If you see the invisible

You can do the impossible

Hunting ByteToBreach: An OSINT Investigation [EN]

Disclaimer: This is an independent OSINT investigation based exclusively on publicly available information. No real-world identity is attributed in this report. The author has not been contacted or paid by any institution or authority. The purpose is to reconstruct historical digital traces and provide a clear investigative lead for the relevant authorities.

Introduction


ByteToBreach is the alias of an attacker who became widely known in Romania after compromising the ANCPI infrastructure, but has been linked to dozens of attacks around the world. I began this investigation to see whether I could help identify him by connecting publicly available information that previous investigations may have overlooked or simply viewed from a different perspective.

So far, those investigating his attacks have understandably focused on the compromised systems: how he got in, what he exploited, what data he obtained, and what technical traces he left behind. But if we focus only on those traces, we risk doing exactly what Bruce Lee warned against: concentrating on the finger and missing all that heavenly glory.

This investigation takes a different approach. Instead of trying to identify him solely through traces left at a time when he already knew he needed to hide his identity, we will go back in time, to a period before the ByteToBreach alias existed, and look for the older identities, aliases, and accounts he may have used when he had far less reason to worry about anonymity or operational security.

We will not follow the finger. We will look beyond it, where overlooked details, pieced together, may reveal the bigger picture.

Cyber Persona


A Cyber Persona is the public or operational identity an individual or group uses to present itself, communicate, and claim responsibility for its activities in cyberspace. It should not automatically be assumed to reflect the real identity behind the accounts.

ByteToBreach is no exception. A black hat, or anyone else involved in criminal activity, has every reason to build a persona that makes attribution more difficult. The concept is similar to a spy's cover identity: a coherent identity built around enough genuine details to feel natural even in unexpected situations, while still concealing the person's real identity. For that reason, such personas often mix truth with false information. ByteToBreach has publicly portrayed himself as an experienced, independent, and financially motivated attacker.
How He Wants to Be Perceived
Age 30+ Security Patch
Hacking Experience 16 years Security Patch
Religion Christian Stop Ransomware
Moral Code Avoids targets where human lives could be put at risk Stop Ransomware
Motivation Financial / No political motivation Stop Ransomware
Public Website bytetobreach.com ByteToBreach
Attributed Locations Neither Greece nor Algeria SOCRadar / KELA
Public Contact Channels Email / Telegram / Signal / Session ByteToBreach
Signature Phrase “in the grace of the Lord” Security Intelligence
ByteToBreach portrays himself as an attacker in his 30s or older, with years of experience behind him. He says he is “too old for being in groups” and claims to have been active for 16 years, spending much of that time analyzing malware and practicing in Hack The Box labs. If he started in his teens, as that timeline would suggest, his own account would place him at least in his 30s.

That claimed experience is paired with a strong religious identity and a personal moral code. When asked what values guide his decisions, he replied, “Christianity. The desire to learn”, and closed the interview with, “Stay faithful to Jesus Christ, our one true Savior and Lord”.

He says he avoids hospitals and systems where disruption could put human lives at risk. During attacks involving healthcare systems in Brazil, he claims to have blocked entire subnets to avoid interfering with patient systems. At the same time, he describes his motivation as purely financial, saying, “My main motivation is money”, “No politics” and, in reference to ANCPI, “It was financially motivated, nothing more”.

His public persona was further shaped through bytetobreach.com, presented as “Pentesting Ltd”, where victims were described as “clients” or “very angry clients”, alongside phrases such as “Let Me Harm Your Data”, “Industry-leading Threat Actor”, “stolen data” and “get hacked”.

He has responded with irony to investigations suggesting possible links to Greece or Algeria, saying that having several competing theories about his identity is actually reassuring. The same confidence is reflected in the number of public contact channels he maintains, including Proton Mail, Tuta, Gmail, Telegram, Signal and Session. While this may suggest confidence in his OPSEC, reusing the same identity across multiple platforms also creates more opportunities for correlation.

That image is reinforced further by his use of the religious phrasein the grace of the Lord” as a personal signature, including after conversations about attacks and financial negotiations.

As noted earlier, however, this persona may still contain genuine elements. One of the most effective ways to hide the truth is to mix it with false information and leave it in plain sight.

Public Accounts


Below are ByteToBreach’s confirmed public accounts.
Name Address Source
Website bytetobreach.com bytetobreach.com
Telegram @ByteToBreach33 bytetobreach.com
Telegram @ByteToBreach KELA
Telegram (former) CvHNWwEG / inesslopez KELA
Signal @ByteToBreach.33 bytetobreach.com
Session 05c2db4775cb46350f16814dfe3bfa856664f315585653e4c368af08ce50b0c31b bytetobreach.com
Ricochet vgrps2kcrwdlxr5zpnozdwtgnjgpxisftbomw5fiajtiom7tergp2kyd bytetobreach.com
X @GgsFafagas bytetobreach.com
Tuta bytetobreach@tuta.com bytetobreach.com
Outlook dodkhloyka@outlook.com bytetobreach.com
Proton Mail bytes_to_breach@pm.me DNS History
DarkForums ByteToBreach KELA
Dread ByteToBreach KELA
Pastebin ByteToBreach KELA
Spear bytetobreach RansoMonitor

Publicly Known Targets


The list below includes organizations ByteToBreach has claimed to have compromised, as well as others publicly linked to his activity. Their inclusion here should not be taken as independent confirmation that each organization was actually compromised.

View the full list of 60 targets
Name Date Sector Continent
CAC Nigeria 2026-04-14 Government Africa
CardinalStone 2026-04-01 Financial Africa
Ikeja Electric 2026-04-28 Energy Africa
NOC Ethiopia 2026-03-24 Energy Africa
Remita 2026-03-31 Financial Africa
SCB Seychelles 2025-02-05 Financial Africa
Sterling Bank 2026-03-18 Financial Africa
Altruist 2025-11-13 Telecom Asia
BroadBand Tower 2025-12-09 Telecom Asia
GSC Bank 2025-10-06 Financial Asia
ICICI Prudential 2025-11-26 Financial Asia
Interteach 2025-09-21 Financial Asia
Mobiuz 2026-02-16 Telecom Asia
Red Dot Payment 2025-11-26 Financial Asia
Haryana G. Bank 2025-10-08 Financial Asia
Uzbekistan Gov. 2026-02-02 Government Asia
Uzbekistan Airways 2025-08-20 Transport Asia
YAS Takaful 2025-10-30 Financial Asia
AlmavivA 2025-11-20 Telecom Europe
ANCPI 2026-07-14 Government Europe
Avatel 2025-09-16 Telecom Europe
CGI Sverige 2026-03-12 Telecom Europe
Cyprus Post 2025-10-02 Transport Europe
euroAtlantic 2025-09-04 Transport Europe
Eurofiber 2025-11-14 Telecom Europe
Georgia Courts / HCOJ 2026-07-20 Government Europe
Hungary Treasury 2026-07-29 Government Europe
Latvijas Valsts Meži 2026-06-23 Government Europe
MCC Italy 2025-07-18 Financial Europe
Nokia 2025-08-25 Telecom Europe
PKO Bank 2025-09-09 Financial Europe
Slavia 2026-03-09 Financial Europe
SMS Traffic 2025-10-01 Telecom Europe
stepping stone 2025-11-11 Telecom Europe
Straumann 2026-02-19 Healthcare Europe
Symbol Transport 2025-10-27 Transport Europe
Telefónica 2025-09-22 Telecom Europe
Telefónica DE 2025-09-22 Telecom Europe
Ufinet 2025-12-17 Telecom Europe
URW 2025-06-28 Real Estate Europe
Viking Line 2026-03-11 Transport Europe
FINAM 2025-08-10 Financial Europe
Anuvu 2025-09-03 Telecom North America
BD 2025-08-16 Healthcare North America
Clearwater 2025-09-10 Financial North America
Constellis 2025-11-26 Defense North America
IFX Networks 2025-12-24 Telecom North America
Involta / Ark 2025-11-26 Telecom North America
Live Nation 2025-09-04 Entertainment North America
MINSA Panama 2025-09-13 Government North America
Orange IA 2025-09-10 Financial North America
SAT Mexico 2025-12-26 Government North America
UC Berkeley 2025-07-31 Education North America
UNAM 2026-01-05 Education North America
VUMI 2026-04-13 Financial North America
CorreosChile 2025-08-07 Transport South America
Mundivox 2026-01-14 Telecom South America
Unimed M. Valença 2026-01-26 Healthcare South America
Unimed P. Grossa 2026-03-03 Healthcare South America
Valenet Unknown Telecom South America

The dates may reflect when the intrusion occurred, when ByteToBreach claimed responsibility, or when the incident was first reported publicly. If no exact date could be reliably verified, it is marked as “Unknown”.
Statistics

The earliest publicly known target linked to ByteToBreach is Seychelles Commercial Bank, with the attack documented on February 5, 2025. His public activity picked up significantly during the summer of that year: 38 entities were linked to him in 2025, with September being the most active month, accounting for 11 publicly documented cases.

Another 21 entities have been documented in 2026, including ANCPI, while the exact date could not be established for one target. The sequence of victims shows how quickly his activity expanded from a regional bank to financial institutions, telecom companies, government infrastructure, and international corporations across five continents.

Geographically, the 60 entities are distributed as follows:

Geographic distribution: Europe 24 · North America 13 · Asia 11 · Africa 7 · South America 5
By sector: Telecom/IT 18 · Financial 17 · Government 8 · Transport/Logistics 6 · Healthcare 4 · Energy 2 · Education 2 · Security/Defense 1 · Entertainment 1 · Real Estate 1

The choice of targets points to a clear pattern: ByteToBreach tends to focus on organizations that handle valuable or sensitive data, where its loss, unavailability, or public release could cause significant damage and increase the likelihood of a ransom payment.

Website


The bytetobreach.com domain was registered on August 12, 2025, at 02:03:57 UTC through Namecheap. It later became ByteToBreach’s public website, used to publish information about victims and list his contact channels. The registration date marks the beginning of his known public web presence. (Source)

Proton Mail


The Proton address directly linked to ByteToBreach was identified in the DNS history of bytetobreach.com. The SOA record contained the value bytes_to_breach.pm.me, corresponding to the address Bytes_To_Breach@pm.me. The record was documented on October 1, 2025. Because the address was published in the DNS records of his own domain, it provides the confirmed starting point for the analysis. (Source)

To establish a timeline, I examined the associated public PGP keys. Proton automatically generates a PGP key when an account is created and for each additional address added to it. The date of the original key therefore corresponds to the date the address was created, provided the key has not subsequently been replaced or manually regenerated.

Starting with the confirmed address, I identified two username patterns, ByteToBreach and BytesToBreach, across the @pm.me, @proton.me, and @protonmail.com domains. Variants with underscores are equivalent because Proton ignores underscores in email addresses. The six addresses may belong to one or more accounts. (Source 1; Source 2)
Address PGP Key Date
Bytes_To_Breach@protonmail.com April 20, 2024, 00:51:02 UTC
ByteToBreach@pm.me March 13, 2025, 16:55:52 UTC
Bytes_To_Breach@pm.me May 10, 2025, 11:35:23 UTC
ByteToBreach@proton.me June 26, 2025, 00:46:53 UTC
ByteToBreach@protonmail.com November 17, 2025, 13:54:55 UTC
Bytes_To_Breach@proton.me May 19, 2026, 23:06:00 UTC
The earliest address identified dates to April 20, 2024, nearly ten months before the first publicly known attack. The first @pm.me address appears in March 2025, marking the move to a paid Proton plan. Addresses created before the ByteToBreach identity became public are more likely to belong to him. For those created later, however, the possibility that they were registered by imitators cannot be ruled out.

Have I Been Pwned?


A check of the confirmed Bytes_To_Breach@pm.me address through Have I Been Pwned shows that it appears in data from two BreachForums breaches. The first occurred in August 2025 and exposed email addresses from user tables, posts, and private messages. The address appears again in the BreachForums Version 5 breach from March 2026, alongside usernames and Argon2 password hashes. (Source 1; Source 2)

Its first appearance falls between the PGP key generated on May 10, 2025 and the address being published in the SOA record on October 1, 2025, providing another useful point in the timeline.

The BreachForums database was later made publicly available, allowing the relevant authorities or independent researchers to search for this address and correlate the associated record with its username, registration date, IP address, and other internal data. The leak contains 323,988 accounts, of which 70,296 were associated with public IP addresses, while most of the remaining records contained the local address 127.0.0.9. If the record associated with Bytes_To_Breach@pm.me contains a public IP address, it could provide an additional attribution lead and open a new direction for the investigation. (Source)

Key Findings


The data presented above is more than a collection of technical details. Together, it helps establish a timeline of ByteToBreach’s digital footprint and distinguish accounts created before the ByteToBreach identity became public from those that may have been registered later by imitators.
  • April 20, 2024: the earliest Proton address associated with this alias family appears: Bytes_To_Breach@protonmail.com, nearly ten months before the first publicly known attack.
  • February 5, 2025: the first known attack is documented, targeting Seychelles Commercial Bank.
  • March 13, 2025: the first email address using the shorter @pm.me domain appears.
  • May 10, 2025: the PGP key for the later-confirmed address bytes_to_breach@pm.me is generated.
  • August 2025: the same address appears in the compromised BreachForums data, and on August 12, the bytetobreach.com domain is registered.
  • September 2025: 11 entities are publicly claimed, marking a sharp increase in publicly visible activity.
  • October 1, 2025: the bytes_to_breach@pm.me address is published in the domain’s SOA record, directly confirming its association with ByteToBreach.
  • March 2026: the address appears again in the BreachForums Version 5 breach.
What makes these dates important is their sequence. Taken together, they create a traceable history of the ByteToBreach identity, allowing us to follow the emergence of the alias and its associated identifiers over time. Traces that predate the alias becoming widely known are more valuable for attribution because they are less likely to have been created by imitators. These chronological markers can also help identify other accounts created around the same time, or shortly beforehand, while ruling out accounts that are either far too old or appeared later and may belong to unrelated individuals.

First Relevant Lead


From this point on, the investigation moves beyond what has already been documented publicly and focuses on my own OSINT findings. From the beginning, I conducted my own information gathering to independently verify the available information rather than relying solely on conclusions reached by others.

Because some of the accounts were relatively easy to identify, I initially assumed they had already been disclosed in previous investigations. While writing this article, however, I found that some had only been mentioned publicly, while the actual identifiers were kept in reports available upon request. In practice, the public articles also served as showcases for the commercial services offered by those companies.

Among the accounts referenced in previous investigations was an Instagram profile associated with the alias. This account, @ByteToBreach, became the first relevant lead in my own investigation.

The Instagram account was created in October 2024, six months after the Bytes_To_Breach@protonmail.com address appeared on April 20, 2024, and almost four months before the first publicly known attack against Seychelles Commercial Bank on February 5, 2025. This places the account squarely within the period when the ByteToBreach identity was beginning to take shape, making it highly unlikely that it was created later by an imitator, fan, or someone else trying to associate themselves with the alias.

This timing is also relevant from an OPSEC perspective. When the account was created, the actor could not have known how prominent the alias would become or how closely it would later be scrutinized. An Instagram profile with only a handful of followers may have seemed like just another account in his online footprint, making it less likely that strict OPSEC measures were in place. By contrast, an account created after the attacks became public would have been set up with the knowledge that his activity was being investigated, giving him far more reason to avoid any detail that could lead back to his real identity.

Instagram: Achilles' Heel?


Username           : @ByteToBreach
Created            : October 2024
Country            : India
Followers          : 14
Following          : 17
Posts              : 5
Instagram ByteToBreach At first glance, the account appears to offer very little: just a handful of posts and almost no activity. Others have almost certainly found it before, and with so little content to work with, it would have been easy to dismiss and move on. But this is exactly where the first important clues begin to emerge, if you know where to look and pay attention to the small details.
Account Based: India

The first detail that caught my attention was in About this account, where Instagram lists Account based in: India. This is not a self-reported location or something the user added to the profile. It is determined automatically by Instagram based on the account’s activity. More importantly, the account had existed since 2024, long before ByteToBreach became internationally known through his attacks and subsequent media coverage. At the time, he had not yet attracted the level of attention that would later make strict OPSEC necessary, so there was little reason to deliberately conceal his location when logging into this account.
Following List

ByteToBreach’s following list further reinforces the initial clue from Account based in: India. He follows only 17 accounts, 9 of which are Indian. Most of the remaining accounts are internationally known names in cybersecurity or law enforcement, such as the CIA, FBI, HackerOne, and The Hacker News. In other words, once those global accounts, which could be followed by almost anyone interested in cybersecurity, are set aside, the remaining accounts are overwhelmingly connected to India.

Indian accounts: @cyber_detectives, @farah_hawaa, @bitten_tech, @prajwalynx, @securewithtechies, @akashblackhat, @1nv_illusion_cbr, @chaudhary_hardik_yadav, @cyber.tnt.

Other accounts: @cia, @thehackernews, @raw, @thecybersecurityhub, @hacker0x01, @fbimostwanted, @fbi, @0day.
Hashtags

Most of the hashtags used across the five posts are fairly generic, but three stand out: #ezsnippet, linked to a well-known Indian tech creator and used in the first two posts; #diwali, another direct reference to Indian culture; and #money, which appears in the very first post. The last one becomes more interesting in hindsight, given the financial motivation ByteToBreach would later describe in interviews. None of these hashtags proves anything on its own, but the first two add further weight to the clues already seen in Account based in and the list of accounts he follows.
Content Analysis

The first post, published on October 31, 2024, gives us the explanation behind the ByteToBreach alias itself. The author describes his journey with the phrase “from Byte(s) to Breach”, which also helps explain the ByteToBreach / BytesToBreach variations seen earlier: a progression from the fundamentals to more advanced security concepts. At the same time, he presents himself as someone just starting out, eager to learn and publicly document his progress toward his goal of becoming a cybersecurity professional.

The same message appears again just three days later, in the second post, published on November 3, 2024, where he puts it even more explicitly: “Starting my hacking journey” and “Learning in Public”. Both statements reinforce the impression that, at the time, he was still at an early stage of his technical development.

Things become more interesting in the fourth post, published on November 15, 2024. ByteToBreach demonstrates and tests a basic ransomware script written in Python, directly from an Android phone. The footage does not tell us whether he wrote the code himself or was using an existing project. Beyond the technical side, however, the video reveals a few seemingly insignificant details: the terminal contains the reference On One Piece Ep:- 948, while the phone keyboard uses an image of Roronoa Zoro, a character from the same series. This gives us a clear indication that the author is an anime fan, a detail that will become far more relevant later.

In the fifth post, also published on November 15, 2024, ByteToBreach gains access to the website of Sourashtra College in India using what would now be considered a fairly basic technique, the kind of thing almost anyone new to hacking might try to learn early on. More interesting than the technique itself is the choice of target: a local college in India with no obvious international significance. This is a fairly common pattern in unauthorized hacking: people often start with targets that feel close or familiar, then gradually broaden their scope as they gain experience and confidence.

ByteToBreach - Aniyoe Account (extracted from video) If you were wondering whether I had forgotten about the third post, published on November 14, 2024, I had not. I deliberately saved it for last. Not because it is the least interesting, but for exactly the opposite reason: ByteToBreach was kind enough to leave behind a detail that saves us a great deal of work.

After spending several minutes trying to make out what was visible in the video, whose quality leaves a lot to be desired, a simple zoom combined with adjustments to the contrast and brightness was enough to make all the information I needed readable.

That is when I realized that ByteToBreach was using a tool called Zphisher in his demonstration, showing how a fake Instagram login page could be created for phishing. Zphisher is an open-source tool that automates the creation and hosting of cloned login pages for various services and captures the credentials entered into them. To demonstrate it, he needed an account whose login details he could enter and display, so using one he controlled would have been the natural choice.

The timing matters here. In November 2024, ByteToBreach was still unknown to the media, had not yet gained attention through the attacks he would later claim, and was openly describing himself as someone at the beginning of his hacking journey. He had no way of knowing what impact his actions might have in the months or years ahead, or how important the small details he left behind might one day become.
[+] Successfully Hosted at : http://127.0.0.1:8080

[-] Waiting for Login Info, Ctrl + C to exit...

[+] Login Info Found !!

[+] Account : aniyoe.cc
[+] Password : 991191551714

[+] Saved in : auth/usernames.dat

[-] Waiting for Next Login Info, Ctrl + C to exit...


Victim's POV (Right): aniyoe.cc
Instagram Stories
@chaudhary_hardik_yadav
@drj7zz / @dj_.7z
@_utkarsh_panaskar_5556
And that is how I arrived at another alias he had used before ByteToBreach: aniyoe.cc. This time, we are no longer dealing with an assumption based on coincidences, similar usernames, or other OSINT correlations. The connection comes directly from ByteToBreach himself, in his own video, where he uses aniyoe.cc as part of the demonstration. And from here, things become genuinely interesting.

Another relevant detail from the same video is the appearance of @chaudhary_hardik_yadav, one of the 17 accounts also followed by @ByteToBreach. This gives us the first shared social connection between the two identities.

First Update


After analyzing the Instagram account, we can now add several details to the Cyber Persona outlined at the beginning of this article. Unlike his later public statements, these findings come directly from traces ByteToBreach left behind in 2024:

• The @ByteToBreach account was created in October 2024, before the alias became publicly known and before the first known attack.
Account based in: India, the accounts he follows, and several other details in his content consistently point to India.
• He is an anime fan, a seemingly minor detail that will become relevant later in the investigation.
• One of the first targets he publicly showcased was a local college in India, well before his activity expanded to international organizations.
• His first post explains the origin of the ByteToBreach alias and also provides context for the Byte(s)ToBreach variations identified earlier.
• The technical content from this period shows tools and techniques typical of someone still learning, reinforcing his own 2024 statements: “Starting my hacking journey” and “Learning in Public”.
• In one of those demonstrations, he gives us the next lead himself: aniyoe.cc.

Who Is Aniyoe?


Instagram

The first thing to note is that the username aniyoe.cc, visible in the demonstration posted on @ByteToBreach, is no longer used in that form. The account still exists, but its username has been changed four times and is currently @_aniyoe_cc.

This also reveals a pattern that will appear again later in the investigation: the use of different combinations of . and _ in usernames. The same habit appears across other accounts later linked to Aniyoe, giving us another way to connect them. Username          : @_aniyoe_cc
Created           : November 2022
Country           : India
Username changes: 4
Followers         : 33
Following         : 4
Posts             : 19 (8 visible)
Instagram Aniyoe - Realistic Photos The content on @_aniyoe_cc is almost entirely focused on anime. By itself, that may not seem particularly significant, but it matches a detail already seen on @ByteToBreach. In the ransomware demonstration, the message On One Piece: EP. 948 🥂 appears on screen, revealing the exact episode he was watching, while his phone keyboard features Roronoa Zoro, a character from the same series. The same interest in anime therefore appears under both identities, giving us another link between ByteToBreach and Aniyoe.

