Orcinusorca is a self-identified intrusion actor active on underground forums in 2026 that publicly claimed compromises involving U.S. federal infrastructure and Wickr Enterprise, an Amazon-owned secure enterprise messaging platform. The actor used the aliases Orcinusorca and Orcinus orca. The actor’s most visible activity consisted of high-profile breach claims accompanied by limited public proof. In one case, Orcinusorca asserted access to FBI infrastructure and released a sample archive framed as evidence of compromise. Technical review of the released material assessed it as a systematic collection of publicly accessible FBI and U.S. government data, including public APIs, website content, reports, and law-enforcement datasets, rather than evidence of sustained access to internal FBI networks or theft of non-public classified information. The sample also suggested automated collection and polling of public endpoints. In another case, the actor claimed deep access to Wickr Enterprise production infrastructure, including administrative API access and exposure of internal and payment-related keys, but the publicly shown evidence was limited to headers and a small JSON fragment and was not independently validated. Based on currently available information, Orcinusorca is best characterized as an actor making opportunistic, publicity-oriented breach claims against prominent U.S. government and technology targets. Reported behavior includes alleged initial access and post-exploitation claims, as well as reconnaissance-oriented collection from exposed or public-facing services. However, the strongest corroborated evidence supports scraping and repackaging of public data rather than confirmed compromise of internal environments. No high-confidence attribution to a nation state or organized criminal program is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed compromise of FBI infrastructure and release of purported internal data samples, but the content assesses the incident as more likely systematic scraping and repackaging of public FBI/API data rather than a genuine deep internal breach.
Claimed unverified access to Wickr Enterprise production Admin API infrastructure and alleged leakage of internal API keys and Braintree production payment keys.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.