Hector Navarro
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Hector Navarro, also known by the alias Hector Navarro, is a former human resources systems administrator who operated in the United States. He worked for Century 21’s Manhattan department store, where he managed HR systems and timekeeping applications. Navarro resided in Brooklyn, New York, after his employment ended. His role granted him privileged access to employee data and network administration functions.
Navarro’s activities were directed at the retail sector, specifically targeting the internal HR infrastructure of a U.S. based company. The geographic focus of his actions was limited to the New York City area, encompassing both Manhattan where he worked and Brooklyn where he launched post‑employment access. His strategic objectives included financial gain, as evidenced by the attempted alteration of holiday payroll policies that could have produced over fifty thousand dollars in erroneous payments. Additionally, his actions aimed to cause operational disruption by deleting accounts and access information for consultants hired to replace him.
The initial access vector relied on Navarro’s legitimate credentials as a systems administrator, which he used before resignation to create an unauthorized superuser account on the company network. After leaving the organization, he persisted by logging into that superuser account from his personal residence in Brooklyn. Using this privileged account, he tampered with existing user accounts, removed data related to the replacement consultants, and modified payroll configuration files to trigger erroneous holiday payments. No custom malware or external tooling was reported; the threat actor employed native administrative functions and built‑in system utilities to carry out the modifications.
Attribution to Navarro is based solely on the criminal indictment filed by the Manhattan District Attorney’s Office, with no public linkage to a state sponsor, criminal consortium, or larger hacking group. The Century 21 incident represents the only publicly reported operation associated with him, serving as a representative example of insider‑threat driven sabotage and fraud. Consequently, the profile is confined to this single case, reflecting the verified facts presented in the source material.
Incidents
Attributed incidents are available to members.
1 incident