CSIDB logo
Threat actor

@DotGovs

Attribution profile

Type
Activist
Location
-
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-13 03:24
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias @DotGov (also referenced as @DotGovs in some reports) emerged in early 2016 with a public claim of responsibility for leaking personal data of United States federal employees. The actor specifically targeted employees of the Federal Bureau of Investigation (FBI) and the Department of Homeland Security (DHS), publishing names, titles, email addresses and phone numbers of roughly nine thousand DHS staff and indicating possession of data for approximately twenty thousand FBI personnel. The leaked information was accompanied by a message expressing pro‑Palestinian sentiment that referenced the Gaza and West Bank situation, indicating an ideological motivation tied to the Israel‑Palestine conflict rather than financial gain or traditional espionage. Motherboard verified the leaked data by calling random numbers from the lists and confirming that the recipients matched the names and reached employee voicemails. No public statements attribute the actor to a state sponsor or a criminal consortium, and the only identifiable marker remains the Twitter handle used to claim the activity.

Initial access to the source data was obtained through social engineering of a Department of Justice (DOJ) help desk. The actor pretended to be a new employee who could not navigate the DOJ web portal, asked for a token code, and received one that allowed login to a DOJ employee’s work machine. From that workstation the actor downloaded approximately two hundred gigabytes of information from a DOJ‑hosted database of government workers. A DHS spokesperson publicly stated that there was no breach of sensitive or personally identifiable information, while acknowledging that the incident was under investigation. No custom malware or specific malware families are mentioned in the reporting; the operation relied on legitimate credentials and standard system access rather than malicious software. After exfiltrating the data, the actor used a compromised DOJ email account to contact the technology news outlet Motherboard, providing proof of the breach, and subsequently posted the leaked lists on the Twitter account @DotGov, deleting related tweets after the story gained attention.

The February 2016 leak of DHS employee data and the announced forthcoming release of FBI employee information constitute the actor’s most clearly documented campaign. The reporting notes that the leak occurred after other intrusions into the private email accounts of the CIA director and the US Director of National Intelligence, though no direct link is established between those events and @DotGov. Attribution remains uncertain, with no public evidence tying the actor to a nation‑state, organized crime group, or hacktivist collective beyond the expressed pro‑Palestinian message. The activity illustrates a pattern of using social engineering to gain privileged access, exfiltrating large volumes of personnel data, and leveraging social media platforms to publicize the material as a form of ideological protest.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB