Enlace Hacktivist
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Enlace Hacktivist, also known as the Enlace Hacktivist Collective, is a hacktivist group that has been publicly identified as operating from Mexico. The collective describes itself as a loose association of activists who use cyber techniques to draw attention to perceived injustices, particularly those involving surveillance technologies and human rights concerns. Public sources note the group’s location in Mexico but do not provide further details about its size, structure, or internal hierarchy.
The most prominently documented activity attributed to Enlace Hacktivist occurred on January 13 2023, when the group, with the assistance of a whistleblower, leaked approximately 1.7 terabytes of data from the digital forensics firm Cellebrite. The leaked material included Cellebrite’s proprietary software suite, technical guides, and tools such as the UFED device that law enforcement agencies use to extract data from mobile phones. The data was disseminated through torrent networks and made available for direct download on platforms like DDoSsecret, amplifying existing public debate about the potential misuse of Cellebrite’s technology against journalists, activists, and dissidents in various countries. This incident highlighted the group’s focus on targeting organizations that provide surveillance and forensic capabilities to state actors, aiming to expose what they view as enabling mechanisms for human rights abuses.
In terms of tactics, the collective’s approach in this case relied on insider assistance rather than malware or exploit‑based intrusion; the whistleblower provided the data, which the group then exfiltrated and published via public leak channels. No specific malware families, exploit kits, or custom tooling were referenced in the available reporting. Attribution to Enlace Hacktivist is based on the group’s own claim of responsibility and the identification of the leak as being carried out by the collective, with no publicly asserted ties to any nation‑state or criminal syndicate. The Cellebrite breach stands as the group’s most significant and publicly reported operation to date, illustrating its use of data disclosure as a means to challenge perceived abuses linked to surveillance technology.
Incidents
Attributed incidents are available to members.
2 incidents