National Cyber Warfare Foundation (NCWF)

Threat actor 888


0 user ratings
2026-09-10 18:03:16
error

Threat actor 888 is a hacker active in 2024, targeting
companies for data breaches. They\'ve hit Microsoft, BMW (Hong Kong), and others
in tech, freight, and oil & gas industries.

Threat Actor 888 is a prolific cybercriminal group
active in 2024 and 2026, known for targeting major
corporations to steal and sell large datasets.  Unlike
state-sponsored Advanced Persistent Threat (APT) groups that
focus on long-term espionage, 888 is primarily financially motivated,
operating as a data extortionist and breach actor. 

The group has claimed breaches of high-profile organizations
including Microsoft, BMW (Hong Kong), Accenture, IBM, Decathlon, Credit
Suisse
, Shell, and Heineken.  Their
activities involve aggregating sensitive data such as source code, Azure
credentials
, employee records, and internal
documentation
, which they typically list for sale on criminal forums
like PwnForums and BreachForums in exchange
for cryptocurrency like Monero. 





While the name includes \"888,\" which is also
associated with a specific RAT (Remote Access Trojan) tool in
some threat intelligence databases, the actor known as \"888\" in
recent breaches is distinct from any single malware family and is characterized
by its sustained presence on dark web forums and its focus on selling
exfiltrated corporate data rather than nation-state espionage. 

Identity & Background

888 is a financially motivated data broker operating
primarily on the dark web forum PwnForums, where they hold moderator
status
— a distinction that gives their listings a degree of trust
within the criminal ecosystem.  The actor is closely associated
with IntelBroker (identified in some reports as Kai Logan
West) and was a prominent member of a hacking collective that specialized in
siphoning data from misconfigured cloud infrastructure and API
endpoints.  Their real-world identity, location, and team size remain
unknown.

Tactics, Techniques & Procedures

888 operates as what\'s been called a \"silent\"
exfiltration
actor, fundamentally different from ransomware crews:


  • Initial
    access:
    Almost exclusively through misconfigured
    public-facing cloud storage
    (exposed AWS buckets, Azure DevOps
    repositories, etc.) and purchased credentials from
    Initial Access Brokers (IABs). 

  • Data
    collection:
    Uses \"Living off the Land\" (LoL) techniques
    — standard IT utilities like RClone — to slowly siphon
    data at an administrative pace that blends into normal network traffic,
    evading EDR detection. 

  • No
    encryption, no ransom note:
    Unlike traditional ransomware, 888
    does not encrypt systems or demand a
    ransom.  The business model is purely data theft and
    auctioning
    , which means victims often don\'t know they\'ve been breached
    until the data appears for sale. 

  • Payment: Listings
    are structured as one-time sales, payable exclusively in Monero
    (XMR)
    . 

Notable Victims & Incidents

























































mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Victim


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Date


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt .5in 6.0pt 9.0pt\">

What Was Stolen


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Microsoft


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

2024


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Internal data (early activity)


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

BMW (Hong Kong)


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

2024


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Corporate data


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Credit Suisse


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

June 2024


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Sensitive banking data


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

IBM


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Oct 2024


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

~17,500 employee records (via third-party provider)


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Shell


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

2024


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

~80,000 records


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Harley-Davidson


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Dec 2024


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

~66,700 user records


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Insightsoftware


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Jan 2026


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Source code for Atlas (financial
reporting tool for Microsoft Dynamics), private keys, credentials


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

LG Electronics


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Nov 2025


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Source code, config files, SQL files, hardcoded & SMTP
credentials (via contractor access)


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

ESA (European Space Agency)


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Dec 2025


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

200 GB from collaborative engineering servers (Bitbucket
repos, CI/CD pipelines)



Accenture



July 2026



~35 GB of source code, RSA keys, SSH keys, Azure PATs,
Azure Storage access keys


Dataminr has identified more than 70 attacks across
dozens of countries attributed to 888. 

The ESA Dual-Breach Incident

The ESA breach in December 2025 became a
cautionary tale.  888\'s initial 200 GB exfiltration from ESA\'s
engineering servers was treated as an \"unclassified\" incident and
downplayed. However, the stolen material — functionally a complete
network map
including Infrastructure-as-Code (IaC) files and CI/CD
pipeline secrets — enabled a second, successful attack by
the Scattered Lapsus$ Hunters supergroup.  The
lesson: \"unclassified\" data stolen silently can be far more dangerous
than a loud ransomware lockout, especially when the buyer is a nation-state
APT group
rather than a petty criminal.

Supply Chain Risk

888\'s attacks carry second-order implications.  The Insightsoftware breach
is a prime example: by stealing the source code and private keys for Atlas —
a widely used real-time financial reporting solution for Microsoft
Dynamics AX and D365
— 888 created a supply chain vulnerability
affecting every enterprise that uses that
software.  Similarly, the Accenture breach (confirmed by
the company as an \"isolated matter\" with no operational impact)
raises concerns for Accenture\'s extensive client network, since
stolen Azure credentials and source code could enable persistent access to
downstream environments. 

Why 888 Matters in the 2025–2026 Threat Landscape


  • Data-only
    incidents surged 11x in 2025
    , and 888 is at the forefront of this
    shift away from \"loud\" ransomware toward silent
    infrastructure extortion
    . 

  • 50%
    of all global ransomware incidents in 2025 targeted critical
    infrastructure
    (a 34% year-over-year increase), and 888\'s focus
    on engineering blueprints, CI/CD pipelines, and cloud credentials makes
    them a direct threat to national resilience. 

  • The \"forensic
    expiration\" problem
    is a key challenge: because 888 often
    steals data months before announcing an auction, the logs needed to
    investigate the breach have usually aged out by the time the victim even
    knows they\'ve been hit. 





























In short, 888 represents a new paradigm in cybercrime: not a
disruption-for-attention actor, but a professional data broker whose
target is the digital blueprint of the organizations that run
critical global infrastructure. 




Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.