UPDATED 23:03 EDT / AUGUST 26 2019

SECURITY

14M accounts compromised in hack of web hosting provider Hostinger

The details of about 14 million customers of web hosting provider Hostinger International Ltd. have been compromised by a “security incident” that took place on Aug. 23.

To its credit, Hostinger has been upfront with customers in its disclosure, writing Sunday that one of its servers had been accessed by an unauthorized third party.

“This server contained an authorization token, which was used to obtain further access and escalate privileges to our system RESTful API Server*,” Hostinger wrote. “This API Server* is used to query the details about our clients and their accounts.”

The company added that the application programming interface database, which includes client usernames, emails, hashed passwords, first names and IP addresses, was accessed by the third party. Also, the database table that holds client data has information about 14 million Hostinger users, though the data stolen did not include any financial data.

While not disclosing the method of cryptographic hashing used to protect user passwords, Hostinger is forcing all users to reset their passwords as a “precautionary measure.”

Explaining the methodology of the hack, Stephen Gates, cybersecurity evangelist at security software company Checkmarx Ltd., told SiliconANGLE that the APIs were apparently secured using tokens designed to protect them from unauthorized access.

“The real question is how an attacker gained unauthorized access to a ‘server’ where the tokens were stored,” he said. “The likelihood of an attacker exploiting a software vulnerability to gain access to the server in question is quite high since it’s one of the many possible methods of obtaining a foothold into an organization.”

Even though Hostinger has taken steps to reset passwords, he added, users who employ the same password across multiple accounts would be advised to change those as well.

George Avetisov, chief executive officer of cybersecurity company HYPR Corp., noted that this is yet another unwelcome example of the security issues created by the very nature of password- and shared secret-based user authentication.

“Once this sensitive user information finds its way onto the dark web, it allows other hackers to leverage and weaponize it against more unrelated enterprises in credential stuffing attacks which cause all kinds of disruptions from financial fraud via account takeover to more mass data breaches to nation-state espionage,” Avetisov added. “Unfortunately, until enterprises realize the inherent lack of security of passwords and shared secrets, we, the users, will continue to experience the widespread dangers of keeping these 60-year-old systems in place.”

Image: Hostinger

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.