Cyber Threat Actor: Christine Moses Email Hacker
| Actor Type | Location | Known Incidents |
Hacker
|
United States of America
|
1 incident |
|---|
Profile
The threat actor known by the alias Christine Moses Email Hacker has been publicly linked to a single incident involving the Lake Oswego School District. Open‑source reporting indicates the actor operates from within the United States of America, though no more precise geographic detail has been disclosed. The alias itself references the use of compromised email as a primary tactic. No other aliases or affiliated group names have been attributed to this actor in available sources. The actor’s activity to date is limited to the 2018 incident described in breach notifications. No further public identifiers or handles have been associated with this name.
The observed activity targeted the education sector, specifically a public school district located in Lake Oswego, Oregon, United States. The actor gained unauthorized access to an employee’s email account and subsequently used that account to distribute phishing links to roughly two hundred students. In a separate but temporally close action, the same actor compromised the district’s official Twitter account and posted an unauthorized message announcing a change in ownership. The phishing emails served as an initial access vector for delivering malicious links, while the Twitter takeover functioned as a form of online defacement. No malware families, exploit kits, or specific tooling have been reported in connection with these actions. The actor’s methodology appears to rely on credential compromise and social media account hijacking rather than custom malware.
Public attribution does not link the actor to any state‑sponsored program, criminal consortium, or hacker collective; the actor remains unaffiliated in the open‑source record. The Lake Oswego School District breach stands as the sole publicly documented operation associated with the Christine Moses Email Hacker alias. Because no additional incidents or technical details have been released, the full scope of the actor’s capabilities and objectives cannot be determined from existing sources. Law‑enforcement or private‑sector reports have not provided further insight into potential collaborators or subsequent activity. Consequently, the profile reflects only the confirmed facts presented in the breach notification and related coverage. This concludes the summary of what is presently known about the threat actor.
