HomeSecurityHackers say they breached CrowdStrike's Threat Actor Database

Hackers say they breached CrowdStrike's Threat Actor Database

A hacktivist entity known as USDoD has claimed to have leaked CrowdStrike's " entire Threat Actor Database " and is reportedly in possession of the company's " entire IOC [indicators of compromise] list " containing over 250 million pieces of data .

See also: CrowdStrike: Explains the reason for Friday's "blackout"

CrowdStrike database

On July 24, 2024, the USDoD group announced on the English-language cybercrime forum BreachForumsthat it had acquired and leaked CrowdStrike's entire threat actor database.

The group provided a link to download CrowdStrike's alleged Threat Actor Database and shared samples of the data to substantiate its claims.

The leaked information reportedly includes:

  • Nicknames
  • Situation
  • Last active dates for each threat actor
  • Region/Country of Origin
  • Number of targeted industries and countries
  • Threat factor type and motivation

The data samples contained “ LastActive ” dates up to June 2024 , while the Falcon portal last active dates for some carriers extend to July 2024 , suggesting the likely timeframe of data acquisition.

Cyber ​​Press researchers said they were able to see some of the leaked documents, but they do not confirm whether they are CrowdStrike's Threat Actor Database.

See also: Fake CrowdStrike repair manual pushes infostealer Daolpu

The USDoD group has a history of exaggerating its claims, likely to bolster its reputation in the hacktivist and eCrime communities. For example, it previously claimed to have conducted a hack-and-leak targeting a professional networking platform, which was later denied by industry sources as simple web scraping.

Hackers say they breached CrowdStrike's Threat Actor Database

Since at least 2020, USDoD has been involved in both hacktivism and financially motivated breaches, primarily using social engineering tactics . In recent years, it has focused on high-profile targeted hacking campaigns and has attempted to expand its activities into operating cybercrime forums.

The group also claimed to possess “two large dbs from an oil company and a pharmaceutical company (not from the US).” However, the connection between these claims and the alleged CrowdStrike data acquisition remains unclear.

The potential leak of CrowdStrike's Threat Actor Database could greatly impact cybersecurity measures.

  • Violation of ongoing investigations
  • Reporting on monitoring methods for malicious actors
  • Potential advantage for cybercriminals in avoiding detection

The claim comes after CrowdStrike's update caused a global blackout, rendering many systems inoperable.

See also: CrowdStrike CEO called to testify about outage

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In the context of security and data protection, a breach refers to an incident where unauthorized individuals gain access to sensitive information, systems, or networks. Such breaches can occur for a variety of reasons, including cyberattacks ,human error, or system vulnerabilities. The impact of a breach can be significant, leading to data theft, financial loss, and damage to an organization’s reputation. It is vital for businesses and individuals to implement strong security measures and response plans to mitigate the risks associated with potential breaches.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS