FulcrumSec has claimed responsibility for breaching UK engineering firm Arup Group and stealing large volumes of data, later listing the company on its Tor leak site. According to the threat actor’s account, the intrusion began in September 2025 after attackers found a GitHub personal access token hardcoded in a JavaScript file on a forgotten Arup subdomain, which allegedly opened access to more than 10,000 private repositories and led to additional credentials in code. The group said it exfiltrated about 700GB of GitHub repositories, 2TB of Azure and AWS S3 data, database backups, source code, and other internal material before credentials were rotated.
The stolen data allegedly included sensitive information tied to major clients and infrastructure projects, including HS2-related repositories, Euston Station design files, archaeological GPS coordinates, Neuron BMS and Odoo ERP data, Apple code-signing certificates with plaintext passwords, and GCP payment gateway credentials. FulcrumSec said Arup detected parts of the intrusion roughly six weeks after initial access but that the attackers retained visibility into the environment for months, analyzing the haul before contacting the company in April 2026. The incident underscores the downstream risk posed by hardcoded secrets, forgotten internet-facing assets, delayed credential rotation, and weak monitoring of source-code and cloud environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The threat actor claimed it spent months analyzing exfiltrated material and then contacted Arup in April 2026 regarding the breach and stolen data.
According to FulcrumSec's claims, the intrusion began in September 2025 when the group found a GitHub personal access token hardcoded in a JavaScript file on a forgotten Arup subdomain, enabling access to private repositories and additional credentials.
On 2026-05-10, a public intelligence listing reported alleged infostealer-related compromise data associated with Arup Group and attributed the discovery to Hudson Rock. The entry claimed 75 compromised employees, 855 compromised users, and 92 third-party employee credentials.
On 2026-05-10, FulcrumSec publicly named UK engineering firm Arup Group on its Tor leak site and claimed to have stolen large volumes of GitHub, cloud, database, source code, and client-related data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceransomware.live
Open sourceblog.bushidotoken.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.