DeleteSec
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
DeleteSec is a threat actor known by that alias and has been associated with activity traced to China. The group first came to public attention in early 2014 when it claimed responsibility for a series of data breaches that were announced on its Twitter account and accompanied by the public release of stolen information. Its operations have been characterized by the exploitation of web application vulnerabilities to obtain databases containing personal and organizational data, which were then disseminated through file‑sharing services and social media platforms. No public statements have linked DeleteSec to a specific state sponsor or criminal consortium, and the only geographic detail available is the possible China‑based location noted in some reporting.
The actor’s observed targeting spans several distinct sectors, including industrial manufacturing, United Nations‑affiliated policy forums, and national literacy or education initiatives. In each case the initial access vector was a SQL injection or MySQLi flaw in the victim’s website, allowing the attackers to query and extract database contents. After gaining access, DeleteSec typically exfiltrated tables containing names, email addresses, physical addresses and, in some instances, plaintext passwords, which were then packaged into multiple files and uploaded to services such as MediaFire. The group announced the compromises via its Twitter handle, often noting that the underlying vulnerability remained exploitable at the time of disclosure, and it relied on clear‑text credential dumps to demonstrate the impact of the breach.
Representative campaigns include the February 2014 intrusion into SPIROL International, where a SQL injection in the news section yielded approximately 70,000 customer email addresses, 886 password‑containing records, 31,123 company names, 26,856 associated email addresses and 96 sets of clear‑text credentials. A second operation targeted the United Nations Internet Governance Forum, resulting in the leak of over 3,200 user accounts with real names, usernames, email addresses and encrypted passwords from government‑linked participants across 537 email providers. The third notable incident involved the national literacy site Reading Rockets, where a MySQL injection led to the exposure of more than 5,800 user records containing full names, addresses, email contacts and plaintext passwords, distributed in five parts on MediaFire. These incidents illustrate the actor’s repeated use of injection‑based access, public data dumps and social‑media announcements as core elements of its methodology.
Incidents
Attributed incidents are available to members.
3 incidents