CSIDB logo
Threat actor

Mak Man

Attribution profile

Type
Sensationalist
Location
Pakistan
Known incidents
1 incident
First seen
2015-05-28
Last seen
2015-05-28
Updated
2026-08-28 15:52
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Mak Man is the alias used by a threat actor who has been publicly linked to a 2015 data breach affecting the Indian music streaming service Gaana. The actor is reported to be based in Lahore, Pakistan, according to the coverage of the incident. In May 2015, Mak Man exploited a SQL injection vulnerability in Gaana’s web application to gain unauthorized access to its user database. The compromised data included email addresses, full names, MD5‑hashed passwords, dates of birth, and linked social‑media profiles for millions of users.

After obtaining the database, the actor published a searchable version of the records on a Facebook page and shared screenshots of Gaana’s administrative interface. The actor’s own statements indicated that the intrusion was intended to highlight security weaknesses in the service rather than to pursue financial gain. Gaana responded by taking the site offline, patching the vulnerable parameter, resetting all user passwords, and requesting the removal of the exposed database. The incident prompted criticism of Gaana’s use of MD5 for password hashing and led to recommendations for stronger derivation functions and input sanitization. No evidence connects Mak Man to any state‑sponsored program, criminal consortium, or broader campaign beyond this single reported operation. The actor’s known tactics are limited to SQL injection as an initial access vector and the use of social media to disseminate stolen data. No malware families, exploit kits, or additional tooling have been attributed to Mak Man in publicly available sources.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB