The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →On July 20, 2023, CyberScoop reported that Anonymous Sudan claimed a one-hour distributed denial-of-service (DDoS) attack on OnlyFans the previous Wednesday. Reports described intermittent availability that afternoon, but did not establish a confirmed intrusion, data theft, or lasting outage. The incident is best understood as a claimed service-disruption attack—not evidence that OnlyFans was hacked for user data.
What happened to OnlyFans?
Anonymous Sudan claimed responsibility for a one-hour DDoS attack, according to CyberScoop’s July 20, 2023 report. The report said OnlyFans was intermittently unavailable during the afternoon. OnlyFans and its parent company, Fenix International Limited, did not respond to CyberScoop’s request for comment at publication.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Embroidered Zip Hoodie (US, Alpha, XX-Large, Regular, Regular, Black) | $35.00 | Buy on Amazon |
| 2 |
|
Only-Fans T-Shirt | $17.99 | Buy on Amazon |
A DDoS attack attempts to overwhelm an online service with traffic so legitimate users have trouble reaching it. That can cause disruption without an attacker breaking into the service or accessing its data. In this case, the reported impact was intermittent availability; the report did not establish a confirmed intrusion or data theft.
Who is Anonymous Sudan, and how is it linked to Killnet?
CyberScoop characterized Anonymous Sudan as an apparent pro-Russian persona that appeared affiliated with Killnet, citing Mandiant analysis. Mandiant, as quoted by CyberScoop, said it could not confirm collaboration or cooperation between Killnet and Russian security services. It added that Killnet’s targeting “consistently reflects the interests of the Russian state.” That is an analyst assessment of targeting, not proof of state direction of the OnlyFans incident.
#1 Best Overall
- Soft, mid-weight fabric
- Full-length front zipper
- Adjustable drawstring hood
- Relaxed, unisex fit
- Female model wears size S, male model wears size L
Mandiant figures reported by CyberScoop provide context for the group’s activity at that time, not a measure of this specific event: Mandiant attributed DDoS attacks against more than 500 distinct victims to a network of Killnet-affiliated personas, and said Anonymous Sudan accounted for 63% of those attacks after appearing online in January 2023. Those figures do not verify the OnlyFans claim.
Why are pro-Russia hacktivists targeting Western organizations?
The UK National Cyber Security Centre’s 2025 annual review describes pro-Russia hacktivist groups seeking targets in the UK, Europe, the United States and other NATO countries, often in retaliation for what they perceive as Western support for Ukraine and Israel. The NCSC also says these groups’ association with states varies. Its description supports a broader pattern of Western targeting, but does not establish the motive for the OnlyFans claim.
The NCSC says some actors select targets, including critical national infrastructure sectors, based on vulnerability. That can make their activity less predictable; it does not show that OnlyFans was chosen for that reason. A group’s stated rationale, an analyst’s assessment of its relationships, and evidence of state tasking are distinct kinds of attribution.
What do later hacktivist activity figures show?
Later figures illustrate activity tracked across different periods and targets; they do not confirm the OnlyFans claim or describe all attacks. Radware’s 2025 Global Threat Analysis Report says government institutions represented 20% of hacktivist activity it tracked in 2024, while e-commerce platforms and organizational websites represented 9%, and the financial sector 8.9%.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #2
- Only-Fans
- Only-Fans
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
In a September 9, 2026 release, Radware reported that NoName057(16) accounted for 40.5% of recorded hacktivist claims in the first half of 2026. This vendor-tracked share concerns claims attributed to a different actor and a later period. Radware’s figures are claims-based company tracking, not an official census or a direct comparison with the 2023 OnlyFans incident.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to assess claims about cyberattacks
Reports of disruption are easier to interpret when they distinguish what was claimed from what was observed and confirmed. For an incident like this, keep four questions separate:
- Method: Was the activity described as DDoS, an intrusion, or data theft? A DDoS claim does not itself imply access to accounts or files.
- Impact: Did a group claim an effect, did observers report disruption, or did the affected organization confirm it? These are not interchangeable.
- Attribution: Is the source a group’s own claim, an analyst’s assessment, or a formal government attribution? A possible affiliation does not establish who directed a specific operation.
- Rationale: Is the explanation a group’s stated ideology, retaliation, strategic value, or opportunistic targeting of a vulnerable service? General patterns do not prove the motive for an individual incident.
A nearby example shows why these distinctions matter: CERT-EU’s January 2023 brief recorded pro-Russia DDoS claims against European public and private entities. It also noted that several targeted banks reported intermittent technical difficulties without confirming hacktivist responsibility.
What is confirmed about the OnlyFans incident?
The available reporting establishes that Anonymous Sudan claimed a one-hour DDoS attack and that intermittent availability was reported that afternoon. It does not establish a data breach, lasting outage, or Russian government direction. CyberScoop reported that OnlyFans and Fenix International Limited did not respond to its request for comment; the sources cited here provide no later company confirmation. A separate UK Government profile of GRU cyber and hybrid operations discusses attributed Russian operations but does not attribute this OnlyFans incident to the GRU.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

