The hacker who published 2.8 million rows of employee datavia the Amazon MOVEit exploit last week has taken to the dark web to claim to be an ethical hacker and is doing so to raise awareness about poor security practices.
See also: Amazon: Confirms employee data breach

The individual, who uses the online alias "Nam3L3ss," claimed in a series of posts that he obtained data from 25 organizationswhose data was compromised through last year's Amazon MOVEit exploit.
According to Hudson Rock, which verified the data, these organizations include McDonald's, Charles Schwab, Lenovo, Delta Airlines, HSBC and Amazon – with an estimated five million records leaked so far.
However, Nam3L3ss has now taken to the dark web to protest his innocence.
“I am not a hacker! If something requires a username or password, even a default password, I will not attempt to use it! I monitor all ransomware sites and have my own tools that automatically find open AWS and other website buckets,” they wrote on Monday. “I download whatever I can from ransomware TOR sites and open cloud services. Once I have it, I clean the data and remove duplicates from the source and sometimes remove fields/columns where the data is useless.”
See also: Amazon AWS: €1.2 billion investment in data centers in Italy
In a separate post on Tuesday discovered by Infosecurity, the ethical hacker claimed to have leaked the data to raise awareness among organizations about poor information security practices.

“Companies and governments have a responsibility to ensure that they encrypt PII data. Too many companies blame third-party vendors, yet they themselves transfer unencrypted data to those third parties,” he said. “Those who send encrypted data have a responsibility to make sure the third party keeps it encrypted.”
Despite his protests, it is unclear whether the leaked data was collected from third-party sources or whether he obtained it directly through the MOVEit exploit. Given that the types of data across these 25 victim organizations are similar, it is possible that the original source could have been a single third-party vendor.
Nam3L3ss told Hudson Rock researchers that this breach " is just a small part of the data he has ," with more set to leak in the coming days.
See also: Amazon: CEO defends decision to fully return to the office
Ethical hackers, also known as “white hat” hackers, are professionals who use their cybersecurity skills for good. Their primary mission is to identify and fix vulnerabilities in a company’s systems and networks before they can be exploited by malicious hackers. Through controlled attacks, ethical hackers help organizations strengthen their security and protect their digital assets. They always work with the organizations’ permission and follow strict ethical rules to ensure that their actions are legal and for the benefit of the organization.
Source: infosecurity-magazine
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
