Menu
Browse

Cyber Incident Victim: Islamabad

Date:

Mar 2023

Location:

Pakistan

Summary

The Supreme Court of Pakistan's official website was compromised by unidentified attackers who defaced it with a promotional message before government IT specialists restored functionality; post-recovery, a COVID-19 advisory was published despite minimal active cases in the region. While restoration occurred promptly, the extent of data exfiltration and precise disruption duration remain unconfirmed, marking another significant cybersecurity incident following a recent breach at a major online retailer where attackers accessed test data via a compromised developer device.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 28, 2023, the official website of Pakistan’s Supreme Court experienced a cyber attack that temporarily disrupted its operations. Attackers of unidentified origin compromised the website in the morning hours, replacing its normal content with a message stating “our spring sale has started.” The defacement quickly drew public attention, with social media users disseminating screenshots of the altered site. Government IT specialists intervened promptly, restoring the website’s functionality after a brief period of disruption. Following recovery, the website displayed a COVID-19 advisory urging only essential visitors to attend the court premises, despite minimal active cases in Islamabad at the time. The attack’s duration prior to restoration and whether any data was exfiltrated remained unconfirmed. No group claimed responsibility, and the attackers’ methods were not disclosed.

Cyber Incident Image

This incident followed a separate breach earlier in March targeting Pakistani e-commerce platform Naheed, where hackers accessed and leaked user data on the dark web. In that case, attackers exfiltrated approximately 23,000 user records and 108 order details containing personally identifiable information and payment data. Naheed attributed the breach to a developer’s compromised laptop via phishing, emphasizing only non-critical test data from a staging server was affected. The Supreme Court website restoration demonstrated government capacity to address visible defacement swiftly, though technical investigations into both incidents yielded no public findings regarding intrusion vectors, persistent threats, or systemic vulnerabilities. The attacks collectively underscored recurring cybersecurity challenges for Pakistani digital infrastructure without establishing a confirmed operational link between them.

Sources
Sources available to members
1 source