CSIDB logo
Incident

Daba

Incident posture

Attack window
Aug 2016
Location
Iran
Status
Historical
CIA posture
Available to members
Updated
2026-01-31 11:13

Linked entities

Victim
Daba
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Aug 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An Iranian internet service provider was compromised by a pro-Israeli hacker using the alias Zurael_sTz, resulting in the exposure of sensitive customer data including email addresses, usernames, hashed passwords, bank account numbers, and administrator credentials. The attacker leaked three files containing partial information from the breach, initially claiming 52,000 affected users though analysis confirmed 342 email accounts and 2,960 compromised user records with financial and personal details. This intrusion followed the hacker's pattern of targeting Middle Eastern entities and occurred amid ongoing regional cyber conflicts, mirroring historical tensions between Israeli and Palestinian-affiliated hacking groups. The compromised data was verified as authentic through third-party validation.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 2, 2016, Iranian internet service provider Daba suffered a breach of its Parsiva.daba.co.ir domain by an Israeli hacker using the alias Zurael_sTz. The attacker publicly leaked three data files containing customer and administrative credentials via Twitter, claiming to possess information for 52,000 users. Initial analysis by cybersecurity platform Hacked-DB confirmed the authenticity of the leaked data but identified a smaller subset than advertised – 342 email accounts and 2,960 usernames with associated sensitive information. The compromised records included hashed passwords (MD5 algorithm), bank account numbers, email addresses, telephone numbers, mobile addresses, and administrator account credentials. The hacker's social media activity suggested additional data might be released subsequently. Zurael_sTz had previously targeted websites in Palestine, Egypt, and Jordan, establishing a pattern of regional cyber operations aligned with pro-Israeli interests.

The breach exposed critical vulnerabilities in Daba's infrastructure, particularly concerning given its role as a provider of dial-up services, ADSL communications, internet cards, and voice services to Iranian customers. Compromised administrator credentials heightened risks of secondary attacks or system manipulation. Iranian users faced direct threats of financial fraud and identity theft due to the banking information disclosure, compounding existing privacy concerns following a separate incident involving Telegram user data leaks the previous month. The attack reflected ongoing cyber hostilities between Israeli and opposing hacker collectives, exemplified by historical actions like the 2012 IDF hacking team's retaliatory takedowns of Saudi and UAE stock exchange websites following attacks on Israeli financial and aviation targets. No public statements from Daba regarding containment measures or system restoration were documented in available sources at the time of reporting.

Sources

Sources available to members: 1 source.

CSIDB