31.10.2012 Views

We are anonymous inside the hacker world of lulzse

We are anonymous inside the hacker world of lulzse

We are anonymous inside the hacker world of lulzse

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

writes a spo<strong>of</strong> news article about <strong>the</strong> murdered rapper Tupac Shakur being found alive, publishing it through <strong>the</strong> PBS NewsHour website.<br />

The group’s founders discuss forming a second-tier network <strong>of</strong> trusted supporters, many <strong>of</strong> <strong>the</strong>m <strong>hacker</strong> friends <strong>of</strong> Sabu’s.<br />

June 2, 2011—LulzSec announces its hack on SonyPictures.com and says that <strong>the</strong> group has compromised <strong>the</strong> personal information <strong>of</strong><br />

more than one million <strong>of</strong> <strong>the</strong> site’s users.<br />

June 3, 2011—LulzSec defaces <strong>the</strong> website <strong>of</strong> Atlanta InfraGard, an FBI affiliate, and publishes a list <strong>of</strong> e-mails and passwords for 180<br />

users <strong>of</strong> <strong>the</strong> site, some <strong>of</strong> whom <strong>are</strong> FBI agents.<br />

June 6, 2011—LulzSec receives a donation <strong>of</strong> 400 Bitcoins, worth approximately $7,800 at <strong>the</strong> time.<br />

June 7, 2011—Two FBI agents visit Hector “Sabu” Monsegur at his home in New York and threaten to imprison him for two years for<br />

stealing credit card information if he does not cooperate. Monsegur agrees to become an informant while continuing to lead LulzSec.<br />

June 8, 2011—The LulzSec <strong>hacker</strong>s notice that Sabu has been <strong>of</strong>fline for twenty-four hours and worry he has been “raided” by <strong>the</strong> FBI.<br />

Later that night, U.K. time, Topiary makes contact with Sabu, who claims that his grandmo<strong>the</strong>r has died and that he will not be active with<br />

LulzSec for <strong>the</strong> next few days.<br />

June 15, 2011—LulzSec claims responsibility for launching a DDoS attack on <strong>the</strong> <strong>of</strong>ficial website <strong>of</strong> <strong>the</strong> CIA. The attack has been carried<br />

out by former AnonOps operator Ryan, who wields a botnet and now supports LulzSec.<br />

June 16, 2011—A representative <strong>of</strong> WikiLeaks contacts Topiary to say that core organizers want to talk to LulzSec. He and Sabu<br />

eventually hold an IRC discussion with a WikiLeaks representative and someone purporting to be Julian Assange. The representative<br />

“verifies” Assange’s presence by temporarily uploading a YouTube video that shows <strong>the</strong>ir IRC chat happening in real time on a computer<br />

screen, <strong>the</strong>n panning to show Assange on his laptop. The group discusses ways in which <strong>the</strong>y might collaborate.<br />

June 19, 2011—LulzSec publishes a press release encouraging <strong>the</strong> revival <strong>of</strong> <strong>the</strong> Anti-Security (or Antisec) movement and advocating<br />

cyber attacks on <strong>the</strong> websites <strong>of</strong> governments and <strong>the</strong>ir agencies.<br />

June 20, 2011—Galvanized by <strong>the</strong> surprisingly large response to <strong>the</strong> Antisec announcement, Ryan uses his botnet to DDoS several highpr<strong>of</strong>ile<br />

websites, including Britain’s Serious Organised Crime Agency. Later, at 10:30 p.m. that evening in <strong>the</strong> U.K., he is arrested in his<br />

home.<br />

June 23, 2011—LulzSec publishes sensitive documents stolen from Arizona law enforcement, including <strong>the</strong> names and addresses <strong>of</strong><br />

police <strong>of</strong>ficers. Feeling that <strong>the</strong>y have gone one step too far, LulzSec members, including Topiary and Tflow, discuss ending <strong>the</strong> group.<br />

June 24, 2011—Topiary and Tflow tell AVunit and Sabu that <strong>the</strong>y want to end LulzSec; a heated argument ensues.<br />

June 26, 2011—LulzSec announces it is disbanding after “50 Days <strong>of</strong> Lulz.”<br />

July 18, 2011—LulzSec comes back for one more hack, uploading a spo<strong>of</strong> article about <strong>the</strong> death <strong>of</strong> News International owner Rupert<br />

Murdoch on <strong>the</strong> home page <strong>of</strong> his leading British tabloid, The Sun.<br />

July 19, 2011—British police announce <strong>the</strong>y have arrested a sixteen-year-old male who <strong>the</strong>y claim is LulzSec <strong>hacker</strong> Tflow.<br />

July 27, 2011—Police arrest Shetland Islands resident Jake Davis, whom <strong>the</strong>y suspect <strong>of</strong> being LulzSec’s Topiary.<br />

September 2, 2011—British police arrest twenty-four-year-old Ryan Ackroyd, whom <strong>the</strong>y believe to be Kayla.<br />

December 24, 2011—Anonymous announces that it has stolen thousands <strong>of</strong> e-mails and confidential data from <strong>the</strong> U.S. security<br />

intelligence firm Stratfor under <strong>the</strong> banner <strong>of</strong> “Lulz Christmas.” Sabu, who claims to be still at large while o<strong>the</strong>r LulzSec members have been<br />

arrested, keeps tabs on <strong>the</strong> operation from private chat channels and feeds information about <strong>the</strong> attack’s organizers to <strong>the</strong> FBI.<br />

March 6, 2012—News breaks that Hector Monsegur has been acting as an informant for <strong>the</strong> FBI for <strong>the</strong> past eight months, helping <strong>the</strong>m<br />

bring charges against Jeremy Hammond <strong>of</strong> Chicago and five people involved with LulzSec.<br />

Part 1<br />

Chapter 1: The Raid<br />

Notes and Sources<br />

The opening pages, including descriptions <strong>of</strong> Aaron Barr’s early c<strong>are</strong>er, home, and family life, <strong>are</strong> based on interviews with Barr<br />

conducted both on <strong>the</strong> phone and in a face-to-face meeting in London. Fur<strong>the</strong>r details about his work with HBGary Federal came<br />

from an investigative feature article on Wired’s ThreatLevel blog, which dug through his published e-mails and pieced toge<strong>the</strong>r a<br />

picture <strong>of</strong> his plans for <strong>the</strong> company along with <strong>the</strong> proposals he was making to Hunton & Williams. The article was entitled “Spy<br />

Games: Inside <strong>the</strong> Convoluted Plot to Bring Down WikiLeaks,” by contributor Nate Anderson. The Financial Times article in which<br />

Aaron Barr revealed his forthcoming research was entitled “Cyberactivists Warned <strong>of</strong> Arrest,” by San Francisco reporter Joseph<br />

Menn, and was first published Friday, February 4, 2011, <strong>the</strong>n updated <strong>the</strong> following day. Fur<strong>the</strong>r details on e-mails between Barr and<br />

Greg Hoglund <strong>of</strong> HBGary Inc. prior to <strong>the</strong> attack came from <strong>the</strong> HBGary e-mail viewer published by <strong>the</strong> <strong>hacker</strong>s in mid-February.<br />

The details about Sabu hacking computers as a teenager come from interviews with <strong>the</strong> <strong>hacker</strong> conducted via Internet Relay Chat in<br />

April 2011, two months before he was arrested and became an FBI informant. Fur<strong>the</strong>r details about being born and raised in New<br />

York come from court documents after his arrest later that year.<br />

Throughout <strong>the</strong> book, personal details claimed by Kayla stem from interviews with <strong>the</strong> <strong>hacker</strong> conducted between March and<br />

September <strong>of</strong> 2011 via e-mail and Internet Relay Chat. The rumor about stabbing her webcam with a knife came from an online

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!