CSIDB logo
Threat actor

IBH

Attribution profile

Type
Activist
Location
India
Known incidents
3 incidents
First seen
2016-01-02
Last seen
2016-01-08
Updated
2026-07-31 04:40
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as IBH, also referred to as Indian Black Hats, operates from India. It is identified as a hacktivist group that uses the alias IBH in public reporting. The group’s name reflects its self‑description as a collective of Indian hackers. Open source reports associate the actor with retaliatory cyber actions against Pakistani online assets. No further details about its organizational structure or size are publicly available.

The actor’s typical activity involves defacing websites hosted in Pakistan. Targets have included government‑related institutions such as a horse remount organization, a caring store and canteen, and the Pakistan Council. Private sector entities have also been hit, exemplified by a kitchen appliance retailer and a leather products manufacturer. The defacements replace normal site content with tribute messages and images honoring Indian security personnel killed in attacks. The group’s stated objective is to retaliate for terrorist incidents and to pay homage to fallen soldiers, rather than to pursue financial gain or espionage.

A representative campaign occurred in early January 2016 after the Pathankot attack on an Indian Air Force base. During that operation IBH claimed responsibility for defacing seven Pakistani websites, including the Centre for Pakistan and Gulf Studies and FOTILE. The messages left on the sites dedicated the action to the daughter of Lt. Col. Niranjan Kumar and saluted the families of the deceased. Prior to 2016, the group was linked to a larger defacement effort in 2008 that reportedly altered 125 Pakistani websites in response to the Mumbai attacks. Public attribution does not indicate a direct state sponsor; the actor is described as an independent hacktivist collective. Consequently, the actor’s profile is limited to website defacement as its primary tactic, with no publicly disclosed use of malware, exploit kits, or advanced tooling.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB