.
One was infected by Raccoon in September 2022 and the second by StealC in February 2024. His oldest Telegram username, “inesslopez”, was found in the bot files, as well as a phone number directly related to his current Telegram account.
See also: Dartmouth College: Data breach via Oracle EBS

This case demonstrates how modern cyber threat actors combine legitimate technical skills with criminal intent, leveraging marketing-like strategies to exploit stolen data on a global scale.
