{"id":9184,"date":"2025-11-28T04:06:03","date_gmt":"2025-11-28T04:06:03","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=9184"},"modified":"2025-11-28T04:06:03","modified_gmt":"2025-11-28T04:06:03","slug":"meet-rey-the-admin-of-scattered-lapsus-hunters-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=9184","title":{"rendered":"Meet Rey, the Admin of \u2018Scattered Lapsus$ Hunters\u2019 \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A prolific cybercriminal group that calls itself \u201c<strong>Scattered LAPSUS$ Hunters<\/strong>\u201d has dominated headlines this 12 months by frequently stealing knowledge from and publicly mass extorting dozens of main companies. However the tables appear to have turned considerably for \u201cRey,\u201d the moniker chosen by the technical operator and public face of the hacker group: Earlier this week, Rey confirmed his actual life identification and agreed to an interview after KrebsOnSecurity tracked him down and contacted his father.<\/p>\n<p>Scattered LAPSUS$ Hunters (SLSH) is regarded as an amalgamation of three hacking teams \u2014 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/?s=scattered+spider\" target=\"_blank\" rel=\"noopener\"><strong>Scattered Spider<\/strong><\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/?s=lapsus%24\" target=\"_blank\" rel=\"noopener\"><strong>LAPSUS$<\/strong><\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/?s=shiny+hunters\" target=\"_blank\" rel=\"noopener\"><strong>ShinyHunters<\/strong><\/a>. Members of those gangs hail from most of the similar chat channels on the <strong>Com<\/strong>, a largely English-language cybercriminal group that operates throughout an ocean of Telegram and Discord servers.<\/p>\n<p>In Could 2025, SLSH members launched <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2025\/10\/shinyhunters-wage-broad-corporate-extortion-spree\/\" target=\"_blank\" rel=\"noopener\">a social engineering marketing campaign<\/a> that used voice phishing to trick targets into connecting a malicious app to their group\u2019s Salesforce portal. The group later launched a knowledge leak portal that threatened to publish the interior knowledge of three dozen corporations that allegedly had Salesforce knowledge stolen, together with <strong>Toyota<\/strong>,\u00a0<strong>FedEx<\/strong>,\u00a0<strong>Disney\/Hulu<\/strong>, and\u00a0<strong>UPS<\/strong>.<\/p>\n<div id=\"attachment_72275\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-72275\" decoding=\"async\" class=\" wp-image-72275\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sf-extortionsite.png\" alt=\"\" width=\"750\" height=\"517\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sf-extortionsite.png 1275w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sf-extortionsite-768x529.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sf-extortionsite-782x539.png 782w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sf-extortionsite-100x70.png 100w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\"\/><\/p>\n<p id=\"caption-attachment-72275\" class=\"wp-caption-text\">The brand new extortion web site tied to ShinyHunters, which threatens to publish stolen knowledge until Salesforce or particular person sufferer corporations conform to pay a ransom.<\/p>\n<\/div>\n<p>Final week, the SLSH Telegram channel featured a suggestion to recruit and reward \u201cinsiders,\u201d staff at giant corporations who conform to share inner entry to their employer\u2019s community for a share of no matter ransom fee is in the end paid by the sufferer firm.<\/p>\n<p>SLSH has solicited insider entry beforehand, however their newest name for disgruntled staff began making the rounds on social media on the similar time information broke that the cybersecurity agency <strong>Crowdstrike<\/strong> had fired an worker for <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/techcrunch.com\/2025\/11\/21\/crowdstrike-fires-suspicious-insider-who-passed-information-to-hackers\/\" target=\"_blank\" rel=\"noopener\">allegedly sharing screenshots of inner methods<\/a> with the hacker group (Crowdstrike stated their methods have been by no means compromised and that it has turned the matter over to legislation enforcement companies).<\/p>\n<div id=\"attachment_72738\" style=\"width: 684px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72738\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-72738\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/slsh-insider.png\" alt=\"\" width=\"674\" height=\"781\"\/><\/p>\n<p id=\"caption-attachment-72738\" class=\"wp-caption-text\">The Telegram server for the Scattered LAPSUS$ Hunters has been trying to recruit insiders at giant corporations.<\/p>\n<\/div>\n<p>Members of SLSH have historically used different ransomware gangs\u2019 encryptors in assaults, together with malware from ransomware affiliate applications like ALPHV\/BlackCat, Qilin, RansomHub, and DragonForce. However final week, SLSH introduced on its Telegram channel <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/meet-shinysp1d3r-new-ransomware-as-a-service-created-by-shinyhunters\/\" target=\"_blank\" rel=\"noopener\">the discharge of their very own ransomware-as-a-service operation<\/a> known as <strong>ShinySp1d3r<\/strong>.<\/p>\n<p>The person chargeable for releasing the ShinySp1d3r ransomware providing is a core SLSH member who goes by the deal with \u201cRey\u201d and who&#8217;s presently one among simply three directors of the SLSH Telegram channel. Beforehand, Rey was an <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web.archive.org\/web\/20241201110456\/https:\/\/twitter.com\/ReyXBF\/status\/1863177457450573835\" target=\"_blank\" rel=\"noopener\">administrator<\/a> of the info leak web site for <strong>Hellcat<\/strong>, a ransomware group that surfaced in late 2024 and was concerned in assaults on corporations together with <strong>Schneider Electrical<\/strong>, <strong>Telefonica<\/strong>, and <strong>Orange Romania<\/strong>.<\/p>\n<div id=\"attachment_72744\" style=\"width: 484px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72744\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-72744\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/slsh-tg.png\" alt=\"\" width=\"474\" height=\"795\"\/><\/p>\n<p id=\"caption-attachment-72744\" class=\"wp-caption-text\">A latest, barely redacted screenshot of the Scattered LAPSUS$ Hunters Telegram channel description, exhibiting Rey as one among three directors.<\/p>\n<\/div>\n<p>Additionally in 2024, Rey would take over as administrator of the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web.archive.org\/web\/20241129001040\/https:\/\/twitter.com\/ReyXBF\/status\/1862288027579801821\" target=\"_blank\" rel=\"noopener\">most up-to-date incarnation of BreachForums<\/a>, an English-language cybercrime discussion board whose domains have been seized on a number of events by the FBI and\/or by worldwide authorities. In April 2025, Rey <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web.archive.org\/web\/20250418062459\/https:\/\/twitter.com\/ReyXBF\/status\/1913116530658705661\" target=\"_blank\" rel=\"noopener\">posted on Twitter\/X<\/a> about one other FBI seizure of BreachForums.<\/p>\n<p>On October 5, 2025, the FBI <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/FBI\/status\/1977464345651982491\" target=\"_blank\" rel=\"noopener\">introduced<\/a> it had as soon as once more seized the domains related to BreachForums, which it described as a significant legal market utilized by ShinyHunters and others to visitors in stolen knowledge and facilitate extortion.<\/p>\n<p>\u201cThis takedown removes entry to a key hub utilized by these actors to monetize intrusions, recruit collaborators, and goal victims throughout a number of sectors,\u201d the FBI stated.<\/p>\n<p>Extremely, Rey would make a sequence of crucial operational safety errors final 12 months that offered a number of avenues to establish and ensure his real-life identification and site. Learn on to be taught the way it all unraveled for Rey.<span id=\"more-72704\"\/><\/p>\n<h2>WHO IS REY?<\/h2>\n<p>In keeping with the cyber intelligence agency <strong>Intel 471<\/strong>, Rey was an energetic consumer on varied <strong>BreachForums<\/strong> reincarnations over the previous two years, authoring greater than 200 posts between February 2024 and July 2025. Intel 471 says Rey beforehand used the deal with \u201c<strong>Hikki-Chan<\/strong>\u201d on BreachForums, the place their first publish shared knowledge allegedly stolen from the <strong>U.S. Facilities for Illness Management and Prevention<\/strong> (CDC).<\/p>\n<p>In that February 2024 publish concerning the CDC, Hikki-Chan says they may very well be reached on the Telegram username <strong>@wristmug<\/strong>. In Could 2024, @wristmug posted in a Telegram group chat known as \u201cPantifan\u201d a replica of an extortion e-mail they stated they obtained that included their e-mail deal with and password.<\/p>\n<p>The message that @wristmug lower and pasted seems to have been a part of an <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2018\/07\/sextortion-scam-uses-recipients-hacked-passwords\/\" target=\"_blank\" rel=\"noopener\">automated e-mail rip-off<\/a> that claims it was despatched by a hacker who has compromised your pc and used your webcam to file a video of you when you have been watching porn. These missives threaten to launch the video to all of your contacts until you pay a Bitcoin ransom, they usually usually reference an actual password the recipient has used beforehand.<\/p>\n<p>\u201cNoooooo,\u201d the @wristmug account wrote in mock horror after posting a screenshot of the rip-off message. \u201cI have to be achieved guys.\u201d<\/p>\n<div id=\"attachment_72731\" style=\"width: 533px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72731\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-72731\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/mustbedone.png\" alt=\"\" width=\"523\" height=\"800\"\/><\/p>\n<p id=\"caption-attachment-72731\" class=\"wp-caption-text\">A message posted to Telegram by Rey\/@wristmug.