SiegedSec, also known as Sieged Security, was a self-described hacktivist and black-hat collective active from early 2022 until it announced its disbandment in July 2024. The group publicly branded itself as “gay furry hackers” and was associated with the alias vio, identified in reporting as its leader. SiegedSec combined ideologically framed operations with opportunistic and amusement-driven intrusions, and has been characterized as a hacktivist operation with criminal behavior rather than a financially driven enterprise. The group targeted a broad mix of government, intergovernmental, research, media, religious, telecommunications, and politically opposed organizations. Reported victims and claimed targets included NATO portals, Idaho National Laboratory, Atlassian, U.S. state and local government entities, Real America’s Voice, River Valley Church, The Heritage Foundation, and satellite receiver infrastructure in multiple countries. SiegedSec also claimed associations or collaborations with other hacktivist groups including Anonymous Sudan, KittenSec, ThreatSec, ByteMeCrew, Ghost Security, and the so-called Five Families alliance. SiegedSec’s operations frequently involved unauthorized access to internet-exposed systems, credential abuse, data theft, public leaking of stolen information, and occasional claims of destructive actions such as wiping data. The group demonstrated capabilities spanning initial access, credential theft, exfiltration, spoofing, reconnaissance, and post-exploitation. Publicly described tradecraft included use of stolen credentials, exploitation of exposed services, compromise of portals and databases, access to HR and user records, and abuse of messaging infrastructure to send spoofed communications. In one incident, the group claimed opportunistic access to a university listserv using exposed credentials found in a public code repository. In other incidents it claimed breaches of NATO collaboration portals and internet-accessible GNSS receiver infrastructure. A recurring theme in SiegedSec’s activity was politically motivated targeting under banners such as #OpTransRights and #OpTransRights2. These campaigns were framed as retaliation against organizations and U.S. states the group viewed as hostile to transgender rights, abortion access, or LGBTQ+ communities. Targets linked to these themes included U.S. state government entities, churches accused of anti-trans rhetoric, Real America’s Voice, and The Heritage Foundation over Project 2025. At the same time, statements attributed to the group and its leadership also emphasized hacking “for the lulz,” indicating mixed ideological and amusement-driven motives. SiegedSec also claimed anti-NATO and anti-Israel operations. It publicly framed alleged NATO intrusions as retaliation for perceived human-rights abuses by NATO member states and claimed compromises affecting users across numerous alliance countries. During the Gaza conflict period, the group was reported as collaborating with other hacktivist actors in claimed attacks on Israeli telecommunications and infrastructure-related targets. The group announced its disbandment after the Heritage Foundation incident, citing mental health strain, publicity pressure, and concern about FBI attention. Despite the disbandment claim, SiegedSec remains notable for blending hacktivist messaging, public spectacle, politically themed targeting, and criminal intrusion behavior across a diverse victim set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a data leak operation targeting the Heritage Foundation, allegedly obtaining archived website data and leaking chat logs in retaliation for the release of the Project 2025 policy proposal collection; the group also announced its disbandment.
Hacktivist group that claimed responsibility for breaching The Heritage Foundation and leaking data in opposition to Project 2025. The content also says the group previously targeted a US nuclear power lab, Atlassian, and NATO, and that it does not seek money but acts for political and ideological reasons.
Hacktivist collective claiming responsibility for breaching the Heritage Foundation and releasing internal data as part of its #OpTransRights campaign; also claimed prior targeting of NATO systems, Real America’s Voice, and Hillsong.
Hacktivist intrusion and data theft targeting the Heritage Foundation over opposition to Project 2025; also reportedly targeted Israeli companies and churches for political and ideological reasons.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.