Cyber Incident Victim: City of Clarkston, GA
Date:
Sep 2014
Location:
United States of America
Summary
The City of Clarkston, GA experienced a website defacement by Iranian hacking group Ashiyane Digital Security Team, who replaced content with a pro-Iran message. The attackers claimed responsibility under the alias Shadow_Walker58, though no specific motive was provided. This incident mirrored prior attacks by the same group against other U.S. municipal websites, with the compromised site remaining inaccessible and under unauthorized control at the time of reporting.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 2 actors | Available to members | Available to members |
Description
On September 15, 2014, the official website of the City of Clarkston, Georgia, was compromised by the Iranian hacking group Ashiyane Digital Security Team. Attackers replaced the site’s content with a defacement page displaying the message: “We love Iran. Hacked by Ashiyane Digital Security! Shadow_Walker58 was here.” The defacement did not specify any motive for targeting Clarkston’s government site. Evidence indicated the website remained under the attackers’ control at the time of reporting, rendering it inaccessible to legitimate users. The group’s signature tactics aligned with previous incidents, including defacements of Oregon municipal websites in Amity and Sutherlin. No immediate details were confirmed regarding data exfiltration or deeper network infiltration beyond the website compromise.

The incident disrupted public access to Clarkston’s official online services, with the site remaining non-operational during the initial reporting period. Ashiyane Digital Security Team’s history of targeting U.S. local government infrastructure suggested a pattern of opportunistic attacks rather than focused campaigns against specific targets. Municipal websites often serve as low-security entry points for hacktivist groups seeking visibility. The defacement’s geopolitical messaging highlighted the incident’s symbolic nature, though no explicit threats or political demands accompanied the intrusion. Forensic analysis to determine the attack vector or potential data exposure was not publicly disclosed in available reports. Recovery timelines and remediation steps undertaken by Clarkston authorities were not detailed in immediate coverage of the breach.
