CSIDB logo
Threat actor

Tessa88

Attribution profile

Type
Criminal
Location
Russia
Known incidents
2 incidents
First seen
2012-01-01
Last seen
2014-01-01
Updated
2026-08-28 16:29
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Tessa88 operates under that alias and has been publicly linked to Russia. Public reporting associates the handle with the sale of large collections of stolen user credentials on darkweb marketplaces. The actor first came to attention in 2016 when credentials from the Russian social network VK.com were offered for sale. The same identifier has also been seen in connection with credential dumps from other platforms such as MySpace. These activities indicate a focus on harvesting and monetizing account data.

The actor’s known incidents involve social‑media services, including a Russian platform (VK), an international microblogging site (Twitter), and an earlier social network (MySpace). In the Twitter‑related claim, the actor asserted that the credentials were obtained via malware that harvested saved login details from infected browsers rather than through a direct breach of the service’s infrastructure. The VK incident was described as unauthorized access that occurred several years before the data appeared for sale, with the stolen cache containing names, logins and phone numbers. No specific malware family or exploit toolkit is named in the sources, but the browser‑based credential stealer represents the only explicitly mentioned initial‑access vector. The actor’s apparent goal is financial gain, as the data were offered for sale on darkweb forums for a price measured in cryptocurrency.

Publicly available information does not link Tessa88 to any state sponsor or known criminal consortium; the actor remains unattributed beyond the alias. The VK credential sale, advertised as approximately 100 million to 170 million records, represents one of the largest credential‑exposure events associated with the handle. The Twitter claim, asserting over 32 million email‑address and plain‑text password pairs, is another notable operation attributed to the same individual. The actor’s involvement in the MySpace credential dump, though less detailed in the sources, further ties the alias to multiple high‑profile credential leaks. Collectively, these incidents illustrate a pattern of acquiring large volumes of user data and selling them for profit on underground markets.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB