Ameer Elashmawy
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Ameer Elashmawy, also known by the alias Ameer Elashmawy, is an individual who was employed as an information systems security support coordinator at Trillium Health in Rochester, New York. He is a former employee whose actions came to light in early 2020 after unusual network activity was traced to his workstation. Investigators discovered that he had exploited his administrative privileges to access the personal accounts and devices of more than sixty‑five coworkers. The compromised data included hundreds of explicit photographs and videos, social media credentials, driver’s license images, credit‑card details, and Social Security cards. No patient information was accessed according to statements from Trillium Health officials. The organization incurred over one hundred thousand dollars in cybersecurity remediation costs and cooperated with law‑enforcement investigations. Elashmawy was subsequently charged with unauthorized access of a protected computer and identity theft, facing a potential penalty of up to five years in prison and a $250,000 fine if convicted.
The incident demonstrates a targeting pattern focused on the healthcare sector within the United States, specifically a regional health services provider in New York. Elashmawy’s tactics involved the abuse of legitimate administrative rights to log into employee workstations, the reuse of passwords voluntarily provided by a coworker for a legitimate software installation, and the subsequent misuse of those credentials to access personal social media accounts. He employed removable media such as USB thumb drives, external hard drives, and mobile phones to collect and store the exfiltrated data. No malware families or custom tooling are referenced in the available reporting, indicating that the operation relied primarily on privilege abuse and credential misuse rather than sophisticated malicious software.
Publicly available sources do not associate Elashmawy with any state sponsor, criminal consortium, or broader affiliations; he is portrayed as an individual acting alone. The Trillium Health breach of January 2020 represents the sole publicly reported operation attributed to him, notable for the scale of personal data collected from employees and the resulting financial and reputational impact on the organization. Law‑enforcement seizure of multiple storage devices confirmed the extent of the data he possessed, leading to the criminal charges outlined in the complaint. The case remains a documented example of an insider threat leveraging trusted access for personal data exfiltration without evidence of broader ideological or financial motivations.
Incidents
Attributed incidents are available to members.
1 incident