Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
hacktivist-operationoperational-disruptiongovernment-diplomatic-threat

Anonymous Expanded Operation Payback From Anti-Piracy Targets to WikiLeaks Backers

Updated 28d agoFirst seen May 25, 202619 sources

Anonymous used distributed denial-of-service (DDoS) attacks under the banner of Operation Payback to hit anti-piracy groups and related legal entities including the RIAA, MPAA, BPI, AFACT, BREIN, Websheriff, and the law firm Dunlap, Grubb and Weaver. The campaign escalated after the shutdown of LimeWire, with Anonymous publicly planning another attack on the RIAA and portraying the action as retaliation against copyright enforcement. Earlier attacks also coincided with the takedown of ACS:Law, where hundreds of megabytes of internal emails were exposed after the firm was knocked offline.

The operation later widened into a pro-WikiLeaks campaign branded Operation Avenge Assange after PayPal, Visa, MasterCard, and Amazon cut services to WikiLeaks following the publication of US diplomatic cables. Anonymous launched prolonged attacks that disrupted PayPal and targeted other firms seen as censoring WikiLeaks, while police in the UK opened investigations, monitored threats against government sites, and examined the use of the Low Orbit Ion Cannon by participants. The campaign showed how Anonymous evolved from anti-piracy retaliation into politically motivated online disruption aimed at organizations viewed as restricting access, speech, or digital distribution.

Share:
Anonymous Expanded Operation Payback From Anti-Piracy Targets to WikiLeaks Backers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

20 events from the most recent confirmed update back to the earliest known activity.

20 EVENTS
May 29, 20242y ago

SN_Blackmeta claims responsibility for Internet Archive attack

During the ongoing Internet Archive disruption, an anonymous group calling itself SN_Blackmeta claimed responsibility for the DDoS campaign. The claim had not been independently verified at the time of reporting.

May 26, 20242y ago

Internet Archive comes under sustained multi-day DDoS attack

Beginning on Sunday before May 29, 2024, the Internet Archive experienced a sustained, targeted DDoS attack that caused intermittent disruption to its online library and Wayback Machine. The organization said its collections and web archives remained safe despite the impact.

Dec 14, 201214y ago

UK court convicts AnonOps admin 'Nerdo' over Operation Payback

On 2012-12-14, UK authorities announced the conviction of Christopher 'Nerdo' Weatherhead for conspiracy to impair computers in connection with Anonymous's Operation Payback attacks on PayPal and others. Prosecutors said investigators used IRC logs, open-source intelligence, and computer forensics to prove he helped organize the campaign through AnonOps.

UK cops: How we sniffed out convicted AnonOps admin 'Nerdo'
Jul 27, 201115y ago

Anonymous and LulzSec call for PayPal boycott

On 2011-07-27, Anonymous and Lulz Security publicly urged users to boycott PayPal and close their accounts, citing the July 19 arrests of alleged participants and PayPal's continued withholding of WikiLeaks-related funds. The campaign marked a shift from earlier DDoS retaliation to a public economic protest tied to Operation Avenge Assange.

Anonymous, LulzSec Hacking Groups Call for PayPal Boycott
Dec 15, 201016y ago

Arrests and police investigations follow Anonymous attacks

By mid-December 2010, authorities had begun investigating the WikiLeaks-related DDoS campaign, including a Metropolitan Police probe in the UK, and arrests had already been reported. Officials were also monitoring possible further attacks, including threats against UK government sites.

Dec 8, 201016y ago

Swedish prosecution website hit during Assange proceedings

Amid Julian Assange's extradition proceedings, the Swedish prosecution office website was subjected to an 11-hour DDoS attack linked to the same Anonymous campaign. The attack broadened the target set beyond payment and hosting companies.

Visa, MasterCard, and PayPal targeted over WikiLeaks ties

Anonymous-linked DDoS attacks expanded to companies including Visa, MasterCard, and PayPal after those firms cut ties with WikiLeaks. The attacks were conducted under the Operation Payback banner as retaliation for actions against the leak site.

Dec 6, 201016y ago

Operation Payback broadens into Operation Avenge Assange

By 2010-12-06, reporting described Operation Payback as expanding beyond anti-piracy targets into 'Operation Avenge Assange' in response to actions against WikiLeaks. The shift marked a reorientation of Anonymous-linked DDoS activity toward companies seen as cutting off support for WikiLeaks.

