Record ID: GRP-0002
Type: Hacktivist Collective
Status: Dissolved
Active Since: 2022
SiegedSec was a black‑hat hacktivist collective that self‑described as “gay furry hackers” and blended a queer furry online persona with aggressive political hacking campaigns. Emerging in early 2022 around a Telegram channel and related social accounts, the group quickly gained notoriety for defacements, data breaches and leaks targeting governments, critical infrastructure, and conservative organisations across North America, Europe and beyond.
SiegedSec’s operations mixed ideological motives—especially support for LGBTQ+ and trans rights, opposition to conservative and Christian nationalist politics, and anti‑authoritarian rhetoric—with trolling‑inflected humour, vulgar messaging, and sometimes seemingly “for fun” intrusions. High‑profile victims included NATO portals, the Idaho National Laboratory, multiple US state and local governments involved in anti‑trans legislation, Atlassian, a multinational energy firm, and the Heritage Foundation’s Project 2025 infrastructure. The group announced its disbandment on 2024‑07‑10, shortly after claiming a major breach of the Heritage Foundation, citing stress, mental‑health issues and fear of intensified FBI scrutiny.
(Handles above are drawn from open‑source and media reporting; no real‑world identities are asserted here.)
2022-04-01 — SiegedSec’s Telegram channel and branding appear, with sources first observing the group in April 2022 as a new hacktivist outfit styling itself as “gay furry hackers” (month from reporting; exact day approximate). 2023-02-14 — Atlassian breach: SiegedSec uses stolen employee credentials to access internal systems, leaking around 13,000 employee records and office floor plans. 2023-06-23 — “OpTransRights” US state/local government attacks: the group compromises sites and systems for Fort Worth (Texas) and multiple US states (Nebraska, Pennsylvania, South Carolina, South Dakota, Texas) in protest against anti‑trans and anti‑gender‑affirming‑care legislation. 2023-10-04 — NATO portals breach: SiegedSec claims theft of about 3,000 NATO documents (~9 GB of largely unclassified data) from various NATO e‑learning and coordination portals; NATO publicly confirms an investigation. 2023-11-20 — Idaho National Laboratory breach: the group exfiltrates HR data from the US nuclear research facility INL and posts it online, issuing an unusual ransom demand that the lab start a “catgirl research program.” 2024-04-16 — Multinational energy organisation incident: SiegedSec leaks personal data and internal administrative information from an unnamed energy company, claiming access to its admin panel. 2024-07-09 — Heritage Foundation / Project 2025 breach: the group claims to have stolen more than 200 GB of data, including credentials and PII tied to the conservative Heritage Foundation and its Project 2025 initiative. 2024-07-10 — SiegedSec announces it is disbanding following the Heritage attack, citing mental‑health stress and fear of increased FBI scrutiny while acknowledging the risk created by their high‑profile breaches. 2025-03-31 — Reports emerge that the FBI raided vio, SiegedSec’s alleged leader, indicating continued law‑enforcement focus on the group’s past operations despite the 2024 disbandment. | Ref | Source | Date | Notes |
|---|---|---|---|
| cybernews | Wikipedia: SiegedSec | 2024-04-30 | High‑level overview of SiegedSec’s origin, ideology, major operations (NATO, INL, Heritage, Real America’s Voice) and the July 2024 disbandment announcement. |
| cybernews | TheSecMaster: “SiegedSec: Gay Furry Hackers & Hacktivist Group” | 2025-03-10 | Threat‑actor profile detailing the group’s “gay furry hackers” branding, tactics, ideological focus on trans rights, and the role of leader vio/YourAnonWolf. |
| hookphish | Flare: “The Rise and Fall of SiegedSec” | 2026-04-23 | Narrative of SiegedSec’s lifecycle from 2022 creation to 2024 shutdown, emphasising early Telegram channel activity, use of SQLi/XSS, and evolving campaigns. |
| scamadviser | Dataminr case study on SiegedSec | 2024-08-07 | Case study summarising SiegedSec’s attacks on a multinational energy organisation, Atlassian, Fort Worth, and Idaho National Laboratory, with emphasis on TTPs (SQLi, XSS). |
| SecurityAffairs: NATO investigating SiegedSec attack | 2023-10-04 | Describes NATO’s investigation into SiegedSec’s claimed breach of several NATO portals and the leak of about 3,000 documents (~9 GB). | |
| msspalert | The Advocate: FBI raids leader of gay furry hackers | 2025-03-31 | Reports an FBI raid on SiegedSec’s leader (vio), recounts earlier US state government attacks and the Heritage Foundation/Project 2025 breach. |
| hackread | ZeroFox: “The Underground Economist” (SiegedSec disbandment) | 2024-07-xx | Notes SiegedSec’s membership in “The Five Families,” their self‑description as “gay furry hackers,” the Project 2025 breach, and the subsequent disbandment announcement. |
| github | GAY45: “SiegedSec, the Gay Furry Hackers Who Rewrote Cyber Activism” | 2025-02-25 | Investigative feature discussing SiegedSec’s queer/furry identity, political motivations, and impact on hacktivism, including NATO and Project 2025 leaks and reasons for retreat. |
