SiegedSec, also known as Sieged Security, was a self-described hacktivist and black-hat collective active from early 2022 until it announced its disbandment in July 2024. The group was led by the alias "vio" and became widely known for politically themed intrusion-and-leak operations, opportunistic compromises, and provocative public messaging. It frequently branded itself as "gay furry hackers" and ran campaigns such as #OpTransRights and #OpTransRights2 against organizations it viewed as anti-trans or otherwise politically opposed to its stated causes. SiegedSec targeted a broad mix of government, intergovernmental, research, media, religious, telecommunications, and private-sector entities. Reported victims and claimed targets included NATO portals, Idaho National Laboratory, Atlassian, U.S. state and local government systems, Real America’s Voice, River Valley Church, The Heritage Foundation, and Israeli telecommunications and infrastructure-related entities. The group also claimed access to satellite or GNSS receivers in multiple countries and participated in anti-Israel operations during the Israel-Hamas conflict, including claimed denial-of-service activity against Israeli infrastructure in collaboration with Anonymous Sudan. Some of those claims were publicly disputed or not independently confirmed, so operational impact varied by incident. Its tradecraft combined credential abuse, unauthorized access to exposed internet-facing systems, data theft and public leaking, spoofing, and occasional claims of destructive actions such as wiping data. SiegedSec repeatedly publicized stolen records and internal documents, including personnel data and user information, and in some cases claimed to have deleted or altered victim data. The group also conducted nuisance and influence-style actions, such as sending spoofed messages through a university listserv. Reported operations indicate capabilities spanning initial access, credential theft, exfiltration, reconnaissance, scanning, spoofing, and post-exploitation. In several campaigns, the primary objective appeared to be public exposure, embarrassment, or ideological signaling rather than sustained covert access. SiegedSec maintained relationships or claimed collaborations with other hacktivist or criminal actors, including Anonymous Sudan, KittenSec, ThreatSec, ByteMeCrew, and an alliance referred to as the Five Families. Its motivations were predominantly hacktivist, especially around transgender rights and opposition to conservative or anti-LGBTQ positions, though reporting also characterized the group as amusement-driven and at times criminally opportunistic. The group announced it had disbanded citing mental health strain, publicity, and concern about law-enforcement attention.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for denial-of-service attacks against Israeli infrastructure and industrial control systems during the Israel-Hamas conflict; available NetFlow data did not indicate successful attacks at the listed target IPs.
Conducted a data leak operation targeting the Heritage Foundation, allegedly obtaining archived website data and leaking chat logs in retaliation for the release of the Project 2025 policy proposal collection; the group also announced its disbandment.
Hacktivist group that claimed responsibility for breaching The Heritage Foundation and leaking data in opposition to Project 2025. The content also says the group previously targeted a US nuclear power lab, Atlassian, and NATO, and that it does not seek money but acts for political and ideological reasons.
Hacktivist collective claiming responsibility for breaching the Heritage Foundation and releasing internal data as part of its #OpTransRights campaign; also claimed prior targeting of NATO systems, Real America’s Voice, and Hillsong.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.