HeadlinesBriefing favicon HeadlinesBriefing.com

Sweden E-Government Source Code Leaked by ByteToBreach Threat Actor

Hacker News •
×

A threat actor claiming the moniker ByteToBreach has leaked the full source code of Sweden's national e-government platform. The actor asserts this was obtained through a heavily compromised infrastructure belonging to CGI Sverige AB, the Swedish subsidiary of global IT services firm CGI Group. This incident follows the actor's disclosure of a breach at Viking Line just yesterday, highlighting a pattern of targeting critical infrastructure. The actor emphasizes this is the complete platform source code, not partial configuration snippets, and states that citizen PII databases and electronic signing documents were also compromised but are being sold separately.

Technical details reveal the attack leveraged multiple vulnerabilities, including a full Jenkins compromise, Docker escape via the Jenkins user being in the Docker group, SSH private key pivots, analysis of local .hprof files for reconnaissance, and SQL copy-to-program pivots. The leaked data includes the full E-Gov platform source code, staff database, API document signing systems, Jenkins SSH pivot credentials, RCE test endpoints, initial foothold details, and jailbreak artifacts. The actor explicitly blames CGI infrastructure for the breach, referencing the Viking Line and Slavia Pojistovna incidents as other examples of their targeting.

The source code is being released for free with multiple backup download links, while the citizen databases and electronic signing documents are being sold separately. This leak represents a severe compromise of Sweden's digital government infrastructure, exposing critical vulnerabilities in CGI Sverige's security posture and the systems managing sensitive citizen data and electronic signatures.