CSIDB logo
Threat actor

Blood Security Hackers International

Attribution profile

Type
Activist
Location
Philippines
Known incidents
1 incident
Sources
1 source
First seen
2015-01-30
Last seen
2015-01-30
Updated
2026-08-01 18:36
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Blood Security Hackers International, also known as Bloodsec International, is a hacker collective that has been publicly linked to operations originating from the Philippines. The group first came to attention in early 2015 when it altered a journalist's satirical news site to display a condemnatory message aimed at the national leadership. This activity demonstrates the collective operates under at least two interchangeable names and maintains a geographic tie to the Philippine archipelago.

The collective's known targets include media platforms and telecommunications providers, indicating a focus on entities that shape public discourse and connectivity. In the January 2015 incident, the actors gained unauthorized access to Hotmanila.ph, a satirical website run by a Filipino journalist, and replaced its content with a statement criticizing the president's response to the Mamasapano clash and demanding respect for forty‑four fallen police officers. Prior to that defacement, the same group reportedly compromised a telecom operator's online presence, using it to press for accountability regarding the same incident. These actions reveal a pattern of website defacement coupled with the posting of politically charged messages, rather than the deployment of malware or the exfiltration of data.

Public sources do not associate Blood Security Hackers International with any state‑sponsored program or transnational criminal consortium, and no affiliations beyond the self‑described label have been verified. The group's reported activities are limited to the two defacements described above, and no further campaigns have been documented in open‑source reporting. Consequently, the actor is understood as a politically motivated hacktivist entity operating within the Philippine context, whose known capability rests on exploiting web‑application vulnerabilities to alter online content and convey a specific narrative.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 1 source.

CSIDB