Nam3L3ss is an online threat actor associated with the public release of stolen corporate data, including a large leak of Amazon employee work-contact information and similar disclosures affecting numerous other companies. The actor has been observed publishing datasets on hacking forums and claiming access to data obtained from multiple sources, including information allegedly stolen during the 2023 MOVEit mass-exploitation campaign as well as data exposed through misconfigured cloud resources and internet-facing databases. Reported victim organizations span major multinational enterprises across technology, financial services, transportation, insurance, and consumer sectors. In the Amazon case, the leaked information consisted of employee names, work contact details, and building-location data originating from a third-party property-management vendor rather than Amazon or AWS systems directly. The actor’s behavior is consistent with data theft and public disclosure activity centered on acquiring and exposing sensitive business information, but the available information does not support a high-confidence attribution to a nation-state or a clearly defined ransomware operator role.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Leaked corporate employee datasets (Amazon, 3M, HSBC, HP) claimed to have been obtained via the 2023 MOVEit incident; functions as a data leaker/redistributor in this reporting.
Leaked Amazon employee data allegedly stolen during the May 2023 MOVEit attacks after a breach at a third-party service provider.
Nam3L3ss is a threat actor focused on aggregating and leaking large datasets, including those stolen in the MOVEit attacks and from other exposed sources. They collect databases from exposed web sources and leak them on hacking forums.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.