zerodark70
Attribution profile
- Type
- Criminal
- Location
- Turkey
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2017-02-08
- Last seen
- 2017-02-08
- Updated
- 2026-07-31 06:08
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
zerodark70 is the alias used by a hacker who gained public attention in February 2017 after compromising the United Press International news website and offering the stolen data for sale on the AlphaBay dark web marketplace. The actor is associated with Turkey based on the location information provided in the threat actor context. The breach resulted in the exfiltration of approximately eighty‑three thousand user accounts, which included email addresses, real names and passwords that were protected with the outdated MD5 hashing algorithm; the seller had already cracked some of these passwords before listing the database. The compromised information belonged to subscribers, employees and journalists of UPI, a U.S. based news agency whose staff regularly interacts with senior officials in the defense and energy sectors, making the data attractive to buyers seeking credential material. The actor’s primary motivation, as evidenced by the public sale of the dataset for one hundred United States dollars in Bitcoin, was financial gain rather than espionage or disruption. No additional details about the intrusion method, malware families or specific tools employed by zerodark70 were disclosed in the available reporting, so any description of initial access vectors or tooling style would be speculative and is therefore omitted.
The only publicly documented operation linked to zerodark70 remains the UPI incident, which represents a discrete credential‑theft campaign rather than a prolonged series of attacks. The actor did not claim affiliation with any state‑sponsored group or criminal consortium, and no attribution to a particular nation‑state or organized cybercrime network has been established in open sources. Consequently, the profile of zerodark70 is limited to the confirmed facts: a Turkey‑linked individual using the zerodark70 handle who financially motivated the theft and sale of eighty‑three thousand UPI account credentials via a darknet marketplace, leveraging weak MD5 password hashes as part of the disclosed data set. This summary adheres strictly to the information supplied and avoids any unsupported inference.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.