CSIDB logo
Threat actor

ProbablyOnion

Attribution profile

Type
Sensationalist
Location
China
Known incidents
1 incident
First seen
2014-04-02
Last seen
2014-04-02
Updated
2026-08-01 19:31
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

ProbablyOnion is the alias used to refer to a threat actor whose known location, based on available reporting, is China. The actor first came to public attention through a specific incident involving a job‑seeker website, and no other aliases or geographic details have been disclosed in open sources. The name ProbablyOnion appears consistently in the documentation of that event, establishing it as the primary identifier for the actor in the referenced material.

On April 2 2014, ProbablyOnion gained unauthorized access to the website bigmoneyjobs.com by exploiting a SQL injection vulnerability. The exploitation allowed the actor to interact with the site’s backend database without needing legitimate credentials. This technique served as the initial access vector for the operation, enabling the actor to query and extract stored information directly from the database. The attack was carried out remotely, and no additional malware or tooling was described in the public report concerning this compromise.

The compromised database contained more than thirty‑six thousand user accounts, which the actor subsequently dumped and posted online. The exposed data included typical account information such as usernames, email addresses, and likely associated passwords or password hashes, although the exact fields were not detailed in the source. By releasing the dump, the actor made the personal information of those users publicly accessible, increasing the risk of credential reuse and related abuse. The incident was noted for its scale relative to the size of the website at the time.

The details of this activity were documented in a RiskBasedSecurity article published on the same date as the breach, with a source report identifier of 636aadc3-72fe-477c-8f87-e82222f796e7. The article described the SQL injection that led to the leak and provided the timeline and impact figures cited above. No further campaigns, malware families, or tooling have been publicly linked to ProbablyOnion in the sources examined. Consequently, the actor’s broader targeting patterns, strategic objectives, or affiliations remain unspecified in the available open‑source reporting.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB