fibonacci
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
fibonacci is an alias used by a threat actor whose location has been identified as Russia in open‑source reporting. The actor first came to public attention through a claim of responsibility for a data leak involving the Italian military‑focused platform Italia Militare. No other aliases or affiliations have been disclosed in the available sources.
On May 30 2023 fibonacci posted a message on a Telegram channel and an accompanying underground forum thread that advertised a 655 MB SQL file containing approximately 364 000 user records from italiamilitare.it. The post also referenced a 41 MB Data Definition Language (DDL) file that outlined the database schema and included sample entries for each table. The actor explicitly stated that the data was being made freely downloadable and provided links to both files.
The leaked dataset comprised sensitive user information from the Italia Militare portal, and the actor notified the platform’s administrators of the breach via direct message. At the time of reporting the organization had not issued an official statement or confirmation regarding the incident. The RedHotCyber article that documented the event noted that the actor’s post was cross‑promoted between the Telegram channel and the underground forum to maximize visibility.
Italia Militare is described as an Italian online community centered on military topics, and the exposed data therefore pertained to users of that specific niche platform. The actor’s activity was limited to the distribution of the stolen database; no malware, exploit tools, or initial‑access vectors were mentioned in the reporting. No additional campaigns or attributed operations beyond this single incident have been publicly linked to fibonacci.
Based solely on the disclosed information, the actor’s known behavior consists of acquiring and disseminating a large user database from a military‑oriented website, using the alias fibonacci, operating from a Russian location, and sharing the stolen data through Telegram and underground forums. No further details about motives, affiliations, or broader activity are available from the provided sources.
Incidents
Attributed incidents are available to members.
1 incident