Cyber Incident Victim: OurMine
Date:
Aug 2017
Location:
United States of America
Summary
The WikiLeaks website was compromised by the hacking group OurMine, which defaced its homepage with a message claiming to have breached the organization following a prior challenge while also criticizing Anonymous for spreading false information about them. The incident caused intermittent access disruptions, with some visitors encountering an account suspension notice instead of the usual content. OurMine, known for targeting high-profile tech executives and media outlets by exploiting reused or outdated credentials, had previously compromised accounts linked to CEOs of Twitter and Google, as well as entertainment and news platforms like HBO, Variety, and BuzzFeed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On August 31, 2017, WikiLeaks' website homepage was altered to display a message attributed to the hacking group OurMine. The defacement appeared when accessing the site from certain locations in the early morning hours, with the message stating: "Hi, it’s OurMine (Security Group), don’t worry we are just testing your…. blablablab, oh wait, this is not a security test! Wikileaks, remember when you challenged us to hack you?" The message further taunted the Anonymous collective, referencing alleged prior attempts to expose OurMine members using fabricated information. The hackers concluded by urging social media users to promote the hashtag #WikileaksHack. Concurrently, other visitors attempting to access WikiLeaks.org encountered an account suspension notice instead of the defaced content, indicating potential disruptions to the site’s availability or administrative controls. The incident marked a public breach of the prominent document-leaking organization, though the exact duration of the unauthorized access and the full technical scope of the compromise remained unspecified in available reports.

OurMine had established notoriety prior to this incident through high-profile attacks targeting technology executives and media entities. In 2016, the group compromised Twitter CEO Jack Dorsey’s Twitter account and Google CEO Sundar Pichai’s Quora profile. They later breached websites of Variety and BuzzFeed following articles purporting to expose group members. Earlier in August 2017, OurMine hijacked HBO’s social media accounts. The group frequently exploited reused or outdated passwords to gain unauthorized access, though the specific attack vector against WikiLeaks was not disclosed. WikiLeaks did not issue an immediate public statement regarding the hack or the suspension notice observed by some users. The incident underscored ongoing vulnerabilities affecting high-visibility online entities despite their prominence in security-related activities.
