SingularityMD is a self-identified extortion threat actor associated with intrusions targeting U.S. public school districts, notably Clark County School District in Nevada and Jeffco Public Schools in Colorado in 2023. The actor has been linked to theft and threatened publication of large volumes of student, parent, staff, and district administrative data, including highly sensitive education and personal records. Reported activity indicates a focus on education-sector victims and the use of direct pressure tactics against institutions and affected communities. The actor’s claimed intrusion path relied on weak student-account authentication and access control weaknesses in cloud collaboration environments. Reported tradecraft includes obtaining access through student accounts, abusing predictable passwords, leveraging exposed account information, and escalating access through misconfigured Google Groups, shared drives, and related collaboration resources. The actor has also claimed prolonged unauthorized access within victim environments, theft of backups and configuration data, and access to staff communications and administrative records. SingularityMD’s operations are characterized by data theft and extortion rather than ransomware encryption. The actor has threatened to leak stolen information publicly, contact parents and staff directly, and increase reputational and legal pressure on victims if payment demands were not met. In the Clark County School District case, the actor allegedly distributed samples of stolen student data to parents. In the Jeffco Public Schools case, the actor allegedly demanded cryptocurrency payment in exchange for deleting stolen data and threatened broader public disclosure if unpaid. High-confidence reporting supports SingularityMD as an extortion-focused actor targeting K-12 education organizations in the United States. Attribution to a specific nation-state or country of origin is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Extortion-focused intrusions against U.S. school districts, including Clark County School District and Jeffco Public Schools, involving unauthorized network access, data theft, and threats to publish stolen data unless a fee is paid.
Extortion-focused intrusion against Clark County School District involving alleged prolonged network access, theft of large volumes of student and staff data, direct emailing of victims, public leaking of stolen data, and threats to continue leaking data unless payment is made.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.