Iran Cyber Attacks, Sites in Three Different Countries Identified

Tirana's Court has accepted the request of Prosecution Office for the seizure of the online pages that distributed Albanian sensational data stolen by Iran's Cyber attack.

In this way, the Prosecution of Tirana asks the help of United Kingdom, China and Russia for this decision to be implemented, as the online pages distributing the sensational data are based on these three countries. 

Furthermore, Prosecution announced that both cyber attacks -that of July on e-Albania and that of September on Interior Ministry- are being investigated as the same issue due to the suspicion they have been committed by the same source.

"On 19.07.2022, the Prosecutor's Office of the Judicial District of Tirana registered criminal proceedings No. 5430 for the commission of the criminal offenses "Illegal interception of computer data", "Interference with computer data", "Interference with computer systems", "Misuse of equipment", provided by articles 293/a, 293/b, 293/c, 293/ç, of the Criminal Code. 

The object of the investigation is the cyber attack against the state institution of the National Association of National Archives of Albania, which summarizes all the official government websites in the Republic of Albania. 

Likewise, on 09.09.2022, another cyber attack was carried out on the equipment and systems that are administered and managed by the Ministry of the Interior in Albania. 

These two actions, since they were carried out with the same typology and the cyber attack came from the same source, are being investigated in a single case. In the systems where the attack took place, a profile was identified in two different social networks based outside the territory of the Republic of Albania that belonged to the perpetrators/collaborators of this attack. 

Immediately on 19.07.2022, with the decision of the Prosecutor's Office at the Court of First Instance of Tirana, the sequestration of these accounts in two different social networks was ordered, and as a result of this decision, the relevant companies reacted by closing access to these accounts. 

As a result of the lack of access, the perpetrators of the cyber attack opened another page which was used to distribute various messages related to the attack carried out or the publication of the data that was stolen. In the following days and currently, from this page as well as from accounts from online communication applications such as Telegram, etc., documents of the State Police are being posted which constitute an investigative secret. 

The posting of the data, which is suspected to have been hacked and copied from the cyber attack that took place against the computer systems of the AKSHI as well as the computer systems of the Ministry of the Interior, is carried out by the online site with the name "HomelandJustice" and the link https: //homelandjustice.cx/ as well as from the profile on the social network "Telegram" with the name "JusticeHomeland1" and link https://t.me/JusticeHomeland1." From the investigative actions, it has emerged that these sites have IPs in Hong Kong, Great Britain and Russia. 

As above, the Prosecutor's Office at the Court of First Instance of Tirana, on 04.10.2022, based on Article 208 of the Criminal Code, the Council of Europe Convention "On Mutual Legal Assistance in Criminal Matters" (in the case of Great Britain) articles 509 et seq. of the Code of Criminal Procedure "On letters sent abroad" and Law No. 10193 dated December 03, 2009 "On jurisdictional relations with foreign authorities in the criminal field", in the Convention on Crime in the Field of Cybernetics, ratified by law no. 8888 dated 25.04.2002 and on the principle of reciprocity (in the case of the Russian Federation), requested the Court of First Instance of Tirana: 

1. Seizure of data and computer systems, as well as the prohibition to carry out further actions of publishing the hacked documentation from the computer systems of the AKSHI and the computer systems of the Ministry of the Interior of the Republic of Albania from the website: 

-The profile on the social network "Telegram" with the tag "JusticeHomeland1" and the link https://t.me/JusticeHomeland1." with address: Telegram Headquarterers ……London United Kingdom; "HomelandJustice" and link https://homelandjustice.cx/ with ISP…… Hong Kong; 

-The profile on the social network "Telegram" with the name "JusticeHomeland1" and the link https://t.me/JusticeHomeland1." Russia". 

2. Sending all seized data by mail to Albanian law enforcement authorities. 

The implementation of the decision should be done by sending a request for legal assistance from the law enforcement bodies of the respective state Great Britain, the People's Republic of China and the Russian Federation. 

Court of first instance Tirana with Decision no. 1864, 1865 and 1866 Reg. Them. dated 06.10.2022 decided to accept the request of the prosecution. 

In the implementation and execution of these decisions by the Prosecutor's Office at the Court of First Instance in Tirana, requests for Legal Aid were sent by the law enforcement bodies of the relevant state Great Britain, the People's Republic of China and the Russian Federation. 

Let us clarify, as mentioned in the Decisions of the Court of First Instance Tirana no. 1864, 1865 and 1866 dated 06.10.2022, these pages from which the hacked materials originate are the subject of a criminal investigation, data and computer systems have already been seized in accordance with the procedural law of the Republic of Albania and any data that originates from these sites that operate in a criminal manner is subject to investigation and seizure already with court decisions. 

The investigations related to these cases are complex and are ongoing, guaranteeing that the prosecution is maximally engaged and will carry out any investigative action with the aim of fully clarifying this criminal activity and further preventing this activity which aims to harm all the activity of the state bodies of the Republic of Albania, social peace and coexistence between individuals", announces the Prosecutor's Office.