A forum seller claimed to offer 22 TB of material from Indian diplomatic and foreign-affairs entities for US$200,000. Our review of the shared sample found overlap with publicly accessible records, so the claimed breach and data volume remain unverified.

A forum seller claimed to offer 22 TB of material from Indian diplomatic and foreign-affairs entities for US$200,000. Our review of the shared sample found overlap with publicly accessible records, so the claimed breach and data volume remain unverified.

A forum seller claimed to offer 22 TB of material from Indian diplomatic and foreign-affairs entities for US$200,000. Our review of the shared sample found overlap with publicly accessible records, so the claimed breach and data volume remain unverified.

Report Type
Exposing threat actor behind Data Leak Claim / Cyber Threat Intelligence


Subject

Alleged 22 TB data theft from Indian diplomatic and foreign-affairs entities (Indian Embassies and Ministry of Foreign Affairs)

Incident Date

23 September 2026 (forum post)

Report Date

28 September 2026

Threat Actor Handle

RAYLEAS (X Forums) | Telegram: @Rayhucker

Attributed Identity (OSINT)

Rayyan Afridi, Pakistan-based (Peshawar, Khyber Pakhtunkhwa); founder of AsefaSec



1. Executive Summary

On 23rd September 2026, a threat actor on an underground forum named X Forums1 is reportedly claiming approximately 22 TB of data allegedly stolen from Indian diplomatic and foreign-affairs entities, including the Indian Embassy and Ministry of Foreign Affairs, for US$200,000. The accompanying material shown in the sample pictures references a substantial collection of official documents and large reference databases, including senior appointment circulars, Foreign Service Board records, IFS officer language-proficiency lists, organizational charts, officer directories, journal databases, Foreign Service Institute resources, telephone directories, and large government reference datasets.

2. Leak Sample Evidence

Sample material published by the actor alongside the sale offer is reproduced below.

Sample document from the leak: Embassy of India, Buenos Aires — officer directory with designations, e-mail addresses and telephone numbers.

Figure 1: Sample document from the leak: Embassy of India, Buenos Aires — officer directory with designations, e-mail addresses and telephone numbers.

Forum sale post header: “FULL INDIAN EMBASSIES BREACHED TOTAL OF 22TB DATA” (Indian Division Directories).

Figure 2: Forum sale post header: “FULL INDIAN EMBASSIES BREACHED TOTAL OF 22TB DATA” (Indian Division Directories).

Sample listing: Embassy / All Missions directories, official documents and large reference documents.

Figure 3: Sample listing: Embassy / All Missions directories, official documents and large reference documents.

Sample listing: Indian HQ Division Directories — MEA headquarters divisions covered.

Figure 4: Sample listing: Indian HQ Division Directories — MEA headquarters divisions covered.

3. Key Incident Points

  • The threat actor is operating under the handle “RAYLEAS” shows Moderator (as per his profile on X Forums) and joined the forum on 24th June 2025 and currently has 10 messages and a reaction score of 2.

  • The actor has also shared the Telegram handle “@Rayhucker” and a session ID (056ab8b053a3b77bf0bab81ab3c15be6a360360f13c1251328780f3d0e23355d4d) for sample access and potential data purchase inquiries.

  • The threat actor’s feed contains multiple data-selling posts allegedly related to Indian defence entities, including the Indian Army, BSF and NSG, as well as the Bangladesh Ministry of Defence and CIA email data allegedly associated with the Taliban.

  • One of the threat actor’s posts specifically states that they are seeking military-related documents from countries including India, China, Pakistan, Iran’s IRGC, Saudi Arabia, and other countries across the Middle East. This post provides an indication of the actor’s stated targets and areas of interest.

  • Further analysis of the sample provided by the threat actor determined that the exposed records were already present in publicly accessible open-source datasets.

