CSIDB logo
Threat actor

Sahoo

Attribution profile

Type
Activist
Location
India
Known incidents
1 incident
First seen
2014-08-28
Last seen
2014-08-28
Updated
2026-08-28 16:16
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Sahoo, also referenced as SaHoo, is a threat actor whose public activity is limited to a single website defacement incident reported in August 2014. The actor has stated that he is based in India and operates independently, explicitly denying any affiliation with organized hacker groups, criminal consortia, or state sponsors. In his own correspondence with a security blog, Sahoo emphasized that his actions were not driven by a desire for fame, financial profit, or espionage, but rather by an intention to draw attention to perceived security shortcomings in the target organizations. He repeatedly asserted that he sought neither to cause broader disruption nor to exfiltrate sensitive information, framing his conduct as a modest effort to encourage administrators to improve their defenses.

The observed targeting pattern involves two prominent United States universities, Stanford University and the Massachusetts Institute of Technology, both of which were compromised on the same date. Sahoo reported that he uploaded a defacement page to specific server directories on each institution’s web infrastructure, citing paths such as ~mclindon/cgi-bin/ on Stanford and binlu.scripts.mit.edu/calendar/login.php on MIT. He noted that the affected sections of the sites did not appear to store any sensitive student data and that no server instability, data breaches, or service interruptions resulted from his actions. The actor provided mirrors of the altered content for verification and indicated that while the MIT sub‑domain was quickly restored, the Stanford defacement remained visible on the university’s servers at the time of reporting, demonstrating his ability to maintain persistent file placement on at least one target. Sahoo consistently described the operation as an isolated demonstration meant to highlight security weaknesses rather than as part of a larger, coordinated campaign.

No malware families, exploit kits, or advanced tooling have been associated with Sahoo’s methodology; the described technique is limited to the basic act of putting a defacement file onto a publicly reachable directory. He has not been linked to any subsequent operations, and no further public attributions or ties to broader threat landscapes have been established. Consequently, the available knowledge of Sahoo is confined to this singular defacement effort, which was motivated by a desire to prompt remedial action without seeking profit, notoriety, or any impact beyond the superficial alteration of web pages.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB