Menu
Browse
Date

Jan 2016

Location

Azerbaijan

Status

Historical

Timeline
Occurred
Jan 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

Armenian hackers from the Monte Melkonian Cyber Army targeted Azerbaijani government portals through DDoS attacks and server breaches, disrupting services including the Ministry of Taxes of the Republic of Azerbaijan and leaking sensitive citizen data. The attackers compromised login credentials and personal information from thousands of individuals, including encrypted passwords, identification documents, and other private records, marking a significant breach of national data security. This incident occurred amid ongoing cyber hostilities linked to the Armenia-Azerbaijan conflict, following reciprocal attacks between hacker groups from both nations.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On January 28, 2016, the Monte Melkonian Cyber Army (MMCA), an Armenian hacker group, executed a coordinated cyber attack against multiple Azerbaijani government digital assets to coincide with Armenian Army Day. The attackers deployed distributed denial-of-service (DDoS) attacks combined with server breaches to disrupt the E-Government Portal (e-gov.az), the Ministry of Taxes of the Republic of Azerbaijan (taxes.gov.az), and the central portal for State Bodies (gov.az), causing significant service outages. Following the initial disruption, MMCA penetrated the server infrastructure of Azerbaijan’s Civil Service Commission (csc.gov.az), an entity operating under the President’s administration, and exfiltrated sensitive citizen data. The compromised information included login credentials—names, email addresses, and encrypted passwords—belonging to 5,960 registered users, which the attackers subsequently leaked online. Analysis confirmed the authenticity of this dataset, which had not previously been exposed publicly. Additionally, MMCA released two CSV files containing broader personal records: one with names, emails, and encrypted passwords for 76,211 citizens, and another containing documents, images, usernames, passwords, and other personal identifiers, amplifying the scale of the breach.

Cyber Incident Image

The incident represented a severe compromise of Azerbaijani citizen data, exposing thousands to potential identity theft and fraud. The attackers explicitly linked their actions to the ongoing Nagorno-Karabakh conflict, reflecting the broader pattern of cyber hostilities between Armenian and Azerbaijani groups. This attack followed a prior offensive by Azerbaijani hackers against Armenian government websites, including embassy portals in 40 countries, underscoring the reciprocal nature of the cyber conflict. No diplomatic relations exist between the two nations, which remain technically at war due to the unresolved territorial dispute. The MMCA’s breach of the Civil Service Commission’s systems marked a significant escalation, as the leaked data included not only credentials but also scanned identification documents and images, intensifying privacy risks for affected individuals. The Azerbaijani government did not publicly detail incident response or containment measures in the immediate aftermath, though the attack’s technical sophistication and geopolitical context highlighted systemic vulnerabilities in state digital infrastructure.

Sources
Sources available to members
1 source