4. Threat Actor Identification

The threat actor has shared the Telegram handle “@Rayhucker”, which appears to have links to the name “Rayyan Afridi” based on previously observed Historical Display name associated with the account. The Telegram account is also associated with a Pakistan-based mobile number +92 32******61 and CNIC (Computerized National Identity Card) Number 1730*-6****63-7.

Contact card showing the name Rayyan Afridi, +92 329 5150261, Pakistan

Further open-source checks of the mobile number using publicly available Pakistan-focused OSINT sources indicated a possible association with an individual identified as “Romina Afridi,” reportedly mother of Rayyan Afridi located in the Peshawar, Khyber Pakhtunkhwa region of Pakistan.

4.1 About Rayyan Afridi

The threat actor Github Account2 was further identified, revealing his association with a Pakistan based company named AsefaSec (as founder of company, registered in 2025).

AsefaSec is a Cybersecurity firm focused on helping organizations identify, mitigate, and proactively defend against evolving digital threats and specialized in security services, including penetration testing, vulnerability assessments, application and API security, cloud security, red team assessments, and security consulting.

  • The individual has shared one Instagram story mentioning ISPR3 (Inter Service Public Relations), further confirming his association with Pakistan ISPR.

  • AsefaSec, a company founded by Rayyan Afridi, references capabilities involving ransomware threats, APT group identification, the release of stealth exploits, and zero-day RCE detection. These references have been cited as indicators of potential associations with dark-web and cybercriminal-related activities.

  • His Instagram and LinkedIn post shows GoDaddy, Skeler Security, Secure Purple, Black Byt3, Intel Forge and Singapore Police Force as Strategic partners.

  • Rayyan Afridi is currently working as Penetration Tester on Contract at Digiinn360 (an Islamabad based Cyber Security Firm).

  • The social media post of Rayyan Afridi, also shows his participation in Cyber Security Hackathons and Events.

  • The Threat actor Rayyan Afridi has also been observed using the alias “RAY,” derived from the first three letters of his name, across X Forums (Rayleas), Telegram (Rayhucker), GitHub (Ray0x01), and LinkedIn (Rayreal). The consistent use of this alias across these platforms further supports the assessment of a potential connection between the accounts and the identified threat actor.

4.2 Publicly Available Data Repackaged as a “Leak”

Further analysis of the sample shared by the threat actor identified substantial overlap with information already available through publicly accessible sources.

This demonstrates why dark-web leak claims should not be treated as confirmed breaches without validating the data’s provenance, uniqueness, and source. This reinforces the need for independent validation before classifying dark-web claims as genuine breaches.

Telegram groups joined by threat actor along with his messages in groups and common users in the groups were found. The detailed analysis along with screenshots are attached below for reference.

4.3 Historical Display Name

Historical Display Name

Recorded Timestamp

Rayyan Afridi

24/09/2026, 22:19:50

4.4 Threat Actor Profile on X Forums, Telegram and Session

X Forums profile of “Rayleas” — Staff Team / MOD, joined 24 Jun 2025, 9 messages, reaction score 2.

Figure 5: X Forums profile of “Rayleas” — Staff Team / MOD, joined 24 Jun 2025, 9 messages, reaction score 2.

Telegram profile — username @Rayhucker (display name shown: “XRay GEx”).

Figure 6: Telegram profile — username @Rayhucker (display name shown: “XRay GEx”).


4.5 Telegram Groups Joined by the Threat Actor

Group / Chat Name

Chat Id

Target Message Count

Last Active Date

TECTUM 🔗 Fastest Blockchain & SoftNote

1284662604

2

1/17/2025, 8:34:58 AM

4.6 Message of Threat Actor in Telegram Groups

Timestamp

Group Title

Message

1/17/2025, 8:34:58 AM

TECTUM 🔗 Fastest Blockchain & SoftNote

who can i dm? and post the vulnerabilities

1/17/2025, 8:34:43 AM

TECTUM 🔗 Fastest Blockchain & SoftNote

Hey There Developer Team I have found some issues in tectum it was a while ago I reported them to security team aswell but no reply then i reach put to Alexender CEO and he told me to reach you guys out here

Telegram message screenshot (Developer Support group, January 17, 2025).

Figure 7: Telegram message screenshot (Developer Support group, January 17, 2025).

4.7 Common Users in Group

User Id

Full Name

Username

Common Group Count

8815752388

Nader

@nader4321

1

5235979983

Ggg

@onae3725

1

7482339540

Alex Leyendas

N/A

1

7756289431

Gal

@gostyyy

1

5383071234

NTAWUTAVUGWA Albert

@jalos23

1

7150990201

🅑🅘🅐🅝🅒🅞 🍥 | Web3 Incubator

@Bianco009

1

5150301439

Dkay

@dkaysthetics

1

7233664957

Nafisa Rahman

@Netflix_Nafisa_Rohman

1

1076047841

All

@RubyboyA

1

6614558869

Jams

N/A

1

5911654710

Muhammad 🐐

@muhammadaltamash5030

1

1830660820

Usman Fahmiazi

@amiewww

1

1250252929

Dragon

@Poppy_Haunam

1

7671238514

Mariam Mohammed

@ariaohamm

1

8067109335

ThorSpeed 🏁

@Thor_rose0

1

638548784

Lung Thang

N/A

1

2001392869

FaisalWeb3

@Daniewar

1

7808400198

Lena🥰

N/A

1

7318213074

jiayin

N/A

1

7793042041

John Staz

N/A

1

6854949519

Ayesha Maher

@Ayeshamaher

1

2101775908

Pradayrol Cel

@Invest_cel

1

5667286076

PAVEL [ Owner - Crypto Analysis ]

@Owner_analysis

1

5452721617

Mirko

@Cviki89

1

6308997782

FADAFADAWEB3

@Fadafadaweb3

1

5417197005

Anderson

@Andi1731

1

6594922232

Zuma𝕏

@ZumaniaX

1

584653250

Bright Swan

@Octavn

1

725496190

BrainBox

@BrainBox1212

1

5073555464

0xgimic

@Arrienugroho

1

930064575

Un Salida

@UnSalida

1

6977647427

Macdonald 🍅 🐾 🐐 Ekworo

@mcekworo1972

1

8360390227

Jaelynn | Listing

@Jaelynn_OG

1

6054880385

KinGKinG

N/A

1

6241313848

Carlo FRGST-Froggies

@CarloGreatfrog

1

6787713705

Jules@margcoinOG

N/A

1

983092572

Appzz Zz ▪️ 🐾

@PKAppz

1

7857060564

Chloe Cook

N/A

1

6190388285

Gemstone 💎

@Gemboxes

1

716078334

Mr Dou

@Dou007

1

8487750782

Gabriela Blofin

@Gabriela_Blofinlistings1

1

424350965

Fat Cat

@SuicidalBear

1

1055049258

BitVogel

@stefanbaer1979

1

6232725054

Dennie

@Dennie0313

1

6774392744

😉😉😉

N/A

1

7128787606

Ivanoff

@Agent022022

1

7216038852

Tuğçe Kılıç

N/A

1

8430854234

A.M.X

N/A

1

1613275485

vansStrong always eligible

@hiraaaaaaaa

1

7172224768

Salomeh

N/A

1

4.8 Other Data Leaks Posted by Threat Actor4

Threads posted by the actor on X Forums (data-sale and request posts).

Figure 8: Threads posted by the actor on X Forums (data-sale and request posts).


Date

Target

Data Size

Sample

23 September 2026

FULL INDIAN EMBASSIES + MOFA BREACHED

22 TB

Yes

07 September 2026

BSF, NSG Military Movement 2026 to 2028 All Movement Deployment Etc.

20 TB

Yes

01 September 2026

Ministry Of Defense All Military Colonels Data For Sale.

