Microsoft: Iran unit behind Charlie Hebdo hack-and-leak op

Feb 2, 2023, 5:12 PM | Updated: Feb 3, 2023, 9:40 am
FILE - Iranian demonstrators set fire to French flags during their gathering to protest against the...

FILE - Iranian demonstrators set fire to French flags during their gathering to protest against the publication of offensive caricatures of the Iranian Supreme Leader Ayatollah Ali Khamenei in the French satirical magazine Charlie Hebdo, in front of the French Embassy in Tehran, Iran, Sunday, Jan. 8, 2023. After the French satirical magazine Charlie Hebdo's launched a cartoon contest to mock Iran's ruling cleric, a state-backed Iranian cyber unit struck back in early January with a hack-and-leak campaign intent on striking fear with the claimed pilfering of a big subscriber database, Microsoft security researchers say. (AP Photo/Vahid Salemi, File)

(AP Photo/Vahid Salemi, File)

After the French satirical magazine Charlie Hebdo launched a cartoon contest to mock Iran’s ruling cleric, a state-backed Iranian cyber unit struck back with a hack-and-leak campaign that was designed to provoke fear with the claimed pilfering of a big subscriber database, Microsoft security researchers say.

The FBI blames the same Iranian cyber operators, Emennet Pasargad, for an influence operation that sought to interfere in the 2020 U.S. presidential election, the tech giant said in a blog published Friday. Iran has in recent years stepped up false-flag cyber operations as a tool for discrediting foes.

Calling itself “Holy Souls” and posing as hacktivists, the group claimed in early January to have obtained personal information on 200,000 subscribers and Charlie Hebdo merchandise buyers, according to Microsoft’s Digital Threat Analysis Center.

As proof of the data theft, “Holy Souls” released a 200-record sample with names, phone numbers and home and email addresses of Charlie Hebdo subscribers that “could put the magazine’s subscribers at risk for online or physical targeting” by extremists. The group then advertised the supposed complete data cache on several dark web sites for $340,000.

Microsoft said it did not know whether anyone purchased the cache.

A representative for Charlie Hebdo said Friday that the newspaper would not comment on the Microsoft research. Iran’s mission to the United Nations did not immediately respond to a request for comment Friday.

The Jan. 4 sample release coincided with the publication of Charlie Hebdo’s cartoon contest issue. Entrants were asked to draw offensive caricatures of Iran’s supreme leader, Ayatollah Ali Khamenei.

The French newspaper Le Monde verified multiple victims of the leak from the sample, Microsoft said. The Iranian cyber operators sought to boost news of the hack-and-leak operation — and fuel outrage at the cartoon edition — through fake French “sock-puppet” accounts on social media platforms that included Twitter, Microsoft said.

The operation coincided with verbal attacks by Tehran condemning Charlie Hebdo’s “insult.”

The provocatively irreverent magazine has a long history of publishing vulgar cartoons which critics consider deeply insulting to Muslims. Two French-born al-Qaida extremists attacked the newspaper’s office in 2015, killing 12 cartoonists, and it Charlie Hebdo has been the target of other attacks over the years.

The magazine billed the Khamenei caricature contest as a show of support for nationwide antigovernment protests that have convulsed Iran since the mid-September death of Mahsa Amini, a 22-year-old woman detained by Iran’s morality police for allegedly violating the country’s strict Islamic dress code.

After the cartoon issue was published, Iran shut down a decades-old French research institute. Last week, it announced sanctions targeting more than 30 European individuals and entities, including three senior Charlie Hebdo staffers. The sanctions are largely symbolic as they bar travel to Iran and allow its authorities to block bank accounts and confiscate property in Iran.

According to the FBI, Emennet Pasargad authored what amounted to a relatively ham-fisted campaign to interfere with the 2020 U.S. presidential election. The group obtained confidential U.S. voter information from at least one state election website and sent threatening email messages to intimidate voters posing as the far-right group Proud Boys, the FBI says.

Emennet Pasargad has also, since 2018, conducted cyber-operations targeting news, shipping, airlines, oil and petrochemical, financial, and telecommunications, in the U.S., Europe, and the Middle East, the FBI says. The U.S. newspaper chain Lee Enterprises was among the suspected targets, according to the Council on Foreign Relations.

The group’s attacks since 2020 have primarily targeted Israel, the FBI says. They follow a pattern of intrusion, theft, data leak and then amplification through social media and online forums. In some cases destructive malware has been used.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

FILE - The OpenAI logo is seen on a mobile phone in front of a computer screen displaying output fr...
Associated Press

Musk, scientists call for halt to AI race sparked by ChatGPT

Are tech companies moving too fast in rolling out powerful artificial intelligence technology that could one day outsmart humans?
1 day ago
starbucks...
Associated Press

Starbucks leader grilled by Senate over anti-union actions

Longtime Starbucks CEO Howard Schultz faced sharp questioning Wednesday before the Senate Health, Education, Labor and Pensions Committee
2 days ago
FILE - The overdose-reversal drug Narcan is displayed during training for employees of the Public H...
Associated Press

FDA approves over-the-counter Narcan; here’s what it means

The U.S. Food and Drug Administration on Wednesday approved selling naloxone without a prescription, the first over-the-counter opioid treatment.
2 days ago
FILE - A Seattle police officer walks past tents used by people experiencing homelessness, March 11...
Associated Press

Seattle, feds seek to end most oversight of city’s police

  SEATTLE (AP) — The U.S. Justice Department and Seattle officials asked a judge Tuesday to end most federal oversight of the city’s police department, saying its sustained, decade-long reform efforts are a model for other cities whose law enforcement agencies face federal civil rights investigations. Seattle has overhauled virtually all aspects of its police […]
3 days ago
capital gains tax budgets...
Associated Press

Washington moves to end child sex abuse lawsuit time limits

People who were sexually abused as children in Washington state may soon be able to bring lawsuits against the state, schools or other institutions for failing to stop the abuse, no matter when it happened.
3 days ago
Three children and three adults were killed in a shooting at a private Christian grade school in Na...
Associated Press

Nashville shooter who killed 6 drew maps, surveilled school

Three children were killed in a shooting at a private Christian grade school in Nashville on Monday, hospital officials said.
4 days ago

Sponsored Articles

Compassion International...

Brock Huard and Friends Rally Around The Fight for First Campaign

Professional athletes are teaming up to prevent infant mortality and empower women at risk in communities facing severe poverty.
Emergency Preparedness...

Prepare for the next disaster at the Emergency Preparedness Conference

Being prepared before the next emergency arrives is key to preserving businesses and organizations of many kinds.
SHIBA volunteer...

Volunteer to help people understand their Medicare options!

If you’re retired or getting ready to retire and looking for new ways to stay active, becoming a SHIBA volunteer could be for you!
safety from crime...

As crime increases, our safety measures must too

It's easy to be accused of fearmongering regarding crime, but Seattle residents might have good reason to be concerned for their safety.
Comcast Ready for Business Fund...
Ilona Lohrey | President and CEO, GSBA

GSBA is closing the disparity gap with Ready for Business Fund

GSBA, Comcast, and other partners are working to address disparities in access to financial resources with the Ready for Business fund.
SHIBA WA...

Medicare open enrollment is here and SHIBA can help!

The SHIBA program – part of the Office of the Insurance Commissioner – is ready to help with your Medicare open enrollment decisions.
Microsoft: Iran unit behind Charlie Hebdo hack-and-leak op