CSIDB logo
Incident

Statistical Centre of Iran

Incident posture

Attack window
May 2016
Location
Iran
Status
Historical
CIA posture
Available to members
Updated
2025-12-10 00:00

Linked entities

Victim
Statistical Centre of Iran
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A government website in Iran, the Statistical Centre, experienced a cyberattack that temporarily disrupted its services. Iranian cyber police attributed the breach to hackers operating from Saudi Arabia and two other Arab countries, dismissing initial speculation of ISIS involvement and linking it instead to a previously identified individual. Authorities reported no compromise of sensitive or classified data, characterizing the attack as superficial and primarily demonstrative, intended to fulfill prior Saudi threats. Iran submitted technical evidence, including IP addresses, to Saudi Arabia via Interpol for legal action and announced plans to conduct specialized cyber defense exercises to bolster its security capabilities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 24, 2016, hackers targeted Iran’s Statistical Centre, temporarily disrupting its website and rendering it out of service. Iran’s cyber police, led by General Kamal Hadianfar, monitored the attack and traced the originating IP addresses to three Arab countries, with Saudi Arabia identified as the primary source. The attackers employed deceptive techniques to breach the center’s systems, though Hadianfar downplayed the technical sophistication of the intrusion. Iranian authorities compiled a detailed report documenting the hackers’ IP addresses and physical locations, which they submitted to Saudi Arabia through Interpol to facilitate legal action against the perpetrators. Initial reports on May 25 speculated about possible involvement by ISIS, but Hadianfar explicitly rejected this, stating the hacker had a prior record and had been identified by Iran’s Cyber Police (FATA).

The attack did not compromise sensitive or classified information, according to Brigadier General Gholam Reza Jalali, head of Iran’s Civil Defence Organization. He characterized the breach as superficial, limited to the "first layer" of defenses, and stated it caused no significant damage. Jalali interpreted the incident as an attempt by Saudi Arabia to demonstrate cyber capabilities rather than inflict substantive harm, aligning it with prior Saudi threats. In response, Iran announced plans to conduct specialized cyber defense war games in subsequent months to strengthen its resilience against future attacks. The Statistical Centre resumed normal operations after temporary disruptions, with no evidence of data exfiltration or persistent network compromise. Iranian officials framed the event as a manageable intrusion while emphasizing proactive measures to deter similar incidents.

Sources

Sources available to members: 1 source.

CSIDB