Lizard Squad: The Hacking Group That Targeted Global Gaming Giants

Lizard Squad: The Hacking Group That Targeted Global Gaming Giants

In the mid-2010s, a hacking collective known as Lizard Squad became infamous for orchestrating a series of high-profile cyberattacks. Specializing primarily in Distributed Denial of Service (DDoS) attacks—a method where multiple compromised computer systems flood a target server with traffic to crash it—the group targeted some of the largest gaming infrastructures and corporate websites in the world.

Key Facts

  • Primary Method: Distributed Denial of Service (DDoS) attacks.
  • Major Targets: PlayStation Network, Xbox Live, League of Legends, and Malaysia Airlines.
  • Peak Activity: Late 2014 through mid-2015.
  • Notable Incident: A massive Christmas Day attack in 2014 affecting millions of gamers.
  • Diversification: Attempted a Sybil attack on the Tor network and targeted North Korean internet services.

The 2014 Gaming Offensive

Lizard Squad began gaining notoriety in late 2014 by systematically targeting popular gaming services. Their campaign started on August 18, 2014, when they took the servers of League of Legends offline. This was followed shortly after by a disruption of the PlayStation Network on August 24.

As the year progressed, the group expanded its reach. On November 23, they targeted Destiny servers, and on December 1, they attacked Xbox Live, leaving users unable to connect and displaying error code 80151909. Beyond DDoS attacks, the group also engaged in defacement—the act of changing the visual appearance of a website—when they replaced the front page of Machinima.com with ASCII art of their logo on December 2.

[ไม่มีภาพประกอบ]

The Christmas Day Chaos

The group's most impactful operation occurred on December 25, 2014. Lizard Squad launched a massive DDoS attack against both the PlayStation Network (PSN) and Xbox Live during peak holiday hours. At the time, PSN had approximately 110 million subscribers and Xbox Live had roughly 48 million.

While Xbox Live was restored within 24 hours, PSN suffered extended outages that hindered both existing users and new console owners. Reports from Gizmodo suggested the attacks may have ended after Kim Dotcom offered the group 3,000 accounts on his upload service, MEGA. During this period, a member using the alias "Ryan" (Julius Kivimäki) appeared on Sky News, claiming the goal was to embarrass corporations and encourage people to spend time with their families.

Expanding Beyond Gaming

Lizard Squad's ambitions extended beyond the gaming industry. On December 22, 2014, the group claimed to have taken the internet in North Korea offline, providing an IP address located within the country as evidence. Services were restored the following day.

On December 26, 2014, the group attempted a Sybil attack—a security threat where a single entity creates multiple fake identities to gain disproportionate influence over a network—against the Tor network. They deployed over 3,000 relays named "LizardNSA." However, Tor relay operator Thomas White noted the attack was largely ineffective, as the group only controlled about 0.2743% of the network.

[ไม่มีภาพประกอบ]

The Malaysia Airlines Incident

On January 26, 2015, the group targeted the Malaysia Airlines website, rebranding themselves as a "cyber caliphate." The site was defaced with an image of a tuxedo-wearing lizard and the headline "404 - Plane Not Found," a reference to the disappearance of flight MH370. Some regional versions of the page included the phrase "ISIS will prevail," leading to media speculation regarding links to the Islamic State. Malaysia Airlines confirmed that no customer data was compromised during the event.

Retaliation and Daybreak Games

The group's activity continued into mid-2015. On July 9, they targeted the Daybreak Game Company, disrupting servers for titles such as H1Z1 and PlanetSide 2. This specific attack was framed as retaliation against the company's CEO, John Smedley, who had made legal threats after being targeted by the group.

[ไม่มีภาพประกอบ]

Summary of Notable Attacks

Timeline of Major Lizard Squad Operations
Date Target Type of Attack Impact/Outcome
Aug 18, 2014 League of Legends DDoS Servers taken offline
Dec 1, 2014 Xbox Live DDoS Error code 80151909 for users
Dec 22, 2014 North Korea DDoS Internet taken offline temporarily
Dec 25, 2014 PSN & Xbox Live DDoS Millions of users disrupted on Christmas
Dec 26, 2014 Tor Network Sybil Attack Controlled 0.2743% of the network
Jan 26, 2015 Malaysia Airlines Defacement Website redirected; no data breach
July 9, 2015 Daybreak Games DDoS H1Z1 and PlanetSide 2 disrupted

Frequently Asked Questions

What is a DDoS attack?

A Distributed Denial of Service (DDoS) attack occurs when multiple compromised computer systems flood a target server or network with an overwhelming amount of traffic, causing it to slow down or crash entirely.

How many people were affected by the Christmas 2014 attacks?

The attacks targeted the PlayStation Network, which had roughly 110 million subscribers, and Xbox Live, which had approximately 48 million subscribers, disrupting services for millions of users worldwide.

Did Lizard Squad steal any data from Malaysia Airlines?

No. While the group defaced the website and redirected users to a different page, Malaysia Airlines assured customers and clients that no customer data had been compromised.

What was the purpose of the Tor Sybil attack?

The group attempted to gain influence over the Tor network by creating more than 3,000 relays. However, the attack was considered insignificant as they only managed to control a tiny fraction (0.2743%) of the network.

Why did Lizard Squad attack Daybreak Game Company?

The attack on July 9, 2015, was carried out in retaliation for legal threats made by Daybreak's CEO, John Smedley, after he had been targeted by the hacking group.

References

  1. "How A Hacker Gang Literally Saved Christmas For Video Game Players Everywhere". Business Insider. Archived from the original on 17 January 2015. Retrieved 25 December 2014.
  2. "Lizard Squad Hacker Collective Announces Disbanding". Softpedia News. Archived from the original on 29 June 2020. Retrieved 26 December 2014.
  3. MalwareTech (December 2014). "Darkode - Ode to Lizard Squad (The Rise and Fall of a Private Community)". Archived from the original on 21 July 2015. Retrieved 4 August 2015.
  4. Buncombe, August (15 July 2015). "Darkode: FBI shuts down notorious online forum and cracks 'cyber hornet's nest of criminal hackers'". The Independent. Archived from the original on 14 June 2020. Retrieved 4 September 2017.
  5. Paine, Justin (29 April 2016). "Lizard Squad Ransom Threats: New Name, Same Faux Armada Collective M.O." CloudFlare Blog. CloudFlare, Inc. Archived from the original on 14 June 2020. Retrieved 17 May 2016.