The operators claimed to have targeted several hundred companies through a single enterprise SaaS platform, and threatened to publish data taken from those tenants unless extortion demands were met. Reporting describes millions of records compromised across the disclosed incidents.
The "several hundred" figure originates with the attackers and is recorded here as a claim.
This Is Concentration Without A Shared Compromise
The corpus files supplier concentration constantly — one vendor breached, dozens of downstream victims, as at 25-0814 and 25-0801. This is a different shape and produces the same outcome.
The platform was not compromised. Each tenant was reached separately, through its own employees, using its own legitimate authorisation flow. What concentrated was not the data but the *method*: every customer of a widely-adopted platform presents the same interface, the same consent screen and the same vocabulary for a caller to use.
Standardisation is what makes enterprise software work. It also means research costs are paid once and reused indefinitely — the sector-rotation argument at 25-0512, generalised from an industry to a product.
The Platform Vendor Cannot Fix It And Cannot Escape It
No defect existed to patch. The vendor’s consent model worked as designed; its customers authorised applications they should not have.
And yet the vendor is the only party positioned to act at the scale of the problem — by changing enrolment defaults, restricting connected-app authorisation, or alerting on anomalous grants across tenants. The party with no fault has the only lever, which is an accountability structure this database has not previously recorded in quite this form.
Compiled from published research and regulatory advisories, listed below. The victim count is an attacker claim and is not established. Corrections: corrections@forensicpost.com.