UK Cybercrime Journal: Arup Group Breached by FulcrumSec
ID: 6ce96b1b-9563-5aa2-90cc-e3f4fe87846d
STIX ID: report--6ce96b1b-9563-5aa2-90cc-e3f4fe87846d
Feed Name: BushidoToken Blog
On 10 May 2026 FulcrumSec published a data leak claiming exfiltration of ~700GB of private GitHub repositories and ~2TB of Azure/AWS cloud storage from Arup Group, exposing sensitive client files, internal engineering documents (including HS2-related data), source code, and credentials; the adversary reported initial access via a hardcoded GitHub personal access token on a forgotten subdomain and subsequent pivoting using discovered keys. The report assesses FulcrumSec as a financially motivated data-theft-extortion group active since September 2025 and provides defensive takeaways such as asset inventory, secret management, GitHub monitoring, incident response automation, third-party risk management, and deception techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
