Find notable cyber news and cases, enriched with sources, timelines, and signals.

3BB hit by data theft breach

Incident
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

The 3BB network intrusion gave an attacker root access to internal machines and a hidden MeshCentral backdoor inside the Thai broadband provider's environment, increasing exposure of subscriber credentials and internal management systems. The operation was still live on June 3, 2026, when an exposed command server and control list were captured. Recovered scripts show password spraying, SSH-based probing of more than 55 internal computers, and searches for stored passwords, database logins, and SSH keys. The toolkit also targeted subscriber RADIUS databases and a FortiGate SSL-VPN gateway tied to CVE-2024-21762, but successful exploitation and data theft were not confirmed.

Related Happenings

Initial access broker (IAB) campaign expands across multiple victims

Campaign
H score89 First: 22.06.2026 23:01 Last: 22.06.2026 23:01 Sources 1

About this happening: The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...

Latest development: 23.06.2026 13:30

On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.

Timeline

  1. 14.09.2026 21:01 1 articles · 3h ago

    Exposed attacker server reveals active 3BB intrusion

    Untyped Phase

    On June 3, 2026, Hunt.io captured an exposed attacker server while the intrusion inside 3BB's network in Thailand was still live; recovered tooling showed root access on an internal server, MeshCentral configured as a hidden backdoor reporting to www.ayuthayatech[.]com under TH-3BB, cleanup steps meant to erase logs while preserving access, password spraying over SSH against more than 55 internal computers, and a toolkit aimed at 3BB's FortiGate SSL-VPN gateway for CVE-2024-21762.

    Show sources
  2. 14.09.2026 21:01 2 articles · 3h ago

    Hunt.io publishes 3BB MeshCentral intrusion analysis

    Initial Disclosure

    On September 14, 2026, Hunt.io publicly described an attacker inside 3BB's network in Thailand using MeshCentral as a hidden backdoor to keep root access on internal machines, said the findings were shared with the affected companies and the relevant national response team before publication, and advised patching CVE-2024-21762, checking for unauthorized MeshCentral agents, rotating exposed credentials, and preserving logs before cleanup.

    Show sources