On February 5, 2011, Aaron Barr, CEO of the security firm HBGary Federal, told the Financial Times that he had identified the leaders of Anonymous and planned to hand the information to the FBI at the RSA Conference the following week. The article ran on a Saturday. By Sunday night, Anonymous had breached HBGary Federal's website, stolen 68,000 internal emails, deleted the company's backups, hijacked Barr's Twitter account to post his personal information, and wiped the contents of his iPad remotely. By Monday, Barr's LinkedIn had been redirected to a gay pornography site. By Wednesday, he had resigned.
The HBGary Federal hack became one of the most technically detailed and publicly documented Anonymous operations. Unlike most hacktivist operations that relied primarily on DDoS attacks, this one involved SQL injection, social engineering, and privilege escalation across multiple systems. The stolen email archive, released on The Pirate Bay, contained not just embarrassing internal communications but evidence of a set of government and corporate surveillance programs that had never been publicly disclosed - programs that ultimately generated congressional investigations and proved far more damaging to HBGary's clients than to Anonymous.
HBGary, HBGary Federal, and Aaron Barr
HBGary was a legitimate security research firm known for rootkit analysis and memory forensics. Its sister company, HBGary Federal, was a defense contractor focused on government clients, led by Aaron Barr. The two companies shared infrastructure and some personnel but operated separately. Barr's approach to intelligence work was based on social network analysis: mapping the relationships between online personas, correlating social media activity across platforms, and using pattern analysis to attribute pseudonymous accounts to real identities.
Barr had been working for months to identify Anonymous leadership, particularly in the context of the organization's Operation Payback campaign (DDoS attacks against Visa, Mastercard, PayPal, and Amazon in retaliation for their cutting off WikiLeaks). His methodology involved creating fake personas on Anonymous IRC channels and social media, tracking who appeared in which channels at what times, correlating posting styles, and building a relationship graph he believed identified the core organizers.
The FT article set off an immediate response in Anonymous's IRC channels. Rather than panicking or dispersing, members who saw the article began systematically reviewing HBGary Federal's public-facing infrastructure. Within hours they had identified the attack surface: the company's content management system.
The Attack Chain
HBGary Federal's website ran on a CMS that was vulnerable to SQL injection. The attack was straightforward: by injecting SQL commands into the website's URL parameters, the attackers were able to extract the site's user database, which contained usernames and hashed passwords for CMS administrators including Aaron Barr and HBGary's president Ted Vera.
The passwords were hashed with MD5, which by 2011 was well understood to be inadequate for password storage. More importantly, Barr and Vera had chosen weak passwords. Barr's password, "kibafo33," was cracked in minutes using rainbow tables. Vera's password, "w0rkingmAnz," fell similarly quickly. The use of these passwords extended beyond the CMS: both men had reused them across multiple accounts.
With Barr's email credentials obtained from the hashed database, Anonymous logged into HBGary Federal's Google Apps email system. The company used Google Apps for Business for email hosting. Google Apps at the time had no brute-force protection and minimal authentication logging visible to administrators. Anonymous gained complete access to HBGary Federal's entire corporate email archive.
Access to email led to access to more infrastructure. Within the email archive, Anonymous found credentials and VPN configuration for HBGary's servers, internal documentation about system architecture, and SSH keys stored in email threads. They used this material to access HBGary (not Federal - the parent company's) servers directly, ultimately gaining root access and exfiltrating the full email archive. They also accessed Barr's Twitter account and his iPhone's Find My iPhone account, which they used to remotely wipe his device.
What the Emails Revealed
The 68,000 emails released on The Pirate Bay were significant far beyond the embarrassment to HBGary. They contained detailed proposals for government and corporate surveillance programs that had never been publicly disclosed.
Three sets of documents were particularly significant. The first was a proposal from HBGary Federal in consortium with Palantir Technologies and Berico Technologies, submitted to Bank of America's law firm Hunton and Williams. The proposal described a campaign to undermine WikiLeaks and its journalist Glenn Greenwald using false documents, fabricated personas, and social manipulation. It included a slide labeled "Cyber Attacks Against WikiLeaks" describing strategies to "identify, infiltrate, and discredit" WikiLeaks's support networks. Bank of America was a potential WikiLeaks target because rumors circulated that Julian Assange possessed damaging Bank of America documents.
