Operation Darknet

2011internet eventclassic

Published September 20, 2026

Operation Darknet was a 2011 Anonymous hacktivist campaign that used DDoS attacks and database leaks to take down child sexual abuse material hosted on Tor's hidden services. The operation crashed Freedom Hosting, exposed 1,589 usernames from a site called Lolita City, and set a template that Anonymous returned to in the 2017 Freedom Hosting II breach.

Overview

Rather than a single hack, Operation Darknet ran as a chained series of named sub-attacks executed between October 14 and November 5, 2011, each one announced through PasteBin dumps and IRC channels5. The group combined denial-of-service floods against Freedom Hosting with database intrusions that pulled site membership lists, then dropped those lists as evidence2. Every phase carried a codename, including 'Chris Hanson' (spamming To Catch a Predator clips onto the compromised host) and 'Paw Printing' (a 24-hour honeypot phase)5.

The campaign's signature technical trick was a modified TorButton for Firefox called 'The Honey Pawt,' pushed only through the Hard Candy wiki, which logged the IP addresses of anyone who installed it to visit Lolita City5. Anonymous framed the whole effort in a video manifesto uploaded by the YouTube channel BecomeAnonymous on October 17, 2011, stating the target was CSAM hosting specifically, not Tor or the darknet as a concept8. That distinction mattered in early coverage, where security researchers warned the DDoS approach could taint evidence trails in ongoing police cases2.

Specific fan-made remixes of the operation are not archived in available sources; the campaign's primary artifacts are the group's own manifesto video8, the PasteBin communiques5, and the leaked Lolita City username list dropped on October 18, 20111.

Origin & Background

Platform
Tor hidden services (source) / PasteBin and YouTube (public spread)
Creator
Anonymous
Date
2011

The operation began in early October 2011 when Anonymous members noticed links to images of child sexual abuse on the Hidden Wiki, a Tor-based index of hidden services2. Members stripped the links, watched them get re-posted, and knocked the wiki offline with a denial-of-service attack while tracing where the linked material actually lived2. Nearly all of it shared a hosting fingerprint pointing to Freedom Hosting, at the time one of the biggest hosts of Tor-based sites1.

At 9 p.m. CST on October 14, 2011, the group issued Freedom Hosting an ultimatum to pull the material5. Freedom Hosting refused. Two and a half hours later, Anonymous knocked its services offline with a DDoS flood that included dropping a 1GB SQL payload and 100,000 ASCII Guy Fawkes masks onto the host every five minutes5.

How It Spread

Cultural Impact

Coverage moved beyond tech blogs quickly. By October 24, 2011, the Wall Street Journal, Information Week, and the BBC had all run stories on the takedown27. Techie Buzz published an IRC interview with a hacker using the handle 'arson,' who told the outlet the mission focused only on illegal material and was not triggered by any single event5. The operation drew a rare positive note from commentators who had criticized Anonymous over earlier actions, with the Huffington Post writing that this target was 'unlikely to bring Anonymous much scorn'4.

The Mary Sue framed the takedown as one of the strongest applications of the group's skill set while cautioning that pulling material offline did not reach the predators who produced it6. Security researchers quoted by the BBC warned the DDoS approach could scupper live police work and taint evidence trails2. Six years later, Sarah Jamie Lewis told The Verge that the follow-up 2017 Freedom Hosting II wipe knocked out 'personal or political blogs and forums' alongside abuse sites, showing how much of the Tor ecosystem still sat on a single host3.

Fun Facts

The 'Chris Hanson' sub-attack uploaded episodes of To Catch a Predator labeled as CP files onto Freedom Hosting's servers, referencing the show's host Chris Hansen5.

The DDoS payload dropped a 1GB SQL file and 100,000 ASCII Guy Fawkes masks onto Freedom Hosting every five minutes during the October 14 takedown5.

Operation Darknet was scheduled to end on November 5, 2011, Guy Fawkes Day, with the closing PasteBin note describing the group as 'sailing away for another Lulz'5.

Ars Technica reported that Anonymous initially only managed to keep Freedom Hosting offline for about 30 hours despite repeated attacks7.

The 2017 Freedom Hosting II hacker later told VICE Motherboard that the FHII breach was their 'first hack ever,' according to reporting summarised on Know Your Meme5.

Derivatives & Variations

Operation Paw Printing: a 24-hour honeypot phase on October 27, 2011, that logged 190 unique IPs through a modified TorButton pushed via the Hard Candy wiki[5].

'The Honey Pawt': a modified Firefox TorButton, revealed in the November 2, 2011 PasteBin post, that recorded user information for anyone who tried to access Hard Candy or Lolita City with it installed[5].

Freedom Hosting II breach (February 3, 2017): an Anonymous-affiliated hacker used a similar playbook to wipe FHII and deface roughly 10,613 hidden-service sites, offering to sell the data back for 0.1 bitcoin[3].

Frequently Asked Questions