CSIDB logo
Threat actor

@Compl3x1ty

Attribution profile

Type
Sensationalist
Location
United States of America
Known incidents
2 incidents
First seen
2015-02-14
Last seen
2015-02-14
Updated
2026-07-31 04:00
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known online as @Compl3x1ty, also using the alias @Shinji_Kagawa, has been identified as operating from the United States of America. Public references to the actor appear in a 2015 data breach disclosure where the actor announced the compromise via Twitter. The actor’s aliases are the only persistent‑handle markers associated with the activity. No further personal details such as real name, age, or organizational affiliation have been disclosed in open sources. The location attribution is based on the actor’s self‑described presence in the United States.

The only observed activity involves a medical group in the United States, specifically the St. Joseph Medical Group associated with Lutheran Health Network. The actor exploited an outdated file‑sharing application that had been inactive for an extended period, gaining access through an SQL injection vulnerability. The compromised data consisted of staff usernames, MD5‑hashed passwords, and email addresses from that application, which was used for non‑patient documents. No patient records or financial information were reported as part of the exposed dataset. The breach was disclosed publicly via Twitter by the actor, prompting external notification attempts.

The actor’s tactics, as described in the breach report, center on SQL injection as the initial access vector; no malware families, custom tools, or post‑exploitation frameworks were mentioned in the public account. No evidence links the actor to a state sponsor, criminal consortium, or any broader affiliation, and attribution remains limited to the individual handles. The disclosed operation represents the sole publicly reported campaign, wherein the actor released a dump of 98 credential sets and subsequently assisted in notification efforts via social media. The actor’s tweet linking to the dump drew attention from security researchers and led to external notification attempts. No subsequent activities or additional incidents have been attributed to @Compl3x1ty or @Shinji_Kagawa in the sources reviewed.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB