BreachesSep 30, 2026
Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data
Attacker joins recreation platform as member to plant webshells and steal card data.
Summary
Threat actors compromised three web servers of a recreation management platform used by local municipalities and parks organizations. The attackers gained access by signing up as members, then planted webshells to gain further control and search for payment card data. The intrusion was first observed on September 10, 2026.
Entities
webshells (product)Huntress (vendor)