Syrian Electronic Army hacks into Facebook’s domain

9:30 ET, 6 February 2014

The Syrian Electronic Army claimed Wednesday that it managed to hack into Facebook violating an administrator account of the Facebook’s Domain Registrar.


Syrian Electronic Army hit again, 2014 has started with the exploits of the popular group hackers that hit the giants of IT industry. MicrosoftPayPal, Ebay and also the CNN were hacked in the last month. This time the group has targeted Facebook website, also in this case the member of the Syrian Electronic Army claimed that they hacked an administrator account of the MarkMonitor, the Facebook’s Domain Registrar.

MarkMonitor Inc. is an American software company which develops software to protect corporate brands from illicit activities including fraud, piracy, counterfeiting and cybersquatting, it is the same domain registrar of Ebay/PayPal. MarkMonitor acquired AllDomains in 2001 and DtecNet in 2010, and it was itself acquired by Thomson-Reuters in 2012.


The Syrian Electronic Army modified the contact information for the Facebook Domain, referring to a Syrian email address on the company’s WHOIS domain information page. Fortunately the hackers failed to hijack the entire Facebook domain, in this case, the attack could have had very serious consequences, the hackers anyway claimed that they have tried to update the nameserver information, but the process had to be abandoned because it was “taking too much time…“.

Probably there are in place, I hope so, procedures to validate any changes to the records, for example, requesting a two-factor authentication to unlock the domain or anyway requesting that any change to DNS settings have to be manually verified and authenticated.

If Syrian Electronic Army had succeeded in updating the nameserver record for Facebook, then the millions of users could have been impacted, they could have been redirected to a malicious website serving a malware or to a fake authentication page to capture the users’ credentials.


The Syrian Electronic Army has attacked Facebook because the company removed from its social network the pages managed by dissidents because they violate standards for permitted content, the decision of the company has caused the loss of important information about the conflict.

The deletion of Syrian opposition pages by Facebook removes important information regarding the evolution of the Syrian internal conflict. News regarding the revolution, detailed reportage and also information about the use of chemical weapons in the country.

Facebook has confirmed that no user has been impacted and that it hasn’t observed traffic hijacking.  At the time of writing  the registrar contact details were restored and the situation is normal.

Pierluigi Paganini

(Editor-In-Chief, CDM)







FAIR USE NOTICE: Under the "fair use" act, another author may make limited use of the original author's work without asking permission. Pursuant to 17 U.S. Code § 107, certain uses of copyrighted material "for purposes such as criticism, comment, news reporting, teaching (including multiple copies for classroom use), scholarship, or research, is not an infringement of copyright." As a matter of policy, fair use is based on the belief that the public is entitled to freely use portions of copyrighted materials for purposes of commentary and criticism. The fair use privilege is perhaps the most significant limitation on a copyright owner's exclusive rights. Cyber Defense Media Group is a news reporting company, reporting cyber news, events, information and much more at no charge at our website Cyber Defense Magazine. All images and reporting are done exclusively under the Fair Use of the US copyright act.

Global InfoSec Awards 2022

We are in our 10th year, and these awards are incredibly well received – helping build buzz, customer awareness, sales and marketing growth opportunities, investment opportunities and so much more.


10th Anniversary Exclusive Top 100 CISO Conference & Innovators Showcase