Middle East Cyber Army
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The Middle East Cyber Army, also known by the alias MECA, is a hacker group that has been identified in open sources as operating from New Zealand. The group publicly declares its affiliation with Islam, often posting messages such as “WE ARE MUSLIMS AND WE ARE PROUD!!!” accompanied by Arabic phrases affirming faith when it compromises websites. Its activities have consisted primarily of website defacements rather than data theft or financial gain, with attackers replacing normal content with warfare imagery and ideological statements. No public reporting has linked the group to a state sponsor or a criminal consortium, and no evidence of espionage or monetary motives has been presented in the sources examined. The actors have shown a pattern of targeting low‑traffic or low‑profile online assets, including municipal department sites, arts organization pages, educational institution subdomains, school district websites, and small community domains in regions such as the United States and Canada. Their stated goal appears to be disruption and the propagation of a political‑religious message, as evidenced by the replacement of site homepages with protest‑style graphics and declarations.
Among the documented incidents, the Middle East Cyber Army defaced the Arizona Department of Weights and Measures website on June 7 2015, displaying an exploding city image and causing the agency to shut the site down while it considered merging with the Department of Agriculture; the group also defaced the Scottsdale‑based Art and Sol site around the same time. On May 17 2015 the group compromised the University of Auckland’s English Language Academy website, posting the Islamic pride message and an Arabic phrase, leaving an “under maintenance” notice for over twelve hours before restoration. The same actors have previously claimed responsibility for defacing an Arkansas school district website and the website of a Quebec community with fewer than two thousand residents, though they mistakenly referred to the latter as “The University of the Australian” in a social‑media post. In each case, investigators reported that no sensitive data were exfiltrated, intrusion methods remained undetermined, and affected organizations relied on backups or temporary shutdowns to restore service. These examples illustrate the group’s recurrent use of defacement as a means to convey ideological content while avoiding more invasive or financially motivated tactics.
Incidents
Attributed incidents are available to members.
2 incidents