Mr. Raccoon
Attribution profile
- Type
- Undetermined
- Location
- -
- Known incidents
- 2 incidents
- Sources
- 0 sources
- First seen
- 2026-04-01
- Last seen
- 2026-04-20
- Updated
- 2026-09-04 12:52
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Mr. Raccoon is a threat actor whose public footprint, based on available reporting, is primarily defined through two alleged operations tied to high-profile data theft and subsequent extortion. The alias has appeared in the aftermath of breaches affecting large enterprises, and the actor's activity suggests an opportunistic approach that leverages weaknesses in third-party vendors and outsourced support functions rather than direct assaults on hardened primary targets. The associated operations have resulted in the exposure of sensitive personal, financial, and corporate information, followed by public leak activity consistent with double-extortion ransomware behavior.
In terms of targeting, the incidents attributed to Mr. Raccoon focus on organizations that handle sensitive personal and financial data, with observed victims in the financial and technology sectors. The first documented operation, dated April 20, 2026, targeted Frost Bank through a shared third-party vendor, resulting in the exposure of personal and tax-related information belonging to more than 250,000 individuals, including names, addresses, Social Security numbers, taxpayer identification numbers, mortgage interest records, W-2 forms, 1099s, and HSA contribution data. The second documented operation, dated April 1, 2026, allegedly affected Adobe via an Indian business process outsourcing support vendor. Together, these incidents indicate a pattern of pivoting through trusted external partners to reach well-protected primary organizations, prioritizing targets where supply-chain access yields high-value data.
The tactics, techniques, and procedures observed in these operations center on social engineering and third-party exploitation. In the Adobe case, the actor used a phishing email to deliver a remote access tool, leveraged that foothold to pivot into a manager's account, and then used access to the helpdesk environment to export support tickets, employee records, and internal bug bounty submissions from HackerOne. The Frost Bank case demonstrates a supply-chain intrusion through a shared vendor, with the compromised data ultimately appearing on a ransomware leak site operated by the Everest group. This blend of phishing-initiated remote access and third-party infiltration for large-scale data extraction constitutes the core of Mr. Raccoon's documented tradecraft.
Attribution information remains limited. The Frost Bank data was published on the Everest ransomware group's leak site, indicating a possible collaborative or affiliate-style relationship between Mr. Raccoon and established ransomware operations, though the exact nature of that connection is not publicly detailed. No state nexus or specific criminal consortium affiliation has been publicly established for Mr. Raccoon beyond this apparent overlap with Everest's extortion infrastructure. Public class action litigation followed the Frost Bank breach, underscoring the operational and legal consequences of the actor's data theft and leak activity.
Incidents
Attributed incidents are available to members.
2 incidentsSources
Sources available to members: 0 sources.