They announced their own disbandment on June 25, 2011 with a manifesto that read like a victory lap: "For the past 50 days we've been seizing your bitches, kissing your asses, pissing on your ruins. We are LulzSec, and this is our Lulz Boat."
The group had existed for less than two months. In that time they had taken down the CIA's public website, compromised the US Senate, leaked internal files from the FBI's InfraGard affiliate, destroyed the reputation of a major security company, exfiltrated data from Sony Pictures affecting millions of users, and - most devastatingly - exposed the head of HBGary Federal by publishing 68,000 of the company's private emails in response to his threat to reveal Anonymous members to the FBI.
What the final manifesto didn't mention was that the group's leader, Sabu, had been arrested by the FBI eleven days earlier. He had already agreed to cooperate. He had already begun feeding information to federal investigators. LulzSec's dissolution wasn't a triumphant retirement. It was a controlled demolition.
//Origins: The HBGary Humiliation
The event that created LulzSec wasn't LulzSec's own action. It was Anonymous's.
In February 2011, Aaron Barr - CEO of the security firm HBGary Federal - made an announcement at a security conference: his team had infiltrated Anonymous and identified its leadership. He planned to sell the intelligence to the FBI and present it publicly. He had names. He had faces. He had Twitter accounts.
Anonymous found out before he could present. A small group of hackers, including the people who would become the LulzSec core, launched a response that was both technically efficient and deliberately humiliating. They exploited a combination of SQL injection on HBGary.com and social engineering - calling a HBGary support administrator while impersonating another employee - to gain control of Barr's email account, root access to HBGary's servers, and eventually the email archives of the entire company.
Then they deleted everything - servers wiped, backups destroyed - and published 68,000 emails to the internet. The emails revealed that HBGary had been building profiles on journalists, that Barr's supposed Anonymous intelligence was laughably inaccurate (his "leader" was a teenager who had no actual role), and that various US government and financial industry clients had commissioned work that skirted the boundaries of legality and ethics. The company CEO resigned. HBGary Federal closed. Barr's career effectively ended.
The lesson: if you announce publicly that you know who Anonymous is, Anonymous will show you what it actually knows about you.
//Formation and the 50 Days
LulzSec crystallised around six core members in May 2011, drawing from Anonymous but with a different sensibility: more focused, more media-aware, more interested in spectacle than politics. The name positioned them explicitly as operating "for the lulz" - for entertainment value, not ideology. This was partly genuine and partly protective cover. If the stated motivation is jokes, there's less to argue about in court.
The attacks came in rapid succession. PBS, after an unflattering documentary about WikiLeaks. Sony Pictures, in the largest data breach of the year - customer names, passwords, email addresses, home addresses for 77 million PlayStation Network accounts. The US Senate website. Bethesda Softworks. The CIA's public-facing website, taken offline for hours with a DDoS. The Arizona Department of Public Safety, with internal files, officer information, and intelligence documents published online.
They ran a public phone line. They hosted a @LulzSec Twitter account that tracked their operations in real time, building an audience that followed along like fans at a sporting event. They released music. They had a "Lulz Boat" theme. They responded to requests for targets from followers. They were, in a very deliberate sense, performing.
//Sabu's Arrest: June 7, 2011
Hector Xavier Monsegur - Sabu - was a 28-year-old unemployed man living on the Lower East Side of Manhattan, a Puerto Rican neighbourhood he had grown up in and never left. He had been hacking since his teens, had a history of fraud arrests, and had two young children whose guardian status was a point of significant leverage.
On a single occasion in June 2011, he logged into an IRC channel without routing through Tor. His real IP address appeared in the connection log. That IP resolved to his apartment building. FBI agents visited on June 7th. They presented their evidence. They presented the potential sentence - estimated exposure over 100 years. They presented an alternative.
Monsegur agreed to cooperate within hours. The FBI moved him to a temporary location, allowed him to continue operating as Sabu on IRC and Twitter, and spent the next ten months using him as an instrument inside the group he had built.
During those ten months, LulzSec officially dissolved (Sabu announced it), AntiSec continued with Sabu still seemingly at the helm, and Sabu directed other members toward targets and operations that generated evidence. The group members trusted him. He was, after all, the leader. When the FBI rolled up the rest of LulzSec and AntiSec in March 2012, the arrests covered five countries simultaneously.
//The Stratfor Hack
The most damaging single operation to result from LulzSec's evolution into AntiSec was the December 2011 breach of Strategic Forecasting (Stratfor), a geopolitical intelligence firm whose clients included government agencies, corporations, and media organisations.
The attacker was Jeremy Hammond - hacktivist, not career criminal - who extracted over 200 gigabytes of email archives and 850,000 client records including card data stored in plaintext. The emails were provided to WikiLeaks, which published them as the "Global Intelligence Files." The breach revealed how private intelligence firms operated, their relationships with government, and intelligence they had collected on public figures and organisations.
Hammond was directed to the Stratfor target by Sabu - who was, by that point, actively feeding FBI investigators information about every step. The FBI later acknowledged that the Stratfor breach was conducted while Sabu was a cooperating witness and that investigators were aware of the operation's planning. Hammond, who received no cooperation consideration, was sentenced to 10 years. Sabu received time served.
The ethics of the FBI's decision to allow the Stratfor breach to proceed while documenting it remains contested. Investigators argue the evidence collected was essential to building the case. Critics argue it means the FBI knowingly allowed a major data breach affecting hundreds of thousands of people in order to generate prosecutable evidence.
//The Legacy
LulzSec's 50-day run established several things that remained true for the decade following:
First, that a small group of technically competent but not uniquely skilled individuals could cause significant, public damage to major institutional targets. Sony, the CIA, and HBGary Federal were not defeated by nation-state tooling. They were defeated by SQL injection, social engineering, and password reuse.
Second, that public visibility amplifies impact in ways that private crime doesn't. LulzSec's media presence meant that each breach became a news story, which meant each breach became a demonstration of institutional vulnerability, which meant the impact was larger than the data itself.
Third, that cooperation with law enforcement is the most effective tool for unwinding these groups - not technical surveillance. The FBI didn't hack LulzSec. One member made one mistake and agreed to talk. Everything else followed from that.
Anonymous continued after LulzSec. Distributed, leaderless structures are more resilient to the cooperating-informant problem precisely because there's no single person whose cooperation unravels the whole network. LulzSec's tight core structure - six people who all trusted each other - was its operational strength and its existential vulnerability.