888 is a financially motivated cybercriminal persona active on cybercrime forums since at least 2024, primarily associated with the advertisement, sale, leak, or claimed possession of stolen corporate and institutional data. The actor has been linked to multiple high-profile breach claims affecting organizations across technology, consulting, aerospace, education, real estate, events, and online services, including Accenture, the European Space Agency, CIEE, Diner en Blanc, Ledil Immobilier, ThankQCamping, Samsung Medison, and datasets involving Microsoft and Nokia personnel. The persona appears to operate as a data broker and extortion-oriented breach actor rather than a ransomware brand. Observed activity centers on obtaining or claiming access to internal repositories, cloud-hosted data stores, databases, credentials, and business records, then monetizing that access through one-time sales, public leaks, or forum postings. Reported data types associated with 888 include source code, private repository contents, CI/CD-related material, configuration files, API and access tokens, SSH and RSA keys, cloud storage access keys, internal documentation, SQL data, personally identifiable information, and business transaction records. In at least one major incident involving a Brazilian organization, the exposed data was assessed as authentic and tied to a publicly accessible cloud storage misconfiguration, indicating opportunistic exploitation of weak cloud security controls. Other incidents involved claims of access to development platforms and external collaboration infrastructure. Tradecraft attributed or associated with 888 includes data theft from cloud storage, collection of unsecured credentials such as private keys and tokens, access to information repositories, use of valid accounts or exposed secrets, and possible exploitation of public-facing applications or third-party services. The actor consistently uses underground forums to publicize breaches and commonly seeks payment in Monero. Public reporting also notes that some claims by 888 have been disputed or only partially substantiated, so the persona has a mixed record that includes both credible leaks and allegations whose full scope was not independently verified. 888 has been described as having a credible reputation in dark web communities for large-scale data breaches, particularly where substantial datasets or sensitive records are exposed. The actor’s targeting pattern suggests broad opportunism rather than a clearly defined ideological or sector-specific mission. There is no high-confidence public evidence establishing 888 as a nation-state actor. Some reporting has noted possible operational overlap with IntelBroker, but no definitive public proof confirms that the two are the same individual or part of the same operation. Overall, 888 is best characterized as a prolific breach-market actor focused on monetizing stolen or exposed data, with recurring emphasis on cloud assets, developer environments, credentials, and large databases containing sensitive personal or enterprise information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Actor accused of exfiltrating and offering for sale more than 35 GB of allegedly stolen Accenture data, including source code, RSA keys, SSH keys, Azure PATs, Azure Storage access keys, and configuration files.
Claimed responsibility for breaching Accenture and stealing 35 GB of source code and sensitive data, then offered the alleged data for sale on PwnForums. The actor was also linked in the article to a prior alleged attempt to sell purported Accenture employee data in 2024.
Allegedly selling claimed stolen Accenture data, including source code, RSA/SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files, via a cybercrime forum.
Cybercrime forum persona selling allegedly stolen corporate data and credential bundles, including claimed Accenture source code, RSA keys, SSH keys, Azure PATs, storage keys, and configuration files. The content also notes a prior allegedly inflated Accenture-related claim in 2024 and multiple other claimed corporate data sales.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.