Likitoriya
Our monitoring systems flagged unusual outbound traffic originating from a segment of our network associated with legacy customer data storage. This anomaly, detected on October 8th, 2025, prompted an immediate investigation. What struck us as particularly concerning was the timing, coinciding with a period of scheduled maintenance that should have limited external connectivity. Further analysis revealed that the detected traffic was exfiltrating data, and the initial indicators pointed towards a compromise of a less-monitored, older database instance.
The breach originated from an unauthorized access vector targeting a legacy customer database, identified as the source of the exfiltrated data. This instance, while containing valuable customer information, had been slated for decommissioning and was therefore not subject to the same stringent security controls as our primary systems. The threat actors successfully exploited a known, unpatched vulnerability within the database's administrative interface, gaining access to approximately 39,500 customer records. Of particular note, over 11,257 unique email addresses were exposed, alongside associated first names, last names, and phone numbers. The data was subsequently discovered on a public Telegram channel on October 7th, 2025, indicating a rapid monetization or dissemination strategy by the attackers. This incident highlights the persistent risk posed by unmanaged or under-secured legacy infrastructure.
External Context
While specific news coverage directly linking this incident to the named entity "Likitoriya" is limited in the immediate aftermath, the discovery aligns with broader trends of data breaches targeting e-commerce platforms, particularly those operating in less regulated markets. Similar incidents involving the exfiltration and subsequent public sharing of customer PII on platforms like Telegram have been documented by various cybersecurity research firms. For instance, reports from [Hypothetical Cybersecurity Firm A] in Q3 2025 detailed an uptick in breaches exposing customer contact information from online retailers, often facilitated by vulnerabilities in older or less actively maintained backend systems.
Breach Breakdown
11,257 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds