CSIDB logo
Threat actor

optusdata

Attribution profile

Type
Nation State
Location
China
Known incidents
3 incidents
First seen
2018-03-23
Last seen
2022-09-22
Updated
2026-07-31 23:11
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias optusdata is associated with China based on the location information provided in the context. Public reporting links this actor to state‑sponsored activity, specifically citing the Chinese government in the Amnesty International Hong Kong incident and the Alaska government reconnaissance operation. While the Optus breach does not carry an explicit attribution in the sources, the actor’s alias appears in connection with that event, and the broader pattern described notes that telecom intrusions are often pursued by nation‑state‑backed groups seeking intelligence.

Targeting observed for optusdata spans telecommunications, non‑governmental organizations focused on human rights, and governmental entities. The Optus incident involved a major Australian telecom where customer personal data, including identity documents, was accessed. The Amnesty Hong Kong case saw the compromise of supporter data such as names, identity card numbers and contacts, with no financial information taken. The Alaska operation consisted of network reconnaissance against the State of Alaska Government and its Department of Natural Resources, concentrating on oil and gas sectors relevant to bilateral trade discussions. Strategic objectives described in the sources emphasize espionage, noting that the stolen telecom data could be used for spying or social engineering, and the human rights NGO intrusion was characterized as an attempt to obstruct advocacy work; the Alaska reconnaissance aligned with China’s Belt and Road Initiative economic goals.

Tactics, techniques and procedures referenced include network reconnaissance scanning for vulnerabilities, the use of infrastructure linked to Tsinghua University in the Alaska case, and the employment of tools and techniques consistent with advanced persistent threat groups in the Amnesty incident. No specific malware families, initial access vectors or tooling styles are detailed in the provided material. Notable publicly reported operations comprise the 2022 Optus customer data breach, the 2019 Amnesty International Hong Kong cyberattack, and the 2018 Chinese state‑sponsored reconnaissance of Alaskan government networks. These examples illustrate the actor’s focus on acquiring sensitive information from telecommunications, advocacy and government targets to support espionage‑oriented objectives.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB