Internet Yiff Machine (IYM) is a self-described hacktivist actor associated with the 2026 breach of P3 Global Intel and related Navigate360 tip-reporting platforms, an incident widely referred to as BlueLeaks 2.0. The actor claimed responsibility for obtaining a large dataset of approximately 8.3 million tip submissions spanning decades and affecting platforms used by law enforcement, schools, and government-linked safety programs. Public reporting and the actor’s own statements consistently frame the operation as anti-law-enforcement in motivation. IYM is reported to have targeted systems supporting Crime Stoppers and school safety reporting programs, including services associated with Safe2Tell, Safe2SayPA, and Sandy Hook Promise. The compromised data reportedly included highly sensitive tip narratives, chat logs, and personal information relating to both tipsters and reported individuals, including minors. The victim ecosystem included broad U.S. school usage and some Canadian schools, as well as public-sector and law-enforcement users. The actor claimed the intrusion began with social engineering against program staff, followed by exploitation of a cross-site scripting weakness to abuse an authenticated session, and then insecure direct object reference flaws to bypass authorization and access data across linked environments. Reported tradecraft also included large-scale database extraction over multiple days. Statements attributed to IYM further alleged weak security controls in the victim environment, including inadequate access controls and insufficient rate limiting. After the intrusion, the actor provided copies of the stolen dataset to transparency and media organizations, later advertised the data for sale, and also offered paid lookups against the dataset before stating that the material had been withdrawn from sale. Based on available reporting, Internet Yiff Machine is best characterized as a hacktivist intrusion actor with capabilities spanning initial access, session hijacking, exfiltration, reconnaissance of exposed application weaknesses, and post-exploitation abuse of authorization flaws. No high-confidence attribution to a nation-state or specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist responsible for obtaining and providing a massive dataset of allegedly anonymous tip submissions from systems associated with P3 Campus, P3 Global Intel, and Navigate360, exposing sensitive student and law-enforcement-related reports.
Hacktivist group claiming responsibility for the P3/"BlueLeaks 2.0" breach, exfiltrating more than 93 GB of data and 8.3 million tips from the P3 Anonymous Reporting System and providing the data to DDoSecrets, later offering it for sale.
Responsible for hacking P3 Global Intel and exfiltrating a dataset of 8.3 million supposedly anonymous and secure tips; later listed the dataset for sale and offered paid lookup services before stating the data had been taken off the market.
Hacktivist actor that breached P3/Navigate360’s anonymous tip platform, exfiltrated roughly 8.3 million sensitive tips, provided the dataset to DDoSecrets and a journalist, and later offered a copy for sale.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.