CSIDB logo
Threat actor

Eugene Belford

Attribution profile

Type
Activist
Location
Russia
Known incidents
1 incident
First seen
2014-02-23
Last seen
2014-02-23
Updated
2026-08-01 00:37
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Eugene Belford is the alias used by a threat actor whose known location, if any, is Russia. The actor first came to public attention on 2014-02-23 when they defaced the website of EC‑Council, an international information‑security certification and training organization. During the defacement the actor posted a photograph of Edward Snowden’s passport, a 2010 email correspondence involving Snowden, and claimed to have obtained thousands of passport records belonging to law‑enforcement and military personnel. The actor also criticized the target’s password‑reuse practices and referenced historical grievances alleging plagiarism in EC‑Council’s training materials. No further personal identifiers or organizational ties for the actor have been disclosed in the available sources.

The actor’s targeting appears focused on entities involved in cybersecurity certification and education, as demonstrated by the EC‑Council incident. The strategic objectives evident from the defacement include drawing attention to perceived security weaknesses, exposing personal data, and publicizing accusations of content plagiarism. The actor’s reported tactics, techniques, and procedures involve DNS hijacking and gaining unauthorized access to Google Apps through a domain‑verification‑account reset; no specific malware families or custom tooling are mentioned in the reporting. These actions resulted in website alteration and the disclosure of sensitive personal information, indicating a combination of disruption and data‑exposure motives.

Attribution to a state sponsor or criminal consortium is not established in the public record; the only geographic clue is the actor’s possible association with Russia. The EC‑Council defacement remains the sole publicly reported operation linked to the alias Eugene Belford, and it serves as the primary example of the actor’s activity. No additional campaigns, malware usage, or financial motives are described in the source material, so the profile is limited to the facts presented above.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB