Scotland Yard’s e-crime unit arrested Ryan Cleary, 19, in Wickford, Essex, a day after the hacking group LulzSec claimed responsibility for taking the Serious Organised Crime Agency website offline. The arrest followed a joint investigation with the FBI.
What happened
- Over the previous weeks, LulzSec had publicised attacks on targets including Sony, the US broadcaster PBS, and the CIA’s public website.
- Cleary was charged with offences including the SOCA denial-of-service attack and building botnets for such attacks.
- He also faced charges over earlier attacks on music industry bodies, the BPI and the IFPI, in late 2010.
- Cleary was later sentenced in the UK alongside other people convicted over LulzSec’s activities.
Why it mattered
The arrest marked the beginning of a wave of law enforcement action against LulzSec, whose high-profile campaign dominated security headlines during 2011. The group announced it was disbanding a few days later.
Lessons for organisations
Hacktivist groups often exploit basic weaknesses such as unpatched web applications and SQL injection flaws. Regular vulnerability scanning, web application testing, and DDoS protection reduce exposure, as does removing old or unused web content that attackers can exploit.
Sources: The Register, Naked Security
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.