actors:vio

Vio

Record ID: ACT-0038
Handle(s): Vio, YourAnonWolf, @cybercrimecat, VioWorm-69
Status: Inactive/Unknown
First Observed: 2020 (Claimed entry into hacking via OpMinneapolis) / 2022-02 (Claimed founding of SiegedSec)


Summary

Actor “Vio” is the self-proclaimed founder, public leader, and primary technical operator of the hacktivist group SiegedSec. Openly identifying as a “gay trans furry hacker,” Vio maintains a highly eccentric, hyper-sexualized, and chaotic online persona characterized by furry roleplay and extreme trolling. Despite this intentionally absurd public image, Vio is a highly active threat actor specializing in web exploitation, API vulnerabilities (specifically IDOR), directory traversal, and data exfiltration.

Vio states they are entirely self-taught, having entered the cybersecurity community in 2020 inspired by Anonymous' “Operation Minneapolis.” While they formerly belonged to several groups they describe as “skid groups” (BreachSec, HackersGhost25, AxoSec) and GhostSec, Vio is best known for driving SiegedSec's operations. Under Vio's technical execution, SiegedSec has targeted high-profile entities including NATO, U.S. government facilities (e.g., Idaho National Laboratory), telecommunications companies, medical databases, and organizations they deem anti-LGBTQ+ or bigoted (e.g., Westboro Baptist Church). Vio actively rejects financially motivated cybercrime, claiming that stolen funds are either wasted or intended for charity, and relies solely on public donations.


Aliases

  • Vio — Primary moniker across Telegram and public defacements/leaks.
  • YourAnonWolf / @YourAnonWolf_ — Legacy Twitter and hacker alias used during early operations.
  • @cybercrimecat — Primary Telegram and Twitter handle used for direct messaging and SiegedSec administration.
  • VioWorm-69 — Self-referenced joke handle in chats.
  • The wolf in sheeps clothing — Self-proclaimed title adopted from a news article.

Affiliations

  • SiegedSec (Founder / Primary Operator / Leader)
  • GhostSec (Former member; left due to disputes with leader “sebby”)
  • Anonymous (Former participant; cites OpMinneapolis as origin)
  • The Five Families (Former alliance including ThreatSec, GhostSec, Stormous, and Blackforums; ended in hostility)
  • KittenSec (Former collaborator)
  • ByteMeCrew (Former collaborator)
  • Anonymous Sudan (Former collaborator)
  • *Legacy Affiliations:* BreachSec, HackersGhost25, AxoSec (Described by Vio as “skid groups”).

Activity with SiegedSec

Vio founded SiegedSec in February 2022 alongside a co-founder named “sryakarad” (who coined the name and the motto “Sieging Our Victims Security,” inspired by LulzSec). Vio eventually ousted sryakarad and another member, “rootsauce,” citing their lack of technical contribution and unwelcoming attitudes. Vio molded SiegedSec into a “gay furry” hacktivist collective with a philosophy centered on fighting for minority groups, LGBTQ+ rights, and Palestinian solidarity, while explicitly targeting governments, telecommunications, and anti-LGBTQ+ organizations.

Tactics, Techniques, and Procedures (TTPs): Contrary to early media reports, Vio claims SiegedSec rarely uses SQL Injection or Cross-Site Scripting (XSS). Instead, Vio's methodology relies heavily on:

  • API vulnerabilities (especially Insecure Direct Object Reference / IDOR).
  • Directory traversal and exploiting exposed directories.
  • Local File Inclusion (LFI) paired with insecure deserialization to achieve Remote Code Execution (RCE).
  • Decompiling mobile applications to analyze source code and intercept requests.
  • Heavy OSINT and Social Engineering (notably utilized in their extended breach of NATO systems).

Inter-Group Drama & The Five Families Schism: SiegedSec was originally part of a threat actor syndicate known as “The Five Families.” On December 20, 2023, a post appeared on SiegedSec's blog claiming the group only accepted “MAPs” (Minor Attracted Persons) and zoophiles. This prompted The Five Families to publicly disavow them. Vio and SiegedSec immediately denied writing the post, revealing it was planted by the hosting provider, “Kmeta” (a member of The Five Families). Kmeta later admitted on BreachForums to planting the post because he was disgusted by Vio and the group's constant zoophilia and sexual roleplay jokes in their Telegram chats. Following this, and a separate dispute where Vio exposed GhostSec leader “sebby” as a scammer, SiegedSec completely severed ties with The Five Families.


Timeline

  • 2020-XX-XX — Vio enters the hacking scene, inspired by Anonymous' OpMinneapolis.
  • 2022-02-XX — SiegedSec is founded by Vio and sryakarad.
  • 2022-09-06 — Last known activity on the @YourAnonWolf_ Twitter account.
  • 2023-02-21 — Vio claims responsibility for breaching Atlassian, US gov documents, and a 50GB Chinese citizen database.
  • 2023-12-20 — The “Kmeta” blog sabotage incident causes a schism between SiegedSec and The Five Families.
  • 2023-12-25 — Exfiltration of citizen and employee data from Idaho National Laboratory (INL).
  • 2024-04-01 — First breach of River Valley Church (15k records leaked).
  • 2024-04-08 — Second breach of River Valley Church; Vio doxxes Pastor Rob Ketterling and sabotages church funds ($6,200 spent on inflatable sea lions).
  • 2024-04-16 — Leak of Real America's Voice (p1media) user data.
  • 2024-04-29 — Breach of the Westboro Baptist Church database and source code.


Evidence

Ref Source Date Notes
[1] zeniyonsecurity chat 2023-02-21 Actor claims to be behind Atlassian hack, US gov docs leak, and 50GB Chinese data leak.
[2] zeniyonsecurity chat 2023-03-03 Actor explicitly confirms their role as leader of SiegedSec and member of GhostSec.
[3] UnPato Writting Interview 2026-04-18 Actor details their origin in 2020 (OpMinneapolis), former skid groups, and solo work on OpColombia.
[4] UnPato Writting Interview 2026-04-18 Actor outlines SiegedSec's technical methodology (APIs, IDOR, LFI) and explicitly refutes heavy reliance on SQLi/XSS.
[5] UnPato Writting Interview 2026-04-18 Documents the December 2023 inter-group conflict with Kmeta, The Five Families, and GhostSec's “sebby”.
[6] SiegedSec Cult 2024-04-08 Actor details compromising an e-commerce platform used by River Valley Church and sabotaging their funds.
[7] SiegedSec Cult 2024-05-15 Actor explains the provenance of leaked “p1media” files (Real America's Voice).

Notes

  • Psychological Profile & Leadership: Vio admits to experiencing severe stress and feeling overwhelmed by the responsibilities of leading SiegedSec and being a high-profile target for law enforcement. However, they view their hacktivism as a lifelong calling, stating they will stay in it until they “physically cant anymore.”
  • Contradictory/Trolling Claims: Vio actively spreads disinformation in chats for operational security and amusement. The extreme furry/sexual roleplay documented in their Telegram logs directly contributed to the real-world operational schism with “The Five Families” when partner actors (like Kmeta) took the shock-humor literally or found it intolerable.
  • OpSec: Claims to practice robust operational security. Vio advises others to “shut the fuck up,” assume all communications are monitored, use Mullvad VPN, encrypt data, and use burner SMS numbers (e.g., smspva.com) for Telegram registration.

Record created: 2026-05-06

actors/vio.txt · Last modified: by admin [Admin]