Fenice is a threat actor alias associated with the public release of a large stolen dataset from National Public Data in August 2024. The actor is known for publishing what was described as the most complete publicly available copy of the breached data on a criminal forum, following earlier sale and partial-release activity by other actors including USDoD and Petrovic. Fenice also claimed that the underlying breach had been conducted by another actor identified as SXUL, but high-confidence attribution for the original intrusion is not established here. Fenice’s observed role is the dissemination and exposure of stolen personal data rather than a clearly documented intrusion set with a broader established operational history. The leaked material reportedly contained massive volumes of plaintext personal information tied primarily to individuals in the United States, with references also indicating possible impact to people in the United Kingdom and Canada. Based on the available facts, Fenice is best characterized as a data-leak actor involved in post-compromise publication of exfiltrated information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Published the complete stolen National Public Data dataset publicly, escalating the breach into mass exposure.
Released for free the most complete leaked copy of the stolen National Public Data dataset on the Breached hacking forum.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.