SXUL
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the handle SXUL emerged publicly in late 2023 as the individual who originally compromised National Public Data, a data‑broker that aggregates United States public records such as voter registrations, property filings, marriage certificates, motor‑vehicle records, criminal and court documents, death records, professional licenses and bankruptcy filings. SXUL operated under a Telegram account that was later deleted, apparently in response to heightened media attention surrounding the breach. No public source has linked SXUL to a nation‑state sponsor, a criminal syndicate or any other organized group, and the actor remains unattributed beyond the pseudonym.
The data exfiltrated by SXUL consists of extensive personal information on millions of U.S. residents, including social‑security numbers, addresses and other identifiers that are routinely used for identity verification. Investigative reporting notes that the stolen dataset quickly entered an underground ecosystem where it fuels large‑scale identity‑theft and account‑takeover operations, indicating a financially motivated objective rather than espionage or disruption. Because the source material consists of nationwide public records, the targeting is effectively indiscriminate with respect to industry or geography, focusing instead on the broad pool of U.S. consumers whose data is aggregated by data‑broker services.
The actor’s tactics, techniques and procedures are described only in broad terms: the initial intrusion involved gaining unauthorized access to National Public Data’s systems, after which the stolen database was transferred through illicit channels. Subsequent distribution occurred via underground forums such as Breachforums and was facilitated by communications over Telegram. No specific malware families, exploit kits or custom tooling are mentioned in the source material, so the TTP description is limited to the compromise of a data‑broker platform and the ensuing data‑trafficking workflow.
Attribution to any state‑linked or criminal consortium has not been established in open sources; the only affiliated actor referenced is the moniker USDoD, who claimed to have later possessed and traded the same dataset but explicitly stated they did not obtain it from SXUL. The most notable operation associated with SXUL is the December 2023 theft of the National Public Data database, which triggered a cascade of data sharing that culminated in a public leak on Breachforums and has since fed widespread fraud‑related activity. This episode represents the actor’s principal publicly documented campaign to date.
Incidents
Attributed incidents are available to members.
0 incidents