Menu
Browse

Cyber Threat Actor: Icarus

Updated 2026-07-27 20:28
Actor Type Location Known Incidents
 Icon
Criminal
11 incidents
Profile

Icarus is an alias used by a threat actor that publicly claimed responsibility for a breach disclosed on June 16 2026. The actor asserted that they had compromised the Salesforce environment belonging to The Credit Pros, a company operating in the credit‑services sector. According to the actor’s claim and subsequent breach notifications, the intrusion resulted in the acquisition of a wide range of personal and financial data. The exposed information reportedly included names, contact details, dates of birth, residential addresses, credit and debit card numbers, Social Security numbers, and bank account information. The actor’s statement was disseminated through a press release that also noted the involvement of a national class‑action law firm investigating the incident. No additional identifiers, such as real names, geographic origins, or affiliations, have been made public in connection with the Icarus alias.

The compromise of The Credit Pros’ Salesforce platform represents the only publicly documented operation attributed to Icarus to date. The method by which the actor gained initial access to the Salesforce environment has not been detailed in the available sources, and no specific malware families, toolkits, or exploit techniques have been linked to this incident. Consequently, any description of the actor’s typical targeting patterns, preferred vectors, or strategic objectives would rely on speculation rather than confirmed evidence. The breach prompted notifications to affected individuals, who were advised of an elevated risk of identity theft and fraud based on the data that was accessed. While the incident has spurred legal scrutiny, no further campaigns or operations have been publicly associated with Icarus beyond this single reported compromise.

Incidents
Attributed incidents available to members
11 incidents
Sources
Sources available to members
0 sources