THE Luna Moth Files appear to be a data leak, not a hack, according to DataBreaches[.]net. A researcher who had long involvement with the case says they found an open Rocket[.]Chat server backed by a MongoDB instance that was left accessible without a password. The researcher’s observations, later echoed by DataBreaches, indicate the MongoDB backup for Silent Ransom Group (SRG) contained the Rocket[.]Chat messages and was publicly accessible.
The exposed data were confirmed as matching the material in the Luna Moth Files, with the last visible content dated 29 September 2026 and the exposure dating back to at least August 2026. Screenshots, though partially redacted, show the MongoDB instance labeled “rocketchat” was open on 24 August 2026 and again on 28 September 2026 on an IP address in Lithuania. In short, no credential leakage was observed for Rocket[.]Chat itself, but the SRG backup was unprotected, making the contents publicly viewable.
The investigation notes that at least two entities downloaded and disseminated the data: the researcher who contacted DataBreaches[.]net and an unknown second party who obtained the leaked files. The first public reference to the Luna Moth Files appeared on X on 3 October, though it is unclear who posted it. The article states that SRG claimed the data were fake, a position the publication disputes, asserting instead that the files constitute a genuine leak.
The exposed content included chats, and the team behind Luna Moth Files argues the material offers a substantial resource for researchers and law enforcement, now that its authenticity is supported by the evidence of the open MongoDB exposure.