The leaked file is a PDF report, originally submitted in early 2025. It contains:

The report is fully redacted in terms of candidate name, but the machine names, IPs, and exploit paths are intact.


Even without reading the actual report, here are proven study takeaways:


Offensive Security (OffSec) has a history of rotating exam content when leaks become widespread. We can likely expect them to retire the compromised exam machines and introduce new scenarios. This is a standard operational response, but it is a reactive one.

However, OffSec has also been known to revoke certifications. If a candidate’s report is found to match the leaked content too closely (a common side effect of copying rather than doing), they risk not just failing the exam, but being banned from future certifications. The risk/reward ratio for using these leaks is incredibly poor.