Wealth Squad Chris
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Wealth Squad Chris is an alias that has appeared in open‑source reporting related to a cyber incident involving a healthcare organization’s Twitter account. The threat‑actor context supplied with this task notes that the actor’s location, if known, is Russia. No public sources cited in the available material link the alias to a specific state sponsor, criminal consortium, or financial motive.
The only publicly referenced article describing the actor’s activity is Becker’s Hospital Review piece published on November 16, 2021, with the source report ID 1cd3ce7b-c39e-4697-ad29-01c7cd5e688e and the title “Novant Health hospital Twitter hijacked, forcing it to shut down account.” The article outlines three specific details of the incident: the Twitter handle was changed to @cjjohnso17th, the display name was altered to read “Wealth Squad Chris,” and the account was subsequently shown as suspended on the platform. It also notes that on November 15, 2021, Novant Health confirmed to WWAY television that its account had been hacked and that the organization was working to resolve the issue.
Following the hijack, Twitter suspended the compromised account, and Novant Health responded by temporarily shutting down the handle while it pursued remediation to regain control and eliminate the impersonation. The hospital’s statement emphasized that it was addressing the breach and taking steps to restore legitimate access to the account. No mention of malicious software, exploit kits, or credential‑theft tools appears in the reporting, indicating that the activity was confined to unauthorized modification of the social‑media profile. The article provides a direct link to the suspended Twitter handle, allowing readers to view the account’s status at the time of publication.
Because this Twitter takeover is the sole publicly documented operation attributed to Wealth Squad Chris, it serves as the representative example of the actor’s observed tactics, which involve social‑media account hijacking rather than traditional network intrusion. The targeting of a U.S.‑based healthcare entity suggests a sector focus on health services, although the article does not specify whether the act was intended for financial gain, espionage, disruption, or merely notoriety. Attribution to a specific base rests solely on the location field provided in the threat‑actor context; no additional evidence ties the alias to a particular government agency or organized‑crime group. Consequently, the current profile of Wealth Squad Chris is limited to the alias, the presumed geographic origin, and the single confirmed incident of account takeover.
Incidents
Attributed incidents are available to members.
1 incident