Desorden Group
| Primary URL | Location | Industry | Undetermined |
Country
Singapore
|
Telecommunications
|
|---|
Profile
DESORDEN, also known as the Desorden Group, is a cybercriminal threat actor organization headquartered in Singapore. The group specializes in infiltrating corporate networks to exfiltrate sensitive data and then leveraging that information for extortion. Its known activities include targeting large Malaysian service providers that hold extensive personal and financial records. On September 19, 2022, DESORDEN compromised a Malaysian telecommunications provider serving over 1.2 million subscribers. During that breach the attackers copied databases and source code containing customer national identification numbers, addresses, phone numbers, and email addresses. After obtaining the data, DESORDEN escalated to the provider’s financial and insurance partnership programs when initial demands went unanswered. The group threatened to publish the stolen information publicly unless contacted within a specified deadline. Independent verification confirmed the authenticity of leaked data samples by matching them against the telecom’s internal records before the leak was removed. This incident demonstrated the group’s ability to move from initial intrusion to broader exploitation of ancillary business units. The episode highlighted the risks posed by DESORDEN’s focus on personally identifiable information that can be misused for identity theft and fraud.
Earlier, on September 9, 2021, the Desorden Group breached a Malaysian logistics carrier over a three‑week period. The attackers exfiltrated corporate, financial, and customer databases, obtaining millions of records that included personal details, financial information, employee names, birthdates, contact details, and plaintext passwords. DESORDEN claimed that the compromised data also affected users of regional e‑commerce platforms such as Shopee and Lazada, although those companies did not publicly confirm involvement. The victim’s IT team detected the intrusion and patched one vulnerability, but the group asserted that additional entry points remained exploitable. Proof of the breach, including a video showing the stolen files, was posted on a forum that later disappeared from the clearnet but stayed reachable via the Tor network. The timing of the leak coincided with a rise in cybercrime activity directed at businesses across the ASEAN region. By sharing evidence through underground channels, DESORDEN sought to validate its claims and increase pressure on the target organization. The logistics incident illustrated the group’s capacity to maintain prolonged access within a network while systematically harvesting diverse data sets. Together, the two incidents reveal a pattern of targeting high‑volume service sectors in Malaysia, extracting extensive personal and financial datasets, and using the threat of public sale to compel payment. DESORDEN’s operational base in Singapore and its reliance on anonymizing tools such as Tor underscore its transnational approach to cyber extortion.
