Threats Feed|Haghjoyan|Last Updated 03/07/2026|AuthorCertfa Radar|Publish Date28/12/2023

Haghjoyan Group's Cyber Offensive: Data Leaks, Defacement, and Infrastructure Attacks

  • Actor Motivations: Disinformation,Espionage,Exfiltration,Financial Gain,Sabotage
  • Attack Vectors: Defacement,Malware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Haghjoyan hacker group, self-proclaimed as Iran's cyber army, has emerged during the Israel-Hamas conflict, openly aligning themselves with Iran and diverging from the typical secrecy of cyber warfare groups. Their operations include data leaks and sales, particularly targeting US military personnel's information for Bitcoin. They have conducted website defacement attacks for disruption and propaganda, indicating a geopolitical alignment with Russia. Haghjoyan has claimed responsibility for several significant cyberattacks, such as targeting Israeli Red Alert Emergency Response System, VNC systems controlling Israeli infrastructure, and infecting Israeli computer users with malware. They also targeted surveillance systems, showcasing a strategic approach to cyber warfare.

Detected Targets

TypeDescriptionConfidence
SectorMilitary
Verified
SectorUtilities
Verified
RegionIsrael
Verified
RegionUnited States
High

FAQs

Haghjoyan Cyber Threat Briefing

A cyber warfare group has been conducting a series of digital attacks, data leaks, and website defacements. They have targeted critical infrastructure, emergency systems, and surveillance cameras, while also stealing and selling sensitive information online.

The attacks are carried out by a group calling themselves "Haghjoyan." They openly claim to be the "Iranian cyber army," making their national affiliation public, which is unusual for these types of threat actors.

The group aims to cause widespread disruption and spread political propaganda related to the Israel-Hamas conflict. Alongside their political motives, they also seek financial gain by selling stolen data for cryptocurrency.

The attacks have a significant scale. The group claims to have infected over 5,000 computer users, stolen over 2 terabytes of data, and compromised numerous cameras and critical utility systems.

Yes. The group specifically targeted Israeli critical infrastructure, including water, electricity, and gas systems, as well as the Red Alert emergency system. They also specifically targeted the personal data of U.S. military personnel.

The attackers found poorly protected remote access tools and surveillance cameras connected to the internet and broke into them. Once inside, they installed malicious software to steal data, disrupt services, and change websites to display their political messages.

Systems like emergency alerts and public utilities are critical to national security and public safety. Successfully disrupting these services causes maximum chaos and draws significant attention to the group's political message.

Organizations should ensure that remote access systems and surveillance cameras are not directly exposed to the internet and are protected with strong passwords. Additionally, employing standard security software to detect malicious activity and monitoring for unusual data transfers can help prevent these attacks.

This is a highly targeted issue. The attacks are focused specifically on entities involved in or aligned with certain geopolitical conflicts, primarily focusing on Israeli infrastructure and U.S. military assets.

About Affiliation
Haghjoyan
Haghjoyan is an Iranian-linked hacktivist persona that emerged following the October 2023 Hamas-Israel conflict, conducting defacement and data leak operations against Israeli and Western targets. The group uses Telegram to claim attacks and publish stolen content, following the established Iranian pattern of hacktivist branding to amplify disruption while maintaining deniability. Activity attributed to Haghjoyan largely ceased by late December 2023, suggesting it may have been a short-lived operational persona or merged into broader Iranian hacktivist campaigns.
View Haghjoyan's Insights