Spirigatito is a cybercriminal threat actor associated with public data-leak and data-sale activity on cybercrime forums and related marketplaces. The actor has been observed claiming compromises of government-linked and public-sector organizations and publishing or advertising stolen datasets affecting consumers, public institutions, and administrative records. Observed activity includes the public leak of customer data from LCBO in Canada, the leak of data associated with Den kulturelle skolesekken (DKS), a Norwegian national cultural programme operated by Kulturtanken under the Ministry of Culture, and claims of a large-scale compromise of Tanzanian government infrastructure linked to BRELA, the Business Registrations and Licensing Agency. In the BRELA case, the actor allegedly structured the stolen information into multiple databases and offered access through a custom marketplace, indicating deliberate monetization rather than simple notoriety posting alone. The actor’s operations are consistent with theft, aggregation, publication, and sale of sensitive records from information repositories. Reported exposed data types include customer account information, personal contact data, government and programme administration records, internal communications, business registration data, shareholder information, tax-related identifiers, and parliamentary-related records. This activity creates downstream risk of phishing, impersonation, fraud, and broader criminal exploitation of exposed personal and institutional data. High-confidence behaviors associated with Spirigatito include initial access through exploitation of public-facing applications in at least one reported intrusion claim, collection from information repositories, exfiltration, and post-compromise monetization via leak forums and marketplace-style distribution. The actor is best characterized as a financially motivated data-breach and leak actor rather than a ransomware operator, with no high-confidence evidence here of encryption-based extortion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among the threat actors detected in the CTI research covering the spike in data-leak claims against French targets.
Posted and leaked a breached database belonging to Den kulturelle skolesekken (DKS), exposing PII, internal communications, and programme planning data from Norway's national cultural-schoolbag programme.
Posted and leaked an LCBO customer database on a public cybercrime forum, claiming exposure of 165,840 customer records containing names, emails, phone numbers, account IDs, and account type data.
Claimed compromise of Tanzanian government infrastructure linked to BRELA, exfiltration of 10.2 million records across six curated databases, and monetization of the stolen data through a custom cryptocurrency-enabled marketplace.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.