The record
Written from the 1 report below. Nothing here is unsourced.
- An attacker operated inside the network of 3BB, one of Thailand's largest broadband providers, using a legitimate remote-management tool called MeshCentral as a hidden backdoor.
- The intrusion was uncovered by threat intelligence firm Hunt.io, which captured the attacker's exposed server on June 3, 2026, while the operation was still live.
- Recovered scripts targeted 3BB's RADIUS databases, which store the login credentials of broadband subscribers, though the evidence shows the databases were targeted rather than any data actually taken.
- The attacker's toolkit included an exploit for a serious 2024 Fortinet flaw (CVE-2024-21762) in a 3BB VPN gateway, but the evidence does not confirm this was how the initial entry was achieved.
- The finding matters because broadband subscriber credentials and shared infrastructure with the Jasmine network may be at risk, and it is unknown whether the attacker still retains access inside 3BB.
What to watch next
- Whether 3BB confirms any subscriber data was actually taken from its RADIUS databases.
- Whether the attacker still holds access inside 3BB, or the intrusion has been fully remediated.
- Whether Jasmine's shared infrastructure is confirmed breached, and whether the CVE-2024-21762 FortiGate flaw is confirmed as the entry point.
Coverage1
1 report
English national1
All filed from India
Named Thailand · 3BB · Jasmine · Fortinet · Hunt.io · MeshCentral
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
