groups:example_group

Tooda.sh (TOoDA)

Record ID: GRP-0001
Type: Network / Collective
Status: Inactive
Active Since: 2024


Summary

Tooda.sh, also referred to as TOoDA, is a small hacker and doxxing collective that operates primarily through the website tooda.sh and related social media accounts. The group is best known for compromising the doxxing platform Doxbin in 2024–2025, deleting or wiping user accounts, locking out administrators, and leaking a database of over 130,000 user identifiers and email addresses along with a so‑called “blacklist” of people who allegedly paid to keep their information off the site. Reporting indicates that the attack was at least partly motivated by a dispute in which Doxbin staff allegedly accused a Tooda member of being a pedophile, leading to a retaliatory breach and doxxing of Doxbin administrators.

The group’s public-facing site tooda.sh uses the slogan “We Ride at Dawn” and lists several pseudonymous members, while hosting highly controversial content including “Pedophile of the Year” lists used as smear tactics within hacker communities. Security write‑ups and breach notifications describe Tooda/TOoDA as a cybercrime group focused on doxxing, account compromise and data dumping rather than traditional ransomware or financially motivated extortion, although the Doxbin breach created significant downstream risk for victims including phishing and identity theft.


Known Members

  • Eco — Listed as a Tooda member on the public tooda.sh site.
  • Ego — Listed as a Tooda member on the public tooda.sh site.
  • emo — Listed as a Tooda member on the public tooda.sh site; also appears as “emo.rip” in attribution for the leaked Doxbin dataset.
  • user — Listed as a Tooda member on the public tooda.sh site.
  • Dante — Listed as a Tooda member on the public tooda.sh site.
  • meebop6 — Listed as a Tooda member on the public tooda.sh site.
  • Clark — Listed as a Tooda member on the public tooda.sh site.

(Only handles and roles publicly self‑attributed by the group are included; no real‑world identities are confirmed here.)


Associated Groups

  • Doxbin — Notorious doxxing platform targeted in the 2024–2025 breach attributed to TOoDA, resulting in mass user data exposure and administrative lock‑out.
  • emo.rip — Handle credited as the source that provided the breached Doxbin data to breach‑notification services, overlapping with the Tooda‑associated alias “emo.”

Timeline

  • 2024-02-12 — Breach of the doxxing website Doxbin, attributed to a group calling themselves “TOoDA,” with data later cataloged as the “Doxbin (TOoDA)” breach and publicly dumped.
  • 2024-11-30 — Registration of the domain tooda.sh, later identified as the group’s main public site and infrastructure hub.
  • 2025-02-11 — Public reporting details the conflict between Doxbin admins and Tooda members, including allegations that Tooda wiped Doxbin accounts, locked admin access, and leaked user data and administrator doxxes.
  • 2025-02-11 — Tooda‑branded social media activity (e.g., @tooda_sh) references the slogan “We Ride At Dawn,” reinforcing the link between the online persona and the tooda.sh site.
  • 2025-03-03 — WHOIS records show an update to the tooda.sh domain registration, indicating that the site and, by extension, the group’s web presence remained active.

  • Doxbin (TOoDA) data breach — Compromise and public dumping of the Doxbin user database, including approximately 136,000–136,814 user IDs, usernames and email addresses, along with a “blacklist” of individuals who allegedly paid to suppress their data on the platform.

Evidence

Ref Source Date Notes
cybernews Cybernews — “Hackers clash over Doxbin lost account access” 2025-02-11 Describes the Doxbin breach attributed to Tooda, outlines the dispute with Doxbin admins, and reports claims that Tooda wiped accounts, locked admins, and leaked user data.
cybernews Hackread — “Doxbin Data Breach: Hackers Leak 136K User Records…” 2025-02-12 Details Tooda’s claimed control over Doxbin’s backend, the deletion of accounts, admin lock‑out, and release of 136,814 IDs/usernames/emails plus a “blacklist” file.
hookphish Have I Been Pwned — “Doxbin (TOoDA)” breach entry 2025-02-13 Confirms a breach of Doxbin in February 2024 attributed to “TOoDA,” affecting about 136.5k accounts and 336k unique email addresses.
scamadviser HookPhish / RedPacket Security breach summaries 2025-02-12 / 2025-02-13 Provide breach metadata (name “DoxbinTOoDA,” breach date 2024‑02‑12, compromised account counts) and attribution to TOoDA.
linkedin LinkedIn posts on the Tooda–Doxbin conflict 2025-02-11 / 2025-02-14 Discuss Tooda’s role in the Doxbin breach, note operation via tooda.sh with the slogan “We Ride at Dawn,” and list public member handles (Eco, Ego, emo, user, Dante, meebop6, Clark).
msspalert MSSP Alert brief on retaliatory Doxbin breach 2025-02-12 Summarizes the attack as retaliation for accusations against a Tooda member and notes conflicting claims over the extent of the breach (full DB vs. admin credentials only).
hackread WHOIS / infrastructure reporting for tooda.sh 2025-03-03 (last update) Shows domain creation on 2024‑11‑30, privacy‑protected registrant (1337 Services LLC), low traffic/visibility, and generally “legit” technical configuration despite association with a threat group.
github X (Twitter) profile @tooda_sh 2025-02-11 Associates the “TOoDA” persona with the slogan “We Ride At Dawn,” reinforcing branding seen on tooda.sh and in third‑party reporting.

Notes

Record created: 2026-05-06. Last updated based on open‑source reporting available as of early 2026.

groups/example_group.txt · Last modified: by admin [Admin]