HOME

TheInfoList



OR:

LulzSec (a contraction for Lulz Security) was a black hat computer hacking group that claimed responsibility for several high profile attacks, including the compromise of user accounts from
PlayStation Network PlayStation Network (PSN) is a digital media entertainment service provided by Sony Interactive Entertainment. Launched in November 2006, PSN was originally conceived for the PlayStation video game consoles, but soon extended to encompass smar ...
in 2011. The group also claimed responsibility for taking the
CIA The Central Intelligence Agency (CIA ), known informally as the Agency and historically as the Company, is a civilian foreign intelligence service of the federal government of the United States, officially tasked with gathering, processing, ...
website offline. Some security professionals have commented that LulzSec has drawn attention to insecure systems and the dangers of password reuse. It has gained attention due to its high profile targets and the sarcastic messages it has posted in the aftermath of its attacks. One of the founders of LulzSec was computer security specialist Hector Monsegur, who used the online moniker Sabu. He later helped law enforcement track down other members of the organization as part of a
plea deal A plea bargain (also plea agreement or plea deal) is an agreement in criminal law proceedings, whereby the prosecutor provides a concession to the defendant in exchange for a plea of guilt or ''nolo contendere.'' This may mean that the defendant ...
. At least four associates of LulzSec were arrested in March 2012 as part of this investigation. Prior, British authorities had announced the arrests of two teenagers they alleged were LulzSec members, going by the pseudonyms T-flow and
Topiary Topiary is the horticultural practice of training perennial plants by clipping the foliage and twigs of trees, shrubs and subshrubs to develop and maintain clearly defined shapes, whether geometric or fanciful. The term also refers to plants w ...
. At just after midnight ( BST, UT+01) on 26 June 2011, LulzSec released a "50 days of lulz" statement, which they claimed to be their final release, confirming that LulzSec consisted of six members, and that their website was to be shut down. The sudden disbandment of the group was unexpected. Their final release included accounts and passwords from many different sources. Despite claims of retirement, the group committed another hack against newspapers owned by
News Corporation News Corporation (abbreviated News Corp.), also variously known as News Corporation Limited, was an American multinational mass media corporation controlled by media mogul Rupert Murdoch and headquartered at 1211 Avenue of the Americas in New ...
on 18 July, defacing them with false reports regarding the death of
Rupert Murdoch Keith Rupert Murdoch ( ; born 11 March 1931) is an Australian-born American business magnate. Through his company News Corp, he is the owner of hundreds of local, national, and international publishing outlets around the world, including ...
. The group had also helped launch Operation AntiSec, a joint effort involving LulzSec,
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anony ...
, and other hackers.


Background and history

A federal indictment against members contends that, prior to forming the hacking collective known as LulzSec, the six members were all part of another collective called Internet Feds, a group in rivalry with
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anony ...
. Under this name, the group attacked websites belonging to
Fine Gael Fine Gael (, ; English: "Family (or Tribe) of the Irish") is a liberal-conservative and Christian-democratic political party in Ireland. Fine Gael is currently the third-largest party in the Republic of Ireland in terms of members of Dáil É ...
,
HBGary HBGary is a subsidiary company of ManTech International, focused on technology security. In the past, two distinct but affiliated firms had carried the HBGary name: ''HBGary Federal'', which sold its products to the US Government, and ''HBGary ...
, and
Fox Broadcasting Company The Fox Broadcasting Company, commonly known simply as Fox and stylized in all caps as FOX, is an American commercial broadcast television network owned by Fox Corporation and headquartered in New York City, with master control operations ...
. This includes the alleged
incident Incident may refer to: * A property of a graph in graph theory * ''Incident'' (film), a 1948 film noir * Incident (festival), a cultural festival of The National Institute of Technology in Surathkal, Karnataka, India * Incident (Scientology), a ...
in which e-mail messages were stolen from HBGary accounts. In May 2011, following the publicity surrounding the
HBGary HBGary is a subsidiary company of ManTech International, focused on technology security. In the past, two distinct but affiliated firms had carried the HBGary name: ''HBGary Federal'', which sold its products to the US Government, and ''HBGary ...
hacks, six members of Internet Feds founded the group LulzSec. The group's first recorded attack was against Fox.com's website, though they still may have been using the name Internet Feds at the time. It claimed responsibility for leaking information, including passwords, altering several employees'
LinkedIn LinkedIn () is an American business and employment-oriented online service that operates via websites and mobile apps. Launched on May 5, 2003, the platform is primarily used for professional networking and career development, and allows job se ...
profiles, and leaking a database of
X Factor ''The X Factor'' is a television music competition franchise created by British producer Simon Cowell and his company Syco Entertainment. It originated in the United Kingdom, where it was devised as a replacement for ''Pop Idol'' (2001–2003) ...
contestants containing contact information of 73,000 contestants. They claimed to do so because the rapper
Common Common may refer to: Places * Common, a townland in County Tyrone, Northern Ireland * Boston Common, a central public park in Boston, Massachusetts * Cambridge Common, common land area in Cambridge, Massachusetts * Clapham Common, originally ...
had been referred to as "vile" on air. LulzSec drew its name from the
neologism A neologism Ancient_Greek.html"_;"title="_from_Ancient_Greek">Greek_νέο-_''néo''(="new")_and_λόγος_/''lógos''_meaning_"speech,_utterance"is_a_relatively_recent_or_isolated_term,_word,_or_phrase_that_may_be_in_the_process_of_entering_com ...
"
lulz LOL, or lol, is an initialism for laughing out loud and a popular element of Internet slang. It was first used almost exclusively on Usenet, but has since become widespread in other forms of computer-mediated communication and even face-to ...
", (from
lol LOL, or lol, is an initialism for laughing out loud and a popular element of Internet slang. It was first used almost exclusively on Usenet, but has since become widespread in other forms of computer-mediated communication and even face-to ...
), "laughing out loud", which represents laughter, and "Sec", short for "Security". The ''
Wall Street Journal ''The Wall Street Journal'' is an American business-focused, international daily newspaper based in New York City, with international editions also available in Chinese and Japanese. The ''Journal'', along with its Asian editions, is published ...
'' characterized its attacks as closer to Internet pranks than serious cyber-warfare, while the group itself claimed to possess the capability of stronger attacks. It gained attention in part due to its brazen claims of responsibility and lighthearted taunting of corporations that were hacked. It frequently referred to
Internet meme An Internet meme, commonly known simply as a meme ( ), is an idea, behavior, style, or image that is spread via the Internet, often through social media platforms. What is considered a meme may vary across different communities on the Internet ...
s when defacing websites. The group emerged in May 2011, and successfully attacked websites of several major corporations. It specialized in finding websites with poor security, stealing and posting information from them online. It used well-known straightforward methods, such as
SQL injection In computing, SQL injection is a code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution (e.g. to dump the database contents to the attacker). SQL in ...
, to attack its target websites. Several media sources have described their tactics as
grey hat A grey hat (greyhat or gray hat) is a computer hacker or computer security expert who may sometimes violate laws or typical ethical standards, but usually does not have the malicious intent typical of a black hat hacker. The term came into us ...
hacking. Members of the group may have been involved in a previous attack against the security firm
HBGary HBGary is a subsidiary company of ManTech International, focused on technology security. In the past, two distinct but affiliated firms had carried the HBGary name: ''HBGary Federal'', which sold its products to the US Government, and ''HBGary ...
. The group used the motto "Laughing at your security since 2011!" and its website, created in June 2011, played the theme from ''
The Love Boat ''The Love Boat'' is an American romantic comedy/drama television series that aired on ABC from 1977 to 1986; in addition, four three-hour specials aired in 1986, 1987, and 1990. The series was set on the luxury passenger cruise ship MS ''Pa ...
''. It announced its exploits via Twitter and its own website, often accompanied with lighthearted
ASCII art ASCII art is a graphic design technique that uses computers for presentation and consists of pictures pieced together from the 95 printable (from a total of 128) characters defined by the ASCII Standard from 1963 and ASCII compliant char ...
drawings of boats. Its website also included a
bitcoin Bitcoin (abbreviation: BTC; sign: ₿) is a decentralized digital currency that can be transferred on the peer-to-peer bitcoin network. Bitcoin transactions are verified by network nodes through cryptography and recorded in a public distr ...
donation link to help fund its activities. Ian Paul of ''
PC World ''PC World'' (stylized as PCWorld) is a global computer magazine published monthly by IDG. Since 2013, it has been an online only publication. It offers advice on various aspects of PCs and related items, the Internet, and other personal tech ...
'' wrote that, "As its name suggests, LulzSec claims to be interested in mocking and embarrassing companies by exposing security flaws rather than stealing data for criminal purposes." The group was also critical of
white hat White hat, white hats, or white-hat may refer to: Art, entertainment, and media * White hat, a way of thinking in Edward de Bono's book ''Six Thinking Hats'' * White hat, part of black and white hat symbolism in film Other uses * White hat (compu ...
hackers, claiming that many of them have been corrupted by their employers. Some in the security community contended that the group raised awareness of the widespread lack of effective security against hackers. They were credited with inspiring
LulzRaft LulzRaft is the name of a computer hacker group or individual that gained international attention in 2011 due to a series of high-profile attacks on Canadian websites. Their targets have included the Conservative Party of Canada and Husky Energy. ...
, a group implicated in several high-profile website hacks in Canada. In June 2011 the group took suggestions for sites to hit with
denial-of-service attack In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host conne ...
s. The group redirected telephone numbers to different customer support lines, including the line for
World of Warcraft ''World of Warcraft'' (''WoW'') is a massively multiplayer online role-playing game (MMORPG) released in 2004 by Blizzard Entertainment. Set in the '' Warcraft'' fantasy universe, ''World of Warcraft'' takes place within the world of Azer ...
, magnets.com, and the FBI
Detroit Detroit ( , ; , ) is the largest city in the U.S. state of Michigan. It is also the largest U.S. city on the United States–Canada border, and the seat of government of Wayne County. The City of Detroit had a population of 639,111 at t ...
office. The group claimed this sent five to 20 calls per second to these sources, overwhelming their support officers. On 24 June 2011, ''
The Guardian ''The Guardian'' is a British daily newspaper. It was founded in 1821 as ''The Manchester Guardian'', and changed its name in 1959. Along with its sister papers '' The Observer'' and '' The Guardian Weekly'', ''The Guardian'' is part of the ...
'' released leaked logs of one of the group's IRC chats, revealing that the core group was a small group of hackers with a leader Sabu who exercised large control over the group's activities. It also revealed that the group had connections with
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anony ...
, though was not formally affiliated with it. Some LulzSec members had once been prominent Anonymous members, including member
Topiary Topiary is the horticultural practice of training perennial plants by clipping the foliage and twigs of trees, shrubs and subshrubs to develop and maintain clearly defined shapes, whether geometric or fanciful. The term also refers to plants w ...
. At just after midnight (UTC) on 26 June 2011, LulzSec released a "50 days of lulz" statement, which they claimed to be their final release, confirming that LulzSec consisted of six members, and that their website was to be taken down. The group claimed that they had planned to be active for only fifty days from the beginning. "We're not quitting because we're afraid of law enforcement. The press are getting bored of us, and we're getting bored of us," a group member said in an interview to the
Associated Press The Associated Press (AP) is an American non-profit news agency headquartered in New York City. Founded in 1846, it operates as a cooperative, unincorporated association. It produces news reports that are distributed to its members, U.S. new ...
. Members of the group were reported to have joined with Anonymous members to continue the AntiSec operation. However, despite claiming to retire, the group remained in communication as it attacked the websites of British newspapers ''
The Times ''The Times'' is a British daily national newspaper based in London. It began in 1785 under the title ''The Daily Universal Register'', adopting its current name on 1 January 1788. ''The Times'' and its sister paper '' The Sunday Times'' ( ...
'' and '' The Sun'' on 18 July, leaving a false story on the death of owner
Rupert Murdoch Keith Rupert Murdoch ( ; born 11 March 1931) is an Australian-born American business magnate. Through his company News Corp, he is the owner of hundreds of local, national, and international publishing outlets around the world, including ...
.


Former members and associates

LulzSec consisted of seven core members. The online handles of these seven were established through various attempts by other hacking groups to release personal information of group members on the internet, leaked IRC logs published by ''
The Guardian ''The Guardian'' is a British daily newspaper. It was founded in 1821 as ''The Manchester Guardian'', and changed its name in 1959. Along with its sister papers '' The Observer'' and '' The Guardian Weekly'', ''The Guardian'' is part of the ...
'', and through confirmation from the group itself. * Sabu – One of the group's founders, who seemed to act as a kind of leader for the group, Sabu would often decide what targets to attack next and who could participate in these attacks. He may have been part of the Anonymous group that hacked
HBGary HBGary is a subsidiary company of ManTech International, focused on technology security. In the past, two distinct but affiliated firms had carried the HBGary name: ''HBGary Federal'', which sold its products to the US Government, and ''HBGary ...
. Various attempts to release his real identity have claimed that he is an information technology consultant with the strongest hacking skills of the group and knowledge of the
Python Python may refer to: Snakes * Pythonidae, a family of nonvenomous snakes found in Africa, Asia, and Australia ** ''Python'' (genus), a genus of Pythonidae found in Africa and Asia * Python (mythology), a mythical serpent Computing * Python (pro ...
programming language. It was thought that Sabu was involved in the media outrage cast of 2010 using the skype "anonymous.sabu" Sabu was arrested in June 2011 and identified as a 29-year-old unemployed man from New York’s Lower East Side. On 15 August, he pleaded guilty to several hacking charges and agreed to cooperate with the FBI. Over the following seven months he successfully unmasked the other members of the group. Sabu was identified by Backtrace Security as Hector Montsegur on 11 March 2011 in a PDF publication named "Namshub." *
Topiary Topiary is the horticultural practice of training perennial plants by clipping the foliage and twigs of trees, shrubs and subshrubs to develop and maintain clearly defined shapes, whether geometric or fanciful. The term also refers to plants w ...
– Topiary was also a suspected former member of the
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anony ...
, where he used to perform media relations, including hacking the website of the
Westboro Baptist Church The Westboro Baptist Church (WBC) is a small American, unaffiliated Primitive Baptist church in Topeka, Kansas, founded in 1955 by pastor Fred Phelps. Labeled a hate group, WBC is known for engaging in homophobic and anti-American pickets, ...
during a live interview. Topiary ran the LulzSec
Twitter Twitter is an online social media and social networking service owned and operated by American company Twitter, Inc., on which users post and interact with 280-character-long messages known as "tweets". Registered users can post, like, and ...
account on a daily basis; following the announcement of LulzSec's dissolution, he deleted all the posts on his Twitter page, except for one, which stated: "You cannot arrest an idea". Police arrested a man from
Shetland Shetland, also called the Shetland Islands and formerly Zetland, is a subarctic archipelago in Scotland lying between Orkney, the Faroe Islands and Norway. It is the northernmost region of the United Kingdom. The islands lie about to the n ...
,
United Kingdom The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom (UK) or Britain, is a country in Europe, off the north-western coast of the continental mainland. It comprises England, Scotland, Wales and ...
suspected of being Topiary on 27 July 2011. The man was later identified as Jake Davis and was charged with five counts, including unauthorized access of a computer and conspiracy. He was indicted on conspiracy charges on 6 March 2012. * Kayla/KMS – Ryan Ackroyd of London, and another unidentified individual known as "lol" or "Shock.ofgod" in LulzSec chat logs. Kayla owned a
botnet A botnet is a group of Internet-connected devices, each of which runs one or more bots. Botnets can be used to perform Distributed Denial-of-Service (DDoS) attacks, steal data, send spam, and allow the attacker to access the device and its conn ...
used by the group in their distributed denial-of-service attacks. The botnet is reported to have consisted of about 800,000 infected
computer server In computing, a server is a piece of computer hardware or software ( computer program) that provides functionality for other programs or devices, called " clients". This architecture is called the client–server model. Servers can provide var ...
s. Kayla was involved in several high-profile attacks under the group "gn0sis". Kayla also may have participated in the Anonymous operation against
HBGary HBGary is a subsidiary company of ManTech International, focused on technology security. In the past, two distinct but affiliated firms had carried the HBGary name: ''HBGary Federal'', which sold its products to the US Government, and ''HBGary ...
. Kayla reportedly wiretapped 2 CIA agents in an anonymous operation. Kayla was also involved in the 2010 media outrage under the Skype handle "Pastorhoudaille". Kayla is suspected of having been something of a deputy to Sabu and to have found the vulnerabilities that allowed LulzSec access to the
United States The United States of America (U.S.A. or USA), commonly known as the United States (U.S. or US) or America, is a country Continental United States, primarily located in North America. It consists of 50 U.S. state, states, a Washington, D.C., ...
Senate systems. One of the men behind the handle Kayla was identified as Ryan Ackroyd of London, arrested, and indicted on conspiracy charges on 6 March 2012. * Tflow – (Real name: Mustafa Al-Bassam) The fourth founding member of the group identified in chat logs, attempts to identify him have labelled him a PHP coder,
web developer A web developer is a programmer who develops World Wide Web applications using a client–server model. The applications typically use HTML, CSS, and JavaScript in the client, and any general-purpose programming language in the server. is used f ...
, and performer of scams on
PayPal PayPal Holdings, Inc. is an American multinational financial technology company operating an online payments system in the majority of countries that support online money transfers, and serves as an electronic alternative to traditional paper ...
. The group placed him in charge of maintenance and security of the group's website lulzsecurity.com.
London London is the capital and List of urban areas in the United Kingdom, largest city of England and the United Kingdom, with a population of just under 9 million. It stands on the River Thames in south-east England at the head of a estuary dow ...
Metropolitan Police announced the arrest of a 16-year-old hacker going by the handle Tflow on 19 July 2011. * Avunit – He is one of the core seven members of the group, but not a founding member. He left the group after their self-labelled "Fuck the FBI Friday". He was also affiliated with Anonymous AnonOps HQ. Avunit is the only one of the core seven members that has not been identified. * Pwnsauce – Pwnsauce joined the group around the same time as Avunit and became one of its core members. He was identified as Darren Martyn of Ireland and was indicted on conspiracy charges on 6 March 2012. The Irish national worked as a local chapter leader for the Open Web Application Security Project, resigning one week before his arrest. * Palladium – Identified as Donncha O'Cearbhaill of Ireland, he was indicted on conspiracy on 6 March 2012. * Anarchaos – Identified as
Jeremy Hammond Jeremy Hammond (born January 8, 1985) is an American activist and former computer hacker from Chicago. He founded the computer security training website HackThisSiteLuman, Stuart. ''Chicago'' Magazine, July 2007"The Hacktivist" in 2003.Hayes, ...
of Chicago, he was arrested on access device fraud and hacking charges. He was also charged with a hacking attack on the U.S. security company Stratfor in December 2011. He is said to be a member of
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anony ...
. * Ryan Cleary, who sometimes used the handle ViraL. Cleary faced a sentence of 32 months in relation to attacks against the US Air Force and others.


Ideology

LulzSec did not appear to hack for financial profit, claiming their main motivation was to have fun by causing mayhem. They did things "for the lulz" and focused on the possible comedic and entertainment value of attacking targets. The group occasionally claimed a political message. When they hacked PBS, they stated they did so in retaliation for what they perceived as unfair treatment of
WikiLeaks WikiLeaks () is an international non-profit organisation that published news leaks and classified media provided by anonymous sources. Julian Assange, an Australian Internet activist, is generally described as its founder and director and ...
in a ''Frontline'' documentary entitled ''WikiSecrets''. A page they inserted on the PBS website included the title "FREE BRADLEY MANNING. FUCK FRONTLINE!" The 20 June announcement of "Operation Anti-Security" contained justification for attacks on government targets, citing supposed government efforts to "dominate and control our Internet ocean" and accusing them of corruption and breaching privacy. The news media most often described them as grey hat hackers. Karim Hijazi, CEO of security company Unveillance, accused the group of
blackmailing Blackmail is an act of coercion using the threat of revealing or publicizing either substantially true or false information about a person or people unless certain demands are met. It is often damaging information, and it may be revealed to fami ...
him by offering not to attack his company or its affiliates in exchange for money. LulzSec responded by claiming that Hijazi offered to pay them to attack his business opponents and that they never intended to take any money from him. LulzSec has denied responsibility for misuse of any of the data they breached and released. Instead, they placed the blame on users who reused passwords on multiple websites and on companies with inadequate security in place. In June 2011, the group released a manifesto outlining why they performed hacks and website takedowns, reiterating that "we do things just because we find it entertaining" and that watching the results can be "priceless". They also claimed to be drawing attention to
computer security Computer security, cybersecurity (cyber security), or information technology security (IT security) is the protection of computer systems and networks from attack by malicious actors that may result in unauthorized information disclosure, t ...
flaws and holes. They contended that many other hackers exploit and steal user information without releasing the names publicly or telling people they may possibly have been hacked. LulzSec said that by releasing lists of hacked usernames or informing the public of vulnerable websites, it gave users the opportunity to change names and passwords elsewhere that might otherwise have been exploited, and businesses would be alarmed and would upgrade their security. The group's later attacks have had a more political tone. They claimed to want to expose the "racist and corrupt nature" of the military and
law enforcement Law enforcement is the activity of some members of government who act in an organized manner to enforce the law by discovering, deterring, rehabilitating, or punishing people who violate the rules and norms governing that society. The term ...
. They have also expressed opposition to the
War on Drugs The war on drugs is a global campaign, led by the United States federal government, of drug prohibition, military aid, and military intervention, with the aim of reducing the illegal drug trade in the United States.Cockburn and St. Clair, 1 ...
. Lulzsec's Operation Anti-Security was characterized as a protest against government censorship and monitoring of the internet. In a question and answer session with BBC ''
Newsnight ''Newsnight'' (or ''BBC Newsnight'') is BBC Two's news and current affairs programme, providing in-depth investigation and analysis of the stories behind the day's headlines. The programme is broadcast on weekdays at 22:30. and is also availa ...
'', LulzSec member Whirlpool (AKA: Topiary) said, "Politically motivated ethical hacking is more fulfilling". He claimed the loosening of
copyright law A copyright is a type of intellectual property that gives its owner the exclusive right to copy, distribute, adapt, display, and perform a creative work, usually for a limited time. The creative work may be in a literary, artistic, educatio ...
s and the rollback of what he sees as corrupt
racial profiling Racial profiling or ethnic profiling is the act of suspecting, targeting or discriminating against a person on the basis of their ethnicity, religion or nationality, rather than on individual suspicion or available evidence. Racial profiling involv ...
practices as some of the group's goals.


Initial targets

The group's first attacks came in May 2011. Their first recorded target was Fox.com, which they retaliated against after they called Common, a rapper and entertainer, "vile" on the
Fox News Channel The Fox News Channel, abbreviated FNC, commonly known as Fox News, and stylized in all caps, is an American multinational conservative cable news television channel based in New York City. It is owned by Fox News Media, which itself is ...
. They leaked several passwords, LinkedIn profiles, and the names of 73,000 X Factor contestants. Soon after on 15 May, they released the transaction logs of 3,100
Automated Teller Machine An automated teller machine (ATM) or cash machine (in British English) is an electronic telecommunications device that enables customers of financial institutions to perform financial transactions, such as cash withdrawals, deposits, fund ...
s in the United Kingdom. In May 2011, members of Lulz Security gained international attention for hacking the American
Public Broadcasting System The Public Broadcasting Service (PBS) is an American public broadcaster and non-commercial, free-to-air television network based in Arlington, Virginia. PBS is a publicly funded nonprofit organization and the most prominent provider of educati ...
(PBS) website. They stole user data and posted a fake story on the site which claimed that
Tupac Shakur Tupac Amaru Shakur ( ; born Lesane Parish Crooks, June 16, 1971 – September 13, 1996), also known as 2Pac and Makaveli, was an American rapper. He is widely considered one of the most influential rappers of all time. Shakur is among the b ...
and
Biggie Smalls Christopher George Latore Wallace (May 21, 1972 – March 9, 1997), better known by his stage names the Notorious B.I.G., Biggie Smalls, or simply Biggie, was an American rapper. Rooted in East Coast hip hop and particularly gangsta ...
were still alive and living in New Zealand. In the aftermath of the attack, CNN referred to the responsible group as the "Lulz Boat". Lulz Security claimed that some of its hacks, including its attack on PBS, were motivated by a desire to defend
WikiLeaks WikiLeaks () is an international non-profit organisation that published news leaks and classified media provided by anonymous sources. Julian Assange, an Australian Internet activist, is generally described as its founder and director and ...
and
Chelsea Manning Chelsea Elizabeth Manning (born Bradley Edward Manning; December 17, 1987) is an American activist and whistleblower. She is a former United States Army soldier who was convicted by court-martial in July 2013 of violations of the Espionage A ...
. A
Fox News The Fox News Channel, abbreviated FNC, commonly known as Fox News, and stylized in all caps, is an American multinational conservative cable news television channel based in New York City. It is owned by Fox News Media, which itself is o ...
report on the group quoted one commentator, Brandon Pike, who claimed that Lulz Security was affiliated with the
hacktivist In Internet activism, hacktivism, or hactivism (a portmanteau of ''hack'' and ''activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. With roots in ha ...
group
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anony ...
. Lulz Security claimed that Pike had actually hired it to hack PBS. Pike denied the accusation and claimed it was leveled against him because he said Lulz Security was a splinter of Anonymous. In June 2011, members of the group claimed responsibility for an attack against
Sony Pictures Sony Pictures Entertainment Inc. (commonly known as Sony Pictures or SPE, and formerly known as Columbia Pictures Entertainment, Inc.) is an American diversified multinational mass media and entertainment studio conglomerate that produces, acq ...
that took data that included "names, passwords, e-mail addresses, home addresses and dates of birth for thousands of people." The group claimed that it used a SQL injection attack, and was motivated by Sony's legal action against
George Hotz George Francis Hotz (born October 2, 1989), alias geohot, is an American security hacker, entrepreneur, and software engineer. He is known for developing iOS jailbreaks, reverse engineering the PlayStation 3, and for the subsequent lawsuit bro ...
for jailbreaking the
PlayStation 3 The PlayStation 3 (PS3) is a home video game console developed by Sony Interactive Entertainment, Sony Computer Entertainment. The successor to the PlayStation 2, it is part of the PlayStation brand of consoles. It was first released on Novemb ...
. The group claimed it would launch an attack that would be the "beginning of the end" for Sony. Some of the compromised user information was subsequently used in scams. The group claimed to have compromised over 1,000,000 accounts, though Sony claimed the real number was around 37,500.


Corporate attacks

Lulz Security attempted to hack into
Nintendo is a Japanese multinational video game company headquartered in Kyoto, Japan. It develops video games and video game consoles. Nintendo was founded in 1889 as by craftsman Fusajiro Yamauchi and originally produced handmade playing cards ...
, but both the group and Nintendo itself report that no particularly valuable information was found by the hackers. LulzSec claimed that it did not mean to harm Nintendo, declaring: "We're not targeting Nintendo. We like the N64 too much — we sincerely hope Nintendo plugs the gap." On 11 June, reports emerged that LulzSec hacked into and stole user information from the pornography website www.pron.com. They obtained and published around 26,000 e-mail addresses and passwords. Among the information stolen were records of two users who subscribed using email addresses associated with the Malaysian government, three users who subscribed using United States military email addresses and 55 users who LulzSec claimed were administrators of other adult-oriented websites. Following the breach, Facebook locked the accounts of all users who had used the published e-mail addresses, and also blocked new Facebook accounts opened using the leaked e-mail addresses, fearing that users of the site would get hacked after LulzSec encouraged people to try and see if these people used identical user name and password combinations on Facebook as well. LulzSec hacked into the
Bethesda Game Studios Bethesda Game Studios is an American video game developer and a studio of ZeniMax Media based in Rockville, Maryland. The company was established in 2001 as the spin-off of Bethesda Softworks' development unit, with Bethesda Softworks itself re ...
network and posted information taken from the network onto the Internet, though they refrained from publishing 200,000 compromised accounts. LulzSec posted to Twitter regarding the attack, "Bethesda, we broke into your site over two months ago. We've had all of your '' Brink'' users for weeks, Please fix your junk, thanks!" On 14 June 2011, LulzSec took down four websites by request of fans as part of their "Titanic Take-down Tuesday". These websites were ''
Minecraft ''Minecraft'' is a sandbox game developed by Mojang Studios. The game was created by Markus "Notch" Persson in the Java programming language. Following several early private testing versions, it was first made public in May 2009 before b ...
'', ''
League of Legends ''League of Legends'' (''LoL''), commonly referred to as ''League'', is a 2009 multiplayer online battle arena video game developed and published by Riot Games. Inspired by '' Defense of the Ancients'', a custom map for ''Warcraft III'', ...
'', ''The Escapist'', and IT security company
FinFisher FinFisher, also known as FinSpy, is surveillance software marketed by Lench IT Solutions plc, which markets the spyware through law enforcement channels. FinFisher can be covertly installed on targets' computers by exploiting security lapses in t ...
. They also attacked the login servers of the massively multiplayer online game ''
EVE Online ''Eve Online'' (stylised ''EVE Online'') is a space-based, persistent world massively multiplayer online role-playing game (MMORPG) developed and published by CCP Games. Players of ''Eve Online'' can participate in a number of in-game profes ...
'', which also disabled the game's front-facing website, and the ''
League of Legends ''League of Legends'' (''LoL''), commonly referred to as ''League'', is a 2009 multiplayer online battle arena video game developed and published by Riot Games. Inspired by '' Defense of the Ancients'', a custom map for ''Warcraft III'', ...
'' login servers. Most of the takedowns were performed with distributed denial-of-service attacks. On 15 June, LulzSec took down the main server of S2 Games' ''
Heroes of Newerth ''Heroes of Newerth'' (''HoN'') was a multiplayer online battle arena (MOBA) video game originally developed by S2 Games for Microsoft Windows, Mac OS X, and Linux. The game idea was derived from the '' Warcraft III: The Frozen Throne'' custo ...
'' as another phone request. They claimed, "''Heroes of Newerth'' master login server is down. They need some treatment. Also, ''DotA'' is better." On 16 June, LulzSec posted a random assortment of 62,000 emails and passwords to
MediaFire MediaFire is a file hosting, file synchronization, and cloud storage service based in Shenandoah, Texas, United States. Founded in June 2006 by Derek Labian and Tom Langridge, the company provides client software for Microsoft Windows, macOS, L ...
. LulzSec stated they released this in return for supporters flooding the
4chan 4chan is an anonymous English-language imageboard website. Launched by Christopher "moot" Poole in October 2003, the site hosts boards dedicated to a wide variety of topics, from anime and manga to video games, cooking, weapons, television, ...
/b/ board. The group did not say what websites the combinations were for and encouraged followers to plug them into various sites until they gained access to an account. Some reported gaining access to Facebook accounts and changing images to sexual content and others to using the Amazon.com accounts of others to purchase several books. Writerspace.com, a literary website, later admitted that the addresses and passwords came from users of their site.


Government-focused activities

LulzSec claimed to have hacked local
InfraGard InfraGard is a national non-profit organization serving as a public-private partnership between U.S. businesses and the Federal Bureau of Investigation. The organization is an information sharing and analysis effort serving the interests, and c ...
chapter sites, a non-profit organization affiliated with the FBI. The group leaked some of InfraGard member e-mails and a database of local users. The group defaced the website posting the following message, "LET IT FLOW YOU STUPID FBI BATTLESHIPS", accompanied with a video. LulzSec posted: On 9 June, LulzSec sent an email to the administrators of the British
National Health Service The National Health Service (NHS) is the umbrella term for the publicly funded healthcare systems of the United Kingdom (UK). Since 1948, they have been funded out of general taxation. There are three systems which are referred to using the " ...
, informing them of a security vulnerability discovered in NHS systems. LulzSec stated that they did not intend to exploit this vulnerability, saying in the email that "We mean you no harm and only want to help you fix your tech issues." On 13 June, LulzSec released the e-mails and passwords of a number of users o
senate.gov
the website of the
United States Senate The United States Senate is the upper chamber of the United States Congress, with the House of Representatives being the lower chamber. Together they compose the national bicameral legislature of the United States. The composition and po ...
. The information released also included the
root directory In a computer file system, and primarily used in the Unix and Unix-like operating systems, the root directory is the first or top-most directory in a hierarchy. It can be likened to the trunk of a tree, as the starting point where all branche ...
of parts of the website. LulzSec stated, "This is a small, just-for-kicks release of some internal data from senate.gov – is this an act of war, gentlemen? Problem?" referencing a recent statement by
the Pentagon The Pentagon is the headquarters building of the United States Department of Defense. It was constructed on an accelerated schedule during World War II. As a symbol of the U.S. military, the phrase ''The Pentagon'' is often used as a metony ...
that some cyberattacks could be considered an act of war. No highly sensitive information appears in the release. On 15 June, LulzSec launched an attack o
CIA.gov
the public website of the United States
Central Intelligence Agency The Central Intelligence Agency (CIA ), known informally as the Agency and historically as the Company, is a civilian foreign intelligence service of the federal government of the United States, officially tasked with gathering, processing, ...
, taking the website offline with a distributed denial-of-service attack. The website was down from 5:48 pm to 8:00 pm
eastern time The Eastern Time Zone (ET) is a time zone encompassing part or all of 23 states in the eastern part of the United States, parts of eastern Canada, the state of Quintana Roo in Mexico, Panama, Colombia, mainland Ecuador, Peru, and a small ...
. On 2 December, an offshoot of LulzSec calling itself LulzSec Portugal, attacked several sites related to the government of Portugal. The websites for the Bank of Portugal, the Assembly of the Republic, and the Ministry of Economy, Innovation and Development all became unavailable for a few hours.


