Six people, one cat-with-a-monocle logo, and fifty days. In the summer of 2011 a splinter of Anonymous calling itself Lulz Security sailed the "Lulz Boat" through Sony, PBS, the CIA's public website, an FBI affiliate, the U.S. Senate and half the gaming industry — not for money, they said, but "just because we could." They ran a phone hotline for hack requests, told the world Tupac was alive and well in New Zealand, and signed off with a manifesto. Then the boat sank — not to a rival crew, not to the feds' brilliance, but from the inside, when the captain turned out to have been wearing a wire since week one.
For the past 50 days we've been disrupting and exposing corporations, governments, often the general population itself, and quite possibly everything in between, just because we could.
LulzSec ("Lulz Security") — a six-person offshoot of Anonymous, active ~May–June 2011 FACT
SCENE
Crew: Sabu (Hector Monsegur), Topiary (Jake Davis), Kayla (Ryan Ackroyd), Tflow (Mustafa Al-Bassam), Pwnsauce (Darren Martyn), and AVunit (never identified). Descended from the Antisecurity movement; rivals with TeaMp0isoN
THE DRAMA
A self-declared "50-day" spree — Sony Pictures, PBS, InfraGard, the CIA public site, Fox/X-Factor, the gaming networks — then Operation AntiSec with Anonymous, then dissolution, then the reveal that leader Sabu had been an FBI informant the whole time
RECORD
Multiple guilty pleas and convictions on both sides of the Atlantic (Davis, Ackroyd, Al-Bassam, Martyn in the UK/Ireland; U.S. co-conspirators on the Sony hack). Monsegur cooperated and received time served plus one year's supervised release FACT
STATUS
DISBANDED — sank June 2011; scattered into AntiSec, then into the docket. The template every later "for the lulz" crew would copy
This file is not an accusation; the accusations were the government's, and most of them stuck. It is a record of the loudest fifty days the scene ever had — a crew that treated breach disclosure as stand-up comedy, exposed a genuinely embarrassing amount of bad corporate security, dumped a lot of ordinary people's passwords along the way, and was undone not by a firewall but by its own captain. The through-line is the gap between the theatre — the Lulz Boat, the monocle cat, the Tupac gag — and the paperwork, which shows real intrusions, real victims, real pleas, and an informant steering from the bridge.
the drama timeline
ACT I — THE BOAT SETS SAIL (Feb–May 2011)
Out of the wreckage of Anonymous's HBGary humiliation, a smaller, funnier, meaner crew casts off — with a mascot, a slogan, and a taste for spectacle.
FEB 2011
The HBGary wreckage
Anonymous eviscerates security firm HBGary Federal after its CEO boasts he'd unmasked the collective — dumping tens of thousands of emails and gutting the company's reputation. Several of the operators who ran that job would, weeks later, sail off under a new flag. LulzSec is born from that milieu, and from the older Antisecurity ethos.
The crew adopts the name Lulz Security, a monocled cartoon cat, and the motto "Laughing at your security since 2011." First marquee hit under the name: Fox.com — leaking X-Factor contestant data and staff details. Days later they publish transaction logs from thousands of UK ATMs. The tone is set: breach as performance art.
PBS, Sony, an FBI affiliate, the CIA's front page, a hack-request hotline, and a fake obituary for a rapper who'd been dead fifteen years. The spree becomes a daily news event.
MAY 30, 2011
Tupac is alive in New Zealand
In retaliation for a Frontline documentary on WikiLeaks, LulzSec breaches PBS and plants a fake story that Tupac Shakur is alive and well in New Zealand. It is the joke that makes them famous — a data breach with a punchline attached.
LulzSec breaches SonyPictures.com via SQL injection and claims to have lifted the personal data of roughly a million accounts — passwords, the group noted with delight, stored in plaintext. Sony disputed the totals; the intrusion was real. Two U.S. men (Cody Kretsinger and Raynaldo Rivera) later pleaded guilty to the Sony hack and were ordered to pay restitution.
The crew breaches InfraGard (the Atlanta chapter), an FBI–private-sector partnership, dumping user credentials and emails. Hacking the feds' friends becomes the pivot from prank to politics.
LulzSec knocks over gaming and industry targets in a single day — Minecraft, League of Legends, EVE Online, The Escapist — and, at the peak of the circus, stands up a public request line so fans can phone in targets. Bethesda, Nintendo, and Eidos also get hit across the spree. The audience is now part of the act.
The crew posts internal files from the U.S. Senate website (June 13) and takes the CIA's public site (cia.gov) offline with a denial-of-service attack (June 15). It is a defacement of prestige, not of secrets — the public front page, not the Directorate — but the headline writes itself.
Not everyone is laughing. Rival crew TeaMp0isoN publicly mocks LulzSec as attention-seeking amateurs, declaring in their own zine, in banner text: "Lulzsec ARE Script Kiddies." The scene's oldest argument — skill versus spectacle — plays out in real time.
ACT III — OPERATION ANTISEC & THE GOODBYE (Jun 20–26, 2011)
The jokes acquire a manifesto. LulzSec merges its fire with Anonymous, points it at governments — then, at the height of the notoriety, announces it's sailing off.
JUN 20, 2011
Operation AntiSec
LulzSec and Anonymous jointly launch Operation Anti-Security (AntiSec) — a call to breach and leak government and law-enforcement data in the name of anti-surveillance and anti-corruption. The "for the lulz" crew now flies an avowedly political flag. AntiSec would outlive LulzSec by far, running into the Stratfor breach later that year.
Under the AntiSec banner, the crew dumps documents from the Arizona Department of Public Safety in protest of the state's immigration-enforcement law — the clearest statement yet that this was never only about laughs.
Just after midnight BST on June 26, LulzSec releases the "50 Days of Lulz" statement — a farewell dump (AT&T internal data, hundreds of thousands of credentials) and a manifesto declaring the "planned 50 day cruise has expired." They beg the "movement" to continue without them. The Lulz Boat, officially, docks.
Channel 4 News, June 2011, reporting LulzSec's disbandment at the end of the self-declared fifty-day spree — contemporaneous broadcast coverage of the Lulz Boat docking.
The boat didn't sink to a rival or a firewall. It sank because the man at the helm had been cooperating with the FBI since the third week of the spree.
JUN 7, 2011
The knock on the door
While LulzSec is still mid-spree, FBI agents arrive at Hector Monsegur's apartment in Lower Manhattan. He confesses almost immediately and agrees to cooperate. For the remaining weeks of the "50 days," the crew's de facto leader — Sabu — is working for the other side.
Within weeks of the goodbye, Tflow (Mustafa Al-Bassam, then 16) is arrested on July 19, and Topiary (Jake Davis) is arrested in the Shetland Islands on July 27. The crew that had run rings around global corporations starts falling one by one — and the survivors begin to wonder why Sabu never gets touched.
The FBI unseals it: Sabu has been an informant since June 2011, and his cooperation has produced charges against five associates — Davis, Ackroyd, Al-Bassam, Martyn, and Donncha O'Cearrbhail. The government says his help disrupted more than 300 attacks. The scene's reaction is equal parts fury and grim recognition: the loudest crew in history was steered into the rocks by its own captain.
The crew is sentenced: Davis and Ackroyd draw UK prison terms; Al-Bassam, a minor at the time, gets a suspended sentence and goes on to a legitimate security-research career. In the U.S., the Sony co-conspirators do federal time. In May 2014, Monsegur — sentencing postponed six times while he cooperated — receives time served and one year's supervised release, walking out of court to prosecutors' praise. Same template, opposite endings.
The "just kids / vandals" case: strip the manifesto away and LulzSec was six people running SQL injection and denial-of-service against soft targets for applause. They dumped the passwords of ordinary people — gamers, X-Factor hopefuls, forum users — who had done nothing but trust a company with bad security. Rival crew TeaMp0isoN put it bluntly in their own zine: "Lulzsec ARE Script Kiddies." Courts agreed the intrusions were crimes; the pleas and prison terms are real.
The harm was real: exposing a million Sony accounts doesn't punish Sony — it punishes the account holders. Knocking gaming networks offline for a laugh is vandalism with a live audience, not accountability journalism.
The "political actors" case: LulzSec exposed genuinely indefensible security — a Fortune-500 studio storing passwords in plaintext, an FBI affiliate breached through basic flaws, government sites falling to garden-variety attacks. Operation AntiSec had an explicit politics: anti-surveillance, anti-corruption, "chinga la migra." In their own words they hoped the "movement" would "manifest itself into a revolution."
The disclosure worked: nothing concentrated corporate minds on password hygiene in 2011 quite like the possibility of being the Lulz Boat's next port of call. The joke had a curriculum.
YOU DECIDE
The intrusions were real and members pleaded to them. But the crew that ran the loudest fifty days in the scene's history also dragged genuinely rotten security into daylight — and was undone not by any of it, but by the fact that its own captain had been an informant since week one. Were they vandals cosplaying as a movement, or a movement that couldn't resist a punchline? The archive keeps both the victim list and the plaintext-password finding, and lets you weigh them.
The archive does not deify. It keeps the manifesto — and the cooperation agreement.
evidence locker
PRIMARY / REFERENCE
Wikipedia — LulzSecATTRIBUTED — dated timeline: formation (May 2011), the Fox/X-Factor, PBS/Tupac, Sony Pictures, InfraGard, gaming, Senate and CIA hits, the 50-day span, Operation AntiSec, the "50 Days of Lulz" farewell, disband date, and the member roster.
en.wikipedia.org/wiki/LulzSec
Wikipedia — Operation AntiSecATTRIBUTED — the June 20, 2011 joint LulzSec/Anonymous campaign, its targets, politics, and afterlife.
en.wikipedia.org/wiki/Operation_AntiSec
Wikipedia — Hector Monsegur ("Sabu")ATTRIBUTED — the June 7, 2011 arrest, cooperation, informant status, and 2014 sentencing to time served plus supervised release.
en.wikipedia.org/wiki/Hector_Monsegur
BBC News — "Hacker 'Sabu' gets lenient sentence after helping US"ATTRIBUTED — May 2014, Monsegur's time-served sentence and the extent of his cooperation.
bbc.com/news/technology-27588976
NPR — "Former LulzSec Hacker Turned Informant Avoids Further Jail Time"ATTRIBUTED — the sentencing outcome and the "300 attacks disrupted" figure.
npr.org/sections/thetwo-way/2014/05/27/316337873/
CONTEXT & CROSS-LINKS
TeaMp0isoN zine — "Lulzsec ARE Script Kiddies"ATTRIBUTED — rival crew's verbatim characterization, from the local archive mirror of the TeaMp0isoN e-zine (research/zines/exploit-db/onion/TeaMp0isoN/TeaMp0isoN_2.txt). Attributed opinion, not adopted.
troll.fan/crew-rivalries.html
troll.fan — TimelineCROSS-LINK — LulzSec's fifty days in the wider chronology of the scene.
troll.fan/timeline.html
The standard. LulzSec is a mostly-adjudicated public matter: the intrusions, the guilty pleas, the sentences, and Sabu's cooperation are all documented in court filings and contemporaneous reporting, and are stated here as fact. The record counts LulzSec claimed (e.g. the Sony totals) are given as the group's claims, as Sony disputed them. The rival "script kiddies" line is attributed to TeaMp0isoN as opinion, quoted from their own zine, not adopted as our judgment. The "vandals vs. political actors" question is left open, with both sides on the record. Real names appear only where publicly charged, convicted, and self-acknowledged; nothing beyond the public record is asserted. If a line here couldn't survive scrutiny, it wouldn't be on the page.