Iran unit behind Charlie Hebdo hack-and-leak op
Share and Follow

After the French satirical magazine Charlie Hebdo launched a cartoon contest to mock Iran’s ruling cleric, a state-backed Iranian cyber unit struck back with a hack-and-leak campaign that was designed to provoke fear with the claimed pilfering of a big subscriber database, Microsoft security researchers say.
The FBI blames the same Iranian cyber operators, Emennet Pasargad, for an influence operation that sought to interfere in the 2020 US presidential election, the tech giant said in a blog published Friday.

Iran has in recent years stepped up false-flag cyber operations as a tool for discrediting foes.

A special edition of the satirical newspaper Charlie Hebdo that marks one year after, "1 an apres" the attacks on it, on a newsstand Wednesday, Jan. 6, 2016 at a train station in Paris.
After the French satirical magazine Charlie Hebdo launched a cartoon contest to mock Iran’s ruling cleric, a state-backed Iranian cyber unit struck back with a hack-and-leak campaign (AP)
Calling itself Holy Souls and posing as hacktivists, the group claimed in early January to have obtained personal information on 200,000 subscribers and Charlie Hebdo merchandise buyers, according to Microsoft’s Digital Threat Analysis Center.

As proof of the data theft, Holy Souls released a 200-record sample with names, phone numbers and home and email addresses of Charlie Hebdo subscribers that “could put the magazine’s subscribers at risk for online or physical targeting” by extremists.

The group then advertised the supposed complete data cache on several dark web sites for $US340,000 ($489,000).

Microsoft said it did not know whether anyone purchased the cache.

A representative for Charlie Hebdo said Friday that the newspaper would not comment on the Microsoft research. Iran’s mission to the United Nations did not immediately respond to a request for comment Friday.
Iranian demonstrators set fire to French flags during their gathering to protest against the publication of offensive caricatures of the Iranian Supreme Leader Ayatollah Ali Khamenei in the French satirical magazine Charlie Hebdo, in front of the French Embassy in Tehran, Iran, Sunday, Jan. 8, 2023.
Iranian demonstrators set fire to French flags during their gathering to protest against the publication of offensive caricatures of the Iranian Supreme Leader Ayatollah Ali Khamenei in the French satirical magazine Charlie Hebdo, in front of the French Embassy in Tehran, Iran, Sunday, Jan. 8, 2023. (AP)

The January 4 sample release coincided with the publication of Charlie Hebdo’s cartoon contest issue. Entrants were asked to draw offensive caricatures of Iran’s supreme leader, Ayatollah Ali Khamenei.

The French newspaper Le Monde verified multiple victims of the leak from the sample, Microsoft said. The Iranian cyber operators sought to boost news of the hack-and-leak operation — and fuel outrage at the cartoon edition — through fake French “sock-puppet” accounts on social media platforms that included Twitter, Microsoft said.

The operation coincided with verbal attacks by Tehran condemning Charlie Hebdo’s “insult.”

The provocatively irreverent magazine has a long history of publishing vulgar cartoons which critics consider deeply insulting to Muslims. Two French-born al-Qaida extremists attacked the newspaper’s office in 2015, killing 12 cartoonists, and it Charlie Hebdo has been the target of other attacks over the years.

The magazine billed the Khamenei caricature contest as a show of support for nationwide antigovernment protests that have convulsed Iran since the mid-September death of Mahsa Amini, a 22-year-old woman detained by Iran’s morality police for allegedly violating the country’s strict Islamic dress code.

Heavily-armed French police patrol in Longpont, north of Paris during the hunt for the Charlie Hedbo gunmen, (AAP)
Heavily-armed French police patrol in Longpont, north of Paris during the hunt for the Charlie Hedbo gunmen, (AAP) (AAP)

After the cartoon issue was published, Iran shut down a decades-old French research institute. Last week, it announced sanctions targeting more than 30 European individuals and entities, including three senior Charlie Hebdo staffers. The sanctions are largely symbolic as they bar travel to Iran and allow its authorities to block bank accounts and confiscate property in Iran.

According to the FBI, Emennet Pasargad authored what amounted to a relatively ham-fisted campaign to interfere with the 2020 US presidential election. The group obtained confidential US voter information from at least one state election website and sent threatening email messages to intimidate voters posing as the far-right group Proud Boys, the FBI says.

Emennet Pasargad has also, since 2018, conducted cyber-operations targeting news, shipping, airlines, oil and petrochemical, financial, and telecommunications, in the US, Europe, and the Middle East, the FBI says. The US newspaper chain Lee Enterprises was among the suspected targets, according to the Council on Foreign Relations.

The group’s attacks since 2020 have primarily targeted Israel, the FBI says. They follow a pattern of intrusion, theft, data leak and then amplification through social media and online forums. In some cases destructive malware has been used.

Sign up here to receive our daily newsletters and breaking news alerts, sent straight to your inbox.
Share and Follow
You May Also Like
Bloodied horses run through London in rush hour chaos

Chaos in London as bloodied horses run during rush hour

Five military horses bolted during routine exercises near King Charles III’s main…
Elon Musk to test takedown power of Australia's internet cop

Elon Musk will test the strength of Australia’s internet regulator with a takedown trial

Billionaire Elon Musk’s escalating battle with Australia’s eSafety Commissioner and how far…

Initial Communication: The Gweagal Spears are Given Back to the Community

Four of the surviving Gweagal spears taken by James Cook and Joseph…
'Hundreds of times stronger than heroin': Severe overdoses trigger warnings in NSW

Warning Issued in NSW Due to Extremely Potent Overdoses

A warning has been issued after a series of severe opioid overdoses…
Four Aboriginal spears that were brought to England by Captain James Cook more than 250 years ago and have now been repatriated to Australia in a ceremony at Trinity College in Cambridge, Tuesday April 23, 2024.

Indigenous Australians Reclaim Aboriginal Spears Taken by Captain Cook in 1770

The artifacts were all that remain of some 40 spears that Cook…

The Meaning of Kokoda to Australians: Bravery, Friendship, and Selflessness

Each year, on 25 April, soldiers from Australia and New Zealand, acknowledging…
Adelaide House Fire

Devastating fire leaves Adelaide family homeless

An Adelaide family has lost its home after a devastating fire that…

Hours for Anzac Day trading in 2024: Find out what is open and when

On 25 April every year, Australia marks Anzac Day with a public…