CSIDB logo
Threat actor

pwncoder

Attribution profile

Type
Criminal
Location
United States of America
Known incidents
1 incident
First seen
2023-10-01
Last seen
2023-10-01
Updated
2026-07-31 07:43
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

pwncoder is a threat actor referenced by that alias in open‑source reporting. The actor’s true identity has not been disclosed in any of the available sources. The only geographic detail provided is that the actor is associated with the United States of America. No additional aliases or alternative handles have been reported for pwncoder. The actor’s organizational affiliations, if any, remain unknown based on the current material.

In early October 2023, an anonymous source told BleepingComputer that the stolen voter records from the District of Columbia Board of Elections were first posted for sale on the hacking forums BreachForums and Sinister.ly by a user using the pwncoder handle. The posts, which have since been removed from those forums, advertised a dataset that originated from a compromised MSSQL database. According to the source, the data dump contained records for more than six hundred thousand District of Columbia voters. The information included both publicly accessible voter details and confidential fields such as partial Social Security numbers and driver’s license numbers. The same voter data was later offered for sale on the dark web leak site operated by the RansomedVC group. The timing indicates that pwncoder’s forum activity preceded the RansomedVC promotion of the material. No technical details about the intrusion vector, malware, or tools employed by pwncoder have been disclosed in the reporting. The actor’s role appears limited to the initial distribution of the stolen data on the mentioned forums. No further posts or activity linked to the pwncoder alias have been identified in the sources examined.

Beyond the forum posts related to the DCBOE incident, no other campaigns or operations have been publicly attributed to pwncoder. The actor has not been linked to any state‑sponsored group, criminal consortium, or specific malware family in the available information. Consequently, statements about the actor’s typical targets, strategic objectives, or preferred tactics cannot be substantiated by the evidence presented. The profile therefore reflects only the confirmed facts concerning the alias, location, and the single observed activity involving the MSSQL‑derived voter data dump. No additional information about pwncoder’s motivations, capabilities, or infrastructure is available from the material reviewed. This concludes the factual summary based solely on the provided sources.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB