A hacktivist entity known as USDoD has claimed to have leaked CrowdStrike's " entire Threat Actor Database " and is reportedly in possession of the company's " entire IOC [indicators of compromise] list " containing over 250 million pieces of data .
See also: CrowdStrike: Explains the reason for Friday's "blackout"

On July 24, 2024, the USDoD group announced on the English-language cybercrime forum BreachForumsthat it had acquired and leaked CrowdStrike's entire threat actor database.
The group provided a link to download CrowdStrike's alleged Threat Actor Database and shared samples of the data to substantiate its claims.
The leaked information reportedly includes:
- Nicknames
- Situation
- Last active dates for each threat actor
- Region/Country of Origin
- Number of targeted industries and countries
- Threat factor type and motivation
The data samples contained “ LastActive ” dates up to June 2024 , while the Falcon portal last active dates for some carriers extend to July 2024 , suggesting the likely timeframe of data acquisition.
Cyber Press researchers said they were able to see some of the leaked documents, but they do not confirm whether they are CrowdStrike's Threat Actor Database.
See also: Fake CrowdStrike repair manual pushes infostealer Daolpu
The USDoD group has a history of exaggerating its claims, likely to bolster its reputation in the hacktivist and eCrime communities. For example, it previously claimed to have conducted a hack-and-leak targeting a professional networking platform, which was later denied by industry sources as simple web scraping.

Since at least 2020, USDoD has been involved in both hacktivism and financially motivated breaches, primarily using social engineering tactics . In recent years, it has focused on high-profile targeted hacking campaigns and has attempted to expand its activities into operating cybercrime forums.
The group also claimed to possess “two large dbs from an oil company and a pharmaceutical company (not from the US).” However, the connection between these claims and the alleged CrowdStrike data acquisition remains unclear.
The potential leak of CrowdStrike's Threat Actor Database could greatly impact cybersecurity measures.
- Violation of ongoing investigations
- Reporting on monitoring methods for malicious actors
- Potential advantage for cybercriminals in avoiding detection
The claim comes after CrowdStrike's update caused a global blackout, rendering many systems inoperable.
See also: CrowdStrike CEO called to testify about outage
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In the context of security and data protection, a breach refers to an incident where unauthorized individuals gain access to sensitive information, systems, or networks. Such breaches can occur for a variety of reasons, including cyberattacks ,human error, or system vulnerabilities. The impact of a breach can be significant, leading to data theft, financial loss, and damage to an organization’s reputation. It is vital for businesses and individuals to implement strong security measures and response plans to mitigate the risks associated with potential breaches.
Source: cybersecuritynews