<\/p>\n<\/div>\n<p>In posting their screenshot, @wristmug redacted the username portion of the e-mail deal with referenced within the physique of the rip-off message. Nonetheless, they didn&#8217;t redact their previously-used password, they usually left the area portion of their e-mail deal with (@proton.me) seen within the screenshot.<\/p>\n<h2>O5TDEV<\/h2>\n<p>Looking out on @wristmug\u2019s slightly distinctive 15-character password within the breach monitoring service <strong>Spycloud<\/strong> finds it&#8217;s recognized to have been utilized by only one e-mail deal with: <strong>cybero5tdev@proton.me<\/strong>. In keeping with Spycloud, these credentials have been uncovered at the least twice in early 2024 when this consumer\u2019s machine was contaminated with an infostealer trojan that siphoned all of its saved usernames, passwords and authentication cookies (a discovering that was <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.kelacyber.com\/blog\/hellcat-hacking-group-unmasked-rey-and-pryx\/\" target=\"_blank\" rel=\"noopener\">initially revealed<\/a> in March 2025 by the cyber intelligence agency <strong>KELA<\/strong>).<\/p>\n<p>Intel 471 exhibits the e-mail deal with cybero5tdev@proton.me belonged to a BreachForums member who glided by the username <strong>o5tdev<\/strong>. Looking out on this nickname in Google brings up at the least two web site defacement archives exhibiting {that a} consumer named o5tdev was beforehand concerned in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web.archive.org\/web\/20251124165751\/https:\/\/haxor.id\/archive\/mirror\/179443\" target=\"_blank\" rel=\"noopener\">defacing websites with pro-Palestinian messages<\/a>. The screenshot beneath, for instance, exhibits that 05tdev was a part of a bunch known as <strong>Cyb3r Drag0nz Crew<\/strong>.<\/p>\n<div id=\"attachment_72730\" style=\"width: 758px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72730\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-72730\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/hackedbyo5tdev.png\" alt=\"\" width=\"748\" height=\"332\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/hackedbyo5tdev.png 1115w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/hackedbyo5tdev-768x341.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/hackedbyo5tdev-782x347.png 782w\" sizes=\"auto, (max-width: 748px) 100vw, 748px\"\/><\/p>\n<p id=\"caption-attachment-72730\" class=\"wp-caption-text\">Rey\/o5tdev\u2019s defacement pages. Picture: archive.org.<\/p>\n<\/div>\n<p>A 2023 report from <strong>SentinelOne<\/strong> described Cyb3r Drag0nz Crew as a hacktivist group with a historical past of launching DDoS assaults and cyber defacements in addition to participating in knowledge leak exercise.<\/p>\n<p>\u201cCyb3r Drag0nz Crew claims to have leaked knowledge on over 1,000,000 of Israeli residents unfold throughout a number of leaks,\u201d SentinelOne <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.sentinelone.com\/blog\/hacktivism-in-the-israel-hamas-conflict-citizen-data-leaked-using-old-malware\/\" target=\"_blank\" rel=\"noopener\">reported<\/a>. \u201cSo far, the group has launched a number of .RAR archives of purported private data on residents throughout Israel.\u201d<\/p>\n<p>The cyber intelligence agency <strong>Flashpoint<\/strong> finds the Telegram consumer @05tdev was energetic in 2023 and early 2024, posting in Arabic on anti-Israel channels like \u201cGhost of Palestine\u201d [full disclosure: Flashpoint is currently an advertiser on this blog].<\/p>\n<h2>\u2018I\u2019M A GINTY\u2019<\/h2>\n<p>Flashpoint exhibits that Rey\u2019s Telegram account (ID7047194296) was notably energetic in a cybercrime-focused channel known as <strong>Jacuzzi<\/strong>, the place this consumer shared a number of private particulars, together with that their father was an airline pilot. Rey claimed in 2024 to be 15 years outdated, and to have household connections to Eire.<\/p>\n<p>Particularly, Rey talked about in a number of Telegram chats that he had Irish heritage, even posting a graphic that exhibits the prevalence of the surname \u201c<strong>Ginty<\/strong>.\u201d<\/p>\n<div id=\"attachment_72732\" style=\"width: 689px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72732\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-72732\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/imaginty.png\" alt=\"\" width=\"679\" height=\"370\"\/><\/p>\n<p id=\"caption-attachment-72732\" class=\"wp-caption-text\">Rey, on Telegram claiming to have affiliation to the surname \u201cGinty.\u201d Picture: Flashpoint.<\/p>\n<\/div>\n<p>Spycloud listed tons of of credentials stolen from cybero5dev@proton.me, and people particulars point out that Rey\u2019s pc is a shared Microsoft Home windows machine positioned in Amman, Jordan. The credential knowledge stolen from Rey in early 2024 present there are a number of customers of the contaminated PC, however that every one shared the identical final title of Khader and an deal with in Amman, Jordan.<\/p>\n<p>The \u201cautofill\u201d knowledge lifted from Rey\u2019s household PC incorporates an entry for a 46-year-old <strong>Zaid Khader<\/strong> that claims his mom\u2019s maiden title was Ginty. The infostealer knowledge additionally exhibits Zaid Khader continuously accessed inner web sites for workers of <strong>Royal Jordanian Airways<\/strong>.<\/p>\n<h2>MEET SAIF<\/h2>\n<p>The infostealer knowledge makes clear that Rey\u2019s full title is <strong>Saif Al-Din Khader<\/strong>. Having no luck contacting Saif instantly, KrebsOnSecurity despatched an e-mail to his father Zaid. The message invited the daddy to reply by way of e-mail, cellphone or Sign, explaining that his son gave the impression to be deeply enmeshed in a critical cybercrime conspiracy.<\/p>\n<p>Lower than two hours later, I obtained a Sign message from Saif, who stated his dad suspected the e-mail was a rip-off and had forwarded it to him.<\/p>\n<p>\u201cI noticed your e-mail, sadly I don\u2019t assume my dad would reply to this as a result of they assume its some \u2018rip-off e-mail,&#8217;\u201d stated Saif, who informed me he turns 16 years outdated subsequent month. \u201cSo I made a decision to speak to you instantly.\u201d<\/p>\n<p>Saif defined that he\u2019d already heard from European legislation enforcement officers, and had been making an attempt to extricate himself from SLSH. When requested why then he was concerned in releasing SLSH\u2019s new ShinySp1d3r ransomware-as-a-service providing, Saif stated he couldn\u2019t simply instantly stop the group.<\/p>\n<p>\u201cEffectively I cant simply dip like that, I\u2019m making an attempt to scrub up the whole lot I\u2019m related to and transfer on,\u201d he stated.<\/p>\n<div id=\"attachment_72752\" style=\"width: 722px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72752\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-72752\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/hellcat.png\" alt=\"\" width=\"712\" height=\"693\"\/><\/p>\n<p id=\"caption-attachment-72752\" class=\"wp-caption-text\">The previous Hellcat ransomware website. Picture: Kelacyber.com<\/p>\n<\/div>\n<p>He additionally shared that ShinySp1d3r is only a rehash of Hellcat ransomware, besides modified with AI instruments. \u201cI gave the supply code of Hellcat ransomware out principally.\u201d<\/p>\n<p>Saif claims he reached out on his personal lately to the Telegram account for <strong>Operation Endgame,<\/strong> the codename for an ongoing legislation enforcement operation <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2024\/05\/operation-endgame-hits-malware-delivery-platforms\/\" target=\"_blank\" rel=\"noopener\">concentrating on cybercrime companies, distributors and their clients<\/a>.<\/p>\n<p>\u201cI\u2019m already cooperating with legislation enforcement,\u201d Saif stated. \u201cThe truth is, I&#8217;ve been speaking to them since at the least June. I&#8217;ve informed them almost the whole lot. I haven\u2019t actually achieved something like breaching right into a corp or extortion associated since September.\u201d<\/p>\n<p>Saif steered {that a} story about him proper now might endanger any additional cooperation he could possibly present. He additionally stated he wasn\u2019t certain if the U.S. or European authorities had been in touch with the Jordanian authorities about his involvement with the hacking group.<\/p>\n<p>\u201cA narrative would deliver a lot undesirable warmth and would make issues very tough if I\u2019m going to cooperate,\u201d Saif stated. \u201cI\u2019m not sure whats going to occur they stated they\u2019re in touch with a number of international locations relating to my request however its been like a complete week and I obtained no updates from them.\u201d<\/p>\n<p>Saif shared a screenshot that indicated he\u2019d contacted Europol authorities late final month. However he couldn\u2019t title any legislation enforcement officers he stated have been responding to his inquiries, and KrebsOnSecurity was unable to confirm his claims.<\/p>\n<p>\u201cI don\u2019t actually care I simply need to transfer on from all these things even when its going to be jail time or no matter they gonna say,\u201d Saif stated.<\/p>\n<\/p><\/div>\n<p><template id="9DNtIkPP5hAtRkBcdo9Z"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A prolific cybercriminal group that calls itself \u201cScattered LAPSUS$ Hunters\u201d has dominated headlines this 12 months by frequently stealing knowledge from and publicly mass extorting dozens of main companies. However the tables appear to have turned considerably for \u201cRey,\u201d the moniker chosen by the technical operator and public face of the hacker group: Earlier this [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":9186,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[895,5712,262,5711,2072,6640,2075,211],"class_list":["post-9184","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-admin","tag-hunters","tag-krebs","tag-lapsus","tag-meet","tag-rey","tag-scattered","tag-security"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9184"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9184\/revisions"}],"predecessor-version":[{"id":9185,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9184\/revisions\/9185"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/9186"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-12 05:15:59 UTC -->