SiegedSec was a hacktivist collective that emerged in April 2022 around the time of Russia's invasion of Ukraine and the leak of the US Supreme Court Dobbs draft. Led publicly by "vio," the group cultivated a deliberately provocative "gay furry hackers" brand and operated openly via Telegram, releasing stolen data as ideological statements rather than for direct financial extortion. Its tradecraft was typical of opportunistic hacktivism: exploitation of exposed/misconfigured web applications and third-party portals, credential and database exfiltration, defacement, and public data dumps, often with exaggerated or disputed claims about scope and whether data was truly "hacked" versus scraped from public sources. The group announced its own disbandment on 10-11 July 2024 shortly after the Heritage Foundation leak, citing mental-health strain, mass publicity, and fear of FBI/law-enforcement scrutiny.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
SiegedSec first drew attention in mid-2022 with a Roe v. Wade-themed campaign, dumping several gigabytes of data it claimed came from the government servers of Kentucky and Arkansas in response to those states' abortion bans; officials in both states countered that the leaked data was publicly available rather than obtained via intrusion. Through 2022-2023 the group ran a series of ideologically-tagged operations (e.g., #OpTransRights against US entities opposing gender-affirming care, hitting municipal and state targets such as Fort Worth, and claiming records tied to the Nebraska Supreme Court and South Carolina police). In February 2023 it claimed an Atlassian-related leak of employee records. Its most prominent activity came in 2023 with two claimed breaches of NATO's unclassified Communities of Interest (COI) Cooperation Portal, an information-sharing site used by partner nations; SiegedSec posted roughly 700-845MB of documents and thousands of user records spanning ~31 nations, prompting NATO to open an investigation (the data was unclassified). In November 2023 it claimed a breach of the Idaho National Laboratory via an Oracle HR system. In 2024 the group leaked ~200GB tied to the conservative Heritage Foundation over its Project 2025 agenda (an operation widely covered under an anti-Project-2025 framing); Heritage disputed the intrusion, stating the material was a two-year-old Daily Signal archive exposed on a contractor's public-facing site. Days later SiegedSec disbanded. Note: the prompt's "Operation Transparency/OpTransparency" label does not map cleanly to a documented SiegedSec operation name in authoritative reporting; the group's anti-Israel activity was instead tracked under OpIsrael-style waves (see below). MENA relevance: REAL but CLAIM-BASED. SiegedSec genuinely and repeatedly targeted Israel during the 2023-2024 Gaza conflict, largely in concert with Anonymous Sudan and pro-Palestinian hacktivist blocs. Multiple threat-intel trackers (Hackmanac, FalconFeeds) and press documented a sequence of named OpIsrael waves in which SiegedSec claimed breaches of Israeli telecoms and infrastructure (Cellcom ~180k records, Bezeq ~50k customers), retailer Shufersal, and airline Israir, plus "government sector" documents. The targeting itself is well-attested across independent sources, so the Israel country tag is justified as genuine intent and activity; however, the magnitude and authenticity of the individual breaches are unverified hacktivist self-claims typical of the group's pattern of overstated or scraped-data dumps, and none were confirmed by the victims or independent forensic analysis. Verdict: keep the Israel tag as real targeting, but treat SiegedSec's Israeli breach impact as claim-based/unverified, not corroborated.