DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Babuk re-organizes as Payload Bin, offers its first leak

Posted on May 31, 2021 by Dissent

At the end of April, threat actors known as Babuk indicated that they were closing up shop and switching to a different model:

Babuk changes direction, we no longer encrypt information on networks, we will get to you and take your data, we will notify you about it if you do not get in touch we make an announcement.

Also for other groups that do not have their own blog or have but they want to exert additional pressure, you can not be placed with us.

Two weeks later, they wrote:

Hello! We announce the development of something really cool, a huge platform for independent leaks, we have no rules and bosses, we will publish private products in a single information platform where we will post leaks of successful no-name teams that do not have their own blogs and names, these are not girls who run with ship like rats and change the policy of their resources. these are really strong guys.

Another loud leak awaits you within a week.

Today, we began to see the changes as the site is now called Payload Bin.

Image: DataBreaches.net

The About and Rules pages are not available yet and so far there is only one leak listed under Announcements:  CD Projekt. CD Projekt was attacked in February by attackers using what is believed to be the Hello Kitty ransomware. The hackers had put the stolen source code up for sale on a Russian-language forum, listing it all as:

  • Full sources for the games Thronebreaker , Witcher 3 , the undeclared Witcher 3 RTX (the version of the Witcher with raytracing) and of course Cyberpunk 2077
  • Dumps of internal documents
  • CD Projekt RED offenses .

They subsequently withdrew the auction listing, claiming that they had received a satisfactory offer from outside of the forum, and that because of a condition of no further distribution, they were removing the listing from auction.

Source code withdrawn from auction. Image: DataBreaches.net

Now Payload Bin says they will make all source code available on its site. So what, exactly, happened to that sale with “no further distribution?”

Image: DataBreaches.net

No related posts.

Category: Breach IncidentsMalwareOf Note

Post navigation

← Claiming to be the “new generation,” threat actors declare, “No more discounts or long negotiations”
IA: Union Community School District publicly silent after threat actors dump files on dark web →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Five youths arrested on suspicion of phishing
  • Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure
  • Kentfield Hospital victim of cyberattack by World Leaks, patient data involved
  • India’s Max Financial says hacker accessed customer data from its insurance unit
  • Brazil’s central bank service provider hacked, $140M stolen
  • Iranian and Pro-Regime Cyberattacks Against Americans (2011-Present)
  • Nigerian National Pleads Guilty to International Fraud Scheme that Defrauded Elderly U.S. Victims
  • Nova Scotia Power Data Breach Exposed Information of 280,000 Customers
  • No need to hack when it’s leaking: Brandt Kettwick Defense edition
  • SK Telecom to be fined for late data breach report, ordered to waive cancellation fees, criminal investigation into them launched

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • On July 7, Gemini AI will access your WhatsApp and more. Learn how to disable it on Android.
  • German court awards Facebook user €5,000 for data protection violations
  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher
  • Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law
  • US healthcare offshoring: Navigating patient data privacy laws and regulations
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • Google Trackers: What You Can Actually Escape And What You Can’t

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.