SiegedSec, also known as Sieged Security and self-described as the “Gay Furry Hackers,” is a black-hat hacktivist collective formed in early 2022. Led by an individual using the alias vio, the group became known for politically motivated intrusions and public data leaks, alongside opportunistic attacks conducted for amusement. It announced its disbandment on July 10, 2024, citing mental health concerns, publicity-related stress, and a desire to avoid FBI scrutiny. The group targeted U.S. government entities, NATO information-sharing portals, technology companies, telecommunications providers, religious organizations, and conservative political and media organizations. Its #OpTransRights campaigns opposed restrictions on gender-affirming care and organizations it considered hostile to LGBTQ+ rights. Targets included the city of Fort Worth, the Nebraska Supreme Court, Real America’s Voice, and River Valley Church. In July 2024, it published data associated with The Heritage Foundation in opposition to Project 2025; Heritage disputed a compromise of its internal systems and identified the exposed material as an older archive of The Daily Signal. SiegedSec’s activities included credential-based unauthorized access, theft and publication of employee and user information, and abuse of compromised communications systems. Its Atlassian intrusion involved stolen employee credentials and exposed employee records. A breach affecting Idaho National Laboratory involved an external vendor system supporting cloud human-resources services. The group also published unclassified documents and personnel information associated with NATO portals; NATO acknowledged security incidents affecting unclassified websites and reported no impact on missions, operations, or military deployments. At the University of Connecticut, unauthorized access to a restricted listserv enabled fictitious announcements impersonating university communications. SiegedSec additionally accessed satellite receivers in Colombia and targeted devices in the United States. SiegedSec was a constituent of the Five Families coalition alongside ThreatSec, GhostSec, Stormous, and BlackForums. Its principal operational pattern was hack-and-leak activity rather than ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for denial-of-service attacks against Israeli infrastructure and industrial control systems during the Israel-Hamas conflict; available NetFlow data did not indicate successful attacks at the listed target IPs.
Attacked The Heritage Foundation because of its Project 2025 proposals. The breach exposed names, email addresses, passwords, and usernames associated with the think tank. The incident is used as a concrete example of politically motivated targeting and the reputational risks facing politically engaged organizations.
Conducted a data leak operation targeting the Heritage Foundation, allegedly obtaining archived website data and leaking chat logs in retaliation for the release of the Project 2025 policy proposal collection; the group also announced its disbandment.
Hacktivist group that claimed responsibility for breaching The Heritage Foundation and leaking data in opposition to Project 2025. The content also says the group previously targeted a US nuclear power lab, Atlassian, and NATO, and that it does not seek money but acts for political and ideological reasons.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.