Lizard Squad: The Hacking Group That Targeted Global Gaming Giants
In the mid-2010s, a hacking collective known as Lizard Squad became infamous for orchestrating a series of high-profile cyberattacks. Specializing primarily in Distributed Denial of Service (DDoS) attacks—a method where multiple compromised computer systems flood a target server with traffic to crash it—the group targeted some of the largest gaming infrastructures and corporate websites in the world.
Key Facts
- Primary Method: Distributed Denial of Service (DDoS) attacks.
- Major Targets: PlayStation Network, Xbox Live, League of Legends, and Malaysia Airlines.
- Peak Activity: Late 2014 through mid-2015.
- Notable Incident: A massive Christmas Day attack in 2014 affecting millions of gamers.
- Diversification: Attempted a Sybil attack on the Tor network and targeted North Korean internet services.
The 2014 Gaming Offensive
Lizard Squad began gaining notoriety in late 2014 by systematically targeting popular gaming services. Their campaign started on August 18, 2014, when they took the servers of League of Legends offline. This was followed shortly after by a disruption of the PlayStation Network on August 24.
As the year progressed, the group expanded its reach. On November 23, they targeted Destiny servers, and on December 1, they attacked Xbox Live, leaving users unable to connect and displaying error code 80151909. Beyond DDoS attacks, the group also engaged in defacement—the act of changing the visual appearance of a website—when they replaced the front page of Machinima.com with ASCII art of their logo on December 2.
[ไม่มีภาพประกอบ]
The Christmas Day Chaos
The group's most impactful operation occurred on December 25, 2014. Lizard Squad launched a massive DDoS attack against both the PlayStation Network (PSN) and Xbox Live during peak holiday hours. At the time, PSN had approximately 110 million subscribers and Xbox Live had roughly 48 million.
While Xbox Live was restored within 24 hours, PSN suffered extended outages that hindered both existing users and new console owners. Reports from Gizmodo suggested the attacks may have ended after Kim Dotcom offered the group 3,000 accounts on his upload service, MEGA. During this period, a member using the alias "Ryan" (Julius Kivimäki) appeared on Sky News, claiming the goal was to embarrass corporations and encourage people to spend time with their families.
Expanding Beyond Gaming
Lizard Squad's ambitions extended beyond the gaming industry. On December 22, 2014, the group claimed to have taken the internet in North Korea offline, providing an IP address located within the country as evidence. Services were restored the following day.
On December 26, 2014, the group attempted a Sybil attack—a security threat where a single entity creates multiple fake identities to gain disproportionate influence over a network—against the Tor network. They deployed over 3,000 relays named "LizardNSA." However, Tor relay operator Thomas White noted the attack was largely ineffective, as the group only controlled about 0.2743% of the network.
[ไม่มีภาพประกอบ]
The Malaysia Airlines Incident
On January 26, 2015, the group targeted the Malaysia Airlines website, rebranding themselves as a "cyber caliphate." The site was defaced with an image of a tuxedo-wearing lizard and the headline "404 - Plane Not Found," a reference to the disappearance of flight MH370. Some regional versions of the page included the phrase "ISIS will prevail," leading to media speculation regarding links to the Islamic State. Malaysia Airlines confirmed that no customer data was compromised during the event.
Retaliation and Daybreak Games
The group's activity continued into mid-2015. On July 9, they targeted the Daybreak Game Company, disrupting servers for titles such as H1Z1 and PlanetSide 2. This specific attack was framed as retaliation against the company's CEO, John Smedley, who had made legal threats after being targeted by the group.
[ไม่มีภาพประกอบ]
Summary of Notable Attacks
| Date | Target | Type of Attack | Impact/Outcome |
|---|---|---|---|
| Aug 18, 2014 | League of Legends | DDoS | Servers taken offline |
| Dec 1, 2014 | Xbox Live | DDoS | Error code 80151909 for users |
| Dec 22, 2014 | North Korea | DDoS | Internet taken offline temporarily |
| Dec 25, 2014 | PSN & Xbox Live | DDoS | Millions of users disrupted on Christmas |
| Dec 26, 2014 | Tor Network | Sybil Attack | Controlled 0.2743% of the network |
| Jan 26, 2015 | Malaysia Airlines | Defacement | Website redirected; no data breach |
| July 9, 2015 | Daybreak Games | DDoS | H1Z1 and PlanetSide 2 disrupted |
Frequently Asked Questions
What is a DDoS attack?
A Distributed Denial of Service (DDoS) attack occurs when multiple compromised computer systems flood a target server or network with an overwhelming amount of traffic, causing it to slow down or crash entirely.
How many people were affected by the Christmas 2014 attacks?
The attacks targeted the PlayStation Network, which had roughly 110 million subscribers, and Xbox Live, which had approximately 48 million subscribers, disrupting services for millions of users worldwide.
Did Lizard Squad steal any data from Malaysia Airlines?
No. While the group defaced the website and redirected users to a different page, Malaysia Airlines assured customers and clients that no customer data had been compromised.
What was the purpose of the Tor Sybil attack?
The group attempted to gain influence over the Tor network by creating more than 3,000 relays. However, the attack was considered insignificant as they only managed to control a tiny fraction (0.2743%) of the network.
Why did Lizard Squad attack Daybreak Game Company?
The attack on July 9, 2015, was carried out in retaliation for legal threats made by Daybreak's CEO, John Smedley, after he had been targeted by the hacking group.