Punishing Owl leak of Russian state and scientific organizations
Data Leak
Summary
Hide ▲
Show ▼
A Punishing Owl leak operation is exposing sensitive information from Russian state institutions, scientific enterprises, and IT organizations, increasing the risk of public disclosure and downstream abuse. The actor is described as stealing and leaking data on the dark web and has been active since December 2025. The leak thread adds a distinct disclosure risk on top of broader Russia-focused intrusion activity.
Related Happenings
FIFA logins traded on dark-web markets
Data Leak
First: 27.05.2026 14:28
Last: 27.05.2026 14:28
Sources 1
About this happening:
Around **2,500 FIFA logins** have surfaced on **dark-web markets**, turning stolen credentials into an active exposure that can fuel account abuse and downstream fraud. The leak i...
FIFA logins traded on dark-web markets
Data LeakAbout this happening: Around **2,500 FIFA logins** have surfaced on **dark-web markets**, turning stolen credentials into an active exposure that can fuel account abuse and downstream fraud. The leak i...
RondoDox persistent IoT and web app botnet campaign
Campaign
First: 01.01.2026 11:19
Last: 01.01.2026 11:19
Sources 1
About this happening:
**Scattered Lapsus$ Hunters** claimed they breached **Resecurity** and stole internal chats, logs, employee data, threat intelligence reports, and a complete client list, but Rese...
RondoDox persistent IoT and web app botnet campaign
CampaignAbout this happening: **Scattered Lapsus$ Hunters** claimed they breached **Resecurity** and stole internal chats, logs, employee data, threat intelligence reports, and a complete client list, but Rese...
Latest development: 03.01.2026 22:34
Scattered Lapsus$ Hunters claimed they gained full access to Resecurity systems and stole internal chats, logs, employee data, threat intelligence reports, and a complete client list, while Resecurity said the accessed environment was a deliberately deployed honeypot with fake employee, customer, and payment data used to monitor the actor.
Proton Data Breach Observatory launches with real-time dark web breach monitoring
Security Tool/Service
First: 30.10.2025 13:00
Last: 30.10.2025 13:00
Sources 1
About this happening:
**Proton** launched the **Data Breach Observatory**, a monitoring service built with **Constella Intelligence** that scans the dark web for breached records and can flag exposure...
Proton Data Breach Observatory launches with real-time dark web breach monitoring
Security Tool/ServiceAbout this happening: **Proton** launched the **Data Breach Observatory**, a monitoring service built with **Constella Intelligence** that scans the dark web for breached records and can flag exposure...
Timeline
-
09.02.2026 12:58 1 articles · 3mo ago
Punishing Owl leak of Russian state and scientific organizations
Initial DisclosurePunishing Owl began **stealing and leaking data on the dark web** from **Russian state institutions, scientific enterprises, and IT organizations**. The leak activity has been active since **December 2025**.
Show sources
- Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign — thehackernews.com — 09.02.2026 12:58