SiegedSec
hacktivist group

SiegedSec, short for Sieged Security and commonly self-described as the "Gay Furry Hackers", was an extremist far left black-hat criminal hacktivist group, that was formed in early 2022, that committed a number of high profile cyber attacks, including attacks on NATO, Idaho National Laboratory, and Real America's Voice. On July 10, 2024, after attacking The Heritage Foundation, the group announced that they would be disbanding in an effort to avoid closer scrutiny.
Description
SiegedSec was led by an individual under the alias "vio". Short for "Sieged Security", SiegedSec's Telegram channel was first created in April 2022, and they commonly referred to themselves as "gay furry hackers". SiegedSec has targeted a wide variety of organisations, ranging from intergovernmental organisations like NATO and federal research facilities like the Idaho National Laboratory to right-wing movements like The Heritage Foundation and Real America's Voice, and various U.S. states that have pursued legislative decisions against gender-affirming care.
Research
In mid 2024, a paper released by the United Nations Office of Counter-Terrorism referenced Siegedsec along with GhostSec and Anonymous Sudan, stating:
Such individuals and groups, or 'collectives', are often branded as 'hacktivists' and seek to utilize cyber-attacks to advance their political, religious, or social beliefs, targeting entities perceived as adversaries or aligned with opposing belief systems. The technical capabilities of these malicious actors can vary but their fluidity enables calls to action for cybercriminals across the cyber skillset in support of diverse causes. Leading examples of these types of groups would be Anonymous – the decentralized hacktivist collective – as well as GhostSec, ThreatSec, SiegedSec, Killnet, and Anonymous Sudan, to name but a few. Notably, these groups claim to have targeted critical infrastructure, including hospitals and utility systems, and express the explicit intent to maximize societal impact, inflicting extensive damage, with clear disregard for harm to innocent individuals.
Notable attacks
Atlassian
On February 14, 2023, major Australian software provider Atlassian had its data leaked on the internet by SiegedSec, which used stolen employee credentials.
This brief starts where responsible research should: with the source description of “SiegedSec” as hacktivist group. Everything that follows is an evidence route, not borrowed authority.
Why this record matters
The subject matters to the general reference register because the source frames it as hacktivist group. Its deeper value depends on whether names, dates, institutions and citations support that framing.
Vocabulary and entity names are the principal evidence signals here, because they determine the precision of every later search. The source revision retrieved here is dated Sep 23, 2026. The linked authority identifier is Q127433247. None of the 1 selected statements returned an explicit reference. The first chronological checks are 2022, 2024 and 2023.
The absence of detail may reflect summary conventions rather than a lack of surviving documentation. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “SiegedSec”, its source revision and the description used here.
- Expand the search: follow SiegedSec primary sources, SiegedSec archive and SiegedSec research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “SiegedSec”?
- What terminology or title could unlock a more precise catalogue search?
- Which cited source is closest to the event, object or claim?
Search terms from this dossier
This entry incorporates text from “SiegedSec” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.