Nam3L3ss is a pseudonymous data-leak actor known for collecting and redistributing previously compromised corporate employee datasets on BreachForums. Disclosures in November and December 2024 included records associated with Amazon, Jones Lang LaSalle, Bank of America, Morgan Stanley, HSBC, MetLife, HP, Lenovo, Xerox, Koch Industries, Cardinal Health, Brown-Forman, McDonald’s, and Medibank. The affected organizations span financial services, information technology, real estate, healthcare, industrials, and consumer sectors. Published information includes employee names, work contact details, building locations, job titles, departmental information, and internal organizational identifiers. Several redistributed datasets originated from the 2023 MOVEit Transfer compromise campaign, in which CL0P exploited CVE-2023-34362. Redistribution of those datasets does not establish that Nam3L3ss conducted the original intrusions or participated in CL0P’s extortion operations. Amazon confirmed the exposure of employee work contact information through a third-party property management vendor, while stating that Amazon and AWS systems were not compromised. Nam3L3ss published more than 2.8 million lines of Amazon employee data. The actor’s demonstrated activity centers on publishing previously stolen information rather than confirmed ransomware deployment or direct intrusion. Making employee records readily accessible can facilitate targeted phishing, identity theft, and organizational reconnaissance. Nam3L3ss’s identity, operating location, and dominant motivation are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Publishes previously stolen corporate employee databases on BreachForums, exposing millions of records containing contact information, job titles, internal identifiers, and organizational structures. Claims no direct affiliation with CL0P and says the redistribution is intended to highlight poor corporate data security rather than generate profit. The article does not establish that Nam3L3ss conducted the original intrusions.
Leaked corporate employee datasets (Amazon, 3M, HSBC, HP) claimed to have been obtained via the 2023 MOVEit incident; functions as a data leaker/redistributor in this reporting.
Leaked Amazon employee data allegedly stolen during the May 2023 MOVEit attacks after a breach at a third-party service provider.
Nam3L3ss is a threat actor focused on aggregating and leaking large datasets, including those stolen in the MOVEit attacks and from other exposed sources. They collect databases from exposed web sources and leak them on hacking forums.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.