The threat actor behind the MOVEit exploit, which lead to the breach of 2.8 million lines of employee data from Amazon, has now claimed themselves to be an ethical hacker.
The hacker, who goes by the name Nam3L3ss on the dark web, claimed in a round of posts to have been the culprit behind the MOVEit exploit which took place last year and stole data from 25 different organisations.
Hudson Rock verified the data, showing that targeted organisations include McDonalds, HSBC, Amazon, Charles Schwab, Lenovo, and Delta Airlines, with five million records leaked and counting.
Contact information, as well as more sensitive information about departmental roles and assignments, were breached, which could lead these to further security incidents in the future.
However, the culprit, which released the data to Hudson Rock researchers, is claiming that they leaked the data to draw attention to lacking security posture from major companies.
“People, I am not a hacker! If something requires a username or password, even a default password, I will not try and use it! I track all of the ransom group sites and have my own tools that auto find AWS, AWS and other sites’ open buckets,” Nam3l3ss wrote on Monday on the dark web. “I download everything I can from ransom group TOR sites and from open cloud services. Once I have it I then clean the data and remove duplicates from the source and sometimes remove fields/columns where the data is useless.”
Later on Tuesday, the perpetrator posted again, defending their data leak further, as seen by Infosecurity Magazine.
“Companies and governments alike have a responsibility to make damn sure they are encrypting PII data,” the post read.
“Too many companies blame third-party vendors, yet they themselves are transferring unencrypted data to these third parties,” they said. “Those that are sending encrypted data have a responsibility to make damn sure the third-party is keeping it encrypted.”
Recommended reading
- UK Gov: Data Centres Are Now Critical National Infrastructure
- Amazon Confirms Data Breach Linked to MOVEit Vulnerability
- AWS Commits Over £180 Million to GenAI Startups
- New Survey Reveals UK T&L Has “Significant” Data and AI Gap
Amazon has recently admitted that the data breach of nearly 3 million lines of employee data was related to a vulnerability in the MOVEit transfer software.
Amazon says that its services, as well as AWS, remain secure, and they have not experienced a security incident.
It remains unclear, despite the claims of Nam3l3ss, if the data was scraped from alternative sources or if they were leaked directly from the MOVEit exploit. The MOVEit exploit was originally carried out in 2023 and was linked to the Cl0P ransomware group.
The large scale and nature of the breach, as well as Amazon’s claims, bring doubt to the culprit’s motive and method.
Nam3l3ss has said that the leaked data it shared with Hudson Rock is just a “tiny portion” of the total data they have, and more can be expected to be leaked in the coming days.





