Menu
Browse

Cyber Incident Victim: Islamic State

Date:

Aug 2016

Location:

Israel

Summary

A cybersecurity firm hacked an ISIS-affiliated forum hosted on Telegram, uncovering plans for imminent terrorist attacks targeting US military installations in Kuwait, Bahrain, and Saudi Arabia, selected due to their role in coalition airstrikes against the group. The compromised forum also contained maps identifying Israeli military bases. Intelligence indicated preparations for assaults using knives, mirroring a prior lethal incident at a French church. This intrusion followed a pattern of hacktivist operations against ISIS communication channels, though the firm leveraged specialized expertise to access encrypted content and extract actionable threat data regarding planned operations against international military assets.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

In early August 2016, Israeli cyber-intelligence firm Intsights disclosed it had infiltrated an ISIS-operated Dark Web forum hosted on the Telegram messaging service. The company, staffed by former Israel Defense Forces intelligence officers, reported uncovering evidence of planned terrorist attacks targeting US military installations. Forum participants shared a map identifying US bases in Kuwait, Bahrain, and Saudi Arabia selected for attacks, with these locations chosen due to their role in supporting coalition airstrikes against ISIS positions in Syria and Iraq. The same map, circulated on August 1, 2016, also included coordinates of Israeli military facilities. Intsights linked these plans to ISIS's operational history, referencing the July 26, 2016 attack in Saint-Étienne-du-Rouvray, France, where assailants murdered an 85-year-old priest. While the firm provided no technical details regarding its access methods, it alerted Israeli media outlet Channel 10 about the compromised forum's contents, which contained attack planning materials and operational discussions among ISIS members.

Cyber Incident Image

This intrusion occurred amid broader efforts by cybersecurity researchers and hacktivist groups to disrupt ISIS online activities. Entities like Anonymous had previously hacked ISIS forums with limited media coverage, though Intsights' military-specific findings garnered significant attention. The disclosure coincided with separate Black Hat security conference presentations detailing Telegram vulnerabilities, including an Iranian espionage operation that harvested data from 15 million Telegram profiles. Intsights did not specify whether its access exploited similar technical weaknesses or relied on alternative methods. The company's actions provided intelligence regarding imminent threats to military assets but did not include details about subsequent law enforcement or military responses to the uncovered plots.

Sources
Sources available to members
1 source