Inside SpeakTeam: What Open-Source Intelligence Can (and Cannot) Tell Us #
The Threat #
In early 2026, a threat actor collective called SpeakTeam began a sustained campaign of data breaches targeting Mexican institutions. Universities, state governments, financial entities, electoral bodies, and emergency systems were compromised. The stolen data was distributed and sold through Telegram channels and posted on PwnForums, a dark web breach forum.
The group operates under two known handles: MagoSpeak (the self-described “Lider”) and Z3r00, a technical operator responsible for posting the majority of leaked databases. Z3r00 is the primary focus of this investigation.
Confirmed or claimed targets include:
- BBVA Mexico (200,000 cardholder records)
- Multiple state universities (student registries containing CURP, phone numbers, financial data)
- Aguascalientes state government HR database
- INE Sinaloa, the National Electoral Institute (blueprints, network topology, live CCTV streams)
- The Governor of Yucatán (political doxing)
- Estado de México 911 emergency system (10 years of call data)
- ISSSTE, the federal social security institution (25 million records)
- Telmex, Mexico’s largest telecom (214,418 credentials)
- Secretaría de Finanzas y Tesorería of Nuevo León
All targets were Mexican. The campaign was systematic and sustained between February and June 2026.

The Structure #
Multiple independent cyber threat intelligence firms, including VECERT, Brinztech, and TPX Security, identified two distinct handles operating within SpeakTeam: MagoSpeak (described as the “Lider”) and Z3r00. They co-published leaks and appeared to divide responsibilities within the group.
The forum posts confirm this structure. On PwnForums, Z3r00 writes:
“en conjunto de ataque y compañerismo con SpeakTeam aca MagoSpeak y yo Z3r00” (“in a joint attack and companionship with SpeakTeam, here MagoSpeak and me Z3r00”)

Z3r00 on PwnForums #
Z3r00’s profile on PwnForums (a .onion breach forum) reveals the following:
- Joined: April 7, 2026
- Last visit: July 20, 2026
- Time spent online: 12 hours, 12 minutes, 49 seconds
- Total threads: 17
- Total posts: 20
- Forum section: Databases
- Rank: “Pwned” (entry-level)
- User ID: 713355
The account was created just 10 days before the first major post (Telmex credential dump on April 14). All 17 threads are in the Databases section. The total time online (roughly 12 hours across 3+ months) suggests this account is used exclusively for posting leaks, not for browsing or community participation.

Z3r00’s Posts #
Telmex Credential Dump (April 14, 2026) #
Z3r00’s first major post: 214,418 usernames and passwords from Mexico’s largest telecommunications provider.

INE Sinaloa Infrastructure Leak (May 23, 2026) #
A joint operation with MagoSpeak targeting the National Electoral Institute of Sinaloa. Z3r00 writes:
“left the attack space free for this, this in collaboration with SpeakTeam Lider MagoSpeak and here Z3r00”
The post contains institutional blueprints, network topology documents, and CCTV access credentials. Signed: “Hacked By Z3r00 and MagoSpeak.”
Instituto Consorcio Clavijero, Veracruz (July 8, 2026) #
Z3r00’s most recent post. 13,445 student records from 2013 to 2026. Z3r00 taunts the institution directly:
“informacion estudiantil en esta encontraran datos desde el 2013 hasta el 2026 la data fue vulnerada por mi Z3r00” (“student information, in this you will find data from 2013 to 2026, the data was compromised by me, Z3r00”)
“a ver si van arreglando sus cagaditas y dejan de exponer tantos alumnos” (“let’s see if you fix your screw-ups and stop exposing so many students”)
The post contains: matricula, timestamp, CURP, nombre_completo, municipio, localidad, status. Signed: “Hacked By Z3r00.”
Nuevo León Financial Core #
Z3r00 announces full access to the state financial system:
“Hello community, we have full access to the Nuevo León Financial Core.”
The leaked data includes registration IDs, request numbers, request status, and administrative levels.
Escuela Normal Experimental (joint attack) #
Another joint operation. Z3r00 writes:
“de pwnforums en esta ocasion en conjunto de ataque y compañerismo con SpeakTeam aca MagoSpeak y yo Z3r00” (“from pwnforums, on this occasion in a joint attack and companionship with SpeakTeam, here MagoSpeak and me Z3r00”)
The Problem With “Z3r00” #
Z3r00 is an extremely common username. It is a basic leet-speak variation of “zero” used by thousands of unrelated people across gaming platforms, social media, and forums worldwide. Any attribution effort that begins with a common username must establish, with specificity, that the Z3r00 operating within SpeakTeam is the same Z3r00 found in historical records.
This is the central challenge of this investigation, and the point where confidence has clear limits.
What We Can Identify With High Confidence #
Separate from the SpeakTeam question, breach databases and OSINT sources reveal a specific Mexican individual who has used the handle Z3r00 across underground forums since approximately 2013. The attribution chain for this person is strong.
Step 1: Z3r00 on hacking forums tied to a specific email #
The username Z3r00 appears in breach records from viphackforums.com, blackhatworld.com, and btc-e.com, linked to an email: pro*****@gmail.com. The blackhatworld record includes a Mexican IP address (201.145.x.x) and a DOB of 1992-10-03.
Step 2: That email links to a second email through shared identifiers #
The email pro*****@gmail.com appears on Cardmafia.cc (username: eecv0), nulled.to (username: eecv, IP: 187.190.x.x), and blackhatprotools.info (username: elixum). A second email, zer*****@gmail.com, shares the same usernames (eecv0, elixum), the same distinctive password, and the same Mexican IP ranges. These two emails are controlled by the same person.
Step 3: The second email links to a real identity through WHOIS records #
The email zer*****@gmail.com was used to register at least seven domains. Historical WHOIS records (captured in 2018, before privacy protections were applied) contain a full name, a physical address in Cuernavaca, Morelos, Mexico, and a phone number. The domains include names echoing the “zero” motif present across all aliases: zero****.net**, ****0.net, and others. One domain is clearly personal, containing the registrant’s family surname.
The registrant company is listed as “Vilanet.”
Step 4: Corroboration from multiple independent sources #
- XSplit.com breach (2013):
zer*****@gmail.comregistered under the name “Enrique *****” with username zer00cr4ck - LeadHunter database: full legal name with additional surname, same address, same phone number
- Deezer.com breach: full legal name used as username on the personal domain
- Backtrack Academy: full legal name publicly displayed, described as “information security student”
- Freelancer.com: handle Zer00cr4ck, listed as from Mexico, commissioning game character designs
- Seven domain WHOIS records: consistent name, address, phone, and email across all registrations

The Gap #
The problem is connecting this specific Z3r00 (active on hacking forums 2013-2022, identified through WHOIS and breach data) to the Z3r00 who joined PwnForums on April 7, 2026 and posts SpeakTeam leaks.
The evidence supporting this connection is circumstantial:
| Factor | Assessment |
|---|---|
| The identified individual is Mexican and based in Morelos; SpeakTeam’s Z3r00 targets exclusively Mexican institutions | Consistent but not unique |
| The identified individual has 10+ years of cybercriminal forum history, demonstrating capability | Supports but does not confirm |
| The identified individual’s machine was compromised by an infostealer in March 2026, during SpeakTeam’s active period (first activity: February 26, 2026) | Temporally suggestive |
| MagoSpeak specifically targeted Instituto Tecnológico de Zacatepec, a small school located 35km from Cuernavaca in the same state (Morelos) where the identified individual lives | Geographically suggestive |
| The PwnForums Z3r00 is a Spanish speaker who also writes in English, consistent with the identified individual’s bilingual forum history | Consistent but common |
Thus the link between the identified individual and SpeakTeam’s Z3r00 remains a hypothesis.
The Infostealer Detail #
In March 2026, a machine associated with the username Z3r00 was infected by an Acreed infostealer. This infection occurred weeks after MagoSpeak’s first tracked publication (February 26) and days before the PwnForums Z3r00 account was created (April 7).
This is suggestive but not conclusive. It places a Z3r00 user in an active compromise during SpeakTeam’s operational window. Whether this is the same Z3r00 posting on PwnForums cannot be confirmed from available data alone.
The Profile #
Setting aside the SpeakTeam attribution question, the individual behind the historical Z3r00/eecv0/elixum/zer00cr4ck accounts has the following profile:
- Location: Cuernavaca, Morelos, Mexico
- Age: Early-to-mid 30s (DOB approximately 1990-1992)
- Education: Cybersecurity student (Backtrack Academy)
- Side projects: Indie game development (Freelancer.com)
- Hobbies: Competitive CS:GO, manga, mobile gaming
- Forum history: 10+ years on underground forums including carding, DDoS-for-hire, RAT tools, and cracking communities
- Domains owned: Seven, including zero****.net (active), ****0.net, and a personal family domain
- Passwords: Consistent use of a distinctive password combining two words across all platforms for 10+ years
Lessons #
This case illustrates both the power and the limits of open-source attribution.
What worked:
- Password reuse across a decade created an unbreakable chain from underground forums to real-world identity
- Historical WHOIS data persisted in breach databases long after privacy protection was added
- Mixing hacking handles with legitimate platforms (Freelancer.com, Backtrack Academy) created permanent bridges between personas
- Multiple independent sources (XSplit, LeadHunter, Deezer, WHOIS) corroborated the same identity
- Forum post language and structure revealed operational relationships between actors
What remains unresolved:
- A common username (Z3r00) creates ambiguity when attempting to link historical records to a specific 2026 threat actor
- Without access to Telegram metadata, forum post IPs, or protected CTI data, the final link in the chain cannot be confirmed through open sources alone
- Z3r00’s own words (“MagoSpeak y yo Z3r00”) confirm SpeakTeam is at least two people, meaning identifying one does not identify the other
- The “DAN” component of MagoSpeak’s handle remains unexplored
Conclusion #
The investigation identifies a specific individual in Cuernavaca, Morelos, Mexico who has used the handle Z3r00 across cybercriminal forums for over a decade. The attribution to this person is high confidence.
Whether this individual is the same Z3r00 currently operating within SpeakTeam alongside MagoSpeak is a separate question. The circumstantial evidence is consistent: same country, same state, same handle, demonstrated capability, temporal overlap. But circumstantial evidence is not confirmation.
The honest assessment: strong candidate, not proven match. Closing this gap would require access to Telegram channel metadata, PwnForums IP logs, or the full credential dump from the March 2026 infostealer infection.
What is clear: SpeakTeam is at least a two-person operation. Z3r00 is the technical operator who posts breach data. MagoSpeak (“DAN”) is the leader. Both are Spanish-speaking, Mexico-based, and focused exclusively on Mexican targets. Their operational security, while imperfect, has so far prevented definitive public attribution.
This analysis is based on publicly available information, breach data, forum posts, and open-source intelligence. Identifying details have been partially redacted. No accusations of guilt are made. Attribution represents analytical assessment based on available evidence.