Exempt's doxing group is a financially motivated cybercriminal collective engaged in doxing-as-a-service operations. The group is associated with an individual using the name Exempt and has been described as exploiting emergency data request processes at major technology and communications providers to obtain victims' personal information. Its operations center on social engineering and legal-process impersonation rather than malware-centric intrusion activity. The group is known for impersonating law enforcement personnel and abusing emergency disclosure workflows intended for urgent threats to life or safety. Reported tradecraft includes use of spoofed or compromised law-enforcement-associated email accounts, fabrication of subpoenas and other legal documents, reuse of real officer names and badge numbers, and procedural research designed to make fraudulent requests appear legitimate. The actor has also sought access to secure law-enforcement request portals through compromised accounts or insider cooperation. These activities demonstrate strong capabilities in spoofing, reconnaissance, initial access through deception, and post-exploitation data acquisition for exfiltration. Victimology includes major US technology companies, communications providers, and online platforms. Reported targets include large consumer technology and e-commerce firms, internet platforms, and telecommunications providers, indicating a focus on organizations that hold subscriber, account, and identifying information useful for harassment, swatting, and paid doxing services. The actor's objective appears primarily financial, with revenue reportedly derived from selling unlawfully obtained personal data and related services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.