CSIDB logo
Incident

9 канал

Incident posture

Attack window
Apr 2022
Location
Israel
Status
Historical
CIA posture
Available to members
Updated
2026-01-28 08:12

Linked entities

Victim
9 канал
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Apr 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The website experienced a temporary disruption due to a DDoS attack by Iraqi Shiite hackers, who targeted it alongside other Israeli platforms. The attackers cited retaliation for Qasem Soleimani's death, identifying the site as symbolic of Israeli media despite its lack of direct involvement in the military operation. Service was restored by the hosting provider after a brief outage, though the attack persisted at the time of reporting. This incident follows a previous unsuccessful hacking attempt by Turkish actors during an earlier Israeli military conflict.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the night of April 20, 2022, the Israeli news website 9tv.co.il experienced a temporary outage due to a distributed denial-of-service (DDoS) attack conducted by Iraqi Shiite hackers. The attackers targeted multiple Israeli websites, flooding 9tv.co.il's servers with excessive requests to overwhelm system capacity and force downtime. This coordinated electronic assault commenced around 1 AM local time, deliberately timed to coincide with the anniversary of Qasem Soleimani's death—an Iranian Quds Force commander killed by U.S. forces in 2020. The hackers publicly claimed responsibility, explicitly identifying 9tv.co.il as a symbolic target representing Israeli media influence. While the website had reported on Soleimani's elimination, it had no operational connection to the event. Service was restored within hours after the hosting provider implemented countermeasures, though intermittent DDoS attempts persisted. The attack disrupted reader access to the outlet’s Middle East coverage but did not compromise data integrity or internal systems.

This incident marked the second major cyber assault against 9tv.co.il within a year. During Israel’s 2021 "Guardian of the Walls" military operation, Turkish hackers unsuccessfully attempted to breach the site. The repeated targeting reflects the platform’s perceived significance among anti-Israel groups as a representative voice in regional information warfare. No data theft, defacement, or persistent network infiltration occurred during either event. Hosting infrastructure resilience limited operational downtime during the 2022 DDoS, enabling continuous content delivery despite adversarial efforts to silence the outlet. Attack methodology remained consistent with volumetric DDoS tactics rather than advanced persistent threats, focusing on disruption over data exfiltration.

Sources

Sources available to members: 1 source.

CSIDB