A devastating cybersecurity breach has been uncovered in India, affecting a major IT provider and exposing sensitive data on thousands of individuals. The attackers appear to have exploited vulnerabilities in the company’s systems using sophisticated backdoors known as FLATROOF and ROOFDECK, which were likely linked to the notorious Jade Sleet hacking group.
At the heart of this breach is a complex web of identity exposure and privilege escalation. It seems that hackers gained access to sensitive information on employees and clients by exploiting weaknesses in authentication protocols. Once inside, they used their newfound privileges to map out the company’s systems, identifying key choke points where they could insert additional backdoors.
The use of FLATROOF and ROOFDECK is particularly concerning, as these custom-built tools are designed to provide persistent access to compromised systems. They allow hackers to maintain a presence on the network without being detected, making it increasingly difficult for security teams to respond effectively. The fact that Jade Sleet was likely involved only adds to the severity of this breach, given their reputation for relentless and highly targeted attacks.
The Indian IT provider affected is thought to have had thousands of clients across multiple industries, including finance and healthcare. While there’s no indication yet that sensitive data has been stolen or misused, the mere exposure of employee and client information puts these individuals at risk of identity theft and other malicious activities. The long-term consequences of this breach are still unknown, but it’s clear that swift action is needed to contain the damage.
The Jade Sleet group’s involvement in this breach highlights the ongoing threat posed by sophisticated nation-state hackers. Their use of custom-built tools like FLATROOF and ROOFDECK underscores the need for organizations to stay ahead of emerging threats through continuous security monitoring and proactive measures. This includes regular vulnerability scanning, robust access controls, and comprehensive incident response planning.
In the face of such a brazen attack, it’s essential that individuals take steps to protect their own identities and sensitive information. This means using strong passwords, enabling two-factor authentication whenever possible, and regularly monitoring credit reports for any suspicious activity. By being vigilant and proactive about security, we can reduce our exposure to these types of threats and prevent them from escalating into full-blown breaches.
Source: The Hacker News — 2026-09-21