Ghost Squad Hackers
   HOME

TheInfoList



OR:

Ghost Squad Hackers ("GSH") is a
hacktivist Hacktivism (or hactivism; a portmanteau of '' hack'' and ''activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. A form of Internet activism with roo ...
group responsible for several cyber attacks. Former targets of the group include
central bank A central bank, reserve bank, national bank, or monetary authority is an institution that manages the monetary policy of a country or monetary union. In contrast to a commercial bank, a central bank possesses a monopoly on increasing the mo ...
s,
Fox News The Fox News Channel (FNC), commonly known as Fox News, is an American Multinational corporation, multinational Conservatism in the United States, conservative List of news television channels, news and political commentary Television stati ...
,
CNN Cable News Network (CNN) is a multinational news organization operating, most notably, a website and a TV channel headquartered in Atlanta. Founded in 1980 by American media proprietor Ted Turner and Reese Schonfeld as a 24-hour cable ne ...
, the
United States Armed Forces The United States Armed Forces are the Military, military forces of the United States. U.S. United States Code, federal law names six armed forces: the United States Army, Army, United States Marine Corps, Marine Corps, United States Navy, Na ...
and the government of
Israel Israel, officially the State of Israel, is a country in West Asia. It Borders of Israel, shares borders with Lebanon to the north, Syria to the north-east, Jordan to the east, Egypt to the south-west, and the Mediterranean Sea to the west. Isr ...
. The group is led by a '' de facto'' leader known as ''s1ege'' (
leet Leet (or "1337"), also known as eleet or leetspeak, or simply hacker speech, is a system of modified spellings used primarily on the Internet. It often uses character replacements in ways that play on the similarity of their glyphs via refle ...
for "siege"), and selects targets primarily for political reasons. The group forms a part of the hacktivist group
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anonym ...
.


List of attacks on governments and organizations


Defacements of the Ethiopian government

In January 2016, GSH defaced
Ethiopian government The government of Ethiopia () is the federal government of Ethiopia. It is structured in a framework of a federal republic, federal parliamentary system, parliamentary republic, whereby the Prime Minister of Ethiopia, prime minister is the hea ...
websites in response to the killing of nearly 500 students and activists by Ethiopian Security Forces during protests that became extremely violent was involved in the latter part of 2015 and then sparked again between August and October in 2016 Ethiopian protests.


Attacks on Donald Trump

On May 21, 2016 GSH targeted
Donald Trump Donald John Trump (born June 14, 1946) is an American politician, media personality, and businessman who is the 47th president of the United States. A member of the Republican Party (United States), Republican Party, he served as the 45 ...
's official website by launching Distributed Denial of Service (DDoS) attacks for what they saw as racist comments made towards refugees and Mexicans. Shortly after targeting Trump's official website GSH shut down Trump's hotel collection websites.


Attacks on the Israeli Defense Force

The group gained more notoriety after having successfully leaked data of the
Israeli Defense Force The Israel Defense Forces (IDF; , ), alternatively referred to by the Hebrew-language acronym (), is the national military of the State of Israel. It consists of three service branches: the Israeli Ground Forces, the Israeli Air Force, and ...
on April 7, 2016. This was the day #OpIsrael was launched along with
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anonym ...
, leaking the Database of Israel Defense Force posting thousands of IDF soldiers, border patrol, and
Israeli Air Force The Israeli Air Force (IAF; , commonly known as , ''Kheil HaAvir'', "Air Corps") operates as the aerial and space warfare branch of the Israel Defense Forces (IDF). It was founded on May 28, 1948, shortly after the Israeli Declaration of Indep ...
personnel information online.


Attacks on the Ku Klux Klan

On April 23, 2016 GSH targeted the Loyal White Knights of the Ku Klux Klan by taking their websites down in the protest of racism while
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anonym ...
vs. KKK protests were happening in the state of Georgia, U.S.A.


Attacks on Black Lives Matter

In 2016, GSH took down the official website of
Black Lives Matter Black Lives Matter (BLM) is a Decentralization, decentralized political and social movement that aims to highlight racism, discrimination and Racial inequality in the United States, racial inequality experienced by black people, and to pro ...
, claiming the organization fueled further racism.'


Attacks on banks

GSH and Anonymous worked in correlation together when
Operation Icarus
was first launched in February 2016. The op was aimed at attacking the central banking system which the attackers accused the banks with corruption and wanted to raise public awareness. This attack sparked the invitation of more hacking teams and affiliations of Anonymous to focus their attention towards that of the
Central Banks A central bank, reserve bank, national bank, or monetary authority is an institution that manages the monetary policy of a country or monetary union. In contrast to a commercial bank, a central bank possesses a monopoly on increasing the monet ...
in direct regards of further scrutiny and cyber attacks. ''Ghost Squad Hacker's'' leader s1ege claimed responsibility for the attacks which were carried out on the
Bank of England The Bank of England is the central bank of the United Kingdom and the model on which most modern central banks have been based. Established in 1694 to act as the Kingdom of England, English Government's banker and debt manager, and still one ...
email server and dozens of other banking websites including the
New York Stock Exchange The New York Stock Exchange (NYSE, nicknamed "The Big Board") is an American stock exchange in the Financial District, Manhattan, Financial District of Lower Manhattan in New York City. It is the List of stock exchanges, largest stock excha ...
,
Bank of France The Bank of France ( ) is the national central bank for France within the Eurosystem. It was the French central bank between 1800 and 1998, issuing the French franc. It does not translate its name to English, and thus calls itself ''Banque de F ...
,
Bank of Greece The Bank of Greece ( , ) is the national central bank for Greece within the Eurosystem. It was the Greek central bank from 1927 to 2000, issuing the drachma. Since 2014, it has also been Greece's national competent authority within European ...
, Bank of Jordan and the Bank of South Korea, among others. s1ege went on to state that they want to "start an online revolution" to retaliate against the "elite banking cartels putting the world in a perpetual state of chaos." Hundreds of banks were targeted in this operation and to this day the exact number of banks affected is unknown.


Attacks on CNN, Fox News

Notoriety of the group continued to escalate as the heat was turned up during the month of June, 2016. After censoring of media coverage in regards to OpIsrael, OpSilence was initiated targeting mainstream media outlets such as
CNN Cable News Network (CNN) is a multinational news organization operating, most notably, a website and a TV channel headquartered in Atlanta. Founded in 1980 by American media proprietor Ted Turner and Reese Schonfeld as a 24-hour cable ne ...
and
Fox News The Fox News Channel (FNC), commonly known as Fox News, is an American Multinational corporation, multinational Conservatism in the United States, conservative List of news television channels, news and political commentary Television stati ...
.


Data leakage of the U.S Armed Forces/Military

A data dump was later leaked after hacking the
United States Military The United States Armed Forces are the Military, military forces of the United States. U.S. United States Code, federal law names six armed forces: the United States Army, Army, United States Marine Corps, Marine Corps, United States Navy, Na ...
personnel files and releasing information on close to 2,437 army personnel. The information contained in the link was uploaded to an onion link on the
dark web The dark web is the World Wide Web content that exists on darknets ( overlay networks) that use the Internet but require specific software, configurations, or authorization to access. Through the dark web, private computer networks can communica ...
along with a paste-bin link which contained credit card numbers and personal information on
U.S. Army The United States Army (USA) is the primary land service branch of the United States Department of Defense. It is designated as the Army of the United States in the United States Constitution.Article II, section 2, clause 1 of the United Stat ...
personnel.


Defacement of Baton Rouge City government website

July 19, 2016 the sub domain of Baton Rouge City government website was hacked twice in one day by GSH after previously making news after attack towards both the KKK and BLM. These attacks however were targeting the City of
Baton Rouge, Louisiana Baton Rouge ( ; , ) is the List of capitals in the United States, capital city of the U.S. state of Louisiana. It had a population of 227,470 at the 2020 United States census, making it List of municipalities in Louisiana, Louisiana's second-m ...
in protest against police brutality in which a city native
Alton Sterling On July 5, 2016, Alton Sterling, a 37-year-old black man, was shot and killed by two Baton Rouge Police Department officers, Blane Salamoni and Howie Lake II, in Baton Rouge, Louisiana. Police were responding to a report that Sterling was selli ...
was shot and killed by Baton Rouge police officers on the 5th earlier that month. The Baton Rouge website was defaced along with a picture of Alton Sterling with a message that read, "''Being black is not a crime! This is for the shooting of Alton Sterling, just because he's black does not mean he is a bad guy. You will pay. We are the justice. We are Ghost Squad Hackers. /R.I.P. Alton Sterling''".


Attacks on the Afghanistan government and its officials

On July 31, 2016 GSH took over the official
Twitter Twitter, officially known as X since 2023, is an American microblogging and social networking service. It is one of the world's largest social media platforms and one of the most-visited websites. Users can share short text messages, image ...
account of Afghanistan's Chief Executive Dr. Abdullah Abdullah in an effort to raise awareness against corruption and alleged drug deals between
Afghanistan Afghanistan, officially the Islamic Emirate of Afghanistan, is a landlocked country located at the crossroads of Central Asia and South Asia. It is bordered by Pakistan to the Durand Line, east and south, Iran to the Afghanistan–Iran borde ...
and the
U.S. The United States of America (USA), also known as the United States (U.S.) or America, is a country primarily located in North America. It is a federal republic of 50 states and a federal capital district, Washington, D.C. The 48 contiguous ...
They also targeted the Afghan Public Credit Registry website by defacing it which also further allowed them access to several social media accounts including Dr. Abdullah's in which they tweeted, " Afghanistan Gov Hacked by GhostSquadHackers #CheifExecutiveOfficer Can you hear me now? twitter.com/afgexecutive. We found an exploit in the government server and pulled every login we could. We have more also but Dr. Abdullah was not using phone restriction and 2FA was not enabled". The attacks on the
Afghan government The government of Afghanistan, officially called the Islamic Emirate of Afghanistan and informally known as the Taliban government, is the central government of Afghanistan, a unitary state. Under the leadership of the Taliban, the government is ...
continued relentlessly on the first of September after prior targeting of Afghanistan's Chief Executive Twitter account, GSH further assaulted the government by defacing twelve websites in one day all of which were affiliated with the
Afghan government The government of Afghanistan, officially called the Islamic Emirate of Afghanistan and informally known as the Taliban government, is the central government of Afghanistan, a unitary state. Under the leadership of the Taliban, the government is ...
. This included Afghanistan's Ministry of Justice, the Ministry of Defense, the
Ministry of Foreign Affairs In many countries, the ministry of foreign affairs (abbreviated as MFA or MOFA) is the highest government department exclusively or primarily responsible for the state's foreign policy and relations, diplomacy, bilateral, and multilateral r ...
, the Ministry of Refugees and Repatriations, and the Afghan Attorney General's Office. Further assaults continued in hopes of raising awareness for
Palestine Palestine, officially the State of Palestine, is a country in West Asia. Recognized by International recognition of Palestine, 147 of the UN's 193 member states, it encompasses the Israeli-occupied West Bank, including East Jerusalem, and th ...
as part of OpSilence and OpIsrael after shutting down the Israeli Prime Minister and the
Bank of Israel The Bank of Israel (, ) is the central bank of Israel. The bank's headquarters is located in Kiryat HaMemshala in Jerusalem with a branch office in Tel Aviv. The current governor is Amir Yaron. The primary objective of the Bank of Israel is to ...
.


Operation Decrypt ISIS

The group's focus in 2017 shifted slightly towards targeting
ISIS Isis was a major goddess in ancient Egyptian religion whose worship spread throughout the Greco-Roman world. Isis was first mentioned in the Old Kingdom () as one of the main characters of the Osiris myth, in which she resurrects her sla ...
and removing them off the
internet The Internet (or internet) is the Global network, global system of interconnected computer networks that uses the Internet protocol suite (TCP/IP) to communicate between networks and devices. It is a internetworking, network of networks ...
and
social media Social media are interactive technologies that facilitate the Content creation, creation, information exchange, sharing and news aggregator, aggregation of Content (media), content (such as ideas, interests, and other forms of expression) amongs ...
completely. A multitude of accounts from
Facebook Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
,
Twitter Twitter, officially known as X since 2023, is an American microblogging and social networking service. It is one of the world's largest social media platforms and one of the most-visited websites. Users can share short text messages, image ...
, and
Telegram Telegraphy is the long-distance transmission of messages where the sender uses symbolic codes, known to the recipient, rather than a physical exchange of an object bearing the message. Thus flag semaphore is a method of telegraphy, whereas pi ...
alike were hacked and added to an extensive list of
ISIS Isis was a major goddess in ancient Egyptian religion whose worship spread throughout the Greco-Roman world. Isis was first mentioned in the Old Kingdom () as one of the main characters of the Osiris myth, in which she resurrects her sla ...
removed. Further efforts by GSH later revealed bomb instructions and plans to be carried out by ISIS. In a 2018 interview with
CBS News CBS News is the news division of the American television and radio broadcaster CBS. It is headquartered in New York City. CBS News television programs include ''CBS Evening News'', ''CBS Mornings'', news magazine programs ''CBS News Sunday Morn ...
, s1ege stated: "We really do not care about attacking the U.S. elections. They've already been hacked. We mostly hack ISIS". On February 12, 2019 s1ege released a massive leak on Islamic State
Telegram Telegraphy is the long-distance transmission of messages where the sender uses symbolic codes, known to the recipient, rather than a physical exchange of an object bearing the message. Thus flag semaphore is a method of telegraphy, whereas pi ...
and
WhatsApp WhatsApp (officially WhatsApp Messenger) is an American social media, instant messaging (IM), and voice-over-IP (VoIP) service owned by technology conglomerate Meta. It allows users to send text, voice messages and video messages, make vo ...
group's/channel's administrators. The leak included hacked phones/mobile devices, hacked Telegram accounts, hacked Facebook's, hacked Twitter accounts, credit cards, geolocation data, government issued ID cards, and IP logs belonging to the administrators. The group successfully infiltrated the Islamic state community on encrypted communication applications and exposed the administrators by using malware and exploits. The leak was published on mega.nz and Ghost Squad Hackers Official Twitter account. One of the Telegram and WhatsApp Admins (Riffat Mahmood Khan) was a former taxi driver living in Auburn was linked to ISIS and accused of administering the group's encrypted messages. He traveled to Syria in support of the Islamic State in 2015. He returned from the conflict zone via Turkey six months later, and was promptly picked up by
Australian Federal Police The Australian Federal Police (AFP) is the principal Federal police, federal law enforcement agency of the Australian Government responsible for investigating Crime in Australia, crime and protecting the national security of the Commonwealth ...
officers at the airport as he flew in, in September 2015. Video footage from the raids obtained by ''The Herald'' showed his wife and the children being led away from the home by uniformed police, while officers swarm on the Auburn home. He is believed to not have actually participated in the fighting in Syria, but spent time there with the radical group before returning and allegedly continuing his work for the Caliphate. The man remained involved with the Islamic State's encrypted online messaging and continued to take care of the WhatsApp and Telegram groups that the radical Islamic group uses to communicate internally and for recruiting. Documents leaked by GSH showed that several of the accused ISIS supporter's children were enrolled in local Islamic school Al Bayan. He attended South Granville mosque Al Noor, where some sources suggest he became radicalized. Images from his hacked phone exposed by GSH depicted the ISIS flag flying above Venice, explosions, blood-stained knives, children brandishing ISIS flags, a meme saying 'One bullet away from Paradise' and critically wounded soldiers. Leaked data from GSH showed one Belgian (Siraj El Moussaoui), known to be an ISIS supporter, had a video on his phone about how to most effectively behead someone. Siraj El Moussaoui tried in vain to join the Islamic State in 2016 and was arrested shortly after on suspicion of plotting an attack in Belgium.


Defacements of the Indian Government

Starting in April 2020 GSH conducted in a large number of mass defacements of government websites as well as root ownership of an
Indian Government The Government of India (ISO: Bhārata Sarakāra, legally the Union Government or Union of India or the Central Government) is the national authority of the Republic of India, located in South Asia, consisting of 36 states and union territor ...
server and leaked data from the
Australian government The Australian Government, also known as the Commonwealth Government or simply as the federal government, is the national executive government of Australia, a federal parliamentary constitutional monarchy. The executive consists of the pr ...
. This also included governments such as
Australia Australia, officially the Commonwealth of Australia, is a country comprising mainland Australia, the mainland of the Australia (continent), Australian continent, the island of Tasmania and list of islands of Australia, numerous smaller isl ...
,
India India, officially the Republic of India, is a country in South Asia. It is the List of countries and dependencies by area, seventh-largest country by area; the List of countries by population (United Nations), most populous country since ...
and various others. The Twitter feed of ''GSH'' has shared a multitude of alleged attacks on various government websites during the pandemic using hashtags associated with previous campaigns of ''#FreeJulianAssange''. In June the group claimed responsibility for the hacking of other
Indian government The Government of India (ISO: Bhārata Sarakāra, legally the Union Government or Union of India or the Central Government) is the national authority of the Republic of India, located in South Asia, consisting of 36 states and union territor ...
websites in protest against the internet ban in
Jammu Jammu () is a city in Indian-administered Jammu and Kashmir (union territory), Jammu and Kashmir in the disputed Kashmir region.The application of the term "administered" to the various regions of Kashmir and a mention of the Kashmir dispute ...
and
Kashmir Kashmir ( or ) is the Northwestern Indian subcontinent, northernmost geographical region of the Indian subcontinent. Until the mid-19th century, the term ''Kashmir'' denoted only the Kashmir Valley between the Great Himalayas and the Pir P ...
. GSH gave warning in a LiveWire interview saying “To the people of
Jammu Jammu () is a city in Indian-administered Jammu and Kashmir (union territory), Jammu and Kashmir in the disputed Kashmir region.The application of the term "administered" to the various regions of Kashmir and a mention of the Kashmir dispute ...
and
Kashmir Kashmir ( or ) is the Northwestern Indian subcontinent, northernmost geographical region of the Indian subcontinent. Until the mid-19th century, the term ''Kashmir'' denoted only the Kashmir Valley between the Great Himalayas and the Pir P ...
, we will support your efforts and continue to back you through this pandemic and tyrannical government's grip. If India's government is persistent, we will be more persistent and consistent. No region/state/ethnic group should not have access to the internet, not even limited access. These are basic civil rights and liberties.”


