journalists, rights defenders, activists targeted with Pegasus – a global investigation

An international collaborative reporting on the #PegasusProject released simultaneously by a number of international media, including The Guardian, the Wire India, the Washington Post, and OCCRP among 12 others, the global investigation documents how NSO Group, an Israeli surveillance company, sold Pegasus, a hacking software, to authoritarian regimes to target human rights activists, journalists, and lawyers across the world based on an investigation into a massive data leak. The investigation and the list were coordinated and obtained by the Paris-based journalism nonprofit Forbidden Stories and advised by Amnesty International.

Among the countries revealed to be using Pegasus was also Azerbaijan.

Ever since traces of surveillance technology were revealed to be in use to targeted civil society in Azerbaijan, there were suspicions that among the technology deployed, was also Pegasus. The most recent investigation, confirms these suspicions.

The data leak, containing some 50,000 phone numbers also showed that some of the people identified as owners of the targeted phone numbers were people of interest by clients of NSO since 2016.

According to OCCRP, at least 1000 of those numbers are from Azerbaijan.

“Reporters spent months establishing the identity of the people behind the numbers, and succeeded in verifying nearly a quarter. While NSO Group describes itself as a company that helps governments detect and prevent terrorism and crime, the list of Azerbaijanis selected for targeting shows how the tool was systematically abused. All but a few of the numbers identified by reporters belonged to journalists, activists, lawyers, and members of the country’s beleaguered opposition.

Of the 245 Azerbaijani phone numbers on the list that were identified, a fifth belonged to reporters, editors, or media company owners.”

In its response, NSO Group, “claimed the data used by reporters was misinterpreted and that it does not allow its clients to abuse its software, which, it reiterated, is meant only to surveil criminals and terrorists,” while not responding to specific questions about Azerbaijan.

“NSO describes its customers as 60 intelligence, military and law enforcement agencies in 40 countries, although it will not confirm the identities of any of them, citing client confidentiality obligations. The consortium found many of the phone numbers in at least 10 country clusters, which were subjected to deeper analysis: Azerbaijan, Bahrain, Hungary, India, Kazakhstan, Mexico, Morocco, Rwanda, Saudi Arabia and the United Arab Emirates. Citizen Lab also has found evidence that all 10 have been clients of NSO, according to Bill Marczak, a senior research fellow.”

Among identified journalists and activists on the list are:

  • Khadija Ismayilova, journalist
  • Sevinc Vagifgizi, journalist, Meydan TV
  • Fatima Movlamli, activist/journalist
  • Ilkin Rustamzade, activist, and his former wife Amina
  • Nine current and former journalists from Azadliq.info
  • Bahaddin Haziyev, editor, “Bizim Yol” newspaper
  • Elkhan Shukurlu, editor-in-chief of Strateq.az
  • Avaz Zeynalli, editor-in-chief of Khural
  • Anar Orujov, founder of Kanal 13
  • Aziz Orujov, director of Kanal 13
  • Rauf Arifoglu, editor in chief of Musavat newspaper
  • Mehman Huseynov, former political prisoner, and citizen journalist
  • Bayram Mammadov (who died in Istanbul earlier this year) and Giyas Ibrahimov – the graffiti prisoners (Mammadov, his father, and Ibrahimov’s mother are all on the list

According to OCCRP, the list also includes “more than 40 Azerbaijani activists and their family members on the list. Their presence on the list begins in 2019.”

In its report, the Washington Post writes, “the list does not identify who put the numbers on it, or why, and it is unknown how many of the phones were targeted or surveilled. But forensic analysis of the 37 smartphones shows that many display a tight correlation between time stamps associated with a number on the list and the initiation of surveillance, in some cases as brief as a few seconds.”

“The numbers on the list are unattributed, but reporters were able to identify more than 1,000 people spanning more than 50 countries through research and interviews on four continents: several Arab royal family members, at least 65 business executives, 85 human rights activists, 189 journalists, and more than 600 politicians and government officials — including cabinet ministers, diplomats, and military and security officers. The numbers of several heads of state and prime ministersalso appeared on the list.

Among the journalists whose numbers appear on the list, which dates to 2016, are reporters working overseas for several leading news organizations, including a small number from CNN, the Associated Press, Voice of America, the New York Times, the Wall Street Journal, Bloomberg News, Le Monde in France, the Financial Times in London and Al Jazeera in Qatar.”

How does Pegasus work

According to Access Now, since 2016, some 46 countries were identified where NSO Group’s Pegasus has been in use. “Reports from Access NowCitizen Lab, and others all show that an alarming number of people targeted using Pegasus have been journalists, lawyers, and activists, whose only crime was speaking out against and reporting on the injustices in their home countries.”

In March of this year, AIW reported on a France-based blogger, whose phone too may have potentially been infected with Pegasus. At the time, there was only suspicion and no conclusive evidence. While this still may be the case, three months later, it is now confirmed, that not only the government in Azerbaijan has been using various methods, to crack down on dissent with arrests, intimidation, and physical threats against civil society, but that it has been doing so using authoritarian technology including Pegasus.

new report documents a decade of censorship in Azerbaijan

On July 16, Qurium Media Foundation released a report, “A Decade of Efforts To Keep Independent Azerbaijani Media Online”. 

The report highlights the work carried out by Qurium since 2010 assisting targeted independent and opposition online news platforms in Azerbaijan. “For more than a decade, Qurium has monitored and mitigated a wide range of cyberattacks against the websites and since 2016, no less than twenty forensics reports have been released to document our findings,” reads the new report.

Denial of Service attacks

During five years (2010-2015), Qurium mitigated dozens of denial of service attacks against Azerbaijani media, and was forced to invest in mitigation hardware and to increase its Internet capacity. Commercial mitigation of denial of service was not possible for Azeri media organizations as the average cost for such services was close to 1,000 Euro/month for a small website.

During 2014-2016, several corporate efforts made Denial of Service more difficult for the attackers, both Cloudflare (2014) and later Google (2016) started to offer free protection to journalists and human rights groups and many stress testing services (aka “booters”) since then were dismantled by FBI, such as the infamous VDOS Booter and the Mirai botnet.

After three years of research of development (2014-2017), Qurium built its own mitigation hardware and upgraded its Internet capacity by a factor of 200. Although the Denial of service attacks slowly had decreased since 2017, new challenges emerged. Internet Network Interference.

Internet Network Interference

In late 2013, a new type of challenge emerged when we discovered that websites artificially were slowed down. Instead of blocking the websites that clearly would expose the motivations and those responsible for the disruptions, the websites were slowed down by limiting the amount of bandwidth available to reach them. Qurium was forced to develop a method to detect “Internet Congestion” and to keep moving affected websites to other IP addresses to keep them online. Other large providers, such as Akamai, hosting other Azeri media was also slowed down and was unable to respond effectively to the challenge.

Exposing a coordinated cyberwar strategy

Starting from 2017, the cyberwar landscape changed. 

During that year, we received customized denial of service, pen testing and vulnerability scans and the first reports of targeted malware.

A series of diverse attacks and forensics analysis including tracing back the source of a malware sent to journalists helped us to confirm that new Ministry of Transport, Communications and High Technologies and the “hacker community” built around the government, sponsored cybersecurity events were actively targeting our hosted media.

After hosting and protecting Azeri media for almost seven years, we had no doubt about the actors behind the attacks, and could publicly document that a “State Actor” was orchestrating diverse forms of cyber attacks.

Deep Packet Inspection

Also in 2017, a new method used against independent and opposition media was identified by Qurium – the Deep Packet Inspection or shortly DPI. 

In April 2017, we identified that new technical means were implemented in several operators to block some of the websites. The Azeri authorities had invested in Deep Packet Inspection equipment to block the media outlets once and for all.

By the end of April 2017 Qurium learned that there were a court order against some of our hosted media organizations. To our surprise, the websites under Deep Packet Inspection were many more than the ones mentioned in the court order. The court order stated that the listed websites (Azadliq.info, Azadliq.org, Azerbaycansaati.com, Meydan.tv and Turan TV) were “creating threats to the legitimate interests of the state and society” and must therefore be blocked.

After two years of research between 2017-2019, Qurium identified the use of DPI hardware from Allot Communications and Sandvine inside several operators in Azerbaijan.

Website flooding, phishing, and more

By 2018, many of the “stress testing services” often used to launch the Denial of Service attacks had been dismantled world wide. The attackers were forced to find new alternatives to conduct their traffic floods aiming to take the websites offline. During another forensic investigation we traced back this new source of denial of service to Russian Fineproxy (Region40). By identifying the service provider used to conduct the attacks, we could not only expose their business practices but also their management that kindly disabled the account of the attacker.

In late 2018, Denial of Service became a second priority in the strategy to harass Azeri media and once again other means were needed.

By April 2020, Qurium could finally link the denial of service attacks launched using Fineproxy service with the very same threat actor from the Ministry of Internal Affairs: sandman. Access to sandman github account provided us with a good insight of the toolset that was being used against online media and journalists in Azerbaijan.

A final report of our findings showed even more advanced capabilities, like the ability to create fake SMS or hijack SMS sent to the journalists giving the attackers the ability to take control over their social media accounts.

Phishing remains a major attack vector against journalists and human right activists, the latest phishing campaign in early July 2021 impersonated human rights watch so as to implant a malware capable of recording the desktop and webcam or exfiltrate all important documents of the victims.

Conclusion

What started in 2010 and went on for years with Denial of service attacks using third party stress testing services was extended with more sophisticated attacks in 2017 including targeted phishing and the introduction of dedicated hardware to block the websites using technologies as DART from Allot and PCEF from Sandvine.

The national blocking of many websites, not always supported by legal court orders, has been weaponized to limit visibility of the media in the country. Despite our multiple efforts to provide alternatives to make the content available, the blocking has had a huge impact in the revenue creation of the alternative media and the growth of readership.

After the introduction of Internet blocking by means of more sophisticated deep packet inspection against alternative websites in 2018, many of the blocked media opted to increase their presence in Facebook but that has proven to be an advantageous situation for the Azeri government and their secret cyber operations as Facebook has showed a bad track record in dealing with “coordinated inauthentic behavior” in the country.

You can read the full report here.

attention: phishing attack detected

On July 8, Azerbaijan Internet Watch received a notification that an email sent on behalf of Human Rights Watch reached a number of prominent Azerbaijani civil society activists. The email contained an attachment “Human Rights Invoice Form Document – 2021.docx” prompting the recipient to download the attached file.

AIW, reached out to partners at Qurium to analyze the attachment. The forensics confirmed the suspicions that the email was indeed a virus. According to preliminary conclusions, “the e-mail included a link to malware, with the capability of webcam and Desktop recording, execution of windows commands (WMI) as well as extraction and uploading of selected files from the victim’s computer.

Screenshot from the original email that was sent.

Phishing incidents targeting civil society activists are common in Azerbaijan.

Numerous reports, including several by AIW, in partnership with Qurium, documented and investigated these attacks, over the recent years [see below].

A detailed report by Qurium presents an analysis of the malware and explains how it was built, its capabilities, and where it was hosted. Among the findings were:

desktoprecord
webcamrecord
download
implant
makepersistent
massdownload
stopimplant
upload
uploadexec
wmicexec
aueval

In addition to taking screen captures and webcam recording, there was another interesting detail – insufficient knowledge or lack of an auto-correct program run on a computer or the user, developing the malware. As captured by Qurium, there were several grammatical mistakes in the pop-up window informing the owner of the device who downloaded the email “Unsopported Microsoft Word version!” & @CRLF & “File corrupted. Error numer: 0x65415681.”

Qurium forensics report.

Qurium also released its report titled “A decade of efforts to keep Azerbaijani media online” that sums up the assistance the platform has provided since 2010 including monitoring and mitigating a wide range of cyberattacks against the websites in Azerbaijan and since 2016, releasing no less than twenty forensics reports to document their findings.

Further, read:

instagram user from Azerbaijan explicitly targets women online – will Facebook and Google take notice?

Violence and harassment against women in Azerbaijan have reached a new level when a user named [@] panturaloriginal mocked women and the way they choose to dress during a live feed via his Instagram account. While the video is no longer available on the user’s Instagram account Shafi Shafiyev, an activist from Azerbaijan shared one part of the video via his Twitter:

Here is a brief translation of what user panturaloriginal is saying in the video: “There are some women who encourage men to slap them from behind when they open their body parts. You just want to slap them. And if they turn around and ask why I would tell them ‘are you out of your mind?! You have left your body parts exposed and I am slapping them. Are you messing with me?!’ Why do you leave your parts exposed? If they are, then I will touch them. I enjoy it. You are playing with my natural instinct.  Do I have to walk around like a blind man [covering his eyes with his hands] because of you? Then dress properly. Cover your body parts. Why is it so important for you to show it? If you are showing it, then I will slap you. I enjoy it. It turns me on. This is how I have been made. It is a natural sensation. Why do I have to control myself?! You have left your body parts exposed, so I am going to slap it like that.”

On July 1, 2021, Facebook, Twitter, TikTok, and Google made commitments to tackle the abuse of women on their platforms as more than 200 women signed a letter calling for tech companies to “prioritize the safety of women.” 

Among their commitments announced at the UN Generation Equality Forum in Paris are: 

Build better ways for women to curate their safety online by:

  • Offering more granular settings (e.g. who can see, share, comment or reply to posts)
  • Using more simple and accessible language throughout the user experience
  • Providing easy navigation and access to safety tools
  • Reducing the burden on women by proactively reducing the amount of abuse they see

Implement improvements to reporting systems by:

  • Offering users the ability to track and manage their reports
  • Enabling greater capacity to address context and/or language
  • Providing more policy and product guidance when reporting abuse
  • Establish additional ways for women to access help and support during the reporting process

The user has two Instagram accounts [panturallive] and [panturaloriginal] and a youtube channel [pantural]. The account from which the live feed was done, has over 68k followers. Both Instagram accounts are now private. 

what’s new in the new media law

The plans to roll out a new Media Law in Azerbaijan were announced in January 2021 following a Presidential Decree “on deepening media reforms in the Republic of Azerbaijan.” In addition to a new Media Law, the decree also called for an establishment of a brand new body, the Azerbaijani Agency for Media Development replacing the State Support Fund for Mass Media Development. 

Six months after the initial announcement, the law is ready, but not for the public eye or independent journalists. The critics say, the law will further restrict the work of independent and opposition media platforms, while supporters argue the law will strengthen the media environment in the country. 

According to Ahmad Ismayilov, the Executive Director at the newly set up Agency for Media Development, the law – which is currently being developed behind-closed-door discussions – will be evaluated by the parliament in its final form, and only after the reading at the parliament will be open to public debate. 

