Department of Peace is a self-described hacktivist operation that has publicly claimed responsibility for compromising systems associated with the U.S. Department of Homeland Security and leaking contractor-related records tied to DHS and U.S. Immigration and Customs Enforcement. The group framed the operation as retaliation connected to protest-related grievances and positioned the leak as an effort to expose organizations supporting federal immigration enforcement. Reported leaked material was said to include records from DHS’s Office of Industry Partnership and information on thousands of organizations involved in DHS contracting, including applicants and award recipients. Based on the available reporting, the actor is associated with data exposure and politically motivated intrusion claims against U.S. government targets. High-confidence, corroborated information supports characterization of the group as hacktivist and focused on unauthorized access and disclosure activity; broader technical tradecraft, infrastructure, and organizational structure remain publicly unconfirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Alleged hacktivist intrusion and data theft targeting the U.S. Department of Homeland Security (DHS), followed by public leaking of purportedly stolen DHS Office of Industry Partnership data (including DHS/ICE contracts) via DDoSecrets, framed as retaliation for killings of protesters.
Hacktivist data-theft/leak operation claiming intrusion into U.S. Department of Homeland Security systems to exfiltrate and publish internal contractor records related to ICE; data was released via a whistleblower/leak site (DDoSecrets) with an ideological motive to expose companies supporting ICE/DHS operations.
Hacktivist group claiming intrusion into the U.S. Department of Homeland Security and leaking allegedly stolen documents/contract-related data via a third-party publishing collective.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.