Skip to content
Leak-site post naming amzur.com, captured by ThreatCluster

amzur.com

unsafe

Ransomware leak-site victim intelligence

Files
9
Views
15,518
Posted
Aug 28, 2026
Country
BR
Industry
Not Found

Summary

Written by ThreatClusterfrom file listing, victim profile, leak post, screenshot, ransom note

The group unsafe claims amzur.com's GitHub repository, client source code, access tokens, and private keys were taken and may become publicly available. Sample filenames published by the group include amzur.com_aws_client.png and amzur.com_aws_client1.png through amzur.com_aws_client7.png. The leak page lists victim amzur.com with revenue of $73.4 million and GitHub as the named platform; the post is published, and the group states the data may become publicly available and urges contact.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

Victim profile

Platforms
GitHub

What was taken

Your GitHub repository, client source code, access tokens, and private keys may become publicly available. If that happens, the resulting damage could be so severe that no one will want to work with you. Get in touch with me as soon as possible. Time is running out.

Data categories
client source codeaccess tokensprivate keys
File types seen
png × 8
Sample files (8)
amzur.com_aws_client.png
amzur.com_aws_client1.png
amzur.com_aws_client2.png
amzur.com_aws_client4.png
amzur.com_aws_client5.png
amzur.com_aws_client3.png
amzur.com_aws_client6.png
amzur.com_aws_client7.png

Ransom note

Published by the group on their leak site, reproduced verbatim.

Your GitHub repository, client source code, access tokens, and private keys may become publicly available. If that happens, the resulting damage could be so severe that no one will want to work with you. Get in touch with me as soon as possible. Time is running out.

Also stated on the leak page

Fields this group publishes that do not map to a standard column. Labels are the site's own.

Visit onion link
http://yc2wa25fe2pxooe7osfqvzjagwbiqulg22swm4uchli4srjlcyudx2ad.onion/

Leak-site images (2)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture
Screenshot of a command-line interface displaying error messages related to AWS access and permissions.
onion leak page349 KB