News.Ycombinator
Sweden's E-Government Platform Source Code Leaked by ByteToBreach
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
The threat actor ByteToBreach has leaked the complete source code of Sweden's E-Government platform, claiming it was acquired through a compromised CGI Sverige AB infrastructure. This breach also includes sensitive citizen PII databases and electronic signing documents, which are being sold separately. The attack exploited vulnerabilities such as a full Jenkins compromise, Docker escape, and SSH private key pivots. The actor has listed various sensitive components, including a staff database and RCE test endpoints. They assert that the Swedish e-government is the primary victim and criticize companies blaming third parties for breaches. The source code is available for free download, while the citizen databases are for sale. This incident follows a previous breach involving Viking Line, indicating a pattern of attacks by the same actor.
Key Points: • ByteToBreach leaked the entire source code of Sweden's E-Government platform. • Sensitive citizen data, including PII databases, is being sold separately. • The breach exploited multiple vulnerabilities, including Jenkins and Docker issues.