Linker Squad
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Linker Squad, also known as the Linker Squad, is a hacking group that has been publicly linked to several data theft incidents in Europe. The group’s location is noted as France in available reporting. Its activities have focused on media and telecommunications organizations, with attacks reported against French state television, a Spanish telecom operator, and a French broadcaster’s online shopping service. In the April 2015 breach of France Télévisions, the group was described as acting for financial gain, intending to sell the exfiltrated personal data. The stolen information consisted of names, postal and email addresses, and telephone numbers, with no passwords or financial details taken. This incident followed a separate disruptive attack on another French broadcaster, highlighting the group’s interest in the media sector. The group’s public statements to a Belgian outlet indicated plans to sell and share the data online.
Technically, Linker Squad has relied on web application vulnerabilities to gain initial access. The Orange Spain incident in January 2015 involved the exploitation of SQL injection flaws to reach customer databases and extract millions of records. The France Télévisions breach was attributed to insufficient security safeguards that the group leveraged to exfiltrate contact lists and viewer requests. For the TF1 magazine subscription site, the attackers compromised a third‑party shopping tool operated by Viapresse, demonstrating a pattern of targeting auxiliary services linked to major broadcasters. No specific malware families or custom tooling are mentioned in the sources; the group’s approach appears to center on exploiting known web flaws rather than deploying bespoke payloads. Attribution to Linker Squad comes from statements by the victims and from the group’s own claims to media outlets, with no evidence presented of state sponsorship or affiliation with a larger criminal consortium. The documented campaigns illustrate a consistent focus on acquiring personal data, primarily through data exfiltration from poorly protected web‑facing assets.
Incidents
Attributed incidents are available to members.
3 incidents