SuperExtremeShitpostingTeam
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor identified as SuperExtremeShitpostingTeam appears in open‑source reports linked to a 2015 data leak. The alias is associated with the compromise of the Patreon donations platform. Public notes indicate a possible connection to Russia, although the source material does not provide definitive geographic attribution. The intrusion is dated to September 24, 2015, when the actor allegedly gained unauthorized access to Patreon’s servers. Approximately fifteen gigabytes of information were extracted during the incident. The exfiltrated material comprised password records, donation transaction logs, private messages, campaign specifics and internal source code.
Security researcher Troy Hunt examined the dump and confirmed its authenticity, noting that the presence of source code pointed to a compromise broader than a routine SQL injection. Hunt’s analysis also revealed that the leak contained over two point three million distinct email addresses belonging to Patreon users. Although the passwords were protected with bcrypt hashing, the exposure of source code raised concerns about potential risks to other encrypted data. Users were advised to reset their Patreon passwords and to change credentials on any other services where the same login details had been reused. The breach additionally exposed supporter identities and financial contribution records, which have become a permanent part of the public internet record. No specific malware families, exploit kits or toolsets are described in the available reporting, so the actor’s technical tooling remains unspecified. Likewise, the documents do not establish any state sponsorship or affiliation with a known criminal consortium. Because the public record lacks explicit statements of intent, the actor’s strategic objectives cannot be deduced from the disclosed facts beyond the observed data theft. The Patreon incident constitutes the sole publicly documented operation attributed to SuperExtremeShitpostingTeam. This case demonstrates how the actor’s actions resulted in the widespread dissemination of sensitive user information across online repositories.
Incidents
Attributed incidents are available to members.
1 incident