Discovered
2026-08-25 14:25 UTC
Est. attack date
2026-08-25
Country
Sector
Agriculture and Food Production
Education
Energy & Utilities
Financial Services
Government & Defense
Healthcare
Hospitality
Manufacturing
Other
Professional Services
Retail & E-Commerce
Technology
Transportation
Description:
We Breached A-plus through a sql injection vulnerability and downloaded everything in there backend. We gained access to there system on 08/18/2026
The following data was stolen:
1. Website User Data (`usr.csv`)
- This file contains the administrative backend infrastructure for the website, exposing:
- 10 internal accounts, including the usernames `admin`, `debuger`, `camby`, `asuka`, `jimmy`, `ricole`, and `green`.
- Password hashes (SHA-1 format) revealing that almost all administrative users shared the exact same password.
- Internal access metadata
2. Marketing and Public Web Content
- The remaining four files contain the text, configuration, and structural layout used to display information to visitors on `a-plussoft.com`:
`- products.csv`
13 lines): The master list of software solutions and mobile apps sold by the company (such as SalesAnywhere).
`- product_content.csv` (101 lines): The detailed marketing descriptions, features, specifications, and text modules displayed on individual product pages.
`- news.csv` (89 lines): The text content of all historical corporate announcements, updates, and press releases published by the company.
`- news_cate.csv` (2 lines): The category organization tags used to sort the news section on the website
Uncompressed size
total records: 211
2,787,292 Bytes, which equals 2.6582 Megabytes (MB).
mirror 1: https://anonfilesnew.com/[REDACTED]
mirror 2: https://pixeldrain.com/[REDACTED]
DNS Records:
The following DNS records were found for the victim's domain.
-
aplussoft-com0c.mail.protection.outlook.com.
Microsoft 365
- v=spf1 include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.