LulzSec carried out a short but highly visible campaign of intrusions and disruption against media, government, law-enforcement, and gaming targets, including PBS, Sony Pictures, the U.S. Senate, InfraGard, the CIA website, and the UK's SOCA. The group used website defacements, data theft, credential leaks, SQL injection, and distributed denial-of-service attacks, while amplifying its notoriety through Twitter, leaked data dumps, a public call-in line for target suggestions, and the broader AntiSec push alongside Anonymous. One early operation followed PBS reporting on WikiLeaks, and later leaked chat logs portrayed LulzSec as a small, publicity-driven but operationally cautious crew led by Sabu, with members such as Topiary and Kayla, amid internal strain and growing fear of retaliation.
Law-enforcement pressure quickly escalated on both sides of the Atlantic. British police arrested and charged Ryan Cleary over alleged botnet and DDoS activity tied to attacks including SOCA, though LulzSec denied he was a core member, and later cases identified Jake Davis, Ryan Ackroyd, and others as participants or associates. In the U.S., authorities revealed that LulzSec leader Hector Xavier Monsegur (Sabu) had become an FBI informant after his arrest, helping investigators prevent hundreds of attacks and identify co-conspirators. The group announced it was disbanding after roughly 50 days, but prosecutions continued: multiple suspects were arrested in coordinated international operations, two British members later pleaded guilty, and subsequent court filings tied the campaign to substantial financial and operational damage across numerous victims.

TTPs, infrastructure, and targeting history in one profile.
21 events from the most recent confirmed update back to the earliest known activity.
After cooperating with investigators, Hector Xavier Monsegur was sentenced in New York and left court a free man.
Court documents said Hector Xavier Monsegur, known as 'Sabu,' provided extensive post-arrest cooperation to the FBI that helped prevent roughly 300 cyberattacks and supported multiple prosecutions.
Reporting in April 2013 said LulzSec hacktivists pleaded guilty to cyberattacks affecting organizations including the NHS, Sony, and News International.
Ryan Cleary and Jake Davis pleaded guilty in London to conspiring with LulzSec members to attack government, media, and law-enforcement websites.
Authorities announced charges against five men in the U.K., Ireland, New York, and Chicago for hacking-related offenses tied to LulzSec, while reporting said alleged leader Hector Xavier Monsegur had already pleaded guilty.
Authorities in the United Kingdom, United States, and the Netherlands carried out coordinated arrests and searches targeting suspected members or associates of LulzSec and Anonymous.
The Metropolitan Police arrested two men in a coordinated international investigation into attacks attributed to LulzSec and Anonymous, saying the suspects were linked to offenses associated with the online identity 'Kayla.'
A teenager from Shetland was charged in connection with computer hacking allegations tied to the LulzSec investigation.
FBI agents searched the Hamilton, Ohio home of a teenager suspected of being LulzSec member 'm_nerva,' though no charges were filed at that time.
A teenager accused of attacking the SOCA website in the LulzSec investigation was released on conditional bail in the UK.
LulzSec said it was ending operations after a 50-day run of high-profile attacks, citing its farewell in a final release that also encouraged support for Anonymous and AntiSec.
Reporting on June 24 said LulzSec publicly denied responsibility for retaliatory attacks on The Sun and The Times websites following Ryan Cleary's arrest and charging.
British authorities charged Ryan Cleary with offenses tied to distributed denial-of-service attacks, including one connected to the Serious Organised Crime Agency website, while investigators examined seized equipment for broader links.
After a Pastebin post claimed LulzSec had obtained 2011 UK census records, the group publicly denied responsibility and warned that fake releases should not be trusted unless confirmed through its Twitter account.
British police arrested 19-year-old Ryan Cleary at his home in Wickford, Essex, in an investigation linked to attacks believed tied to LulzSec, with assistance from the FBI.
LulzSec said it had knocked the CIA website offline in a denial-of-service attack, and the CIA stated that it was investigating the incident.
LulzSec publicized a call-in number on Twitter to solicit target suggestions from the public as part of its campaign activity, claiming to receive thousands of calls and voicemails.
Leaked logs published in early June linked LulzSec participants to Anonymous-associated channels and showed internal discussions about operational security, media strategy, and ongoing attacks.
LulzSec targeted an FBI-affiliated InfraGard website, an intrusion later cited in reporting and leaked chat logs as a significant escalation that increased internal concern about law-enforcement attention.
In interviews following the PBS intrusion, LulzSec said it attacked the broadcaster for what it viewed as unfair treatment of WikiLeaks and framed the operation as done for 'lulz and justice.'
LulzSec compromised PBS.org after the broadcaster aired a critical WikiLeaks documentary and defaced the site with a false report claiming Tupac Shakur was alive in New Zealand.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
34 references tracked. Mallory keeps watching after this page renders.
pcmag.com
Open sourcetheguardian.com
Open sourcetheguardian.com
Open sourcetheguardian.com
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourcepastebin.com
Open sourceforbes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.