CSIDB logo
Threat actor

Hack for Trump

Attribution profile

Type
Hacker
Location
United States of America
Known incidents
2 incidents
First seen
2015-09-18
Last seen
2016-03-19
Updated
2026-07-31 02:56
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known publicly as Hack for Trump and also operating under the alias New World Hacking is based in the United States of America, according to the limited open‑source information available. The group first came to attention in 2015 when it identified itself as Hack for Trump in a ransom demand against a financial institution, and later in 2016 it was linked to Anonymous through the New World Hacking moniker during a distributed denial‑of‑service campaign. No formal organizational structure, size, or funding details have been disclosed in the sources examined. The actor’s public statements suggest a loose affiliation with hacktivist circles rather than a state‑sponsored entity or a defined criminal consortium.

Targeting patterns observed in the two reported incidents span government space agencies and private financial services, indicating a willingness to pursue both high‑profile institutional targets and profit‑motivated victims. In the NASA‑related operation the actor claimed to seek disruption of online services as part of a broader protest alleging censorship, while the Fidelity Group attack involved website compromise followed by an extortion demand for monetary payment. No references to specific malware families, exploit kits, or sophisticated intrusion tools appear in the reporting; the described tactics rely on distributed denial‑of‑service traffic and direct website defacement or data theft threats. Consequently, the actor’s technical approach appears to leverage readily available disruption methods and basic web‑application compromise rather than custom malware or advanced persistent techniques.

The most notable publicly reported activities include Operation Censorship, a March 2016 DDoS effort against NASA’s website and email servers that the group said was intended to pressure the agency over alleged withheld information about ISIS and to prepare for future actions against political figures. The earlier September 2015 incident saw Hack for Trump breach Fidelity Group’s online platform, threaten to release stolen data unless a $30,000 ransom was paid, and prompt the victim to temporarily shut down its services while notifying customers. These episodes represent the actor’s known operational repertoire: a blend of disruptive protests and financially motivated extortion, each accompanied by public claims of impact but lacking verifiable evidence of the alleged consequences. No further campaigns have been documented in the supplied material.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB