David Pokora
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
David Pokora, also known by the alias David Pokora, is a Canadian national residing in Mississauga, Ontario who was identified as a member of the hacking collective referred to as Xbox Underground. Between January 2011 and March 2014 the group allegedly breached the networks of several prominent technology and defense organizations, including Microsoft, Epic Games, Valve, Zombie Studios and the United States Army. The intrusions resulted in the exfiltration of unreleased software, source code, pre‑release video game titles and military training applications such as Apache helicopter simulation tools, alongside internal financial and sensitive corporate data that did not involve customer information. The Department of Justice estimated the value of the stolen intellectual property to be between one hundred and two hundred million dollars. Pokora, together with three co‑defendants, was charged on eighteen counts encompassing conspiracy to commit computer fraud, copyright infringement, wire fraud, mail fraud, identity theft and theft of trade secrets, with additional individual counts of aggravated identity theft and unauthorized computer access. He and Sanadodeh Nesheiwat pleaded guilty to conspiracy to commit computer fraud and copyright infringement, each facing a potential maximum sentence of five years imprisonment, while an Australian associate linked to the conspiracy also faced charges in the United States.
The alleged tactics employed by the group relied primarily on SQL injection attacks and the use of compromised employee credentials, including usernames and passwords obtained from software development partners, to gain initial access to target networks. Once inside, the actors navigated systems to locate and copy proprietary assets such as game source codes, unreleased builds and defense simulation software, which were then removed from the compromised environments. No specific malware families or custom tooling are described in the available sources, highlighting the reliance on credential theft and injection techniques rather than bespoke malicious code. The operation is publicly attributed to the Xbox Underground ring, a criminal consortium whose members were prosecuted in the District of Delaware, establishing a clear nexus to the alleged activities without any indication of state sponsorship or broader affiliations. The case represents a notable example of cross‑sector intellectual property theft that spanned the gaming industry and military contractors over a multi‑year period.
Incidents
Attributed incidents are available to members.
4 incidents