Digileaker
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Digileaker is an alias used by an individual who was formerly employed by the cryptocurrency derivatives exchange Digitex. The actor is known to be based in Namibia, according to available threat‑intelligence references. In February 2020 the actor exploited login credentials obtained from Digitex’s third‑party KYC provider, Sum and Substance, to gain unrestricted access to the exchange’s customer identification records. Using that access, Digileaker extracted passport scans, driver’s licence images, addresses, phone numbers and IP addresses for more than eight thousand users. The stolen data was initially disclosed through a hijacked Digitex Facebook account that released user email addresses, after which the actor moved to the messaging platform Telegram to publish the full KYC documentation. Digitex characterized the incident as an internal security breach carried out by a scheming and manipulative former employee, denying any external hack.
The actor’s actions went beyond simple data disclosure; after leaking a few identification documents, Digileaker began posting demands on Telegram, indicating that further leaks would be prevented only if certain conditions were met. This pattern shows an extortion‑oriented objective, wherein the threat actor sought compensation in exchange for withholding the remainder of the stolen KYC material. The primary initial‑access vector was the misuse of legitimate credentials rather than malware or exploit kits, highlighting a reliance on credential theft and abuse of trusted access. No specific malware families or custom tooling were reported in the coverage; the actor’s toolkit consisted of the stolen login, the ability to hijack a corporate social‑media account, and the use of Telegram for distribution. The breach demonstrates how insider access to third‑party service credentials can be leveraged to compromise large volumes of sensitive personal data.
Attribution to any state sponsor, criminal consortium or organized group has not been established in the public reporting; Digileaker remains identified solely by the alias and the individual’s former employment relationship with Digitex. The incident is notable as one of the few publicly documented cases where an ex‑employee used a third‑party KYC provider’s credentials to conduct a large‑scale data leak in the cryptocurrency sector. Digitex sought legal counsel and released statements attributing the leak to a former employee, while noting the uncertainty about the full scope of exposed data. No further campaigns or operations linked to Digileaker have been reported in open sources beyond the February 2020 Digitex incident.
Incidents
Attributed incidents are available to members.
1 incident