2019 is a cybercriminal forum persona first observed in January 2026 that has been associated with posting alleged stolen databases for free distribution on underground forums rather than advertising them for sale. The actor has been linked to claims involving organizations in multiple countries, including the United States, Australia, Singapore, Italy, France, and New Zealand. Reported victims include consumer technology and business-platform organizations, as well as Australian entities in public services, real estate, and cultural institutions. The actor’s activity is characterized by publishing sample records and offering download access to purported datasets, indicating a leak-and-share model centered on data exposure and downstream criminal reuse. Claimed datasets have included customer, billing, review, company, outlet, order, and contact information, which—if authentic—could support phishing, business email compromise, invoice fraud, social engineering, and broader criminal exploitation. The available reporting consistently describes these breach claims as unverified, and there is no high-confidence public attribution tying 2019 to a specific intrusion set, malware family, or state sponsor. Based on observed behavior, 2019 is best understood as a data-leak-focused cybercriminal actor engaged in publicizing and distributing allegedly stolen information for criminal ecosystem consumption. No confirmed nation-state affiliation is established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Allegedly leaked and published Waggle customer, billing, and review data on a cybercrime forum as a free download.
A newly emerged cybercrime threat actor that posts allegedly stolen victim data on forums and appears to leak it freely rather than offer it for sale. The group has recently listed multiple Australian victims and also targets entities in the US, Italy, France, and New Zealand.
Claimed leak and free distribution of an alleged Zeemart platform database containing 510,000+ records, including user, company, outlet, order, and financial data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.