Operation Payback was a coordinated, decentralized group of attacks on high-profile opponents of Internet piracy by Internet activists using the "Anonymous" moniker. Operation Payback started as retaliation to distributed denial of service (DDoS) attacks on torrent sites; piracy proponents then decided to launch DDoS attacks on piracy opponents. The initial reaction snowballed into a wave of attacks on major pro-copyright and anti-piracy organizations, law firms, and individuals. The Motion Picture Association of America, the Pirate Party UK and United States Pirate Party criticised the attacks. Following the United States diplomatic cables leak in December 2010, the organizers commenced DDoS attacks on websites of banks who had withdrawn banking facilities from WikiLeaks.
Background and initial attacks In 2010, several Bollywood companies hired Aiplex Software to launch DDoS attacks on websites that did not respond to takedown notices. Piracy activists then created Operation Payback in September 2010 in retaliation. The original plan was to attack Aiplex Software directly, but upon finding some hours before the planned DDoS that another individual had taken down the firm's website on their own, Operation Payback moved to launching attacks against the websites of copyright stringent organisations Motion Picture Association of America (MPAA) and International Federation of the Phonographic Industry, giving the two websites a combined total downtime of 30 hours. In the following two days, Operation Payback attacked a multitude of sites affiliated with the MPAA, the Recording Industry Association of America (RIAA), and British Phonographic Industry. Law firms such as ACS:Law, Davenport Lyons and Dunlap, Grubb & Weaver (of the US Copyright Group) were also attacked.
Attacks on the recording industry
Law firms On September 21, 2010, the website of United Kingdom law firm ACS:Law was subjected to a DDoS attack as part of Operation Payback. When asked about the attacks, Andrew Crossley, owner of ACS:Law, said: "It was only down for a few hours. I have far more concern over the fact of my train turning up 10 minutes late or having to queue for a coffee than them wasting my time with this sort of rubbish." When the site came back online a 350MB file, which was a backup of the site, was visible to anyone for a short period of time. The backup, which included copies of emails sent by the firm, was downloaded and made available on various peer-to-peer networks and websites including The Pirate Bay. Some of the emails contained unencrypted Excel spreadsheets, listing the names and addresses of people that ACS:Law had accused of illegally sharing media. One contained more than 5,300 Sky broadband customers whom they had accused of illegally sharing pornography, while another contained the details of 8,000 Sky customers and 400 Plusnet customers accused of infringing the copyright on music by sharing it on peer-to-peer networks. This alleged breach of the Data Protection Act has become part of the ongoing investigation into ACS:Law by the Information Commissioner's Office. On September 30, the Leesburg, Virginia office of Dunlap, Grubb & Weaver law firm – also doing business as the "U.S. Copyright Group" – was evacuated by the police after an emailed bomb threat was received. It's believed the event could be connected to Anonymous. Non-related copyright or law firms sites, such as websheriff.com, were also attacked. These attacks were originally organized through an Internet Relay Chat channel. The attacks also became a popular topic on Twitter.
Australian pro-copyright organization On September 27, 2010, the DDoS attack on the Australian Federation Against Copyright Theft (AFACT) unintentionally brought down 8,000 other small websites hosted on the same server.
ACAPOR In September 2010, in an attempt to ensure that Portuguese citizens could not access thepiratebay.org, Associação do Comércio Audiovisual de Portugal (ACAPOR) filed a complaint against The Pirate Bay. The complaint was filed with the General Inspection of Cultural Activities, which is part of the Portuguese Ministry of Culture. According to the movie rental association, The Pirate Bay is directly responsible for about 15 million illegal downloads in Portugal every year. By installing a Pirate Bay block on all ISPs, ACAPOR hoped to decrease the financial damage it claims The Pirate Bay causes. On October 18, 2010, the ACAPOR website was defaced, presenting text from Operation Payback and a redirect to The Pirate Bay after a few seconds. In addition to defacing the website, a copy of the email database of ACAPOR was uploaded to The Pirate Bay. The leaked e-mails so far revealed ACAPOR's methods of denunciation, its dissatisfaction with the Portuguese government and justice system, its perception of the copyright debate as war, and its antagonism with the ISPs. ACAPOR claimed that "the business of ISPs is illegal downloading."
More attacks On October 4, 2010, Operation Payback launched an attack on the Ministry of Sound website and the Gallant Macmillan website. On October 7, 2010, they attacked the website of the Spanish copyright society, sgae.es. As of October 7, 2010, the total downtime for all websites attacked during Operation Payback was 537.55 hours. On October 15, 2010, Copyprotected.com was SQL injected and defaced, and three days later Operation Payback launched a DDoS attack against the UK Intellectual Property Office. Production companies SatelFilm.at and Wega-Film.at were hit by "drive-by" DDoSes on October 21, 2010, in response to their efforts to gain a court injunction against an ISP that refused to block a movie-streaming website, Operation Payback then knocked porn website Hustler.com offline the following day.
Musician and copyright advocate During the 2010 MIPCOM convention, Gene Simmons of Kiss stated:
Make sure your brand is protected ... Make sure there are no incursions. Be litigious. Sue everybody. Take their homes, their cars. Don't let anybody cross that line. In response to Simmons' comments, members of Operation Payback switched their attentions to his two websites, SimmonsRecords.com and GeneSimmons.com, taking them both offline for a total of 38 hours. At some point during the course of this DDoS, GeneSimmons.com was hacked and redirected to ThePirateBay.org. In response to the attack Simmons wrote:
… excerpt ends here. Continue reading the full article.


