INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Moldova's Government Denies Allegations of Hackers' Claims and Leaked Data

| 2026-02-19 12:32 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
A data leak on a dark web listing allegedly from Moldova's [IOC HIDDEN • LOGIN REQUIRED].md portal, which enables residents to register and apply for energy bill compensation, has raised questions about the government's claims of network security. The leaked data does not support hackers' claims that they obtained it through selling access credentials on the darknet; instead, it suggests a potential breach occurred prior to their claim in January 2026 when the Bashe Team (formerly Eraleign APT73) listed Compensatii on its site and posted a .csv file as proof. The leak affects approximately millions of residents who registered for compensation using sensitive personal information such as name, surname, IDNP, energy consumption data, mortgage loan amounts, and IBAN accounts; the leaked data includes this information from over 1 million households in Moldova.
Technical Mitigations AI-generated
• Monitor for suspicious activity on dark web marketplaces, such as the one where Bashe Team listed Compensatii data. • Implement a robust authentication method to prevent unauthorized access to sensitive data, similar to the qualified electronic signature used by STISC (Information Technology and Cyber Security Service). • Regularly review and update software and systems for vulnerabilities, including those related to outdated or weak passwords.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ca•••••.gov
co•••••.gov
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA NORTH_AMERICA financefinance
Intelligence Sources