_Incident · Other_

# Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets

Canonical ID: `d099d8f4-57b1-4f14-b9da-b27975ecf5ec`

- **Occurred:** 2025-11-07
- **Kind:** `other`
- **Status (derived):** active
- **Company:** [Knownsec](/companies/knownsec.md) (id: `d66c7ff3-115f-45ca-9b4d-a90a164caf22`)

In November 2025, a massive data leak from Chinese cybersecurity firm [Knownsec](/companies/knownsec.md) was posted on GitHub by an actor using the alias t1g3r. The leak exposed over 12,000 internal documents including offensive cyber tools (GhostX, Un-Mail, Windows T-Horse RAT), global surveillance target lists covering 20+ countries, and evidence of stolen data including 95 GB of Indian immigration records and 3 TB of South Korean call logs. The documents revealed Knownsec operates as a state-aligned cyber contractor supporting Chinese intelligence objectives, with clients including Public Security Bureaus, the State Grid Corporation, and China Telecom. The leak was analyzed by Resecurity, DomainTools, and Field Effect, among others.

## Sources (2)

1. **Resecurity** · https://www.resecurity.com/blog/article/knownsec-data-breach-a-trove-of-espionage-tradecraft-with-an-insider-narrative · 2025-12-31
2. **DomainTools Investigations** · https://dti.domaintools.com/research/the-knownsec-leak-yet-another-leak-of-chinas-contractor-driven-cyber-espionage-ecosystem · 2026-01-09

## Status history

- **active** · 2026-08-27 · agent:recon

## Common questions

### What happened in Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets?

In November 2025, a massive data leak from Chinese cybersecurity firm Knownsec was posted on GitHub by an actor using the alias t1g3r. The leak exposed over 12,000 internal documents including offensive cyber tools (GhostX, Un-Mail, Windows T-Horse RAT), global surveillance target lists covering 20+ countries, and evidence of stolen data including 95 GB of Indian immigration records and 3 TB of South Korean call logs. The documents revealed Knownsec operates as a state-aligned cyber contractor supporting Chinese intelligence objectives, with clients including Public Security Bureaus, the State Grid Corporation, and China Telecom. The leak was analyzed by Resecurity, DomainTools, and Field Effect, among others.

### When did this incident occur?

The incident is recorded as occurring on November 7, 2025 on the DEPLOY registry. The date reflects the underlying real-world event, not the registry record's creation date.

### Who was involved in Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets?

The incident is recorded as involving Knownsec on the DEPLOY registry. No specific robot model is linked to this incident in the registry.

### Has anyone responded to Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets?

No responses to this incident are recorded on the DEPLOY registry. Operators, manufacturers, or affected parties can submit responses to the editorial team; absence is not a guarantee no response was issued.

### What is the current status of Massive data leak from Knownsec exposes 12,000+ internal documents revealing state-linked cyber espionage tools and global targets?

This incident is an active record on the DEPLOY registry; no retraction or correction has been issued.


_API: GET /v1/incidents/d099d8f4-57b1-4f14-b9da-b27975ecf5ec · sources: /v1/incidents/d099d8f4-57b1-4f14-b9da-b27975ecf5ec/sources · responses: /v1/incidents/d099d8f4-57b1-4f14-b9da-b27975ecf5ec/responses · status: /v1/incidents/d099d8f4-57b1-4f14-b9da-b27975ecf5ec/status · canonical URL: /incidents/knownsec-data-breach-leak-2025-11_
