Record ID: GRP-0001
Type: Network / Collective
Status: Inactive
Active Since: 2024
Tooda.sh, also referred to as TOoDA, is a small hacker and doxxing collective that operates primarily through the website tooda.sh and related social media accounts. The group is best known for compromising the doxxing platform Doxbin in 2024–2025, deleting or wiping user accounts, locking out administrators, and leaking a database of over 130,000 user identifiers and email addresses along with a so‑called “blacklist” of people who allegedly paid to keep their information off the site. Reporting indicates that the attack was at least partly motivated by a dispute in which Doxbin staff allegedly accused a Tooda member of being a pedophile, leading to a retaliatory breach and doxxing of Doxbin administrators.
The group’s public-facing site tooda.sh uses the slogan “We Ride at Dawn” and lists several pseudonymous members, while hosting highly controversial content including “Pedophile of the Year” lists used as smear tactics within hacker communities. Security write‑ups and breach notifications describe Tooda/TOoDA as a cybercrime group focused on doxxing, account compromise and data dumping rather than traditional ransomware or financially motivated extortion, although the Doxbin breach created significant downstream risk for victims including phishing and identity theft.
(Only handles and roles publicly self‑attributed by the group are included; no real‑world identities are confirmed here.)
2024-02-12 — Breach of the doxxing website Doxbin, attributed to a group calling themselves “TOoDA,” with data later cataloged as the “Doxbin (TOoDA)” breach and publicly dumped. 2024-11-30 — Registration of the domain tooda.sh, later identified as the group’s main public site and infrastructure hub. 2025-02-11 — Public reporting details the conflict between Doxbin admins and Tooda members, including allegations that Tooda wiped Doxbin accounts, locked admin access, and leaked user data and administrator doxxes. 2025-02-11 — Tooda‑branded social media activity (e.g., @tooda_sh) references the slogan “We Ride At Dawn,” reinforcing the link between the online persona and the tooda.sh site. 2025-03-03 — WHOIS records show an update to the tooda.sh domain registration, indicating that the site and, by extension, the group’s web presence remained active. | Ref | Source | Date | Notes |
|---|---|---|---|
| cybernews | Cybernews — “Hackers clash over Doxbin lost account access” | 2025-02-11 | Describes the Doxbin breach attributed to Tooda, outlines the dispute with Doxbin admins, and reports claims that Tooda wiped accounts, locked admins, and leaked user data. |
| cybernews | Hackread — “Doxbin Data Breach: Hackers Leak 136K User Records…” | 2025-02-12 | Details Tooda’s claimed control over Doxbin’s backend, the deletion of accounts, admin lock‑out, and release of 136,814 IDs/usernames/emails plus a “blacklist” file. |
| hookphish | Have I Been Pwned — “Doxbin (TOoDA)” breach entry | 2025-02-13 | Confirms a breach of Doxbin in February 2024 attributed to “TOoDA,” affecting about 136.5k accounts and 336k unique email addresses. |
| scamadviser | HookPhish / RedPacket Security breach summaries | 2025-02-12 / 2025-02-13 | Provide breach metadata (name “DoxbinTOoDA,” breach date 2024‑02‑12, compromised account counts) and attribution to TOoDA. |
| LinkedIn posts on the Tooda–Doxbin conflict | 2025-02-11 / 2025-02-14 | Discuss Tooda’s role in the Doxbin breach, note operation via tooda.sh with the slogan “We Ride at Dawn,” and list public member handles (Eco, Ego, emo, user, Dante, meebop6, Clark). | |
| msspalert | MSSP Alert brief on retaliatory Doxbin breach | 2025-02-12 | Summarizes the attack as retaliation for accusations against a Tooda member and notes conflicting claims over the extent of the breach (full DB vs. admin credentials only). |
| hackread | WHOIS / infrastructure reporting for tooda.sh | 2025-03-03 (last update) | Shows domain creation on 2024‑11‑30, privacy‑protected registrant (1337 Services LLC), low traffic/visibility, and generally “legit” technical configuration despite association with a threat group. |
| github | X (Twitter) profile @tooda_sh | 2025-02-11 | Associates the “TOoDA” persona with the slogan “We Ride At Dawn,” reinforcing branding seen on tooda.sh and in third‑party reporting. |
Record created: 2026-05-06. Last updated based on open‑source reporting available as of early 2026.