What is known about some of the provisions

  • one unified registry system for media outlets, their offices, and journalists in order to systematize information on media entities, their offices and staff (this specifically has caused dissatisfaction among independent journalists and bloggers, according to Turan News Agency reporting);
  • the registration process requires that all print, online media platforms, news agencies, and journalists apply for registration;
  • a separate body – Audiovisual Council – will register audiovisual media platforms;
  • all media platforms and journalists registered through the system will receive certificates and press cards (valid for three years) respectively;
  • the registration system does not apply to foreign journalists who will require to receive approval from the Ministry of Foreign Affairs;
  • all media platforms must be legally registered and show proof of sustainability with registering;
  • journalists registering through the system, will be required to meet a set of requirements – those without higher education, previous convictions won’t be registered; journalists must provide contracts with media platforms that must be registered within the system; journalists must provide at least three years of work experience or relevant work experience;
  • the registry may remove media platforms and journalists already registered;  
  • the draft law will require internet television to obtain licenses in order to operate;
  • the draft law will be submitted to the national parliament (no dates announced yet); put on the agenda and posted on the Parliament’s website. Only then will there be a discussion on the main provisions and assessments of the overall bill;
  • the draft law prohibits state censorship and financing of the media; 
  • the draft law ensures pluralism and freedom of the media; 
  • according to one of the provisions, illegal interference in the work of journalists, their persecution, and harassment are inadmissible; 

According to Rustam Ahmadov, director of the Media Development Agency’s Department for Work with Media Entities and Journalists and Media Support Projects, it is possible that the bill will be adopted in the first reading. But it is also possible the draft will be returned for revision, to address suggestions and comments. “Unfortunately, I can not say exactly when the bill will be submitted to the parliament,” Ahmadov told Turan News Agency in an interview. 

Pundits’ response

Until the bill has been made public, it is hard to comment on its transparency said media lawyer Khalid Agaliyev in an interview with Turan News Agency. So far, the closed discussions are only creating doubts and eliminating optimism about the progress of the law, said a media lawyer. 

Aghaliyev pointed to three issues about the draft law that is especially worrying, “unified registry of journalists, licensing of online media, the creation of a media register (that would also require registration of their staff). All three are seriously controversial in terms of the concept of the right to freedom of expression, and there are elements of discrimination.”

On the provision about single press cards Aghaliyev said, this provision would allow the government to choose who keeps tabs on the work the government does because, under normal circumstances, it is the media and journalists who exercise public control over government activities. Aghaliyev also pointed out that the right to access, prepare and disseminate information is not only given to journalists but to every citizen according to the Constitution and international agreements Azerbaijan signed. Enforcing the single card rule is not an additional opportunity. “There are editorial offices established in accordance with the law, there is an editorial policy, their press cards should suffice to take advantage of the opportunities created by the state for journalists,” said Aghaliyev.

On the provision about licensing internet television and one single registry, Aghaliyev said this would go against the right to freedom of expression. “Rules such as the creation of a register of all media outlets and the registration of those included in the register as journalists are seriously problematic and discriminatory in terms of the right to freedom of expression.”

Aghaliyev also reminded that a media registry already exists in Azerbaijan as newspapers must inform the Ministry of Justice and once approved, start operating. “In this case, the creation of a separate register indicates the intention to more easily control, direct and suppress the media and journalists.” 

Media censorship in Azerbaijan through the lens of network measurement – July 2021 report

On July 1, Azerbaijan Internet Watch launched a new report titled “Media censorship in Azerbaijan through the lens of network measurement”. The report was prepared in partnership with the Open Observatory of Network Interference (OONI) summarising key findings from network measurements conducted between January 2020 to May 2021. The full report can be accessed here.

About the report

In light of reports on the blocking of websites in Azerbaijan, the Open Observatory of Network Interference (OONI) and Azerbaijan Internet Watch (AIW) formed a partnership to collaborate on researching internet censorship in the country. Over the past year, OONI and AIW have collaborated on collecting and regularly analyzing censorship measurements from Azerbaijan, while providing timely updates through reports. In this report, we share findings from our analysis of OONI network measurements collected from Azerbaijan between 1st January 2020 to 1st May 2021. The aim of this study is to document and increase the transparency of internet censorship in Azerbaijan through the analysis of empirical network measurement data.

Key findings

  • Blocking of independent news media and circumvention tool websites. Throughout the testing period, several independent news media and circumvention tool sites presented HTTP failures caused by connection timeouts. This suggests the potential use of Deep Packet Inspection (DPI) by ISPs in Azerbaijan.
  • Attempts to block Tor and Psiphon. ISPs in Azerbaijan attempted to block Tor and Psiphon amid the 2020 Nagorno-Karabakh war. However, both attempts appear to have been quite ineffective. 
  • Temporary blocking of social media amid 2020 Nagorno-Karabakh war. Between September 2020 to November 2020, several social media websites presented the same HTTP failures (as news media and circumvention tool sites), while the testing of WhatsApp and Telegram presented signs of TLS level interference.
  • Variance of censorship across networks. ISPs in Azerbaijan appear to be adopting similar censorship techniques. However, censorship varies from network to network, as different ISPs block different websites and apps at different moments in time.

Blocked news media websites

Several independent news media websites presented signs of blocking in Azerbaijan throughout the analysis period.

These domains include:

  1. `azerbaycansaati.tv`
  2. `criminal.az` 
  3. `www.24saat.org` 
  4. `www.abzas.net` 
  5. `www.azadliq.info`
  6. `www.azadliq.org`
  7. `www.gununsesi.info`
  8. `www.gununsesi.org`
  9. `www.kanal13.tv`
  10. `www.meydan.tv`

OONI data also suggests that the site (`www.occrp.org`) of the Organized Crime and Corruption Reporting Project (OCCRP) and the site (`www.rferl.org`) of RadioFreeEurope/RadioLiberty (RFE/RFL) were blocked in Azerbaijan as well. The blocking of the OCCRP site reportedly began in September 2017, following the publication of a major investigation (“Azerbaijani Laundromat”) into corruption, bribery, and money laundering in which powerful figures were allegedly involved. The blocking of the RFE/RFL website also reportedly began in 2017, following an Azerbaijani court order which RFE/RFL described as “another blatant attempt at silencing its reporting in the country”

Blocking of social media amid 2020 Nagorno-Karabakh war

Amid the 2020 Nagorno-Karabakh war, OONI data shows that access to several social media websites and apps was blocked in Azerbaijan. The following chart, limited to social media websites that presented signs of blocking between February 2020 to May 2021, aggregates OONI measurement findings collected from 4 AS networks in Azerbaijan.

Blocking of social media websites in Azerbaijan based on OONI data (collected between March 2020 to May 2021), https://explorer.ooni.org/search?since=2020-01-01&probe_cc=AZ&test_name=web_connectivity&only=anomalies

As is evident from the above chart, most of these social media websites primarily presented signs of blocking during the 2020 Nagorno-Karabakh war (between 27th September 2020 to 10th November 2020), but were found accessible when tested (on several networks in Azerbaijan) in the months before and after the war. Notably, most anomalous measurements presented HTTP failures (because the HTTP requests timed out), similarly to the blocking of news media websites (discussed previously). This provides a stronger indication that these social media websites were blocked, particularly since ISPs often use the same censorship technique(s) to block a variety of different websites. 

Blocked circumvention tool sites

Numerous circumvention tool websites presented signs of potential blocking when tested (on up to 3 AS networks) in Azerbaijan between February 2020 to May 2021, as illustrated through the following chart.

Blocking of circumvention tool websites in Azerbaijan based on OONI data (collected between January 2020 to May 2021), https://explorer.ooni.org/search?since=2020-01-01&probe_cc=AZ&test_name=web_connectivity&only=anomalies

Similar to the blocking of news media and social media websites, we observe that the testing of circumvention tool websites often resulted in HTTP failures caused by connection timeouts. This consistency in terms of failures, observed on several AS networks over the period of a year, strongly suggests blocking of these circumvention tool websites. As testing coverage increased from January 2021 onwards, we observed an increased volume of anomalous measurements, most presenting the same HTTP failures.

Conclusion

Press freedom appears to be quite limited in Azerbaijan, as suggested by the blocking of several independent news media websites in the country. These media websites presented signs of blocking throughout their testing (on several local AS networks) between January 2020 to May 2021 (corroborating past reports on the blocking of media websites in Azerbaijan), with recent OONI measurements suggesting that their blocking remains ongoing

Potentially in an attempt to prevent the circumvention of media censorship, ISPs in Azerbaijan appear to have blocked access to a number of circumvention tool websites over the last year as well. It remains unclear, however, if the apps of these circumvention tool sites were also blocked (as they were not tested as part of this study); and even if they were, it’s possible that local internet users may have been able to use them nonetheless, given that circumvention tools often include in-built circumvention techniques for evading censors. 

Amid the 2020 Nagorno-Karabakh war, ISPs in Azerbaijan appear to have attempted to block the Tor and Psiphon circumvention tools. Yet, these attempts were likely ineffective, given that both tools have in-built circumvention techniques and fallback options for circumventing blocks. In Tor measurements, we observe that most ISPs did not block all tested Tor directory authorities, suggesting that it was possible to use Tor nonetheless (as also indicated by the spike in Tor usage from Azerbaijan during that period). Similarly, many Psiphon measurements during this period were successful, suggesting that it may have been possible to use the Psiphon VPN on many networks.

Several social media websites (such as `www.facebook.com` and `www.youtube.com`) and apps (primarily WhatsApp and Telegram) presented signs of blocking between September 2020 to November 2020, which coincides with the 2020 Nagorno-Karabakh war. It is, therefore, possible that ISPs may have increased efforts to block circumvention tools (during this period) in an attempt to prevent the circumvention of social media censorship.

Interestingly, we observe similar censorship techniques adopted by different ISPs in Azerbaijan, but variance in terms of which internet services are blocked by ISPs over time. In other words, we see ISPs blocking websites and apps in similar ways (seemingly using the same censorship techniques), but different ISPs block access to different websites and apps (and sometimes this varies at different moments in time). 

Throughout the testing period, independent news media and circumvention tool websites presented HTTP failures caused by connection timeouts, suggesting the potential use of Deep Packet Inspection (DPI) by ISPs in Azerbaijan. Similarly, when social media websites were temporarily blocked amid the 2020 Nagorno-Karabakh war, their testing also presented HTTP failures caused by connection timeouts. This suggests that most ISPs in Azerbaijan block websites using similar (if not the same) censorship techniques.

