‼️🇵🇹 BLAT Studio (
blatstudio.com), a Lisbon-based creative digital agency, has allegedly been breached, exposing personal data of Portuguese PSD political deputies and hashed credentials from multiple Portuguese university student associations.
⠀
‣ Threat Actor: Boogeymann
‣ Category: Data Leak
‣ Victim: BLAT Studio (with downstream impact on PSD deputies and Portuguese universities)
‣ Industry: Marketing / Political / Education
⠀
The actor states the data was obtained through an exposed Firebase database instance left without security rules. The breach impacts BLAT Studio's clients, which include Portugal's Social Democratic Party (PSD) and several student associations across Portuguese universities (ISCAL, IST, FADU, ESML, and others).
⠀
What's in it:
⠀
▪️ 119 university emails from student associations with hashed credentials (Base64 encoded bcrypt)
▪️ 127 records of PSD political deputies, including names, addresses, phone numbers, work and personal emails, positions, and social media links (Facebook, Instagram, Twitter, TikTok, YouTube, LinkedIn)
▪️ 1,018,396 lines of internal BLAT Studio communications with clients, including message bodies, timestamps, user IDs, attachments, and conversations