RawShark
Attribution profile
- Type
- Activist
- Location
- New Zealand
- Known incidents
- 3 incidents
- Sources
- 1 source
- First seen
- 2014-08-18
- Last seen
- 2014-08-18
- Updated
- 2026-09-03 17:24
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
RawShark, also known as whaledump, is a threat actor whose activity has been publicly linked to New Zealand. The actor operates under the aliases RawShark and whaledump, which appear in the same incident reporting. Public sources locate the actor in New Zealand, although no further geographic detail is provided. The alias RawShark was used when the actor claimed responsibility for leaking emails from a conservative blogger’s account in August 2014. The same actor is referenced by the handle whaledump in the accompanying coverage of the leak. No other aliases or affiliations have been disclosed in open sources.
The observed activity involved gaining access to the email account of Cameron Slater, a New Zealand‑based political blogger. The breach exposed communications that implicated government officials, including then‑Justice Minister Judith Collins, in efforts to undermine agencies investigating financier Mark Hotchin. The leaked material was cited in the book Dirty Politics and contributed to public pressure that led to Collins’s resignation. The released emails were subsequently interpreted as showing improper conduct by government officials. The hacker further claimed that his motivations were such that any lapse in operational security would lead to rapid identification. No evidence points to financial gain, espionage for a state, or disruption of critical infrastructure as a goal.
The August 2014 email leak remains the only publicly documented operation attributed to RawShark/whaledump. The actor described himself as a teenage hacktivist, though no technical details about malware, tools, or intrusion methods were released. Consequently, no specific malware families, exploit vectors, or tooling styles can be confirmed from the available reporting. Attribution to any state sponsor, criminal consortium, or hacker collective has not been established in open sources. The incident illustrates a capability to compromise personal email accounts and to disseminate obtained information for political impact. Beyond this single episode, no further activity has been reliably linked to the actor in the sources consulted.
Incidents
Attributed incidents are available to members.
3 incidentsSources
Sources available to members: 1 source.