Defacements of the European Space Agency (ESA)

The group defaced the
European Space Agency The European Space Agency (ESA) is a 23-member International organization, international organization devoted to space exploration. With its headquarters in Paris and a staff of around 2,547 people globally as of 2023, ESA was founded in 1975 ...
(ESA) website https://business.esa.int in July 2020. GSH claimed the attack was just for fun. They explained that they exploited a
server-side request forgery Server-side request forgery (SSRF) is a type of computer security exploit where an attacker abuses the functionality of a server causing it to access or manipulate information in the realm of that server that would otherwise not be directly acces ...
(SSRF) remote code execution vulnerability in the server, then they gained access to the ''business.esa.int'' server and defaced it. Having no interest in leaking any data their intent was solely to show the server was vulnerable. Within a week of hacking the business domain of the ESA they defaced the https://space4rail.esa.int website as well.


Defacements of Idaho State websites

On July 27, 2020 GSH successfully targeted
Idaho Idaho ( ) is a landlocked U.S. state, state in the Pacific Northwest and Mountain states, Mountain West subregions of the Western United States. It borders Montana and Wyoming to the east, Nevada and Utah to the south, and Washington (state), ...
state websites servers locking agencies out of their own servers. Idaho Government websites targeted included the
Idaho supreme court The Idaho Supreme Court is the state supreme court of Idaho and is composed of the chief justice and four associate judge, justices. The decisions of the Idaho Supreme Court are binding on all other Idaho State court (United States), state court ...
, Idaho court, Idaho Parks and Recreation, Idaho STEM Action Center, and were victims to the group. The sites were used to broadcast messages referencing
Julian Assange Julian Paul Assange ( ; Hawkins; born 3 July 1971) is an Australian editor, publisher, and activist who founded WikiLeaks in 2006. He came to international attention in 2010 after WikiLeaks published a series of News leak, leaks from Chels ...
, founder of
WikiLeaks WikiLeaks () is a non-profit media organisation and publisher of leaked documents. It is funded by donations and media partnerships. It has published classified documents and other media provided by anonymous sources. It was founded in 2006 by ...
, who was charged with violating the
Espionage Act The Espionage Act of 1917 is a United States federal law enacted on June 15, 1917, shortly after the United States entered World War I. It has been amended numerous times over the years. It was originally found in Title 50 of the U.S. Code ( ...
. The messages read ''“Free Julian Assange! Journalism is not a crime.”''


Data leakage on various Sheriff/Police departments

September 3, 2020 - GSH claimed responsibility for the breach of the
Vermont Vermont () is a U.S. state, state in the New England region of the Northeastern United States. It borders Massachusetts to the south, New Hampshire to the east, New York (state), New York to the west, and the Provinces and territories of Ca ...
Sheriff's Association, which resulted in a data leak of names, addresses, financial data and communications between/to various
Vermont Vermont () is a U.S. state, state in the New England region of the Northeastern United States. It borders Massachusetts to the south, New Hampshire to the east, New York (state), New York to the west, and the Provinces and territories of Ca ...
sheriffs. The leaked data was published in retaliation to the shootings of various individuals who fell victim to police brutality; including
George Floyd George Perry Floyd Jr. (October 14, 1973 – May 25, 2020) was an African-American man who was murdered by a white police officer in Minneapolis, Minnesota, during an arrest made after a store clerk suspected Floyd had used a counterfeit tw ...
, Jacob Blake, and
Breonna Taylor Breonna Taylor (June 5, 1993 – March 13, 2020) was an African-American woman who Killing of Breonna Taylor, was shot and killed while unarmed in her Louisville, Kentucky home by three police officers who entered under the auspices of a No-kn ...
.


References

{{Reflist Hacker groups Hacking in the 2000s Anonymous (hacker group) Cybercrime