Security

Cyber-crime

I stole 20 GB of data from Capgemini – and now I'm leaking it, says cybercrook

Allegedly pilfered database has source code, private keys, staff info, T-Mobile VM logs, more


Updated A miscreant claims to have broken into Capgemini and leaked a large amount of sensitive data stolen from the technology services giant – including source code, credentials, and T-Mobile's virtual machine logs.

The French multinational IT and consulting firm did not immediately respond to The Register's request for comment, and has yet to formally confirm or deny the cyber-criminal's claims. We will update this story if and when a spokesperson replies to our inquiries. We had heard rumblings of a recent security breach at Capgemini, which earlier declined to comment on those rumors.

According to a BreachForums post today announcing the leak, a crook who goes by "grep" said they allegedly compromised Capgemini this month and swiped 20GB of data from the biz. This is said to include some databases, source code, private keys, credentials, API keys, projects, employee data, and other information.

In portions of the leaked information reviewed by The Register we could see lists of Capgemini employees with what looks like their names, email addresses, usernames, and password hashes. There were also what appeared to backup archives, and files related to Capgemini clients, including internal configuration details for their cloud infrastructure.

"They had more data but I decided to exfiltrate only big files, company confidential, Terraform, and many more," the thief wrote. As well as offering the stolen data to fellow forum users, grep also shared some select samples, including what's said to be T-Mobile VM logs. Screenshots of the allegedly stolen data posted on X appear to show customer info.

Capgemini generated more than €22 billion (about $24 billion) in revenue in 2023.

In July, the consultancy won a controversial UK government contract worth up to £574 million.

Under the lucrative deal, valued between £403 million and £574 million, Capgemini will run legacy tax management systems for His Majesty's Revenue and Customs until 2029.

Both of the services in the contract, Enterprise Tax Management Platform (ETMP) and Enterprise Operations (EOPS), run SAP ECC 6.0, a legacy system from the German software giant that exits mainstream support at the end of 2027. ®

Updated to add

For your information, spokespeople for T-Mobile US have been in touch to say its virtual machines weren't caught up in this leak.

"From what we can tell, we believe this may be a T-Mobile brand outside of the US," a representative told us.

We're happy to pass this on.

Send us news
20 Comments

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used

Ransomware 'not off the table,' Arctic Wolf threat hunter tells El Reg

Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days

'Codefinger' crims on the hunt for compromised keys

Mitel 0-day, 5-year-old Oracle RCE bug under active exploit

3 CVEs added to CISA's catalog

Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases

Gee, wonder why Beijing is so keen on the – checks notes – Committee on Foreign Investment in the US

Russia's Star Blizzard phishing crew caught targeting WhatsApp accounts

FSB cyberspies venture into a new app for espionage, Microsoft says

China's Salt Typhoon spies spotted on US govt networks before telcos, CISA boss says

We are only seeing 'the tip of the iceberg,' Easterly warns

FBI wipes Chinese PlugX malware from thousands of Windows PCs in America

Hey, Xi: Zài jiàn!

Microsoft sues 'foreign-based' cyber-crooks, seizes sites used to abuse AI

Scumbags stole API keys, then started a hacking-as-a-service biz, it is claimed

Crims backdoored the backdoors they supplied to other miscreants. Then the domains lapsed

Here's what $20 gets you these days

FireScam infostealer poses as Telegram Premium app to surveil Android devices

Once installed, it helps itself to your data like it's a free buffet

Charter, Consolidated, Windstream reportedly join China's Salt Typhoon victim list

Slow drip of compromised telecom networks continues

Chinese cyber-spies reportedly targeted sanctions intel in US Treasury raid

OFAC, Office of the Treasury Secretary feared hit in data-snarfing swoop