Just like @ByteToBreach, Instagram lists “Account based in: India” for @_aniyoe_cc as well. We now have two connected identities, created at different times, both independently pointing to the same country. This further strengthens the possibility that the person behind ByteToBreach is based in India.

The posts themselves reveal even more. Some still contain tags pointing to older usernames, while the profile bio explicitly identifies another account as “Main AC: @aarex_cc”. A wider network of connected accounts and aliases begins to emerge around Aniyoe, with several of them following the same username patterns seen earlier. Some of these accounts, perhaps even all four followed by @_aniyoe_cc, may have been controlled by the same person. For this investigation, however, we only need to follow the traces that lead somewhere useful.

What makes these clues especially valuable is the age of the account. @_aniyoe_cc dates back to November 2022, almost two years before ByteToBreach emerged as a public identity. At the time, that persona did not even exist, and the user had no reason to expect that these accounts, or the connections between them, might one day become relevant to an investigation into ByteToBreach.

This post reveals two more usernames previously used by the same account, allowing us to reconstruct the sequence of changes: aniyoe.ccaniyoe_.cc_aniyoe__aniyoe_cc, its current username. The same post also tags @aarex_cc, the account identified in the profile bio as “Main AC”.
Pinterest

The same post includes 7 images of anime characters placed over photos of real-world locations. That immediately raised a question: did Aniyoe find those background photos online, or did he take them himself? If they were his own photos, they could reveal where he was at the time.

Instagram - Aniyoe - Pinterest Picture For the analysis, I chose the image containing the most useful details for OSINT geolocation. I looked at the surrounding urban environment, infrastructure, weather, vegetation, road signs, and visible commercial elements, each of which could help narrow down the location step by step.


Element Geolocation Value
Bus stop The design of the bus stop, together with the surrounding buildings, infrastructure, and street layout, could potentially help identify the street or even the exact location.
Winter / snow The weather conditions can rule out regions where this type of climate would be unlikely and help narrow down both the location and the time of year.
McCrispy ad The graphics, colors, and overall style can be compared with McDonald's campaigns from different countries and periods, providing both geographic and chronological clues.
Bollard Its distinctive design could help identify the manufacturer or model and, from there, the countries, cities, or organizations where it is commonly used.
Trees / vegetation The tree species and the way they are used in urban landscaping can point to certain climate zones or local landscaping practices.
Road signs The shape, design, and placement of the signs, along with the direction of traffic, can quickly eliminate many countries and narrow down the search area.
The bollard was the easiest clue to identify. It appears to be a Weebol, a model commonly used across the UK, including Scotland. The road layout and sign placement also pointed to left-hand traffic, while the McCrispy ad matched a campaign launched in the UK in 2022. The tree behind the bus stop also appears to be a Himalayan cedar, with roughly 70% confidence, another species commonly found in UK urban landscaping.

The clues pointed to the UK, but they still were not enough to pinpoint the exact location. So I tried a different approach: remove the anime character from the image, reconstruct as much of the original background as possible, and run it through a reverse image search. I used Magic Eraser to clean up the image, then searched it with Google Lens.

That worked. I found the exact location, but also discovered that the photo itself came from Pinterest.com. So what initially looked like a promising lead to Aniyoe/ByteToBreach’s location turned out to be a dead end. To make sure, I ran another one of the 7 images through Google Lens. This time I found the same image online with the anime character already added, confirming that even the edit was not his work.

Still, the Pinterest connection opened up another possibility. If Aniyoe had found the first image there, the Pinterest account he used might have been among the users who interacted with it before he posted it on Instagram. The image had 123 pins and more than 40 saves, so I filtered out every interaction that happened after Aniyoe published his post.

That left roughly 15 accounts. If Pinterest was indeed where he found the image, one of those accounts could have been his. Even a completely unrelated-looking username could have led to another account, alias, or useful piece of information.

I decided not to repeat the entire process with the second image. It would have meant spending a lot of time on a lead with a relatively low chance of going anywhere, especially since his Pinterest username could have been completely random. I kept it as a checked lead and moved on to other parts of the investigation that offered stronger, more concrete connections.
X / Twitter
Display name      : aniyoe.cc
Username          : @1aniyoe1
Created           : April 2024
Country           : India
Connected via     : India Android App
Username changes: 1
Following         : 94
X - Aniyoe.cc Once I had identified an older alias, the next question was obvious: if Aniyoe had been using it before ByteToBreach, where else had it appeared? Searching for the same identifier across other platforms led me to an account on X.

The account fits neatly into the timeline we have built so far. It was created in April 2024, when the Aniyoe alias was already in use, but several months before the @ByteToBreach account appeared. Its display name is aniyoe.cc, and the account has gone through only one username change. The previous username is no longer visible, but it may have been @aniyoe.cc itself or a closely related variation.

More importantly, the same geographic pattern appears again. X lists both Account based in: India and Connected via India Android App. This gives us yet another pre-ByteToBreach account pointing directly to India, reinforcing what we had already seen on Instagram.

The account follows 94 profiles. Many are global accounts, but among the rest there are once again numerous profiles connected to India. On its own, that would not mean much. Combined with the location information X assigns to the account and the other traces identified so far, however, it becomes another piece of the same pattern.

I did not spend much time analyzing the rest of the profile because the most useful clue was somewhere else. When starting the password recovery process for @1aniyoe1, X partially reveals the email address associated with the account:

X - Aniyoe.cc - Recover Password
That gives us a new identifier directly tied to the Aniyoe.cc account: an email address beginning with ra and using a .com domain. X masks the remaining characters, so we cannot determine the full address at this stage, but it gives us another useful detail to carry into the next round of correlations.
HackerOne

HackerOne - ByteToBreach If he was really just getting started and learning cybersecurity at the time, having a HackerOne account would make perfect sense. It is one of the best-known bug bounty platforms, so I searched for the alias and found the aniyoe profile.

The account was created in June 2024, right in the middle of the timeline we have been following, and it uses the exact alias aniyoe. There is no notable bug bounty activity on the profile, but it gives us something far more useful: the display name is Ranveer (aniyoe).

This is the first clue we have found that could point to the real identity behind the alias. Ranveer may be his first name, but for now it remains only a hypothesis until we can match it with information from another independent source.

There is one important point to keep in mind. There is no public evidence that ByteToBreach ever used the aniyoe alias for attacks or other malicious activity. When he was using that username, he would have had much less reason to hide or falsify personal information than he did later, after ByteToBreach became associated with criminal activity. At the time, aniyoe appears to have been little more than an alias tied to his interest in anime.

It gets more interesting when we compare this with the X/Twitter account found earlier. The recovery page for @1aniyoe1 reveals an email address beginning with ra: ra**********@*****.com. The HackerOne profile, independently, gives us the name Ranveer. The two pieces fit together and come from separate platforms, making Ranveer a stronger candidate for the first name of the person behind the older alias.
XVideos

Years ago, I sometimes used a less conventional method to correlate real email addresses and identify possible password reuse: compromising websites in the adult industry. The reasoning was simple. Pornography attracts users from virtually every background, and the databases I accessed included everything from @gov and @mil addresses to corporate and personal email accounts belonging to people across a wide range of industries. At the time, the chances of finding useful correlations this way were surprisingly high.

Following the same logic, I checked whether the older aniyoe alias had ever appeared on platforms in that space. It had. I found an aniyoe profile on XVideos, created on November 24, 2020. This profile adds several new details: the user identifies as male, lists India as his country, and gives his age as 32. It is also the oldest trace of the aniyoe alias I have found so far.

What makes this especially relevant is how the account was found. I did not start with a profile from India and work backward to a similar username. I searched for the highly specific alias aniyoe, and once again, the account tied to that alias points to India. The profile also dates back to 2020, about four years before ByteToBreach appeared, and there is nothing on it linking the account to hacking. At that point, there would have been little reason to build a fake identity around the alias. For the first time, however, we also get an age: 32, giving us another useful detail when trying to build a profile of the person behind it.

Alias Ecosystem


Following the accounts identified so far reveals an entire ecosystem of aliases that predates ByteToBreach. The connections between them are not based only on similar usernames or mutual follows. The profile bios themselves repeatedly point to another account as Main Ac: @username, allowing us to reconstruct the chain:

@ByteToBreach@_aniyoe_cc@aarex_cc@_azaanedits_@_.azaan._

All of these accounts belong to the same Indian online ecosystem, are connected to one another, and revolve around the same interest in anime. The username pattern first noticed with Aniyoe also keeps reappearing: periods and underscores are repeatedly added, removed, or moved around. We see it across @_aniyoe_cc, @aarex_cc, @_azaanedits_, and @_.azaan._, suggesting a recurring habit in the way these aliases were created and modified. At this point, we are no longer looking at just one older alias, but at a sequence of older online identities used before ByteToBreach appeared.

The azaanedits alias also appears outside Instagram, including on Fiverr and Freelancer. In these cases, however, any connection to ByteToBreach should be treated only as a hypothesis based on reuse of the same username.

The Fiverr profile is not verified, uses the name Azaan Hakim, lists Pakistan as its location, and mainly offers video editing and YouTube automation services. The account does date back to 2024, which fits the timeline we have established so far. However, Azaan/Azan is a relatively common name, so the username match carries much less weight than a distinctive alias such as aniyoe. For that reason, I would put this connection at roughly 50/50: interesting enough to document, but nowhere near strong enough to claim that the person behind the profile is ByteToBreach.

Linguistic Analysis


If the evidence presented so far is still not enough to support the hypothesis that ByteToBreach is Indian, we can take the analysis one step further: linguistic analysis.

About a week ago, I gave an interview to Observator / Antena 1 in which I shared my assessment of the attacker’s profile. Afterwards, I asked for the original Signal conversation between the reporter and ByteToBreach. The reason was simple: analyzing text published on websites, prepared statements, or interviews paraphrased by the media is very different from analyzing original messages written spontaneously during a conversation.

For this analysis, I used techniques from forensic linguistics, including linguistic profiling, Native Language Identification (NLI), L1 interference, error analysis, lexical, syntactic, and phraseological analysis, as well as elements of stylometry. In practical terms, I looked at how he structures sentences, the vocabulary he uses, recurring expressions, and the kinds of patterns that can emerge when someone thinks in their native language and carries those structures over into English.

A simple example can be drawn from Romanian. „De-abia aștept să vină sfârșitul de săptămână” might spontaneously be rendered in English as „I can't wait for the week end to come”. To a native speaker, certain constructions may sound incorrect or unnatural, even though they may feel perfectly normal to someone speaking a different variety of English or carrying patterns over from their first language.

That is exactly what emerged from the conversation. The patterns I observed are consistent with Indian English and with the kind of linguistic influence commonly seen in Indian speakers. Some phrases that might sound grammatically incorrect or unusual to a British or American speaker are found in Indian English, a variety of English shaped by a different linguistic, historical, and cultural context.

One particularly interesting example is the phrase ByteToBreach uses as a signature: „in the grace of the Lord”. A native speaker would be far more likely to say „by the grace of the Lord”, while the former construction can also be found in India, including in religious and institutional contexts.

This also connects with another part of the persona he presents. ByteToBreach says he is Christian and repeatedly uses Christian references. Although Christians make up only around 2.3% of India’s population, there are regions with substantial Christian communities, particularly Nagaland, Mizoram, and Meghalaya in the northeast, as well as Kerala and Tamil Nadu in the south.

Linguistic analysis alone cannot establish someone’s nationality, just as religion cannot pinpoint where a person lives. What makes the result significant here is that it provides an independent line of support for the same direction already suggested by the other traces. The older accounts, social ecosystem, and associated activity all pointed toward India, and the way ByteToBreach uses English spontaneously is consistent with that same hypothesis.

