Some of August's biggest breach claims were fabricated

Published

In August, someone offered 33 million customer records from a South Korean e-commerce platform for sale on a cybercrime forum. The records were not real. Researchers who examined the sample concluded the data had been fabricated.

That finding comes from the August dark web breach review published by AhnLab's ATCP team, which spent the month tracking database leaks, sales of internal company data and the trading of initial access on dark web and deep web forums. What makes the review worth reading is that it tested the loudest claims instead of simply repeating them, and several of them failed.

Three big numbers that did not survive

Alongside the fabricated e-commerce listing, ATCP flagged roughly 48 million records attributed to a South Korean public health insurance body. The team could not confirm that any breach took place: the posted sample showed signs of manipulation, and the institution denied being breached. A third batch, advertised as data from South Korean online travel and lodging brands, was assessed as having low credibility.

None of that means the forums went quiet. It means the headline figure attached to a post is often the least reliable thing in it, and that an organization named in one has a real question to settle before it answers publicly.

Some of it was entirely credible

Other August listings held up. Personal information on members of South Korean religious organizations circulated with detailed field structures intact, which ATCP assessed as a relatively credible case and connected to a similar episode in April 2026. The team also logged roughly 1 TB taken from the internal file servers of a domestic asset management firm, about 47.96 million customer, delivery driver and franchisee records from a logistics platform, 637 GB from an industrial automation company, internal data from two manufacturers, and administrator and root credentials for 2,980 network video recorders offered for sale.

ShinyHunters kept up the pressure

ShinyHunters spent August making consecutive breach claims and issuing public threats against a run of organizations, among them a US data center operator, a live streaming platform, a digital healthcare company, an open-source analytics platform, a global medical device maker and a French intellectual property services firm. The pattern is familiar from the group's 284 million record claim against McKesson at the end of the month.

Government bodies featured heavily too, with claimed leaks of personal and internal data from a Brazilian government IT service agency, a French education administration agency, an Argentine identity management agency, an electoral management agency in the Dominican Republic and a Chinese law enforcement agency. ATCP is explicit that the Brazilian and French figures rest on the attackers' word alone and have not been independently verified.

Saudi Arabia drew a concentrated run of claims across logistics and transport firms, digital service platforms, IPTV services, IT companies and hotel operators. In Sweden, enterprise administrator credentials for virtualization and remote access products used by technology and SaaS companies were advertised for sale, which is the kind of listing that precedes an intrusion rather than reporting one.

Check the sample before you brief the board

The practical lesson from a month like this is that a dark web post is an allegation, not a finding. Before an organization concedes a breach or a customer count, the sample needs to be pulled and matched against real records, and the field structure needs to look like something that organization would actually hold. Credentials being sold deserve faster attention than a leak claim, because those point forward rather than back. A number on a forum is a marketing figure, written by someone with every incentive to inflate it.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions