Find notable cyber news and cases, enriched with sources, timelines, and signals.

Unnamed Western government organization data exposed after WordPress breach

Data Leak
First reported
Last updated
Happening score
H score 66
1 unique sources, 1 articles

Summary

Hide ▲

A Western government organization suffered a data leak after attackers reached an internal SQL server and stole 18,566 records, exposing accounts, plaintext passwords, and PII. The stolen data was tied to government and law-enforcement agencies, making the theft operationally sensitive. The breach sat inside a broader wp2shell exploitation wave against WordPress Core that hit multiple organizations across 29 countries.

Timeline

  1. 22.09.2026 23:35 2 articles · 0h ago

    Wp2shell breach exposes 18,566 records at a Western government organization

    Initial Disclosure

    GreyNoise attributes a Chinese-speaking threat actor's wp2shell exploitation of WordPress Core to an intrusion at an unnamed Western government organization, where backend SQL credentials were used in a password-spraying attack to reach an internal SQL server and steal at least 18,566 records containing accounts, plaintext passwords, and PII tied to government and law-enforcement agencies.

    Show sources