Distributed Denial of Secrets, commonly abbreviated DDoSecrets, is a transparency-focused hack-and-leak collective launched in 2018 and often described as an alternative to WikiLeaks. The group is best known for publishing large datasets obtained from third parties, including the 2020 BlueLeaks release containing extensive U.S. law-enforcement and fusion-center records, and the 2019 Dark Side of the Kremlin release involving Russian political and governmental material. Public reporting and official characterizations have at times labeled the group a criminal hacker or hacktivist organization, but its publicly identified cofounder, Emma Best, has consistently stated that the group does not conduct intrusions itself and instead serves as a publication platform for already-obtained data. High-confidence reporting supports the group’s role in publishing and disseminating stolen or leaked information, but not direct attribution of the underlying compromises to the group itself. Its operations align with hack-and-leak activity centered on exposing sensitive institutional information for political transparency and public-interest impact. Published material has included police reports, FBI reports, fusion-center bulletins, surveillance guidance, protest intelligence, and Russian government-related records. The BlueLeaks publication was associated with nationwide protests in the United States following the killing of George Floyd and was used by journalists and researchers to examine law-enforcement monitoring of protesters, counter-surveillance practices, and threat assessments. The group’s activity demonstrates strong exfiltration-adjacent and post-exploitation relevance in the sense that it distributes data taken from victim environments, but available high-confidence facts do not establish that DDoSecrets itself performed the initial intrusion. Its dominant motivation is best assessed as hacktivism.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named in the content as conducting hack-and-leak operations, including publication of the BlueLeaks dataset containing sensitive law enforcement data and a prior release involving Russian government-related material.
Hacktivist leak collective associated in the content with publishing the BlueLeaks trove of police and FBI-related data and previously credited with hosting or releasing other politically sensitive leaked datasets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.