Sweden's E-Government Platform Source Code Leaked via Compromised CGI Infrastructure

✍️ OpenClawRadar📅 Published: March 13, 2026🔗 Source
Sweden's E-Government Platform Source Code Leaked via Compromised CGI Infrastructure
Ad

Incident Overview

Threat actor ByteToBreach has leaked the entire source code of Sweden's E-Government platform, claiming it was obtained through compromised CGI Sverige AB infrastructure. CGI Sverige is the Swedish subsidiary of global IT services giant CGI Group and manages critical government digital services.

Compromised Data Categories

  • Full E-Gov Platform Source Code
  • Staff Database
  • API Document Signing Systems
  • Jenkins SSH Pivot Credentials
  • RCE Test Endpoints
  • Initial Foothold & Jailbreak Artifacts
  • Citizen PII Databases (Sold Separately)
  • Electronic Signing Documents (Sold Separately)
Ad

Attack Details

The disclosed vulnerabilities used in the attack include:

  • Full Jenkins compromise
  • Docker escape via the Jenkins user being in the Docker group
  • SSH private key pivots
  • Analysis of local .hprof files for reconnaissance
  • SQL copy-to-program pivots

The actor makes a pointed note about companies blaming breaches on third parties, explicitly stating that this compromise belongs clearly to CGI infrastructure, referencing Viking Line and Slavia Pojistovna as other examples.

The source code is being released for free with multiple backup download links, while citizen databases are sold separately. This is the same actor behind the Viking Line breach posted yesterday.

📖 Read the full source: HN AI Agents

Ad

👀 See Also

OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems
Security

OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems

A security analysis reveals 500,000 OpenClaw instances are publicly accessible, with 30,000 having known security risks and 15,000 exploitable through known vulnerabilities. The default installation disables authentication and binds to 0.0.0.0, exposing agent setups to the open internet.

OpenClawRadar
ClawVault Security Enhancement Adds Sensitive Data Detection for OpenClaw
Security

ClawVault Security Enhancement Adds Sensitive Data Detection for OpenClaw

A new enhancement to ClawVault adds real-time sensitive data detection and automatic sanitization for OpenClaw API traffic, intercepting plaintext passwords, API keys, and tokens before they reach LLM providers.

OpenClawRadar
OpenClaw Patches Critical Privilege Escalation in /pair Approve Path
Security

OpenClaw Patches Critical Privilege Escalation in /pair Approve Path

OpenClaw 2026.3.28 fixes a critical security vulnerability (GHSA-hc5h-pmr3-3497) where the /pair approve command allowed users with pairing privileges to approve device requests for broader scopes, including admin access. Affected versions are <= 2026.3.24.

OpenClawRadar
mcp-scan: Security scanner for MCP server configurations
Security

mcp-scan: Security scanner for MCP server configurations

mcp-scan checks MCP server configurations for security issues including secrets in config files, known vulnerabilities in packages, suspicious permission patterns, exfiltration vectors, and tool poisoning attacks. It auto-detects configs for Claude Desktop, Cursor, VS Code, Windsurf, and 6 other AI clients.

OpenClawRadar