Logan
Attribution profile
- Type
- Criminal
- Location
- Netherlands
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2017-07-25
- Last seen
- 2017-07-25
- Updated
- 2026-07-31 22:33
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Logan is a pseudonym used by an individual who operates as a dark web vendor and is known to be based in the Netherlands. According to open source reporting, Logan is not affiliated with any criminal group or state actor and is described as acting alone while employed at an unspecified cybersecurity company. The individual is over eighteen years old and has been noted to travel internationally. The alias appears in connection with the sale of large volumes of U.S. voter registration data on underground forums.
The actor’s observed targeting focuses on government‑held voter records from multiple U.S. states, specifically Arkansas, Colorado, Connecticut, Delaware, Florida, Michigan, Ohio, Oklahoma, and Washington State, with claims of possessing data from an additional twenty to twenty‑five states. The data includes names, addresses, voter identifiers, status, and party affiliations. Regarding strategic objectives, analysis from LookingGlass Cyber Solutions indicates that Logan’s primary motive is likely not financial, as evidenced by the sale of over ten million records for a minimal price. Nevertheless, the individual has been observed trading portions of the voter data for stolen credit card information and login credentials, indicating a secondary exchange of personal data for other illicit assets.
In terms of tactics, Logan reportedly acquired the voter records through a combination of social engineering techniques and Freedom of Information Act (FOIA) requests, with no mention of specific malware families or custom tooling. The notable operation involved offering more than forty million voter records from nine states on the RaidForums marketplace for under five dollars, a transaction that attracted attention due to the low cost and volume of data exchanged. The actor also asserted possession of further state‑level voter databases and continued to seek alternative data types in return for the voter information, highlighting a pattern of data bartering rather than a single‑purpose campaign. This activity underscores the use of publicly available request channels and interpersonal deception to assemble and monetize sensitive personal information on illicit markets.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.