Skip to content
← Back to FarmoriaFarmoria incident report · updated 26 September 2026
Jump to a report section
PUBLIC INCIDENT REPORT

Cross Incident Threat Actor Assessment

Consolidated forensic and open source findings from the Farmoria and Rokstats incidents

Assessment: Farmoria telemetry and the supplied Rokstats evidence identify the same hollowarc. Discord account and reuse of Farmoria linked infrastructure. The cross incident association is assessed with high confidence. The equivalence of the public claimant HPCane and the HollowArc operator remains a moderate confidence persona assessment.
FarmoriaResidential IPs, OAuth accounts, VPN sessions, meshvision.xyz lead
HollowArc identityDiscord ID 1070712235770527744 and verified account record
RokstatsExclusive vulnerable endpoint access and HPCane claim
Investigating partiesFarmoria and Rokstats
Report date24 September 2026 · updated 26 September 2026
ReferenceIR-2026-0921
Executive assessment

One actor cluster links both incidents

The strongest evidence is the reuse of a stable Discord identity, supported by two AT&T residential addresses observed at Farmoria. A later Rokstats log cross-check confirmed HollowArc activity from 107.206.22.143; Rokstats investigators independently reported use of 68.90.146.47 without prior knowledge of its Farmoria connection. The surrounding aliases, domain, e-mail addresses, and public profiles expand the cluster.

Report scope. Farmoria investigated the activity on its own service; Rokstats separately investigated its incident and shared findings for cross-incident analysis. This report brings those findings together with an interactive workbench derived from Farmoria's completed forensic acquisition. The workbench exposes chronology, supporting and competing evidence, request-volume context and bounded triage leads; secret values and unrelated personal data remain excluded.
Overall judgment. The same operator, or a very closely coordinated operator with access to the same account and residential connections, conducted the Farmoria reconnaissance and subsequent Rokstats activity. This conclusion is High confidence. The statement that HPCane and HollowArc are the same person is Moderate confidence.
9,063HTTP requests reviewed
18Accounts in the actor pool
3,689Error reports accepted
0Confirmed data breaches

Key judgments

  1. The Farmoria activity was deliberate black box testing and abuse tool development. The operator performed ordered reconnaissance, object identifier enumeration, billing probes, upload tests, account rotation, and ticket and error-report flooding. The observed requests show no clear sign of advanced technical knowledge; the route probing followed publicly known wordlists and easily detectable patterns.
  2. Farmoria controls prevented unauthorized object access, code execution, and payment abuse. Other users' objects returned only refusal or validation responses. Accepted files were inert test images. The incident caused minor service load and outbound support e-mail amplification, with no confirmed breach.
  3. The Farmoria account hollowarc. is directly tied to 68.90.146.47. A second account, dbquery., was registered from 107.206.22.143, later used through the same VPN session as the active testing, and carried the e-mail domain meshvision.xyz. A later cross-check of Rokstats logs also confirmed hollowarc. activity from 107.206.22.143 during that separate incident.
  4. The supplied Rokstats record resolves to the same Discord identity. It records username hollowarc., Discord ID 1070712235770527744, and verified e-mail [email protected]. The record was last seen on 16 September 2026.
  5. HollowArc was the only account reported to have accessed the vulnerable Rokstats endpoint. That exclusive access makes the account central to the later incident. The HPCane claim and reuse of Farmoria-linked addresses support close coordination, but do not prove the two personas belong to one person.
  6. D***** M****** is a moderate-confidence person-of-interest lead. The lead warrants further investigation, but no stable identifier independently ties this person or a public profile to the operator.

Business meaning

Observed effects

Farmoria received automated requests that triggered 176 outbound e-mails and abusive ticket creation. The actor also enumerated routes and assets already exposed by the public web application. No service degradation, unauthorized customer data access, admin access, code execution, or payment benefit was confirmed.

Forward risk

The actor demonstrated a repeatable account rotation method and then appeared in a later incident. Blocking individual IPs will slow reuse, while address aware registration controls, per-address rate limits, and identity provider reporting provide the durable response.

Interactive evidence workbench · forensic expansion 24 September 2026

One chronology, with proof and uncertainty kept separate

Explore the incident sequence, test each finding against its supporting evidence and alternatives, and review archive-wide leads without promoting automated triage into attribution.

—origin requests parsed across retained access logs
—retained nginx evidence window
80 / 80manifested files independently re-hashed
0missing, size-mismatched or hash-mismatched entries
Evidence closure. All log paths identified by the forensic context and permission-denial records were acquired. The final manifest SHA-256 is 383d1ce77db1b9703d22a39280fe2feb4c61835bd60df602d02f132defe83e27. Active files remain qualified point-in-time captures; nothing after the recorded acquisition boundaries is claimed.

Synchronized incident timeline

Select a marker for evidence, analytic weight and the caveat that limits the claim.

observed attack or impact identity, linkage or response contextual or inferred activity evidence boundary

Chronology summary. The retained record begins 26 August; a rehearsal occurs 31 August; residential staging spans 1–5 September; the principal Farmoria test and abuse window occurs 5 September; a probable victim recovery follows on 7 September; return and containment activity occurs 9 September; the supplied Rokstats record is last seen 16 September; cross-incident containment follows 21 September; forensic acquisition closes 23 September.

Retained origin traffic by day

Archive-wide volume provides context, not attribution. Select a bar for the exact count.

Findings explorer

Filter the judgments; every row includes the competing explanation or evidence gap.

Signals that were easy to underweight

These change detection and response priorities even where they do not change attribution.

31 August was a rehearsal

The earlier VPN session shared the later ordered target list, limiter testing and naming pattern. Treating it as generic scanning would miss five days of preparation.

Benign-looking staging mattered later

Pricing and build retrieval on residential addresses looked harmless until the same paths became account anchors and resurfaced in the cross-incident record.

The account pool contains victim evidence

The 7 September recovery/deletion sequence means provider identities must be protected and remediated, not published wholesale as actor IOCs.

The full archive extends visibility by one day

Origin evidence begins 26 August, not 27 August as previously summarized. No known-actor event was promoted from that extra day, and earlier or Cloudflare-blocked activity still cannot be disproved.

Attack-surface outcomes

Attempt, observed result and residual gap are kept in separate columns.

SurfaceTargetObserved actionOutcomeConfidence
Rokstats evidence desk

The follow-on incident, separated by evidence type

The supplied account record is directly observed, and a later Rokstats log cross-check confirmed HollowArc activity from 107.206.22.143. Reuse of 68.90.146.47 and exclusive endpoint access remain reported findings. Exploit mechanics remain unresolved without the full endpoint request records.

1stable Discord provider ID shared across both incidents
2Farmoria residential paths linked to Rokstats; one log-confirmed
1account reportedly accessing the vulnerable endpoint
0raw Rokstats endpoint requests available in this case set
Evidence itemObserved or reported valueWeightMeaning and limitSource class
Current Rokstats conclusion. The exact Discord ID and two reused residential paths support the same operator cluster at high confidence. The precise exploit request and impact cannot be independently reconstructed until the Rokstats access, application and relevant database records are preserved and supplied.

Application-log corroboration

Aggregate-only scan of dated Laravel, support, billing and Stripe logs; no raw messages or secret values are embedded.

—dated application log files analyzed
—application-log lines classified
—application-log analysis window
—known-address text occurrences for correlation review
CategoryMatching log linesUse

Cross-incident relationship register

Stable identifiers carry more weight than aliases, location or an IP address in isolation.

EntityRelated entityWeightBasis

Archive-wide triage leads

High-signal route and automation heuristics from the complete retained nginx set. These are investigation leads, not confirmed HollowArc activity.

AddressWindowRequests flaggedHigh-signal reasonsRepresentative paths
Do not operationalize raw triage as attribution. Internet-facing services receive commodity scanning, authorized tools and normal high-volume users. A lead should be promoted only after request sequencing, authentication context, outcomes and independent identifiers converge. Probable victim addresses 200.63.47.185 and 200.63.46.202 remain excluded.

Host-level Internet background

Authentication, firewall and ban telemetry is separated from the HollowArc cluster unless an independent identifier overlaps.

—host-log lines analyzed
—failed SSH authentication events
—UFW block or audit events
—known HollowArc address occurrences in this host-log set
SignalSource addressEventsAssessment
Farmoria host-log result. The scan counted generic SSH and firewall attack traffic, but none of the six known actor/probable-victim addresses appeared in the targeted Farmoria authentication, firewall, kernel, syslog, audit or fail2ban text logs. This bounded result concerns Farmoria's host-attack background, not the later Rokstats incident: a separate Rokstats log cross-check confirmed HollowArc using the Farmoria-linked address 107.206.22.143. The host-log search does not cover traffic stopped elsewhere or all binary journal content.

Known infrastructure in the full retained window

Observed counts and path families are generated from the acquired access-log rotations.

AddressRoleFirst / last seenRequestsDominant flagged behavior
Cross incident linkage

The stable account is the central bridge

Follow the account from Farmoria to Rokstats. The account and address links are separate from HPCane's later claim about the Rokstats endpoint.

LinkAssessmentBasis
hollowarc. to FarmoriaConfirmedFarmoria OAuth record tied the account to 68.90.146.47 and Discord ID 1070712235770527744.
hollowarc. to Rokstats recordConfirmedExact username and Discord ID in the account record shared by Rokstats, with a provider verified e-mail.
Farmoria to Rokstats activityHighSame stable identity, log-confirmed HollowArc use of 107.206.22.143 in the later incident, independently reported use of 68.90.146.47 before its Farmoria connection was known, and reported exclusive vulnerable endpoint access.
meshvision.xyz to dbquery.ConfirmedThe Farmoria account used [email protected]. This confirms use of a domain e-mail address, not domain ownership.
meshvision.xyz to HollowArcLow · indirectA reported BreachForums appearance adds an indirect online association. No domain ownership or control has been verified.
HPCane to HollowArcModerateHPCane claimed the Rokstats attack, while HollowArc was reportedly the sole account accessing the vulnerable endpoint. A false claim or coordination remains possible.
Arcane to the incidentsInconclusiveNo stable identifier, infrastructure, or observed server action connects Arcane. We do not currently suspect involvement, but the available evidence cannot rule it out.
Unified timeline

Farmoria preceded the Rokstats follow on

Times from Farmoria are shown in CEST. Database timestamps were converted from UTC in the source forensic report. Rokstats record times remain UTC where stated.

31 Aug 2026 05:07 to 05:51 CEST

First Farmoria working session

173.245.217.11 performed reconnaissance, framework and admin path guessing, public library enumeration, login limiter testing, and targeted e-mail guessing. The session shared the later toolchain and naming pattern.

1 Sep 2026 21:32 CEST

First residential connection

107.206.22.143 opened Farmoria pricing content.

4 Sep 2026 18:51 to 19:08 CEST

HollowArc account created at Farmoria

68.90.146.47 registered hollowarc., loaded the frontend build, and reviewed plans. No active probing occurred in this session.

5 Sep 2026 04:44 CEST

Second residential account created

107.206.22.143 registered dbquery. with [email protected].

5 Sep 2026 05:02 to 07:00 CEST

Active Farmoria test and abuse script development

108.171.110.79 carried out route discovery, object identifier walks, billing probes, upload tests, rapid account creation, ticket flooding, and error-report flooding.

5 Sep 2026 05:29 to 06:01 CEST

Residential and VPN sessions linked

The dbquery. account created from 107.206.22.143 became active through 108.171.110.79.

5 Sep 2026 06:36 to 06:37 CEST

Fifteen OAuth accounts created in 69 seconds

The account pool enabled per-user rate limit evasion.

5 Sep 2026 06:40 to 07:00 CEST

Error-report flood accepted

4,919 requests were sent and 3,689 returned 204 without a 429. The endpoint returned no data and production logging discarded the accepted report bodies.

7 Sep 2026 19:22 to 19:34 CEST

Probable identity owner deleted one account

A different user on a Mexican mobile network used Google sign-in, viewed privacy information, reset a password, and deleted an account created in the burst. This supports the assessment that many OAuth identities were compromised.

9 Sep 2026 09:31 CEST

Return check from 107.206.22.143

The address fetched static assets only, consistent with checking whether the site still loaded.

9 Sep 2026 19:02 CEST

Farmoria containment

Seventeen accounts and four addresses were banned for multi-account abuse.

After the Farmoria session

Rokstats follow-on activity

A later Rokstats log cross-check confirmed HollowArc activity from 107.206.22.143. Rokstats investigators also independently identified 68.90.146.47 in their incident and reported that HollowArc alone accessed the vulnerable endpoint. The persona HPCane later claimed the attack.

16 Sep 2026 23:23:46 UTC

Rokstats account record updated and last seen

The account record shared by Rokstats for hollowarc. carries this update and last-seen timestamp.

21 Sep 2026 09:18 CEST

Farmoria HollowArc account banned

User 203 was banned after the cross-organization tip linked the account to the subsequent incident.

Farmoria findings

Reconnaissance progressed into automated abuse testing

Farmoria's retained request logs show a rehearsal, two account signups from residential connections, and a two-hour VPN session that progressed from route testing to account rotation and support and error-report flooding. The testing exposed scaling weaknesses but did not produce confirmed cross-tenant access or code execution.

Farmoria recorded hollowarc. signing up from 68.90.146.47 and dbquery. signing up from 107.206.22.143. The dbquery. account then appeared in the active VPN session. Rokstats separately found the same HollowArc Discord ID, confirmed later account activity from 107.206.22.143, and independently reported use of 68.90.146.47. The earlier rehearsal and other rotated accounts are linked by behavior and session records, not by a direct HollowArc login from every address.

Observed entity relationship map

Technical attack chain

Phase and time (CEST)Actor actionTechnical result
Rehearsal
31 Aug, 05:07-05:51
From 173.245.217.11, the operator requested marketing pages, robots.txt, sitemaps, authentication routes, /api/user, /health, public library records, developer paths, admin paths, and common Laravel tooling. The session issued 1,692 requests and 497 POST /login attempts.Developer and sensitive paths returned 403, 404, or 405. Of the login posts, 324 failed CSRF handling, 97 were rate limited, and 76 reached real credential validation; none authenticated.
Residential staging
1-5 Sep
107.206.22.143 first viewed pricing and later registered dbquery.. 68.90.146.47 registered hollowarc., downloaded 444 frontend assets, and reviewed plans. The dbquery. account used [email protected].Two AT&T residential connections established the accounts and exposed the frontend route and feature structure before the active VPN session.
Route discovery
5 Sep, 05:02-05:29
From 108.171.110.79, curl tested OAuth providers, referrals, /admin, Nova, Horizon, Telescope, Pulse, log-viewer APIs, storage, exports, WebAuthn, impersonation, automation, command-chain, and account-request routes.Protected tooling stayed unavailable. Responses were predominantly 403, 404, 405, 419, or 422. One WebAuthn request returned the incident's only 503.
Object and billing tests
5 Sep, 05:24-05:50
The operator walked governor, session, export, account-health, bot, worker, configuration, and marketplace-slot identifiers, including slots 1-200. Coupon validation, checkout, referral, and a forged Stripe webhook were also tested.Roughly 270 object-oriented requests produced no unauthorized 200 response. Other users' objects remained inaccessible, and no coupon, subscription, referral, or payment benefit was created.
Attachment tests
5 Sep, 06:02-06:18
The operator sent a malformed upload, targeted a ticket belonging to another user, uploaded a six-byte GIF, tried an unsupported type, and then stored a 70-byte 1×1 PNG.The cross-user ticket returned 404, the unsupported type was rejected by content sniffing, and the accepted GIF and PNG were inert. No executable content or web shell was stored.
Account pool assembly
5 Sep, 06:36:23-06:37:32
Fifteen Discord accounts were registered in 69 seconds. Across the session, sixteen accounts completed 102 OAuth round trips from the same VPN address.Registration applied no address-based delay, challenge, or rate limit. The operator acquired enough accounts to multiply limits enforced per user.
Ticket script verification
5 Sep, 06:02-07:00
Twenty-four tickets used labels such as “abuse test,” “ticket flood script test,” “script fix verification,” and “single account isolate.” At 06:54, fifteen fresh accounts each created a ticket, uploaded the same PNG, and closed the ticket in a timed sequence.Single-account throttling generated 25 refusals, while rotation through fresh accounts permitted the scripted series. The workflow generated 176 outbound support e-mail events.
Error-report flood
5 Sep, 06:40-07:00
The account pool sent 4,919 requests to POST /client-errors at roughly 460 requests per minute.3,689 requests returned 204 and none returned 429. The endpoint returned no response data; accepted report bodies were discarded at the production log level.
Return and containment
9-21 Sep
107.206.22.143 returned for static assets on 9 September. Farmoria banned seventeen pool accounts and four addresses that day, then banned hollowarc. after the cross-organization notification on 21 September.The static-only return is consistent with a post-incident availability check. Administrative containment stopped the known accounts and access paths.

Access paths and their limits

AddressNetwork and roleObserved activity and cross-incident link
173.245.217.11Netprotect consumer VPN exitEarlier rehearsal session: 1,692 requests, reconnaissance, login testing, and targeted guessing.
107.206.22.143AT&T broadband; likely residential accessAt Farmoria: pricing reconnaissance, dbquery. registration, and a later return check; that account crossed to the active VPN session. A separate Rokstats log cross-check confirmed later hollowarc. account activity from this address.
68.90.146.47AT&T US residential rangeAt Farmoria: hollowarc. registration, 444 frontend asset requests, and plan views. Rokstats investigators independently reported use of this address in their incident.
108.171.110.79Netprotect consumer VPN exit6,687 requests and all active exploitation tests, account rotation, ticket creation, uploads, and error-report flooding.
200.63.47.185
200.63.46.202
ALTAN Redes Mexican mobile carrierProbable legitimate identity owner. The behavior supports lifting blocks on these addresses.

What the shared provider tells us. ARIN registers both 107.206.22.143 and 68.90.146.47 to AT&T. The reverse-DNS naming for 107.206.22.143 is consistent with consumer broadband, making residential-style access likely for that address. AT&T serves many subscribers, so the shared provider does not show that the same person, household, or subscription used both connections. The account and log matches carry the cross-incident link. These network lookups establish neither a location nor whether either connection was shared or used as a proxy. See S14.

Farmoria identity and network joins

Observed joinWhy it mattersConfidence
68.90.146.47 → hollowarc.The residential address created the exact account later present in the Rokstats evidence, with stable Discord provider ID 1070712235770527744.Confirmed
107.206.22.143 → dbquery.The second residential address created the account using [email protected], connecting the attack pool to an e-mail address at that domain without establishing domain ownership.Confirmed
dbquery. → 108.171.110.79The same account created from the residential address was authenticated during the active VPN testing session between 05:29 and 06:01.Confirmed
108.171.110.79 → account poolAll rapid Discord registrations, ticket-script activity, uploads, and the error flood originated from this VPN exit during the two-hour session.Confirmed
hollowarc. → Rokstats accountThe exact Discord provider ID appears in both services' account records.Confirmed
107.206.22.143 → hollowarc. at RokstatsThe later Rokstats log cross-check confirmed use of the Farmoria-linked address by the HollowArc account.High
68.90.146.47 → hollowarc. at RokstatsRokstats investigators independently reported use of the Farmoria signup address before its Farmoria connection was known.High · reported
hollowarc. → Rokstats endpointRokstats reported HollowArc was the only account to access its vulnerable endpoint; full request-level evidence is not included here.High · reported

Tool and behavior fingerprints

The active session combined curl/8.17.0, curl/8.21.0, Chrome 152, and a truncated browser user-agent. More distinctive than any single string is the ordered behavior: public route mapping, Laravel tooling probes, object-ID walks, dummy addresses such as <purpose>[email protected], timed OAuth loops, self-describing ticket names, one-ticket-per-account rotation, and a final single-account control run. This sequence supports correlation if it reappears in later server logs.

Techniques and results

TechniqueWhat happenedOutcome
Route and debug discoveryFramework, admin, developer, health, log viewer, Telescope, Pulse, storage, and webhook paths were tested.All sensitive routes returned 403, 404, 405, or validation errors.
Credential guessingDummy e-mail patterns and names harvested from a public library were turned into targeted login attempts.No successful login. Rate limiting stopped repeated guesses, though one customer's exact address was inferable from the display name.
Object identifier enumerationAbout 270 requests named governors, sessions, exports, health objects, automation rules, bot objects, and marketplace slots.No unauthorized 200 response. Object-level access control held.
Billing and entitlement probesCoupon, checkout, referral, and forged webhook requests were attempted.No coupon, subscription, referral, or payment benefit.
Upload testsA bare GIF, one unsupported type, and sixteen identical 1x1 PNGs were submitted.The GIF and PNGs were inert. The unsupported file was rejected by content sniffing before storage. No code execution or web shell.
Rapid OAuth registrationFifteen Discord registrations completed in 69 seconds, with 102 OAuth round trips.No address based registration limit, delay, or challenge applied.
Ticket flood developmentTickets labelled "abuse test", "spam vector test", "ticket flood script test", and "script fix verification" were created and closed.Per-account limits were bypassed by rotating through the account pool. Support received 176 outbound e-mail events.
Error-report flood4,919 requests hit POST /client-errors; 3,689 were accepted at about 460 per minute.The per-user limit scaled with the account pool. Responses contained no data and accepted bodies were not retained at production log level.
QuestionFindingBasis
Unauthorized customer data read?No evidenceEvery tested object owned by another user was refused. Large legitimate pages still require a code review of their page properties.
Admin or debug access?NoEvery attempt returned 403 or 404.
Payment or entitlement abuse?NoAll coupon, checkout, webhook, and referral attempts failed.
Code execution or malicious file?NoOnly inert images were stored; content sniffing rejected the alternate file type.
Service degradation?MinorOne 503 occurred, with no recorded outage.
Activity outside the web application?No evidenceNo matches in SSH, firewall, mail, bot-gate, origin-pull, drop-box, or canary logs across four hosts.
Identity pool caution. The sixteen rapidly used Discord identities likely include unrelated victims. One owner later recovered and deleted an account. Those identities should be reported to the provider as compromised and should not be attributed to the HollowArc operator as civil identities.
Tactics, techniques, and procedures

