SYS::ONLINE
Wasteland.
Briefs1525
Issues20
SinceFeb 2026
LIVE
▣ Breach RAPIDFORT-XPL0ITRS 2026-07-24

RapidFort: xpl0itrs Claims 569GB CanisterWorm Breach

"Threat actor xpl0itrs is advertising 569GB of data allegedly stolen from software supply chain security vendor RapidFort, tied to the CanisterWorm campaign run jointly with TeamPCP. Dataminr detected the sale listing on…"

Threat actor xpl0itrs is advertising 569GB of data allegedly stolen from software supply chain security vendor RapidFort, tied to the CanisterWorm campaign run jointly with TeamPCP. Dataminr detected the sale listing on 21 July 2026, and the actor claims the trove includes 140,061 files pulled from 48 S3 buckets, some of it government and defense affiliated. RapidFort has not publicly confirmed or denied the claim at time of writing. The claim is credible but remains unverified.

What Happened

At 18:00 local time on 21 July 2026, Dataminr detected xpl0itrs posting under the persona "Com Boss" on a dark web forum, offering the alleged RapidFort dataset for sale. The actor attributes the intrusion to CanisterWorm, a supply chain campaign previously and publicly claimed as a joint operation between xpl0itrs and TeamPCP. Both groups have a documented history of collaborative software supply chain compromises that produce cascading downstream victim impact.

RapidFort is a software supply chain and container security vendor with a reported customer base that includes enterprise and U.S. government organizations. The actor claims the data dates to March 2026 and alleges RapidFort has not notified affected customers, extending the potential exposure window for any organization integrated with the platform. Separately, Knox Systems published a statement on 23 July confirming it reviewed the RapidFort incident and was unaffected.

What Was Taken

The listing advertises 569GB of data comprising 140,061 files extracted from 48 S3 buckets. Automated analysis of the alleged dataset surfaced several high-risk data categories:

The government data claim is unconfirmed. If substantiated, it would materially raise the incident's national security and regulatory profile. The presence of cloud release credentials is the most immediately actionable element, as exposed AWS and Azure keys enable credential abuse against downstream customer environments regardless of whether the broader dataset is authentic.

Why It Matters

RapidFort sits in the software supply chain, which means a compromise does not stop at a single vendor. Pipeline hardening data and vulnerability scan results describe the security posture of every customer that runs the platform, effectively handing an attacker a map of where downstream weaknesses live. Combined with the cloud credentials in the dataset, that context turns a vendor breach into a potential foothold across many organizations at once.

The CanisterWorm attribution reinforces the concern. xpl0itrs and TeamPCP have a track record of collaborative supply chain intrusions engineered for cascading impact, so this claim fits an established pattern rather than an isolated incident. The alleged three month gap between the March 2026 data date and public disclosure means any exposed credentials may have been valid and unrotated for months.

The Attack Technique

The specific initial access vector has not been disclosed by the actor or confirmed by RapidFort. The stated exfiltration path centers on 48 S3 buckets from which 140,061 files were allegedly pulled, consistent with cloud storage access rather than an on premises intrusion. The presence of AWS and Azure release credentials in the dataset suggests credential exposure may have played a role in either the initial compromise or lateral movement across cloud storage. Until RapidFort issues a statement, defenders should treat the S3 and cloud credential angle as the working hypothesis and act on the credential abuse risk accordingly.

What Organizations Should Do

Sources: Cyber Intel Brief: xpl0itrs Claims RapidFort Breach