DonJuji
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
DonJuji is an alias used by a threat actor whose known location is Russia. The actor has been linked to a security breach affecting the dating application MobiFriends, a Barcelona‑based service founded in 2005. This connection is the only publicly reported activity attributed to DonJuji in the available sources.
According to the hacker’s own statement, the compromise of MobiFriends occurred in January 2019, and the resulting dataset was posted online in April 2020. The exposed records total approximately 3.68 million users and contain email addresses, mobile numbers, dates of birth, gender information, usernames, and details of app activity. Passwords were included in the leak but were protected only with the weak MD5 hashing algorithm, making them susceptible to cracking. The leaked data did not comprise private messages, images, or sexual‑related material. Notably, the dataset also contained professional email addresses associated with major corporations such as American International Group, Experian, Walmart, Virgin Media and other F1000 entities. The validity of the data was confirmed by Risk Based Security through comparison with the official MobiFriends website.
After obtaining the data, DonJuji initially offered it for sale on a hacking forum before the material was subsequently distributed freely across numerous online forums. MobiFriends has not publicly acknowledged the incident and did not respond to inquiries from journalists or the security firm that verified the leak. In the aftermath, users were advised to change passwords on any other services where they might have reused the same credentials obtained from the MobiFriends breach. This summarizes the confirmed facts regarding the threat actor DonJuji based on the provided information.
Incidents
Attributed incidents are available to members.
1 incident