CSIDB logo
Threat actor

DFrank

Attribution profile

Type
Activist
Location
Brazil
Known incidents
1 incident
Sources
1 source
First seen
2017-12-05
Last seen
2017-12-05
Updated
2026-08-01 07:23
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the aliases Prison Break and DFrank has been associated with activities originating from Brazil. Public reporting identifies the actor primarily through the alias DFrank used in a 2017 data leak involving the Brazilian e‑commerce site Netshoes. No further biographical details such as age, real name, or organizational ties have been disclosed in open sources. The actor’s location is noted only as Brazil, with no indication of state sponsorship or affiliation with a larger criminal group.

The actor’s stated motivation, as communicated to TecMundo, was to challenge corporate claims that consumer data is secure. DFrank asserted that companies should stop misleading the public about the safety of personal information. The reporting provides no indication that the actor sought financial gain, espionage, or disruption as a primary goal. Thus the activity appears focused on prompting accountability through the disclosure of personal data.

The only technique explicitly referenced in the reporting is fuzzing, which the actor said was used to infiltrate Netshoes’ source code. Fuzzing involves automated input manipulation to discover vulnerabilities in software, suggesting a focus on web application testing. The company Netshoes countered that the leak might have resulted from phishing rather than a direct system breach, leaving the exact initial access vector uncertain. No malware families, exploit kits, or specific tooling beyond the fuzzing approach are mentioned in the available sources.

The most publicly documented operation DFrank carried out was the December 5, 2017 leak of over 17,900 Netshoes customer records on Pastebin. The leaked data included names, email addresses, phone numbers and other personal details but, according to Netshoes, did not contain banking information, credit card numbers or passwords. Security commentators warned that the exposed information could facilitate social engineering attacks such as identity theft or credential recovery scams. The incident remains the sole cited example of the actor’s activity in open source reporting.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 1 source.

CSIDB