CSIDB logo
Threat actor

Gozi

Attribution profile

Type
Hacker
Location
United States of America
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-30 22:05
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Gozi is the alias used by Jonathan Powell, a 29‑year‑old resident of Phoenix, Arizona, who was arrested in April 2023 for a series of unauthorized intrusions into university email systems. According to the criminal complaint filed in Manhattan federal court, Powell employed password‑reset tools to attempt to gain access to thousands of student and staff accounts at two universities in New York and Pennsylvania, successfully changing the passwords for 1,050 accounts. After compromising these email accounts, he proceeded to access linked social media and online services such as Facebook, LinkedIn and Google, extracting confidential information from the associated profiles. The complaint also notes that he searched the contents of compromised Gmail accounts for potentially embarrassing material using keywords like “naked” and “horny.” Powell was apprehended in Arizona, released after a hearing in Phoenix, and the case was prosecuted by the U.S. Attorney’s Office for the Southern District of New York.

The activity described in the complaint shows a clear focus on the higher‑education sector, with primary victims at Pace University in New York and an unnamed institution in Pennsylvania, and additional attempts directed at more than seventy‑five other colleges across the United States. The observed objectives, as stated in the prosecutors’ filings, were to obtain unauthorized access to email and linked accounts in order to harvest personal data and to search for private or embarrassing content, rather than to achieve financial gain, espionage or disruption. The tactics, techniques and procedures highlighted include the use of password‑reset utilities to compromise credentials, subsequent credential reuse to infiltrate associated online services, systematic data mining of those accounts, and targeted keyword searches within email content. No malware families, exploit kits or broader tooling suites are referenced in the source material. Attribution information identifies Powell as an individual actor acting alone; there is no public indication of state sponsorship, affiliation with a criminal consortium, or any broader organizational ties. The campaign represented by the university email intrusions constitutes the most significant publicly reported operation linked to the Gozi alias to date.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB