CGI Sweden and Eurail data breaches expose government and passenger data
Reliability
Based on 19 sources
Publications (16)
Sources (19)Fact-Checking
24 claimsThe hacker group ByteToBreach claims to have published large amounts of sensitive information from CGI Sweden on the darknet.
The leak includes source code, passwords, and encryption keys.
The person or group behind the leak is known for similar intrusions, including recently against Viking Line.
Open Questions
5 questionsCGI states the incident only affects test servers and no production environments.
According to TV4 Nyheterna, Dagens Nyheter (source 3), FeberFiles in the leak indicate information may have been from production servers, specifically linked to MCF's e-services.
According to Dagens Nyheter (source 3)Context: This disagreement raises questions about the true extent of the breach and whether sensitive production data was compromised, impacting risk assessments for government systems.
ByteToBreach is attributed to the CGI breach.
According to TV4 Nyheterna, Feber, ebuildersecurity.comShiny Hunters claims to have obtained 350 GB of data, without specifying if it's related to the same incident.
According to Computer SwedenContext: This creates uncertainty about whether multiple groups are involved or if there is confusion over attribution, which affects understanding of the threat landscape and potential motives.