The Johnny attack we believe was done as retaliation for ruining a phisher's opportunity to mass-phish on a brand new TLD. It started right after a week or two that involved banning 150+ very similar paypal phishing sites that kept being registered on the new .ooo TLD. We were getting 10+ new ones per day and I was banning them within hours of them being set up. We have no motive for Tommy at the moment, though it could be retaliation for the very quick cleanup of AnonymousFox. We thought initially that it was the same attacker as Johnny, just moving targets after Johnny went out for maintenance, but the actual type of attack is different, so that's unlikely. In addition, the Tommy attack subsided, whereas Johnny's was nearly continuous for 3 weeks and ended with the server being put out for maintenance... My last post on the first page of this topic is a good read: https://www.helionet.org/index/topic/33824-tommy-server-down/ (note that this was written during the attack, the Tommy attack has since subsided)