Both WhatsApp and Telegram presented signs of TLS level interference on several different AS networks in Azerbaijan amid the 2020 Nagorno-Karabakh war. In the case of WhatsApp, the HTTP requests to `web.whatsapp.com` succeeded, while the HTTPS requests failed (during the TLS handshake), which could be an indication of SNI-based filtering. In the case of Telegram, we see that both HTTP and HTTPS requests to `web.telegram.org` timed out. 

As media censorship (and the blocking of circumvention tool websites) appears to be ongoing in Azerbaijan, there is a need for further testing to evaluate these censorship events in more depth over time. The temporary blocking of social media amid the 2020 Nagorno-Karabakh war also suggests that new censorship events can emerge in Azerbaijan, as political events evolve. 

This study was carried out through the use of open methodologies, free and open source software, and open data, enabling independent third-party verification of our research findings. We encourage researchers to expand upon this study by running OONI Probe and analyzing OONI measurements from Azerbaijan.    

editor facing slander and insult charges

In Azerbaijan, editor of an online news website sozcu.az, Elshan Alisoy is facing slander and insult charges and a hefty fine. The charges leveled against the editor are related to the claims, raised by the Vice President of SOCAR [Azerbaijan State Oil Company] Mikayil Ismayilov. 

The vice president’s demands include a 100,000 AZN compensation [58.8 thousandUSD] for moral damage, charges of slander [Article 147], and insult [Article 148] of the Criminal Code of Azerbaijan and closed-door hearing, over an article, Alisoy shared on Facebook. 

On June 22, a preparatory meeting was held in the Agsu District Court according to reporting by Turan News Agency. The agency reports that the hearing on the merits is scheduled for June 25. 

The editor’s lawyer, Nemat Karimli, says the acceptance of the claim into proceedings is unlawful. “According to Article 60 of the Law on Media, a person who reprints [reshares] an article published in another media is not responsible for the content.”

Titled, “The dark empire of Mikayil Ismayilov” the original article, that the blogger shared on his Facebook, was originally published by an online platform azadsoz.com [free word] on May 18, alleging that Mikayil Ismayilov oversees the management of the entire financial process in SOCAR’s covert operations.

Reposting the article, Elshan Alisoy, wrote the following comment, “Dear God, why they need all this wealth… Mikail Ismayilov is one of the 12 vice presidents of SOCAR. I call this, gluttony and barbarity.”  

The hearing in the case is scheduled for June 25. 

Azerbaijan to license online TV channels

In January, 2021, Az-Net Watch covered the new legal development concerning media freedom environment in Azerbaijan. At the time, it was announced, that a newly established Azerbaijani Agency for Media Development will replace, marred by corruption allegations, the State Support Fund for Mass Media Development and that a new media law was drafted by the Administration of the President for the President’s review in two months. Six months down the line, the draft media law, is finally set for review, albeit much to the disappointment of freedom of the media advocates and media practitioners in Azerbaijan.

According to Azadliq Radio report, the new law, entails licensing the Internet television and radio broadcasting. The proposal spearheaded by the National Television and Radio Council (NTRC) was announced on June 17.

Specifically the draft law states that:

1) the online channel must have its own website and broadcast from this site;

2) the online channels must broadcast for not less than 6 hours as determined by the proposed new draft bill.

In addition, the Agency for the Development of Mass Media would register online news sties and news agencies.

When Turan News Agency reached out to the NTRC for a comment, the Council refuted the claims that the draft bill mentioned the Internet TV. Similarly, when the agency asked the newly created Agency for Media Development, the agency said, it had no information of such requirement mentioned in the bill. And yet, it was the NTRC that told state news agency APA about the draft bill according to Azadliq Radio report.

Several independent experts, said if true, the new bill and specifically the proposal about licensing, violate Article 10 of the European Convention on Human Rights and norms enshrined in Azerbaijan’s Constitution.

Addressing the controversial new bill, a media law expert, Alasgar Mammadli, said in addition to contradicting Article 10 of the Convention the license requirement can only be applied to broadcasters using frequency transmissions which is not the case for Internet television. In another interview, Mammadli said, “Only during the broadcast, there should be compliance with the general law, which is currently regulated by the Law on Mass Media, Criminal Law, and other laws. There are no gaps, and there are even unnecessary regulations (restrictions).” 

Another legal expert, Khaled Aghaliyev, evaluating the bill in a post on social media platform Facebook said, “It was clear that the government, which promised progressive reforms in the legal regulation of the media, worked harder than ever on reactionary regulatory mechanisms.” Aghaliyev said, in all likelihood, the lawyers working on “progressive regulations” took it upon themselves to interpret one specific sentence of Article 10 word for word. That sentence, notes Aghaliyev says, “This Article shall not prevent States from requiring the licensing of broadcasting, television or cinema enterprises.” “But they [lawyers] thought wrong. The mentioning of that licensing applies only to traditional television, and radio. Therefore, the part of the new bill that we know of, is reactionary, binding freedom of expression. It does not comply with our constitutional norms or the European Convention.”

