ByteToBreach
ByteToBreach is a financially motivated cybercriminal described as a data leak trader and access broker, active since at least June 2025. The actor operates across DarkForums, Dread, Telegram, Pastebin, and a public WordPress site branded "Pentesting Ltd.," which was used for self-promotion, victim shaming, and monetization. Reported communication channels include Telegram, ProtonMail, Tuta, Gmail, Signal, and Session, and the actor has also shared or sold data via Google Drive and OwnCloud. The content describes ByteToBreach as targeting high-impact organizations globally across banking, insurance, telecom, airlines, transportation, healthcare, universities, government, and IT services. Reported victim geography spans multiple countries, including the United States, India, Italy, Spain, Russia, the Netherlands, France, Finland, Poland, Portugal, Cyprus, Seychelles, Singapore, Chile, Panama, Uzbekistan, Kazakhstan, Thailand, Ukraine, Ethiopia, and Sweden. The victimology is described as financially driven rather than politically constrained, including targeting of CIS countries as well as Ukraine. Reported initial access methods include exploitation of known vulnerabilities in internet-facing cloud and enterprise software, reuse of stolen credentials from infostealers and phishing, and occasional brute force or abuse of misconfigurations. Post-compromise behavior described in the content includes lateral movement, credential harvesting, tunneling, compromise of backups and security tooling, data exfiltration, extortion, and in at least one claimed case ransomware deployment. Specific claimed techniques in the content include exploitation of public-facing applications, SQL injection, Oracle WebLogic exploitation, Microsoft Exchange ProxyLogon exploitation, Apache Solr local file inclusion, JSP reverse shell upload, Jenkins compromise, Docker escape, SSH key pivots, SQL copy-to-program pivots, credential dumping, tunneling with Ligolo, and exfiltration over web services. The actor is associated in the content with claimed breaches involving VUMI Group, National Oil Ethiopia PLC, Viking Line, CGI Sverige AB and Sweden's e-government platform, Eurofiber France's GLPI and ATE environments, and other alleged victims including banks, telecom providers, airlines, universities, and government-related entities. In the Eurofiber case, ByteToBreach claimed theft of data from roughly 10,000 business and government clients. KELA describes the actor as credible and adaptable, noting that some leaked datasets were later corroborated by affected organizations or contained verifiable technical artifacts. Known aliases and related identifiers directly mentioned in the content include bytetobreach, ByteToBreach, Telegram handle @ByteToBreach, prior Telegram names "CvHNWwEG" and "inesslopez," and the public-facing brand "Pentesting Ltd." The content assesses the actor as likely a single technically skilled individual or a small group.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Insurance
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Tradecraft
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Recent activity
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claims a data breach against VUMI Group involving systematic database enumeration and six days of throttled exfiltration of insurance records, SSNs, passport scans, W-9 forms, and other PII, then distributes the stolen data via OwnCloud.
Conducted a ransomware and data theft intrusion against National Oil Ethiopia, claiming full infrastructure compromise, exfiltration of 800+ GB of data, compromise of Active Directory, Veeam backups, and Kaspersky security tooling, followed by ransomware deployment.
Leaked the full source code of Sweden's e-government platform after allegedly compromising CGI Sverige AB infrastructure, and claimed to have also collected citizen PII databases, electronic signing documents, staff database data, API signing systems, and pivot credentials.
Claimed a data breach against Viking Line in Finland, alleging theft and public release of traveler personal information, vehicle registration plates, and payment-related transaction data, including abuse of the NetAxept payment integration.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.