CSIDB logo
Threat actor

boredbloke

Attribution profile

Type
Hacker
Location
United Kingdom
Known incidents
1 incident
Sources
1 source
First seen
2019-02-13
Last seen
2019-02-13
Updated
2026-07-31 04:11
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

boredbloke is an individual threat actor known by the alias boredbloke and is located in the United Kingdom. The actor came to public attention in February 2019 after compromising the Twitter account of the British Army’s 77th Brigade, a unit responsible for social media influence operations. The compromise was achieved by exploiting an unidentified security vulnerability in the account’s management, which allowed boredbloke to seize control, rename the handle, and post taunting messages before relinquishing access. The actor described the act as an attempt to highlight a gaping hole in the unit’s defenses and to draw attention to the lack of a clear vulnerability reporting channel within military organizations. boredbloke stated that the motivation was not financial gain or espionage but rather to expose a weakness that could be exploited by more malicious actors if left unaddressed.

The targeting observed in the incident was limited to a single United Kingdom military sector, specifically the Army’s information and outreach unit, indicating a focus on governmental social media presences rather than commercial or financial targets. The strategic objective expressed by boredbloke was to provoke a response that would improve vulnerability disclosure mechanisms and to demonstrate the potential consequences of unpatched security flaws. The tactics, techniques, and procedures described involve the discovery and exploitation of an unspecified vulnerability, the use of social media account takeover as the primary impact vector, and the employment of public messaging and account renaming to communicate the finding. No malware families, custom tooling, or advanced persistence mechanisms were referenced in the reporting.

Attribution to boredbloke remains that of an independent actor based in the United Kingdom, with no publicly established links to state sponsors, criminal consortia, or larger hacking groups. The only notable campaign publicly associated with the actor is the February 2019 takeover of the 77th Brigade Twitter account, which resulted in temporary operational disruption, public embarrassment for the Ministry of Defence, and subsequent locking of the account to limit visibility. This incident serves as the sole documented operation illustrating boredbloke’s approach of using a high‑profile social media breach to advocate for better security reporting practices.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 1 source.

CSIDB