Menu
Browse

Cyber Incident Victim: Google

Date:

Jan 2017

Location:

Brazil

Summary

Google Brazil's domain experienced a DNS hijacking attack by a hacker using the alias "Kuroi’SH," resulting in a defaced homepage displaying a message claiming responsibility and referencing additional compromises of Google Paraguay, though the latter lacked confirmation. The disruption lasted approximately 30 minutes before the company took the affected services offline, with unverified reports suggesting Google Maps and Translate Brazil domains were also targeted. The attacker stated the breach aimed to demonstrate universal vulnerability and highlight security shortcomings, while Google acknowledged the incident publicly without elaborating on causes. The individual had previously defaced NASA subdomains to promote political messages.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On January 3, 2017, a hacker using the alias "Kuroi’SH" compromised Google Brazil’s primary domain (google.com.br) through DNS hijacking, rendering it inaccessible to Brazilian users. The attacker replaced the legitimate website with a defacement page containing a message claiming responsibility and taunting other hackers, specifically mentioning "Nofawkx" while dedicating the attack to associates "Prosox & Shinobi h4xor." The defaced site remained publicly visible for approximately 30 minutes before Google administrators took it offline. Unverified reports suggested concurrent breaches of Google Maps and Google Translate Brazil subdomains, though these claims lacked independent confirmation. Google acknowledged the incident via Twitter but did not disclose technical details or root causes during initial response efforts. Restoration attempts encountered difficulties, as the domain remained unavailable for an unspecified period after takedown.

Cyber Incident Image

The attack disrupted access to Google’s core services for Brazilian users during the outage window. Kuroi’SH later confirmed targeting Google Paraguay’s domain simultaneously but stated insufficient time to complete its defacement. When questioned by media outlet Hack Read, the hacker asserted the breach aimed to demonstrate universal vulnerability of online systems and highlight underestimated security risks. Historical context revealed Kuroi’SH had previously defaced NASA subdomains in 2015 to display pro-Palestinian messages. No evidence suggested data theft or secondary exploitation beyond the DNS hijacking and defacement. Google’s public communications remained limited to incident acknowledgment without subsequent elaboration on remediation steps or forensic findings.

Sources
Sources available to members
1 source