-

Yes

27 August 2026

SECRET CIA US EMAIL TO TALIBAN 08/25/2026

6 Pages

Yes

21 August 2026

Any Military Documents 2026 - India, China, Pakistan, IRGC (IRAN), Saudi Arabia, Middle East ETC.

-

-

5. Rayyan Afridi Portfolio

Personal portfolio site attributed to the individual: https://github.com/Ray0x01/portfolio/blob/main/index.html5

Portfolio website — landing page (“Rayyan Afridi — Founding AsefaSec | Red Teamer | Content Creator”).

Figure 9: Portfolio website — landing page (“Rayyan Afridi — Founding AsefaSec | Red Teamer | Content Creator”).

Portfolio website — “Classified Intel” section.

Figure 10: Portfolio website — “Classified Intel” section.

Portfolio website — “Mission Log” timeline.

Figure 11: Portfolio website — “Mission Log” timeline.

Portfolio website — “Secure Channel” contact section.

Figure 12: Portfolio website — “Secure Channel” contact section.

5.1 Pictures of Rayyan Afridi

Photograph of Rayyan Afridi.

Figure 13: Photograph of Rayyan Afridi.

Graphic: “100 Student Leaders of Pakistan” — Rayyan Afridi, Cybersecurity Professional & Founder AsefaSec.

Figure 14: Graphic: “100 Student Leaders of Pakistan” — Rayyan Afridi, Cybersecurity Professional & Founder AsefaSec.


5.2 Identified Accounts of Rayyan Afridi

Github

https://github.com/Ray0x01/

Instagram

https://www.instagram.com/ryan.povz/

LinkedIn

https://www.linkedin.com/in/rayreal/

YouTube

https://www.youtube.com/@pentesterxrayyan

GitHub profile — “Hello, I’m Rayyan Afridi” (Ray0x01), Peshawar, Pakistan.

Figure 15: GitHub profile — “Hello, I’m Rayyan Afridi” (Ray0x01), Peshawar, Pakistan.

Instagram profile — ryan.povz, “Founder @asefasec”, story highlights including ISPR and ECP.

Figure 16: Instagram profile — ryan.povz, “Founder @asefasec”, story highlights including ISPR and ECP.

LinkedIn profile — Rayyan (Ray) Afridi, Offensive Security Specialist, Islamabad, Pakistan (Digiinn360).

Figure 17: LinkedIn profile — Rayyan (Ray) Afridi, Offensive Security Specialist, Islamabad, Pakistan (Digiinn360).

YouTube channel — “Rayyan Afridi ~ Pentester”.

Figure 18: YouTube channel — “Rayyan Afridi ~ Pentester”.

6. About AsefaSec

AsefaSec6 is a Cybersecurity firm focused on helping organizations identify, mitigate, and proactively defend against evolving digital threats and specialized in security services, including penetration testing, vulnerability assessments, application and API security, cloud security, red team assessments, and security consulting.

Company LinkedIn: https://www.linkedin.com/company/asefasec/

AsefaSec website — “Securing the Digital Frontier”.

Figure 19: AsefaSec website — “Securing the Digital Frontier”.

AsefaSec website — “Global Capabilities” (red teaming, web & API pentest, cloud security, code review).

Figure 20: AsefaSec website — “Global Capabilities” (red teaming, web & API pentest, cloud security, code review).


AsefaSec team-update graphic.

Figure 21: AsefaSec team-update graphic.

AsefaSec team-update graphic.

Figure 22: AsefaSec team-update graphic.

AsefaSec team-update graphic.

Figure 23: AsefaSec team-update graphic.

AsefaSec LinkedIn company page.

Figure 24: AsefaSec LinkedIn company page.

AsefaSec LinkedIn overview — core focus areas and company details.

Figure 25: AsefaSec LinkedIn overview — core focus areas and company details.

7. Social Media Posts of ISPR Connection and Participation in Hackathons and Events

A7
https://www.instagram.com/stories/highlights/17909603175299548/

Instagram story A — highlighted “ISPR” and “Pak Cyber Warrior” items.

Figure 26: Instagram story A — highlighted “ISPR” and “Pak Cyber Warrior” items.


B8
https://www.instagram.com/stories/highlights/17868677184417614/

Instagram story B — event participation.

Figure 27: Instagram story B — event participation.


C9
https://www.instagram.com/stories/highlights/17991319349728389/

Instagram story C — workshop at National Skills University Islamabad featuring AsefaSec.

Figure 28: Instagram story C — workshop at National Skills University Islamabad featuring AsefaSec.


D10
https://www.instagram.com/stories/highlights/17991319349728389/

Instagram story D — event / award ceremony.

Figure 29: Instagram story D — event / award ceremony.

8. Threat Actor Indicators Summary

Consolidated from the data above for tracking and monitoring purposes.


Indicator Type

Value

Context

Forum handle

RAYLEAS (X Forums)

Moderator/Staff Team; joined 24 Jun 2025

Forum thread

https://xforums.st/threads/india-full-indian-embassies-mofa-breached-total-of-22tb-data.701718/

Sale post, 22 TB, US$200,000

Telegram

@Rayhucker

Contact for samples and purchase

Telegram historical display name

Rayyan Afridi

Recorded 24/09/2026, 22:19:50

Session ID

056ab8b053a3b77bf0bab81ab3c15be6a360360f13c1251328780f3d0e23355d4d

Contact for samples and purchase

Mobile number

+92 32******61

Pakistan-based; linked to Telegram account

CNIC

1730*-6****63-7

Linked to Telegram account

GitHub

https://github.com/Ray0x01/

Personal profile

Instagram

https://www.instagram.com/ryan.povz/

Personal profile

LinkedIn

https://www.linkedin.com/in/rayreal/

Personal profile

YouTube

https://www.youtube.com/@pentesterxrayyan

Personal channel

Company website

https://asefasec.com/

AsefaSec (founded 2025)

Company LinkedIn

https://www.linkedin.com/company/asefasec/

AsefaSec

9. Analyst Notes and Recommended Actions

Analyst notes. The data volume (22 TB), price and breach claims are statements made by the actor; the sample material appears consistent with diplomatic contact directories and administrative circulars, but full authenticity and scope are not independently confirmed. Identity attribution rests on open-source correlation (display-name history, linked social and code-hosting accounts, and Pakistan-based number/CNIC linkage) and should be treated as an intelligence assessment, not a legal finding. The ISPR-related Instagram story is an associative indicator.

Recommended actions.

  • Validate the sample material against internal records to confirm authenticity and identify the affected missions and divisions.

  • Monitor the X Forums thread, the Telegram handle @Rayhucker and the Session ID for new sample releases or sales.

  • Warn diplomatic and MEA staff about targeted phishing and impersonation attempts that could abuse leaked officer directories and contact details.

  • Review access controls and credentials for systems holding directory, circular and reference-database content.

Footnotes

  1. https://xforums.st/threads/india-full-indian-embassies-mofa-breached-total-of-22tb-data.701718/ ↩

  2. https://github.com/Ray0x01/ ↩

  3. ISPR is the media and public relations wing of the Pakistan Armed Forces ↩

  4. https://xforums.st/search/1087489/?c[users]=Rayleas&o=date ↩

  5. https://github.com/Ray0x01/portfolio/blob/main/index.html ↩

  6. https://asefasec.com ↩

  7. https://www.instagram.com/stories/highlights/17909603175299548/ ↩

  8. https://www.instagram.com/stories/highlights/17868677184417614/ ↩

  9. https://www.instagram.com/stories/highlights/17991319349728389/ ↩

  10. https://www.instagram.com/stories/highlights/17991319349728389/ ↩