CSIDB logo
Incident

Israel Airports Authority

Incident posture

Attack window
Apr 2022
Location
Israel
Status
Historical
CIA posture
Available to members
Updated
2025-10-19 00:00

Linked entities

Victim
Israel Airports Authority
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Apr 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A pro-Iran hacking group named Altahrea Team targeted the Israel Airports Authority's website, claiming retaliation for the killings of Iranian and Iraqi military figures. Concurrently, hacktivist group DoomSec announced compromising the official Israeli government portal and listed additional affected Israeli sites before removing the post, though their broader activities include past collaborations unrelated to Iranian interests. The incidents involved disruptive actions against multiple Israeli digital assets, with differing stated motivations between the groups.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 20, 2022, Israeli media reported that a pro-Iranian hacking group known as Altahrea Team targeted the website of the Israel Airports Authority (רשות שדות התעופה בישראל). The group claimed its attack was retaliation for the January 3, 2020, U.S. assassination of Iranian Quds Force commander Qassem Soleimani and Abu Mahdi Al-Muhandes, commander of Iraq’s pro-Iranian Popular Mobilization Forces. The incident was first disclosed by Maariv and subsequently covered by JNS. Concurrently, a separate hacktivist group called DoomSec announced an attack on Israel’s official government portal (Gov.il) via their Telegram channel on the morning of April 19. DoomSec’s message included explicit anti-Israel rhetoric and the hashtag #DoomSecWasHere, though they did not explicitly align their actions with Iranian interests.

Later on April 19, DoomSec listed multiple Israeli websites they claimed to have compromised, but this post was subsequently deleted from their Telegram channel. The targeting of the Israel Airports Authority website and Gov.il portal represented a coordinated disruption effort, though no technical details of the attacks (e.g., defacement, data exfiltration, or service downtime) were disclosed in available reports. DoomSec’s historical activities included collaborations with the group AgainstTheWest to leak documents related to advanced persistent threat (APT) groups, indicating a broader focus beyond regional conflicts. The incident highlighted overlapping motivations, with Altahrea Team explicitly linking their actions to Iranian geopolitical grievances, while DoomSec’s involvement appeared ideologically opportunistic. No statements from the Israel Airports Authority or Israeli government regarding incident response, mitigation, or confirmed impacts were reported in the sourced material.

Sources

Sources available to members: 1 source.

CSIDB