Cyber Incident Victim: Bangladesh Meteorological Department
Date:
Jul 2024
Location:
Bangladesh
Summary
The Bangladesh Meteorological Department's website was compromised by hackers claiming affiliation with "TE4M UCC INDIAN H4CKERS," resulting in over two hours of downtime. The organization restored access after identifying the breach, with officials investigating potential server damage and working to identify the perpetrators while users faced disrupted service during the outage. A defacement message left by the attackers remained visible until recovery efforts were completed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 2 actors | Available to members | Available to members |
Description
On July 9, 2024, the Bangladesh Meteorological Department (BMD) experienced a cybersecurity incident involving unauthorized access to its official website. The attack commenced at 8:00 AM local time, rendering the site inaccessible to users. During the compromise, hackers defaced the website by displaying the message "HACKED BY ODIYAN911. TE4M UCC INDIAN H4CKERS….." indicating their presence. The disruption persisted for two hours and twenty-seven minutes, during which meteorological data and forecasts remained unavailable to the public and stakeholders. BMD officials detected the intrusion promptly but could not immediately restore services. Monowar Hossain, a meteorologist at BMD, publicly confirmed the breach and subsequent recovery efforts. The department prioritized restoring functionality while initiating preliminary assessments of server integrity.

Technical teams successfully recovered the website at 10:27 AM, concluding the active disruption phase. Post-recovery, BMD authorities launched an investigation to identify the perpetrators and assess potential data or system compromises. Hossain stated no conclusive evidence regarding the attackers' identities or motives had been established at the time of reporting. The incident caused operational interruptions to weather information dissemination, affecting public access during morning hours. No additional details about data exfiltration, malware deployment, or infrastructure damage were disclosed by officials. Recovery efforts focused on service restoration rather than public communications about technical remediation steps. The investigation remained ongoing with no attribution claims or further hacker communications reported following the defacement message removal.
