CSIDB logo
Threat actor

USDoD

Attribution profile

Type
Criminal
Location
United States of America
Known incidents
2 incidents
First seen
2022-12-10
Last seen
2023-12-01
Updated
2026-08-28 17:14
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

USDoD is a cybercriminal alias used by an actor operating from the United States of America. The actor’s activities have been described as financially motivated, with the primary goal of monetizing stolen data through underground marketplaces. Observed targeting has focused on United States‑based victims, including a government‑affiliated information sharing program and a private consumer data broker. No public attributions link the actor to espionage, disruptive campaigns, or state sponsorship.

In the December 2022 InfraGard intrusion, USDoD obtained access by submitting a fraudulent application that used the name, Social Security number, date of birth and contact details of a legitimate financial sector CEO. The actor elected to receive the one‑time authentication code via email rather than SMS, noting that reliance on the victim’s phone number would have hindered the scheme. After approval, the actor exploited an exposed API within the InfraGard portal and enlisted an associate to write a Python script that harvested member records. The resulting dataset contained names and contact information for over 80 000 members, although many fields such as Social Security number and date of birth were empty. USDoD indicated that the account could also be used to send direct messages posing as the CEO, and offered the database for sale at a price the actor considered deliberately high to facilitate negotiation. The transaction was to be guaranteed by Pompompurin, the administrator of the Breached forum, which also hosted the sales thread and provided escrow services. The FBI confirmed awareness of the false account but released no further details.

Reporting attributes a December 2023 breach of a Florida‑based consumer data broker to USDoD, in which attackers initially compromised the broker’s systems and exfiltrated billions of records containing Social Security numbers, names, addresses, phone numbers and email addresses. The stolen data, described as comprising hundreds of millions of unique Social Security numbers and email addresses, was subsequently sold and publicly released on underground forums. Following the disclosure, the broker acknowledged the involvement of a third‑party actor, cooperated with law enforcement, and implemented additional security controls. A class‑action lawsuit was filed, highlighting the potential for identity theft and fraud affecting individuals across multiple countries. The actor’s alias appeared in the breach‑related sales discussions, and the actor’s prior use of the Breached forum and its administrator Pompompurin was noted as a recurring element in both incidents.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB