daghetiaw is a threat actor name associated with the claimed sale and partial leak of alleged customer data from the Spanish technology retailer PcComponentes. Available reporting ties this activity to a credential-stuffing incident rather than a confirmed intrusion into the victim’s internal databases. The actor publicly claimed to possess a large customer database, leaked a subset of records, and offered the remainder for sale, indicating activity centered on monetization of compromised account data and associated personal information. High-confidence facts support account-compromise and data exposure claims linked to reused credentials and infostealer-derived login data, but do not support attribution to a confirmed network breach or broader established intrusion set. Based on the confirmed incident characteristics, daghetiaw’s observed behavior is consistent with credential abuse, theft of accessible account data, and exfiltration for resale. No corroborated evidence in the available facts supports nation-state affiliation, ransomware operations, or a broader alias set beyond the single observed name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed theft and sale of PcComponentes customer data; activity aligns with data-theft monetization claims following account access attempts via credential stuffing.
Claimed theft of a large PcComponentes customer database and attempted monetization by leaking a subset (500,000 records) and offering the remainder for sale; activity appears consistent with account compromise via credential stuffing using credentials sourced from infostealer logs rather than confirmed direct database intrusion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.