The Intune Hijack: How The FAD Team Wiped 200,000 Middle East Systems in 2026
⚠️ THREAT INTELLIGENCE ADVISORY: The cyber threat landscape in the Middle East has crossed a dangerous threshold in…
> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
/actor/the-fad-team/ · 1 intel report
The FAD Team is a hacktivist group that emerged in 2023, conducting web defacement and data exfiltration operations across multiple regions including the Middle East, South Asia, and Europe. The group's motivations appear to blend ideological hacktivism with opportunistic financial crime , a combination increasingly common in the contemporary hacktivist landscape where criminal and political motivations coexist within the same operational framework.
The FAD Team has claimed attacks against government portals, financial sector websites, and commercial entities, publishing defacement screenshots and alleged database dumps on their Telegram channel and affiliated dark web forums. Their targeting does not follow a clearly defined ideological pattern, suggesting opportunism and capability demonstration as primary drivers rather than a consistent political agenda.
The group's technical capabilities are assessed as moderate, utilising a combination of web vulnerability scanning tools, SQL injection frameworks, and social engineering to gain access to target systems. They have demonstrated awareness of multiple exploitation techniques and the ability to adapt their approach based on target vulnerability profiles.
The FAD Team represents a growing category of threat actor groups that occupy the ambiguous space between hacktivism and organised cybercrime , using political or ideological framing to justify operations that may simultaneously serve financial interests through the sale of stolen data or direct extortion of compromised organisations.
The FAD Team is a hacktivist banner, not a ransomware desk. Public activity is DDoS and defacement signalling, often adjacent to other volunteer crews. CyberAsia files their cards as claims unless a screenshot shows a real admin surface or a unique file hash. If a FAD card names a government portal, check the official status page before retweeting an outage.
Defenders: CDN and WAF on citizen sites. Do not open SOC major-incident process for a 20-minute homepage timeout without independent probes.
⚠️ THREAT INTELLIGENCE ADVISORY: The cyber threat landscape in the Middle East has crossed a dangerous threshold in…