CSIDB logo
Incident

Ministry of Energy of Iran

Incident posture

Attack window
Jan 2016
Location
Iran
Status
Historical
CIA posture
Available to members
Updated
2026-01-12 22:39

Linked entities

Victim
Ministry of Energy of Iran
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Turkish hacker group known as Turk Hack Team conducted distributed denial-of-service (DDoS) attacks and website defacements against Iranian government entities, including the Ministry of Energy, as part of a broader campaign targeting nations opposing Turkish policies. The attacks disrupted online services and displayed politically motivated messages criticizing foreign leadership, alongside claims of compromising over 2,000 websites. While Iranian ministries faced operational disruptions through DDoS assaults, the group separately leaked personal data from Russian citizens obtained from e-commerce platforms, though no similar data theft was explicitly confirmed for the Iranian targets. The incidents were framed as retaliation against perceived adversarial stances toward Turkey’s government.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

3 techniques

Description

The Turk Hack Team (THT), a Turkish hacker group, initiated a series of cyber attacks against Iranian and Russian entities between December 2015 and January 2016. On December 25, 2015, THT defaced over 2,000 Russian and Iranian websites, including government platforms, displaying anti-Putin messages accusing the Russian president of treachery and warning of future consequences. The defacement campaign coincided with heightened geopolitical tensions following Turkey's downing of a Russian fighter jet near the Syrian border in November 2015. One day later, on December 26, THT escalated operations under "OpRussia" by leaking personal data of hundreds of Russian citizens on Pastebin. The stolen records included names, cities, phone numbers, email addresses, and encrypted passwords allegedly harvested from Russian online shopping platforms, accompanied by threats of continued attacks against commercial entities.

On January 2, 2016, THT shifted tactics to large-scale distributed denial-of-service (DDoS) attacks targeting critical infrastructure websites in both nations. Russian victims included the Ministry of the Russian Far East Development, Ministry of Construction, State Atomic Energy Corporation ROSATOM, and Ministry of Customs. Iranian government systems compromised in this phase included the Ministry of Energy, Ministry of Information, Ministry of Foreign Affairs, and the official website of Iran's President. The attacks caused confirmed downtime across multiple high-profile domains, though specific technical details regarding attack duration or mitigation efforts were not disclosed. THT publicly claimed responsibility for these operations through social media channels, framing them as retaliation against perceived adversaries of Turkish national interests. No subsequent data breaches or system compromises beyond the initial DDoS disruptions and prior data leaks were documented in the available reporting.

Sources

Sources available to members: 1 source.

CSIDB