The second was a proposal to the US Chamber of Commerce, again through Hunton and Williams, for a campaign targeting labor unions and progressive organizations. The proposal described "persona management" - creating fake online identities to infiltrate and disrupt target organizations - and intelligence gathering on Chamber opponents.
The third was documentation of a software project called "Romas/COIN" being developed under a government contract for psychological operations and persona management at scale. The project appeared to involve creating large numbers of convincing fake social media personas for use in influence operations in Arabic-speaking countries.
Barr's Dossier and Its Errors
The email archive also contained Barr's Anonymous dossier - the document he had planned to present to the FBI. Anonymous members reviewed it carefully and found it riddled with errors. Barr had identified several individuals as Anonymous "leaders" who were either marginal participants, completely uninvolved, or fictional personas. One person he identified as a key organizer turned out to have been banned from the relevant IRC channels months earlier. Another "leader" was a teenager whose main connection to Anonymous had been participating in chat channels.
The methodology Barr had used - correlating social media presence, IRC participation times, and communication style - contained a fundamental error: he had assumed that the same pseudonym appearing in different contexts indicated the same person. It did not, reliably. Pseudonym reuse is common; the same handle used across platforms does not necessarily indicate the same individual. His analysis had also been based substantially on information provided by people inside Anonymous channels who, it turned out, had been feeding him false information.
The broader irony was complete: the security researcher who had boasted publicly about his ability to identify anonymous actors had been defeated by an operation whose participants remained, despite significant law enforcement investigation in the years that followed, largely anonymous for years.
Consequences and Arrests
Barr resigned from HBGary Federal on February 28, 2011, less than four weeks after the hack. HBGary Federal was dissolved. HBGary itself survived but was significantly damaged. Greg Hoglund, HBGary's founder and a respected figure in the rootkit analysis community, separated his work from the tainted company name.
Law enforcement investigations identified several individuals involved in the hack. Hector Monsegur, known as "Sabu," was identified by the FBI in June 2011, arrested, and became an FBI informant. Under FBI direction, he continued operating in LulzSec (the Anonymous spinoff group) while cooperating with investigations that led to the arrest of multiple other members in March 2012: Jeremy Hammond (Anarchaos), who had conducted the Stratfor hack; Ryan Ackroyd (Kayla); Jake Davis (Topiary); and Darren Martyn (pwnsauce) and Donncha O'Cearbhaill (palladium). These arrests effectively ended LulzSec's operations.
None of those arrested were identified as the primary operators in the HBGary Federal hack specifically. The people responsible for the initial SQL injection and email exfiltration were never publicly identified by law enforcement, though participants in the operation communicated about it extensively in the email archive and in subsequent interviews with journalists.
Legacy: What the Hack Demonstrated
The HBGary Federal hack occupied a unique position in the landscape of security incidents: it was an attack on a security company conducted using techniques the company's clients paid that company to protect them against. The attack chain - SQL injection, MD5 hash cracking, credential reuse exploitation, lateral movement via credentials found in email - represented the textbook security fundamentals that HBGary Federal's sales pitch was based on understanding.
It became a standard reference case in security training for multiple reasons: the credential reuse vulnerability, the insufficient password hashing, the absence of multi-factor authentication on the email system, and the failure to segregate credentials between the public website and internal systems. Any one of those failures addressed would likely have prevented the breach from escalating to the full email exfiltration.
The disclosed proposals for "persona management," false document operations, and targeted harassment of journalists and activists had a longer tail in policy discussion. They provided concrete evidence that corporate intelligence contractors were developing capabilities for domestic influence operations - not just foreign intelligence. The disclosures contributed to the environment that produced later discussions about private sector surveillance, social media manipulation, and the governance gap around companies providing capabilities to actors who could deploy them in politically motivated ways.