CSIDB logo
Threat actor

@gift2death

Attribution profile

Type
Activist
Location
China
Known incidents
1 incident
First seen
2016-03-30
Last seen
2016-03-30
Updated
2026-08-01 06:40
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the aliases @gift2death and didthe0x has been linked to a data exposure incident involving the Norfolk Admirals hockey team. Public records indicate the actor’s location is China, though no further geographic details are provided. The aliases appear in the actor’s online communications and in the breach announcement. No other aliases or identifiers are mentioned in the available sources. This establishes the basic identity of the actor for the purpose of this profile.

The actor’s known activity targets a sports and entertainment organization, specifically a minor league hockey team based in Norfolk, Virginia, United States. The disclosed information consisted of names, email addresses, physical addresses and credit card types, but deliberately excluded financial account numbers. The actor stated that prior warnings about the team’s lax online security were ignored, and posted the data online. No evidence suggests the actor sought financial gain from the data, as no payment card numbers were taken or used. The actor’s actions were limited to exposing the information and sharing what was claimed to be the team’s Twitter password.

The source material does not reference any specific malware families, exploit kits, or custom tooling employed by the actor. Likewise, no details are provided about the initial access vector used to obtain the customer data from the Norfolk Admirals website. The actor’s actions are limited to posting the harvested data online and sharing what was claimed to be the team’s Twitter password, without attempting to log into the account. Because no tooling or malware is described, any inference about the actor’s technical capabilities would be speculative and is therefore omitted. The profile therefore notes only the observable actions of data disclosure and credential sharing.

Attribution to a state sponsor or criminal consortium is not established in the publicly available information; the only geographic clue is the actor’s location in China. The Norfolk Admirals incident represents the sole publicly reported operation attributed to this actor, serving as the representative example of their activity. No additional campaigns or historical operations are cited in the sources. Consequently, the actor’s profile is confined to this single event and the associated claims made by the individual. This concludes the factual summary based exclusively on the provided context.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB