🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
SIEGEDSEC

/actor/siegedsec/  ·  0 intel reports

Year Established
2022
Attribution
USA (Suspected)
Motivation
Hacktivism, LGBTQ+ Advocacy, Anti-Government
Modus Operandi (MO)
Data leaks, government targeting, anti-conservative political operations
Primary Aliases
Sieged Sec

SiegedSec is an unusual hacktivist group that emerged in 2022, self-identifying as an LGBTQ+-aligned threat actor conducting cyber operations against US state governments and organisations perceived as hostile to LGBTQ+ rights. The group's political motivation is overtly stated and explicitly tied to opposition against legislation restricting gender-affirming care, abortion access, and LGBTQ+ protections across US states.

The group gained significant media attention through a series of attacks on US state government agencies, including the compromise and data leak of records from multiple US states that had enacted anti-transgender legislation. Their most high-profile operation involved leaking data from government systems in Idaho, South Carolina, and other states, framing each action as retaliation for specific legislative measures they opposed.

SiegedSec has also conducted international operations, including the defacement of systems belonging to NATO entities and participation in broader hacktivist coalitions. The group's technical capabilities appear moderate , relying primarily on known vulnerabilities, credential exposure from previous breaches, and social engineering , but their willingness to target government infrastructure and publish sensitive data has made them a notable entity within the hacktivist ecosystem.

In July 2024, SiegedSec announced it was disbanding its operations, citing concerns about law enforcement attention and the personal safety of its members. However, security researchers continue to monitor for potential reformation or continued activity under alternative identities, as hacktivist groups rarely fully dissolve.

Operational Telemetry and Threat Vector Analysis: In monitored campaigns, SiegedSec executes high-volume disruptive offensives designed to maximize psychological impact and public visibility. The collective coordinates multi-vector Layer 7 distributed denial of service (DDoS) floods, automated CMS vulnerability exploitation, and database dump distributions across encrypted social channels. Enterprise security teams must deploy resilient edge web application firewalls (WAF), enforce continuous vulnerability scanning on public web assets, and establish proactive brand monitoring across dark web discussion hubs.

STATUS: ACTIVE CLASSIFICATION: HACKTIVIST COLLECTIVE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles