Description

The Iranian Atomic Energy Organization (AEOI) confirms that one of its subsidiaries' email servers was hacked, after leaking stolen data on the telegram channel of the 'Black Reward' hacking group. AEOI is the main government agency for operating nuclear energy and nuclear fuel cycle installations in Iran and also responsible for nuclear technology research and development activities in Iran. According to AEOI, the purpose of the data leak was to defame their image and attract public attention, and also states that an unknown unauthorized party from a specific foreign country stole emails from the hacked server. After this incident, AEOI immediately implemented preventive measures to mitigate its effects and informed all parties of the incident, with advice on preparation for possible potential exploitation attempts. A hacker group named 'Black Reward' took responsibility for the data breach by leaking some of the stolen data on their Telegram channel. A 27GB collection of 14 RAR archives containing 85,000 emails was posted by Black Reward with a "perfect for researchers" characterized message and also claims that they had removed all marketing messages and spam emails before publication. Leaked data might include passports and visas of Iranians and Russians working for the agency, reports on power plant performance, contracts, and technical specifications. In addition, the threat actors' messages conclude with a tribute to Mehsa Amini, the young woman who died in Iran's "moral police" and the country's people rallied for a month-long uprising against theocratic rule in response to the events of Mehsa Amini. The hackers' message is signed "For women, life, freedom," giving the email server breach and data leak action as a hacktivism characteristic.