# ShadowByte3 claims A-Plus Software breach

Published: 2026-08-25 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/9eb9c094-c99e-5928-ada9-197108965ea7/shadowbyte3-claims-a-plus-software-breach

> A ransomware/extortion group claims to have exfiltrated backend databases from A-Plus Software via SQL injection, including admin credentials and site content.

Ransomware.live tracked a data leak listing for A-Plus Software (a-plussoft.com), posted by a threat actor identified as ShadowBy3. The actor claims initial access was gained on 2026-08-18 via a SQL injection vulnerability, allowing exfiltration of the site's backend database. The published dataset reportedly includes an administrative user table (usr.csv) with 10 internal accounts and SHA-1 password hashes, several of which allegedly share an identical password, along with marketing and content files (products, product descriptions, news articles, and category tags) totaling roughly 2.66 MB across 211 records.

The leak listing includes mirror links to file-sharing services (anonfilesnew.com and pixeldrain.com) hosting the alleged stolen archive, along with a leak screenshot and DNS reconnaissance showing the victim uses Microsoft 365 for email. No specific ransomware family or encryption payload is mentioned in the posting — the incident appears to be a data-extortion/leak-site listing rather than confirmed deployed ransomware. Given the weak password hygiene reportedly exposed (shared credentials, SHA-1 hashing) and lack of corroborating technical detail, defenders at similarly configured organizations should prioritize input validation on public-facing SQL-backed applications, enforce unique strong credentials for admin accounts, and move away from SHA-1 for password storage.

This is a single-victim extortion claim rather than a widescale campaign; there's no indication of broader targeting patterns, additional victims, or attribution to a known ransomware brand in the available reporting.

## Mentioned in this report

- Threat actors: ShadowByte3

Source reporting: https://www.ransomware.live/id/QS1QbHVzIFNvZnR3YXJlIExpbWl0ZWRAU2hhZG93Qnl0MyQ=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9eb9c094-c99e-5928-ada9-197108965ea7/shadowbyte3-claims-a-plus-software-breach.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
