Operation Payback was a coordinated, [1] decentralized [2] group of attacks on high-profile [3] opponents of Internet piracy by Internet activists using the "Anonymous" moniker. Operation Payback started as retaliation to distributed denial of service (DDoS) attacks on torrent sites; piracy proponents then decided to launch DDoS attacks on piracy opponents. The initial reaction snowballed into a wave of attacks on major pro-copyright and anti-piracy organizations, law firms, and individuals. The Motion Picture Association of America, the Pirate Party UK and United States Pirate Party criticised the attacks.
Following the United States diplomatic cables leak in December 2010, the organizers commenced DDoS attacks on websites of banks who had withdrawn banking facilities from WikiLeaks.
In 2010, several Bollywood companies hired Aiplex Software to launch DDoS attacks on websites that did not respond to takedown notices. [4] [5] Piracy activists then created Operation Payback in September 2010 in retaliation. [4] The original plan was to attack Aiplex Software directly, but upon finding some hours before the planned DDoS that another individual had taken down the firm's website on their own, Operation Payback moved to launching attacks against the websites of copyright stringent organisations Motion Picture Association of America (MPAA) and International Federation of the Phonographic Industry, giving the two websites a combined total downtime of 30 hours. [6] [7] In the following two days, Operation Payback attacked a multitude of sites affiliated with the MPAA, the Recording Industry Association of America (RIAA), [8] and British Phonographic Industry. [4] Law firms such as ACS:Law, Davenport Lyons and Dunlap, Grubb & Weaver (of the US Copyright Group) were also attacked. [9] [10] [11] [12]
On September 21, 2010, the website of United Kingdom law firm ACS:Law was subjected to a DDoS attack as part of Operation Payback. When asked about the attacks, Andrew Crossley, owner of ACS:Law, said: "It was only down for a few hours. I have far more concern over the fact of my train turning up 10 minutes late or having to queue for a coffee than them wasting my time with this sort of rubbish." [9] [11]
When the site came back online a 350MB file, which was a backup of the site, was visible to anyone for a short period of time. [13] The backup, which included copies of emails sent by the firm, was downloaded and made available on various peer-to-peer networks and websites including The Pirate Bay. [13] [14] [15] Some of the emails contained unencrypted Excel spreadsheets, listing the names and addresses of people that ACS:Law had accused of illegally sharing media. One contained more than 5,300 Sky broadband customers whom they had accused of illegally sharing pornography, [16] [17] while another contained the details of 8,000 Sky customers and 400 Plusnet customers accused of infringing the copyright on music by sharing it on peer-to-peer networks. [18] This alleged breach of the Data Protection Act has become part of the ongoing investigation into ACS:Law by the Information Commissioner's Office. [19] [20]
On September 30, the Leesburg, Virginia office of Dunlap, Grubb & Weaver law firm – also doing business as the "U.S. Copyright Group" [21] – was evacuated by the police after an emailed bomb threat was received. [22] [23] It's believed the event could be connected to Anonymous. [24] Non-related copyright or law firms sites, such as websheriff.com, [12] were also attacked. These attacks were originally organized through an Internet Relay Chat channel. [4] The attacks also became a popular topic on Twitter. [4]
On September 27, 2010, the DDoS attack on the Australian Federation Against Copyright Theft (AFACT) unintentionally brought down 8,000 other small websites hosted on the same server. [25]
In September 2010, in an attempt to ensure that Portuguese citizens could not access thepiratebay.org, Associação do Comércio Audiovisual de Portugal (ACAPOR) filed a complaint against The Pirate Bay. The complaint was filed with the General Inspection of Cultural Activities, which is part of the Portuguese Ministry of Culture. According to the movie rental association, The Pirate Bay is directly responsible for about 15 million illegal downloads in Portugal every year. By installing a Pirate Bay block on all ISPs, ACAPOR hoped to decrease the financial damage it claims The Pirate Bay causes. [26]
On October 18, 2010, the ACAPOR website was defaced, presenting text from Operation Payback and a redirect to The Pirate Bay after a few seconds. In addition to defacing the website, a copy of the email database of ACAPOR was uploaded to The Pirate Bay. [27] [28] The leaked e-mails so far revealed ACAPOR's methods of denunciation, its dissatisfaction with the Portuguese government and justice system, [29] its perception of the copyright debate as war, and its antagonism with the ISPs. ACAPOR claimed that "the business of ISPs is illegal downloading." [30]
On October 4, 2010, Operation Payback launched an attack on the Ministry of Sound website and the Gallant Macmillan website. [31]
On October 7, 2010, they attacked the website of the Spanish copyright society, sgae.es. [32] As of October 7, 2010, the total downtime for all websites attacked during Operation Payback was 537.55 hours. [7]
On October 15, 2010, Copyprotected.com was SQL injected and defaced, [7] [33] and three days later Operation Payback launched a DDoS attack against the UK Intellectual Property Office. [34]
Production companies SatelFilm.at and Wega-Film.at were hit by "drive-by" DDoSes on October 21, 2010, in response to their efforts to gain a court injunction against an ISP that refused to block a movie-streaming website, [35] Operation Payback then knocked porn website Hustler.com offline the following day. [36]
During the 2010 MIPCOM convention, Gene Simmons of KISS stated:
Make sure your brand is protected ... Make sure there are no incursions. Be litigious. Sue everybody. Take their homes, their cars. Don't let anybody cross that line. [37]
— Gene Simmons
In response to Simmons' comments, [38] members of Operation Payback switched their attentions to his two websites, SimmonsRecords.com and GeneSimmons.com, taking them both offline for a total of 38 hours. [7] [39] At some point during the course of this DDoS, GeneSimmons.com was hacked and redirected to ThePirateBay.org. [40] In response to the attack Simmons wrote:
Some of you may have heard a few popcorn farts re: our sites being threatened by hackers.
Our legal team and the FBI have been on the case and we have found a few, shall we say "adventurous" young people, who feel they are above the law.
And, as stated in my MIPCOM speech, we will sue their pants off.
First, they will be punished.
Second, they might find their little butts in jail, right next to someone who's been there for years and is looking for a new girl friend.
We will soon be printing their names and pictures.
We will find you.
You cannot hide.
Stay tuned [41]
This led to additional attacks and subsequently more downtime for his websites. [41] [42] [43] [44] Later, Simmons's message was removed from his website. [45] More than one year later, in December 2011, a person supposedly known under the nickname "spydr101" was arrested in relation to the attack against GeneSimmons.com. He was charged with conspiracy and unauthorized impairment of a protected computer. [46] [47] [48]
On October 26, 2010, LimeWire was ordered to disable the "searching, downloading, uploading, file trading and/or file distribution functionality" after losing a court battle with the RIAA over claims of copyright infringement. Not satisfied with the injunction, the RIAA announced its intention to continue the Arista Records LLC v. Lime Group LLC trial to recover damages caused by the program. [49] [50] In retaliation, [51] members of Operation Payback announced that they would attack RIAA's website on October 29, despite the fact that the group typically does not hit the same target twice. [52] [53] On October 29, riaa.org indeed was taken offline via denial-of-service attack. [54] [55] After the attack, riaa.com and riaa.org sites were inaccessible in Europe. [56] Operation Payback's main site was attacked later that day, and they subsequently moved their website from tieve.tk to anonops.net. [57] [58]
During the damages phase of the LimeWire trial, the RIAA attempted to switch from seeking statutory damages per-work to seeking them per-infringement, but did not quote a total damage amount, nor a method of calculating the number of infringements. [59] The judge in the case rejected the proposal, holding that case law only supported statutory damages on a per-work basis for large-scale infringement, thus capping the potential award at $1.5 billion. [59] On March 15, 2011, four days after the ruling, a report appeared on Law.com highlighting the judge's remark that the per-infringement award sought by the record companies might total in the "trillions"; the report estimated $75 trillion in its attention-grabbing headline (USA's nominal GDP in 2012-2013 was about $16–17 trillion). [60] This figure was repeated in PC Magazine on March 23. [61] An Operation Payback call-to-arms followed, citing the $75 trillion figure as if it were still being actively sought by the RIAA, and a DDoS attack on the RIAA website commenced on March 25. [62]
Around October 28, 2010, the group set up a new website with the intention of coordinating protests around the world to raise awareness of their cause. The date for the protest activities were on November 5, the intended day of the Gunpowder Plot, with which Anonymous heavily affiliates through its use of Guy Fawkes masks.
The protest activity included an attack on the United States Copyright Office, after which the FBI launched an investigation. [63] They later arrested one person accused of taking part in the attack on PayPal. [64]
On November 9, 2010, Operation Payback temporarily ceased attacking websites. [65] The hiatus lasted about four months, ending with an early March 2011 attack that temporarily took down the website of BMI, a prominent collection society operating on behalf of music publishers. [66] This was followed by the aforementioned second attack on the RIAA website.
On December 8, 2010, U.S. politician Sarah Palin announced that her website and personal credit card information were compromised. [67] Palin's team believed the attack was executed by Anonymous, though Anonymous never commented about Palin as a possible target for any attack. [67] [68] [69] Palin's technical team posted a screenshot of a server log file showing the wikileaks.org URL. [67] [69] Visa attacks had been denial of service attacks, but credit card data was not compromised. It is unknown whether Palin's card was compromised as part of a broad attack on Visa or a specific attack on the Palins. [69]
In December 2010, WikiLeaks came under intense pressure to stop publishing secret U.S. diplomatic cables. Corporations such as Amazon, PayPal, BankAmerica, Swiss bank PostFinance, MasterCard and Visa either stopped working with or froze their customers' donations to WikiLeaks due to political pressures. In response, those behind Operation Payback directed their activities against these companies. [70] [71] Operation Payback launched DDoS attacks against PayPal, PostFinance and the Swedish Prosecution Authority. [72] [73] [74] On December 8, 2010, a coordinated DDoS attack by Operation Payback brought down both the MasterCard and Visa websites. [75] [76] [77] [78] On December 9, 2010, prior to a sustained DDoS attack on the PayPal website that caused a minor slowdown to its service, PayPal announced on its blog that it would release the frozen funds in the account of the Wau Holland Foundation that was raising funds for WikiLeaks, but would not reactivate the account. [79] [80] Regarding the attacks, WikiLeaks spokesman Kristinn Hrafnsson denied any relation to the group and said, "We neither condemn nor applaud these attacks. We believe they are a reflection of public opinion on the actions of the targets." [81] On the same day, a 16-year-old boy was arrested in The Hague, Netherlands, in connection with the distributed denial-of-service attacks against MasterCard and PayPal. [82] [83] [84] The boy was an IRC operator under the nickname of Jeroenz0r. [85]
On December 10, 2010, The Daily Telegraph reported that Anonymous had threatened to disrupt British government websites if Assange were extradited to Sweden. [86] Anonymous issued a press release [87] in an attempt to clarify the issue. [88]
Electronic Frontier Foundation co-founder John Perry Barlow described the attacks as "the shot heard round the world—this is Lexington." [89] On December 13, 2010 Julian Assange called for supporters to protect WikiLeaks and said that "Visa, Mastercard, PayPal and others are instruments of US foreign policy" in a statement that was seen as likely to add cyber attacks being perpetrated by Anonymous in support of WikiLeaks. [90]
The following is a list of sites and domains known to have been targeted:
Target | Site | Attack time | Ref. |
---|---|---|---|
PostFinance | postfinance.ch | 2010-12-06 | [72] |
Swedish Prosecution Authority | aklagare.se | 2010-12-07 | [91] |
EveryDNS | everydns.com | 2010-12-07 | [70] |
Joseph Lieberman | lieberman.senate.gov | 2010-12-08 | [92] |
MasterCard | mastercard.com | 2010-12-08 | [93] |
Borgstrom and Bodström | advbyra.se | 2010-12-08 | [92] |
Visa | visa.com | 2010-12-08 | [94] |
Sarah Palin | sarahpac.com | 2010-12-08 | [67] |
PayPal | thepaypalblog.com | 2010-12-09 | [95] |
Amazon | amazon.com | 2010-12-09 (Aborted) | [96] [97] |
PayPal | api.paypal.com:443 | 2010-12-10 | [98] |
MoneyBookers | moneybookers.com | 2010-12-10 | [99] |
Conservatives4Palin | conservatives4palin.com | 2010-12-10 | [100] |
Operation Payback's attempt to take down Amazon.com was aborted after they failed to recruit enough users to their botnet; CNN noted that the massive Amazon website "is almost impossible to crash." [96]
In late December, the FBI began to raid suspected participants in Operation Payback. [101]
At the beginning of 2011, Operation Payback brought down Zimbabwean government websites after the Zimbabwean President's wife sued a newspaper for $15 million for publishing a WikiLeaks cable that linked her with the alleged trade in illicit diamonds. [102] On January 27, 2011, five males aged between 15 and 26 were arrested in early morning raids in the U.K. on suspicion of involvement, [103] and the FBI executed 40 search warrants the same day. [104]
The United Kingdom Intellectual Property Office said that when its site was attacked, those responsible were depriving its citizens of access to information they have a democratic right to access. [105] Other critics claimed the attacks restricted Gene Simmons' right to free speech. [105]
A spokesman for the MPAA said, "It's troubling that these groups seem more concerned about the rights of those who steal and copy films, music, books, and other creative resources than the rights of American workers who are producing these products." [63]
There was also some criticism from the Pirate Party UK and United States Pirate Party, which in a joint public statement urged the group to "Immediately cease the Distributed Denial-of-Service (DDoS) attacks and to instead seek out a legal method to express your frustration and disquiet with the copyright industry, and their perversions of copyright law for personal gain." [106]
While acknowledging that the DDoS attacks on credit card and banking web sites serve as political protests, cyber experts said that Operation Payback has not done any long-term damage: most sites are back online, and people are still continuing to use their credit cards to make payments. "This is more like a noisy political demonstration, like a mob surrounding a bank and refusing to let anyone in or out" said one cyber expert. [107]
Operation Payback members used a modified version of the Low Orbit Ion Cannon (LOIC) to execute the DDoS attacks. [108] In September 2010, a "Hive Mind" mode was added to the LOIC. [108] While in Hive Mind mode, the LOIC connects to IRC, where it can be controlled remotely. This allows computers with LOIC installed on them to behave as if they were a part of a botnet. Utilising this tool, the coordinators of Operation Payback were able to quickly take down websites belonging to anti-piracy groups. [108] Botnets of all sizes have also been used. [109]
Members of Operation Payback reportedly used an IRC channel to communicate about which targets to select, after which instructions for attacking the targets were produced and posted on various imageboards (4chan/7chan/711chan/420chan/808chan). [110] Media such as Twitter and Facebook were also utilized for coordination, [110] but on December 8, 2010, Operation Payback's Facebook page was removed and its official Twitter account was suspended. [94] [111] [112] Additionally a federal court order forced Encyclopedia Dramatica to delete its Operation Payback article, which featured a detailed history of the operation, including personal information of some individuals associated with the companies attacked . [113] [114] [115]
In July 2011, 14 members of Operation Avenge Assange were arrested. [116] In October 2013, 13 members of Operation Payback were indicted in Federal court in Alexandria, Virginia as co-conspirators in violation of 18 U.S.C. § 371 and 18 U.S.C. § 1030. [117] In 2014, some of the members received a plea deal, reducing their felony charges to a single misdemeanor. [118] The defendants were penalized with jail sentences, and one defendant with community service. [119]
2010 (MMX) was a common year starting on Friday of the Gregorian calendar, the 2010th year of the Common Era (CE) and Anno Domini (AD) designations, the 10th year of the 3rd millennium and the 21st century, and the 1st year of the 2010s decade.
Internet activism, hacktivism, or hactivism, is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. With roots in hacker culture and hacker ethics, its ends are often related to free speech, human rights, or freedom of information movements.
The Bescherming Rechten Entertainment Industrie Nederland is an advocacy group with international links, based in the Netherlands, which represents the interests of the Dutch entertainment industry and is organised under the Dutch law through the legal form of stichting. It is notable for launching court proceedings against copyright infringement in the country and for engaging in lobbying in order to create legal precedents of global significance.
The Pirate Bay is an online index of digital content of entertainment media and software. Founded in 2003 by Swedish think tank Piratbyrån, The Pirate Bay allows visitors to search, download, and contribute magnet links and torrent files, which facilitate peer-to-peer file sharing among users of the BitTorrent protocol.
The Internet has a long history of turbulent relations, major maliciously designed disruptions, and other conflicts. This is a list of known and documented Internet, Usenet, virtual community and World Wide Web related conflicts, and of conflicts that touch on both offline and online worlds with possibly wider reaching implications.
Peter Sunde Kolmisoppi, alias brokep, is a Swedish entrepreneur and politician. He is best known for being a co-founder and ex-spokesperson of The Pirate Bay, an illegal BitTorrent search engine. He is an equality advocate and has expressed concerns over issues of centralization of power to the European Union in his blog. Sunde also participates in the Pirate Party of Finland and describes himself as a socialist. In April 2017, Sunde founded Njalla, a privacy oriented domain name registrar, hosting provider and VPN provider.
Anonymous is a decentralized international activist and hacktivist collective and movement primarily known for its various cyberattacks against several governments, government institutions and government agencies, corporations and the Church of Scientology.
ACS:Law was a United Kingdom law firm specialising in intellectual property law. Prior to 2009, its most notable case was the defence of a British national accused of public indecency in Dubai. The firm is best known for its actions against persons allegedly infringing copyright through peer-to-peer file sharing. The firm ceased pursuing file sharers in January 2011 and ceased trading on 3 February 2011.
Low Orbit Ion Cannon (LOIC) is an open-source network stress testing and denial-of-service attack application written in C#. LOIC was initially developed by Praetox Technologies, however it was later released into the public domain and is currently available on several open-source platforms.
The US Copyright Group (UCSG) is a business registered by the law firm Dunlap, Grubb & Weaver that also operates under the name SaveCinema.org. It is engaged in suing people in the U.S. who have allegedly used the P2P file sharing protocol BitTorrent to download certain movies.
LulzSec was a black hat computer hacking group that claimed responsibility for several high profile attacks, including the compromise of user accounts from PlayStation Network in 2011. The group also claimed responsibility for taking the CIA website offline. Some security professionals have commented that LulzSec has drawn attention to insecure systems and the dangers of password reuse. It has gained attention due to its high profile targets and the sarcastic messages it has posted in the aftermath of its attacks. One of the founders of LulzSec was computer security specialist Hector Monsegur, who used the online moniker Sabu. He later helped law enforcement track down other members of the organization as part of a plea deal. At least four associates of LulzSec were arrested in March 2012 as part of this investigation. Prior, British authorities had announced the arrests of two teenagers they alleged were LulzSec members, going by the pseudonyms T-flow and Topiary.
Anonymous is a decentralized virtual community. They are commonly referred to as an internet-based collective of hacktivists whose goals, like its organization, are decentralized. Anonymous seeks mass awareness and revolution against what the organization perceives as corrupt entities, while attempting to maintain anonymity. Anonymous has had a hacktivist impact. This is a timeline of activities reported to be carried out by the group.
We Are Legion: The Story of the Hacktivists is a 2012 documentary film about the workings and beliefs of the self-described "hacktivist" collective, Anonymous.
Christopher Weatherhead, also known by his alias Nerdo, is an activist, hacker and technologist. Weatherhead was jailed for his involvement in several cyberattacks by hacker collective Anonymous.
The PayPal 14 are a group of defendants allegedly connected with the hacktivist group Anonymous, thirteen of whom pleaded guilty in a San Jose court in California, United States in December 2013, to charges of conspiring to disrupt access to the PayPal payment service. The attempted four-day disruption of PayPal's operations was allegedly in response to PayPal's refusal to process donations to Wau Holland Stiftung's PayPal account set up to collect funds for WikiLeaks, and was part of a wider Anonymous campaign, Operation Payback.
High Orbit Ion Cannon (HOIC) is an open-source network stress testing and denial-of-service attack application designed to attack as many as 256 URLs at the same time. It was designed to replace the Low Orbit Ion Cannon which was developed by Praetox Technologies and later released into the public domain. The security advisory for HOIC was released by Prolexic Technologies in February 2012.
On October 21, 2016, three consecutive distributed denial-of-service attacks were launched against the Domain Name System (DNS) provider Dyn. The attack caused major Internet platforms and services to be unavailable to large swathes of users in Europe and North America. The groups Anonymous and New World Hackers claimed responsibility for the attack, but scant evidence was provided.
Ghost Squad Hackers ("GSH") is a hacktivist group responsible for several cyber attacks. Former targets of the group include central banks, Fox News, CNN, the United States Armed Forces and the government of Israel. The group is led by a de facto leader known as s1ege, and selects targets primarily for political reasons. The group forms a part of the hacktivist group Anonymous.
Anonymous, a decentralized international activist and hacktivist collective, has conducted numerous cyber-operations against Russia since February 2022 when the Russian invasion of Ukraine began.
{{cite news}}
: |author=
has generic name (help)