CSIDB logo
Threat actor

TuftsLeaks

Attribution profile

Type
Nation State
Location
Russia
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-31 01:06
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as TuftsLeaks has been associated with operations originating from Russia, according to publicly available sources. The alias TuftsLeaks appears in reporting that links the group to a specific intrusion against a state‑level elections board in the United States. Attribution claims cited by a U.S. senator indicate that the IP address used in the breach matches infrastructure the FBI has tied to Russian state security services. This connection provides the only publicly stated link between TuftsLeaks and a state sponsor. No other aliases or geographic details are supplied in the open‑source record.

In the incident described by the Illinois State Board of Elections, TuftsLeaks gained unauthorized access to the board’s voter registration system. The intrusion exposed personal data belonging to approximately eighty thousand Illinois residents, including social security numbers and driver’s license information. The attackers remained inside the network for nearly three weeks before security teams detected the activity. The compromised data consisted solely of identity‑related fields, with no indication that the system itself was altered or destroyed. This case illustrates the actor’s focus on harvesting sensitive personal information from a government target.

The reporting does not specify any particular malware families, exploit kits, or custom tools employed by TuftsLeaks during the Illinois breach. Instead, the narrative emphasizes the longevity of the undetected presence and the successful exfiltration of voter data. No details are provided about phishing, credential theft, or vulnerability exploitation as the initial access vector. Consequently, the only observable TTP theme from the source material is the ability to maintain prolonged, stealthy access to a target environment while collecting specific data sets.

The Illinois elections board intrusion stands as the sole publicly reported operation attributed to TuftsLeaks in the available sources. No additional campaigns, victim sectors, or geographic regions are described elsewhere in the open‑source record. As a result, the profile of TuftsLeaks is currently limited to this single incident, which demonstrates a capability to infiltrate state‑level government systems and retain access long enough to harvest substantial volumes of personal data.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB