ElSurveillance
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
ElSurveillance is a threat actor that has carried out ideologically motivated cyber operations, primarily targeting websites associated with dating services and escort-related platforms. The group's activities combine website defacement with the exposure or threatened exposure of user data, suggesting an intent to publicly shame users and operators of these services while advancing a religious or social messaging agenda. While the operational pattern resembles hacktivism, the actor also demonstrates an interest in collecting and potentially weaponising personal information harvested from compromised databases, blurring the line between defacement-driven activism and data breach exposure.
The organisation's operational footprint, based on documented activity, includes the compromise of at least four dating-oriented platforms in 2016, two of which served Muslim communities. One of these Muslim dating services exposed over two million accounts, with passwords reportedly stored in unencrypted plaintext, while the other leaked approximately 150,000 user profiles alongside 790,000 private messages protected only by weakly hashed MD5 password storage. These incidents occurred within weeks of each other and followed earlier compromises of two other dating platforms that targeted different demographics and involved substantially smaller user bases, though those earlier intrusions were attributed to distinct threat actors rather than to ElSurveillance itself. Separately, in 2015, the group was associated with coordinated defacements of multiple escort-related websites, where homepages were replaced with messages criticising societal values, promoting Quranic listening, and denouncing both ISIS and various governments, while visitor IP addresses and browser data from site logs were exposed.
What distinguishes ElSurveillance from purely opportunistic defacers is the combination of moral or religious messaging with demonstrated access to sensitive user records and a willingness to reference future data releases as a pressure tactic. The group has also used third-party archival and breach notification services to amplify its activities, including mirroring defacement evidence on Zone-h.org and allowing stolen records to surface in public breach databases, which extends the reach and persistence of its operations beyond the initial intrusion. The targeting of platforms serving specific religious or cultural communities, combined with the religious framing of defacement messages, suggests a self-conceived ideological mandate rather than financial motivation as the primary driver. No information is available in the provided material regarding the group's leadership, membership size, geographic composition beyond the United States headquarters designation, formal organisational structure, or any affiliation with broader hacktivist collectives, and these structural details should therefore be treated as undetermined rather than inferred.
Incidents
2 incidents linked to this organisation.