CSIDB logo
Incident

Armenian Embassies

Incident posture

Attack window
Dec 2016
Location
Armenia
Status
Historical
CIA posture
Available to members
Updated
2026-01-14 17:23

Linked entities

Victim
Armenian Embassies
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Dec 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacker known as Cryptolulz compromised the website of the Russian embassy in Armenia by exploiting a blind SQL injection vulnerability, gaining unauthorized access to its database. The attacker exfiltrated and publicly leaked administrative credentials, including emails, login details, and IP addresses from the user table, while deliberately withholding potentially sensitive member records. Cryptolulz claimed the intrusion aimed to expose inadequate security practices after unsuccessful attempts to alert the site's administrators. The hacker, who described their activities as politically motivated, previously targeted government entities and financial institutions, and subsequently joined the Fallensec hacking group following this incident.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On December 14, 2016, the website of the Russian embassy in Armenia (www.embassyru.am) was compromised by the hacker known as Cryptolulz, a former member of the Powerful Greek Army hacking group. The attacker exploited a blind SQL injection vulnerability to gain unauthorized access to the site’s backend database. Cryptolulz publicly disclosed the breach via Twitter, stating he had successfully penetrated the site and taken control of its database. Prior to the attack, he claimed to have attempted contact with the website administrators by email to report security concerns but received no response. After this lack of engagement, he proceeded to extract and leak a portion of the database to demonstrate the vulnerability. The compromised database, identified as a0014414_embassy, contained 36 tables, though Cryptolulz selectively leaked only the “user” table to avoid exposing potentially classified member records.

The leaked user credentials included administrative and editorial staff accounts, with data fields encompassing user IDs, names, roles, email addresses, login credentials, passwords, last visit IP addresses, last visit dates, and profile creation dates. Cryptolulz published this information on Pastebin, framing the action as an effort to raise awareness about inadequate security practices, stating authorities “don’t care much about security.” The hacker described his motivations as politically driven, consistent with his history of targeting government entities, including prior breaches of Mexican telecommunications websites and coordinated DDoS attacks against government and banking sites. At the time of the embassy breach, Cryptolulz announced his affiliation with a new hacking collective called Fallensec. No statements from embassy officials or remediation actions were documented in the source material following the disclosure.

Sources

Sources available to members: 1 source.

CSIDB