Cyber Threat Actor: Jamescarter
| Actor Type | Location | Known Incidents |
Criminal
|
Russia
|
1 incident |
|---|
Profile
The threat actor known by the alias Jamescarter operates from Russia according to the available reporting. This actor uses a .ru contact email address when advertising illicit data on underground markets. Jamescarter came to public attention in July 2020 after offering a database of 4.8 million email addresses and usernames for sale. The advertised data was linked to a prominent United Kingdom ticketing provider that serves customers across multiple countries. Although the seller falsely claimed the records originated from a shopping and forex trading platform, analysts confirmed the true source was the ticketing service. The actor priced the dataset at twenty‑five hundred dollars, indicating a financially motivated intent to monetize stolen personal information. Victims of the breach are primarily located in the United Kingdom, United States, New Zealand, Australia, South Africa, Germany and France. The exposed credentials increase the risk of follow‑on phishing and credential‑stuffing attacks against the affected users. A sample of ten thousand records provided by the seller showed only three percent duplicates, suggesting a high volume of unique accounts. The data set also contained addresses from government domains, raising the potential impact on high‑value targets.
The ticketing provider involved had previously experienced website defacement and appeared on a Pastebin list of sites noted as vulnerable to SQL injection, though no direct link to the breach has been established. Jamescarter’s activity represents a discrete campaign centered on the exfiltration and resale of user credential data rather than a broader espionage or disruption operation. No public attribution ties the actor to a state‑sponsored program or a known criminal consortium; the only confirmed detail is the Russian location associated with the contact email. The July 2020 sale of the United Kingdom ticketing database remains the most clearly documented operation linked to the Jamescarter alias in open sources. This case illustrates how individual actors can monetize large‑scale credential harvested from online services through dark‑web marketplaces.
