Swedish e-government platform source code was leaked by threat actor ByteToBreach after compromising CGI Sverige AB infrastructure through Jenkins compromise, Docker escape, and SSH pivoting. The leak includes full platform source code, staff databases, API signing systems, and separately-sold citizen PII databases and electronic signing documents.
Swedish e-government platform source code was leaked by threat actor ByteToBreach after compromising CGI Sverige AB infrastructure, exposing Jenkins credentials, Docker escape vectors, SSH pivots, and citizen PII databases. The attack chain included Jenkins compromise, Docker group privilege escalation, and SQL injection pivots, with the full platform code released publicly alongside separately monetized citizen databases.