Security

Cyber-crime

I stole 20 GB of data from Capgemini – and now I'm leaking it, says cybercrook

Allegedly pilfered database has source code, private keys, staff info, T-Mobile VM logs, more


Updated A miscreant claims to have broken into Capgemini and leaked a large amount of sensitive data stolen from the technology services giant – including source code, credentials, and T-Mobile's virtual machine logs.

The French multinational IT and consulting firm did not immediately respond to The Register's request for comment, and has yet to formally confirm or deny the cyber-criminal's claims. We will update this story if and when a spokesperson replies to our inquiries. We had heard rumblings of a recent security breach at Capgemini, which earlier declined to comment on those rumors.

According to a BreachForums post today announcing the leak, a crook who goes by "grep" said they allegedly compromised Capgemini this month and swiped 20GB of data from the biz. This is said to include some databases, source code, private keys, credentials, API keys, projects, employee data, and other information.

In portions of the leaked information reviewed by The Register we could see lists of Capgemini employees with what looks like their names, email addresses, usernames, and password hashes. There were also what appeared to backup archives, and files related to Capgemini clients, including internal configuration details for their cloud infrastructure.

"They had more data but I decided to exfiltrate only big files, company confidential, Terraform, and many more," the thief wrote. As well as offering the stolen data to fellow forum users, grep also shared some select samples, including what's said to be T-Mobile VM logs. Screenshots of the allegedly stolen data posted on X appear to show customer info.

Capgemini generated more than €22 billion (about $24 billion) in revenue in 2023.

In July, the consultancy won a controversial UK government contract worth up to £574 million.

Under the lucrative deal, valued between £403 million and £574 million, Capgemini will run legacy tax management systems for His Majesty's Revenue and Customs until 2029.

Both of the services in the contract, Enterprise Tax Management Platform (ETMP) and Enterprise Operations (EOPS), run SAP ECC 6.0, a legacy system from the German software giant that exits mainstream support at the end of 2027. ®

Updated to add

For your information, spokespeople for T-Mobile US have been in touch to say its virtual machines weren't caught up in this leak.

"From what we can tell, we believe this may be a T-Mobile brand outside of the US," a representative told us.

We're happy to pass this on.

Send us news
20 Comments

Drug-screening biz DISA took a year to disclose security breach affecting millions

If there's something nasty on your employment record, extortion scum could come calling

Malware variants that target operational tech systems are very rare – but 2 were found last year

Fuxnet and FrostyGoop were both used in the Russia-Ukraine war

Ghost ransomware crew continues to haunt IT depts with scarily bad infosec

FBI and CISA issue reminder - deep sigh - about the importance of patching and backups

Microsoft names alleged credential-snatching 'Azure Abuse Enterprise' operators

Crew helped lowlifes generate X-rated celeb deepfakes using Redmond's OpenAI-powered cloud – claim

Feds: Army soldier suspected of AT&T heist Googled ‘can hacking be treason,’ ‘defecting to Russia’

FYI: What NOT to search after committing a crime

With millions upon millions of victims, scale of unstoppable info-stealer malware laid bare

244M purloined passwords added to Have I Been Pwned thanks to govt tip-off

Xi know what you did last summer: China was all up in Republicans' email, says book

Of course, Microsoft is in the mix, isn't it

China's Silver Fox spoofs medical imaging apps to hijack patients' computers

Sly like a PRC cyberattack

Snake Keylogger slithers into Windows, evades detection with AutoIt-compiled payload

Because stealing your credentials, banking info, and IP just wasn’t enough

SonicWall firewalls now under attack: Patch ASAP or risk intrusion via your SSL VPN

Roses are red, violets are blue, CVE-2024-53704 is sweet for a ransomware crew

Chinese spies suspected of 'moonlighting' as tawdry ransomware crooks

Some employees steal sticky notes, others 'borrow' malicious code

If you dread a Microsoft Teams invite, just wait until it turns out to be a Russian phish

Roses aren't cheap, violets are dear, now all your access token are belong to Vladimir