CSIDB logo
Threat actor

Fatal Error Crew

Attribution profile

Type
Activist
Location
Brazil
Known incidents
1 incident
First seen
2018-08-23
Last seen
2018-08-23
Updated
2026-07-30 22:13
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Fatal Error Crew operates under that alias and has been linked to activities originating in Brazil. Public reporting identifies a member using the handle @joshua as part of the group. No further details about the actor's structure, size, or sponsorship are available in the open sources. The name itself appears in the leak announcement and has not been associated with any other moniker in the material reviewed.

The group's known activity involves targeting organizations within the retail sector, specifically the Brazilian division of an international fashion retailer. The incident that brought the crew to public attention was described as a retaliatory action against the company's alleged misuse of jobseeker data to meet gift card production quotas. This indicates that the crew's strategic objective in that case was to expose perceived wrongdoing rather than to pursue financial gain or espionage. No other sectors or geographic foci have been documented in the available material, and the actor has not claimed responsibility for any additional incidents beyond the one described.

In August 2018 Fatal Error Crew member @joshua leaked customer data from the retailer's gift card platform on the Pastebin site, exposing information such as identification numbers, email addresses, gift card values, order numbers and purchase dates for roughly thirty‑six thousand individuals. The retailer in question, C&A, acknowledged a cyberattack movement on its gift card and exchange system, activated contingency procedures and initiated legal steps while denying any improper use of personal data. The leaked data included personal identifiers and transaction details that could be used for identity‑theft or fraud, although the actor's statements framed the release as a protest against perceived corporate misconduct. The attack did not involve publicly disclosed malware families or specific intrusion tools; the only disclosed technique was the exfiltration and publication of the data set. Following the leak the retailer reported that it had secured the affected systems and was cooperating with authorities to investigate the breach. No additional campaigns attributed to Fatal Error Crew have been reported in the sources consulted, leaving the 2018 C&A incident as the sole publicly documented operation. The incident highlighted the potential impact of targeting loyalty and gift‑card systems as a means of exerting pressure on corporations. Despite the publicity, no further technical details about the actor's capabilities, infrastructure or motivations have been made public.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB