Shaltai Boltai
Attribution profile
- Type
- Activist
- Location
- Russia
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2014-08-14
- Last seen
- 2014-08-14
- Updated
- 2026-08-01 05:13
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Shaltai Boltai, also referred to as Humpty Dumpty, is a hacker group that has been identified as operating from Russia.
The group is publicly known for publishing leaks sourced from Russian officials.
It operates under the aliases Shaltai Boltai and Humpty Dumpty in open‑source reports.
On 14 August 2014 the group claimed responsibility for hijacking the Twitter account of Russian Prime Minister Dmitry Medvedev.
During the approximate thirty‑minute takeover they posted fabricated messages, including a false resignation announcement and a tweet stating “#Crimea is not ours, please retweet”.
The group also asserted that they had accessed Medvedev’s personal email and shared photographs they said were taken from his iPhone.
Russian government officials later confirmed the breach and denounced the unauthorized posts as false.
The hackers posted a series of images purportedly showing a government meeting, claiming the photos came from Medvedev’s personal device.
These images were accompanied by a Russian‑language caption indicating they had been obtained “by chance” from a compromised iPhone.
The tweets were subsequently deleted, but screenshots were captured by journalists and retweeted by users such as @yellena_p and @RT_com.
Shaltai Boltai’s described tactics involve claiming compromise of official email accounts and exfiltrating personal mobile device photos for public release.
The group distributes the obtained material primarily through social media platforms, notably Twitter, to amplify the leak.
No public reporting links the group to specific malware families, financial fraud tools, or conventional espionage toolkits.
While the group has gained notoriety for leaking information from Russian officials, no definitive attribution to a state sponsor or criminal consortium has been made in the available sources.
Their activity remains limited to the disclosed incidents of account takeover and subsequent information disclosure.
The profile is limited to the facts presented in the source material.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.