Who Is ByteToBreach?


Possible First Name

Ranveermedium-high confidence. The name appears on the HackerOne profile linked to the older aniyoe alias and is indirectly supported by the X account @1aniyoe1, where the password-recovery hint begins with “RA...”. More importantly, both traces predate his publicly known hacking activity, when there was far less reason to build an elaborate false identity or deliberately hide his first name. The name cannot be confirmed with certainty, but the context makes it a significantly stronger lead.
Country

Indiaextremely high confidence. Every relevant geographic clue identified throughout the investigation points to the same country, including information from accounts created before the ByteToBreach identity became public.
Nationality

Indianextremely high confidence. This is supported by the repeated geographic links to India, the ecosystem of older accounts, and the linguistic analysis. So far, none of the other directions examined has produced evidence of comparable strength pointing to another nationality.
Possible Regional Origin

Nagaland, Mizoram, Meghalaya, Kerala, or Tamil Nadulow-medium confidence. This hypothesis comes from combining the strong indications toward India with his stated religious identity and repeated use of Christian language. Confidence remains limited because the religious element could also be part of a deliberate attempt to mislead others about his background.
Age

20–30 years oldmedium confidence. The XVideos profile associated with the Aniyoe alias lists an age of 32, but that figure alone is not reliable enough to establish an exact age. Taken together, the available clues support a broader estimated age range instead.
Known Aliases

ByteToBreach, Aniyoe / aniyoe.cc, Aarex / aarex.cc, Azaan, azaanedits. Several of these aliases also appear in variations created by adding or repositioning “.” and “_”. The same username pattern appears repeatedly throughout the account ecosystem identified in this investigation, including around the ByteToBreach identity itself.
Online Activity

At least 6 years — the earliest traces linked to the Aniyoe alias identified in this investigation date back to 2020, roughly four years before ByteToBreach emerged publicly.
Hacking Experience

At least 4 years — estimated. His public claim of 16 years of experience is not supported by the traces identified so far. His own material from 2024 explicitly shows him in a learning phase. His rapid technical development afterward is entirely plausible, especially with the rise of AI tools, provided they are used as an extension of existing knowledge rather than a substitute for it.
Religion

Christianhigh confidence. This assessment is based on his own statements, his answers in interviews, and his repeated use of Christian references and religious sign-offs. The fact that this behavior appears consistently across different contexts makes it less likely that the religious element was introduced purely as misdirection.
Moral Code

He claims that he does not attack medical systems or infrastructure where disruption could directly put human lives at risk. If that boundary is genuine, it represents one of the few observable moral limits in his choice of targets. One possible explanation could be personal exposure to social environments where access to healthcare is especially critical, although that remains strictly a psychological hypothesis.
Motivation

Primarily financialvery high confidence. His public journey begins with a stated desire to learn and eventually become a cybersecurity professional, but his later behavior and choice of targets point clearly toward financial gain. The earlier image of a future security professional who might eventually move into legitimate work is not supported by his current actions. Based on the behavior observed so far, the profile is clearly black hat, and his compromises of infrastructure in Uzbekistan, Nigeria, Romania, and other countries have caused, or had the potential to cause, significant damage.
Capabilities

High, but difficult to assess in isolation. It is not possible to determine with certainty whether he operates entirely alone or occasionally receives help from a small group during certain stages of an attack. It is also unclear how much of the process relies on traditional methods and how much is assisted by AI. The observable pattern, however, suggests the use of public exploits for initial access, followed by attempts to escalate privileges and gain as much control as possible over the compromised infrastructure.
Emotional Intelligence / OPSEC

Poor relative to the level of risk involved. Running a public website on his own domain, maintaining numerous public contact channels, being almost constantly available, and responding quickly to people who reach out all suggest a genuine need for attention and validation, rather than simply an attempt to maintain a public persona. At the same time, those behaviors create more traces and increase his overall exposure. For a black hat involved in compromising government infrastructure, including systems with national-security relevance, the amount of voluntary exposure compared with the legal risk he is taking points to limited operational self-control, regardless of his technical ability.
Operational Objective

His main objective appears to be obtaining databases and source code from compromised organizations. These assets give him several ways to pressure victims: threatening to delete, corrupt, or publish their data, searching private source code for additional vulnerabilities, and, in the case of critical infrastructure, creating disruptions that can affect an entire sector or national service. If direct pressure fails to produce the financial outcome he wants, the stolen data can also be offered for sale on black markets, where the publicity surrounding his attacks may make it easier to attract potential buyers.
Interests

Hacking, AI/ML, video editing, anime/manga, and chess. These interests are drawn from activity and accounts associated with his older online identities. There may be other interests that overlap with these areas, but the information identified so far is not strong enough to support them with confidence.

Linked Accounts


Name Address
Instagram - ByteToBreach @bytetobreach
Instagram - Aniyoe @_aniyoe_cc
Instagram - Aarex @aarex_cc
Instagram - Azaan Edits @_azaanedits_
Instagram - Azaan @_.azaan._
X / Twitter - ByteToBreach @GgsFafagas
X / Twitter - Aniyoe @1aniyoe1
Facebook - Aniyoe aniyoe.cc
HackerOne - Aniyoe aniyoe
HackerOne - Aarex aarexcc
XVideos - Aniyoe aniyoe
Medium - ByteToBreach @bytetobreach
Hugging Face - ByteToBreach bytetobreach
Chess.com - ByteToBreach bytetobreach
Cloudflare Community - ByteToBreach bytetobreach
Pastebin - Aarex aarex
YouTube - Aarex @aarexcc
Proton Mail bytestobreach@protonmail.com
Proton Mail bytetobreach@pm.me
Proton Mail bytes_to_breach@pm.me
Proton Mail bytetobreach@proton.me
Proton Mail bytetobreach@protonmail.com
Proton Mail bytes_to_breach@proton.me
Fiverr - Azaan Edits azaanedits
Freelancer - Azaan Edits azaanedits
There may be other accounts that have not yet been identified and use the same aliases or variations involving “.” and “_”.