| redpacketsecurity | Cyber Defence: SiegedSec profile | 2025-04-06 | Technical/strategic profile describing SiegedSec as a politically motivated hacktivist collective focusing on disruptive attacks and data leaks rather than ransom. |
| haveibeenpwned | ProteusCyber: Threat Actor Profile SiegedSec | 2024-12-01 | Threat‑actor write‑up attributing founding to YourAnonWolf (vio), documenting SQLi/XSS‑heavy TTPs and comparing the group’s style to LulzSec. |
SiegedSec’s identity as a “gay furry hacker” collective was both a genuine reflection of many members’ queer and furry identities and a deliberate branding exercise aimed at unsettling mainstream expectations of what a hacker group looks like.PinkoGAY45 The group’s own leader, vio, has described how SiegedSec started as a more conventional black‑hat crew before rebranding into “gay furry hackers” partly because it was funny to see that phrase in news coverage, partly to better match the personalities of newer members, and partly to create a more welcoming space for LGBTQ+ and furry hackers in a scene they viewed as hostile or dismissive of such communities.Pinko Over time, this persona became central to their public image and helped attract like‑minded recruits, while also functioning as a political statement about who gets to wield technical power in online spaces.GAY45
Operationally, SiegedSec combined relatively simple but effective web‑app techniques with opportunistic targeting and a strong sense of media choreography.DarkOwlTwingate Threat‑intelligence reports and self‑descriptions emphasise heavy use of SQL injection, cross‑site scripting, exposed admin panels, misconfigured cloud test environments, and hard‑coded credentials rather than bespoke zero‑days.DarkOwlDataminr In interviews, members list standard tools such as nmap, Burp Suite, Nikto, Sudomy, DirBuster and Cobalt Strike, stressing manual recon and walking through web applications request‑by‑request to find overlooked weaknesses.Reddit Daily Dot AMA Critics have compared the group to LulzSec, noting that many of their defacements, leaks and taunts were framed as trolling or “for the lulz,” even when the underlying intrusions exposed serious systemic vulnerabilities across governments, contractors and critical infrastructure.DarkOwl
Ideologically, SiegedSec blended left‑leaning hacktivism with irreverent internet culture, treating operations as both political interventions and performances for an online audience.Wikipedia: SiegedSecThe Advocate Campaigns like “OpTransRights” explicitly targeted states and institutions pushing anti‑trans and anti‑LGBTQ+ policies, while communiqués emphasised raising awareness, forcing officials to acknowledge their motives, and inspiring others who felt powerless in the face of hostile legislation.PinkoReddit Daily Dot AMA At the same time, operations such as the Idaho National Laboratory breach, with its tongue‑in‑cheek ransom demand for “IRL catgirl research,” showed how SiegedSec fused serious intrusions with furry and meme culture, using absurdity to mock powerful institutions while still leaking real, sensitive data.DataminrPinko
The group’s disbandment in July 2024 illustrates the personal and legal pressures that can accumulate around high‑profile hacktivists.The RegisterGay Star News In their farewell Telegram message, SiegedSec cited mental‑health concerns, stress from mass publicity, and fear of closer FBI scrutiny as reasons to “let SiegedSec rest for good,” even while insisting they would remain hackers and continue fighting for others’ rights in some form.Gay Star NewsReddit Telegram repost Subsequent reporting about an FBI raid on vio suggests that law‑enforcement pressure was not merely hypothetical, and that the group’s choice to step back followed a clear escalation in attention from authorities.The Advocate (FBI raid) Analysts widely expect that some former members may reappear under different banners, a common pattern in the hacktivist ecosystem.TechInformed
More broadly, SiegedSec has become emblematic of a new wave of “trans furry hackers” and adjacent subcultural actors who treat cybersecurity not only as a technical field but also as a terrain of queer and countercultural struggle.PinkoGAY45 Commentators argue that by openly embracing queer and furry identities, loudly mocking conservative targets, and publicising their motives alongside their dumps, SiegedSec helped normalise the idea that marginalised online communities can directly contest state and corporate power in the digital arena.GAY45The Advocate Whether one views them primarily as criminals, activists, or something in between, the group’s operations exposed significant security failures, reshaped media narratives around hacktivism, and left a template that later actors and copycats are already adapting.Flare: Rise and Fall of SiegedSecCyber Defence profile
Record created: 2026-05-11. Based solely on open‑source reporting and threat‑intelligence profiles available as of early 2026.