Activists acting under the Anonymous banner launched distributed denial-of-service (DDoS) attacks against Mastercard, Visa, and PayPal. The campaign, dubbed Operation Payback, was in retaliation for the firms cutting off payment services to WikiLeaks.
What happened
- Mastercard’s website was disrupted on 8 December 2010, with attacks on Visa following.
- Participants used a freely available tool called LOIC, which let volunteers join attacks from their own computers, and some reportedly used botnets of compromised machines.
- Websites of politicians who had criticised WikiLeaks, including US Senator Joe Lieberman, were also targeted.
- Police in several countries, including the UK, later made arrests, and some participants were convicted.
Why it mattered
Operation Payback brought hacktivism to mainstream attention and showed that loosely organised volunteers could disrupt the public websites of global financial brands. It also showed that people who joined such attacks from their own computers could be traced and prosecuted.
Lessons for organisations
Plan for DDoS as a realistic threat to public-facing services, using upstream mitigation services and tested continuity plans. Controversial business decisions can change an organisation’s threat profile overnight.
Sources: The Register, TechCrunch
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.