Saved Evidence


This archive contains video recordings and screenshots of the accounts identified during the investigation, preserving their state at the time they were documented in case they are later deleted or modified.
Name Info
Archive Download
SHA-256 019910ec19fffe163d92b16e8616d011b6f163e88f109f80a7ee9785b12d6a12

Irresponsible Attribution


KELA publicly linked the ByteToBreach alias to Zakaria Mahdjoub from Oran, Algeria, based on data from infostealer-infected systems, browser cookies, and other digital artifacts, describing ByteToBreach as “likely operated by Zakaria Mahdjoub”.

Adding the word “likely” does not make the underlying problem disappear. A private cybersecurity company can uncover leads and develop attribution hypotheses, but it is not in a position to officially establish the real identity of a threat actor. In my view, publishing the full name of a real person under these circumstances is neither professional nor ethical, especially when getting that attribution wrong can seriously damage someone’s reputation, career, and personal life.

You can see how quickly that distinction disappears once the information starts circulating. “Likely operated by Zakaria Mahdjoub” soon became, across different publications: Reuters handled the attribution responsibly. It made clear that the claim came from KELA and explicitly stated that Reuters had not been able to independently verify it.

There is a technical problem as well. IP addresses, cookies, infostealer records, and linked accounts can all be useful leads, but they do not necessarily identify the person behind an attack. They may come from compromised systems, shared accounts, other members of the same group, or even artifacts deliberately planted to send investigators in the wrong direction. When dealing with an actor who takes OPSEC seriously, none of these indicators is enough on its own to establish who was actually behind the keyboard.

The DarkSignal case is even more concerning. DarkSignal linked ByteToBreach to a real person in Greece, Anastasios Vasileiadis, and then tied a series of vague indicators to his public profile: allegedly connected accounts, Greek references, a .gr domain, and even extremely common things such as Kali Linux, WordPress, software repositories, or simply working in cybersecurity. Vasileiadis himself says that these kinds of elements were used to connect him to ByteToBreach.

But there is no certainty that the accounts in question were personally operated by ByteToBreach. They could have been shared, used by other members of a group, compromised, or deliberately created as false trails. The remaining indicators are so common across the cybersecurity community that they do little, if anything, to distinguish one individual from another.

Despite that uncertainty, the attribution began spreading publicly through phrases such as “partially deanonymized” and later “an identifiable Greek individual living in Thessaloniki”.

The consequences are no longer hypothetical. Anastasios Vasileiadis categorically denies any connection to ByteToBreach. He says the association was built on “indirect digital correlations” and states that he has begun legal proceedings and filed a civil lawsuit against those responsible for the publication: Public statement by Anastasios Vasileiadis

In my investigation, the situation is different. Some of the connections come from traces left by ByteToBreach himself that lead directly to older aliases and digital identities, rather than from similarities or generic indicators alone. Even so, once those leads narrowed the search down to a small number of real people, I stopped.

From there, the competent authorities can reproduce the methodology described in this investigation and use the legal and technical tools available to them to confirm or rule out those leads. I would only consider it appropriate to publicly associate a real name with ByteToBreach once that identity has been officially confirmed.

Throughout this investigation, I tried to look at the problem from the attacker’s point of view: when would he have taken OPSEC seriously, when would he have had little reason to do so, and which clues might he have deliberately manipulated to throw investigators off track? That line of thinking led me to older traces, aliases, and digital identities that had been overlooked in previous investigations and may still be useful to the authorities. I was never interested in being the first to put a real name out there just to make the story more sensational, especially when getting it wrong could seriously harm someone who may have had nothing to do with the attacks.

Conclusions


When you put all of the findings in this investigation together, one thing stands out: ByteToBreach was far more exposed before he became ByteToBreach. Which naturally raises the question: how has he managed to remain unidentified for this long, despite leaving so many traces behind?

I am not referring to the technical traces left during the attacks themselves, when anonymity and OPSEC had clearly become important to him. I am referring to something much more valuable: the traces he left before he had any reason to hide. Old accounts, reused aliases, personal interests, and social connections all date back to a time when he likely never imagined that, years later, someone would try to piece that history back together.

In this article, I focused mainly on the findings rather than walking through every step of the reasoning behind each lead. I also relied on my own past experience to understand how an attacker might think, how misdirection can be used, what kinds of mistakes are made, and, most importantly, how someone behaves once OPSEC becomes a priority compared with the traces they left behind before it ever mattered.

This is an independent OSINT investigation that I started on my own initiative a few days ago. No institution or authority contacted me or paid me to conduct it.

An official investigation has access to something I do not. Authorities can legally request data associated with the accounts identified here, including registration and login IP addresses, email addresses, access history, and other available identifiers. More importantly, many of these accounts do not use the ByteToBreach identity. They are tied to older aliases such as Aniyoe, Aarex, and Azaan, used before his activities gave him the same reason to protect his identity. Those older accounts may still contain real IP addresses or other identifiers that could connect this network of aliases to a real person.

I did not stop because I ran out of leads. Almost every account identified here opens up other avenues, and following those connections further could lead to much more precise information. I stopped because the purpose of this investigation was to show how much can be uncovered by looking past the ByteToBreach identity and following the traces that existed before it.

Perhaps that is the most important takeaway: in security and investigations, hands-on experience and a different perspective can reveal things that are easy to miss when the focus stays entirely on the incident itself. Sometimes, to see the full picture, you simply have to stop looking at the finger.

This is where I chose to stop. For anyone trying to uncover the real identity and the rest of the digital trail, the leads are there. The authorities also have the legal tools needed to continue once publicly available information is no longer enough.

Happy hunting, boys!

TinKode// Infamous Ethical Hacker

No comments:

Post a Comment