CSIDB logo
Threat actor

Crackas With Attitude

Attribution profile

Type
Activist
Location
United States of America
Known incidents
6 incidents
Sources
3 sources
First seen
2015-10-12
Last seen
2016-01-18
Updated
2026-08-01 05:38
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Crackas With Attitude (CWA) is the name used by a loosely affiliated hacking group that has publicly claimed responsibility for intrusions into U.S. government and law‑enforcement accounts; the group’s members have used the handles “Cracka” and have described themselves as consisting of at least two individuals, one of whom identified himself as an American high‑school student. The teen explicitly stated that he is not Muslim and that his motivation stems from opposition to U.S. foreign policy and support for Palestine, and the group has said its actions are directed “just the government” rather than innocent civilians, indicating a strategic objective of disrupting or exposing governmental entities rather than seeking financial gain. The actors have focused their activities on targets within the United States, specifically naming the CIA director, the Secretary of Homeland Security, and various federal law‑enforcement systems, which establishes a clear geographic and sectoral focus on U.S. intelligence, homeland security, and law‑enforcement domains.

The group’s targeting has included the personal AOL account of CIA Director John Brennan, the personal Comcast account of Homeland Security Secretary Jeh Johnson, and a law‑enforcement portal that provides access to the Joint Automated Booking System (JABS) and a suite of related tools such as the Enterprise File Transfer Service, Cyber Shield Alliance, DFS Test and eGuardian Training, IC3, IDEAFX, Intelink, Intelink IM, Justice Enterprise File Sharing, Special Interest Group, Virtual Command Center, National Data Exchange (N‑DEx), National Gang Intelligence Center, Repository for Individuals of Special Concern (RISC), RISSNET, ViCAP Web National Crime Database, Active Shooter Resources Page, Malware Investigator, and the Homeland Security Information Network (HSIN). Their stated objectives have been to obtain and expose governmental information, as evidenced by the leakage of Brennan’s personal documents and contact details, the posting of Johnson’s billing information, and the public release of JABS arrest records and law‑enforcement agent contact details on Guy Fawkes Day. No financial motive has been expressed in the sources; the actors have framed their activity as a political statement against U.S. policy.

The tactics, techniques and procedures described in the reporting rely heavily on social engineering rather than malware; the teen described tricking Verizon representatives into divulging Brennan’s personal information and deceiving AOL into resetting his password, and he similarly gained access to Johnson’s Comcast account through credential‑based means. The intrusion into the law‑enforcement portal was attributed to an unspecified vulnerability that granted access to JABS and the associated law‑enforcement tools, after which the actors browsed arrest records, extracted data, and exfiltrated it via public posts on Twitter and other platforms. No specific malware families, exploit kits, or custom tooling are mentioned in the source material, and the actors have explicitly stated they were not intending to harm innocent individuals, focusing instead on governmental targets. Notable operations cited include the compromise of Brennan’s AOL account and the subsequent disclosure of his security‑clearance application and Social Security numbers of intelligence officials, the breach of the JABS database and associated law‑enforcement services that yielded arrest records and contact information for officers, and the unauthorized access to Johnson’s Comcast account that yielded a billing screenshot and voicemail access. These incidents represent the publicly reported campaigns attributed to Crackas With Attitude.

Incidents

Attributed incidents are available to members.

6 incidents

Sources

Sources available to members: 3 sources.

CSIDB