Unnamed Western government organization data exposed after WordPress breach
Data Leak
Summary
Hide ▲
Show ▼
A Western government organization suffered a data leak after attackers reached an internal SQL server and stole 18,566 records, exposing accounts, plaintext passwords, and PII. The stolen data was tied to government and law-enforcement agencies, making the theft operationally sensitive. The breach sat inside a broader wp2shell exploitation wave against WordPress Core that hit multiple organizations across 29 countries.
Timeline
-
22.09.2026 23:35 2 articles · 0h ago
Wp2shell breach exposes 18,566 records at a Western government organization
Initial DisclosureGreyNoise attributes a Chinese-speaking threat actor's wp2shell exploitation of WordPress Core to an intrusion at an unnamed Western government organization, where backend SQL credentials were used in a password-spraying attack to reach an internal SQL server and steal at least 18,566 records containing accounts, plaintext passwords, and PII tied to government and law-enforcement agencies.
Show sources
- Chinese hackers exploit multiple technologies to steal govt data — www.bleepingcomputer.com — 22.09.2026 23:35
- Chinese hackers exploit multiple technologies to steal govt data — www.bleepingcomputer.com — 22.09.2026 23:35