Tsar Team
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Tsar Team, also known as Tsar Team Hackers, is a cybercriminal group that has been linked to a data breach targeting a Lithuanian plastic surgery clinic in‑a private medical facility in 2017. The actors are publicly associated with the aliases Tsar Team and Tsar Team Hackers, and open‑source reporting notes that their operational base is believed to be in Russia. No further details about their size, internal structure, or broader criminal network are provided in the available sources.
The group’s observed activity focuses on the healthcare sector, specifically a clinic that stores sensitive patient information and personal photographs, and their actions are confined to the Lithuanian region. Their strategic objective, as evidenced by the incident, is financial gain: they attempted to extort the clinic for a bitcoin ransom, offered to delete the stolen data in exchange for payment, and later marketed the entire dataset on a dark web marketplace at set prices per record or as a bulk package. The tactics described involve gaining unauthorized access to the clinic’s data system, exfiltrating names, addresses, medical records and nude photos, then publicly releasing verified information to pressure the victim, while simultaneously sending untraceable text messages to individual celebrities to demand personal payments. No specific malware families, exploit tools, or initial access vectors are mentioned in the reporting.
Attribution to a state sponsor or a larger criminal consortium is not established in the public record; the only attribution detail is the presumed Russian location of the actors. The most notable operation attributed to Tsar Team remains the 2017 breach of the Lithuanian plastic surgery clinic, during which they stole data from approximately 25,000 patients, attempted ransom negotiations, sold the information on the dark web, and conducted targeted blackmail of high‑profile individuals. This case represents the entirety of the publicly documented activity for the group as reflected in the supplied sources.
Incidents
Attributed incidents are available to members.
1 incident