CSIDB logo
Threat actor

Kristian Boykov

Attribution profile

Type
Activist
Location
Bulgaria
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-31 01:37
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor identified by the alias Kristian Boykov has been associated with a data breach affecting Bulgarian government bodies. Open‑source reporting indicates that the actor obtained information from the National Revenue Agency of Bulgaria. The compromised material consisted of roughly 110 databases with a combined size of close to 21 gigabytes. The actor transferred 57 of those databases, amounting to about 11 gigabytes, to several local news outlets. He stated that the remaining data would be disclosed in the coming days. Beyond the revenue agency files, the leaked sets contained data from the Bulgarian Excise Centralized Information System, which stores excise‑tax details for imported goods. Additional material was noted by media as potentially belonging to the National Health Insurance Fund and the Bulgarian Employment Agency, though the exact nature of those records was not elaborated. Communication with journalists was conducted via a Yandex.ru email address, and the message included a paraphrased quote from Julian Assange reading “Your government is stupid. Your cybersecurity is a parody.” The actor also claimed to have maintained persistent access to the National Revenue Agency’s network for more than eleven years.

The National Revenue Agency announced that it was collaborating with the Ministry of the Interior and the State Agency for National Security to investigate the incident. Shortly after the story appeared, the Bulgarian Ministry of the Interior confirmed that a hack had occurred. In response to the leak, opposition parties in Bulgaria publicly demanded the resignation of the Finance Minister. During a television interview, the actor described himself as a Russian man married to a Bulgarian woman, but the report advised that these statements should not be taken at face value. A separate event involved the temporary detention of a Bulgarian IT expert who had posted instructions for exploiting a vulnerability in a state‑run kindergarten portal to collect personal identification numbers; authorities noted that this case appeared unrelated to the revenue agency breach. No public source has definitively linked the actor to a state sponsor, criminal organization or any particular ideological motive. Consequently, the actor’s broader affiliations, technical toolkit or specific objectives remain unspecified in the available reporting.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB