CSIDB logo
Threat actor

Oppressed Defenders

Attribution profile

Type
Activist
Location
Saudi Arabia
Known incidents
1 incident
First seen
2015-02-23
Last seen
2015-02-23
Updated
2026-07-31 03:58
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as “Oppressed Defenders” operates under that alias and has been linked to Saudi Arabia based on the geographic focus of its activities. Public reporting identifies the group as a hacktivist collective that emerged in early 2015, conducting a series of distributed denial‑of‑service attacks against Saudi financial institutions. The actor’s self‑described motivation, as stated in interviews with journalists, is to pressure the Saudi regime to address alleged human rights violations and to alter domestic policies, framing its actions as warnings intended to compel behavioral change.

The actor’s targeting has been confined to the banking sector within Saudi Arabia, with confirmed incidents against Arab National Bank, AlJazira Bank, Samba Bank, Alahli Bank and Riyad Bank. These attacks are presented as part of an ongoing campaign dubbed “Operation Saudi,” in which the group vows to continue striking financial targets until its demands are met. The strategic objective expressed by the group is disruption of online banking services to create economic and reputational pressure on the Saudi government, rather than financial gain or espionage. No public sources attribute the actor to a state sponsor or a criminal consortium, and no affiliations beyond the self‑identified hacktivist label have been documented.

Technical details disclosed in the reporting are limited to the use of distributed denial‑of‑service (DDoS) techniques as the primary tool for disabling online banking domains. No specific malware families, exploit kits, or initial access vectors have been mentioned in the available sources. The group’s operational pattern involves launching DDoS attacks that render victim websites inaccessible for periods ranging from several minutes to longer outages, followed by public statements threatening escalation if the regime does not respond. The most notable publicly reported operations include the February 2015 DDoS against Arab National Bank’s online banking platform and the earlier February 2015 attack on AlJazira Bank, both of which were explicitly cited as components of the broader Operation Saudi effort targeting the kingdom’s financial sector. No further technical specifics or additional campaigns beyond those described are evident in the provided material.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB