CSIDB logo
Threat actor

NSHC

Attribution profile

Type
Activist
Location
Russia
Known incidents
1 incident
Sources
1 source
First seen
2016-03-16
Last seen
2016-03-16
Updated
2026-07-31 22:03
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

NSHC is a threat actor known by that alias and has been associated with operations originating from Russia, according to the available reporting. The group first came to public attention in March 2016 when it claimed responsibility for a breach of the Swiss People’s Party (SVP), asserting that it had accessed the party’s database and exfiltrated the names and email addresses of more than 50,000 supporters. In the same timeframe NSHC also claimed to have conducted distributed denial‑of‑service attacks against several Swiss online retailers and the Swiss Federal Railways website, temporarily disrupting access to those services. The actors stated that their actions were intended to highlight what they perceived as inadequate cyber‑defenses in Switzerland, framing the activity as a means to raise awareness about the country’s lack of protection against cyber attacks. No explicit financial gain, espionage goal, or other motive was articulated in the sources; the stated objective remains the promotion of awareness regarding perceived security shortcomings.

Regarding tactics, the only techniques explicitly described in the reporting are the unauthorized acquisition of a political party’s database and the execution of DDoS attacks against commercial and transportation‑related online services. No specific malware families, initial access vectors, or tooling styles are mentioned in the provided material, so those details cannot be included. Attribution to a particular state sponsor or criminal consortium is not established in the open sources; the only geographic clue is the possible Russian origin noted in the context. The most notable publicly reported operation linked to NSHC is the March 2016 SVP incident, which involved the claimed theft of supporter data and was accompanied by the DDoS campaigns on Swiss e‑commerce sites and the national railway’s web presence. A separate, unrelated compromise of at least 6,000 Swiss email account passwords was reported by MELANI around the same period, but authorities explicitly stated there was no connection between that credential leak and the NSHC‑claimed activities. These events constitute the entirety of the verified information available for a factual profile of the actor.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 1 source.

CSIDB