Operation Anti-Security

On 20 June, the group announced it had teamed up with Anonymous for "Operation Anti-Security". They encouraged supporters to steal and publish classified government information from any source while leaving the term "AntiSec" as evidence of their intrusion. Also listed as potential targets were major banks. ''
USA Today ''USA Today'' (stylized in all uppercase) is an American daily middle-market newspaper and news broadcasting company. Founded by Al Neuharth on September 15, 1982, the newspaper operates from Gannett's corporate headquarters in Tysons, Virgini ...
'' characterized the operation as an open declaration of
cyberwarfare Cyberwarfare is the use of cyber attacks against an enemy state, causing comparable harm to actual warfare and/or disrupting vital computer systems. Some intended outcomes could be espionage, sabotage, propaganda, manipulation or economic ...
against big government and corporations. Their first target of the operation was the
Serious Organised Crime Agency The Serious Organised Crime Agency (SOCA) was a non-departmental public body of the Government of the United Kingdom which existed from 1 April 2006 until 7 October 2013. SOCA was a national law enforcement agency with Home Office sponsorship ...
(SOCA), a national
law enforcement agency A law enforcement agency (LEA) is any government agency responsible for the enforcement of the laws. Jurisdiction LEAs which have their ability to apply their powers restricted in some way are said to operate within a jurisdiction. LE ...
of the United Kingdom. LulzSec claimed to have taken the website offline at about 11 am EST on 20 June 2011, though it only remained down for a few minutes. While the attack appeared to be a DDoS attack, LulzSec tweeted that actual hacking was taking place "behind the scenes". At about 6:10 pm EST on 20 June, SOCA's website went down yet again. SOCA's website was back online sometime between 20 and 21 June. The website of the local district government of Jianhua District in
Qiqihar Qiqihar () is the second-largest city in the Heilongjiang province of China, in the west central part of the province. The built-up (or metro) area made up of Longsha, Tiefeng and Jianhua districts had 959,787 inhabitants, while the total populat ...
, China, was also knocked offline. Early in the morning on 22 June, it was revealed that LulzSec's "Brazilian unit" had taken down two Brazilian government websites
brasil.gov.br
an
presidencia.gov.br
They also brought down the website of Brazilian energy company
Petrobras Petróleo Brasileiro S.A., better known by the portmanteau Petrobras (), is a state-owned Brazilian multinational corporation in the petroleum industry headquartered in Rio de Janeiro, Brazil. The company's name translates to Brazilian Petrole ...
. On 20 June, two members on the "Lulz Boat" reportedly leaked logs that LulzSec was going to leak on 21 June. They also claimed that the two had leaked information that aided authorities in locating and arresting Ryan Cleary, a man loosely affiliated with the group. LulzSec posted various personal information about the two on
Pastebin A pastebin or text storage site is a type of online content-hosting service where users can store plain text (e.g. source code snippets for code review via Internet Relay Chat (IRC)). The first pastebin was the eponymous pastebin.com. Other s ...
including
IP address An Internet Protocol address (IP address) is a numerical label such as that is connected to a computer network that uses the Internet Protocol for communication.. Updated by . An IP address serves two main functions: network interface ident ...
es and physical addresses. Both had been involved with cyber-crimes in the past, and one had been involved with hacking the game ''
Deus Ex ''Deus Ex'' is a series of role-playing video games, set during the mid 21st century. Focusing on the conflict between secretive factions who wish to control the world by proxy, and the effects of transhumanistic attitudes and technologies in a ...
''. After LulzSec encouragement, some began tagging public locations with physical
graffiti Graffiti (plural; singular ''graffiti'' or ''graffito'', the latter rarely used except in archeology) is art that is written, painted or drawn on a wall or other surface, usually without permission and within public view. Graffiti ranges from s ...
reading "Antisec" as part of the operation. Numerous beachfronts in
Mission Beach, San Diego Mission Beach is a community built on a sandbar between the Pacific Ocean and Mission Bay. It is part of the city of San Diego, California. Mission Beach spans nearly two miles of ocean front. It is bounded by the San Diego River estuary on the ...
were vandalized with the phrase. Some local news organizations mistook the graffiti in Mission Beach as signs of the Antisec Movement. Many commenters on the local news websites corrected this. On 23 June, LulzSec released a number of documents pertaining to the
Arizona Department of Public Safety The Arizona Department of Public Safety (AZDPS) is a state-level law enforcement agency with a primary function of patrolling and enforcing state laws on Arizona highways. Director Heston Silbert was promoted from Deputy Director to Director in ...
, which they titled "chinga la migra", which roughly translates to "fuck the border patrol". The leaked items included email addresses and passwords, as well as hundreds of documents marked "sensitive" or "for official use only". LulzSec claimed that this was in protest of the
law Law is a set of rules that are created and are enforceable by social or governmental institutions to regulate behavior,Robertson, ''Crimes against humanity'', 90. with its precise definition a matter of longstanding debate. It has been vario ...
passed in Arizona requiring some aliens to carry registration documents at all times. Arizona officials have confirmed the intrusion. Arizona police have complained that the release of officer identities and the method used to combat gangs could endanger the lives of police officers. On 24 June 2011, LulzSecBrazil published what they claimed were access codes and passwords that they used to access the Petrobras website and employee profile data they had taken using the information. Petrobras denied that any data had been stolen, and LulzSecBrazil removed the information from their Twitter feed a few hours later. The group also released personal information regarding
President of Brazil The president of Brazil ( pt, Presidente do Brasil), officially the president of the Federative Republic of Brazil ( pt, Presidente da República Federativa do Brasil) or simply the ''President of the Republic'', is the head of state and head o ...
Dilma Rousseff Dilma Vana Rousseff (; born 14 December 1947) is a Brazilian economist and politician who served as the 36th president of Brazil, holding the position from 2011 until her impeachment and removal from office on 31 August 2016. She is the first ...
and
Mayor of São Paulo In many countries, a mayor is the highest-ranking official in a municipal government such as that of a city or a town. Worldwide, there is a wide variance in local laws and customs regarding the powers and responsibilities of a mayor as well as ...
Gilberto Kassab Gilberto Kassab ( or ; born 12 August 1960) is a Brazilian politician and former mayor of São Paulo. His term ended in 2012. A civil engineer and economist, one of the most famous Brazilians of Syrian descent, Kassab took over from José Serra, ...
. On 25 June 2011, LulzSec released what they described as their last data dump. The release contained an enormous amount of information from various sources. The files contained a half
gigabyte The gigabyte () is a multiple of the unit byte for digital information. The prefix '' giga'' means 109 in the International System of Units (SI). Therefore, one gigabyte is one billion bytes. The unit symbol for the gigabyte is GB. This definit ...
of internal information from telecommunication company
AT&T AT&T Inc. is an American multinational telecommunications holding company headquartered at Whitacre Tower in Downtown Dallas, Texas. It is the world's largest telecommunications company by revenue and the third largest provider of mobile ...
, including information relating to its release of 4G LTE and details pertaining to over 90,000 personal phones used by IBM. The
IP address An Internet Protocol address (IP address) is a numerical label such as that is connected to a computer network that uses the Internet Protocol for communication.. Updated by . An IP address serves two main functions: network interface ident ...
es of several large corporations including Sony, Viacom, and
Disney The Walt Disney Company, commonly known as Disney (), is an American multinational mass media and entertainment conglomerate headquartered at the Walt Disney Studios complex in Burbank, California. Disney was originally founded on October ...
, EMI, and
NBC Universal The National Broadcasting Company (NBC) is an American English-language commercial broadcast television and radio network. The flagship property of the NBC Entertainment division of NBCUniversal, a division of Comcast, its headquarters are ...
were included. It also contained over 750,000 username and password combinations from several websites, including 200,000 email addresses, usernames, and encrypted passwords from hackforums.net; 12,000 names, usernames, and passwords of the
NATO The North Atlantic Treaty Organization (NATO, ; french: Organisation du traité de l'Atlantique nord, ), also called the North Atlantic Alliance, is an intergovernmental military alliance between 30 member states – 28 European and two N ...
online bookshop; half a million usernames and encrypted passwords of players of the online game ''
Battlefield Heroes ''Battlefield Heroes'' was a 2009 third-person shooter video game developed by DICE (company), DICE initially and further developed by Easy Studios, published by Electronic Arts for Microsoft Windows. ''Battlefield Heroes'' was a third-person, ...
''; 50,000 usernames, email addresses, and encrypted passwords of various video game forum users; and 29 users of Priority Investigations, an Irish
private investigation A private investigator (often abbreviated to PI and informally called a private eye), a private detective, or inquiry agent is a person who can be hired by individuals or groups to undertake investigatory law services. Private investigators of ...
company. Also included were an internal manual for
AOL AOL (stylized as Aol., formerly a company known as AOL Inc. and originally known as America Online) is an American web portal and online service provider based in New York City. It is a brand marketed by the current incarnation of Yahoo! Inc. ...
engineering staff and a screencapture of a vandalized page from
navy.mil The United States Navy (USN) is the maritime service branch of the United States Armed Forces and one of the eight uniformed services of the United States. It is the largest and most powerful navy in the world, with the estimated tonnage of ...
, the website of the
United States Navy The United States Navy (USN) is the maritime service branch of the United States Armed Forces and one of the eight uniformed services of the United States. It is the largest and most powerful navy in the world, with the estimated tonnage ...
. Members of the group continued the operation with members of Anonymous after disbanding. Despite claiming to have retired, on 18 July LulzSec hacked into the website of British newspaper '' The Sun''. The group redirected the newspaper's website to an also-hacked redesign website of another newspaper ''
The Times ''The Times'' is a British daily national newspaper based in London. It began in 1785 under the title ''The Daily Universal Register'', adopting its current name on 1 January 1788. ''The Times'' and its sister paper '' The Sunday Times'' ( ...
'', altering the site to resemble ''The Sun'' and posting a fake story claiming that
Rupert Murdoch Keith Rupert Murdoch ( ; born 11 March 1931) is an Australian-born American business magnate. Through his company News Corp, he is the owner of hundreds of local, national, and international publishing outlets around the world, including ...
had died after ingesting a fatal dose of
palladium Palladium is a chemical element with the symbol Pd and atomic number 46. It is a rare and lustrous silvery-white metal discovered in 1803 by the English chemist William Hyde Wollaston. He named it after the asteroid Pallas, which was itself ...
. They objected to the involvement of
News Corporation News Corporation (abbreviated News Corp.), also variously known as News Corporation Limited, was an American multinational mass media corporation controlled by media mogul Rupert Murdoch and headquartered at 1211 Avenue of the Americas in New ...
, the Murdoch-owned company that publishes ''The Sun'' and ''The Times'', in a large
phone hacking scandal The News International phone hacking scandal was a controversy involving the now-defunct ''News of the World'' and other British newspapers owned by Rupert Murdoch. Employees of the newspaper were accused of engaging in phone hacking, police b ...
. The hacked website also contained a webcomic depicting LulzSec deciding on and carrying out the attack. The group later redirected ''The Sun'' website to their Twitter feed. News International released a statement regarding the attacks before having the page the statement appeared on also redirected to the LulzSec Twitter page and eventually taken offline. The group also released the names and phone numbers of a reporter for ''The Sun'' and two others associated with the newspaper and encouraged their supporters to call them. In recent times NovaCygni of AntiSec has openly touted that the news channel Russian Television (RT) has openly stated support for the Anonymous movement and that at least one reporter for them is an active member of Anonymous. They further included an old email address and password of former News International executive
Rebekah Brooks Rebekah Mary Brooks (; born 27 May 1968) is a British media executive and former journalist and newspaper editor. She has been chief executive officer of News UK since 2015. She was previously CEO of News International from 2009 to 2011 and w ...
. News Corporation took the websites offline as a precaution later in the day.


Denied attacks

The media reported a number of attacks, originally attributed to LulzSec, that the group later denied involvement in. On 21 June, someone claiming to be from the group posted on Pastebin that they had stolen the entire database of the
United Kingdom Census 2011 A census of the population of the United Kingdom is taken every ten years. The 2011 census was held in all countries of the UK on 27 March 2011. It was the first UK census which could be completed online via the Internet. The Office for Nationa ...
. LulzSec responded by saying that they had obtained no such data and that whoever posted the notice was not from the group. British officials said they were investigating the incident, but have found no evidence that any databases had been compromised or any information taken. The British government, upon concluding their investigation, called the claims that any information on the census was taken a
hoax A hoax is a widely publicized falsehood so fashioned as to invite reflexive, unthinking acceptance by the greatest number of people of the most varied social identities and of the highest possible social pretensions to gull its victims into pu ...
. In June 2011, assets belonging to newspaper publisher
News International News Corp UK & Ireland Limited (trading as News UK, formerly News International and NI Group) is a British newspaper publisher, and a wholly owned subsidiary of the American mass media conglomerate News Corp. It is the current publisher of ...
were attacked, apparently in retaliation for reporting by ''The Sun'' of the arrest of Ryan Cleary, an associate of the group. The newspaper's website and a computer used in the publishing process of ''
The Times ''The Times'' is a British daily national newspaper based in London. It began in 1785 under the title ''The Daily Universal Register'', adopting its current name on 1 January 1788. ''The Times'' and its sister paper '' The Sunday Times'' ( ...
'' were attacked. However, LulzSec denied any involvement, stating "we didn't attack ''The Sun'' or ''The Times'' in any way with any kind of DDoS attack". Members of AntiSec based in Essex England claimed responsibility for the attack.


Hacker actions against LulzSec

A number of different hackers have targeted LulzSec and its members in response to their activities. On 23 June 2011,
Fox News The Fox News Channel, abbreviated FNC, commonly known as Fox News, and stylized in all caps, is an American multinational conservative cable news television channel based in New York City. It is owned by Fox News Media, which itself is o ...
reported that rival hacker group TeaMp0isoN were responsible for outing web designer Sven Slootweg, who they said used the online nickname Joepie91, and that they have intentions to do the same with every member. A Pastebin post in June 2011 from hacker KillerCube identified LulzSec leader Sabu as Hector Xavier Monsegur, an identification later shown to be accurate. A group calling themselves Team Web Ninjas appeared in June 2011 saying they were angry over the LulzSec release of the e-mail addresses and passwords of thousands of normal Internet users. They attempted to publicly identify the online and real world identities of LulzSec leadership and claimed to do so on behalf of the group's victims. The group claimed to have identified and given to law enforcement the names of a number of the group's members, including someone they claimed to be a
United States Marine The United States Marine Corps (USMC), also referred to as the United States Marines, is the maritime land force service branch of the United States Armed Forces responsible for conducting expeditionary and amphibious operations through com ...
. The Jester, a hacker who generally went by the leetspeak handle th3j35t3r, vowed to find and expose members of LulzSec. Claiming to perform hacks out of a sense of American patriotism, he attempted to obtain and publish the real world
personally identifiable information Personal data, also known as personal information or personally identifiable information (PII), is any information related to an identifiable person. The abbreviation PII is widely accepted in the United States, but the phrase it abbreviates ha ...
of key members, whom he described as "childish". On 24 June 2011, he claimed to have revealed the identity of LulzSec leader Sabu as an information technology consultant possibly from New York City. On 24 June 2011, a hacker allegedly going by the name Oneiroi briefly took down the LulzSec website in what he labelled "Operation Supernova". The Twitter page for the group also briefly became unavailable. On 24 June 2011, ''
The Guardian ''The Guardian'' is a British daily newspaper. It was founded in 1821 as ''The Manchester Guardian'', and changed its name in 1959. Along with its sister papers '' The Observer'' and '' The Guardian Weekly'', ''The Guardian'' is part of the ...
'' published leaked logs from one of the group's IRC channels. The logs were originally assumed to have been leaked by a disillusioned former member of the group who went by the nickname m_nerva, yet fellow hacker Michael Major, known by his handle 'hann', later claimed responsibility. After confirming that the leaked logs were indeed theirs, and that the logs revealed personal information on two members who had recently left the group due to the implications of attacking the FBI website, LulzSec went on to threaten m_nerva on their Twitter feed. LulzSec claimed the logs were not from one of their core chatting channels, but rather a secondary channel used to screen potential backups and gather research. A short time before LulzSec claimed to be disbanding, a group calling itself the A-Team posted what they claimed was a full list of LulzSec members online along with numerous chat logs of the group communicating with each other. A rival hacker going by the name of TriCk also claimed to be working to reveal the group's identities and claimed that efforts on the part of rival hackers had pushed the group to disband for fear of being caught.


Law enforcement response

On 21 June 2011, the
London Metropolitan Police The Metropolitan Police Service (MPS), formerly and still commonly known as the Metropolitan Police (and informally as the Met Police, the Met, Scotland Yard, or the Yard), is the territorial police force responsible for law enforcement and ...
announced that they had arrested a 19-year-old man from
Wickford Wickford is a town and civil parish in the south of the English county of Essex, with a population of 33,486. Located approximately 30 miles (50 km) east of London, it is within the Borough of Basildon along with the original town of Basil ...
, Essex, named by LulzSec and locally as Ryan Cleary, as part of an operation carried out in cooperation with the FBI. The suspect was arrested on charges of computer misuse and
fraud In law, fraud is intentional deception to secure unfair or unlawful gain, or to deprive a victim of a legal right. Fraud can violate civil law (e.g., a fraud victim may sue the fraud perpetrator to avoid the fraud or recover monetary compen ...
, and later charged with five counts of computer hacking under the
Criminal Law Act Criminal Law Act (with its many variations) is a stock short title used for legislation in the Kingdom of Great Britain and later in the United Kingdom, as well as in the Republic of Ireland and the Republic of Singapore. The term encompasse ...
and the Computer Misuse Act. News reports described him as an alleged member of LulzSec. LulzSec denied the man arrested was a member. A member of LulzSec claimed that the suspect was not part of the group, but did host one of its
IRC channel Internet Relay Chat (IRC) is a text-based chat system for instant messaging. IRC is designed for group communication in discussion forums, called '' channels'', but also allows one-on-one communication via private messages as well as chat an ...
s on his server. British police confirmed that he was being questioned regarding alleged involvement in LulzSec attacks against the Serious Organized Crime Agency (SOCA) and other targets. They also questioned him regarding an attack on the
International Federation of the Phonographic Industry The International Federation of the Phonographic Industry (IFPI) is the organisation that represents the interests of the recording industry worldwide. It is a non-profit members' organisation registered in Switzerland and founded in Italy in 1 ...
in November 2010. On 25 June 2011 the court released Cleary under the bail conditions that he not leave his house without his mother and not use any device connected to the internet. He was diagnosed the previous week with
Asperger syndrome Asperger syndrome (AS), also known as Asperger's, is a former neurodevelopmental disorder characterized by significant difficulties in social interaction and nonverbal communication, along with restricted and repetitive patterns of beha ...
. In June 2012 Cleary, together with another suspected LulzSec member, 19-year-old Jake Davis, pleaded guilty conspiring to attack government, law enforcement and media websites in 2011. At around the same time as Cleary's arrest,
Federal Bureau of Investigation The Federal Bureau of Investigation (FBI) is the domestic intelligence and security service of the United States and its principal federal law enforcement agency. Operating under the jurisdiction of the United States Department of Justice ...
agents raided the
Reston, Virginia Reston is a census-designated place in Fairfax County, Virginia and a principal city of the Washington metropolitan area. As of the 2020 U.S. Census, Reston's population was 63,226. Founded in 1964, Reston was influenced by the Garden City move ...
facility of Swiss
web hosting service A web hosting service is a type of Internet hosting service that hosts websites for clients, i.e. it offers the facilities required for them to create and maintain a site and makes it accessible on the World Wide Web. Companies providing web ...
DigitalOne. The raid took several legitimate websites offline for hours as the agency looked for information on an undisclosed target. Media reports speculated the raid may have been related to the LulzSec investigation. A few days before LulzSec disbanded, the FBI executed a
search warrant A search warrant is a court order that a magistrate or judge issues to authorize law enforcement officers to conduct a search of a person, location, or vehicle for evidence of a crime and to confiscate any evidence they find. In most countries, ...
on an
Iowa Iowa () is a U.S. state, state in the Midwestern United States, Midwestern region of the United States, bordered by the Mississippi River to the east and the Missouri River and Big Sioux River to the west. It is bordered by six states: Wiscon ...
home rented by Laurelai Bailey. Authorities interviewed her for five hours and confiscated her hard drives, camera, and other electronic equipment, but no charges were filed. Bailey denied being a member of the group, but admitted chatting with members of LulzSec online and later leaking those chats. The FBI was interested in having her infiltrate the group, but Bailey claimed the members hated her and would never let her in. The questioning by the FBI led a local
technical support Technical support (abbreviated as tech support) is a call centre type customer service provided by companies to advise and assist registered users with issues concerning their technical products. Traditionally done on the phone, technical suppor ...
company to fire Laurelai, claiming she embarrassed the company. On 27 June 2011, the FBI executed another search warrant in
Hamilton, Ohio Hamilton is a city in and the county seat of Butler County, Ohio, United States. Located north of Cincinnati, Hamilton is the second largest city in the Greater Cincinnati area and the 10th largest city in Ohio. The population was 63,399 at ...
. The local media connected the raid to the LulzSec investigation; however, the warrant was sealed, the name of the target was not revealed, and the FBI office in
Cincinnati Cincinnati ( ) is a city in the U.S. state of Ohio and the county seat of Hamilton County. Settled in 1788, the city is located at the northern side of the confluence of the Licking and Ohio rivers, the latter of which marks the state line w ...
refused to comment on any possible connection between the group and the raid. No one was charged with a crime after the FBI served the warrant. Some reports suggested the house may have belonged to former LulzSec member m_nerva, whom was originally suspected of leaking a number of the group's logs to the press, and information leading to the warrant supplied by Ryan Cleary. On 19 July 2011, the London Metropolitan Police announced the arrest of LulzSec member Tflow. A 16-year-old male was arrested in South London on charges of violating the Computer Misuse Act, as part of an operation involving the arrest of several other hackers affiliated with Anonymous in the United States and United Kingdom. LulzSec once again denied that any of their membership had been arrested, stating "there are seven of us, and we're all still here." On the same day the FBI arrested 21-year-old Lance Moore in
Las Cruces, New Mexico Las Cruces (; "the crosses") is the second-largest city in the U.S. state of New Mexico and the seat of Doña Ana County. As of the 2020 census the population was 111,385. Las Cruces is the largest city in both Doña Ana County and southern Ne ...
, accusing him of stealing thousands of documents and applications from AT&T that LulzSec published as part of their so called "final release". The Police Central E-Crime Unit arrested an 18-year-old man from
Shetland Shetland, also called the Shetland Islands and formerly Zetland, is a subarctic archipelago in Scotland lying between Orkney, the Faroe Islands and Norway. It is the northernmost region of the United Kingdom. The islands lie about to the n ...
on 27 July 2011 suspected of being LulzSec member
Topiary Topiary is the horticultural practice of training perennial plants by clipping the foliage and twigs of trees, shrubs and subshrubs to develop and maintain clearly defined shapes, whether geometric or fanciful. The term also refers to plants w ...
. They also searched the house of a 17-year-old from
Lincolnshire Lincolnshire (abbreviated Lincs.) is a Counties of England, county in the East Midlands of England, with a long coastline on the North Sea to the east. It borders Norfolk to the south-east, Cambridgeshire to the south, Rutland to the south-we ...
possibly connected to the investigation, interviewing him. Scotland Yard later identified the man arrested as
Yell, Shetland Yell ( sco, Yell) is one of the North Isles of Shetland, Scotland. In the 2011 census it had a usually resident population of 966. It is the second largest island in Shetland after the Mainland with an area of ,Penrith, James & Deborah (2007) ...
resident Jake Davis. He was charged with unauthorized access of a computer under the
Computer Misuse Act 1990 The Computer Misuse Act 1990 is an Act of the Parliament of the United Kingdom, introduced partly in response to the decision in ''R v Gold & Schifreen'' (1988) 1 AC 1063 (see below). Critics of the bill complained that it was introduced hastily ...
, encouraging or assisting criminal activity under the
Serious Crime Act 2007 The Serious Crime Act 2007 is an Act of the Parliament of the United Kingdom that makes several radical changes to English criminal law. In particular, it creates a new scheme of serious crime prevention orders to frustrate crime in England a ...
, conspiracy to launch a denial-of-service attack against the Serious Organised Crime Unit contrary to the
Criminal Law Act 1977 The Criminal Law Act 1977 (c.45) is an Act of the Parliament of the United Kingdom. Most of it only applies to England and Wales. It creates the offence of conspiracy in English law. It also created offences concerned with criminal trespass in ...
, and
criminal conspiracy In criminal law, a conspiracy is an agreement between two or more persons to commit a crime at some time in the future. Criminal law in some countries or for some conspiracies may require that at least one overt act be undertaken in furtherance ...
also under the Criminal Law Act 1977. Police confiscated a
Dell Dell is an American based technology company. It develops, sells, repairs, and supports computers and related products and services. Dell is owned by its parent company, Dell Technologies. Dell sells personal computers (PCs), servers, data ...
laptop and a 100-gigabyte hard drive that ran 16 different
virtual machine In computing, a virtual machine (VM) is the virtualization/ emulation of a computer system. Virtual machines are based on computer architectures and provide functionality of a physical computer. Their implementations may involve specialized h ...
s. Details relating to an attack on Sony and hundreds of thousands of email addresses and passwords were found on the computer. A London court released Davis on bail under the conditions that he live under curfew with his parents and have no access to the internet. His lawyer Gideon Cammerman stated that, while his client did help publicize LulzSec and Anonymous attacks, he lacked the technical skills to have been anything but a sympathizer. In early September 2011, Scotland Yard made two further arrests relating to LulzSec. Police arrested a 24-year-old male in
Mexborough Mexborough is a town in the City of Doncaster in South Yorkshire, England. Situated between Manvers and Denaby Main, it lies on the River Don close to where it joins the River Dearne, and the A6023 road runs through the town. It is contiguous ...
,
South Yorkshire South Yorkshire is a ceremonial and metropolitan county in the Yorkshire and Humber Region of England. The county has four council areas which are the cities of Doncaster and Sheffield as well as the boroughs of Barnsley and Rotherham. ...
and a 20-year-old male in
Warminster Warminster () is an ancient market town with a nearby garrison, and civil parish in south west Wiltshire, England, on the western edge of Salisbury Plain. The parish had a population of about 17,000 in 2011. The 11th-century Minster Church o ...
,
Wiltshire Wiltshire (; abbreviated Wilts) is a historic and ceremonial county in South West England with an area of . It is landlocked and borders the counties of Dorset to the southwest, Somerset to the west, Hampshire to the southeast, Gloucestershire ...
. The two were accused of conspiring to commit offenses under the Computer Misuse Act of 1990; police said that the arrests related to investigations into LulzSec member Kayla. On 22 September 2011, the FBI arrested Cody Kretsinger, a 23-year-old from
Phoenix, Arizona Phoenix ( ; nv, Hoozdo; es, Fénix or , yuf-x-wal, Banyà:nyuwá) is the List of capitals in the United States, capital and List of cities and towns in Arizona#List of cities and towns, most populous city of the U.S. state of Arizona, with 1 ...
who was indicted on charges of conspiracy and the unauthorized impairment of a protected computer. He is suspected of using the name "recursion" and assisting LulzSec in their early hack against Sony Pictures Entertainment, though he allegedly erased the hard drives he used to carry out the attack. Kretsinger was released on his own recognizance under the conditions that he not access the internet except while at work and that he not travel to any states other than Arizona, California, or Illinois. The case against him was filed in Los Angeles, where Sony Pictures is located. Kretsinger pleaded guilty on 5 April 2012 to one count of conspiracy and one count of unauthorized impairment of a protected computer. On 19 April 2013, Kretsinger was sentenced for the "unauthorized impairment of protected computers" to one year in federal prison, one year of home detention following the completion of his prison sentence, a fine of $605,663 in restitution to Sony Pictures and 1000 hours of community service. On 8 August 2013, Raynaldo Rivera, age 21, known by the online moniker "neuron", of Chandler, Arizona, was sentenced to one year and one day in federal prison by United States District Judge John A. Kronstadt. In addition to the prison sentence, Judge Kronstadt ordered Rivera to serve 13 months of home detention, to perform 1,000 hours of community service and to pay $605,663 in restitution to Sony Pictures. On 6 March 2012, two men from Great Britain, one from the United States, and two from Ireland were charged in connection to their alleged involvement with LulzSec. The FBI revealed that supposed LulzSec leader Hector Xavier Monsegur, who went by the username Sabu, had been aiding law enforcement since pleading guilty to twelve counts, including conspiracy and computer hacking, on 15 August 2011 as part of a
plea deal A plea bargain (also plea agreement or plea deal) is an agreement in criminal law proceedings, whereby the prosecutor provides a concession to the defendant in exchange for a plea of guilt or ''nolo contendere.'' This may mean that the defendant ...
. In exchange for his cooperation, federal prosecutors agreed not to prosecute Monsegur for his computer hacking, and also not to prosecute him for two attempts to sell
marijuana Cannabis, also known as marijuana among other names, is a psychoactive drug from the cannabis plant. Native to Central or South Asia, the cannabis plant has been used as a drug for both recreational and entheogenic purposes and in various t ...
, possession of an illegal handgun, purchasing stolen property, charging $15,000 to his former employer's credit card in a case of
identity theft Identity theft occurs when someone uses another person's personal identifying information, like their name, identifying number, or credit card number, without their permission, to commit fraud or other crimes. The term ''identity theft'' was c ...
, and directing people to buy prescription drugs from illegal sources. He still faces a misdemeanor charge of impersonating a federal agent. Five suspects were charged with conspiracy: Jake Davis, accused of being the hacker "Topiary" (who had been previously arrested); Ryan Ackroyd of London, accused of being "Kayla"; Darren Martyn of Ireland, accused of being "pwnsauce"; Donncha O’Cearrbhail of Ireland, accused of being "palladium"; and Jeremy Hammond of
Chicago (''City in a Garden''); I Will , image_map = , map_caption = Interactive Map of Chicago , coordinates = , coordinates_footnotes = , subdivision_type = List of sovereign states, Count ...
, accused of being "Anarchaos". While not a member of LulzSec, authorities suspect Hammond of being a member of Anonymous and charged him with access device fraud and hacking in relation to his supposed involvement in the December 2011 attack on intelligence company
Stratfor Strategic Forecasting Inc., commonly known as Stratfor, is an American geopolitics publisher and consultancy founded in 1996. Stratfor's business model is to provide individual and enterprise subscriptions to Stratfor Worldview, its online public ...
as part of Operation AntiSec. On 8 April 2013, Jake 'Topiary' Davis and three other LulzSec members pleaded guilty to charges of computer hacking at Southwark Crown Court in London. On 24 April 2013,
Australian Federal Police The Australian Federal Police (AFP) is the national and principal federal law enforcement agency of the Australian Government with the unique role of investigating crime and protecting the national security of the Commonwealth of Australia. ...
arrested 24-year-old Matthew Flannery of Point Clare, who boasted on Facebook "I’m the leader of LulzSec". Flannery, who went by the username Aush0k, was arrested for the alleged hacking of the Narrabri Shire Council website on which homepage sexually explicit text and an image were left. On 27 August 2014, Flannery entered guilty pleas to five charges of making unauthorised modification of data to cause impairment, and dishonestly obtaining the Commonwealth Bank details of a woman. Flannery, who said the reference to LulzSec was a joke, lost his job of computer technician in a security company. On 16 October 2014, he was sentenced to 15 months of house arrest which continues until mid-April 2016, alongside a 12 months good behaviour bond.


See also

*
Anonymous (group) Anonymous is a decentralized international activist and hacktivist collective and movement primarily known for its various cyberattacks against several governments, government institutions and government agencies, corporations and the Chu ...
*
Hacktivism In Internet activism, hacktivism, or hactivism (a portmanteau of ''hack'' and ''activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. With roots in hac ...
*
LulzRaft LulzRaft is the name of a computer hacker group or individual that gained international attention in 2011 due to a series of high-profile attacks on Canadian websites. Their targets have included the Conservative Party of Canada and Husky Energy. ...
* MalSec * Operation AntiSec *
Operation Payback Operation or Operations may refer to: Arts, entertainment and media * ''Operation'' (game), a battery-operated board game that challenges dexterity * Operation (music), a term used in musical set theory * ''Operations'' (magazine), Multi-Ma ...
*
2011 PlayStation Network outage The 2011 PlayStation Network outage (sometimes referred to as the PSN Hack) was the result of an " external intrusion" on Sony's PlayStation Network and Qriocity services, in which personal details from approximately 77 million accounts were comp ...
* Securax


References


External links

* *
Lulzsecurity.org
Current website referencing the latest attacks the group LuLzSecReborn {{DEFAULTSORT:Lulz Security Wikipedia articles with ASCII art Hacker groups Anonymous (hacker group) Hacktivists