Threat actor 888 is a hacker active in 2024, targeting
companies for data breaches. They\'ve hit Microsoft, BMW (Hong Kong), and others
in tech, freight, and oil & gas industries.
Threat Actor 888 is a prolific cybercriminal group
active in 2024 and 2026, known for targeting major
corporations to steal and sell large datasets. Unlike
state-sponsored Advanced Persistent Threat (APT) groups that
focus on long-term espionage, 888 is primarily financially motivated,
operating as a data extortionist and breach actor.
The group has claimed breaches of high-profile organizations
including Microsoft, BMW (Hong Kong), Accenture, IBM, Decathlon, Credit
Suisse, Shell, and Heineken. Their
activities involve aggregating sensitive data such as source code, Azure
credentials, employee records, and internal
documentation, which they typically list for sale on criminal forums
like PwnForums and BreachForums in exchange
for cryptocurrency like Monero.
While the name includes \"888,\" which is also
associated with a specific RAT (Remote Access Trojan) tool in
some threat intelligence databases, the actor known as \"888\" in
recent breaches is distinct from any single malware family and is characterized
by its sustained presence on dark web forums and its focus on selling
exfiltrated corporate data rather than nation-state espionage.
Identity & Background
888 is a financially motivated data broker operating
primarily on the dark web forum PwnForums, where they hold moderator
status — a distinction that gives their listings a degree of trust
within the criminal ecosystem. The actor is closely associated
with IntelBroker (identified in some reports as Kai Logan
West) and was a prominent member of a hacking collective that specialized in
siphoning data from misconfigured cloud infrastructure and API
endpoints. Their real-world identity, location, and team size remain
unknown.
Tactics, Techniques & Procedures
888 operates as what\'s been called a \"silent\"
exfiltration actor, fundamentally different from ransomware crews:
- Initial
access: Almost exclusively through misconfigured
public-facing cloud storage (exposed AWS buckets, Azure DevOps
repositories, etc.) and purchased credentials from
Initial Access Brokers (IABs). - Data
collection: Uses \"Living off the Land\" (LoL) techniques
— standard IT utilities like RClone — to slowly siphon
data at an administrative pace that blends into normal network traffic,
evading EDR detection. - No
encryption, no ransom note: Unlike traditional ransomware, 888
does not encrypt systems or demand a
ransom. The business model is purely data theft and
auctioning, which means victims often don\'t know they\'ve been breached
until the data appears for sale. - Payment: Listings
are structured as one-time sales, payable exclusively in Monero
(XMR).
Notable Victims & Incidents
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Victim | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Date | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt .5in 6.0pt 9.0pt\"> What Was Stolen |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Microsoft | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Internal data (early activity) |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> BMW (Hong Kong) | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Corporate data |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Credit Suisse | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> June 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Sensitive banking data |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> IBM | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Oct 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> ~17,500 employee records (via third-party provider) |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Shell | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> ~80,000 records |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Harley-Davidson | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Dec 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> ~66,700 user records |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Insightsoftware | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Jan 2026 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Source code for Atlas (financial |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> LG Electronics | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Nov 2025 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Source code, config files, SQL files, hardcoded & SMTP |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> ESA (European Space Agency) | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Dec 2025 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> 200 GB from collaborative engineering servers (Bitbucket |
Accenture | July 2026 | ~35 GB of source code, RSA keys, SSH keys, Azure PATs, |
Dataminr has identified more than 70 attacks across
dozens of countries attributed to 888.
The ESA Dual-Breach Incident
The ESA breach in December 2025 became a
cautionary tale. 888\'s initial 200 GB exfiltration from ESA\'s
engineering servers was treated as an \"unclassified\" incident and
downplayed. However, the stolen material — functionally a complete
network map including Infrastructure-as-Code (IaC) files and CI/CD
pipeline secrets — enabled a second, successful attack by
the Scattered Lapsus$ Hunters supergroup. The
lesson: \"unclassified\" data stolen silently can be far more dangerous
than a loud ransomware lockout, especially when the buyer is a nation-state
APT group rather than a petty criminal.
Supply Chain Risk
888\'s attacks carry second-order implications. The Insightsoftware breach
is a prime example: by stealing the source code and private keys for Atlas —
a widely used real-time financial reporting solution for Microsoft
Dynamics AX and D365 — 888 created a supply chain vulnerability
affecting every enterprise that uses that
software. Similarly, the Accenture breach (confirmed by
the company as an \"isolated matter\" with no operational impact)
raises concerns for Accenture\'s extensive client network, since
stolen Azure credentials and source code could enable persistent access to
downstream environments.
Why 888 Matters in the 2025–2026 Threat Landscape
- Data-only
incidents surged 11x in 2025, and 888 is at the forefront of this
shift away from \"loud\" ransomware toward silent
infrastructure extortion. - 50%
of all global ransomware incidents in 2025 targeted critical
infrastructure (a 34% year-over-year increase), and 888\'s focus
on engineering blueprints, CI/CD pipelines, and cloud credentials makes
them a direct threat to national resilience. - The \"forensic
expiration\" problem is a key challenge: because 888 often
steals data months before announcing an auction, the logs needed to
investigate the breach have usually aged out by the time the victim even
knows they\'ve been hit.
In short, 888 represents a new paradigm in cybercrime: not a
disruption-for-attention actor, but a professional data broker whose
target is the digital blueprint of the organizations that run
critical global infrastructure.
