Cyber Incident Victim: Embassy of India, Bucharest
Date:
Jun 2016
Location:
Romania
Summary
Pakistani hackers using aliases "Romantic" and "Intruder" defaced websites for seven Indian embassies, including the Embassy in Bucharest, along with a separate attack on a Karnataka State Police site by another hacker from Team Pak Cyber Attackers. The attackers claimed affiliation with the Pakistan Army, leaving propaganda messages promoting Pakistan and taunting Indian authorities, accompanied by national symbols. All compromised sites were subsequently restored following investigations. This incident reflects persistent cyber hostilities between Indian and Pakistani threat actors, historically linked to geopolitical tensions between the nations.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 3 actors | Available to members | Available to members |
Description
On June 11, 2016, Pakistani hackers defaced the official website of the Embassy of India in Bucharest, Romania, as part of a coordinated cyberattack targeting seven Indian diplomatic missions globally. The attackers, identifying themselves as "Romantic" and "Intruder," replaced the embassy's website content with a message claiming association with the Pakistan Army. The defacement text included the phrases "Pakistan Army Zindabad," "Pakistan Zindabad," and "Feel The Power of Pakistan," accompanied by taunts directed at the Indian government. This incident occurred concurrently with attacks on Indian embassies in Ankara (Turkey), Athens (Greece), Mexico City (Mexico), São Paulo (Brazil), Dushanbe (Tajikistan), and Pretoria (South Africa), all displaying identical messages. Separately, a hacker named Faisal 1337 from "Team Pak Cyber Attackers" defaced the Karnataka State Police website, replacing its homepage with the Pakistani flag and offensive content. Authorities restored all affected websites to operational status shortly after detection.

The attacks reflected ongoing cyber hostilities between Indian and Pakistani hacking groups, historically linked to geopolitical tensions since the 1947 partition. This specific campaign followed earlier cyber skirmishes, including Indian retaliatory website defacements after the January 2016 Pathankot terrorist attack. While no data theft or persistent malware was reported in the embassy incidents, the defacements disrupted public access to official information and projected symbolic aggression. Investigations were initiated by Indian authorities, though no attribution details beyond the hackers' aliases were disclosed. The incident underscored the persistent use of website vandalism as a low-cost tactic in the India-Pakistan cyber rivalry, mirroring contemporaneous espionage campaigns like Operation Transparent Tribe and BreachRAT malware operations documented earlier in 2016.
