AlphaV
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
AlphaV, also known as AlphaV Group, is a threat actor that has been linked to operations originating from the United Arab Emirates. The actor uses the aliases AlphaV and AlphaV Group in public communications and leak site postings. No further details about its size, structure, or sponsorship are publicly available. The group first came to attention after claiming responsibility for a cyber incident involving a major education provider in the UAE.
The observed activity of AlphaV focuses on the education sector, specifically targeting institutions within the United Arab Emirates. In the reported case, the actor posted a listing on a dark web leak site and provided alleged proof of exfiltrated personal data, including screenshots of a passport, a birth certificate, and student‑parent details. The actor did not disclose the volume of data taken or the method used to obtain it. No malware families, initial access vectors, or specific tools were described in the public reporting.
The most concrete example of AlphaV’s operations is the February 2022 attack on Gems Education, the largest education operator in the UAE, where the group claimed responsibility and shared the aforementioned evidence on its leak site. The organization stated that the incident had minimal operational impact and that an investigation was underway, while noting that it had not confirmed any breach of personal or financial information. No other campaigns or attributed incidents have been publicly documented for AlphaV at this time. This summarizes the currently verified facts about the actor.
Incidents
Attributed incidents are available to members.
2 incidents