The 414s, also known as the 414 Gang or 414s, was a loosely organized group of teenage computer enthusiasts operating from the Milwaukee, Wisconsin area in 1982–1983. The group took its name from Milwaukee’s telephone area code. Using home computers, modems, dial-in access, and weak authentication controls, members conducted unauthorized intrusions against computer systems in the United States and Canada. Their known targets included Memorial Sloan-Kettering Cancer Center, Los Alamos National Laboratory, Security Pacific National Bank, and a Canadian cement company. During the Sloan-Kettering intrusion, attackers created unauthorized accounts, deleted billing data, and deployed software that captured legitimate users’ passwords. The group became an early high-profile example of remote computer intrusion through public telephone networks and insecure dial-up systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historic U.S. hacker group that conducted unauthorized remote access to scientific, healthcare, and banking systems, using modems and weak authentication mechanisms.
Referenced as a named hacking group in the historical timeline/navigation content.
Named historical hacking group listed in the content's timeline/navigation material.
Referenced as a named hacking group in the 1980s hacking timeline/navigation content only; no operational details are provided in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.