Hacktivist Groups to Watch | IntelBroker, Anonymous Sudan & SiegedSec (Threat Intelligence Guide)

IntelBroker, Anonymous Sudan and SiegedSec are three of the most closely tracked hacktivist and data-leak actors of recent years, and all three have drawn law-enforcement action. IntelBroker sold stolen corporate data, Anonymous Sudan used DDoS floods to knock services offline, and SiegedSec leaked government and think-tank data to make political points. This guide covers who each group is, what they did, and what defenders can learn.
What Is a Hacktivist? Definition, Meaning and Motivation
A hacktivist is a hacker who uses cyberattacks to advance a political, social or religious cause. The word blends “hacker” and “activist,” and in cyber security it covers anyone who attacks systems to make a statement.
What motivates hacktivists
Hacktivists want visibility, not profit. Common drivers include political protest, religious or nationalist grievance, and retaliation for a perceived wrong. US and allied agencies note that pro-Russia hacktivist groups typically seek attention rather than strategic advantage and often overstate the scale of what they did. Treat a group’s claims as marketing until a victim or investigator confirms them.
Common hacktivist methods
The classic toolkit is DDoS floods, website defacement, and stealing and publishing sensitive data. Newer campaigns also include hack-and-leak operations, doxxing, and intrusions into operational technology (OT) systems through poorly protected remote access.
Hacktivist vs. hacker
A hacker is anyone who breaks into or manipulates systems, with motives ranging from curiosity to profit. A hacktivist is a hacker with a declared cause. A cause doesn’t make an attack legal, and several hacktivists in this guide face criminal charges.
What Are Hacktivist Groups, and Why Do They Matter?
Hacktivist groups are loosely organized hackers who attack organizations to make a political, religious, or social statement, typically by leaking data, defacing sites, or taking services offline. They matter because they can cause real operational damage at scale. Prosecutors say Anonymous Sudan’s tool conducted a record 35,000 DDoS attacks in a single year, including attacks on Microsoft’s services.
Hacktivism vs. financially motivated cybercrime
Hacktivists seek attention or change, while cybercriminals want money. The line blurs often. IntelBroker sold stolen data for profit, and Anonymous Sudan sold its DDoS tool as a service to other criminals. SiegedSec is the clearest ideological case, since reporting describes it as not appearing to be financially motivated.
How hacktivist and data-leak actors pick targets
Targets usually follow a grievance or an opportunity. Anonymous Sudan’s early campaigns hit Scandinavian and European countries in response to Quran burnings, then moved to Israel and Kenya. SiegedSec went after institutions tied to causes it opposed, such as NATO and the Heritage Foundation. IntelBroker followed the market, going after companies whose source code, credentials, or customer data would sell.
Why these three groups are worth tracking
Each one represents a different attack model: data theft for sale, application-layer DDoS, and politically motivated leaks. Each also ended differently, so together they show how attribution and enforcement work against modern hacktivist groups.
Who Is IntelBroker?
IntelBroker was a prolific data broker on cybercrime forums. US prosecutors say the persona belongs to a British national, Kai West. The alleged scheme caused more than $25 million in damages across more than 40 victims.

Background and BreachForums role
IntelBroker built its reputation by posting stolen corporate and government data for sale on BreachForums. Prosecutors say West made about 158 threads offering data for forum credits or for free and offered hacked data for sale about 41 times between 2023 and 2025. Reporting also describes IntelBroker as believed to have acted as an administrator of BreachForums.
Identity claims, arrest and Europol action (Kai West)
Prosecutors in New York unsealed a four-count indictment in June 2025 naming West, who was arrested in France in February 2025, with the US seeking extradition. The FBI traced him partly through an undercover purchase of a stolen API key in January 2023 and a cryptocurrency account registered in his real name. Europol appears in IntelBroker’s claimed-victim history, but reporting notes that earlier claims involving Apple and Europol were exaggerated. The charges are accusations, and West is presumed innocent until proven guilty.
Notable breaches: Cisco, HPE, AMD
IntelBroker is linked to high-profile claims involving AMD, Apple and Cisco, which prompted investigations after data appeared for sale. In January 2025, it claimed to hold HPE source code and credentials. HPE said it disabled related credentials and launched an investigation, with no evidence that customer information was involved. Treat these as claims. Some were confirmed, some disputed, and some partly exaggerated.
How IntelBroker sold and leaked data
IntelBroker posted listings on BreachForums, teased samples, and invited buyers to negotiate privately. A DOJ filing cited by SC Media says at least 25 of 158 public messages invited users to message IntelBroker to negotiate a price. Prosecutors say the group sought to collect about $2 million from stolen-data sales. The data included customer information from a telecom company and, in one case, patient records from a municipal healthcare provider.
Where the threat stands after the arrest
The IntelBroker persona’s alleged activity ran from December 2022 until West’s arrest in February 2025. Stolen data already sold or leaked can still circulate, and other brokers on the forums fill the same niche. As of the latest reporting I found, West was in French custody pending extradition, so verify his current legal status before relying on this section.
Who Is Anonymous Sudan?
Anonymous Sudan was a DDoS-focused group that appeared in early 2023 and claimed Sudanese nationalist and Islamist motives. US prosecutors indicted two Sudanese brothers in October 2024, alleging that they ran it and caused more than $10 million in damages to US victims.

Origins, claimed motives and affiliations.
The group emerged at the start of 2023, and Microsoft tracks it as Storm-1359. It publicly cited religious and political grievances but worked alongside other hacktivist groups, including KillNet, SiegedSec and Türk Hack Team. Early researchers doubted its Sudan link, and Flashpoint said it saw no connection to Sudan. The US indictment of two Sudanese nationals complicated that picture, and the group’s true origins remain debated.
Targets: Microsoft, Israel, Kenya and others
The June 2023 DDoS attacks on Microsoft 365 services, including Outlook and Teams, brought the group wide attention. Cloudflare reported that Israel faced more denial-of-service attacks than any other country in the first quarter of 2023 amid Anonymous Sudan’s campaign. In July 2023, it hit Kenya, disrupting the eCitizen portal, Safaricom and Kenya Commercial Bank, with the group citing Kenya’s statements on Sudan. Other victims included Cloudflare, PayPal, X, and Yahoo, and several US government agencies.
DDoS tactics, techniques and procedures (TTPs)
The group favored application-layer (layer 7) floods. Microsoft observed HTTP(S) floods, cache bypass to overload origin servers, and Slowloris attacks, launched from cloud services and open proxy infrastructure. Prosecutors say it used a tool called Godzilla, Skynet, or InfraShutdown. The group coordinated on Telegram and was also known for DDoS extortion, or ransom DDoS.
Indicators of compromise (IOCs) and detection signals
IP-based IOCs for this kind of group go stale quickly because the traffic rotates through cloud and proxy ranges. Behavioral signals last longer. In the Azure incident, Microsoft saw an anomalous spike in HTTP requests against origin servers that bypassed automatic protections. Watch for sudden request surges on expensive endpoints, traffic hitting your origin directly rather than your CDN, and slow-connection patterns. Also watch the group’s public Telegram announcements, which can precede attacks by hours.
Arrests and takedown
The tool was turned off in March 2024, the same month the brothers were arrested, according to reporting on the case. A federal grand jury unsealed the indictment in October 2024. The case is part of Operation PowerOFF, an international effort against DDoS-for-hire infrastructure. The defendants are presumed innocent.
Who Is SiegedSec?
SiegedSec was a self-described “gay furry hacker” collective that leaked data from organizations it opposed, most famously NATO portals in 2023 and the Heritage Foundation in 2024. It disbanded in July 2024.

Who they are and who leads them
The group emerged in early 2022, targeting anti-LGBTQ+ organizations, and was led by an individual using the alias “vio”. Since February 2022, it had leaked data from more than 30 organizations and defaced over 100 domains. Its stated motives were political, and its leaks often came with taunting commentary.
NATO breach (2023)
In July 2023, SiegedSec posted a link on Telegram to roughly 710 files from NATO’s unclassified Community of Interest Cooperation Portal. CloudSEK analysis found about 8,000 user records from 31 countries and suggested the access may have come from stealer logs. In September 2023, the group claimed a second NATO hit, over 3,000 files and 9GB of data from six web portals. NATO said it was investigating the incidents, and the material was unclassified.
Heritage Foundation leak and Project 2025
In July 2024, SiegedSec said it had breached the Heritage Foundation to protest Project 2025. It claimed the attackers stole 200GB of data, including user credentials. Heritage disputed the scale, saying attackers only accessed a Daily Signal website archive and that no Heritage systems were breached. The incident shows how a leak can be contested: the group and the victim described it very differently.
Chat logs, member exposure and the group’s end
The group published Signal chat logs between “vio” and Heritage’s Mike Howell, in which Howell said Heritage was working to identify group members and involving the FBI. Howell confirmed the logs were accurate. An hour after posting the logs, SiegedSec announced it was disbanding, citing mental health, publicity stress, and a wish to avoid the FBI. In March 2025, a former member claimed federal agents had raided the leader, but the FBI declined to comment, and the raid was not independently confirmed.
Why SiegedSec still shows up in 2025 searches
The group is gone, but its stories are not. Project 2025 stayed in the news, the NATO and Heritage leaks remain widely cited, and the spring 2025 raid reports renewed interest in what happened to its members. People also search for the chat logs and the Howell exchange, which became a story in their own right.
Anonymous: The Original Hacktivist Collective
Anonymous is a decentralized, leaderless hacktivist collective that began on internet message boards and became the world’s best-known hacktivist brand. It is not a single organization, which is why the name is easy to borrow.
What Anonymous is and how it’s organized
Anonymous started around 2003 on an anonymous chat board and has no leadership or ranking system. Anyone can join by simply declaring themselves an “anon.” That structure gave it reach but made its goals inconsistent, and the collective has had to disown actions carried out in its name.
Notable Anonymous operations
Its first operation to gain worldwide attention was Project Chanology in 2008, an online and street campaign against the Church of Scientology. Operation Payback in 2010 began against anti-piracy groups and expanded to DDoS attacks on PayPal, Visa and MasterCard after those companies cut off WikiLeaks. Anonymous also lent digital support to protesters in Tunisia and joined later campaigns such as Operation Ferguson in 2014. Each of these shows the pattern: a public cause, a coordinated DDoS or leak, and heavy media attention.
Anonymous today
Anonymous peaked around 2012, when Time named it among the world’s 100 most influential people, and has been less active as a coordinated force since. Arrests of members and the rise of more focused groups reduced its profile. The name still turns up, though. In 2026, groups using Anonymous branding appeared in the Iran-war hacktivist activity, which shows how the name now works as a label that unrelated groups can adopt.
Anonymous vs. Anonymous Sudan
The two are not the same. Anonymous Sudan has said it has no connection to the original Anonymous, and its operations were DDoS-focused attacks that the US later charged two men with running. See the Anonymous Sudan section above for the full profile.
IntelBroker vs. Anonymous Sudan vs. SiegedSec: Side-by-Side Comparison
The three groups differ most in motive and method. IntelBroker stole and sold data, Anonymous Sudan disrupted availability, and SiegedSec leaked data for political reasons.
| Motivation, Methods and Target Profile | IntelBroker | Anonymous Sudan | SiegedSec |
|---|---|---|---|
| Primary Motive | Financial (data sales) | Political/religious claims, plus DDoS-for-hire | Political and ideological |
| Core Method | Network intrusion and data theft, sold on BreachForums | Layer 7 DDoS floods, ransom DDoS | Intrusions and data leaks, defacements |
| Typical Targets | Tech companies, telecoms, healthcare, government | Governments, cloud and tech platforms, hospitals, banks | NATO portals, Heritage Foundation, other political targets |
| Active Period | About Dec 2022 – Feb 2025 | Early 2023 – March 2024 | Early 2022 – July 2024 |
| Outcome | Arrest in France; US charges and extradition request | Two brothers indicted; tool seized | Disbanded; leader’s reported raid unconfirmed |
Data theft vs. DDoS vs. politically motivated leaks
A data-theft actor like IntelBroker threatens confidentiality, so the damage comes from exposed code, credentials, and customer records. A DDoS group like Anonymous Sudan threatens availability, so the damage is downtime and response cost. A leak group like SiegedSec threatens reputation and personnel safety, since exposed staff lists and internal documents can follow people for years.
Law-enforcement outcomes compared
All three ended under enforcement pressure but through different paths. Investigators traced IntelBroker through cryptocurrency and email reuse. A tool takedown and arrests hit anonymous Sudan. SiegedSec dissolved under publicity and fear of the FBI, and the group did not appear to face charges as a group.
Hacktivists vs. State-Sponsored Attackers
Hacktivists act from a declared cause and often operate loosely, while state-sponsored attackers work for or under direction of a government and pursue strategic goals. The line is blurry because states sometimes run hacktivist personas to hide their involvement. Handala is assessed as a persona of an Iran-linked group, and CARR as a front for the GRU. In practice, assume a persona branded as hacktivist may have more capability than the label suggests. Differences to watch include funding and tradecraft (a true hacktivist group tends to be less resourced), goals (visibility vs. strategic effect), and how closely attacks track a government’s current conflict.
What These Groups Reveal About Modern Hacktivism
Modern hacktivism is organized, publicity-driven, and often overlaps with crime. These three cases show how forums, Telegram and opsec mistakes shape what these groups can do and how they get caught.
The role of forums and Telegram in coordinating attacks
BreachForums gave IntelBroker a marketplace and an audience. Telegram let Anonymous Sudan announce targets and claim credit, and let SiegedSec publish leaks and its disbandment notice. These channels make attacks visible early, which helps defenders who monitor them.
Hacktivism as cover for criminal activity
A political label does not make an operation non-criminal. Anonymous Sudan sold access to its DDoS tool and ran extortion-style campaigns. IntelBroker traded in stolen data for money. When assessing a threat, look at what the actor does, since the branding may not reflect the real motive.
Attribution and arrest patterns
In these cases, identification came from ordinary mistakes more than technical brilliance. IntelBroker was tied to a Coinbase account, and email addresses linked to West’s real name, and both used the same IPs. For hacktivist groups that crave publicity, the same public exposure that builds a reputation also leaves a trail.
Hacktivist Activity in 2026
Hacktivist activity surged in 2026, driven by the Iran war that began on February 28 and by continuing pro-Russia campaigns against critical infrastructure. More than 60 groups had claimed actions by March 2.

The Iran war and pro-Iran hacktivist groups
Pro-Iran activity organized quickly under umbrella collectives. Unit 42 describes the Cyber Islamic Resistance as coordinating teams for synchronized DDoS attacks, data wiping and website defacements. Other named groups include 313 Team and DieNet. Many coordinate through Telegram channels called “Electronic Operations Rooms.” Pro-Russian NoName057(16) pledged solidarity with Iran and began DDoS attacks on Israeli targets. US officials warned that state and local networks could face low-level DDoS and defacement, and a US port was reportedly hit by a DieNet DDoS attack.
Handala and the Stryker attack
On March 11, 2026, Stryker disclosed a global disruption to its Microsoft environment. Handala claimed the attack, saying it stole 50 terabytes of data and wiped tens of thousands of systems. Stryker said it had no indication of ransomware or malware and believed the incident was contained, so treat the scale as a claim. Handala first surfaced in December 2023, and Palo Alto Networks assesses it as a persona maintained by Void Manticore, a group affiliated with Iran’s intelligence ministry.
Pro-Russia hacktivists and critical infrastructure
On December 9, 2025, the FBI, CISA, NSA and partners issued a joint advisory naming Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16) and Sector16. The groups exploit exposed VNC remote-access devices to reach OT systems, with impacts that included physical damage in some cases. Google’s threat intelligence team said the advisory confirmed its earlier assessment that CARR is a front tied to Russia’s military intelligence service, the GRU. The same day, a Ukrainian national pleaded not guilty to a US indictment for supporting NoName057(16), after an earlier indictment tied to CARR.
How to Defend Against Hacktivist and Data-Leak Threats
Defense comes down to three layers: stay online under floods, reduce the value of stolen credentials, and detect early when your data is being traded. No single control covers all three groups.
DDoS resilience and rate-limiting
Put your public apps behind a CDN or DDoS-mitigation provider and make sure your origin servers only accept traffic from it. Add rate limiting and bot challenges on expensive endpoints such as search, login, and APIs, since layer 7 floods target those. Write a DDoS response plan before an incident, including who calls the provider and how you will communicate with customers.
Credential and third-party exposure monitoring
Many leak incidents begin with exposed credentials, API keys, or a third party’s weaker environment. Rotate secrets, enforce MFA, and audit what your vendors can reach. Checking whether your staff or customer emails appear in known breaches helps, and DeXpose’s Email Data Breach Scan and Free Darkweb Report are two quick ways to do that.
Monitoring dark web forums and leak channels for your brand
IntelBroker listed data on forums before victims knew. Monitoring forums, paste sites, and Telegram channels for your domains, brand names, and employee emails can shorten that gap from weeks to days. Early notice gives you time to rotate credentials and brief leadership before the story spreads.
Incident-response basics after a leak
First, validate the claim: HPE’s response to IntelBroker’s post was to turn off potentially affected credentials and investigate. Then contain by revoking keys, tokens, and sessions, and preserve logs. Involve legal early for notification duties, and avoid engaging directly with the actors. Monitor for follow-up postings or resale of the same data.
Frequently Asked Questions (FAQ)
Is IntelBroker still active?
The IntelBroker persona is not known to have been active since the alleged operator’s arrest in France in February 2025. Data stolen under that name can still circulate, and other brokers sell similar material. Check for current legal updates, since the extradition case may have moved on.
Was Anonymous Sudan arrested?
US prosecutors say two Sudanese brothers who ran the group were arrested in March 2024 and indicted in October 2024. Authorities also seized and turned off its DDoS tool. The defendants are presumed innocent unless convicted.
Is SiegedSec still operating?
No. SiegedSec announced its disbandment in July 2024 after the Heritage Foundation incident. Reports in 2025 claimed the FBI raided its leader, but that was not independently confirmed.
What is the difference between hacktivists and cybercriminals?
Hacktivists are motivated mainly by a political or social cause and want attention, while cybercriminals are motivated by profit. Real groups often mix both, so judge them by their actions.
Which of these groups is most dangerous to businesses?
It depends on your risk. IntelBroker poses the greatest data-exposure risk, Anonymous Sudan the greatest availability risk, and SiegedSec mainly threatens organizations tied to political causes. Most companies should plan for the first two.


