EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/hacktivism/2023-siegedsec-hacktivist-campaign
141/430

File EL-0290HighOngoingHacktivism / Hacktivist Data Breach and Defacement

SiegedSec Hacktivist Campaign

Also filed as SiegedSec LGBTQ+ Rights Hacks · SiegedSec Government Breaches

SiegedSec is an active hacktivist group primarily targeting governments and organizations perceived to be anti-LGBTQ+. They have breached multiple US state governments, leaked NATO documents, and defaced dozens of websites in protest of anti-LGBTQ+ legislation.

  • #hacktivism
  • #lgbtq-rights
  • #us-government
  • #nato
  • #data-breach
Notoriety7/10
Event
1 Mar 2023
Disclosed
1 Mar 2023
Target
Multiple US State Governments and NATO
Actor
SiegedSec
Scale
Tens of gigabytes
Status
Ongoing

01Summary

SiegedSec emerged as a prominent hacktivist force in 2023, quickly gaining notoriety for a series of high-impact breaches. Their operations include hacking the Texas GOP website, breaching multiple US city and state government databases, and leaking NATO documents. The group explicitly ties its operations to protesting anti-LGBTQ+ legislation in the United States. Their typical modus operandi involves SQL injection, credential theft, and exploiting unpatched vulnerabilities in government web applications. Leaked data often includes employee PII, internal government communications, and databases containing sensitive citizen information.

02Background

The group formed in the context of escalating political polarization and anti-LGBTQ+ legislation being passed in multiple US states. They represent a new generation of hacktivists using technical skills for direct political protest.

03Key revelations

  1. 01Texas GOP internal data leaked in protest of anti-LGBTQ+ policies
  2. 02NATO documents breached and published
  3. 03Multiple US city and state governments compromised

04Technical analysis

SiegedSec commonly exploits SQL injection vulnerabilities and uses compromised credentials to gain access to government and corporate networks. They often deface websites and publicly release stolen data via Telegram channels.

Attack vector
SQL injection / Credential compromise / Vulnerability exploitation
Attack method
Data breach, defacement, and public data disclosure
Initial access
Web application exploitation / Credential compromise
Exfiltration
Bulk data extraction and public disclosure

05Threat actor

SiegedSec is a politically motivated hacktivist collective focused on protesting anti-LGBTQ+ legislation through targeted data breaches, website defacements, and public disclosure of stolen government data.

Aliases

  • Sieged Security

Attribution sources

  • SiegedSec Telegram channels
  • BleepingComputer
  • Media reports

06Victims and impact

Additional victims

  • NATO
  • Texas GOP
  • Multiple city/state governments

Countries affected

  • United States
  • Global

07Data exposed

Data types

  • Government employee PII
  • Internal communications
  • Citizen databases
  • Confidential documents

08Timeline

  1. 2023-03-01SiegedSec emerges with initial operations against US state governments.
  2. 2023-05-01Texas GOP website breached; member data leaked.
  3. 2024-01-01NATO documents breached and published.
  4. 2025-01-01Continued operations against multiple targets.

09Reaction and fallout

Public reaction

Mixed; praised by LGBTQ+ advocacy groups while condemned by targeted governments.

Political impact

Signaled the emergence of politically motivated hacktivism specifically targeting anti-LGBTQ+ legislation.

10Legal

FBI investigations ongoing.

11Significance and legacy

Significance

Represented a new wave of politically motivated hacktivism directly tied to LGBTQ+ rights advocacy in the United States.

12Disclosure and media

Authentication
SiegedSec Telegram channel and media verification

Publishing organisations

  • BleepingComputer

13Field notes

  1. 01SiegedSec explicitly states its operations are in protest of anti-LGBTQ+ legislation.
  2. 02The group has breached government systems across multiple US states simultaneously.

14Resolution

Ongoing; group remains active as of 2026.

15Sources

References

  1. [1]BleepingComputer: SiegedSec coverage
  2. [2]Media reports on SiegedSec operations
Fact sheetEL-0290

Dates

Event
1 Mar 2023
Started
1 Mar 2023
Discovered
1 Mar 2023
Disclosed
1 Mar 2023
Ongoing
Yes

Target

Organisation
Various state governments, NATO, and corporate targets
Type
Government Agency
Sector
Government / Defense / Corporate
Country
United States
Gov. level
Multiple

Actor

Name
SiegedSec
Type
Hacktivist Group
Motivation
Protesting anti-LGBTQ+ legislation by targeting governments and organizations that pass or support such laws.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

Volume
Tens of gigabytes
Sensitivity
High
Published
Yes
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.