Lizard Squad
   HOME

TheInfoList



OR:

Lizard Squad was a
black hat hacking A Black Hat (Black Hat Hacker or Blackhat) is a computer hacker who usually violates laws or typical ethical standards. The term originates from the 1950s westerns, when bad guys typically wore black hats and good guys white hats. Black hat hacker ...
group, mainly known for their claims of
distributed denial-of-service In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connect ...
(DDoS) attacks primarily to disrupt gaming-related services. On September 3, 2014, Lizard Squad seemingly announced that it had disbanded only to return later on, claiming responsibility for a variety of attacks on prominent websites. The organization at one point participated in the
Darkode dark0de, also known as Darkode, is a cybercrime forum and black marketplace described by Europol as "the most prolific English-speaking cybercriminal forum to date". This site which was launched in 2007, serves as a venue for the sale and trade ...
hacking forums and shared hosting with them. On April 30, 2016,
Cloudflare Cloudflare, Inc. is an American content delivery network and DDoS mitigation company, founded in 2009. It primarily acts as a reverse proxy between a website's visitor and the Cloudflare customer's hosting provider. Its headquarters are in San ...
published a blogpost detailing how
cyber criminals A cybercrime is a crime that involves a computer or a computer network.Moore, R. (2005) "Cyber crime: Investigating High-Technology Computer Crime," Cleveland, Mississippi: Anderson Publishing. The computer may have been used in committing the ...
using this group's name were issuing random threats of carrying out DDoS attacks. Despite these threats, Cloudflare claim they failed to carry through with a single attack. As a result of this, the British
National Fraud Intelligence Bureau The National Fraud Intelligence Bureau is a police unit in the United Kingdom responsible for gathering and analysing intelligence relating to fraud and financially motivated cyber crime. The NFIB was created as part of the recommendations of the ...
issued an alert warning businesses not to comply with ransom messages threatening DDoS attacks.


Distributed denial-of-service attacks

A distributed denial-of-service (DDoS) attack occurs when numerous systems flood the bandwidth or resources of a targeted system, usually one or more web servers. Such an attack is often the result of multiple systems (for example a
botnet A botnet is a group of Internet-connected devices, each of which runs one or more bots. Botnets can be used to perform Distributed Denial-of-Service (DDoS) attacks, steal data, send spam, and allow the attacker to access the device and its conn ...
) flooding the targeted system with traffic. When a server is overloaded with connections, new connections can no longer be accepted.


Notable actions

Lizard Squad has claimed responsibility for launching a string of
DDoS attacks In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connect ...
against high-profile game-related services over the course of a few months in late 2014. On August 18, 2014, servers of the game ''
League of Legends ''League of Legends'' (''LoL''), commonly referred to as ''League'', is a 2009 multiplayer online battle arena video game developed and published by Riot Games. Inspired by ''Defense of the Ancients'', a Mod (video games), custom map for War ...
'' were taken offline with a
DDoS attack In computing, a denial-of-service attack (DoS attack) is a cyber-attack A cyberattack is any offensive maneuver that targets computer information systems, computer networks, infrastructures, or personal computer devices. An attacker is a p ...
; this was claimed as Lizard Squad's first attack. Days later, on August 24, the
PlayStation Network PlayStation Network (PSN) is a digital media entertainment service provided by Sony Interactive Entertainment. Launched in November 2006, PSN was originally conceived for the PlayStation video game consoles, but soon extended to encompass smartp ...
was disrupted via a DDoS attack. On November 23, the group claimed they attacked ''
Destiny Destiny, sometimes referred to as fate (from Latin ''fatum'' "decree, prediction, destiny, fate"), is a predetermined course of events. It may be conceived as a predetermined future, whether in general or of an individual. Fate Although often ...
'' servers with a DDoS attack. On December 1,
Xbox Live The Xbox network, formerly and still sometimes branded as Xbox Live, is an Internet, online multiplayer video game, multiplayer gaming and digital media delivery service created and operated by Microsoft. It was first made available to the Xbox ...
was apparently attacked by Lizard Squad: users attempting to connect to use the service would be given the 80151909 error code. On December 2, Lizard Squad defaced
Machinima.com Machinima, Inc. was an American multiplatform online entertainment network owned by WarnerMedia. The company was founded in January 2000 by Hugh Hancock and was headquartered in Los Angeles, California. It originated as a hub for its namesake, m ...
, replacing their front page with
ASCII art ASCII art is a graphic design technique that uses computers for presentation and consists of pictures pieced together from the 95 printable (from a total of 128) characters defined by the ASCII Standard from 1963 and ASCII compliant chara ...
of their logo. A week after, on December 8, Lizard Squad claimed responsibility for another PlayStation Network DDoS attack. On December 22, though not game-related,
Internet in North Korea Internet access is available in North Korea, but is only permitted with special authorization. It is primarily used for government purposes, and also by foreigners. The country has some broadband infrastructure, including fiber optic links betwee ...
was taken offline by a DDoS attack. Lizard Squad claimed responsibility for the attack and linked to an
IP address An Internet Protocol address (IP address) is a numerical label such as that is connected to a computer network that uses the Internet Protocol for communication.. Updated by . An IP address serves two main functions: network interface ident ...
located in
North Korea North Korea, officially the Democratic People's Republic of Korea (DPRK), is a country in East Asia. It constitutes the northern half of the Korea, Korean Peninsula and shares borders with China and Russia to the north, at the Yalu River, Y ...
. North Korean Internet services were restored on 23 December 2014.


Christmas attacks

Lizard Squad had previously threatened to take down gaming services on Christmas. On December 25, 2014 (Christmas Day), Lizard Squad claimed to have performed a
DDoS In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host A ...
attack on the PlayStation Network and Xbox Live. On December 26, 2014, at 2:00 AM, Lizard Squad appeared to stop attacking PlayStation Network and Xbox Live.
Gizmodo ''Gizmodo'' ( ) is a design, technology, science and science fiction website. It was originally launched as part of the Gawker Media network run by Nick Denton, and runs on the Kinja platform. ''Gizmodo'' also includes the subsite ''io9'', whic ...
reported that the attacks may have ceased after
Kim Dotcom Kim Dotcom (born Kim Schmitz; 21 January 1974), also known as Kimble and Kim Tim Jim Vestor, is a German-Finnish Internet entrepreneur and political activist who resides in Glenorchy, New Zealand. He first rose to fame in Germany in the 1990s ...
offered Lizard Squad 3000 accounts on his upload service
MEGA Mega or MEGA may refer to: Science * mega-, a metric prefix denoting 106 * Mega (number), a certain very large integer in Steinhaus–Moser notation * "mega-" a prefix meaning "large" that is used in taxonomy * Gravity assist, for ''Moon-Eart ...
.


Tor sybil attack

On December 26, 2014, a
Sybil attack Sibyls were oracular women believed to possess prophetic powers in ancient Greece. Sybil or Sibyl may also refer to: Films * ''Sybil'' (1921 film) * ''Sybil'' (1976 film), a film starring Sally Field * ''Sybil'' (2007 film), a remake of the 19 ...
involving more than 3000 relays was attempted against the
Tor Tor, TOR or ToR may refer to: Places * Tor, Pallars, a village in Spain * Tor, former name of Sloviansk, Ukraine, a city * Mount Tor, Tasmania, Australia, an extinct volcano * Tor Bay, Devon, England * Tor River, Western New Guinea, Indonesia Sc ...
network. Nodes with names beginning with "LizardNSA" began appearing, Lizard Squad claimed responsibility for this attack. The relevance of the attack was questioned. According to Tor relay node operator Thomas White, the consensus system made that Lizard Squad only managed to control "0.2743% of the network, equivalent of a tiny VPS".


Malaysia Airlines website attack

On January 26, 2015, the website of
Malaysia Airlines Malaysia Airlines Berhad (MAB; ms, Penerbangan Malaysia Berhad), formerly known as Malaysian Airline System (MAS; ), and branded as Malaysia Airlines, is the flag carrier airline of Malaysia and a member of the Oneworld airline alliance. (The ...
was attacked, apparently by Lizard Squad, calling itself a "cyber caliphate". Users were redirected to another page bearing an image of a tuxedo-wearing lizard, and reading "Hacked by Cyber Caliphate". Underneath this was text reading "follow the cyber caliphate on twitter" after which were the Twitter accounts of the owner of UMG, "@UMGRobert" and CEO of UMG, "@UMG_Chris". The page also carried the headline "404 - Plane Not Found", an apparent reference to the airline's loss of flight
MH370 Malaysia Airlines Flight 370 (MH370/MAS370) was an international passenger flight operated by Malaysia Airlines that disappeared on 8 March 2014 while flying from Kuala Lumpur International Airport in Malaysia to its planned destination ...
the previous year. Malaysia Airlines assured customers and clients that customer data had not been compromised.Malaysia Airlines website 'compromised' by 'cyber caliphate' Lizard Squad hackers
ABC News Australia, 26 Jan 2015
Media reports around the world said versions of the takeover in some regions included the wording "ISIS will prevail", which listed concerns of Lizard Squad's association with the
Islamic State An Islamic state is a State (polity), state that has a form of government based on sharia, Islamic law (sharia). As a term, it has been used to describe various historical Polity, polities and theories of governance in the Islamic world. As a t ...
.


Daybreak Games DDoS

On July 9, 2015, game servers operated by
Daybreak Game Company Daybreak Game Company LLC is an American video game developer based in San Diego. The company was founded in December 1997 as Sony Online Entertainment, a subsidiary of Sony Computer Entertainment, but was spun off to an independent investor in ...
, including those of ''
H1Z1 ''Z1 Battle Royale'' (formerly ''H1Z1'' and ''King of the Kill'') is a battle royale game developed and published by Daybreak Game Company. The game's development began after the original ''H1Z1'' was spun off into two separate projects in early ...
'' and ''
PlanetSide 2 ''PlanetSide 2'' is a free-to-play massively multiplayer online first-person shooter developed by Rogue Planet Games and published by Daybreak Game Company. The game supports battles with thousands of players (up to 2,000 on a single map) and inc ...
'', were disrupted by a DDoS attack that Lizard Squad claimed responsibility for. The attack was performed in retaliation to legal threats John Smedley, the company's CEO, had made after being targeted by the hacking group.


False claims


Bomb threats

On August 24, 2014, Lizard Squad claimed that a plane on which the president of
Sony Online Entertainment Daybreak Game Company LLC is an American video game developer based in San Diego. The company was founded in December 1997 as Sony Online Entertainment, a subsidiary of Sony Computer Entertainment, but was spun off to an independent investor in ...
, John Smedley, was flying (
American Airlines American Airlines is a major airlines of the United States, major US-based airline headquartered in Fort Worth, Texas, within the Dallas–Fort Worth metroplex. It is the Largest airlines in the world, largest airline in the world when measured ...
Flight 362), had explosives on board. The flight from Dallas to San Diego made an unscheduled landing in Phoenix, Arizona. Sony Online Entertainment announced that the FBI was investigating the incident.


Facebook, Instagram, and Tinder attack

On January 26, 2015, several social media services including
Facebook Facebook is an online social media and social networking service owned by American company Meta Platforms. Founded in 2004 by Mark Zuckerberg with fellow Harvard College students and roommates Eduardo Saverin, Andrew McCollum, Dustin M ...
and
Instagram Instagram is a photo and video sharing social networking service owned by American company Meta Platforms. The app allows users to upload media that can be edited with filters and organized by hashtags and geographical tagging. Posts can ...
were unavailable to users.
Tinder Tinder is easily combustible material used to start a fire. Tinder is a finely divided, open material which will begin to glow under a shower of sparks. Air is gently wafted over the glowing tinder until it bursts into flame. The flaming tinder i ...
and
HipChat HipChat was a web service for internal private online chat and instant messaging. As well as one-on-one and group/topic chat, it also featured cloud-based file storage, video calling, searchable message-history and inline-image viewing. The soft ...
were also affected. Lizard Squad claimed responsibility for the attacks, via a posting on a
Twitter Twitter is an online social media and social networking service owned and operated by American company Twitter, Inc., on which users post and interact with 280-character-long messages known as "tweets". Registered users can post, like, and ...
account previously used by the group. The outage, originally speculated to be a
distributed denial-of-service attack In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connec ...
, lasted a little under an hour before services were restored. Facebook later released a statement saying its own engineers were to blame, and that the disruption to its services was not the result of a third-party attack, but instead occurred after they introduced a change that affected their configuration systems.


Explicit celebrity photos

On January 27, 2015, Lizard Squad claimed to have compromised
Taylor Swift Taylor Alison Swift (born December 13, 1989) is an American singer-songwriter. Her discography spans multiple genres, and her vivid songwriting—often inspired by her personal life—has received critical praise and wide media coverage. Bor ...
's Twitter and Instagram accounts. Once they claimed to have access, they threatened to release nude photos in exchange for bitcoins. Taylor Swift, however, retorted that "there were no naked pics" and told the offenders to "have fun" finding any.


Conspiracy theory

On January 4, 2021, American lawyer and conspiracy theorist
Lin Wood Lucian Lincoln "Lin" Wood Jr. (born October 19, 1952) is an American attorney and conspiracy theorist. Following his graduation from law school in 1977, Wood worked as a personal injury lawyer, focusing on medical malpractice litigation. He b ...
tweeted out baseless claims that a group of hackers named "the lizard squad" have evidence of a global sex ring involving several high-profile Americans, similar to the discredited
conspiracy theory A conspiracy theory is an explanation for an event or situation that invokes a conspiracy by sinister and powerful groups, often political in motivation, when other explanations are more probable.Additional sources: * * * * The term has a nega ...
Qanon QAnon ( , ) is an American political conspiracy theory and political movement. It originated in the American far-right political sphere in 2017. QAnon centers on fabricated claims made by an anonymous individual or individuals known as "Q". ...
. There seems to be no relation between the "lizard squad" mentioned by Wood and the
black-hat hacking A security hacker is someone who explores methods for breaching defenses and exploiting weaknesses in a computer system or network. Hackers may be motivated by a multitude of reasons, such as profit, protest, information gathering, challenge ...
group Lizard Squad, and Vinnie Omari, a member of the Lizard Squad, denies any claim that his group may have information on a global sex-trafficking organization.


Known members


Vinnie Omari

Vinnie Omari is a member of the Lizard Squad who was arrested and bailed under the alleged offences of "Enter into/concerned in acquisition/retention/use or control criminal property, Fraud by false representation - Fraud Act 2006, Conspire to steal from another, unauthorized computer access with intent to commit other offences". He was used as a public face on television and as a spokesperson for the news to represent LizardSquad.


Julius Kivimäki

Julius Kivimäki (zeekill) is a Finnish member of Lizard Squad convicted in July 2015 on over 50,000 counts of computer crime.


Zachary Buchta

19-year-old Zachary Buchta (fbiarelosers) from Maryland, has been charged with computer crimes associated with a series of distributed denial-of-service (DDoS) attacks, stolen credit cards and selling DDoS-for-hire services. He was one of the members behind LizardSquad and also the Co-Group "PoodleCorp" which launched distributed denial-of-service (DDoS) attacks against multiple networks, YouTubers and gaming services. Buchta was hiding behind the Twitter alias @fbiarelosers, @xotehpoodle, and the online aliases "pein" and "lizard".


Bradley Jan Willem van Rooy

19-year-old Bradley Jan Willem van Rooy (UchihaLS) from the Netherlands, has been charged with computer crimes associated with a series of distributed denial-of-service (DDoS) attacks, stolen credit cards and selling DDoS-for-hire services. He was one of the members behind LizardSquad who was mainly responsible for launching the DDoS-attacks announced by the group. Also he was one of the two managers behind the Twitter account @LizardLands which is the main Twitter account of LizardSquad since January 2015. He was normally hiding behind his Twitter alias @UchihaLS (which stands for Uchiha LizardSquad) and the online aliases "UchihaLS", "Uchiha" and "Dragon".


References

{{Hacking in the 2010s Hacker groups Internet trolling Cyberattacks Cyberattack gangs