Cyber Incident Victim: Daba
Date:
Aug 2016
Location:
Iran
Summary
An Iranian internet service provider was compromised by a pro-Israeli hacker using the alias Zurael_sTz, resulting in the exposure of sensitive customer data including email addresses, usernames, hashed passwords, bank account numbers, and administrator credentials. The attacker leaked three files containing partial information from the breach, initially claiming 52,000 affected users though analysis confirmed 342 email accounts and 2,960 compromised user records with financial and personal details. This intrusion followed the hacker's pattern of targeting Middle Eastern entities and occurred amid ongoing regional cyber conflicts, mirroring historical tensions between Israeli and Palestinian-affiliated hacking groups. The compromised data was verified as authentic through third-party validation.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On August 2, 2016, Iranian internet service provider Daba suffered a breach of its Parsiva.daba.co.ir domain by an Israeli hacker using the alias Zurael_sTz. The attacker publicly leaked three data files containing customer and administrative credentials via Twitter, claiming to possess information for 52,000 users. Initial analysis by cybersecurity platform Hacked-DB confirmed the authenticity of the leaked data but identified a smaller subset than advertised – 342 email accounts and 2,960 usernames with associated sensitive information. The compromised records included hashed passwords (MD5 algorithm), bank account numbers, email addresses, telephone numbers, mobile addresses, and administrator account credentials. The hacker's social media activity suggested additional data might be released subsequently. Zurael_sTz had previously targeted websites in Palestine, Egypt, and Jordan, establishing a pattern of regional cyber operations aligned with pro-Israeli interests.

The breach exposed critical vulnerabilities in Daba's infrastructure, particularly concerning given its role as a provider of dial-up services, ADSL communications, internet cards, and voice services to Iranian customers. Compromised administrator credentials heightened risks of secondary attacks or system manipulation. Iranian users faced direct threats of financial fraud and identity theft due to the banking information disclosure, compounding existing privacy concerns following a separate incident involving Telegram user data leaks the previous month. The attack reflected ongoing cyber hostilities between Israeli and opposing hacker collectives, exemplified by historical actions like the 2012 IDF hacking team's retaliatory takedowns of Saudi and UAE stock exchange websites following attacks on Israeli financial and aviation targets. No public statements from Daba regarding containment measures or system restoration were documented in available sources at the time of reporting.
