UPDATED 23:03 EDT / AUGUST 26 2019

SECURITY

14M accounts compromised in hack of web hosting provider Hostinger

The details of about 14 million customers of web hosting provider Hostinger International Ltd. have been compromised by a “security incident” that took place on Aug. 23.

To its credit, Hostinger has been upfront with customers in its disclosure, writing Sunday that one of its servers had been accessed by an unauthorized third party.

“This server contained an authorization token, which was used to obtain further access and escalate privileges to our system RESTful API Server*,” Hostinger wrote. “This API Server* is used to query the details about our clients and their accounts.”

The company added that the application programming interface database, which includes client usernames, emails, hashed passwords, first names and IP addresses, was accessed by the third party. Also, the database table that holds client data has information about 14 million Hostinger users, though the data stolen did not include any financial data.

While not disclosing the method of cryptographic hashing used to protect user passwords, Hostinger is forcing all users to reset their passwords as a “precautionary measure.”

Explaining the methodology of the hack, Stephen Gates, cybersecurity evangelist at security software company Checkmarx Ltd., told SiliconANGLE that the APIs were apparently secured using tokens designed to protect them from unauthorized access.

“The real question is how an attacker gained unauthorized access to a ‘server’ where the tokens were stored,” he said. “The likelihood of an attacker exploiting a software vulnerability to gain access to the server in question is quite high since it’s one of the many possible methods of obtaining a foothold into an organization.”

Even though Hostinger has taken steps to reset passwords, he added, users who employ the same password across multiple accounts would be advised to change those as well.

George Avetisov, chief executive officer of cybersecurity company HYPR Corp., noted that this is yet another unwelcome example of the security issues created by the very nature of password- and shared secret-based user authentication.

“Once this sensitive user information finds its way onto the dark web, it allows other hackers to leverage and weaponize it against more unrelated enterprises in credential stuffing attacks which cause all kinds of disruptions from financial fraud via account takeover to more mass data breaches to nation-state espionage,” Avetisov added. “Unfortunately, until enterprises realize the inherent lack of security of passwords and shared secrets, we, the users, will continue to experience the widespread dangers of keeping these 60-year-old systems in place.”

Image: Hostinger

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.