Operation:Payback broadens to “Operation Avenge Assange” | PandaLabs Blog
Dec 4, 201016y ago

PayPal website hit by prolonged DDoS attack

As part of Operation Avenge Assange, Anonymous carried out a DDoS attack against a PayPal website that reportedly lasted about eight hours and caused repeated service disruptions. The attack marked one of the first major actions in the pro-WikiLeaks phase of the campaign.

Operation Avenge Assange launches after firms cut off WikiLeaks

In early December 2010, Anonymous shifted Operation Payback toward support for WikiLeaks after PayPal stopped processing donations and Amazon withdrew hosting. The campaign was framed as retaliation against perceived censorship of WikiLeaks.

Oct 29, 201016y ago

Anonymous plans renewed DDoS attack on the RIAA

Anonymous publicized plans to attack the RIAA on October 29, 2010 at 4:00 PM EST, framing it as retaliation for LimeWire's shutdown. The planned action was presented as part of Operation Payback and followed an earlier RIAA targeting on September 19.

Oct 18, 201016y ago

Anonymous hits UK IPO and acapor.pt in fresh Operation Payback wave

On 2010-10-18, Anonymous launched a new round of Operation Payback DDoS attacks that reportedly knocked the UK Intellectual Property Office and Portuguese music industry site acapor.pt offline. The action was framed as retaliation for anti-piracy measures and followed earlier attacks on copyright-enforcement organizations.

Notorious Anonymous hacktivists launch fresh attacks
Oct 14, 201016y ago

Anonymous targets Gene Simmons websites

Anonymous reportedly disrupted GeneSimmons.com and SimmonsRecords.com in apparent retaliation after Gene Simmons publicly called for more aggressive lawsuits against music file sharers. The action was framed as part of the broader Operation Payback campaign against copyright-enforcement supporters.

Gene Simmons gets kiss of death from notorious web forum | Filesharing | The Guardian
Oct 7, 201016y ago

Anonymous targets Spain's SGAE and Promusicae

On 2010-10-07, Anonymous expanded Operation Payback to Spain, launching DDoS attacks against copyright society SGAE and music industry site Promusicae. Reports said SGAE's website crashed before the announced start time, and Panda Security observed hundreds of participants using LOIC, including about 200 in Spain.

Spanish entertainment industry feels wrath of Anonymous
Oct 4, 201016y ago

Anonymous targets Ministry of Sound and related firms

On 2010-10-04, Anonymous-linked Operation Payback DDoS attacks disrupted the websites of the Ministry of Sound, its payment provider, and solicitors Gallant Macmillan. The action was framed as retaliation for legal efforts tied to identifying and suing alleged music uploaders.

Ministry of Sound floored by Anonymous
Sep 30, 201016y ago

Anonymous targets Dunlap, Grubb and Weaver

By the end of September 2010, Operation Payback participants were also attacking the law firm Dunlap, Grubb and Weaver, which was associated with the US Copyright Group. Anonymous said the attacks would continue until they were no longer angry.

Sep 25, 201016y ago

ACS:Law data exposed after Operation Payback attack

During the early Operation Payback campaign, ACS:Law was taken offline and several hundred megabytes of private emails were exposed. The incident became one of the most notable escalations in the campaign beyond simple service disruption.

Sep 23, 201016y ago

Operation Payback begins targeting anti-piracy groups

By late September 2010, Anonymous participants had launched a week-long DDoS campaign under Operation Payback against anti-piracy organizations and related entities. Reported targets included the RIAA, BPI, MPAA, AFACT, BREIN, Aiplex, and Websheriff.

Sep 19, 201016y ago

RIAA website taken offline in early Operation Payback attack

On 2010-09-19, the RIAA reportedly became one of the earliest successful Operation Payback targets when its website was knocked offline in a DDoS attack. The incident followed the earlier MPAA action and preceded the broader late-September wave against multiple anti-piracy organizations.

RIAA Goes Offline, Joins MPAA As Latest Victim Of Successful DDoS Attacks | TechCrunch
Sep 17, 201016y ago

4chan users organize DDoS action against the MPAA

On 2010-09-17, participants linked to Anonymous/4chan reportedly organized a 'surgical strike' DDoS campaign against the MPAA as retaliation tied to anti-piracy actions against The Pirate Bay. This represents an early precursor phase of Operation Payback before the broader late-September wave against multiple anti-piracy groups.

4chan Users Organize Surgical Strike Against MPAA - MediaCenter Panda Security
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.