CSIDB logo
Threat actor

Toogod

Attribution profile

Type
Nation State
Location
China
Known incidents
1 incident
First seen
2019-01-01
Last seen
2019-01-01
Updated
2026-07-31 06:54
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Toogod is an alias used by a threat actor that has been identified as operating from China. The actor is described by Cyble Inc. as a known and reputable entity in the cyber threat landscape. No further details about the actor's structure or affiliations are publicly available in the provided sources. The alias appears in a Taiwan News article dated May 29 2020, which cites Cyble's research.

In May 2020, researchers at Cyble Inc. reported that Toogod had released a dataset titled 'Taiwan Whole Country Home Registry DB' on the dark web. The dataset originated from the Ministry of the Interior's Department of Household Registration in Taiwan. It contained the names, addresses, genders, dates of birth and other private information of more than twenty million citizens. The leak was reported on Friday May 29 2020, according to the Taiwan News coverage.

The leaked file measured approximately 3.5 gigabytes in size. According to the actor's own claim, the data was sourced from 2019, although Cyble analysts noted difficulty in confirming the exact recency of the leak. The release was described as unusual because it involved an entire national registry being exposed. The incident was highlighted by Cyble as an example of a significant breach of personal data on a national scale.

Cyble Inc., a United States‑based cyber threat intelligence firm, provided the analysis and contextualized the incident as a notable example of a large‑scale government data exposure. The firm emphasized that such a comprehensive leak is rare and underscores the potential impact on affected individuals. No additional malware, tooling or initial‑access vectors were described in the reporting. Cyble's own website states that it strives to provide organizations with real‑time views of their supply chain cyber threats and risks.

The overview of the incident highlights the significant risks to citizen privacy and data security that arise from the exposure of such a vast amount of personal information. The event serves as a publicly documented case linking the alias Toogod to a major data leak involving Taiwanese governmental records. No further campaigns or operations attributed to Toogod are detailed in the available material. Consequently, the profile is limited to the confirmed facts presented in the sources.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB