Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
leaked-secret-api-keyunderground-data-leakunmanaged-asset-discoverycloud-misconfiguration

FulcrumSec Claims Arup Breach Exposed GitHub Repos, Cloud Data, and Client Projects

Updated 18d agoFirst seen Jun 10, 20263 sources

FulcrumSec has claimed responsibility for breaching UK engineering firm Arup Group and stealing large volumes of data, later listing the company on its Tor leak site. According to the threat actor’s account, the intrusion began in September 2025 after attackers found a GitHub personal access token hardcoded in a JavaScript file on a forgotten Arup subdomain, which allegedly opened access to more than 10,000 private repositories and led to additional credentials in code. The group said it exfiltrated about 700GB of GitHub repositories, 2TB of Azure and AWS S3 data, database backups, source code, and other internal material before credentials were rotated.

The stolen data allegedly included sensitive information tied to major clients and infrastructure projects, including HS2-related repositories, Euston Station design files, archaeological GPS coordinates, Neuron BMS and Odoo ERP data, Apple code-signing certificates with plaintext passwords, and GCP payment gateway credentials. FulcrumSec said Arup detected parts of the intrusion roughly six weeks after initial access but that the attackers retained visibility into the environment for months, analyzing the haul before contacting the company in April 2026. The incident underscores the downstream risk posed by hardcoded secrets, forgotten internet-facing assets, delayed credential rotation, and weak monitoring of source-code and cloud environments.

Share:
FulcrumSec Claims Arup Breach Exposed GitHub Repos, Cloud Data, and Client Projects
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jun 10, 202618d ago

FulcrumSec contacts Arup after analyzing allegedly stolen data

The threat actor claimed it spent months analyzing exfiltrated material and then contacted Arup in April 2026 regarding the breach and stolen data.

UK Cybercrime Journal: Arup Group Breached by FulcrumSec - Malware News - Malware Analysis, News and Indicators

FulcrumSec allegedly gains initial access to Arup via exposed GitHub token

According to FulcrumSec's claims, the intrusion began in September 2025 when the group found a GitHub personal access token hardcoded in a JavaScript file on a forgotten Arup subdomain, enabling access to private repositories and additional credentials.

UK Cybercrime Journal: Arup Group Breached by FulcrumSec - Malware News - Malware Analysis, News and Indicators
May 10, 20262mo ago

Hudson Rock-linked infostealer exposure for Arup is publicly listed

On 2026-05-10, a public intelligence listing reported alleged infostealer-related compromise data associated with Arup Group and attributed the discovery to Hudson Rock. The entry claimed 75 compromised employees, 855 compromised users, and 92 third-party employee credentials.

Ransomware.live - Victim: Arup Group

FulcrumSec lists Arup on its Tor leak site

On 2026-05-10, FulcrumSec publicly named UK engineering firm Arup Group on its Tor leak site and claimed to have stolen large volumes of GitHub, cloud, database, source code, and client-related data.

UK Cybercrime Journal: Arup Group Breached by FulcrumSec - Malware News - Malware Analysis, News and Indicators
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

39 LINKEDOpen in app
Threat actors
1 linked
Affected products
9 linked
GithubAmazon Simple Storage ServiceCanarytokensAutodeskDocusignJamfMiroCiscoMicrosoft 365
Organizations
24 linked
Amazon Web ServicesArupLexisNexis Risk SolutionsThe Walt Disney CompanyMicrosoft CorporationBPGoogleGitHubMarketoCisco SystemsAtlassianGlobalSignSchneider ElectricAutodeskDocuSignHudson RockVX-UndergroundAppleAdobeJamfWebflowMiroNeuronMentimeter
Breaches
5 linked
HS2LTD-2025-09BP-2025-09ARUPGROUP-2025-09THEWALTDISNEYCOMPANY-2025-09ARUPGROUP-2026-05
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.