Singaporean Hacker Behind 90+ Data Leaks Arrested in Thailand
A 39-year-old Singaporean man, accused of conducting over 90 data breaches, has been arrested in Thailand, following a joint investigation by Singapore and Thailand law enforcement agencies.
Cybercriminal’s Evolution: From ‘Altdos’ to ‘Omid16B’
According to cybersecurity firm Group-IB, which assisted in the investigation, the suspect has been active in cybercrime since 2020 and operated under multiple aliases:
- 2020 – ‘Altdos’
- 2021 – ‘Desorden’
- 2023 – ‘Ghostr’
- 2024 – ‘Omid16B’
Initially, he avoided dark web forums, instead notifying media outlets and data protection regulators to pressure victims into paying. Later, he shifted to selling stolen data on hacker forums, with prices starting at $10,000.
Tracking the Hacker: How Investigators Found Him
Authorities identified the suspect as Chingwei and tracked him through an X (formerly Twitter) account. He reportedly earned significant profits from data sales, as evidenced by the luxury goods found at his residence.
Despite frequently changing aliases, investigators linked his attacks by analyzing:
Writing style
Post formats
Preferred data-sharing sites
Chat applications and targeted regions
Hacking Methods & Attack Techniques
Group-IB detailed his modus operandi, which included:
- SQL Injection Attacks – Using tools like sqlmap to extract sensitive data
Exploiting RDP Vulnerabilities – Gaining unauthorized access via weak Remote Desktop Protocol (RDP) servers
Deploying CobaltStrike Beacons – Using a cracked version of CobaltStrike to control compromised servers
Global Impact: Targeting APAC, North America & Europe
The hacker’s attacks impacted organizations worldwide, with a primary focus on Asia-Pacific (APAC). His victims spanned multiple industries, including:
- Healthcare
- Finance
- Retail & E-commerce
- Property Investment & Real Estate
- Hospitality
- Logistics
- Insurance
His primary goal? Exfiltrating sensitive data and extorting victims by threatening to expose or encrypt their information unless a ransom was paid.
With his arrest, law enforcement agencies are now working to mitigate the impact of his cybercrimes and prevent future data breaches.