Site icon Liquidmatrix Security Digest

Hackers Load Malware Onto Mercury Music Award Site

Oops. It turns out that our web hosting company has been pwned.

Hackers have been able to load malware onto the official Mercury music awards site, as well as hundreds of other sites, after breaking into the systems of US-based hosting firm DreamHost.

DreamHost blamed a security flaw in its web control panel software for an attack that allowed hackers to compromise a “very small subset” of user accounts. Affected customers have been notified by email. DreamHost said only web content – not credit card or billing information – was compromised.

In a statement published Wednesday, DreamHost said: “The security flaw allowed the attackers to log into our customer web control panel with the access privileges of another user. From our web panel they were able to access individual user password information. The attackers also attempted to gain access to our central database and billing information but were ultimately thwarted in that attempt. No credit card information or customer personal information was obtained.”

DreamHost takes care of more than 500,000 domains, according to the firm. An email sent by DreamHost to its customers on 5 June, said approximately 3,500 separate FTP accounts were compromised by the hack. DreamHost has advised its customers to change their FTP account passwords immediately. The firm has promised to update concerned punters about the steps it is taking to prevent a repetition.

After talking with Dreamhost it appears that we here at Liquidmatrix are not among the affected. That being said, we changed our passwords just the same.

🙂

Oh, and here is the statement from Dreamhost.

Article Link (thx Myrcurial)

[tags]Dreamhost Hacked, Breach, Malware[/tags]

Exit mobile version