USDoD is a cybercriminal / hacktivist threat actor active on BreachForums/Breached and other underground forums. The content links USDoD to the December 2022 compromise of the FBI-affiliated InfraGard platform, where the actor claimed to have obtained access via social engineering and sold contact information for roughly 80,000 members. The actor later resurfaced in September 2023 to leak sensitive Airbus employee data; reporting in the content says the Airbus access was enabled through credentials stolen from a Turkish airline employee via RedLine infostealer malware, and USDoD threatened additional targeting of major U.S. defense contractors such as Lockheed Martin and Raytheon. In 2024, USDoD was repeatedly associated with the National Public Data (NPD) breach. Multiple reports and lawsuits cited in the content state that on April 7-8, 2024, USDoD advertised a database titled "National Public Data" on a dark web forum/Breached, claiming it contained about 2.9 billion records covering people in the United States, United Kingdom, and Canada, and offering it for sale for $3.5 million. The leaked data was described across the reporting as including names, Social Security numbers, current and past addresses, dates of birth, phone numbers, email addresses, and aliases, although later public leaks varied in included fields. Subsequent reporting says a 277 GB / 277.1 GB version of the dataset was later leaked for free, and some reporting cited in the content notes another actor, Fenice, attributed the underlying breach to SXUL rather than USDoD. Accordingly, attribution of the original NPD intrusion to USDoD is reported but not uniformly confirmed in the provided content. The content also associates USDoD with claims involving other high-profile data exposures. Reporting says USDoD claimed to have leaked CrowdStrike indicators of compromise and a threat actor database. USDoD was also tied in reporting to an alleged EPA-related data leak; however, the same content states CISA and the FBI assessed the data as publicly available, and USDoD later said there was no EPA breach and that the data had been scraped from a third-party platform called DataRefuge. The actor is described in the content as using social engineering, underground forum sales/leak postings, and the operational use of credentials harvested by infostealer malware. The reporting also notes Brazilian Federal Police arrested a suspect allegedly tied to USDoD in Belo Horizonte, Minas Gerais, and that researchers and reporting linked the alias to a Brazilian individual; however, the investigation was described as ongoing.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the sale of stolen National Public Data records on a dark web forum following the breach.
"I'm Not Pro-Russia and I'm Not a Terrorist!" —- InfraGard and Airbus Hacker “USDoD” Unveils His New Campaigns
Threat actor referenced as advertising stolen National Public Data breach data for sale.
USDoD is an individual threat actor allegedly responsible for high-profile breaches including the FBI’s InfraGard platform, Airbus, the U.S. Environmental Protection Agency, and National Public Data. The actor is known for leaking and selling large databases of personal and sensitive information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.