Goatse Security was a loosely organized hacker group active around 2010 and associated in some reporting with the GNAA. It is best known for the AT&T iPad 3G data exposure incident, in which members enumerated an openly accessible AT&T web application or API that returned customer email addresses when queried with iPad identifiers. The operation resulted in the collection of more than 100,000 AT&T iPad user email addresses, including accounts associated with government, military, media, and major corporate figures, and the group then publicized the issue through Gawker/Valleywag. Known members tied to the incident include Andrew Auernheimer, also known as Weev and Escher, and Daniel Spitler, also known as JacksonBrown. The group presented itself as exposing security weaknesses, but contemporaneous evidence tied members to conduct beyond conventional vulnerability disclosure. Internal discussions referenced possible phishing, spamming, publicity-seeking, and even a contemplated but unexecuted plan to profit from market impact after disclosure. Reporting also indicates that members used scripts to automate identifier enumeration and data harvesting, contacted journalists and some affected individuals using harvested addresses, and debated the legal consequences of their actions. In public accounts surrounding the case, there were conflicting claims about whether AT&T had been notified before disclosure. Goatse Security has also been credited in reporting with identifying flaws affecting Safari, Firefox-related IRC attack vectors, and Amazon’s ratings system, though the AT&T incident remains the defining activity associated with the group. The legal aftermath centered on U.S. federal prosecution of Auernheimer and Spitler under unauthorized-access and fraud-related theories, making the case a prominent point of debate over the boundary between criminal intrusion and controversial vulnerability disclosure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Goatse Security appears only in a generic Wikipedia navigation list of hacking groups, without any discussion tying it to the PoisonIvy content.
Groups Anonymous associated events Avalanche Crime Boys GNAA Goatse Security Insanity Zine Corp. GhostNet Level Seven PLA Unit 61398 Prime Suspectz RBN ShadowCrew World of Hell Sandworm
Associated with collecting and disclosing AT&T iPad users' email addresses obtained by querying a web panel tied to ICC-IDs; members discussed possible phishing use of the data before disclosure.
Groups Anonymous associated events Avalanche Crime Boys GNAA Goatse Security Insanity Zine Corp. GhostNet Level Seven PLA Unit 61398 Prime Suspectz RBN ShadowCrew World of Hell Sandworm
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.