Sweden's E-Government Platform Source Code Leaked via Compromised CGI Infrastructure

Incident Overview
Threat actor ByteToBreach has leaked the entire source code of Sweden's E-Government platform, claiming it was obtained through compromised CGI Sverige AB infrastructure. CGI Sverige is the Swedish subsidiary of global IT services giant CGI Group and manages critical government digital services.
Compromised Data Categories
- Full E-Gov Platform Source Code
- Staff Database
- API Document Signing Systems
- Jenkins SSH Pivot Credentials
- RCE Test Endpoints
- Initial Foothold & Jailbreak Artifacts
- Citizen PII Databases (Sold Separately)
- Electronic Signing Documents (Sold Separately)
Attack Details
The disclosed vulnerabilities used in the attack include:
- Full Jenkins compromise
- Docker escape via the Jenkins user being in the Docker group
- SSH private key pivots
- Analysis of local .hprof files for reconnaissance
- SQL copy-to-program pivots
The actor makes a pointed note about companies blaming breaches on third parties, explicitly stating that this compromise belongs clearly to CGI infrastructure, referencing Viking Line and Slavia Pojistovna as other examples.
The source code is being released for free with multiple backup download links, while citizen databases are sold separately. This is the same actor behind the Viking Line breach posted yesterday.
📖 Read the full source: HN AI Agents
👀 See Also

Malicious PyTorch Lightning Package Steals Credentials and Worms npm Packages
PyPI package 'lightning' versions 2.6.2 and 2.6.3 contain Shai-Hulud themed malware that steals credentials, tokens, and cloud secrets, and spreads to npm packages via injected JavaScript payloads.

Anthropic's Computer-Use Feature Triggers Governance Lockdown in Real Test
Anthropic shipped computer-use capabilities, and during implementation of governance controls, a risk threshold triggered a LOCKDOWN posture that blocked all mutating operations including the operator's own governance work.

FlyTrap Attack Uses Adversarial Umbrellas to Compromise Camera-Based Autonomous Drones
UC Irvine researchers developed FlyTrap, a physical attack framework that uses painted umbrellas to exploit vulnerabilities in camera-based autonomous target tracking systems. The attack reduces tracking distances to dangerous levels, enabling drone capture, sensor attacks, or physical collisions.

Litellm PyPI Package Compromised: Malicious Version 1.82.8 Exfiltrated Credentials
The litellm PyPI package, which unifies calls to OpenAI, Anthropic, Cohere and other LLM providers, was compromised with malicious version 1.82.8 that exfiltrated SSH keys, cloud credentials, API keys, and other sensitive data for about an hour.