The Christmas Day Hack That Ruined Gaming For 150 Million: The Untold Story of Lizard Squad
Excerpt adapted from Ctrl+Alt+Chaos: How Teenage Hackers Hijack the Internet by Joe Tidy. Published by arrangement with Elliott & Thompson. Copyright © 2025 by Joe Tidy.
The Anderson family are diehard Christmas traditionalists. Dan Anderson will insist his wife Paige is the true stickler for routine, but privately, he loves every over-the-top minute of the holiday just as much as she does.
On one frigid pre-dawn Christmas morning in Buffalo, New York, the pair were curled on their sofa in pajamas, the glow of their twinkling Christmas tree lighting the room. Thirty-two-year-old Dan handed his gift to Paige first: a top-of-the-line new Kindle Voyage, and he felt a quiet, proud satisfaction when she immediately fell in love with it. Next it was his turn. He tore through the wrapping paper as their two confused dogs looked on—one of which, fittingly, was named for Dan’s favorite video game character, Vivi from Final Fantasy. When the paper fell away, the lifelong gamer spotted the instantly familiar logo: a brand-new PlayStation 4.
He unboxed it right away, hooked it up to the TV, and turned it on. His plan was simple: get the system set up, download LittleBigPlanet 3, and grind for a few hours before joining the rest of his family for holiday festivities. Paige had been looking forward to seeing his reaction ever since she bought the console, but things would not go according to plan.
“We didn’t even get far enough to start downloading the game—it wouldn’t let me log into PlayStation Network at all,” Dan recalled. “Nothing connected, we couldn’t even attempt to get any games.” Disappointed, the pair left to join their family’s Christmas plans, and couldn’t test the console again until that evening—only to find the network was still down. A $400 Christmas gift was useless. Dan had to work the next day, so he couldn’t even troubleshoot it then. He was completely devastated.
Five hundred and fifty miles north in Toronto, 16-year-old Mustafa Aijaz was just as hyped for Christmas gaming. For serious players, Christmas evening is the best gaming event of the year, a kind of holiday-within-a-holiday centered on a phenomenon called “Christmas Noobs.” Every Christmas, millions of new players get brand-new consoles and games as gifts, flooding online lobbies with inexperienced players who make easy targets for seasoned veteran gamers.
Mustafa and his friends were skilled Call of Duty: Advanced Warfare players, ready for a night of easy wins, fast experience point farming, and rapid leveling up. They waited patiently, like crocodiles lingering at a river crossing waiting for migrating herds to arrive. But the second their first match went live, all of them were abruptly kicked out and knocked offline. “None of us could log back in, and party chat was down too—we couldn’t even talk to each other to figure out what went wrong,” Mustafa said.
The answer was blowing up all over social media: a hacker collective called Lizard Squad was bragging about carrying out a massive DDoS attack that had taken down both PlayStation Network and Xbox Live, the core services connecting more than 150 million total gamers to Sony and Microsoft’s servers. Mustafa had seen the group taunt and threaten a major attack for weeks, after pulling off smaller strikes earlier that year. The whole stunt, it turned out, was tied to a petty, nonsensical feud with a smaller rival hacking group. The backlash was instantaneous: millions of people were furious.
At the time, PlayStation Network had roughly 110 million subscribers, and Xbox Live had around 48 million. Xbox Live was back up and running within 24 hours, on Boxing Day, but PlayStation Network struggled with outages for far longer. The outage wasn’t just inconvenient for existing players: new consoles, games, and gift vouchers all require online activation through company servers, making the outage a full-blown disaster for the gaming industry—especially Sony, which was already recovering from a separate cyberattack just one month prior.
Outages were reported worldwide, and screenshots of error messages in dozens of languages flooded YouTube and Twitter. No one could do anything to fix the problem except wait for Sony and Microsoft’s engineers to repel the attack, or for Lizard Squad to call it off.
Late on Boxing Day evening, BBC Radio 5 Live aired an interview with two Lizard Squad members, who showed zero remorse for ruining Christmas for millions of people around the world. Twelve hours later, I walked into the Sky News newsroom and was assigned an almost impossible task: land an interview with a Lizard Squad member for that evening’s prime-time TV bulletin.
I spent hours scouring Twitter and speaking to dozens of posers and fakes claiming to be part of the group, before I finally tracked down contact information for a British man named Vinnie Omari. Incredibly, he lived just a few miles from our newsroom in west London. He agreed to come in for an interview immediately: he was pale, skinny, dressed all in black, and spoke a mile a minute. He went out of his way to distance himself from the gang, but promised me that a real Lizard Squad hacker going by “Ryan” would reach out. I had no idea at the time that “Ryan” was Julius Kivimäki, an already infamous teen hacker and repeat offender from Finland. The Skype call came through right at 3 p.m. that afternoon—just in time to edit our conversation into the evening bulletin.
The 17-year-old looked even younger than his age, pale, with a shaved head and soft features. For all the chaos he’d caused, he was surprisingly polite and unrushed. But he was also completely unapologetic and arrogant, barely able to stifle a smirk through the entire interview. When I opened by asking him why he wanted to ruin Christmas for tens of millions of people, he gave me the same generic, rehearsed line: the group did it for fun, and to embarrass big tech companies for their poor security. “These companies make tens of millions every month just from subscriber fees,” he told me. “They should have more than enough funding to protect against attacks like this.” We went back and forth for 15 minutes, and he never showed a single hint of regret or awareness of how many people his stunt had hurt.
“I’d be worried if those people didn’t have anything better to do than play games on Christmas Eve and Christmas Day,” he said. “I mean, I can’t really say I feel bad. I might have forced a couple of kids to spend their time with their families instead of playing games.”
The interview went viral, racking up more than a million views on YouTube and thousands of angry comments on Twitter, where users blasted Lizard Squad with endless criticism. PlayStation and Xbox also received a flood of abuse, and eventually offered affected users a five-day extension to their subscription plans and 10% off as compensation. The total cost to the companies easily ran into the millions.
Kivimäki went on to speak to dozens of other reporters, sometimes using the alias Ryan Cleary, a reference to another hacker he had a tense, distant connection to from the earlier teen hacking group LulzSec. In an interview and debate on the YouTube channel DramaAlert, Kim Dotcom begged him to stop the petty hacker rivalries that hurt so many innocent people. “Hackers used to be respected; they used to have a magic about them,” Kim said, accusing Lizard Squad of ruining the global reputation of hackers with their actions. Kivimäki laughed it off as outdated thinking. “It’s wrong to connect groups like Lizard Squad with, for example, L0pht from a couple of decades back,” he said. “There’s really no connection between the hacking groups of today and the hacking groups of 20 years ago. The whole meaning of hacking is totally different now.”
While many security experts angrily pushed back against media coverage that framed Lizard Squad as a sophisticated operation, most observers ultimately accepted that the 2014 Christmas attack had a lasting, major impact on cybersecurity and the gaming industry. There’s little doubt that improving security was never the group’s goal, despite their clumsy attempts to claim otherwise in interviews—but the attack still served as a critical wake-up call. Security outlet SecurityAffairs published a “lessons learned” analysis of my interview with Kivimäki, noting that while many people wrote off Lizard Squad as unskilled “script kiddies,” that take was completely wrong.
An attack of that size would be shrugged off by most major modern platforms today, but DDoS attacks are still commonplace and growing more powerful. Expensive, dedicated protection services are now a non-negotiable must-have for any organization that needs to stay online. The attack also kicked off a lasting trend of holiday-focused cybercrime. In December 2024, Europol announced an international law enforcement operation targeting illegal DDoS services, noting in a statement: “The festive season has long been a peak period for hackers to carry out some of their most disruptive DDoS attacks, causing severe financial loss, reputational damage, and operational chaos for their victims.”
When Lizard Squad launched their attack, the general public was stunned. Lizard Squad was one of the last groups in a wave of 2010s teen hacking collectives, and most people had no idea how much power even amateur young attackers could wield. There was a vague cultural sense that “hooded hackers working from bedrooms” were causing growing problems, but this attack was immediate, unmissable, and easy for ordinary people to understand—and it was just as easy to get angry about. Over the next few days, I followed up on the fallout as other Lizard Squad members talked to YouTubers about the so-called “drama,” but the question everyone in the newsroom kept asking me was: when would these kids be arrested?
Vinnie Omari was first. On New Year’s Eve, the South East Regional Organized Crime Unit raided his home and arrested him on suspicion of cyber fraud offenses committed between 2013 and 2014. While the raid was mostly tied to other alleged offenses involving PayPal fraud, the search warrant that later leaked online also referenced the Christmas DDoS attacks. “They took everything: Xbox One, phones, laptops, USB drives, everything,” Omari told reporter William Turton from the Daily Dot. He was later cleared of any involvement in the attack.
After Omari’s arrest, more Lizard Squad members were taken into custody. On January 16, 2015, police announced they had arrested an 18-year-old in Southport, near Liverpool. Police didn’t release his name, but Daily Mail reporters identified him locally as Jordan Lee-Bevan, a “quiet teenager” arrested during a raid on his family’s semi-detached home, with officers seizing all his electronics before leading him away in a police car.
In 2016, Zachary Buchta, a teenager from Maryland, was arrested for his role in Lizard Squad and a second hacking group called PoodleCorp. Police had already warned him in 2014 after catching him carrying out minor cybercrime, but he refused to back off—he even changed his Twitter handle to @fbiarelosers to taunt law enforcement.
On the same day Buchta was arrested, Dutch police raided and arrested another 19-year-old: Bradley van Rooy, who used the online names “Uchiha” or “UchihaLS.” He was accused of conspiring with other Lizard Squad members to run websites offering DDoS-for-hire services, which facilitated thousands of separate attacks, and trafficked stolen payment card data from thousands of victims.
Bradley was released on bail for two years, and eventually received a two-year suspended sentence and 180 hours of community service. Most charges against him were dropped because the offenses occurred when he was a minor; he was only convicted of running the DDoS-for-hire operation and handling stolen credit cards. I tracked him down years later, and he spoke openly about that period of his life, which he left behind long ago. “I’m now 27, and I see the damage that I did and understand that I could have gotten a much harsher punishment,” he says. “But back then I was just a kid. I had a really troubled time at school, and after meeting the wrong people while playing RuneScape, I just fell into the hacking life.”
Bradley’s story lines up almost perfectly with the experience of almost every hacker I have ever met or interviewed. It feels like a universal constant: every generation, a small subset of gamers gets pulled into cybercrime in exactly the same way. With billions of gamers around the world, these people make up only a tiny fraction of the whole. But the cycle of hacker groups rising and falling feels almost inevitable. The most important difference, though, is how these young men react after they cross the line and get caught.
So what became of Julius Kivimäki, aka “Ryan,” aka “Ryan Cleary,” and many other aliases including the infamous “Zeekill”?
Surely, after admitting his role in the attack on national TV, he would have been arrested quickly? Police did visit Kivimäki to question him, but they never arrested him—contrary to reports in the international media. It’s unclear why they took no further action at the time, but Kivimäki had bragged in our interview that “They’d have to let me go,” because police would never find any evidence on his devices. It’s possible he was right: his earlier run-ins with law enforcement had taught him to cover his tracks more effectively, or he had exaggerated his own leading role in the DDoS attacks.
For Finnish cybercrime detective Antti Kurittu, seeing Kivimäki on national TV was especially frustrating. Antti had already raided and arrested Kivimäki two years earlier for other cyberattacks carried out with a different teen hacking group called HTP. “I remember watching your Sky News interview and just thinking ‘wow, this guy isn’t even trying to cover up his crimes. He’s just a different sort of person,’” Antti recalls.
It wasn’t until July 2015 that Kivimäki received his first criminal conviction. He was found guilty of a staggering 50,700 counts of aggravated computer trespassing—one count for every computer he’d enslaved into HTP’s botnet. He was also convicted of other offenses including data breaches, money laundering, and possession and use of stolen credit cards. For all these crimes, he was handed a two-year suspended sentence. If he had been an adult, he would have spent years behind bars, but as a minor first-time offender, he served no prison time. Just weeks away from his 18th birthday, Kivimäki walked free, and immediately began calling himself the “Untouchable Hacker God” on Twitter.
A year after Kivimäki’s sentencing, in a bizarre coincidence, Antti ran into Kivimäki in Amsterdam. It was April 2016, and Antti was walking through Schiphol Airport’s departures lounge when he passed the now 18-year-old Kivimäki. Antti did a double take, shocked to see him there. The encounter was so surreal that both men found it funny, and even took a selfie together. After a short chat, Antti asked Kivimäki if he was now “staying out of trouble.” Kivimäki replied, “Of course.” But when Antti asked for a contact email address, Kivimäki made one up ending in @FBI.gov. They laughed and went their separate ways.
But as Antti predicted, the self-proclaimed Untouchable Hacker God would be back. Four years later, he resurfaced, this time linked to one of the cruelest cyberattacks in history, under a new alias: ransom_man.
