LulzSec
Attribution profile
- Type
- Hacker
- Location
- France
- Known incidents
- 5 incidents
- Sources
- 0 sources
- First seen
- 2016-01-01
- Last seen
- 2024-02-12
- Updated
- 2026-08-28 17:55
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Lulz Security, also known as LulzSec, is a hacktivist collective that has been publicly linked to operations originating from France. The group operates under the alias LulzSec and has been associated with individual members using handles such as Hanom1960 in specific campaigns. Its activities are characterized by a mix of data disclosure, service disruption, and website defacement aimed at drawing attention to political or social issues.
The collective has targeted government and public‑service entities across multiple regions, including the French family benefits agency, various Philippine government departments, and the Costa Rican Ministry of Foreign Affairs and Worship. In the French incident the actors obtained access to reused credentials and published screenshots containing personal details such as names, family information and payment data, though no financial theft was observed. In the Philippines they conducted distributed denial‑of‑service attacks that disrupted 68 government websites spanning defense, foreign affairs, finance, health and local administration, followed by defacements displaying messages attributed to Chinese authorities. The Costa Rican breach involved unauthorized access to internal systems resulting in the exfiltration of names, email addresses, national identification numbers, phone numbers and hashed passwords of roughly five hundred users, framed as part of the #OpPuraVida campaign opposing the Central America Free Trade Agreement. Observed tactics include credential reuse for initial access, large‑scale DDoS traffic generation, and the posting of defacement messages or screenshots to expose data; no specific malware families or custom tooling are described in the available reports.
Attribution to a state sponsor or a formal criminal consortium has not been established in the sources; the group is described as a hacktivist entity without clear state nexus or organized crime affiliation. Representative operations cited include the 2024 French agency credential‑reuse incident, the mid‑2016 Philippine DDoS and defacement wave, and the early‑2016 Costa Rican ministry data leak. These examples illustrate the group’s pattern of targeting governmental services to achieve disruption, data exposure, or political messaging through relatively straightforward access methods rather than sophisticated malware.
Incidents
Attributed incidents are available to members.
5 incidentsSources
Sources available to members: 0 sources.