Cyber Incident Victim: Channel 9
Date:
Apr 2022
Location:
Israel
Summary
A widespread cyber attack targeted multiple Israeli websites, including Channel 9, the Aviation Authority, and Kan broadcasting corporation, rendering them offline. The Iraqi hacker group ALtahrea Team claimed responsibility for the disruption, identifying themselves as Shiite actors from Iraq and citing retaliation for the assassination of Iranian commander Qasem Soleimani as their motivation.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On April 20, 2022, multiple Israeli websites experienced service disruptions due to a cyber attack claimed by the Iraqi hacker group ALtahrea Team. The attack commenced early Wednesday, targeting several high-profile entities including Channel 9's website, the Israeli Aviation Authority's digital platform, and the Kan public broadcasting corporation's online presence. These websites became inaccessible during the incident, though the specific technical methods used to disrupt services were not disclosed in available reporting. The operational impact manifested as sustained downtime for affected sites, impairing public access to information and services during the attack window. No additional compromised systems or secondary targets beyond the initially affected websites were confirmed in source documentation. The incident represented a geographically motivated offensive against Israeli digital infrastructure, occurring without prior public warnings from the threat actors.

ALtahrea Team publicly attributed the attack to retaliation for the January 2020 assassination of Iranian military commander Qasem Soleimani, establishing clear political motivation for their actions. Open-source identifiers characterized the group as Shiite actors operating from Iraq, though no verifiable organizational structure or member details were provided. The attackers did not claim unauthorized data access or exfiltration beyond causing service disruptions through apparent denial-of-service techniques or website defacements. No Israeli government or private-sector response actions, mitigation measures, or recovery timelines were documented in available incident reporting. The attack's primary verifiable consequence remained temporary website unavailability for the targeted entities, with no corroborated evidence of lasting infrastructure damage or data compromise disclosed through public channels.
