CSIDB logo
Threat actor

@DadSecurity

Attribution profile

Type
Sensationalist
Location
United Kingdom
Known incidents
1 incident
Sources
1 source
First seen
2015-08-19
Last seen
2015-08-19
Updated
2026-08-01 03:32
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias @DadSecurity operates from the United Kingdom.
The group first came to public attention in August 2015 when it claimed responsibility for a series of attacks on the parenting website Mumsnet.
They identify themselves solely through the Twitter handle @DadSecurity, which was later suspended.

The actor’s activity is limited to targeting online communities and individuals associated with those platforms.
In the 2015 incident they directed a distributed denial‑of‑service attack at Mumsnet, aiming to make the site temporarily unavailable.
They also conducted swatting attacks against the site’s founder, Justine Roberts, and a forum user who had interacted with the group.
The attacks resulted in the website being taken offline and armed police being dispatched to two private addresses.

The actor’s tactics include overwhelming a target’s servers with traffic to produce a DDoS outage.
They additionally employ false emergency reports to trigger armed police responses at victims’ residences, a technique known as swatting.
Communication of responsibility and threats was carried out via the now‑suspended Twitter account, where they posted messages such as “RIP Mumsnet” and shared an image of a SWAT team.
No specific malware families or custom tools are mentioned in the open sources describing their activity.

No public attribution links the group to a state sponsor, criminal syndicate, or any larger hacking collective.
The only verifiable detail about their background is the United Kingdom location supplied in the threat actor context.
All known information about @DadSecurity derives from the 2015 Mumsnet incident and the associated Twitter activity.

The Mumsnet DDoS and swatting episode of August 2015 stands as the sole publicly reported operation attributed to @DadSecurity.
During that event the group succeeded in temporarily taking the website offline and prompting armed police visits to two private addresses.
The incident illustrates how the actor combines volumetric network abuse with physical‑world intimidation tactics.
Beyond this episode no further campaigns or operations have been documented in open source reporting.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 1 source.

CSIDB