CSIDB logo
Incident

National Security Service of Armenia

Incident posture

Attack window
Sep 2016
Location
Armenia
Status
Historical
CIA posture
Available to members
Updated
2025-12-09 00:00

Linked entities

Victim
National Security Service of Armenia
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Azerbaijani hacktivists known as the Anti-Armenia Team breached Armenian government systems, leaking sensitive documents including foreign visitors' passport details and internal analytical reports from the National Security Service. Security experts confirmed the legitimacy of the compromised data but suggested the breach likely originated from a compromised employee with system access rather than a direct cyberattack as claimed by the group. The incident reflects ongoing tensions between the neighboring countries, historically rooted in territorial disputes over Nagorno-Karabakh.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around September 2, 2016, Azerbaijani hacktivists operating under the name "Anti-Armenia Team" publicly claimed responsibility for breaching Armenian government systems and leaking sensitive documents. The group asserted they had infiltrated servers belonging to Armenia’s National Security Service (SNS), exfiltrating multiple categories of confidential data. Leaked materials included passport details and scanned copies of foreign visitors’ travel documents, which originated from internal SNS resources used to update visitor information. Additionally, internal analytical reports prepared by the security service for government use were compromised and disseminated. The hacktivists described themselves as an independent collective active for five years, emphasizing their history of conducting cyber operations against Armenian targets.

Independent security intelligence experts verified the authenticity of the leaked passport data and internal documents, confirming the breach occurred. However, a cybersecurity expert consulted during the investigation challenged the hacktivists’ claims of a direct system compromise, suggesting instead that an SNS employee with access to the passport control systems might have been compromised. This assessment pointed to potential insider involvement or credential theft as the source of the data, noting the technical border control service’s integration within the SNS as a plausible vector. The incident occurred against a backdrop of prolonged tensions between Armenia and Azerbaijan, including military clashes earlier that year over the disputed Nagorno-Karabakh region, which had resulted in hundreds of casualties. No official statements from Armenian authorities regarding containment measures or technical responses were documented in available sources following the leak.

Sources

Sources available to members: 1 source.

CSIDB