CSIDB logo
Threat actor

Ryan S. Hernandez

Attribution profile

Type
Sensationalist
Location
United States of America
Known incidents
1 incident
Sources
1 source
First seen
2016-01-01
Last seen
2016-01-01
Updated
2026-08-01 03:34
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Ryan S. Hernandez, also known by the aliases Ryan West and RyanRocks, is a United States‑based threat actor who resided in Palmdale, California. He began his illicit activities as a minor, collaborating with an unnamed associate in 2016 to obtain Nintendo employee credentials through a phishing scheme. Using those stolen credentials, he accessed Nintendo’s internal networks and downloaded confidential files related to games, developer tools, and console hardware, including pre‑release details about the Nintendo Switch. Hernandez continued to intrude on Nintendo servers from June 2018 to June 2019 despite prior FBI warnings, and he disseminated the stolen data publicly via Twitter, Discord, and a self‑created forum called “Ryan’s Underground Hangout.”

His targeting was confined to the gaming and technology sector, specifically the Japanese multinational Nintendo, with the apparent objective of acquiring and disclosing proprietary information as described in the reporting. The initial access vector consistently relied on phishing to harvest employee credentials, which were then reused for persistent access to Nintendo systems. Hernandez employed no publicly cited malware families; instead, his tooling style included the use of circumvention devices for pirated video games and software, as well as the exploitation of social media platforms and a dedicated chat forum for the distribution and discussion of stolen data. Forensic examination of his seized devices also revealed a large collection of child sexual abuse material stored in a folder labeled “Bad Stuff,” though this aspect is separate from the computer intrusion activity.

Law enforcement attribution placed Hernandez as the sole responsible individual, with no publicly identified state sponsorship or affiliation with a criminal consortium. The Nintendo intrusion campaign stands as his most notable operation, culminating in his January 2020 guilty plea to computer fraud and abuse and possession of child pornography. He was sentenced to three years of imprisonment followed by seven years of supervised release, ordered to pay $259,323 in restitution to Nintendo, and required to register as a sex offender. No further connections to broader threat actor groups or nation‑state actors have been established in the available sources.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 1 source.

CSIDB