CSIDB logo
Threat actor

David Do

Attribution profile

Type
Sensationalist
Location
United States of America
Known incidents
1 incident
First seen
2022-07-07
Last seen
2022-07-07
Updated
2026-07-30 19:57
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias David Do has been publicly linked to a social media account takeover targeting a major entertainment destination. Open‑source reporting indicates that the actor is based in the United States of America, although no further biographical details have been disclosed. No other aliases or affiliations have been attributed to this individual in publicly available sources. The actor’s online persona appears limited to the alias used during the Disneyland incident. No public attribution to any state sponsor or criminal consortium has been made regarding this actor.

On July 7, 2022, the actor gained unauthorized access to Disneyland Resort’s official Facebook and Instagram accounts, which together reach approximately 8.4 million followers. Once inside, the attacker posted a series of messages containing racial slurs and expletives, intending to cause offense and disrupt the park’s online presence. The resort’s security team promptly removed the offending content, reset the account credentials, and launched an internal investigation to determine how the breach occurred. Experts noted the incident highlighted non‑financial motives like reputational harm through high‑profile social media targeting. No technical details such as malware families, exploit tools, or initial access vectors were disclosed in the public reports.

The Disneyland takeover occurred shortly after a comparable compromise of the British Army’s social media accounts days earlier, underscoring broader vulnerabilities in organizational social media security. No further incidents have been publicly linked to David Do beyond the July 2022 Disneyland compromise. Because no technical details were released, the actor’s typical TTPs cannot be inferred. Consequently, any assessment of the actor’s typical targeting sectors or regions remains speculative and is therefore omitted. This profile is limited to the confirmed facts presented in the available sources.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB