CSIDB logo
Threat actor

FocaLeaks

Attribution profile

Type
Activist
Location
Brazil
Known incidents
1 incident
First seen
2021-09-02
Last seen
2021-09-02
Updated
2026-07-30 20:17
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

FocaLeaks is a hacktivist group that operates under the alias FocaLeaks and is publicly associated with Brazil as its base of operations. The collective presents itself as a collaborative effort whose stated purpose is to pressure governments that display authoritarian tendencies. In its own communications the group emphasizes that its actions are intended to expose alleged abuses rather than to seek financial profit or conduct espionage. This self‑portrayal places FocaLeaks within the hacktivist milieu, where the primary lever is the release of information to provoke social or political change.

Observed activity links FocaLeaks to targeting law‑enforcement institutions, with the national police of El Salvador serving as the focal point of its known operation. The group’s strategic objective, as articulated in its claims, is to obtain and disclose sensitive records—including data on police agents, civilians and ongoing criminal investigations—in order to highlight what it describes as authoritarian practices while explicitly stating that it does not aim to disrupt or damage critical infrastructure. The reported method of intrusion involved exploiting a vulnerability in a police mobile application, which allowed the actors to access a platform referred to as “Imperium” that allegedly stores civil and criminal records; no mention of malware families, ransomware, or custom tooling appears in the source material. Consequently, the primary TTP attributed to FocaLeaks in open reporting is the exploitation of application‑level flaws to facilitate data exfiltration.

On September 2, 2021, FocaLeaks announced that it had breached El Salvador’s National Police by leveraging a flaw in the agency’s mobile app, asserting that it had extracted information on approximately 37,000 officers as well as civilian details and investigative files. The police acknowledged the incident publicly but did not verify the authenticity of the leaked data, and a transparency collective later disseminated redacted portions of the material through DDoSecrets. The group’s statements indicated that the accessed “Imperium” system contained comprehensive civil and criminal records, which it viewed as evidence of authoritarian governance. No public reporting ties FocaLeaks to a state sponsor, criminal syndicate, or any other formal affiliate network, leaving the group described solely as a loosely organized hacktivist collective. This El Salvador breach remains the principal, publicly documented campaign that defines the current understanding of FocaLeaks’ activity.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB