Menu
Browse

Cyber Threat Actor: Middle East Cyber Army

Aliases: 2 aliases
Actor Type Location Known Incidents
 Icon
Activist
New Zealand
2 incidents
Profile

The threatactor known as the Middle East Cyber Army, also abbreviated as MECA, has been publicly linked to New Zealand based on available reporting. The group uses the alias Middle East Cyber Army in its communications and has claimed responsibility for several website defacements. No formal affiliation with a state or criminal consortium has been established in open sources.

MECA’s activities have consistently involved the defacement of low‑profile websites across multiple sectors and regions, including government agencies in the United States, educational institutions in New Zealand, arts organizations, school districts and small municipal sites in Canada. The group’s public statements during these incidents have emphasized ideological messaging, such as declaring “WE ARE MUSLIMS AND WE ARE PROUD!!!” and displaying Arabic phrases affirming Islamic faith, while asserting that no sensitive data was compromised. These actions indicate a focus on disruption and symbolic messaging rather than financial gain or espionage.

The actor’s observed tactics, techniques and procedures are limited to website defacement; no malware families or specific tooling have been referenced in the sources. Initial access vectors remain undetermined for the incidents described, and the group has relied on exploiting third‑party hosting environments to replace site content with warfare imagery or ideological messages. Representative operations include the June 2015 defacement of the Arizona Department of Weights and Measures website, the May 2015 compromise of the University of Auckland’s English Language Academy site, and earlier attacks on a Scottsdale arts organization, an Arkansas school district website and a Quebec community site with a population under two thousand. These examples illustrate MECA’s pattern of targeting accessible, low‑traffic online presences to achieve visibility through disruption.

Incidents
Attributed incidents available to members
2 incidents
Sources
Sources available to members
2 sources