LulzSec Hackers Get Personal, Dump 26,000 Porn Site Usernames And Passwords
After high profile takedowns of PBS and Sony, the anarchic hacker group LulzSec now seems determined to maximize its exploits' embarrassment factor. — On Friday afternoon the group announced that it had stolen …
Context & Ripple Effects
LulzSec's June 10 dump of 26,000 usernames and passwords from a porn site marks a shift in method for a group that spent May and early June on institutional targets: defacing PBS-style media sites and riding the fallout of the Sony PlayStation Network breach, which has drawn a Congressional investigation into stolen credit card numbers and an upcoming appearance by Sony executive Tim Schaff before lawmakers.
The group has been explicit about escalation — declaring open conflict against FBI affiliates and whitehat hackers on June 3 — and this dump weaponizes a different asset: its victims' private identities. The speed with which outlets like Risky.biz picked up the story suggests the tactic is working; LulzSec is optimizing for humiliation rather than downtime.
First-order effects
- Roughly 26,000 account holders at the targeted site have their login credentials published, exposing them to account takeover wherever they reused passwords — the direct harm now lands on individuals rather than corporations.
- LulzSec demonstrates it can extract and release full user databases, raising the immediate stakes for every site in its path that stores passwords unhashed.
Second-order effects
- Sites holding similar user data face forced re-evaluation of credential storage and breach-notification practice, under the shadow of a Congress already probing how Sony disclosed the PlayStation Network theft.
- Law enforcement pressure intensifies: hacking-related arrests have already been reported in Spain in connection with the global wave of attacks, and LulzSec's declared war on FBI affiliates invites a matching investigative response.
Third-order effects
- If credential-dumping becomes the signature move, the measure of a breach shifts from service outage to identity exposure — pushing password hashing, salting, and reuse-prevention from best practice to baseline expectation across consumer web services.
- Hacktivism consolidates around spectacle-and-shame economics, where publicity value rivals technical impact, complicating both prosecution (speech vs. crime) and corporate breach-response playbooks built for quieter adversaries.
The trend: Hacktivist groups are moving from knocking services offline to publishing their users' private credentials, making personal embarrassment — not downtime — the primary cost of a breach.