01Summary
On May 29, 2011, LulzSec, a splinter group of Anonymous, hacked into PBS's web servers. The attackers defaced the PBS website with a false news story claiming that deceased rapper Tupac Shakur was alive and living in New Zealand. More significantly, LulzSec exfiltrated and published internal PBS data including email addresses, passwords, and administrative credentials. The group stated the attack was retaliation for a Frontline documentary titled 'WikiSecrets' that portrayed WikiLeaks and Julian Assange in a negative light. PBS quickly took the site offline to contain the damage and launched an investigation.
02Background
LulzSec emerged in May 2011 as a splinter group from Anonymous, adopting a more chaotic and humorous approach to hacking. The PBS attack was one of their first major operations and established their modus operandi: high-profile targets, humorous defacements, and data leaks.
03Technical analysis
LulzSec exploited a vulnerability in PBS's content management system to gain administrative access to the website. Once inside, they defaced the site and extracted internal data including user credentials from the backend database.
- Attack vector
- Content management system exploitation
- Attack method
- Website Defacement and Data Exfiltration
- Initial access
- Web application exploitation
- Exfiltration
- Database extraction
- Tool / malware
- SQL injection / CMS exploit
- Malware type
- Web Exploit
Vulnerabilities exploited
- CMS vulnerability
MITRE ATT&CK techniques
- T1190
04Threat actor
LulzSec was a splinter group from Anonymous that operated for 50 days in 2011. Known for high-profile, humorous hacks motivated by 'lulz' (amusement) rather than political ideology, they targeted major media, gaming, and government organizations.
Aliases
- Lulz Security
Known members
- Sabu (Hector Monsegur)
- Kayla (Mustafa Al-Bassam)
- Topiary
- Tflow
Attribution sources
- LulzSec Claims
- Media Reports
- FBI Investigation
05Victims and impact
Countries affected
- United States
06Data exposed
Data types
- Email Addresses
- Passwords (hashed)
- Internal Credentials
- Administrative Data
Notable documents
- PBS Internal Data Dump
07Financial damage
Reputational damage and operational disruption to PBS.
08Timeline
- 2011-05-29LulzSec hacks and defaces PBS website.
09Key figures
- Hector Monsegur (Sabu)LulzSec Leader · LulzSecAmericanArrested, became FBI informant.
10On the record
We are LulzSec. We do it for the lulz.
11Reaction and fallout
Public reaction
The hack generated significant media coverage, establishing LulzSec as a major new player in the hacktivist landscape.
Political impact
The attack highlighted tensions between media organizations and the hacker community over WikiLeaks coverage.
12Legal
PBS cooperated with the FBI. LulzSec members were eventually arrested and convicted.
Prosecutions
- Hector Monsegur (Sabu)Pleaded guilty, became FBI informant
- Charge
- Computer hacking conspiracy
- Jurisdiction
- United States
- Sentence
- Probation (due to cooperation)
13Aftermath
Security improvements
- PBS enhanced CMS security and patched exploited vulnerabilities.
14Significance and legacy
Significance
The PBS hack was LulzSec's first major operation, announcing the group's arrival on the global stage with a characteristic blend of humor and data theft.
Legacy
The attack established the template for LulzSec's 50-day rampage of high-profile hacks in May-June 2011.
15Disclosure and media
- Authentication
- LulzSec publication and PBS confirmation
Publishing organisations
- LulzSec
17Field notes
- 01The fake Tupac story was deliberately absurd to maximize media attention.
- 02The hack occurred on the same weekend that LulzSec also hacked Sony Pictures.
18Resolution
PBS restored its website. LulzSec members were later arrested.
19Sources
References
- [1]Media reports (CNN, The Guardian)
- [2]LulzSec statements









