His Royal Gingerness
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
His Royal Gingerness, also known by the abbreviation HRG, is a threat actor whose known alias originates from a pseudonym used during a 2015 intrusion against Norwich International Airport’s website. The actor is located in the United Kingdom, as indicated by the source material referencing the airport’s UK setting and the actor’s self‑identification. On October 9 2015, HRG breached the airport’s standalone website, gaining access to a media‑center database that contained names and email addresses of individuals registered for media services. The intrusion was described by the actor as taking between two to three minutes, suggesting a relatively quick exploitation of a web‑facing vulnerability. HRG told the BBC that the purpose of the breach was to demonstrate the site’s vulnerability and to verify whether the claimed remediation efforts had been effective after a month. The airport’s general manager confirmed that no operational systems, commercial data, or physically sensitive information were compromised, and that the breach did not meet reporting thresholds under the Data Protection Act.
The incident shows that HRG’s targeting has been limited to a single UK‑based aviation sector website, with no evidence of broader geographic or sectoral patterns in the publicly available record. The stated strategic objective was to highlight security weaknesses rather than to pursue financial gain, espionage, or disruptive outcomes, as the actor explicitly framed the act as a vulnerability test. No specific malware families, exploit kits, or tooling styles were referenced in the reporting; the description focuses on unauthorized access to a web application and extraction of database contents. Attribution to any state sponsor, criminal consortium, or larger hacking group has not been established in the sources, and HRG remains unaffiliated in public disclosures. The Norwich International Airport breach stands as the sole publicly reported operation associated with this actor, serving as a representative example of their activity to date.
Incidents
Attributed incidents are available to members.
1 incident