Covert operation: FBI agent bought data of Albanian citizens from Iranian hackers

2026-03-20 22:04:57 / AKTUALITET ALFA PRESS

Covert operation: FBI agent bought data of Albanian citizens from Iranian

A document published by the US Department of Justice reveals new details about the activity of a hacker network linked to Iran, which also includes Albania as a target of attacks and data leaks.

According to the material, US authorities seized four domains used by the Iranian Ministry of Intelligence and Security (MOIS), which served to claim responsibility for cyberattacks, publish stolen data, and exert pressure on opponents of the regime.

In this context, the document also reveals a covert FBI operation, where an agent, acting undercover, purchased sensitive data related to Albanian citizens through Telegram.

According to the investigative file, persons connected to the network claimed to own “e-Albania and other databases covering Albanian identity cards and other sensitive information,” offering to sell them in direct communications.

A subsequent analysis confirmed that the secured database contained “Albanian national identification numbers, names, dates of birth, addresses and other sensitive personally identifiable information (PII)”, exposing citizens to the risk of data abuse and illegal use.

The document shows that this activity was not sporadic, but part of a structured operation.

Investigations revealed that the seized domains – including Justicehomeland[.]org and Karmabelow80[.]org – had been used to publish and distribute stolen data, including from Albanian institutions.

In one of the cases, actors associated with MOIS claimed responsibility for the theft of documents from an Albanian government organization, in a context related to Albania's political stances towards an Iranian opposition group.

US authorities emphasize that these platforms did not serve only for propaganda, but were part of a well-organized "playbook" that included destructive cyberattacks and psychological operations through the publication of stolen data.

According to the Department of Justice, these actions were intended to intimidate adversaries, discredit targets, and amplify the Iranian regime's influence through cyberspace.

At the same time, the FBI investigation found that the same actors were using emails and online platforms to send death threats to journalists and dissidents, even offering rewards for physical attacks on them.

 

Happening now...