Observed activity maps to reconnaissance, access, evasion, and impact techniques

The mapping below applies MITRE ATT&CK terminology to the observed Farmoria and Rokstats behavior. A technique assignment describes the procedure that was observed or attempted; it does not imply that the technique succeeded or produced a breach.

ATT&CK techniqueObserved procedureAssessment
T1595.002
Vulnerability Scanning
Ordered route enumeration, status-code comparison, developer and sensitive-path probes, object identifier walking, and billing, upload, and webhook tests against the public Farmoria application.Confirmed Reconnaissance and vulnerability discovery.
T1585.001
Social Media Accounts
Discord identities were used to create and rotate OAuth-backed Farmoria accounts. Fifteen registrations occurred in a 69-second burst and were then used in the coordinated ticket workflow.High ATT&CK analogue for account infrastructure used in the attack.
T1078
Valid Accounts
Authenticated OAuth sessions and multiple valid application accounts were rotated to continue testing after per-account throttling.Confirmed Valid identities were used; ownership of every provider account is not attributed.
T1090
Proxy
The operator moved from residential AT&T access paths to NetProtect consumer VPN exits for the rehearsal and active testing sessions.Confirmed Infrastructure concealment and access-path rotation.
T1110.001
Password Guessing
The rehearsal recorded 497 POST requests to /login and targeted guessing behavior. Request bodies were not retained, so the exact credential values cannot be reconstructed.Moderate Attempted authentication testing; no successful credential validation was confirmed.
T1190
Exploit Public-Facing Application
Farmoria received structured object, billing, upload, and workflow abuse tests. In the later Rokstats incident, HollowArc was reportedly the only account to access the vulnerable public endpoint.High Public application exploitation behavior; Rokstats impact remains limited by the missing raw request log.
T1499.004
Application or System Exploitation
The account pool sent 4,919 requests to POST /client-errors, generated ticket traffic, and triggered 176 outbound support e-mails.High observed behavior Application-layer resource and workflow amplification occurred, but no sustained outage or confirmed availability loss was observed.
Interpretation boundary. ATT&CK is used here as a common language for the observed procedures. Application-specific behavior does not always map perfectly to enterprise endpoint techniques, and no technique should be read as proof of access or impact beyond the evidence stated above.
Farmoria account records

Farmoria account sequence and technical joins

The supplied Farmoria data contains 18 account records in one confirmed attack cluster. Their shared access paths, near-simultaneous creation, OAuth cadence, and coordinated abuse behavior establish the relationship. Two handles were clearly selected by the actor; the legitimate ownership of the remaining Discord identities is separate and may involve compromised or borrowed accounts.

Attribution boundary. All 18 records are related to the same attack workflow at Confirmed or High confidence. The same VPN address, a 69-second registration burst, shared request timing, and coordinated ticket, upload, and error-report activity establish common control during the incident. This does not prove that each legitimate Discord owner participated. hollowarc. and dbquery. carry the strongest direct actor linkage; record R-11 is assessed as a probable victim whose identity was used.
Account-record context. The records below show account use in the incident workflow. Legitimate provider-account owners may be unrelated to the operator.
Complete portal-username sequence. hollowarc.; dbquery.; luis62yeh; nntien1010; aishaaaaaaaaaaa_; kautiz.; yutaakina; la_jeta.de_.tu.tia3; jawad.ff.official_21722; dapwn_91734; [pseudonymised probable-victim account]; arman7398; sms_47; ryford185; beat85mx2421; larbi6874; faycal5430; moxnster.

Why the records form one cluster

Shared behaviorObserved evidenceAssessment
Common access pathThe rotating identities authenticated and acted through 108.171.110.79. The dbquery. account bridged its residential registration address to that active VPN session.Confirmed
Creation cadenceFifteen Discord-backed Farmoria accounts were registered from 06:36:23 through 06:37:32 CEST, a 69-second burst consistent with one automation loop.Confirmed
OAuth cadenceSixteen accounts completed 102 OAuth round trips from the same VPN address during the active session.Confirmed
Coordinated actionsThe accounts created tickets, uploaded the same 70-byte PNG, closed tickets in account order, and contributed to the POST /client-errors flood.High common control
Shared dispositionSeventeen cluster accounts were banned for multi-account abuse on 9 September; hollowarc. was banned after the cross-organization notification on 21 September.Confirmed response

Farmoria incident account records

Verbatim evidentiary content. The R-05 e-mail address is reproduced exactly as stored, including offensive language. It is an account identifier from the forensic record and does not reflect report language or an attribution to the legitimate provider-account owner.

Registration and technical correlation fields

All Farmoria registration timestamps are CEST. Short times in the source table occurred on 5 September 2026.

Personal and public-profile leads

The incident account sequence above preserves the technical joins. Public aliases, personal contact pivots and profile identifiers have been withheld from this public edition while the D***** M****** lead remains unconfirmed.

Rokstats investigation findings

The later endpoint activity reuses the Farmoria identity cluster

The available Rokstats evidence identifies the account, the two residential access paths, and exclusive access to the vulnerable endpoint. It does not include the complete server request log, endpoint path, request body, or response data, so the report distinguishes the confirmed account linkage from the still-unresolved exploit impact.

Technical sequence supported by the supplied evidence

Time or orderObserved eventTechnical interpretation
14 Jun 2026
23:00:57 UTC
The supplied application record created hollowarc. and records the first login at the same time. The OAuth profile carries Discord ID 1070712235770527744 and a provider-verified e-mail.The account existed before either investigated attack and provides a stable identity anchor independent of display-name reuse.
After the 5 Sep Farmoria sessionA later Rokstats log cross-check confirms hollowarc. activity from 107.206.22.143. Rokstats investigators independently reported 68.90.146.47 in the later activity.Both addresses were already tied to account creation at Farmoria. The confirmed 107.206.22.143 match links the access path directly to the same account in the later incident.
Rokstats attack windowHollowArc was reportedly the only account that accessed the vulnerable endpoint.Exclusive endpoint access makes the account action the strongest technical attribution fact in the Rokstats evidence. The missing raw log prevents independent reconstruction of method, payload, status code, and returned data.
After endpoint accessThe persona HPCane claimed responsibility for the Rokstats attack. Arcane produced no stable identifier or infrastructure match.The claim is consistent with the exclusive HollowArc access, supporting a moderate-confidence persona link. It remains weaker than the account and network evidence.
16 Sep 2026
23:23:46 UTC
The supplied account record was updated and last seen.The record confirms continued presence after the Farmoria incident and is consistent with the reported follow-on order.
FieldObserved valueAssessment
Account namehollowarc.Exact match to the Farmoria OAuth account.
Discord provider ID1070712235770527744Stable identifier and strongest record-level bridge.
Provider verified e-mail[email protected]Directly recorded in the OAuth profile and top-level account record.
Record created and first login14 Jun 2026 23:00:57 UTCPredates the Farmoria activity.
Updated and last seen16 Sep 2026 23:23:46 UTCPostdates the Farmoria session and aligns with the reported follow-on sequence.
MFA and localeMFA enabled; en-USAccount settings only. They do not establish the operator's location.
Credential fieldsOAuth access and refresh token fields presentValues deliberately omitted. Treat the source file as a secret, restrict access, and revoke or rotate credentials.
Application record and role6a2f32a9dcbe089d00311f5f
66e8ff7aa75b70702c49fe0a
Internal account and role references preserved for server-side correlation.
Account and authorization stateActive; not super-administrator; balance 0; tokens earned 0; tokens spent 0; no governor profiles; no kingdom accessNo elevated application role or in-app asset activity appears in the supplied record.
Discord profile flagsDiscriminator 0; public flags 256; account flags 256; premium type 0; no global name, clan, or primary guildProvider profile metadata. These values are useful for record matching but do not identify the human operator.
Application preferencesPreferred language en; decimal mark .; no thousands separator; virtual-kingdom and payment-sync flags falseStored application settings only.
Consent and referral stateAge confirmation false; referral credited falseNo affirmative league-age confirmation or credited referral in the supplied record.
Avatar cache artifactSHA-1 6727d9d3601c1f1cf256f7df082291d07b235418
discord:1070712235770527744:a_afd3887fe7192777c78b1b7a39ca0fd9
WebP, 4,782 bytes; updated 16 Sep 2026 00:51:05 UTC
Stable cached artifact for lawful cross-record comparison. Discord banner reference: a_2ec9465ff2e314c89bcf9d9dcb6104cf.

Cross-server connection analysis

ConnectionEvidence across the serversAssessment
Stable account identityFarmoria and the Rokstats record share exact username hollowarc. and Discord ID 1070712235770527744.Confirmed
Residential address reuse68.90.146.47 created hollowarc. at Farmoria; 107.206.22.143 created the linked dbquery. account. HollowArc use of 107.206.22.143 in the later Rokstats incident was confirmed by log cross-check; 68.90.146.47 reuse remains reported.High
SequenceFarmoria's active testing ended 5 September. The supplied Rokstats evidence places the endpoint incident afterward, and the account remained present through 16 September.High
Exclusive vulnerable-endpoint accessRokstats investigators identified HollowArc as the only account to access the endpoint associated with their incident.High, pending raw-log preservation
Claimed personaHPCane claimed the Rokstats attack; the endpoint account was HollowArc. No provider ID, e-mail, or network record directly joins the two names.Moderate
ArcaneNo unique account identifier, address, domain, or server action connects Arcane to either technical record. We do not currently suspect involvement.Inconclusive
Cross-incident technical judgment. The same online identity and the same two residential access paths appear in both incidents, after Farmoria recorded deliberate reconnaissance and automated abuse testing. This supports a High confidence assessment that the incidents belong to the same operator cluster. A complete Rokstats server-log extract is still required to determine the exact exploit request and impact.
Data minimization. The source export lists 112 Discord communities and unrelated account metadata. Those details were excluded because they do not improve incident attribution and would expose third parties.
Attribution assessment

Account attribution is stronger than person attribution

The evidence reliably identifies accounts, addresses, and an online persona cluster. It does not establish a verified legal identity or exact residence. The table keeps those questions separate.

Analytic questionJudgmentConfidenceAlternative explanation
Did the same online identity appear in both incidents?Yes. The exact hollowarc. account and Discord ID link the records.ConfirmedNone that fits the stable provider ID.
Did the same operator likely control the activity?Yes, or a very closely coordinated operator shared the account and residential connections.HighCredential sharing or account compromise could let another person operate the identity.
Is HPCane the HollowArc operator?Likely, based on the claim and HollowArc exclusive endpoint access.ModerateThe claim may be false, exaggerated, or made by a collaborator.
Is Arcane linked?No observed link; Arcane is not currently suspected.InconclusiveNew evidence could change this assessment.
Does the D***** M****** lead identify the operator?There is an investigative lead, but no stable technical identifier joins this person to the attack activity.Moderate leadAccount sharing, misleading public profiles, and unrelated name matches remain possible.
Does HollowArc control meshvision.xyz?Ownership is unverified. The dbquery. e-mail and a reported BreachForums appearance provide an indirect association.InconclusiveThe domain address could be shared, borrowed, or unrelated to the forum appearance.

Analytic confidence

LevelMeaning in this report
ConfirmedDirect record, exact stable identifier, or verified forensic observation.
HighMultiple independent indicators with no persuasive benign explanation.
ModerateEvidence supports the judgment, but one or more plausible alternatives remain.
LowLead or partial corroboration that should not drive enforcement alone.
InconclusiveThe supplied evidence cannot distinguish between material alternatives.

Person-of-interest lead

D***** M****** is a moderate-confidence person-of-interest lead, not a confirmed operator. Our technical records link online accounts across the two incidents; they do not establish who controlled them.

The available location clues point to Louisiana. Based on a candidate public profile, D***** M****** most likely works in a network operations center there. We have not verified that the profile belongs to the operator or that this person was in Louisiana during either incident.

Public aliases, posts and interests can belong to unrelated people. The shared Discord identity carries more weight than a profile or location clue. Two residential connections support the cross-incident link; VPN exits and browser fingerprints are weaker. The rapid account pool may include compromised identities.

We are withholding the candidate profile, portrait, personal contact details and employment specifics. Detailed indicators are reserved for direct sharing with affected services and incident responders.

Analytic conclusion

HollowArc is the technical identity; HPCane is assessed as a closely coordinated collaborator

The technical evidence establishes HollowArc as the account identity used across both incidents. The exact HollowArc Discord identity appears at Farmoria and Rokstats, the two Farmoria-linked residential addresses reappear in the Rokstats investigation, and HollowArc was reportedly the only account to access the vulnerable Rokstats endpoint. HPCane then claimed the Rokstats attack.

Assessment. The favored explanation is that HPCane was a closely coordinated collaborator with access to HollowArc operational details, account access, or shared infrastructure. This is assessed at High confidence. The alternative that HollowArc and HPCane are two personas used by the same operator remains plausible at Moderate confidence. The available evidence does not support treating the two personas as unrelated.
HypothesisAssessmentReasoning
HPCane is a closely coordinated collaboratorHigh - favoredThe claim aligns with exclusive HollowArc endpoint access, reused Farmoria infrastructure, and the incident timing. A collaborator could know the exploit details or share account access, infrastructure, and operational information with HollowArc.
HollowArc and HPCane are the same operatorModerate - plausibleThe same operator may use both personas, but no stable HPCane account identifier currently joins the names directly. This remains a credible alternative to close collaboration.
HPCane is an unrelated false claimantLowThe claim is supported by the exclusive HollowArc access and cross-incident network linkage. Coincidence or an uninformed false claim explains the evidence less well.
Arcane participated in either incidentInconclusiveNo stable account identifier, address, domain, or observed server action connects Arcane to the technical record. We do not currently suspect involvement, though it cannot be ruled out.
What would raise confidence. A stable HPCane provider ID, shared verified e-mail, direct message history, device evidence, or server logs showing the same authenticated session would distinguish a single operator from a close collaborator.
Recommended actions

Contain identity reuse and close the scaling path

PriorityActionOwner and outcome
ImmediateMaintain the completed hashed Farmoria evidence set in restricted storage and obtain the exact Rokstats endpoint logs and timestamps for the two residential addresses if they are not already preserved.Incident response and platform teams. Maintains evidential continuity.
ImmediateRevoke every OAuth token contained in the Rokstats-shared export, rotate related application secrets where necessary, and store the raw export in restricted evidence storage.Rokstats identity and security teams. Removes credential exposure created by the export.
ImmediateReport Discord ID 1070712235770527744 and the compromised identity pool to Discord Trust and Safety with the two incident timelines.Joint incident team. Disrupts the reusable identity pool and supports victims.
ImmediateBlock or challenge 68.90.146.47 and 107.206.22.143, and apply managed challenges to the Netprotect ranges on login, registration, OAuth callback, ticket, and sensitive API paths.Edge security. Slows known infrastructure while accounting for VPN rotation.
Short termRate limit OAuth registration by address and subnet, add a first-time signup challenge, and alert on rapid provider identity rotation.Application engineering. Closes the account creation scaling path.
Short termApply ticket and POST /client-errors limits by both account and address. Suppress staff e-mail for very new accounts with no linked game identity.Application engineering. Prevents account pool amplification.
Short termReview large authenticated page properties, especially command and configuration template pages, for accidental cross-tenant data.Application security. Resolves the remaining visibility gap that access logs cannot answer.
Short termStop deriving public display names from e-mail local parts and contact the customer whose exact address was guessed to reset credentials and enable two-factor authentication.Product and customer support. Reduces targeted guessing exposure.
Short termFix the attachment processor error that rejects legitimate uploads, while keeping content sniffing, private storage, random names, ownership checks, and sandboxed delivery.Application engineering. Restores customer functionality without weakening controls.
StructuralAdopt a shared cross-incident indicator register that records stable account IDs, domains, evidence source, confidence, first and last seen times, and disposition.Security operations. Enables defensible partner correlation.
StructuralDefine an attribution review gate before naming a civil person or exact location in customer, provider, or law-enforcement reporting.Incident leadership and legal counsel. Keeps account evidence separate from identity claims.
Sources and analytic limits

Evidence supports account linkage, with stated limits

  1. S1 Farmoria forensic reconstruction dated 21 September 2026.Nginx access logs, selected database tables, audit data, identity records, tickets, attachments, abuse and throttle records, and negative searches across host logs.
  2. S2 HollowArc public exposure ledger dated 21 September 2026.Public GitHub, Steam, Tumblr, Space Station 14, Bluesky, Docker Hub, DNS, RDAP, and certificate transparency observations.
  3. S3 Rokstats-shared account export for hollowarc..Discord provider ID, verified e-mail, account timestamps, profile flags, and credential field presence. Token values and unrelated community memberships were excluded.
  4. S4 Rokstats investigation findings shared during collaboration.Vulnerable endpoint exclusivity, address reuse, the HPCane claim, Arcane lead status, and threat-intelligence e-mail correlation.
  5. S5 Archived public weather record used for a bounded regional cross-check.Exact location details are withheld from this public version.
  6. S6 Restricted public-profile review for the D***** M****** lead.Identifying profile details and visual exhibits are withheld from this public version.
  7. S7 Validated threat-intelligence resource capture.The resource was validated and summarized in sanitized form. Credential hash material and adjacent third-party records were excluded.
  8. S8 Public Hack The Box profile for user 411676, reviewed 21 September 2026.Exact handle HollowArc; joined September 2020; first visible activity records a Lame machine system flag on 2 October 2022.
  9. S9 CyberInt threat-intelligence alias finding for chacon111 and public exact-handle enrichment, reviewed 21 September 2026.CyberInt is the trusted threat-intelligence platform used for this investigation. Public enrichment found one eBay review dated 29 May 2024 and one QuickBooks Community question dated 29 October 2022; ownership of those public accounts was not established.
  10. S10 MITRE ATT&CK Enterprise technique definitions, reviewed 21 September 2026.T1595.002 Vulnerability Scanning; T1585.001 Social Media Accounts; T1078 Valid Accounts; T1090 Proxy; T1110.001 Password Guessing; T1190 Exploit Public-Facing Application; and T1499.004 Application or System Exploitation.
  11. S11 Completed VDS forensic collection, closed 23 September 2026.Verified MySQL, nginx, journal, audit, system, application and historical-log artifacts; final MySQL delta and live prefix; 80-entry SHA-256 manifest with zero verification mismatches. Active-file and acquisition-boundary qualifications are retained.
  12. S12 Subsequent Rokstats log cross-check shared during collaboration.Confirmed hollowarc. activity from 107.206.22.143 in the later incident. The underlying endpoint requests and responses are not included in this public report.
  13. S13 BreachForums observation reported during incident review.Supports only an indirect HollowArc association with meshvision.xyz. The public report does not establish domain ownership or account control.
  14. S14 ARIN registrations for 107.206.22.143 and 68.90.146.47, plus a reverse-DNS lookup for 107.206.22.143, checked 26 September 2026.AT&T is the registered holder of both ranges. Shared ISP ownership does not identify a subscriber or location; the reverse-DNS naming supports likely consumer broadband for 107.206.22.143 only.

Material limits

  • The interactive workbench adds archive-wide traffic context and evidence-linked findings, but it remains an analytical view rather than a substitute for the preserved source artifacts. Reproduce material conclusions against the hashed evidence before legal or enforcement use.
  • The MITRE ATT&CK mapping describes observed or attempted procedures. It does not assert technique success or impact beyond the supporting evidence.
  • Farmoria access logs record request path, status, size, address, and client metadata, but not POST bodies or response content.
  • Traffic blocked at the Cloudflare edge may not appear in origin logs.
  • The completed Farmoria web-log archive begins on 26 August 2026, extending the previously summarized boundary by one day. Earlier behavior is not visible in that dataset.
  • The Rokstats-shared account export is treated as evidence from Rokstats' separate investigation. Its acquisition method and full chain of custody were not independently validated by Farmoria.
  • An account, e-mail address, or IP address identifies an online access path. It does not by itself identify the human at the keyboard.
  • Provider identities in the rapid Farmoria account pool may belong to victims. They should not be publicly named as attackers.
  • Public profile data can be false, stale, borrowed, or intentionally misleading. Negative search results mean only that no defensible result was observed.
  • D***** M****** remains a moderate-confidence person-of-interest lead. No stable technical identifier links the person or a specific public profile to the operator.
  • Person-specific images and profile links are withheld from this public version.
  • The breach-data capture comes from a validated threat-intelligence resource. The HollowArc record was retained as evidence; the credential hash and unrelated records were excluded.
  • Language overlap and public web-security activity are broad behavioral signals. Neither identifies a person as the operator.
  • The Hack The Box exact-handle and timing match is a low-confidence lead. No verified e-mail, account ID, or other stable identifier joins user 411676 to the confirmed HollowArc cluster.
  • CyberInt confirms chacon111 as a HollowArc alias. The separate eBay and QuickBooks exact-handle accounts are not attributed to HollowArc without a second stable identifier.
  • The location assessment is regional and probabilistic. It should not be used to identify a home address or individual without independent lawful corroboration.
Public handling. This version withholds person-specific profile material and credential values. Detailed evidence remains restricted to the incident teams and affected providers.