Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

Anonymous Hacks Security Think Tank Stratfor

Credit card information and data from government agencies and defense firms targeted in Christmas weekend attack.



10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
Anonymous, over the Christmas weekend, hacked Stratfor, potentially compromising data on the security think-tank's clients, which include government agencies and defense firms.

Stratfor warned of the attack--which exposed online names, home addresses, and credit card information of 4,000 of the firm's clients--on its Facebook page Monday.

Stratfor, which gathers intelligence data to provide analysis for a variety of companies, warned clients that their information may have been compromised and provided information on its Facebook page for how they can report any unauthorized access.

However, it denied that a "private client list" Anonymous posted on its Pastebin site was indeed that. Stratfor said the list was merely clients that have purchased some of the firm's publications and is not an exclusive client list.

[ Success of hacktivist attacks have caused many to wonder: Can Anonymous Cripple Critical U.S. Infrastructure? ]

Government and related entities found on that list include the Department of Defense, including the Army and Air Force; the Departments of Justice, Energy, and Treasury; and defense contractors such as DRS Defense Solutions and Total Defense Logistics.

Anonymous claimed responsibility for the attack on its Pastebin page and also kept a running play-by-play of its activities on its Twitter feed. The group said it planned to use the credit cards to steal money to make a variety of Christmas donations.

Indeed, some of Stratfor's clients said they experienced unauthorized transactions on their credit cards, according to a report in the Wall Street Journal.

Along with related groups like LulzSec and Anti-Sec, Anonymous made headlines this year with a spree of high-profile, politically inspired attacks that targeted government agencies, among others. Government contractors Booz Allen Hamilton and IRC Federal were among those targeted in that spree.

The hacktivist groups appear to be gearing up for another wave of attacks. Anonymous warned that the Stratfor attack would be the first in a Christmastime torrent of attacks it's mounting called "LulzXmas."

To help clients who have been affected by the breach, Stratfor said it has retained an identity theft protection and monitoring service and will email clients with information about the service by Wednesday.

Stratfor's website remained offline Tuesday, as it has been since the attack was discovered.

In this new Tech Center report, we profile five database breaches--and extract the lessons to be learned from each. Plus: A rundown of six technologies to reduce your risk. Download it here (registration required).

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
n_dude
50%
50%
n_dude,
User Rank: Apprentice
12/29/2011 | 12:40:12 AM
re: Anonymous Hacks Security Think Tank Stratfor
Looks like things have progressed since this report. Apparently there were credit card details and client emails also compromised including high profile companies and individuals. Apparently Aonymous has denied responsibility for the hack.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5615
PUBLISHED: 2020-08-04
Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2020-5616
PUBLISHED: 2020-08-04
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] fre...
CVE-2020-5617
PUBLISHED: 2020-08-04
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unspecified vectors.
CVE-2020-11583
PUBLISHED: 2020-08-03
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
CVE-2020-11584
PUBLISHED: 2020-08-03
A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.