Cyber Incident Victim: Azerbaijani Ministry of Labour and Social Protection
Date:
Dec 2015
Location:
Azerbaijan
Summary
Azerbaijan's Ministry of Labour and Social Protection and Ministry of Emergency Situations suffered a data breach by Armenian hacker group Monte Melkonian Cyber Army, which exfiltrated sensitive documents including citizen IDs, passports, family records, resumes, and images. The attackers claimed the intrusion was retaliation for fatal border clashes between Armenian and Azerbaijani forces, maintaining unauthorized server access for over a month before being blocked following data leaks on Facebook. This incident reflects ongoing cyber hostilities between groups from both nations, with the same collective previously compromising Azerbaijan's Central Bank and leaking thousands of citizens' financial and personal records.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On December 19, 2015, Armenian hacker group The Monte Melkonian Cyber Army (MMCA) breached servers belonging to Azerbaijan's Ministry of Labour and Social Protection and Ministry of Emergency Situations. The attackers exfiltrated sensitive documents, images, resumes, family records, national identification cards, and passport numbers belonging to registered citizens. MMCA representatives stated the intrusion was retaliation for fatal border clashes earlier that month involving the deaths of three Azerbaijani soldiers and one Armenian soldier. The group maintained unauthorized access to the compromised systems for over one month prior to public disclosure. Attackers did not disclose the specific vulnerabilities exploited but confirmed their access was terminated when Azerbaijani authorities blocked their IP addresses following the data leak. The stolen records appeared on Facebook pages controlled by MMCA, though the full distribution scope wasn't detailed in available reports.

This incident exposed personally identifiable information of Azerbaijani citizens through unauthorized disclosures on social media platforms. The breach represented an escalation in MMCA's operations, following their July 2015 leak of 5,000 Azerbaijani ID cards and passports and a November 2015 attack on Azerbaijan's Central Bank that compromised customer banking details. Azerbaijani authorities implemented IP blocking measures to terminate the attackers' server access after the data became public. Historical context indicates persistent cyber hostilities between Armenian and Azerbaijani groups, exemplified by Azerbaijani hackers targeting Armenian presidential and ministry websites in June 2014. The Nagorno-Karabakh territorial dispute remains the primary motivator for these cross-border cyber operations, with both nations maintaining no formal diplomatic relations and a technical state of war since the 1990s ceasefire.
