1
0 Comments

ZeffSec Claims Breach of Gozine2 After Sudden Telegram Return

A hacker group called ZeffSec has reappeared on Telegram after a long period of silence — and within a day of coming back online, it claimed responsibility for a breach involving the Iranian platform gozine2.ir.

The group previously announced it was stepping away from X (formerly Twitter) and shifting its activity fully to Telegram. Shortly after that, it posted claims of a compromise affecting what it describes as an educational platform tied to government-related data handling.

According to ZeffSec’s own statements, the issue stems from exposed database credentials allegedly accessible through a backup endpoint. They say this allowed access to a large dataset connected to the system.

The group claims the breach includes more than 200,000 records, with data such as:

Phone numbers
Home addresses
National ID numbers
Full names
Employee-related records
Internal emails and documents (reportedly several GB worth)

They also say they accessed internal database configuration details. Some screenshots were shared on their Telegram channel, but there’s been no independent confirmation that any of it is real or complete.

Not long after the initial post, ZeffSec claimed the dataset was being offered for sale in underground spaces.

A message attributed to the group framed the incident in ideological terms:

“You built a world on surveillance, control, and silence.
We’re here to rewrite the code.”

So far, there’s been no official response from gozine2.ir confirming or denying the incident.

From a broader angle, this is another example of a pattern we keep seeing: threat actors resurfacing after inactivity, making a “big announcement” breach, and using Telegram as both a broadcast channel and distribution point.

Whether the claims are fully accurate or inflated (as often happens in these cases), the risk surface is the same — if exposed data like national IDs and addresses are involved, the downstream impact can be very real: phishing, identity fraud, and long-tail abuse.

reference:
t.me/zeffsec

on May 14, 2026