Hacktivist group SiegedSec claimed it stole and leaked about 2GB of data tied to The Heritage Foundation, saying the operation was part of its #OpTransRights campaign and motivated by opposition to Project 2025. Reports said the exposed material included usernames, passwords or partial password data, email addresses, logs, comments, and IP address information, with SiegedSec asserting it had compromised a Heritage-linked server and published a ZIP archive of the data on Telegram before the public dump was later removed. The group framed the intrusion as retaliation against policies it said threatened abortion access and LGBTQ+ communities.
The Heritage Foundation disputed the breach claims, saying its core systems were not compromised and that the data came from a publicly accessible, two-year-old archive of The Daily Signal hosted by a contractor, affecting contributor and commenter records rather than internal Heritage systems. SiegedSec rejected that account and pointed to an allegedly hostile exchange involving Heritage Oversight Project executive director Mike Howell as evidence the organization was downplaying the incident. Shortly after publicizing the leak, SiegedSec announced it was disbanding, citing mental health strain, unwanted publicity, and concern about FBI attention.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
By July 12, 2024, reporting indicated that the public dump of the allegedly stolen Heritage Foundation data had been removed from public access. The takedown followed the group's leak and the ensuing dispute over what systems or data had actually been exposed.
Shortly after publicizing the alleged Heritage breach, SiegedSec said on Telegram that it was disbanding. Members cited mental health strain, publicity, and concern about FBI attention as reasons for ending the group.
On July 11, 2024, the Heritage Foundation disputed SiegedSec's claims, saying attackers did not breach its systems but instead accessed a publicly available two-year-old Daily Signal archive hosted by a contractor. Heritage said the exposed information was limited to contributor and commenter data, including usernames, names, email addresses, incomplete password data, comments, and commenter IP addresses.
By July 9, 2024, hacktivist group SiegedSec publicly claimed it had breached the Heritage Foundation as part of its #OpTransRights campaign and released roughly 2GB of allegedly stolen data. The group said the leak included usernames, passwords, logs, and other internal or user information tied to Heritage and The Daily Signal.
Salon reports that in April 2024, the Heritage Foundation attributed a separate cyberattack to nation-state hackers and said it had to shut down its network in response. This is described as an earlier incident preceding the July SiegedSec claims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcetheverge.com
Open sourcesalon.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.