NightBroker is a data-leak and intrusion-claim actor observed advertising or releasing allegedly stolen databases on criminal forums in 2026. Activity attributed to this alias centers on opportunistic compromise claims against internet-exposed web applications and small online services, with victims spanning multiple countries and sectors. Reported targets include WordPress and WooCommerce sites, an AI-driven recruitment platform, and an Indian food-delivery application. NightBroker has also been credited as a collaborator in a separate claimed breach of a French travel company alongside the aliases misere and ChimeraZ. The actor’s reported tradecraft is consistent with low-complexity exploitation of exposed or weakly secured internet-facing assets. Claimed access vectors include search-engine reconnaissance to locate vulnerable sites, abuse of weaknesses in a GraphQL API including authentication bypass and unauthenticated data access, exposure of a demo administration panel, and association with a SQL injection-based database theft claim through a collaborator post. The actor’s operations appear focused on obtaining and publishing bulk data rather than deploying ransomware or destructive payloads. Data allegedly exposed in NightBroker-linked incidents includes customer and applicant personally identifiable information, resumes and recruitment metadata, order histories, payment-related references, session material, authentication tokens, password-reset material, and password hashes. In one campaign, the actor reportedly released multiple unrelated databases for free, suggesting an emphasis on notoriety or commoditized leak activity rather than exclusively direct monetization. Some posts were points-gated or otherwise forum-mediated, indicating a marketplace-oriented leak model. Observed targeting includes organizations in India, the United States, France, Ireland, South Africa, New Zealand, Germany, Turkey, and Austria. Affected sectors include information technology and online platforms, consumer-facing commerce and food delivery, and travel services. The available reporting repeatedly characterizes the breach claims as unverified and not independently corroborated, so attribution should be treated with caution. Even so, the consistent pattern associated with the alias indicates capabilities in reconnaissance, initial access through exposed web weaknesses, credential and session-related data theft, and broader exfiltration of backend databases.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Published a dump of 12 allegedly exposed WordPress/WooCommerce databases affecting small business e-commerce sites across multiple countries, reportedly found via search engine reconnaissance and released for free.
Claims to have breached Suitable AI and leaked a partial dump of 15,176 applicant records, allegedly obtained by abusing GraphQL API weaknesses including an authentication bypass and unauthenticated queries.
Named as a collaborator credited in the claimed Pachatours breach post.
Claimed breach and leak of Deliware's database, allegedly obtained via an exposed demo administration panel, with posted data said to include user records, orders, restaurant data, authentication material, and Stripe API keys.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.