CSIDB logo
Threat actor

SiegedSec

Attribution profile

Type
Activist
Location
United States of America
Known incidents
10 incidents
Sources
5 sources
First seen
2023-02-15
Last seen
2023-10-03
Updated
2026-07-30 20:33
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

SiegedSec is a hacking group that operates under the alias SiegedSec and has been identified as operating from the United States of America. Public sources describe the group as politically motivated hacktivists who explicitly state that their actions are protests against specific policies such as abortion bans, gender‑affirming care restrictions, and perceived human‑rights shortcomings of NATO member states. The group has repeatedly emphasized that it does not seek financial gain, noting that it leaks stolen data without making monetary demands and that its operations are not financially driven.

The group’s observed tactics include obtaining legitimate employee credentials that were inadvertently posted in public repositories and then using those credentials to access third‑party applications, as seen in the Atlassian‑Envoy incident where they accessed employee data via the Envoy app. They also frequently deface public‑facing government websites, exfiltrate data such as names, email addresses, job titles and internal documents, and then share screenshots of the defacements and alleged leaks on Telegram to claim responsibility. No specific malware families or custom tooling are mentioned in the available sources; their activity appears to rely on credential reuse, web‑site defacement and data disclosure rather than sophisticated malware.

Among their reported operations, SiegedSec claimed responsibility for breaching NATO’s unclassified websites in October 2023, leaking non‑public strategic documents on hypersonic weapons, drone threats and radioactive waste testing. Earlier in July 2023 they targeted NATO’s COI Cooperation Portal, exposing hundreds of user profiles. In June 2023 they conducted a multi‑state campaign against U.S. state and local government sites, defacing the Nebraska Supreme Court intranet, the South Dakota Boards and Commissions portal, the Texas Behavioral Health Executive Council, the Pennsylvania Provider Self‑Service platform and the South Carolina Criminal Justice Information Services website, while also asserting data theft from several of those targets. The same month they compromised the City of Fort Worth’s internal work‑order system, posting attachments, emails and spreadsheets as a political statement. Earlier, in February 2023, they leaked over 13 000 Atlassian employee records and office floor plans after obtaining valid credentials from a publicly exposed employee repository. The group also referenced a 2022 intrusion into Kentucky and Arkansas government systems that was framed as a reaction to abortion‑restriction legislation.

Attribution to a state sponsor or a criminal consortium has not been established in the material provided; the group is consistently characterized as an independent hacktivist collective with a U.S. base of operations and the alias SiegedSec. This profile reflects only the facts presented in the source material.

Incidents

Attributed incidents are available to members.

10 incidents

Sources

Sources available to members: 5 sources.

CSIDB