CSIDB logo
Threat actor

Seize

Attribution profile

Type
Criminal
Location
China
Known incidents
1 incident
First seen
2023-02-17
Last seen
2023-02-17
Updated
2026-07-31 05:21
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Seize is a threat actor known by the alias Seize, with publicly available information indicating a possible location in China. The actor first came to attention in February 2023 when they claimed to have obtained internal data from a major telecommunications provider. No further details about the actor’s size, structure, or broader affiliations have been disclosed in open sources.

In the reported incident, Seize posted samples of what they described as TELUS employee information, including names and email addresses, on a data breach forum and asserted possession of over 76 000 unique email addresses scraped from the company’s internal APIs. Shortly thereafter, the actor offered to sell what they characterized as TELUS’s private GitHub repositories, source code, payroll records, and associated credentials such as AWS and Google authentication keys, highlighting the presence of a “sim‑swap‑api” that could enable SIM swap attacks. The posts were made on a underground forum where the actor labeled the material a “FULL breach” and promised to sell all associated data. TELUS confirmed that the leaked samples contained valid employee details for current technical staff but stated that its investigation had not found evidence of corporate or customer data compromise, describing the exposure as limited to internal source code and select employee information.

The observed behavior of Seize includes the exfiltration and attempted monetization of internal source code, employee directories, payroll data, and cloud service credentials, as well as the development or possession of a tool facilitating SIM swap attacks. The actor’s activities have been limited to a single publicly reported campaign targeting a telecommunications firm, with no additional incidents attributed to them in the available sources. No statements regarding the actor’s motives, sponsorship, or broader strategic goals have been made public, and any such inferences would exceed the provided information.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB