Ransomware victim disclosure
← All victimsA-Plus Software Limited
Claimed by ShadowByt3$ · listed 2 hours ago
Status timeline
- ListedAug 25, 2026
- Data leakeddate unknown
At a glance
- Group
- ShadowByt3$
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Technology
- Listed on leak site
- Aug 25, 2026
What the group claims
We Breached A-plus through a sql injection vulnerability and downloaded everything in there backend. We gained access to there system on 08/18/2026 The following data was stolen: 1. Website User Data (`usr.csv`) - This file contains the administrative backend infrastructure for the website, exposing: - 10 internal accounts, including the usernames `admin`, `debuger`, `camby`, `asuka`, `jimmy`, `ricole`, and `green`. - Password hashes (SHA-1 format) revealing that almost all administrative users shared the exact same password. - Internal access metadata 2. Marketing and Public Web Content - The remaining four files contain the text, configuration, and structural layout used to display information to visitors on `a-plussoft.com`: `- products.csv` 13 lines): The master list of software solutions and mobile apps sold by the company (such as SalesAnywhere). `- product_content.csv` (101 lines): The detailed marketing descriptions, features, specifications, and text modules displayed on individual product pages. `- news.csv` (89 lines): The text content of all historical corporate announcements, updates, and press releases published by the company. `- news_cate.csv` (2 lines): The category organization tags used to sort the news section on the website Uncompressed size total records: 211 2,787,292 Bytes, which equals 2.6582 Megabytes (MB). mirror 1: https://anonfilesnew.com/s/XtgbXhRkQQ8 mirror 2: https://pixeldrain.com/u/jUpuUyj9
Sources
- Victim sitewww.a-plussoft.com
- Leak posthttps://transfer.it/t/Ek7m9dkzhZ6Y
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

