DOXXED by his CAT PROFILE PICTURE

DOXXED by his CAT PROFILE PICTURE

🎙 John Hammond 👥 2.2M 📅 August 27, 2026 ⏱ 17 min 👁 1K 📄 documentary 🧭 2026-08-27
Available in: English (current) Français

Keywords

OSINTTeam PCPdeanonymizationsupply chain attackFlare

Summary

The video recounts the deanonymization of the leader of the hacker group Team PCP, responsible for major software supply chain attacks in 2026. John Hammond, using Flare’s OSINT platform, walks through the investigation process that linked the alias ‘DeadCat X3’ to a real person, Reuben Thompson. The investigation started with a single stolen token that led to a five-day campaign poisoning multiple software ecosystems. The group’s online bravado and reused handles, avatars, and infrastructure references provided the trail. Key steps included searching the username ‘DeadCat X3’ on OSINT.industries, which revealed accounts on HackerOne, Hugging Face, and a C2 domain. A Gmail address ‘surfinup8@gmail.com ’ was found, and using Flare’s credential browser, they discovered a TikTok account with a video showing a Steam profile. The Steam profile picture matched a Telegram account used by Team PCP, providing high-confidence evidence. The investigation was confirmed by law enforcement, leading to an arrest. The video emphasizes the importance of OSINT techniques and the role of threat intelligence platforms in unmasking cybercriminals.

167 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides a valuable, real-world example of OSINT investigation, demonstrating how seemingly insignificant details like a profile picture can be pivotal. The argumentation is solid, building a logical chain of evidence from the initial alias to the final identification. The presenter clearly explains each step, making the methodology accessible. However, the video is an abbreviated showcase, and some steps are glossed over, which may leave the viewer with questions about the full process. The presenter’s enthusiasm for Flare is evident, but it does not undermine the core narrative.

Scientific Rigor, Source Quality, Title Accuracy

The video relies on the investigation by Flare’s emerging threats team, which is a credible source in the cybersecurity industry. The presenter also mentions Brian Krebs, a well-known journalist, as having covered the story. The sources cited in the description are mostly links to Flare’s resources and the presenter’s own content, which are relevant but not primary sources for the investigation. The title accurately reflects the content, focusing on the cat profile picture as the key clue. The video does not provide a detailed methodology or raw data, but it is a compelling summary of a real investigation.

202 words

Title / Content Match

The title is catchy and accurately reflects the key role of the cat profile picture in the deanonymization.

Quality & Reliability

7/10

The video presents a real-world OSINT investigation by Flare's emerging threats team, with a clear methodology and corroborating evidence. However, it is a secondary account of the investigation, with some details abbreviated, and the presenter's enthusiasm may introduce bias.

Key Moments

Cited Sources

  • Flare's Team PCP blog post — The blog post detailing the full investigation by Flare's emerging threats team.
  • Flare's cat-themed page — A page on Flare's website, possibly related to the investigation or the cat profile picture.
  • Just Hacking Training — John Hammond's cybersecurity training platform.
  • Newsletter sign-up — John Hammond's newsletter for updates.
  • InfoSec Map — A resource for cybersecurity events.
  • CodeCrafters — A platform for learning coding, mentioned as a resource.
  • OpenVPN — A resource for hosting a VPN.
  • CyberDefenders — A platform for blue team training and SOC analyst certifications.

Concurring Sources

  • Brian Krebs' coverage — Mentioned in the video as an independent investigation on the same topic.

Contribution & Novelties

The video provides a unique, behind-the-scenes look at a real OSINT investigation, showing how a single alias can be traced to a real identity through publicly available information. It highlights the importance of threat intelligence platforms like Flare and demonstrates practical OSINT techniques. The narrative is engaging and educational, making complex cybersecurity concepts accessible.

Pour aller plus loin :

  • OSINT framework — A comprehensive collection of OSINT tools and resources.
  • Supply chain attack — Wikipedia article on supply chain attacks, relevant to the context of Team PCP’s activities.
  • GitHub Actions security — Official documentation on securing GitHub Actions workflows, which was the initial attack vector.

105 words

Radar Profile

The radar profile shows high scores in information quantity and quality, reflecting the video's rich content and credible sources. The technical level is also high, indicating a detailed walkthrough. The overall reliability is strong, though slightly lower due to the presenter's enthusiasm and the abbreviated nature of the investigation.

Reliability 7/10

💬 No comments were provided for analysis.