A threat actor claims to have breached Kanał ZERO, a prominent Polish online media outlet. The actor alleges that they gained access to the company’s entire database by exploiting a publicly accessible development environment.
According to the actor, the compromised data includes a wide range of sensitive information. The allegedly exfiltrated data includes:
- Full names
- Email addresses
- Hashed passwords
- Google OAuth tokens
- Internal financial data
- Contracts and invoices
- Details on corporate partners and equipment purchases












