groups:siegedsec

SiegedSec

Record ID: GRP-0002
Type: Hacktivist Collective
Status: Dissolved
Active Since: 2022


Summary

SiegedSec was a black‑hat hacktivist collective that self‑described as “gay furry hackers” and blended a queer furry online persona with aggressive political hacking campaigns. Emerging in early 2022 around a Telegram channel and related social accounts, the group quickly gained notoriety for defacements, data breaches and leaks targeting governments, critical infrastructure, and conservative organisations across North America, Europe and beyond.

SiegedSec’s operations mixed ideological motives—especially support for LGBTQ+ and trans rights, opposition to conservative and Christian nationalist politics, and anti‑authoritarian rhetoric—with trolling‑inflected humour, vulgar messaging, and sometimes seemingly “for fun” intrusions. High‑profile victims included NATO portals, the Idaho National Laboratory, multiple US state and local governments involved in anti‑trans legislation, Atlassian, a multinational energy firm, and the Heritage Foundation’s Project 2025 infrastructure. The group announced its disbandment on 2024‑07‑10, shortly after claiming a major breach of the Heritage Foundation, citing stress, mental‑health issues and fear of intensified FBI scrutiny.


Known Members

  • vio — Public leader and founder of SiegedSec, also known as “YourAnonWolf”; directed the group’s operations from its creation in 2022 until the July 2024 disbandment, and has been linked in reporting to membership in GhostSec.
  • YourAnonWolf — Earlier alias of vio noted in threat‑intelligence write‑ups as the creator of SiegedSec’s initial channels and early campaigns.
  • mewmrrpmeow — Former member who publicly disclosed in 2025 that the FBI had raided vio in connection with SiegedSec’s activities and the Heritage Foundation / Project 2025 breach.

(Handles above are drawn from open‑source and media reporting; no real‑world identities are asserted here.)


Associated Groups

  • GhostSec — Hacktivist collective with which SiegedSec’s leader vio/YourAnonWolf was reportedly affiliated, indicating overlap between ghost‑themed and furry‑themed hacktivist circles.
  • The Five Families — Loose coalition of hacker crews; SiegedSec was described as an early member, collaborating within this umbrella on ideologically and financially motivated attacks before focusing on its own brand and operations.

Timeline

  • 2022-04-01 — SiegedSec’s Telegram channel and branding appear, with sources first observing the group in April 2022 as a new hacktivist outfit styling itself as “gay furry hackers” (month from reporting; exact day approximate).
  • 2023-02-14 — Atlassian breach: SiegedSec uses stolen employee credentials to access internal systems, leaking around 13,000 employee records and office floor plans.
  • 2023-06-23 — “OpTransRights” US state/local government attacks: the group compromises sites and systems for Fort Worth (Texas) and multiple US states (Nebraska, Pennsylvania, South Carolina, South Dakota, Texas) in protest against anti‑trans and anti‑gender‑affirming‑care legislation.
  • 2023-10-04 — NATO portals breach: SiegedSec claims theft of about 3,000 NATO documents (~9 GB of largely unclassified data) from various NATO e‑learning and coordination portals; NATO publicly confirms an investigation.
  • 2023-11-20 — Idaho National Laboratory breach: the group exfiltrates HR data from the US nuclear research facility INL and posts it online, issuing an unusual ransom demand that the lab start a “catgirl research program.”
  • 2024-04-16 — Multinational energy organisation incident: SiegedSec leaks personal data and internal administrative information from an unnamed energy company, claiming access to its admin panel.
  • 2024-07-09 — Heritage Foundation / Project 2025 breach: the group claims to have stolen more than 200 GB of data, including credentials and PII tied to the conservative Heritage Foundation and its Project 2025 initiative.
  • 2024-07-10 — SiegedSec announces it is disbanding following the Heritage attack, citing mental‑health stress and fear of increased FBI scrutiny while acknowledging the risk created by their high‑profile breaches.
  • 2025-03-31 — Reports emerge that the FBI raided vio, SiegedSec’s alleged leader, indicating continued law‑enforcement focus on the group’s past operations despite the 2024 disbandment.

