CloudSEK said on 5 October 2026 that an open directory exposed a ransomware affiliate who calls himself Azazel. CloudSEK says he worked with the Gentlemen group, yet ran his own leak site, LEAKNED, and kept the extortion money. His staging server held about 6TB of stolen data in more than two dozen victim folders across six countries. One copy job was still running.
CloudSEK says it warned victims before publishing; it does not say whether the servers are offline. It says most victims were reached through GitLab, where pipeline settings and git history (the record of past code changes) gave up tokens, passwords and SSH keys. One GitLab instance served two unrelated companies, and a single token opened three cloud servers of the second. The AI-company intrusion was a separate chain. It began with an imaging API that fetched web addresses without checking them. There, a login-bypass token deleted from code was still in git history, and he recovered it.
For the GitLab victims, the pipeline held keys to many systems, so one token reached far. Leaders should ask who can read pipeline secrets, what each token can open, and whether exposed secrets are replaced, since deleting one from code leaves it in history.