-
An underground forum actor claims to hold API keys and MySQL access details for an unnamed billion-dollar company.
-
The alleged company stores customer identification photos and other files in an Amazon Web Services cloud setup.
-
The actor reportedly seeks help from someone with web intrusion and ransomware skills to reach the database.
An unidentified company with more than $1 billion in yearly revenue may have exposed access credentials. Dark Web Informer shared the claim in a post on X, citing an underground forum actor. The company involved has not been publicly named.
According to the post, the actor claims to have API keys and remote MySQL connection details. The actor also says an IP legal currently blocks direct database access.
An IP legal allows only approved network addresses to connect to a system. The actor reportedly asked for help from someone with web intrusion and ransomware experience.
The alleged target reportedly keeps customer identification photos and other files in an Amazon Web Services, or AWS, cloud setup. The available information does not confirm whether the credentials work or whether anyone accessed the customer files.
Credentials Allegedly Linked to Company Database
The claim centers on several types of access details. These include API keys and remote MySQL connection information linked to the unnamed company. API keys can help software connect with other online services.
MySQL is a database system that organizations use to store and manage information. Exposed credentials can fuel phishing campaigns, scammers in France have been using photos and voice messages to trick delivery victims.
The actor reportedly said an IP legal is stopping direct access to the database. This means the database only accepts connections from approved network addresses.
The forum post therefore appears to seek another person who can help bypass that barrier. The requested skills reportedly include web intrusion and ransomware expertise. The alleged database may also contain sensitive customer material.
The post claims that customer identification photos and other files sit inside an AWS environment. However, no public evidence currently confirms that the credentials belong to the unnamed company. There is also no confirmation that the actor accessed its database or customer files.
The claim comes as researchers continue to warn about exposed access details online. A March 2026 study called “Keys on Doormats: Exposed API Credentials on the Web” examined 10 million webpages.
The researchers found 1,748 unique credentials from 14 service providers across nearly 10,000 webpages. Their findings also showed that some credentials stayed exposed for months or even years.
Recent Breaches Show How Credentials Can Open Doors
Recent incidents have also shown how stolen or exposed credentials can provide access to connected systems.
In June, TechCrunch reported on a breach at Klue. Hackers reportedly entered Klue’s systems using a compromised legacy credential linked to an integration service. The attackers then used access to steal data from customer cloud systems. The stolen information reportedly included business contact details and other customer records.
A later TechCrunch report said the credential dated back to 2022. Klue said the credential had originally been given to a third party for a limited pilot. The company said it was reviewing how it manages credentials and controls access from outside vendors.
Another case involved Vercel, a company that hosts apps and websites. TechCrunch reported that hackers breached Vercel’s internal systems. The attackers reportedly used a connection involving third-party software to take over an employee’s Google account. They then reached some internal systems that contained unencrypted credentials and customer information.
Alleged Customer Data Exposure Remains Unclear
The latest claim could be serious if the alleged access details are genuine. Customer identification photos are sensitive records that can reveal personal information about individuals. Still, the available information does not establish that any customer data was stolen. It also does not show that the actor successfully entered the database.
The unnamed company’s identity remains unknown. The claim comes from an underground forum actor and was shared by Dark Web Informer. No affected company has publicly confirmed the alleged compromise.
No independent researcher has publicly confirmed that the actor possesses valid API keys or MySQL credentials. The same applies to the alleged customer identification photos and other files. There is currently no public evidence showing that the actor accessed or removed those files.
For now, the central claim remains that an actor says they possess credentials connected to a large company. The actor reportedly faces an IP legal that limits database access. The post also reportedly seeks outside help to reach the database. Until more evidence appears, the identity of the company and the status of the alleged credentials remain unknown.