888 is a financially motivated cybercriminal persona active on cybercrime forums since at least 2024, primarily associated with the theft, brokering, and sale of allegedly stolen datasets from high-profile organizations. The actor has been linked to breach claims involving Accenture, the European Space Agency, CIEE, Diner en Blanc, Ledil Immobilier, ACRE Africa, MinasBet, Samsung Medison, and datasets involving Microsoft and Nokia personnel. Public reporting consistently places the persona in data-leak and access-broker style activity rather than ransomware operations. The actor’s tradecraft centers on obtaining or claiming access to cloud-hosted data stores, source-code repositories, external collaboration platforms, and business databases, then advertising the material for sale or release on criminal forums, often as one-time sales and frequently requesting Monero. Reported datasets have included source code, internal documentation, configuration files, private keys, access tokens, cloud storage material, and large volumes of personally identifiable information. In multiple cases, 888 published screenshots or sample records as proof-of-claim, including apparent access to Azure DevOps and Bitbucket environments, but the full scope of several claims remained only partially verified publicly. Observed behavior supports capabilities in initial access, credential theft, exfiltration, post-exploitation, reconnaissance, and monetization of stolen information. Reported incidents also indicate targeting of exposed or misconfigured cloud resources and information repositories, with follow-on risk from leaked credentials and secrets. The actor has shown repeated interest in technology firms, government-related research organizations, real-estate platforms, event-management services, and recruitment platforms, as well as victims in Brazil, France, Canada, Kenya, and Zambia. Some reporting has noted possible operational overlap with IntelBroker, but no definitive public proof establishes that they are the same actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Forum user allegedly offering and publishing an unverified ACRE Africa breach dataset containing farmer records, source code, configuration files, access tokens, private keys, and hardcoded credentials.
Actor accused of exfiltrating and offering for sale more than 35 GB of allegedly stolen Accenture data, including source code, RSA keys, SSH keys, Azure PATs, Azure Storage access keys, and configuration files.
Claimed responsibility for breaching Accenture and stealing 35 GB of source code and sensitive data, then offered the alleged data for sale on PwnForums. The actor was also linked in the article to a prior alleged attempt to sell purported Accenture employee data in 2024.
Allegedly selling claimed stolen Accenture data, including source code, RSA/SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files, via a cybercrime forum.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.