1011 is a hacker persona associated with a public claim of unauthorized access to a NordVPN development-related environment and the subsequent posting of alleged database dumps and configuration samples on BreachForums. The actor claimed the intrusion was achieved through brute-force access against a misconfigured system and asserted that the exposed material included development data and credentials associated with business tooling. Available reporting does not provide independent verification that 1011 compromised NordVPN production infrastructure or obtained genuine sensitive customer data. NordVPN stated that the exposed material originated from an isolated third-party test environment containing dummy content rather than live internal systems. Based on the currently corroborated facts, 1011 is best characterized as a forum-based intrusion actor publicly claiming initial access and data exposure against a technology-sector target, with brute-force activity and public leak behavior directly associated with the persona. No reliable attribution to a nation-state, organized ransomware operation, or broader intrusion set is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
1011 is known for breaching NordVPN's development infrastructure, exfiltrating and leaking source code, database schemas, and critical authentication credentials, including Salesforce API keys and Jira tokens. The group used credential brute-forcing against a misconfigured development server to gain access, exposing NordVPN to significant operational and security risks.
Claimed responsibility for breaching a NordVPN development server and leaking database dumps and configuration samples, including alleged Salesforce API keys and Jira tokens, on BreachForums.
Claimed responsibility for a brute-force attack against a NordVPN development server, alleging theft of databases containing Salesforce API keys and Jira tokens. The data was later confirmed by NordVPN to be dummy data from a third-party test environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.