2019 is a cybercriminal forum persona active since January 2026. The actor has claimed responsibility for publishing or selling purported customer and organizational databases, including alleged datasets associated with U.S. virtual psychiatric-care provider Blossom Health, U.S. pet-technology company Waggle, Australian financial-services firm Kalkine, and Singaporean B2B procurement platform Zeemart. The actor has used both cryptocurrency sale listings and free-download posts, typically providing samples or schema information to support claims. The alleged datasets contain personal contact, account, billing, health-administrative, business, and order information that could facilitate phishing, invoice fraud, business email compromise, medical identity fraud, and physical targeting. Multiple intrusion and data-leak claims attributed to 2019 remain unverified, and no confirmed intrusion method or technical toolset is publicly established. Reported victim listings also include organizations in Australia, Italy, France, and New Zealand.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Advertised an unverified, purported database containing records for more than 29,600 Blossom Health mental-health patients, including personal, clinical-administration, and insurance billing information, for a one-time cryptocurrency sale.
Allegedly leaked and published Waggle customer, billing, and review data on a cybercrime forum as a free download.
A newly emerged cybercrime threat actor that posts allegedly stolen victim data on forums and appears to leak it freely rather than offer it for sale. The group has recently listed multiple Australian victims and also targets entities in the US, Italy, France, and New Zealand.
Claimed leak and free distribution of an alleged Zeemart platform database containing 510,000+ records, including user, company, outlet, order, and financial data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.