CSIDB logo
Incident

OurMine

Incident posture

Attack window
Aug 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-16 00:00

Linked entities

Victim
OurMine
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Aug 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The WikiLeaks website was compromised by the hacking group OurMine, which defaced its homepage with a message claiming to have breached the organization following a prior challenge while also criticizing Anonymous for spreading false information about them. The incident caused intermittent access disruptions, with some visitors encountering an account suspension notice instead of the usual content. OurMine, known for targeting high-profile tech executives and media outlets by exploiting reused or outdated credentials, had previously compromised accounts linked to CEOs of Twitter and Google, as well as entertainment and news platforms like HBO, Variety, and BuzzFeed.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 31, 2017, WikiLeaks' website homepage was altered to display a message attributed to the hacking group OurMine. The defacement appeared when accessing the site from certain locations in the early morning hours, with the message stating: "Hi, it’s OurMine (Security Group), don’t worry we are just testing your…. blablablab, oh wait, this is not a security test! Wikileaks, remember when you challenged us to hack you?" The message further taunted the Anonymous collective, referencing alleged prior attempts to expose OurMine members using fabricated information. The hackers concluded by urging social media users to promote the hashtag #WikileaksHack. Concurrently, other visitors attempting to access WikiLeaks.org encountered an account suspension notice instead of the defaced content, indicating potential disruptions to the site’s availability or administrative controls. The incident marked a public breach of the prominent document-leaking organization, though the exact duration of the unauthorized access and the full technical scope of the compromise remained unspecified in available reports.

OurMine had established notoriety prior to this incident through high-profile attacks targeting technology executives and media entities. In 2016, the group compromised Twitter CEO Jack Dorsey’s Twitter account and Google CEO Sundar Pichai’s Quora profile. They later breached websites of Variety and BuzzFeed following articles purporting to expose group members. Earlier in August 2017, OurMine hijacked HBO’s social media accounts. The group frequently exploited reused or outdated passwords to gain unauthorized access, though the specific attack vector against WikiLeaks was not disclosed. WikiLeaks did not issue an immediate public statement regarding the hack or the suspension notice observed by some users. The incident underscored ongoing vulnerabilities affecting high-visibility online entities despite their prominence in security-related activities.

Sources

Sources available to members: 1 source.

CSIDB