Dataminr INTEL BRIEF

Cyber Intel Brief: xpl0itrs Claims 569GB RapidFort Breach Tied to CanisterWorm Campaign

Threat actor xpl0itrs claims a 569GB breach of software supply chain vendor RapidFort, tied to the CanisterWorm campaign conducted jointly with TeamPCP. The claim includes government-affiliated data and alleges RapidFort has yet to notify customers. Here's what defenders need to know.

Cyber Intel Brief: xpl0itrs Claims 569GB RapidFort Breach Tied to CanisterWorm Campaign
DATE July 23, 2026
AUTHOR Dataminr Threat Research
SHARE
CYBER DEFENSE SECURITY OPERATIONS CENTER

Key Takeaways

  • Credible but Unverified Claim: Threat actor xpl0itrs is advertising 569GB of data allegedly exfiltrated from RapidFort, a software supply chain security vendor with reported deployments across enterprise and U.S. government customers. RapidFort has not issued a public statement confirming or denying the claim at time of writing. However, Knox Systems published a statement today about the RapidFort incident and that they were unaffected.
  • Attributed to a Known Supply Chain Campaign: The actor states the data originates from “CanisterWorm,” a joint operation previously and publicly attributed to xpl0itrs and TeamPCP. Both groups have a documented history of collaborative software supply chain compromises with cascading downstream victim impact.
  • Delayed or Absent Disclosure Alleged: xpl0itrs claims the data dates to March 2026, extending the potential exposure window for any organization integrated with RapidFort’s platform.
  • Government Data Alleged: The actor claims the dataset includes data belonging to U.S. government and defense-affiliated entities. This claim is unconfirmed; if substantiated, it would materially raise the incident’s national-security and regulatory profile.
  • The Advantage of Contextualized Alerting: If RapidFort sits in your vendor stack, you’d have seen more than a bare claim – you’d have seen why it mattered. Automated analysis tied the alleged dataset (pipeline hardening data, vulnerability scan results, and AWS/Azure release credentials) to concrete supply-chain and credential-abuse risk as soon as xpl0itrs posted it, giving you enough specificity to start vendor questions and credential rotation before RapidFort issued any statement.

Incident Overview

At 18:00 local time on 21 July 2026, Dataminr detected the threat actor xpl0itrs, posting under the persona “Com Boss” on a dark web forum, advertising for sale allegedly 569GB of data containing 140,061 files extracted from 48 S3 buckets. The data was allegedly stolen from RapidFort, a software supply chain and container security vendor with a reported customer base that includes U.S. government organizations. The actor attributes the intrusion to “CanisterWorm,” a supply chain campaign previously and publicly claimed as a joint operation between xpl0itrs and TeamPCP, two threat actor groups with an established pattern of collaborative software supply chain compromises and cascading downstream victim impact.

xpl0itrs claims the data dates to March 2026 and that the dataset includes data belonging to U.S. government and defense-affiliated entities, a detail that, if substantiated, would significantly raise the incident’s national security and regulatory profile. RapidFort has not issued a statement confirming or denying the claim at time of writing, and the incident should be treated as unverified but credible pending independent confirmation.

Dataminr Alert

Dataminr alerting on this incident related to xpl0itrs breaching RapidFort. Enhanced with Intel Agents
Dataminr alerting on this incident related to xpl0itrs breaching RapidFort. Enhanced with Intel Agents
The post by xpl0itrs posting the allegedly stolen data for sale
The post by xpl0itrs posting the allegedly stolen data for sale.

Technical Details

The claimed dataset totals 569GB across 140,061 files, reportedly extracted from 48 distinct AWS S3 buckets. xpl0itrs has referenced an accompanying manifest of the affected buckets, though its specific contents were not visible in the material reviewed. The actor has not disclosed the initial access vector used to obtain this data, but Independently documented CanisterWorm reporting associates the broader campaign with credential and access-token abuse — specifically stolen npm tokens and CI/CD credentials taken from the Trivy compromise — rather than direct S3 bucket exfiltration. Whether the RapidFort claim reflects a downstream consequence of that campaign, a separate intrusion opportunistically branded with the CanisterWorm name, or an entirely unrelated or fabricated claim cannot currently be determined. 

Threat Actor & Motivation

xpl0itrs is a financially motivated threat actor group active since early 2026, known for monetizing software supply chain compromises through forum-based data and access sales. The group maintains a close operational partnership with TeamPCP, with both groups having previously claimed joint responsibility for the CanisterWorm campaign and other supply chain intrusions. xpl0itrs’ public-facing persona has previously signaled escalating operations, including the announced launch of a dedicated leak site. The RapidFort listing is consistent with the group’s established playbook: extract data from a supply chain vendor, package it for sale, and use the presence of high-value data (in this case, alleged government-affiliated records) to maximize buyer interest and pressure on the alleged victim organization.

This targeting pattern is a deliberate strategic choice, not incidental: rather than attacking government agencies or critical-infrastructure operators directly, xpl0itrs and TeamPCP go after the shared suppliers those organizations depend on, converting a single vendor compromise into leverage over many downstream, harder-to-reach targets at once.

Immediate Actions & Recommendations

  • Map third-party concentration risk: Identify every downstream system, customer, or regulatory obligation that depends on RapidFort as a single point of assurance (FedRAMP hardening, NIS2 supply-chain evidence, or equivalent), since a supplier-level compromise can create simultaneous exposure across otherwise unrelated organizations.
  • Engage RapidFort directly: Organizations using Rapidfort should reach out to their point of contact for a private statement and details on this claim.
  • Rotate credentials and tokens: Any organization with API keys, service accounts, or CI/CD integration tokens tied to RapidFort should rotate them as a precaution, pending vendor confirmation.
  • Audit third-party access: Review OAuth/API token scopes granted to RapidFort integrations and monitor for anomalous activity from associated infrastructure.
  • Hunt for credential abuse indicators: Given the CanisterWorm/xpl0itrs/TeamPCP pattern of PAT and OAuth token abuse, review GitHub, GitLab, or equivalent audit logs for unusual PAT usage or spikes in secrets-access events.
  • Assess government data exposure: Organizations with government or defense-affiliated contracts that use RapidFort should evaluate whether any of their data could be implicated, and prepare for potential regulatory or contractual notification obligations if the claim is substantiated.
  • Monitor for secondary listings: Track dark web forums and future xpl0itrs/TeamPCP posts for additional data samples, updated pricing, or confirmation of buyer activity, which would indicate elevated urgency.

2026 Cyber Threat Landscape Report

In a time of increasing cyber threats and AI-driven attacks, security teams need actionable insights to drive a preemptive cyberdefense strategy. This report analyzes global risks and offers the intelligence needed for a proactive cybersecurity strategy.

Download Report

Jul 23, 2026

SHARE
  • Cyber Defense
  • Security Operations Center
  • Cyber Risk
  • Intel Brief