Stressing the importance of adopting a new media law, Aghaliyev instead offers a different approach. “The government should share the full text of the new draft law and let the civil society prepare an alternative. The two drafts should then go to the Council of Europe experts. Let the Council decide and adopt the one recommended instead.” [A similar initiative took place in 2017 when Azerbaijan’s civil society submitted an alternative analysis of the law on access to information as part of the Good Governance partnership]. 

Screen shot from the report “Compliance of the Republic of Azerbaijan with the International
Covenant on Civil and Political Rights”. The full report can be accessed here: https://tbinternet.ohchr.org/Treaties/CCPR/Shared%20Documents/AZE/INT_CCPR_CSS_AZE_25228_E.pdf
An attempt to license online television was previously discussed in 2010, 2011, 2012, 2016. Over the past decade, the national lawmakers suggested regulating social media platforms on several occasions as well. In March 2017, Azerbaijani lawmakers approved legislation tightening rules for Internet use. Shortly after, scores of independent and opposition news websites were blocked inside Azerbaijan for access. 
*”National Television and Radio Council (NTRC) of Azerbaijan, was established by decree № 794 of the President of Azerbaijan Republic dated October 5, 2002 to ensure the implementation and regulation of state policy in broadcasting sector. The objective of the Council is to regulate the activity of television and radio companies, protect interests of the public during the broadcast, and control the observance of legislation on broadcasting.”

6 journalists and bloggers behind bars in Azerbaijan

On June 8, Justice for Journalists issued a statement in support of jailed media workers worldwide. 

The Justice for Journalists Foundation and its Media Risk Map partners monitoring attacks on media workers in the post-Soviet space call on international organisations and governments of all countries to do their utmost to secure the early release of all incarcerated media workers and to end the barbaric violations of their rights. According to the JFJ’s experts, at least 84 media workers from Azerbaijan, Belarus, Crimea, Russia, Turkmenistan and Uzbekistan are awaiting trial in detention or under house arrests, or have already been sentenced to long-term imprisonment and are held in prisons and prison camps. 

According to JfJ the following journalists and bloggers remain behind bars in Azerbaijan: 

Legal analysis of a COVID tracing app released last year in Azerbaijan

This is part three in a series of detailed legal reports and analyses on existing legal amendments, and new legislation affecting privacy, freedom of expression, media, and online rights in Azerbaijan and their compliance with international standards for freedom of expression.  

In July, of last year, authorities in Azerbaijan released their very own COVID tracing tracker application. Launched by Tebib (Azerbaijan Administration of Regional Medical Division) the app was quick to draw attention, especially over its privacy issues.

The mobile app is operated by the Data Processing Center (DPC), which is the main structure of the information technologies of the Ministry of Transport, Communications, and High Technologies. According to the app’s version history at App Store, the application “update” was done on 27 May 2021. 

e-Tebib is just one of the deluge of apps unveiled during the height of the COVID-19 pandemic by various governments, promising to detect COVID-19 exposure and not only.

Below, we break down the pervasiveness of the app having analyzed existing national and international legislation.

Features and concerns

According to the app’s description, “E-Tebib is designed to inform users in real-time about the number of patients (both sick and recovered) in Azerbaijan.” Since the start of the pandemic, the official data for Azerbaijan on the number of infected patients and recoveries were made available here and the numbers were updated once a day – based on the numbers reported by the Operational Headquarters set up under the Cabinet of Ministers of the Republic of Azerbaijan (the unit was established on February 27, 2020). Already from the start, it was unlikely the app was going to provide real-time indicators when the main body in charge only shared the information once a day. 

In addition, article 4.4 in the user agreement of the app, explicitly said that any information, obtained through the app, may not be precise, correct, or trusted. And yet, the app also claimed to reduce the number of infected patients by informing users of potential COVID infected patients around them via Bluetooth technology. 

Although the app claimed it did not collect any personal data aside from the user’s phone number the article 5.3 of the license agreement stated, the center [the Ministry of Communication, Transportation and High Technologies who owns the app’s license] collected users’ names, last names, phone numbers, social media accounts, emails, national ID numbers, and location.

Article 5.1 mentioned the center was sharing this information with third parties. These third parties were allowed to analyze collected information including users’ browsing history [The center did claim that it did not allow third parties, to use the obtained information for other purposes]. Article 5.5.1 stated the center may share users’ information with government bodies and/or representatives’ legal requests; court orders; or under any other legal condition. Furthermore, article 5.6 stated that users’ information may be shared with third parties in other countries for security purposes.

What the law says

According to Article 5.1 of the Law on Personal Data personal information is protected from the moment it is collected and for this purpose, it is divided into confidential and public categories according to the type of access. Article 5.2 of the Law on Personal Data stipulates that confidential personal data must be protected by the owner, operator, and users who have access to this information on a level required by law. Confidential personal information may be disclosed to third parties only with the consent of the subject, except as provided by law. Article 5.3 of the Law on Personal Data defines open personal data as information anonymously duly declared, made public by the subject, or entered into the information system with the consent of the subject. The person’s name, surname, and patronymic are permanently open personal information.

The terms of the agreement [of the app] on sharing private information with the third parties are vaguely regulated and open to wide interpretation for unlawful transmission of the private information with third parties.

Furthermore, article 5.5.1 of the app’s agreement that states information might be shared upon the government representatives’ legal requests are problematic from the human rights perspective. It fails to specify on which grounds and under what conditions the state authorities might request the private information which is necessary for terms of procedural fairness and safeguards against arbitrariness.

Where personal information is stored for the interest of the protection of health, there should be adequate and effective guarantees against abuse by the state. The law in question, which allows the storing of such information, must indicate with sufficient clarity the scope and conditions of exercise of the authorities’ discretionary power. These standards to some extent are also backed in Article 11.2.2 of the Law on Personal Data which states that when collecting personal data, the owner or operator must notify the subject about the purpose of personal data that is being processed and the legal grounds of this purpose.

In other words, it is not clear whether any state authority can have access to private information simply upon requesting it without legal justification. This is also a requirement of the Law “About operational search activities” as per Article 10. Thus, Article 10 of the Law states that the extraction of information from technical communication channels and other technical means is carried out on the basis of the decision of the court [judge].

Article 5.10., of the app’s user agreement states that all user-related data is kept for a month. But it fails to explain whether the same expiry date applies to “third parties” that may have access[ed] [to the] users’ information. This is contrary to Article 8.2., of the Law on Personal Data. Law on Personal Data requires that for the purpose of collecting and processing of personal data (specifically Article 8.2.3.,) and conditions of destruction or archiving of personal data collected in the relevant information system after the expiration of the period of storage or after the death of the subject in the manner prescribed by law must include a written consent for the processing of the subject’s personal data.

Such vagueness is also contrary to the ECtHR’s well-established case law. In Aycaguer v. France case, the ECtHR ruled, there was a violation of Article 8 (right to respect for private life) of the Convention by “determining the duration of storage of […] personal data depending on the purpose of the file stored […]”. The Court noted that, to date, no appropriate action was taken on that reservation and that there was currently no provision for differentiating the period of storage. The Court also ruled that the regulations on the storage of DNA profiles did not provide the data subjects with sufficient protection, owing to its duration and the fact that the data could not be deleted. The regulations, therefore, failed to strike a fair balance between the competing public and private interests.

Another concern was that the application was developed by A2Z Advisors LLC and the app’s privacy policy was linked to the company’s website. The landing page of A2Z Advisors LLC, however, did not provide any information on the app’s privacy policy. At the time when the app was launched, AIW reached out for comment via email as per A2Z’s recommendation but never received a response.

Similarly, in the App Store for IOs when clicking on the “App Support” tab, the page once again led to the A2Z company website and once again failed to provide any information related to the App. Instead, the privacy policy was accessible via this link that a user had access to but only after downloading and launching the app. This in itself was contrary to the several articles of the Law on Personal Data.

According to Article 11 of the law, it is required, when collecting personal data, that the owner or operator, notifies the subject about the level of protection of personal data collected and processed in the information system [11.2.3.]; the information on the existence of a certificate of conformity of information systems and state examination [11.2.4.]; and the scope of the intended uses of personal data, including the information system for which the information is to be exchanged [11.2.5.]. However, no such information was provided in the app’s agreement.

The app was also not an open-source code and was licensed under the Ministry of Communication, Transportation, and High Technologies. This is contrary to the requirement [Article 6.22.,] of the Resolution of the Cabinet of Ministers about “Requirements on creation and management of Internet information resources of state bodies”, which requires that open source content management systems should not be used in internet information resources.

FaktYoxla, a fact-checking platform in Azerbaijan concluded after a detailed legal analysis over the license agreement that e-Tebib was not designed in accordance with the national legislation on data privacy. The fact-checking platform, having analyzed the respective case-law of the European Court, the EU Data Protection Directive, and the Council of Europe Treaty 108, concluded that the e-Tebib application contradicted the obligations imposed by international standards.

On July 10, 2020, following widespread privacy concerns and questions over the app’s transparency, changes were made to the terms of the agreement.

Originally users’ information was transferred to third parties, which were not explicitly defined in the agreement. At the time, independent experts and lawyers said this was against Article 32 of Azerbaijan’s state constitution and in violation of Article 8 of the European Convention on Human Rights.  Azerbaijan’s constitution, namely, Article 8, stipulates that no one has a right to collect personal information without an individual’s permission. The convention, on the other hand, refers to respect for privacy. 

***In Copland v. the United Kingdom case (no. 62617/00, ECHR 2007-I), the Court found that it was irrelevant that the data held by the college where the applicant worked was not disclosed or used against her in disciplinary or other proceedings. Just storing the data amounted to an interference with private life.

The updated license agreement said that only under necessary circumstances, and within the normative legal framework personal information may be transferred to third parties. The revised agreement, still, fails to explicitly mention the precise list of institutions considered under third parties.

Fuad Niftaliyev – the head of the app development project later explained that the third parties referred to in the agreement are the Ministry of Health, Tebib, and the Operational Headquarters [set up under the Cabinet of Ministers of the Republic of Azerbaijan]. Niftaliyev clarified that the collected information was stored on the servers operated by the Ministry of Communication and Information, however that too was problematic, given the questionable transparency of the government institutions in Azerbaijan especially as surveillance technology is widely used by the ministries alike.