logo

UK Cybercrime Journal: Arup Group Breached by FulcrumSec

ID: 6ce96b1b-9563-5aa2-90cc-e3f4fe87846d

STIX ID: report--6ce96b1b-9563-5aa2-90cc-e3f4fe87846d

Feed Name: BushidoToken Blog

Threat Score
85/100

Date Published: 2026-06-10

Date Updated: 2026-06-11

...
...

On 10 May 2026 FulcrumSec published a data leak claiming exfiltration of ~700GB of private GitHub repositories and ~2TB of Azure/AWS cloud storage from Arup Group, exposing sensitive client files, internal engineering documents (including HS2-related data), source code, and credentials; the adversary reported initial access via a hardcoded GitHub personal access token on a forgotten subdomain and subsequent pivoting using discovered keys. The report assesses FulcrumSec as a financially motivated data-theft-extortion group active since September 2025 and provides defensive takeaways such as asset inventory, secret management, GitHub monitoring, incident response automation, third-party risk management, and deception techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.