CSIDB logo
Threat actor

Crash Override

Attribution profile

Type
Activist
Location
United States of America
Known incidents
2 incidents
First seen
2016-11-05
Last seen
2021-01-09
Updated
2026-07-31 19:39
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Crash Override is the alias used by an individual threat actor who has been publicly identified in connection with two separate cyber incidents. The actor is known to operate from the United States of America, as indicated in the available threat actor context. No additional personal details or real‑world identity have been disclosed in the sources provided.

The actor’s observed targeting includes a right‑wing social media platform based in the United States and a Metropolitan Police news website located in the United Kingdom. In the 2021 incident the actor accessed and downloaded all user‑generated content from Parler, including messages, images, videos, location data and previously deleted posts, with the stated aim of enabling public accountability and potential doxxing of users. In the 2016 incident the actor claimed responsibility for disrupting the Metropolitan Police news website for approximately eight hours, linking the action to retaliation for arrests made during an anti‑capitalist protest. These actions demonstrate a focus on disruption and activism rather than financial gain or espionage, as no monetary or state‑sponsored motives are mentioned in the reporting.

The tactics, techniques and procedures described involve exploiting an internal web address to enumerate and scrape all data from a service, organizing a crowdsourced effort to download and archive the harvested information, and publishing the archive on the Internet Archive for broad access. For the police website disruption the actor employed a method that caused the site to be unavailable for eight hours, which is consistent with a denial‑of‑service or defacement technique, although specific malware families or tooling are not referenced in the sources. Attribution information shows that the 2016 police website action was publicly claimed by an individual using the Crash Override alias and was associated with the Anonymous collective, while the 2021 Parler breach was attributed solely to the Crash Override handle on Twitter without any asserted group affiliation. The two campaigns represent the actor’s notable publicly reported operations: the large‑scale data extraction from Parler in early 2021 and the temporary disruption of the Metropolitan Police news website during the 2016 Million Mask March. No further details about the actor’s size, sophistication, revenue or broader geographic scope are available in the provided material.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB