CSIDB logo
Incident

sofiadelterra.com

Incident posture

Attack window
Jul 2015
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-14 16:37

Linked entities

Victim
sofiadelterra.com
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The website sofiadelterra.com was compromised by threat actor @ElSurveillance alongside multiple other escort-related services, resulting in defacement with a message promoting religious reflection and criticism of societal values. The attacker displayed server logs containing visitors' IP addresses and browser information but initially refrained from leaking personal user data beyond this exposure. However, the hacker later claimed to possess additional user data from the targeted sites while withholding its public release. The incident highlighted risks associated with accessing such platforms, particularly regarding potential exposure of user activity through compromised logs.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 20, 2015, the website sofiadelterra.com was compromised by an individual using the alias @ElSurveillance as part of a coordinated attack targeting multiple escort-related services. The attacker defaced the homepage with a message criticizing the morality of such websites and their societal impact, while promoting religious content and anti-government sentiments. The defacement included a block of text urging visitors to listen to the Qur’an and distrust media portrayals of ISIS, alongside a direct reference to accessing site logs containing visitor IP addresses. This incident occurred concurrently with breaches of at least five other escort service domains—ohcecilia.com, seductivealchemy.com, taliaamour.com, tabithalayne.com, and tawnybrie.com—all defaced with identical messaging. Evidence of the compromise was archived on Zone-h.org under mirror ID 24614736 for sofiadelterra.com, consistent with @ElSurveillance’s pattern of publicly documenting hacks through this platform.

Initial analysis indicated the attacker accessed and displayed server logs containing visitor IP addresses and browser information but did not initially release more sensitive user data. The defacement served primarily as a protest against the sites’ operations rather than a conventional data theft operation, though @ElSurveillance later informed DataBreaches.net that user data had been acquired from breached sites without immediate public release. No evidence suggested encryption bypass or financial system compromises during the incident. The attacker’s operational focus appeared centered on disrupting services and delivering ideological messaging, with secondary emphasis on data exfiltration. Visitor metadata exposure created reputational risks for site users despite the absence of credential or payment card leaks. No documented containment actions or victim responses were reported in available sources following the defacement and log disclosures.

Sources

Sources available to members: 1 source.

CSIDB