A hacking group has been impersonating law enforcement officers to trick major US tech companies into disclosing sensitive personal data. By sending spoofed emergency data requests, the attackers have successfully obtained names, addresses, phone numbers, and email addresses of targeted individuals from companies such as Charter Communications, Apple, Amazon, and Rumble. The process reportedly takes as little as 20 minutes, with the hackers providing doxing-as-a-service to paying customers seeking private information held by these firms.
The scheme relies on easily faked documents and spoofed email addresses, exploiting the trust tech companies place in urgent law enforcement requests. Law enforcement and company representatives have expressed concern over the ease with which these attacks are carried out, but declined to comment on specific incidents. The hackers show little regard for how the stolen information is used, raising significant privacy and security concerns for individuals whose data is exposed through these fraudulent requests.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
A hacker posing as Officer Jason Corse of the Jacksonville Sheriff's Office sent a fraudulent emergency data request to Charter Communications. A Charter privacy specialist responded within minutes and disclosed sensitive subscriber information including the target's name, address, phone numbers, and email.
Public reporting revealed that doxers had been posing as law enforcement to trick major tech firms into handing over private user data, highlighting weaknesses in emergency disclosure processes and email-based verification. The coverage also noted that the actors were profiting from the scheme and continuing to seek ways around improved defenses.
After incidents involving fraudulent emergency data requests, Amazon implemented additional safeguards to better verify law enforcement requests. The reporting indicates the broader problem persisted because many companies still accepted such requests through insecure email channels.
A hacking group led by an individual known as Exempt used compromised or spoofed law enforcement email accounts and forged emergency legal paperwork to impersonate police and request user data from major US tech companies. The activity affected companies including Apple, Amazon, Charter Communications, and Rumble, though the references do not specify when the campaign began.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.