@DadSecurity
Attribution profile
- Type
- Sensationalist
- Location
- United Kingdom
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2015-08-19
- Last seen
- 2015-08-19
- Updated
- 2026-08-01 03:32
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the alias @DadSecurity operates from the United Kingdom.
The group first came to public attention in August 2015 when it claimed responsibility for a series of attacks on the parenting website Mumsnet.
They identify themselves solely through the Twitter handle @DadSecurity, which was later suspended.
The actor’s activity is limited to targeting online communities and individuals associated with those platforms.
In the 2015 incident they directed a distributed denial‑of‑service attack at Mumsnet, aiming to make the site temporarily unavailable.
They also conducted swatting attacks against the site’s founder, Justine Roberts, and a forum user who had interacted with the group.
The attacks resulted in the website being taken offline and armed police being dispatched to two private addresses.
The actor’s tactics include overwhelming a target’s servers with traffic to produce a DDoS outage.
They additionally employ false emergency reports to trigger armed police responses at victims’ residences, a technique known as swatting.
Communication of responsibility and threats was carried out via the now‑suspended Twitter account, where they posted messages such as “RIP Mumsnet” and shared an image of a SWAT team.
No specific malware families or custom tools are mentioned in the open sources describing their activity.
No public attribution links the group to a state sponsor, criminal syndicate, or any larger hacking collective.
The only verifiable detail about their background is the United Kingdom location supplied in the threat actor context.
All known information about @DadSecurity derives from the 2015 Mumsnet incident and the associated Twitter activity.
The Mumsnet DDoS and swatting episode of August 2015 stands as the sole publicly reported operation attributed to @DadSecurity.
During that event the group succeeded in temporarily taking the website offline and prompting armed police visits to two private addresses.
The incident illustrates how the actor combines volumetric network abuse with physical‑world intimidation tactics.
Beyond this episode no further campaigns or operations have been documented in open source reporting.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.