CSIDB logo
Threat actor

g0retrance

Attribution profile

Type
Activist
Location
-
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-13 12:00
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the aliases g0retrance and netsaosa came to public attention after compromising the website of the Massachusetts Interscholastic Athletic Association (MIAA). The intrusion occurred in early November 2021 when the actor gained unauthorized access to the MIAA web server. After gaining access, the actor defaced the site by displaying the word “pwned” prominently on the page. A pop‑up window redirected visitors to a Twitter account associated with the g0retrance handle. Beneath the defacement message the actor left a note stating, “should have listened to my emails instead of ignoring me … don’t worry, this is harmless. just to get ur attention :)”. The accompanying article reported that the actor said they hoped to help expose security flaws and merely wanted to draw attention to the issue. The MIAA is a statewide organization governing high school athletics in Massachusetts, United States, indicating the actor’s activity was focused on a U.S.–based sports entity. No financial gain or espionage motive was expressed in the actor’s own words; the stated aim was to highlight a perceived security shortcoming. The incident caused a temporary disruption to the release of the MIAA’s official tournament brackets. The actor’s communication framed the act as harmless and intended as a wake‑up call rather than a destructive attack.

Technical details about how the actor initially accessed the MIAA server were not disclosed in the reporting, so no specific initial‑access vector can be confirmed. The observed tactics consisted of website defacement, a redirect pop‑up, and the posting of a taunting message, without any mention of malware deployment or exploit kits. Consequently, no particular malware families, tooling suites, or post‑exploitation frameworks can be attributed to this actor based on the available source. Public attribution to a state sponsor, criminal syndicate, or hacker collective has not been established; the actor operates under the pseudonyms g0retrance and netsaosa with no known affiliations. The MIAA defacement remains the sole publicly documented operation linked to these aliases, serving as the representative example of their activity. Because no further campaigns or tools have been reported, the profile is limited to the facts presented in the single incident. The actor’s self‑described goal of exposing security flaws and attracting attention defines the observed motivation within the scope of the available evidence. No additional information regarding geographic focus beyond the Massachusetts target, financial objectives, or advanced capabilities is present in the source material. Consequently, any description of the actor must remain confined to the confirmed details of the website compromise and the accompanying statements.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB