CSIDB logo
Threat actor

TarTarX

Attribution profile

Type
Criminal
Location
China
Known incidents
1 incident
First seen
2022-07-19
Last seen
2022-07-19
Updated
2026-07-31 05:56
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

TarTarX, also referred to as the TarTarX Group, is a threat actor that has been publicly linked to a data breach affecting the virtual pet website Neopets in July 2022. Open‑source reporting indicates the actor operates from China, although no further geographic details have been disclosed. The alias appears in underground forums and was used by the individual who offered the stolen Neopets source code and member database for sale. According to a BleepingComputer interview, TarTarX claimed to have exfiltrated approximately 460 MB of compressed source code and a database containing personal information for over 69 million Neopets members.

The compromised data included usernames, names, email addresses, birth dates, gender, country, zip code and other registration‑related fields. TarTarX stated that the data was not ransomed to Neopets’ owner Jumpstart but was advertised for four bitcoins, valued at roughly $94 000 at the time of the offer. Verification of the breach was provided by a forum administrator who registered a new Neopets account and received the corresponding record from the actor, confirming continued access to the site while the data was being sold. The actor declined to disclose the exact method of intrusion but told reporters that the exploit used was a general website vulnerability unrelated to the Neopets codebase. This description aligns with independent observations from a longtime Neopets database reader who noted that the breach did not stem from any known flaw in the site’s own source code.

No malware families, custom tools, or specific exploit kits were mentioned in the reporting, indicating that the actor relied on a readily available web‑application flaw rather than bespoke malware. The incident represents the only publicly documented operation attributed to TarTarX, and no additional campaigns or victim sectors have been identified in open sources. Attribution to a state sponsor, criminal consortium, or any broader affiliation has not been established; the actor remains classified as an independent entity based solely on the Neopets case. Consequently, the known profile of TarTarX is limited to the alias, the alleged Chinese location, the theft and attempted sale of Neopets source code and member data, and the use of a general web exploit to gain and maintain access.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB