Anonymous-affiliated attackers breached private intelligence firm Stratfor, stealing subscriber records, payment data, and a vast archive of internal correspondence. Reporting on the intrusion said the attackers accessed administrative systems, expanded into databases and mail servers, and exfiltrated data affecting about 860,000 user accounts and more than 60,000 credit cards; some reports said card numbers were stored in plaintext, while passwords were protected with weak unsalted MD5 hashes. The attackers defaced Stratfor’s website, deleted server contents, published stolen card data, and used some of the payment information for fraudulent charitable donations, contributing to losses that reports put at at least $700,000 and broader damages of roughly $2 million.
The breach escalated when WikiLeaks began publishing roughly 5 million Stratfor emails, exposing the firm’s client relationships, source-handling practices, monitoring of activist groups, and sensitive geopolitical claims contained in internal messages. Subsequent reporting said the FBI had visibility into parts of the operation through informant Hector Xavier Monsegur ("Sabu") and later built its case against alleged participant Jeremy Hammond, while Stratfor faced delayed customer notification and legal fallout. Years later, researchers also warned that some documents in the leaked Stratfor archive contained live malware, including files exploiting CVE-2010-3333, creating additional risk for journalists and researchers who downloaded the material.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
In July 2015, researchers warned that documents in WikiLeaks' searchable Stratfor archive still contained malicious attachments, including files exploiting older Microsoft Office vulnerabilities such as CVE-2010-3333. They advised journalists and researchers to handle the leaked files cautiously and in isolated environments.
Have I Been Pwned cataloged the Stratfor breach in March 2026, summarizing the December 2011 attack and the exposed data types, including email addresses, internal system data, time zones, and unsalted MD5 password hashes. The listing also noted the theft of credit card data and its fraudulent use.
After the compromise and delayed notifications, Stratfor faced a class-action lawsuit from affected customers. Reporting also said the company estimated roughly $2 million in damages and lost revenue from the incident.
In early March 2012, court filings and investigative reporting described how Jeremy Hammond and other Antisec members allegedly accessed Stratfor through an admin panel, moved into databases and mail servers, and stole more than 60,000 payment cards and extensive email archives. The reports also said four servers were wiped and 30,000 card numbers were published.
As WikiLeaks began publishing the emails, Stratfor CEO George Friedman said the disclosures were being overstated and denied wrongdoing, while also suggesting some messages might have been altered. The company framed the leak as embarrassing but not proof of criminal conduct.
In late February 2012, WikiLeaks started releasing about five million emails taken from Stratfor, exposing internal correspondence, source-handling practices, and client-related intelligence work. The publication was described as a partnership with Anonymous.
Following the breach, Stratfor postponed notifying affected customers because of an FBI request tied to the ongoing investigation. The delay later became part of the public controversy and subsequent litigation around the incident.
By late December 2011, the attackers had released stolen subscriber information, including email addresses, passwords, and credit card details, and used some of the cards for unauthorized charitable donations and other purchases. Reports put fraudulent charges at at least $700,000.
In late December 2011, attackers linked to Anonymous/Antisec compromised Stratfor's systems, defaced its website, and gained access to customer data, internal systems, and large volumes of email. Reporting indicates the intrusion exposed roughly 860,000 user accounts and tens of thousands of payment cards.
After learning of the breach on December 6, 2011, the FBI used informant Hector Xavier Monsegur ("Sabu") to monitor the attackers, collect evidence, and receive stolen data transferred to FBI-controlled systems. The bureau later said the compromise was already well underway when it acted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
haveibeenpwned.com
Open sourcetheregister.com
Open sourceweb.archive.org
Open sourcetheguardian.com
Open sourcehaaretz.com
Open sourcewikileaks.org
Open sourcebits.blogs.nytimes.com
Open sourcejoshwieder.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.