Cyber Incident Victim: 9 канал
Date:
Apr 2022
Location:
Israel
Summary
The website experienced a temporary disruption due to a DDoS attack by Iraqi Shiite hackers, who targeted it alongside other Israeli platforms. The attackers cited retaliation for Qasem Soleimani's death, identifying the site as symbolic of Israeli media despite its lack of direct involvement in the military operation. Service was restored by the hosting provider after a brief outage, though the attack persisted at the time of reporting. This incident follows a previous unsuccessful hacking attempt by Turkish actors during an earlier Israeli military conflict.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On the night of April 20, 2022, the Israeli news website 9tv.co.il experienced a temporary outage due to a distributed denial-of-service (DDoS) attack conducted by Iraqi Shiite hackers. The attackers targeted multiple Israeli websites, flooding 9tv.co.il's servers with excessive requests to overwhelm system capacity and force downtime. This coordinated electronic assault commenced around 1 AM local time, deliberately timed to coincide with the anniversary of Qasem Soleimani's death—an Iranian Quds Force commander killed by U.S. forces in 2020. The hackers publicly claimed responsibility, explicitly identifying 9tv.co.il as a symbolic target representing Israeli media influence. While the website had reported on Soleimani's elimination, it had no operational connection to the event. Service was restored within hours after the hosting provider implemented countermeasures, though intermittent DDoS attempts persisted. The attack disrupted reader access to the outlet’s Middle East coverage but did not compromise data integrity or internal systems.

This incident marked the second major cyber assault against 9tv.co.il within a year. During Israel’s 2021 "Guardian of the Walls" military operation, Turkish hackers unsuccessfully attempted to breach the site. The repeated targeting reflects the platform’s perceived significance among anti-Israel groups as a representative voice in regional information warfare. No data theft, defacement, or persistent network infiltration occurred during either event. Hosting infrastructure resilience limited operational downtime during the 2022 DDoS, enabling continuous content delivery despite adversarial efforts to silence the outlet. Attack methodology remained consistent with volumetric DDoS tactics rather than advanced persistent threats, focusing on disruption over data exfiltration.
