CSIDB logo
Threat actor

Austin Alcala

Attribution profile

Type
Criminal
Location
United States of America
Known incidents
4 incidents
Sources
1 source
First seen
2011-01-01
Last seen
2011-01-01
Updated
2026-07-31 23:01
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Austin Alcala, also known by his legal name, is an individual associated with the Xbox Underground hacking ring and was identified as one of four defendants charged in a federal indictment unsealed in April 2014. He resides in McCordsville, Indiana, United States of America, and was 18 years old at the time of the charges. The alleged activities of the group spanned from January 2011 to March 2014, during which they allegedly infiltrated the networks of several prominent technology companies and a U.S. military installation. The indictment describes the collective as a criminal consortium without any indicated state sponsorship or foreign government direction. Their operations resulted in the theft of unreleased software, source code, pre‑release video game titles, and military training applications, including Apache helicopter simulation tools.

The group’s targeting focused on the technology sector—specifically firms involved in gaming and software development such as Microsoft, Epic Games, Valve, and Zombie Studios—and on the defense sector through the United States Army. Their strategic objective, as documented in the prosecution’s filings, was the exfiltration of intellectual property whose estimated value ranged between one hundred million and two hundred million dollars. Reported tactics, techniques, and procedures relied primarily on SQL injection attacks and the use of compromised employee usernames and passwords, sometimes obtained via software development partners. No specific malware families or custom tooling are referenced in the available sources. Legal proceedings saw two of the four co‑defendants plead guilty to conspiracy to commit computer fraud and copyright infringement, while Alcala and the remaining co‑defendant faced the same charges; an additional Australian suspect linked to the conspiracy was also charged separately. The case highlighted the convergence of commercial and military networks as targets for financially motivated intellectual property theft.

Incidents

Attributed incidents are available to members.

4 incidents

Sources

Sources available to members: 1 source.

CSIDB