Menu
Browse

Cyber Incident Victim: Armenian Embassies

Date:

Dec 2016

Location:

Armenia

Summary

A hacker known as Cryptolulz compromised the website of the Russian embassy in Armenia by exploiting a blind SQL injection vulnerability, gaining unauthorized access to its database. The attacker exfiltrated and publicly leaked administrative credentials, including emails, login details, and IP addresses from the user table, while deliberately withholding potentially sensitive member records. Cryptolulz claimed the intrusion aimed to expose inadequate security practices after unsuccessful attempts to alert the site's administrators. The hacker, who described their activities as politically motivated, previously targeted government entities and financial institutions, and subsequently joined the Fallensec hacking group following this incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On December 14, 2016, the website of the Russian embassy in Armenia (www.embassyru.am) was compromised by the hacker known as Cryptolulz, a former member of the Powerful Greek Army hacking group. The attacker exploited a blind SQL injection vulnerability to gain unauthorized access to the site’s backend database. Cryptolulz publicly disclosed the breach via Twitter, stating he had successfully penetrated the site and taken control of its database. Prior to the attack, he claimed to have attempted contact with the website administrators by email to report security concerns but received no response. After this lack of engagement, he proceeded to extract and leak a portion of the database to demonstrate the vulnerability. The compromised database, identified as a0014414_embassy, contained 36 tables, though Cryptolulz selectively leaked only the “user” table to avoid exposing potentially classified member records.

Cyber Incident Image

The leaked user credentials included administrative and editorial staff accounts, with data fields encompassing user IDs, names, roles, email addresses, login credentials, passwords, last visit IP addresses, last visit dates, and profile creation dates. Cryptolulz published this information on Pastebin, framing the action as an effort to raise awareness about inadequate security practices, stating authorities “don’t care much about security.” The hacker described his motivations as politically driven, consistent with his history of targeting government entities, including prior breaches of Mexican telecommunications websites and coordinated DDoS attacks against government and banking sites. At the time of the embassy breach, Cryptolulz announced his affiliation with a new hacking collective called Fallensec. No statements from embassy officials or remediation actions were documented in the source material following the disclosure.

Sources
Sources available to members
1 source