booloop
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
booloop is the alias used by an individual who claimed responsibility for releasing a large dataset containing personal information of U.S. military‑affiliated individuals. The actor is known to operate from the United States of America, as indicated in the available context. In August 2018 booloop posted a thread on a public forum asserting that they had obtained and were sharing the personal data of approximately 850,000 people with ties to the U.S. military. The post described the data as having been extracted from an Elasticsearch database and included full names, telephone numbers, and email addresses, with a notable subset of .mil addresses. booloop stated that the dataset was received from an anonymous source earlier that year and that they did not know the origin or ownership of the database.
The disclosed information reportedly originated from a recruitment platform associated with recruitmilitary.com, which at the time claimed over 1.3 million job seekers. According to booloop’s forum post, the leaked file was a compressed archive hosted on mega.co.nz that expanded to 277 MB and contained raw JSON output for 850,934 records from an index named “core_users_1447139122296”. Analysis of the data by the poster revealed 35,489 .mil email addresses, 218,437 Gmail addresses, and test accounts linked to mutantshark.com and recruitmilitary.com, with the latter showing multiple role types and a recent update date of June 2017. The actor did not describe any malware, specific intrusion techniques, or tooling used to obtain the data, nor did they attribute the breach to any state sponsor, criminal group, or financial motive. The incident remains the sole publicly documented activity associated with the booloop alias in the provided sources.
Incidents
Attributed incidents are available to members.
1 incident