CSIDB logo
Threat actor

SeigedSec

Attribution profile

Type
Activist
Location
Russia
Known incidents
1 incident
First seen
2023-03-04
Last seen
2023-03-04
Updated
2026-08-28 17:36
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

SeigedSec is a hacking group known by that alias, with open‑source reporting indicating a possible base in Russia. The group first came to public attention through a series of website defacements and data‑disclosure claims that were shared on Telegram channels. Their activity has been described in news reports as involving the compromise of publicly accessible web platforms and the subsequent release of screenshots purporting to show internal data. While the group’s exact size and internal structure remain undisclosed, the available sources treat SeigedSec as a distinct actor operating under a single moniker. Observations of their operations span at least late 2022 through early 2023, based on the reported incidents.

Observed targets include government‑affiliated or government‑funded web properties, such as the Visit Faroe Islands tourism site, which receives public funding but is privately operated, and various U.S. state government websites that the group claimed to have compromised after the 2022 abortion‑rights rulings in Kentucky and Arkansas. In each case, the group accessed website modules, content‑management systems, and newsletter subscriber lists, and they downloaded source code that they later posted online. They also extracted the names and email addresses of individuals who had subscribed to the website’s newsletters, as confirmed by Faroese IT officials. Their typical tactics involve exploiting vulnerabilities in web‑application components to gain initial access, extracting publicly available data or limited personal information, and then amplifying the incident through Telegram posts and collaboration with other hacking collectives like GhostSec. No specific malware families or custom tooling are mentioned in the reporting.

Notable operations cited in open sources are the March 4 2023 defacement of the Faroe Islands tourist website, where SeigedSec claimed to have stolen employee data and source code while officials confirmed only the site’s CMS and newsletter database were accessed. Earlier, in late 2022, the group asserted breaches of Kentucky and Arkansas state government websites, although state authorities later clarified that the material consisted of publicly available records. The group’s claims have been echoed and amplified by GhostSec, which similarly circulated false allegations of large‑scale data thefts from Maine’s government websites. Following the Faroe Islands incident, local data protection authorities were notified to assess potential privacy implications for the compromised newsletter data. These episodes illustrate a pattern of claiming extensive intrusions that are later shown to involve only openly accessible information.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB