CSIDB logo
Incident

Ernakulam Siva Temple

Incident posture

Attack window
Jun 2018
Location
India
Status
Historical
CIA posture
Available to members
Updated
2025-11-29 00:00

Linked entities

Victim
Ernakulam Siva Temple
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The official website of Ernakulam Siva Temple was hacked, displaying anti-national slogans, offensive language, and a Pakistan flag, prompting police to register a case under the IT Act and initiate an investigation with cyber cell assistance. Authorities preserved critical data this time to aid forensic analysis, seeking admin login details to determine if the attack originated abroad or domestically via proxy servers—contrasting with a prior incident where evidence deletion prevented identifying perpetrators responsible for similar defacement. This marked the second known cyberattack compromising the temple’s website.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 28, 2018, authorities confirmed the hacking of the Ernakulam Siva Temple's official website (www.ernakulathapan.com), discovered approximately on June 27-28. The attackers defaced the homepage with anti-national slogans, offensive language, and a Pakistan flag. Kochi City District Police Chief M.P. Dinesh directed the Central police to register a case under the IT Act and initiate an investigation with cyber cell support. Investigators sought administrative login credentials and access logs from temple authorities to determine the attack's origin, noting the IP address indicated foreign involvement but acknowledging potential obfuscation through proxy servers. The cyber cell emphasized the critical need for admin login histories and geographic access data to verify whether the breach originated internationally or domestically via disguised routing.

This marked the second cyberattack against the temple's website, following a November 2016 incident where hackers similarly posted anti-India and pro-Pakistan content. The 2016 investigation failed to identify perpetrators after temple administrators deleted crucial forensic evidence, inadvertently obstructing investigative efforts. During the 2018 incident, temple officials deliberately preserved all compromised data and refrained from unauthorized alterations to avoid repeating prior evidence destruction. No technical details regarding attack vectors, data exfiltration, or system vulnerabilities were disclosed publicly. The incident prompted formal police documentation but yielded no immediate attribution or arrest disclosures from available reports.

Sources

Sources available to members: 1 source.

CSIDB