Home All Victims A-Plus Software Limited

A-Plus Software Limited

ShadowByt3$

This record tracks a ransomware attack claimed by the ShadowByt3$ group against A-Plus Software Limited. It collects the publicly disclosed attack details — sector, location and timeline — as published on the operator's leak site and indexed by Breach House.

Window Zero

EXPOSURE GAP

Window Zero is the time the breach stayed in the open before anyone said so — the gap between when the attack was first discovered on the operator's leak site (t1) and when it was publicly disclosed (t2). The wider this window, the longer victims, staff and customers were exposed with no warning.

0days open
t1 · Published t2 · Pending
Aug 25, 2026Not disclosed yet
Country
United Kingdom
Business Category
IT
Employees
51-100
Discovered
2026-08-25
Published
August 25, 2026
Disclosed / Notified
Not disclosed yet
Victim ID
aEvcDM1ZPqVB

Attack Summary

We Breached A-plus through a sql injection vulnerability and downloaded everything in there backend. We gained access to there system on 08/18/2026 The following data was stolen: 1. Website User Data (`usr.csv`) - This file contains the administrative backend infrastructure for the website, exposing: - 10 internal accounts, including the usernames `admin`, `debuger`, `camby`, `asuka`, `jimmy`, `ricole`, and `green`. - Password hashes (SHA-1 format) revealing that almost all administrative users shared the exact same password. - Internal access metadata 2. Marketing and Public Web Content - The remaining four files contain the text, configuration, and structural layout used to display information to visitors on `a-plussoft.com`: `- products.csv` 13 lines): The master list of software solutions and mobile apps sold by the company (such as SalesAnywhere). `- product_content.csv` (101 lines): The detailed marketing descriptions, features, specifications, and text modules displayed on individual product pages. `- news.csv` (89 lines): The text content of all historical corporate announcements, updates, and press releases published by the company. `- news_cate.csv` (2 lines): The category organization tags used to sort the news section on the website Uncompressed size total records: 211 2,787,292 Bytes, which equals 2.6582 Megabytes (MB). mirror 1: https://anonfilesnew.com/s/XtgbXhRkQQ8 mirror 2: https://pixeldrain.com/u/jUpuUyj9

Leak Screenshots

SAMPLE

Proof-of-breach screenshots the operator posted from the stolen data. Previews are redacted and locked — the originals are available on HaveIBeenRansom.

file_tree.png
finance_2024.xlsx
passport_scan.jpg
contract_signed.pdf
Sign in or explore HaveIBeenRansom to view the full leak gallery.
View leak gallery →

Dark Web Exposure

Findings for a-plussoft.com — indexed by HaveIBeenRansom.
26
found in Infostealer logs
2
found in Traditional breaches
0
found in Ransomware leaks
Dropbox_BF.7z
B F R e p o V 3 F i l e s · breach
••• emails
Leak volumes are locked
Sign in to reveal how many records each source exposed.
Want the complete picture — passwords, machines, full leak files? It's all searchable on HaveIBeenRansom.
Search this victim →
Visit Website Original Post View Group: ShadowByt3$
Legal Disclaimer: This ransomware victim record reflects information published on the operator's leak site. Breach.house does not acquire, download, host, access or redistribute unlawfully obtained data. It indexes only publicly visible information posted by ransomware, breach and infostealer operators and open web sources, without accessing the underlying stolen content. The service supports public awareness, legitimate research and cyber-resilience.