All cases

Albania Government Cyber Attack

July – September 2022

DestructivePeak: DestructionAttribution: High ConfidenceGovernment
Year
2022
Actor country
Iran
Target regions
Albania
Unpeace score
10

Executive Summary

Iran-linked actors launched destructive cyber attacks against Albanian government systems, deploying wiper malware and ransomware that took e-government services offline for weeks. Albania attributed the attack to Iran and took the unprecedented step of severing diplomatic relations — the first known rupture of diplomatic ties over a cyber operation.

Why This Matters

Albania's decision to sever diplomatic ties over a cyber attack — backed by NATO solidarity — set a new precedent for treating destructive cyber operations as grounds for the most serious peacetime diplomatic consequences.

Escalation Profile

7-Dimension Profile

Escalation Ladder

Probing
Intrusion
Disruption
Degradation
Destruction
Strategic

Phases

2021-05
Intrusion

Persistent access established

Iranian actors maintained access to Albanian government networks for over a year prior to the destructive phase.

2022-07-15
Destruction

Wiper and ransomware deployment

Wiper malware and ransomware deployed against government IT systems, taking down e-services including border control and tax platforms.

2022-09
Disruption

Second wave and data leaks

A follow-on attack in September targeted law enforcement systems; stolen data leaked online as part of an influence operation.

Threshold Crossings

  • First known severance of diplomatic relations over a cyber attack
  • State-sponsored destructive attack against a NATO member's government systems

Restraint Factors

  • Attacks targeted government IT, not civilian critical infrastructure
  • No reported physical harm

Attribution Assessment

High ConfidenceAttributed by Albania, the US, and allied governments to Iranian state actors affiliated with MOIS
Iran
Homeland JusticeDEV-0861DEV-0166
1. Technical

Threat actor mapped to Iran based on infrastructure analysis, malware attribution, and operational patterns.

Evidence: Microsoft: Iranian Attacks Against the Albanian Government

2. Political / Legal
Public AttributionSanctions Imposed
  • Albania severed diplomatic relations with Iran (Sep 2022)
  • NATO issued a statement of allied solidarity
  • US imposed sanctions on Iran's MOIS and senior officials
  • CISA issued joint advisory with FBI on Iranian threat activity

Sources: White House: Statement on Iran's Cyberattack Against Albania; FBI/CISA Advisory AA22-264A: Iranian State Actors Conduct Cyber Operations Against Albania

3. Open Source

No dedicated journalistic sources in dataset. See sources section for full references.

High Confidence” reflects available public evidence. All assessments carry inherent uncertainty and should be read alongside source material.

Unpeace Position

10

Unpeace Score

Composite severity rating on the peace–conflict spectrum

Stable
Contested
Escalatory
03060100

Contributing Dimensions

Escalation peak5/6
Threshold crossings2/4
Governance flags5/8
Sectors affected1/6
Entanglement3/10
Country scope1/6

Coercive Function

Destructive

Destruction of data or systems — coercive value through denial, punishment, or deterrence signaling.

Observed coercive effects

  • First known severance of diplomatic relations over a cyber attack
  • State-sponsored destructive attack against a NATO member's government systems

Entanglement Risk

Entanglement score3

Sectors affected

Government

Countries / regions

Albania

Impact summary

E-government services offline for weeks; border control, tax, and law enforcement systems disrupted; diplomatic break with Iran.

Infrastructure Meaning

Malware / tooling

ZeroCleare variantChimneysweep

Capability profile

E-government services offline for weeks; border control, tax, and law enforcement systems disrupted; diplomatic break with Iran.

4 ATT&CK techniques mapped — see ATT&CK mapping below.

Governance Analysis

Governance Flags

!Norm Violation
APublic Attribution
SSanctions Imposed
IIndictment
UUN Discussion
RRegulatory Change
CInternational Cooperation
DDeterrence Signal

Norms invoked

  • Sovereignty and non-intervention
  • UN GGE norm on responsible state behavior in ICT

Policy responses

  • Albania severed diplomatic relations with Iran (Sep 2022)
  • NATO issued a statement of allied solidarity
  • US imposed sanctions on Iran's MOIS and senior officials
  • CISA issued joint advisory with FBI on Iranian threat activity

Regulatory changes

  • Albania accelerated e-government security overhaul with allied support
  • NATO reinforced cyber defense commitment to member states

Governance impact assessment

Established that cyber attacks can trigger real diplomatic rupture and NATO solidarity, expanding the practical consequences states may face for destructive cyber operations against alliance members.

Sources

V

Microsoft: Iranian Attacks Against the Albanian Government

Vendor Report2022-09-08
G

White House: Statement on Iran's Cyberattack Against Albania

Government2022-09-07
G

FBI/CISA Advisory AA22-264A: Iranian State Actors Conduct Cyber Operations Against Albania

Government2022-09-21

Sources listed reflect publicly available materials used to construct this case entry. Inclusion does not imply endorsement. Where no URL is provided, the source may be found via its title and date.