Menu
Browse

Cyber Threat Actor: Maxim Gorki

Actor Type Location Known Incidents
 Icon
Criminal
1 incident
Profile

Maxim Gorki is an alias used by an individual or group that has been linked to a cyberattack against Turkey’s Municipality of Konya in March 2021. The actor’s name appeared on a hacker forum where stolen data from the incident was offered for sale, establishing the alias as a point of reference in public reporting of the breach. No other aliases or alternative identifiers have been publicly associated with this actor in the available sources. The incident remains the only documented activity attributed to Maxim Gorki in the open‑source record.

The observed targeting involved a governmental entity, specifically a municipal administration in Turkey, indicating a focus on public sector institutions within that country. The compromised data consisted of personal information belonging to approximately one million individuals who had previously communicated with the municipality via email, including national identification numbers and other sensitive details. After the intrusion, the actor placed the exfiltrated dataset on a underground marketplace, suggesting an intent to monetize the stolen information. No additional sectors, regions, or victim types have been reported in connection with this alias.

The tactics, techniques, and procedures described in the reporting center on the exploitation of email‑related data stores maintained by the municipality. The actor gained access to personal information that was stored as part of email correspondence, though the specific initial access vector—such as phishing, credential theft, or vulnerability exploitation—is not detailed in the source material. No particular malware families, toolkits, or custom utilities were mentioned in the coverage of the Konya incident. The post‑infection activity noted was the aggregation and listing of the stolen data on a hacker forum for sale, which represents the observable exfiltration and distribution phase of the operation.

Attribution to any state sponsor, criminal consortium, or broader threat actor network has not been established in the publicly available information concerning Maxim Gorki. Consequently, the actor’s affiliations remain unknown based on the evidence presented. The Konya municipality breach stands as the sole representative campaign attributed to this alias, illustrating a data‑theft operation that targeted a Turkish governmental body and resulted in the large‑scale exposure of citizen personal data. This case provides the only concrete reference point for understanding the actor’s observed behavior to date.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
0 sources