DEPLOYDatabase

Incident · Other

Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets

In November 2025, a massive data leak from Chinese cybersecurity firm Knownsec was posted on GitHub by an actor using the alias t1g3r. The leak exposed over 12,000 internal documents including offensive cyber tools (GhostX, Un-Mail, Windows T-Horse RAT), global surveillance target lists covering 20+ countries, and evidence of stolen data including 95 GB of Indian immigration records and 3 TB of South Korean call logs.

The documents revealed Knownsec operates as a state-aligned cyber contractor supporting Chinese intelligence objectives, with clients including Public Security Bureaus, the State Grid Corporation, and China Telecom. The leak was analyzed by Resecurity, DomainTools, and Field Effect, among others.

Occurred 2025-11-07 · Knownsec

How to read this record

Incident records on DEPLOY are compiled from public sources (regulatory filings, news reports, and operator disclosures) and reflect what has been reported and tracked to date. They are not legal findings, determinations of fault, or safety ratings, and may be updated as new information is verified. See the sources below for the underlying references.

Machine-readable surfaces

Sources (2)

  1. Resecurity · https://www.resecurity.com/blog/article/knownsec-data-breach-a-trove-of-espionage-tradecraft-with-an-insider-narrative · 2025-12-31
  2. DomainTools Investigations · https://dti.domaintools.com/research/the-knownsec-leak-yet-another-leak-of-chinas-contractor-driven-cyber-espionage-ecosystem · 2026-01-09

Status history

  • Active · 2026-08-27 · agent:recon

Common questions

What happened in Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets?
In November 2025, a massive data leak from Chinese cybersecurity firm Knownsec was posted on GitHub by an actor using the alias t1g3r. The leak exposed over 12,000 internal documents including offensive cyber tools (GhostX, Un-Mail, Windows T-Horse RAT), global surveillance target lists covering 20+ countries, and evidence of stolen data including 95 GB of Indian immigration records and 3 TB of South Korean call logs. The documents revealed Knownsec operates as a state-aligned cyber contractor supporting Chinese intelligence objectives, with clients including Public Security Bureaus, the State Grid Corporation, and China Telecom. The leak was analyzed by Resecurity, DomainTools, and Field Effect, among others.
When did this incident occur?
The incident is recorded as occurring on November 7, 2025 on the DEPLOY registry. The date reflects the underlying real-world event, not the registry record's creation date.
Who was involved in Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets?
The incident is recorded as involving Knownsec on the DEPLOY registry. No specific robot model is linked to this incident in the registry.
Has anyone responded to Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets?
No responses to this incident are recorded on the DEPLOY registry. Operators, manufacturers, or affected parties can submit responses to the editorial team; absence is not a guarantee no response was issued.
What is the current status of Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets?
This incident is an active record on the DEPLOY registry; no retraction or correction has been issued.
Methodology: Verified · 2 sources (no primary) · last reviewed 2026-09-29

Verification posture

Verified

Low confidence

Review state

Stable

Last reviewed 2026-09-29

Sources by quality tier

2
unclassified
Unclassified source

The framework is documented at /methodology. Corrections at /corrections. Reviewer: DEPLOY editorial team.

Methodology surface for Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets.

Deploy Watch

Track this incident.

We notify you when the regulator updates the record, the remedy status changes, or a related incident surfaces.


Canonical ID d099d8f4-57b1-4f14-b9da-b27975ecf5ec