  • Atlassian employee data breach (2023) — SiegedSec leaks around 13,000 Atlassian employee records and office blueprints using compromised credentials, illustrating its ability to move beyond simple defacement to serious data exfiltration.
  • OpTransRights US state government intrusions (2023) — A series of June 2023 attacks on US state and local government systems in Nebraska, Pennsylvania, South Carolina, South Dakota, Texas and Fort Worth, framed as protest against anti‑trans and anti‑gender‑affirming‑care laws.
  • NATO portal data leak (2023) — Breach of multiple NATO‑run portals with roughly 3,000 documents and 9 GB of data leaked; SiegedSec presents this as anti‑militarist hacktivism and gains significant international media attention.
  • Idaho National Laboratory catgirl ransom breach (2023) — Compromise of INL HR databases, public leak of employee information, and a tongue‑in‑cheek ransom demand for “catgirl research,” underscoring the group’s mix of serious intrusion and absurdist furry culture references.
  • Heritage Foundation / Project 2025 breach (2024) — High‑impact leak of Heritage Foundation/Project 2025 data, positioned as direct opposition to a conservative blueprint perceived by the group as threatening LGBTQ+ rights and democracy; immediately followed by SiegedSec’s disbandment announcement.

Evidence

Ref Source Date Notes
cybernews Wikipedia: SiegedSec 2024-04-30 High‑level overview of SiegedSec’s origin, ideology, major operations (NATO, INL, Heritage, Real America’s Voice) and the July 2024 disbandment announcement.
cybernews TheSecMaster: “SiegedSec: Gay Furry Hackers & Hacktivist Group” 2025-03-10 Threat‑actor profile detailing the group’s “gay furry hackers” branding, tactics, ideological focus on trans rights, and the role of leader vio/YourAnonWolf.
hookphish Flare: “The Rise and Fall of SiegedSec” 2026-04-23 Narrative of SiegedSec’s lifecycle from 2022 creation to 2024 shutdown, emphasising early Telegram channel activity, use of SQLi/XSS, and evolving campaigns.
scamadviser Dataminr case study on SiegedSec 2024-08-07 Case study summarising SiegedSec’s attacks on a multinational energy organisation, Atlassian, Fort Worth, and Idaho National Laboratory, with emphasis on TTPs (SQLi, XSS).
linkedin SecurityAffairs: NATO investigating SiegedSec attack 2023-10-04 Describes NATO’s investigation into SiegedSec’s claimed breach of several NATO portals and the leak of about 3,000 documents (~9 GB).
msspalert The Advocate: FBI raids leader of gay furry hackers 2025-03-31 Reports an FBI raid on SiegedSec’s leader (vio), recounts earlier US state government attacks and the Heritage Foundation/Project 2025 breach.
hackread ZeroFox: “The Underground Economist” (SiegedSec disbandment) 2024-07-xx Notes SiegedSec’s membership in “The Five Families,” their self‑description as “gay furry hackers,” the Project 2025 breach, and the subsequent disbandment announcement.
github GAY45: “SiegedSec, the Gay Furry Hackers Who Rewrote Cyber Activism” 2025-02-25 Investigative feature discussing SiegedSec’s queer/furry identity, political motivations, and impact on hacktivism, including NATO and Project 2025 leaks and reasons for retreat.
redpacketsecurity Cyber Defence: SiegedSec profile 2025-04-06 Technical/strategic profile describing SiegedSec as a politically motivated hacktivist collective focusing on disruptive attacks and data leaks rather than ransom.
haveibeenpwned ProteusCyber: Threat Actor Profile SiegedSec 2024-12-01 Threat‑actor write‑up attributing founding to YourAnonWolf (vio), documenting SQLi/XSS‑heavy TTPs and comparing the group’s style to LulzSec.

Notes

Notes

SiegedSec’s identity as a “gay furry hacker” collective was both a genuine reflection of many members’ queer and furry identities and a deliberate branding exercise aimed at unsettling mainstream expectations of what a hacker group looks like.PinkoGAY45 The group’s own leader, vio, has described how SiegedSec started as a more conventional black‑hat crew before rebranding into “gay furry hackers” partly because it was funny to see that phrase in news coverage, partly to better match the personalities of newer members, and partly to create a more welcoming space for LGBTQ+ and furry hackers in a scene they viewed as hostile or dismissive of such communities.Pinko Over time, this persona became central to their public image and helped attract like‑minded recruits, while also functioning as a political statement about who gets to wield technical power in online spaces.GAY45

Operationally, SiegedSec combined relatively simple but effective web‑app techniques with opportunistic targeting and a strong sense of media choreography.DarkOwlTwingate Threat‑intelligence reports and self‑descriptions emphasise heavy use of SQL injection, cross‑site scripting, exposed admin panels, misconfigured cloud test environments, and hard‑coded credentials rather than bespoke zero‑days.DarkOwlDataminr In interviews, members list standard tools such as nmap, Burp Suite, Nikto, Sudomy, DirBuster and Cobalt Strike, stressing manual recon and walking through web applications request‑by‑request to find overlooked weaknesses.Reddit Daily Dot AMA Critics have compared the group to LulzSec, noting that many of their defacements, leaks and taunts were framed as trolling or “for the lulz,” even when the underlying intrusions exposed serious systemic vulnerabilities across governments, contractors and critical infrastructure.DarkOwl

Ideologically, SiegedSec blended left‑leaning hacktivism with irreverent internet culture, treating operations as both political interventions and performances for an online audience.Wikipedia: SiegedSecThe Advocate Campaigns like “OpTransRights” explicitly targeted states and institutions pushing anti‑trans and anti‑LGBTQ+ policies, while communiqués emphasised raising awareness, forcing officials to acknowledge their motives, and inspiring others who felt powerless in the face of hostile legislation.PinkoReddit Daily Dot AMA At the same time, operations such as the Idaho National Laboratory breach, with its tongue‑in‑cheek ransom demand for “IRL catgirl research,” showed how SiegedSec fused serious intrusions with furry and meme culture, using absurdity to mock powerful institutions while still leaking real, sensitive data.DataminrPinko

The group’s disbandment in July 2024 illustrates the personal and legal pressures that can accumulate around high‑profile hacktivists.The RegisterGay Star News In their farewell Telegram message, SiegedSec cited mental‑health concerns, stress from mass publicity, and fear of closer FBI scrutiny as reasons to “let SiegedSec rest for good,” even while insisting they would remain hackers and continue fighting for others’ rights in some form.Gay Star NewsReddit Telegram repost Subsequent reporting about an FBI raid on vio suggests that law‑enforcement pressure was not merely hypothetical, and that the group’s choice to step back followed a clear escalation in attention from authorities.The Advocate (FBI raid) Analysts widely expect that some former members may reappear under different banners, a common pattern in the hacktivist ecosystem.TechInformed

More broadly, SiegedSec has become emblematic of a new wave of “trans furry hackers” and adjacent subcultural actors who treat cybersecurity not only as a technical field but also as a terrain of queer and countercultural struggle.PinkoGAY45 Commentators argue that by openly embracing queer and furry identities, loudly mocking conservative targets, and publicising their motives alongside their dumps, SiegedSec helped normalise the idea that marginalised online communities can directly contest state and corporate power in the digital arena.GAY45The Advocate Whether one views them primarily as criminals, activists, or something in between, the group’s operations exposed significant security failures, reshaped media narratives around hacktivism, and left a template that later actors and copycats are already adapting.Flare: Rise and Fall of SiegedSecCyber Defence profile

Record created: 2026-05-11. Based solely on open‑source reporting and threat‑intelligence profiles available as of early 2026.

groups/siegedsec.txt · Last modified: by admin [Admin]