Saint Bear
Attribution profile
- Type
- Criminal
- Location
- Russia
- Known incidents
- 0 incidents
- Sources
- 1 source
- First seen
- -
- Last seen
- -
- Updated
- 2026-07-31 01:02
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is known by the aliases Saint Bear and Saint and is publicly associated with Russia. This actor gained notoriety for compromising the FBI’s InfraGard program, a partnership that links critical‑infrastructure owners with federal agencies. The compromise involved the creation of a fraudulent account using stolen personal data of a corporate chief executive officer, which was then approved through the InfraGard vetting process.
The actor’s targeting focused on the InfraGard membership database, which contains contact information for individuals across sectors such as drinking water, power utilities, communications, financial services, transportation, manufacturing, healthcare, and nuclear energy. By exploiting the approved account, the actor accessed an internal API to harvest member data and employed a custom Python script to query and exfiltrate the information. The actor also used the InfraGard messaging portal to send direct messages while posing as the compromised CEO, demonstrating an attempt to leverage the access for further communication or influence. No specific malware families or exploit kits were referenced in the reporting.
The operation was linked to the Breached cybercrime forum, where the actor using the handle USDoD offered the InfraGard database for sale, citing Pompompurin, the forum’s administrator, as the transaction guarantor. Pompompurin has previously been noted for abusing an FBI online portal to distribute hoax emails. While the actor’s location and alias suggest a Russian nexus, no explicit state sponsorship or criminal consortium affiliation is publicly confirmed in the available sources. The InfraGard incident remains a representative example of the actor’s use of social engineering, API abuse, and credential misuse to obtain and monetize sensitive data from a high‑value trust network.
Incidents
Attributed incidents are available to members.
0 incidentsSources
Sources available to members: 1 source.