According to authorities this malphish-based compromise was done by a 13 and a 15 year old, and my heart is filling with warmth:

https://twitter.com/buherator/status/1590379495092953088 #cantfindonmastodon

@[email protected] on Twitter

“The below screenshot (of the PreventSQLInjection function...) is from the systems that most Hungarian schools use as a parent-teacher dashboard. The developer company was breached via a client-side attack, the local hax0rz leaked the source (allegedly).”

Twitter
The perpetrators still appear to be active, and share more data to disprove authorities claims [HU]: https://telex.hu/tech/2022/12/18/a-kreta-t-feltoro-hekkerek-nem-ertik-a-rendoroket-13-eves-tagjuk-nincs-szemelyes-adataik-viszont-vannak
A KRÉTA fejlesztőjét feltörő hekkerek nem értik a rendőröket

Azt mondják, 13 éves tagjuk nincs, személyes adatokhoz viszont igenis hozzájutottak. Megmutattak egy screenshotot is.

Telex