BigBrother’s Gaze
Attribution profile
- Type
- Sensationalist
- Location
- China
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2019-12-24
- Last seen
- 2019-12-24
- Updated
- 2026-07-31 20:22
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor referred to as BigBrother’s Gaze is known from a single publicly reported intrusion that occurred in December 2019. Open‑source context lists the actor’s location as China, although no further biographical or organizational details have been disclosed. The alias first appeared in connection with a live YouTube broadcast of surveillance footage taken inside a Thai prison. No other aliases, affiliations, or prior operations have been attributed to this actor in the available material.
On 24 December 2019 the actor gained unauthorized access to the security camera system at Lang Suan Prison in Chumphon province, southern Thailand, and streamed live video from multiple internal cameras to a YouTube channel under the BigBrother’s Gaze name. A reporter discovered the broadcast and alerted authorities, after which Thai officials confirmed that the feed showed prisoners’ activities from several different cameras and was incorrectly labeled as originating from a Bangkok prison. The YouTube channel also hosted unrelated security‑camera feeds, including views of a Thai company’s office, street scenes from Salt Lake City, an office in Australia, and a café in Amsterdam. Upon learning of the incident, the Corrections Department Director‑General Police Col. Narat Sawettanan ordered the prison to shut down its camera system, launch an internal investigation, and file a police complaint; the video was subsequently removed from the platform.
Investigators noted that the compromised cameras were part of an Internet of Things deployment whose security had been neglected, allowing external actors to reach the devices through the network. The breach is cited as an example of the risks posed by inadequately secured IoT equipment, but no specific malware families, exploit tools, or post‑infection techniques were described in the reporting. Attribution remains limited to the inference that the actor operated from outside Thailand, with the only publicly available geographic clue pointing to China. Beyond this single incident, no additional campaigns or publicly linked operations have been associated with BigBrother’s Gaze.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.