CSIDB logo
Incident

National Security Service of Armenia

Incident posture

Attack window
Apr 2016
Location
Armenia
Status
Historical
CIA posture
Available to members
Updated
2025-12-11 00:00

Linked entities

Victim
National Security Service of Armenia
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Apr 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Turkish hacker group known as Turk Hack Team launched cyber attacks against Armenian government and financial institutions, including the National Security Service, in solidarity with Azerbaijan amid heightened tensions over the Nagorno-Karabakh conflict. The attackers claimed responsibility for disrupting access to multiple critical sites, leveraging DDoS capabilities previously demonstrated against other targets. This offensive followed retaliatory actions by Armenian hackers from the Monte Melkonian Cyber Army, who had targeted Azerbaijani government servers through defacements and data leaks. Both sides engaged in disruptive operations, with the Turkish group explicitly framing their attacks as a protest against Armenia's military actions in the disputed region.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early April 2016, amid escalating hostilities between Armenia and Azerbaijan over the disputed Nagorno-Karabakh region, the Turk Hack Team (THT) launched coordinated cyber attacks against Armenian government infrastructure. This offensive followed physical clashes that resulted in at least 30 military fatalities, with THT explicitly declaring solidarity with Azerbaijan through a Pastebin statement. The group targeted multiple critical Armenian institutions, including the National Security Service of Armenia, National Bank of Armenia, Ministry of Energy and Economy, and the central government portal. THT employed distributed denial-of-service (DDoS) attacks as their primary tactic, successfully disrupting access to these entities' online services. Their actions were framed as retaliation against Armenia's position in the territorial dispute and as a direct response to prior cyber operations conducted by the Armenian hacker group Monte Melkonian Cyber Army (MMCA), which had compromised Azerbaijani government servers the previous day.

The attacks caused significant service disruptions across Armenia's governmental digital infrastructure, though specific technical details regarding downtime duration or data compromise were not disclosed in available records. THT's statement emphasized their success in "closing all access" to targeted sites, indicating widespread availability impacts. MMCA, known for previous data leaks and defacements against Azerbaijani targets, did not publicly document countermeasures during this specific incident phase. The cyber operations occurred alongside ongoing kinetic hostilities, with both nations attributing blame for the physical conflict while hacker groups pursued parallel digital engagements. No official remediation actions or technical responses from Armenian authorities were detailed in source materials, though the incident highlighted the growing role of non-state hacker collectives in geopolitical conflicts.

Sources

Sources available to members: 1 source.

CSIDB