π΄ββ οΈ Shadowbyt3$ has just published a new victim : A-Plus Software Limited
Brief
We Breached A-plus through a sql injection vulnerability and downloaded everything in there backend. We gained access to there system on 08/18/2026
The following data was stolen:
- Website User Data (`usr.csv`)
- This file contains the administrative backend infrastructure for the website, exposing:
- 10 internal accounts, including the usernames `admin`, `debuger`, `camby`, `asuka`, `jimmy`, `ricole`, and `green`.
- Password hashes (SHA-1 format) revealing that almost all administrative users shared the exact same password.
- Internal access metadata
- Marketing and Public Web Content
- The remaining four files contain the text, configuration, and structural layout used to display information to visitors on `a-plussoft.com`:
`- products.csv` 13 lines): The master list of software solutions and mobile apps sold by the company (such as SalesAnywhere).
