Tooda.sh (TOoDA)

Record ID: GRP-0001
Type: Network / Collective
Status: Inactive
Active Since: 2024


Summary

Tooda.sh, also referred to as TOoDA, is a small hacker and doxxing collective that operates primarily through the website tooda.sh and related social media accounts. The group is best known for compromising the doxxing platform Doxbin in 2024–2025, deleting or wiping user accounts, locking out administrators, and leaking a database of over 130,000 user identifiers and email addresses along with a so‑called “blacklist” of people who allegedly paid to keep their information off the site. Reporting indicates that the attack was at least partly motivated by a dispute in which Doxbin staff allegedly accused a Tooda member of being a pedophile, leading to a retaliatory breach and doxxing of Doxbin administrators.

The group’s public-facing site tooda.sh uses the slogan “We Ride at Dawn” and lists several pseudonymous members, while hosting highly controversial content including “Pedophile of the Year” lists used as smear tactics within hacker communities. Security write‑ups and breach notifications describe Tooda/TOoDA as a cybercrime group focused on doxxing, account compromise and data dumping rather than traditional ransomware or financially motivated extortion, although the Doxbin breach created significant downstream risk for victims including phishing and identity theft.


Known Members

(Only handles and roles publicly self‑attributed by the group are included; no real‑world identities are confirmed here.)


Associated Groups


Timeline



Evidence

Ref Source Date Notes
cybernews Cybernews — “Hackers clash over Doxbin lost account access” 2025-02-11 Describes the Doxbin breach attributed to Tooda, outlines the dispute with Doxbin admins, and reports claims that Tooda wiped accounts, locked admins, and leaked user data.
cybernews Hackread — “Doxbin Data Breach: Hackers Leak 136K User Records…” 2025-02-12 Details Tooda’s claimed control over Doxbin’s backend, the deletion of accounts, admin lock‑out, and release of 136,814 IDs/usernames/emails plus a “blacklist” file.
hookphish Have I Been Pwned — “Doxbin (TOoDA)” breach entry 2025-02-13 Confirms a breach of Doxbin in February 2024 attributed to “TOoDA,” affecting about 136.5k accounts and 336k unique email addresses.
scamadviser HookPhish / RedPacket Security breach summaries 2025-02-12 / 2025-02-13 Provide breach metadata (name “DoxbinTOoDA,” breach date 2024‑02‑12, compromised account counts) and attribution to TOoDA.
linkedin LinkedIn posts on the Tooda–Doxbin conflict 2025-02-11 / 2025-02-14 Discuss Tooda’s role in the Doxbin breach, note operation via tooda.sh with the slogan “We Ride at Dawn,” and list public member handles (Eco, Ego, emo, user, Dante, meebop6, Clark).
msspalert MSSP Alert brief on retaliatory Doxbin breach 2025-02-12 Summarizes the attack as retaliation for accusations against a Tooda member and notes conflicting claims over the extent of the breach (full DB vs. admin credentials only).
hackread WHOIS / infrastructure reporting for tooda.sh 2025-03-03 (last update) Shows domain creation on 2024‑11‑30, privacy‑protected registrant (1337 Services LLC), low traffic/visibility, and generally “legit” technical configuration despite association with a threat group.
github X (Twitter) profile @tooda_sh 2025-02-11 Associates the “TOoDA” persona with the slogan “We Ride At Dawn,” reinforcing branding seen on tooda.sh and in third‑party reporting.

Notes

Record created: 2026-05-06. Last updated based on open‑source reporting available as of early 2026.