SiegedSec leaks Heritage Foundation data in protest over Project 2025

Organization
The Heritage Foundation
Exploit
Hacking
Industry
Think Tank

On 9 July 2024 the hacktivist group SiegedSec, which described itself as a collective of self-styled gay furry hackers, published data it said came from the Heritage Foundation. The group tied the release to its opposition to Project 2025, the conservative policy blueprint the think tank had assembled, and framed it as part of a campaign it called #OpTransRights.

Accounts of the volume differed. SiegedSec told The Intercept it had obtained more than 200 gigabytes of material, including credentials and user records from a Heritage database and archives of Heritage blogs and The Daily Signal website as they stood in November 2022. The Register reported that roughly 2 gigabytes were actually released, containing usernames, passwords and logs. The group claimed the credentials covered every user in the database, including Heritage president Kevin Roberts and some U.S. government employees.

Heritage disputed that it had been hacked. A spokesperson said an organized group had come across a two-year-old archive of The Daily Signal on a public-facing website owned by a contractor, adding that no Heritage systems were breached and that its databases and websites remained secure. Mike Howell, who ran Heritage's Oversight Project, separately exchanged messages with a SiegedSec member and threatened to identify the group's members.

SiegedSec announced on 12 July 2024 that it was disbanding, citing mental health and a wish to avoid FBI attention. The leak was the second security incident Heritage faced that year, following an April 2024 network intrusion that a Heritage official attributed to nation-state hackers.

Sources