lulzintel is a data-breach actor associated with the public posting of allegedly stolen databases on BreachForums and other open-web venues. Reported activity includes claims involving a Singapore-based Traditional Chinese Medicine clinic and a Polish e-commerce retailer, indicating opportunistic targeting across multiple sectors and geographies rather than a narrowly specialized victim profile. Observed operations center on obtaining and publishing large datasets containing personal information and, in some cases, credential-related material and business records. The actor has been linked to breach claims affecting healthcare and retail organizations. In the healthcare case, lulzintel allegedly advertised a database containing patient and treatment-related information from a Singapore clinic. In the retail case, the actor allegedly leaked a full PrestaShop database from a Polish retailer, exposing customer identity data, hashed passwords, password-reset material, account metadata, business customer fields, and internal mail records. The reported tradecraft in that incident is consistent with exploitation of a public-facing application, access to backend information repositories, theft of credential-related data, and subsequent exfiltration and public release of the stolen database. Based on the available reporting, lulzintel demonstrates capabilities in initial access, credential theft, exfiltration, and post-compromise data monetization or exposure through leak publication. The actor is best characterized as a breach-and-leak operator. Attribution to a specific country, formal intrusion set, or state sponsor is not supported by the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data breach activity involving the public leak of VegeHome's PrestaShop customer database, exposing over 100,000 customer records and related internal mail data.
Claimed compromise and leak of approximately 150,000 patient records from a Singapore-based Traditional Chinese Medicine clinic, with data including personal, medical, appointment, invoice, and treatment records.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.