AppState Leaks
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
AppState Leaks is a threat actor known by the alias AppState Leaks and is associated with the United States of America based on publicly available information. The actor emerged in public view when it claimed responsibility for releasing academic records from a university in the southeastern United States. No further details about the actor’s structure, funding, or broader affiliations have been disclosed in open sources.
The actor’s observed activity targets the education sector, specifically a public university, and the geographic focus appears to be within the United States. In December 2016 the actor posted a PDF on a Twitter account bearing the same name as the alias, which contained the first names, majors, academic years, and grade point averages of 1,768 students from Appalachian State University. The university’s Information Security Department confirmed that the release did not indicate a compromise of its secure databases, suggesting the data was obtained through other means.
The tactics, techniques, and procedures demonstrated by AppState Leaks involve the use of social media platforms for data dissemination and the creation of a document format to consolidate and share the stolen information. No malware families, exploit kits, or specific initial access vectors were referenced in the reporting of this incident. The actor’s tooling style appears limited to basic file preparation and public posting rather than sophisticated intrusion frameworks.
Public attribution efforts have not linked AppState Leaks to any state‑sponsored group, criminal consortium, or other known threat actor network. The single reported operation remains the most notable campaign associated with the alias, highlighting a focus on exposing personal academic data without evidence of broader system infiltration. This incident stands as the primary publicly documented activity attributed to AppState Leaks.
Incidents
Attributed incidents are available to members.
1 incident