CSIDB logo
Threat actor

Slashx

Attribution profile

Type
Hacker
Location
United States of America
Known incidents
1 incident
Sources
0 sources
First seen
2021-06-29
Last seen
2021-06-29
Updated
2026-08-28 17:48
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Slashx is a threat actor known by that alias and believed to be based in the United States of America. The actor came to public attention in June 2021 after compromising a virtual private network provider, exfiltrating roughly sixty‑nine thousand user records that included plaintext passwords, IP addresses, billing information and private keys capable of decrypting traffic. The stolen data was subsequently advertised for sale on a cybercrime forum, with samples showing transaction histories and subscriber names while omitting direct payment‑card details because the provider used third‑party processing. In addition to the data theft, Slashx claimed responsibility for taking the company’s website offline and displaying malware infection warnings, indicating an intent to disrupt the service as well as profit from the leaked information. Researchers verified the breach by examining leaked samples and communicating with the perpetrator, and the victim confirmed unauthorized access to its backup server, prompting credential resets and a full system audit.

The incident reveals that Slashx primarily targets technology‑focused infrastructure, specifically services that handle user privacy and network traffic. The actor’s demonstrated objectives appear to be financial gain through the sale of stolen data and disruption achieved via website defacement or malware deployment. Technical details disclosed in the reporting note that the initial intrusion involved unauthorized access to the backup server, though specific exploit methods, malware families or toolkits were not identified in the source material. No public attribution links Slashx to a state sponsor, criminal consortium or larger hacking group; the only established facts are the alias and the presumed U.S. location. The VPN provider breach stands as the most representative operation publicly associated with Slashx, illustrating a pattern of data exfiltration coupled with service disruption for monetary motive.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 0 sources.

CSIDB