Back to Feed
BreachesSep 30, 2026

Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data

Attacker joins recreation platform as member to plant webshells and steal card data.

Summary

Threat actors compromised three web servers of a recreation management platform used by local municipalities and parks organizations. The attackers gained access by signing up as members, then planted webshells to gain further control and search for payment card data. The intrusion was first observed on September 10, 2026.

Entities

webshells (product)Huntress (vendor)