Locata
Attribution profile
- Type
- Criminal
- Location
- Russia
- Known incidents
- 1 incident
- Sources
- 0 sources
- First seen
- 2024-07-01
- Last seen
- 2024-07-01
- Updated
- 2026-08-01 20:44
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is known by the aliases Locata and Kilanas and has been associated with operations originating from Russia, according to publicly available location information. Observed activity indicates a focus on entities that provide software services to public sector organizations, particularly those managing housing and local government functions. The actor’s targeting has been observed in the United Kingdom, where a compromise of a housing software provider affected multiple councils in the Greater Manchester area.
In the incident reported on 2024‑07‑01, the actor gained access to the internal systems of the housing software provider Locata, which led to the compromise of public‑facing websites used by several councils. This breach resulted in the exposure of limited personal data belonging to residents and facilitated a follow‑on phishing campaign in which recipients received fraudulent emails urging them to activate tenancy options and disclose sensitive information. Affected councils confirmed that the malicious activity spread through Locata’s infrastructure and advised individuals to monitor financial accounts, change passwords, and report any losses to authorities. The software provider acknowledged the attack, engaged third‑party experts for investigation, and cooperated with local law enforcement to mitigate the impact.
Publicly available sources do not establish a clear state sponsorship or criminal consortium affiliation for this actor beyond the geographic association with Russia. No additional details about alliances, sponsorships, or broader campaign networks have been reported in the referenced material. Consequently, any assertions about political motivations, financial gain, or espionage objectives would be speculative and are omitted here.
The only tactics, techniques, and procedures explicitly described in the available reporting involve the compromise of a third‑party software provider’s environment, the subsequent alteration of hosted web services, the exfiltration of limited personal data, and the use of that data to craft targeted phishing emails. No specific malware families, exploit kits, or toolsets are mentioned in the sources, so further technical detail cannot be provided without speculation. The profile therefore remains confined to the confirmed facts of the actor’s aliases, location, observed targeting, and the documented incident involving the housing software provider.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 0 sources.