N.T.R.
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
N.T.R. is an alias used by an Indian IT consultant who was born in Thiruvananthapuram, Kerala and at the time of the reported incident resided in Tokyo, Japan. The actor is known primarily for a single large‑scale data breach that targeted the Kerala government’s civil supplies department website in November 2016. According to his own statements, he repeatedly contacted the National Informatics Centre and the civil supplies office to warn them about security weaknesses in the site before taking any further action. After receiving no response, he decided to make the vulnerability public by extracting and publishing the data on Facebook. The breach exposed personal information of approximately 34 million residents, including names, addresses, birth dates, gender, monthly income, electoral card details, and consumer numbers for power and cooking gas connections.
The breach was first reported in a Gulf News article published on September 16, 2018, which quoted N.T.R. describing his actions and the ease with which he accessed the site. N.T.R. described the attack as straightforward, noting that the site had published the complete list of Public Distribution System beneficiary numbers, which he used to query the corresponding records. He reported sending over thirty million HTTP requests from a single IP address, a volume that most servers would normally block, yet the primitive security controls allowed the requests to succeed. He also said he was appalled that no security alert was triggered despite the high volume of requests from his IP address. Over the course of about one week he extracted roughly one hundred gigabytes of data without employing any specialized malware or advanced tooling. The actor did not use any known malware families, exploit kits, or custom frameworks; his method relied on simple enumeration and the lack of rate‑limiting or authentication checks on the target website. No public attribution links him to a state sponsor, criminal syndicate, or hacker collective, and he has not been associated with any other reported campaigns beyond the Kerala incident. The episode remains the most prominent activity publicly tied to the N.T.R. alias.
Incidents
Attributed incidents are available to members.
1 incident