Threat · curated 2 Oct 2026

Operation Open Ledger: an AI-assembled crew exfiltrating ERP data from Spanish SMBs

Coverage timeline

2 Oct 2026huntback.io

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Operation Open Ledger shows attackers using AI coding agents like opencode to assemble and operate exploit kits and cloud-API exfiltration pipelines at scale, lowering the bar for real intrusions against SMBs.

Huntback recovered 10,428 files from an open directory on 89.124.67.72 exposing a Russian-speaking intrusion crew's working environment, including a custom Microsoft Dynamics 365 Business Central exfiltration pipeline, a six-product enterprise exploit kit, AD tooling, Sliver C2, and 15 GB of data stolen from Spanish SMBs. The crew stole an Azure service-principal secret via gitleaks, minted OAuth tokens, and bulk-dumped tenants through the Business Central REST API; the operator drove the work through an 'opencode' AI agent with PoCs visibly AI-assisted (one README credits ChatGPT).