February 13th, 2014, 22:52 PM
Hackers circulate thousands of FTP credentials, New York Times among those hit
Hackers are circulating credentials for thousands of FTP sites and appear to have compromised file transfer servers at The New York Times and other organizations, according to a security expert.
The hackers obtained credentials for more than 7,000 FTP sites and have been circulating the list in underground forums, said Alex Holden, chief information security officer for Hold Security, a Wisconsin-based company that monitors cyberattacks.
In some cases, hackers used the credentials to access FTP servers and upload malicious files, including scripts in the PHP programming language. In other instances, they placed files on FTP servers that incorporate malicious links directing people to websites advertising work-at-home schemes and other scams.
An FTP server run by The New York Times was among those affected, and hackers uploaded several files to the server, Holden said.
Eileen Murphy, head of communications for the Times, said via email the company was “taking steps to secure” its network and could not comment further due to an investigation.
UNICEF, another organization whose credentials appear on the list, did not confirm it had been compromised but said it had disabled the FTP application in question, which it said was part of a system no longer in use.
UNICEF has been moving to a “more robust” content management platform and the organization uses third parties to check its infrastructure for vulnerabilities, spokeswoman Sarah Crowe said via email.
“It is therefore very rare for us to witness such a breach,” she said.
Not all the credentials on the list are valid but a sampling showed that many of them work, said Holden, whose research credits include discovering large data breaches affecting the retailer Target and software vendor Adobe Systems.
Holden said he did not know the name of the group responsible for the FTP attacks.