Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

A-Plus Software Limited

www.a-plussoft.com

Discovered 2026-08-25 14:25 UTC
Est. attack date 2026-08-25
Country GB
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

We Breached A-plus through a sql injection vulnerability and downloaded everything in there backend. We gained access to there system on 08/18/2026 The following data was stolen: 1. Website User Data (`usr.csv`) - This file contains the administrative backend infrastructure for the website, exposing: - 10 internal accounts, including the usernames `admin`, `debuger`, `camby`, `asuka`, `jimmy`, `ricole`, and `green`. - Password hashes (SHA-1 format) revealing that almost all administrative users shared the exact same password. - Internal access metadata 2. Marketing and Public Web Content - The remaining four files contain the text, configuration, and structural layout used to display information to visitors on `a-plussoft.com`: `- products.csv` 13 lines): The master list of software solutions and mobile apps sold by the company (such as SalesAnywhere). `- product_content.csv` (101 lines): The detailed marketing descriptions, features, specifications, and text modules displayed on individual product pages. `- news.csv` (89 lines): The text content of all historical corporate announcements, updates, and press releases published by the company. `- news_cate.csv` (2 lines): The category organization tags used to sort the news section on the website Uncompressed size total records: 211 2,787,292 Bytes, which equals 2.6582 Megabytes (MB). mirror 1: https://anonfilesnew.com/[REDACTED] mirror 2: https://pixeldrain.com/[REDACTED]

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • aplussoft-com0c.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot