CSIDB logo
Threat actor

Graham Clark

Attribution profile

Type
Criminal
Location
United States of America
Known incidents
1 incident
First seen
2020-08-06
Last seen
2020-08-06
Updated
2026-07-31 06:35
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Graham Clark, also known as Graham Ivan Clark, is a threat actor based in the United States of America. He has been publicly linked to two distinct incidents: a disruptive intrusion into a virtual bond hearing conducted via Zoom in August 2020 and a large‑scale compromise of verified Twitter accounts in July 2020 that was used to promote a cryptocurrency scam. These events establish his presence in both the legal‑proceedings domain and the social‑media sphere, indicating a pattern of targeting high‑visibility online platforms located within the United States.

From the Zoom bombing, the actor’s strategic objective appears to be disruption, as unauthorized participants injected loud music, explicit video, and other audio content into a public court proceeding, forcing the judge to terminate the broadcast. The Twitter account takeover, meanwhile, was financially motivated; compromised accounts were used to solicit bitcoin transfers to a fraudulent address, resulting in over $100,000 in proceeds from hundreds of transactions. Both incidents demonstrate a focus on exploiting widely used digital services to achieve either immediate disturbance or illicit gain, without evidence of espionage or state‑directed aims.

The tactics observed in these operations include exploiting insufficient security settings in videoconference platforms to allow unsolicited media sharing, and employing social engineering to target employees with access to internal systems and tools, thereby gaining the ability to post unauthorized content. In the Twitter case, internal Twitter tools were abused after credential compromise, leading to the dissemination of scam tweets from high‑profile accounts. The Zoom incident similarly relied on the ability to share disruptive audio and video streams once inside the meeting. These tactics—social engineering, internal‑tool abuse, and the manipulation of platform‑level sharing controls—represent the core TTP themes associated with this actor’s publicly reported operations.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB