Team Poison was a British hacking group active in the early 2010s, commonly associated with hacktivist operations and publicized intrusions. The group is notable for its collaboration with Anonymous in campaigns such as #OpCensorThis and the so-called Operation Robin Hood. Team Poison was also linked to the compromise of the United Nations, where sensitive login information was publicly exposed. Public reporting identifies Junaid Hussain, later known as Abu Hussain al-Britani after joining the Islamic State cyber apparatus, as a former leader or member of Team Poison. The group’s activity reflects a mix of hacktivism, publicity-driven intrusion, and criminal conduct. Reported behavior includes unauthorized access to online services, exposure of stolen account data, and schemes involving stolen payment-card information purportedly intended to fund charities or protest activity. Team Poison’s operations therefore span both ideological messaging and financially harmful cybercrime. Its collaboration with Anonymous further places it within the broader ecosystem of loosely organized activist hacking collectives that used coordinated online campaigns, social-media amplification, and data leaks to attract attention. Known aliases in the supplied material are limited to Team Poison itself. High-confidence reporting ties the group to the United Kingdom through its membership and leadership, particularly Junaid Hussain of Birmingham. Although one former member later became involved with Islamic State cyber activity, Team Poison itself is best characterized as a UK-linked hacktivist hacking group rather than a nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UK hacker group previously associated with Junaid Hussain before he joined ISIS's cyber operations.
A British hacker group formerly led by Junaid Hussein, noted here in connection with account compromise activity and later jihadist cyber recruitment links.
Collaborating with Anonymous on "Operation Robin Hood," involving stolen credit card data, fraudulent purchases and donations, and possible laundering through PayPal; also described as having hacked the United Nations and leaked sensitive login data.
Joining Anonymous in the #OpCensorThis hacktivist/activist effort, with campaign promotion and updates shared through social media.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.