This articlemay havetoo many section headings. Please help consolidate the article.(June 2025) (Learn how and when to remove this message) |
| Formation | 2008 |
|---|---|
| Dissolved | 2012 |
| Type | Hacktivism |
| Membership | TriCk,MLT[1][2][3][4][5] |
Teamp0ison was a computer security research group consisting of 3 to 5 core members. The group gained notoriety in 2011/2012 for itsblackhat hacking activities, which included attacks on theUnited Nations,NASA,NATO,Facebook, Minecraft Pocket Edition Forums, and several other large corporations and government entities.[6] TeaMp0isoN disbanded in 2012 following the arrests of some of its core members,"TriCk", and"MLT".[7]
TeaMp0isoN released several documents pertaining to theEnglish Defence League (EDL), leaking information which included personal details of several high-ranking EDL members.[8] In addition, TeaMp0isoN went on to deface EDL's official website.[9]
In January 2011, unauthorized status updates were posted onMark Zuckerberg and French PresidentNicolas Sarkozy's accounts on social-networking siteFacebook. On 25 January, a spokesperson for Facebook acknowledged the bug in their system and said it has been fixed. Later that weekThe Daily Beast reported that "TriCk", a member of TeaMp0isoN, along with members of a group known as "ZHC", said they had exploited a bug in the web site on the previous New Year's Eve, allowing them to post unauthorized status updates and to block temporary newsfeeds to a list of 130 pages. A spokeswoman for one of the targeted groups, the English Defence League, confirmed that they were targeted and their pages critical ofIslam were indeed hacked. Members of Facebook's security team said after being contacted on the matter byThe Daily Beast, they had found no evidence of malicious activity in their logs.[10]
In June 2011, the group published what appeared to be the address book and other private data of former British Prime MinisterTony Blair onPastebin. According to TeaMp0isoN, the data was obtained originally in December 2010. Blair's spokesman said the data was not obtained from Blair directly, but from the personal email account of his former staff.[11] TeaMp0isoN responded to this, commenting "Blairs sheep are lying about how we got the info, we got into the webmail server via a private exploit & we wiped the logs so Good luck".[12]
During the2011 England riots it was believed that theBlackBerry Messenger service was used by looters for collaboration. TeaMp0isoN defaced the official BlackBerry blog as a response toResearch In Motion (RIM), the maker of the BlackBerry, promising to co-operate with theUnited Kingdom police and government. TeaMp0isoN released a statement saying, "We are all for the rioters that are engaging in attacks on the police and government."[13]
In July 2011, TeaMp0isoN released eight Court Cases againstSarah Palin, claiming they had intentions to do the same withBarack Obama.[14]
On 8 August 2011, TeaMp0isoN released the hashed administrator passwords for a website hosted underNASA's domain, after using a public vulnerability.[15]
In November 2011, TeaMp0isoN released a list of email addresses and passwords that were reportedly obtained via anSQL injection vulnerability in the United Kingdom'sMinistry of Defence.[16] The Ministry of Defence is responsible for controlling Britain's defence policies and is also the headquarters of theBritish Armed Forces.
In December 2011, TeaMp0isoN leaked the account data of 13 million South Korean online game subscribers.[17]
In April 2012, TeaMp0isoN targeted MI6 (the UK'sSecret Intelligence Service). The group created a script that allowed them to repeatedly flood the anti-terrorism hotline with computer-generated calls, before calling up the hotline themselves in order to mock officers. The officers then warned them that they would be traced and reported to the FBI. TeaMp0isoN then reportedly wiretapped the MI6 agents, recording a conversation between officers and posting the leaked conversation onYouTube.[18][19]
On 3 April 2012, TeaMp0isoN gained access to aNATO web server, before leaking data obtained from the server and defacing the index page of the site.[20][21]
TeaMp0isoN joined forces with the hacker collectiveAnonymous to announce OpCensorThis, an operation intended to protest against censorship. The operation received a lot of media attention and music artists such asLyricist Jinn and Tabanacle created a music video in order to raise awareness of the operation.[22][23]
TeaMp0isoN then went on to deface several sites in support of OpCensorThis, the most significant being theUnited Nations Development Programme, and the British tabloid newspaper, theDaily Mail.[24][25]
In response to theOccupy Movement, an online announcement claimed that TeaMp0isoN joined Anonymous to launch Operation Robin Hood, intending to hack into websites, obtain credit cards and make donations to activist organizations while the banks would have to refund the hacked accounts.[26][27] The video stated: "Operation Robin Hood will take credit cards and donate to the 99% as well as various charities around the globe. The banks will be forced to reimburse the people their money back", while encouraging people to "move your accounts into secure credit unions".[26]
As part of Operation Robin Hood, TeaMp0isoN leaked over 26,000 Israeli credit card details, obtained via vulnerabilities in Israeli banks, One and CityNet.[28]
TeaMp0isoN went on to publish the credit card details and passport scans of well-known rapperSean Combs (also known as P-Diddy). TeaMp0isoN then used his credit card to donate money to charity and to order pizzas for those who requested viaTwitter.[29] P-Diddy launched an internal investigation to attempt to track down TeaMp0isoN, reportedly hiring a team of private detectives.[30]
Following the arrest of founding TeaMp0isoN member "TriCk," the group announced Operation Retaliation, which began with reportedDDoS attacks against MI6, before attacks took place against, among others, the Japanese electronics multinationalPanasonic, the Australian Government, and theWorld Health Organization.[31] In addition, Consternation Security andDoxbin were also reported to have been hacked.[32][33]
In November 2011, TeaMp0isoN released more than 128 usernames and login details, which they say were obtained from the United Nations Development Programme. According to a spokeswoman for the UNDP the data was extracted from "an old server which contains old data".[34] TeaMp0isoN disputed this statement, releasing server logs and other evidence to suggest that the server was still in fact actively being used by the United Nations.[35]
In April 2012, TeaMp0isoN hacked the United Nations again, this time targeting the UN's World Health Organization and leaking a list of usernames and hashed passwords, including administrator credentials.[36][37]
On 10 April 2012, the group created a script to call the British Anti-Terrorism Hotline with hoax calls continuously for a 24-hour period to protest the extradition of terrorist suspects to the United States. On 12 April, police arrested two teenagers, aged 16 and 17, over the incident under suspicion of violating theMalicious Communications Act 1988 and theComputer Misuse Act.[38]
On 9 May 2012, alleged TeaMp0isoN member and spokesperson "MLT" was arrested by officers from Scotland Yard on suspicion of offences under the Computer Misuse Act, relating to the attacks on the Anti-Terrorist Hotline and other offences.[39]
In 2015, TeaMp0isoN returned and no longer appear to be committing any illegal activities. Posting from their official Twitter account, they have identified and disclosed vulnerabilities inGoogle,Amazon,eBay,Harvard University,NOAA,Comcast, Time Warner Cable,Western Union, the United Nations, theLondon Stock Exchange,Autodesk and several other large systems. TeaMp0isoN has also released severalzero-day exploits, including one that affected the memorial sites ofMalcolm X andMarilyn Monroe, and one that affected a commonly usedWordPress plugin used by a large number of websites. In addition to this, their website and forums have returned alongside their newly launchedIRC network, and it appears they also have plans for a wargaming website allowing penetration testers to hone their skills within a legal and ethical environment.[citation needed]
In April 2015, TeaMp0isoN identified and disclosed vulnerabilities in many major universities including Harvard University,Stanford University,Princeton University, theUniversity of Texas, and theUniversity of California, among others. The majority of the vulnerabilities found were viaSQL injection flaws.[40] Also at this time, TeaMp0isoN identified a zero-day SQL Injection vulnerability, resulting in many sites being compromised, includingCrime Stoppers in Waterloo, Ontario, Peel and other Canadian cities and districts.[41]
In May 2015, TeaMp0isoN member "KMS" targeted theMinecraft Pocket Edition Forum, seemingly infiltrating their database and leaking a list of over 16,000 usernames and passwords.[42]
Activities in 2016 indicated that they came back as a mix between ablack hat and awhite hat group. They disclosed vulnerabilities in theUnited States Department of Education,UCLA, and various other institutions.
In February/March 2016, the group breached both a UN Agency and one of America's largestInternet service providers. During mid-February, TeaMp0isoN breached the United NationsWorld Tourism Organization and defaced their forum index.[43] During late February, TeaMp0isoN breached theTime Warner Cable Business Class Managed Security Services Portal. Their (since suspended) Twitter feed indicated that they gained access to the backend ticket system as well as the details of 4,191 users.[44]
TeaMp0isoN member "TriCk" is believed to beJunaid Hussain, a black hat hacker who was arrested fordoxing Tony Blair's personal information. He fled the UK while on police bail and reportedly joinedISIL.[45] It is believed that Hussain became a prominent ISIL propagandist, using social media to recruit soldiers to join ISIL, and was behind several high-profile attacks under the group name "CyberCaliphate".[46] Hussain is also believed to have links toJihadi John. Hussain has also been suspected of cooperating with other ISIL members to unmask individuals who report to rebel media groups, and doxing U.S. soldiers and their families.[47]
Hussain was a prominent target on the Pentagon'sDisposition Matrix due to his influence overseas. On 26 August 2015, U.S. officials said they have a "high level of confidence" that Hussain was killed in a drone strike in Syria.[48]