Ad network compromise led to rogue page redirects on Reuters site

The Syrian Electronic Army compromised a third-party widget to redirect some Reuters.com visitors to a defacement page

Users who accessed some stories on the Reuters website Sunday were redirected to a message from hackers criticizing the news agency's coverage of Syria.

The attack was carried out by the Syrian Electronic Army (SEA), a hacker group that's publicly supportive of Syrian President Bashar al-Assad and his government and which has targeted various media organizations in the past, including IDG.

"Stop publishing fake reports and false articles about Syria! UK government is supporting the terrorists in Syria to destroy it. Stop spreading its propaganda," the rogue message seen by some Reuters.com visitors read.

According to a security researcher named Frederic Jacobs, SEA did not actually hack into Reuters' website, but injected the redirect code into it through a New York-based advertising network called Taboola.

"It is still unclear how Taboola was compromised but given SEA's track record, phishing would be my first guess," Jacobs said Sunday in a blog post.

The value of compromising Taboola is actually greater for SEA than compromising Reuters, because according to the ad network's site, it delivers its recommendations to 350 million unique visitors each month and has partnerships with high-profile media sites including Time.com, USA Today, the New York Times, BBC, TMZ, The Hollywood Reporter, Politico.com, Examiner and others.

Any of Taboola's clients could have been attacked in a similar way to Reuters, Jacobs said.

Taboola acknowledged being the source of the compromise and said that SEA hacked one of its widgets used on Reuters.com.

The security breach lasted from 7 a.m. to 8 a.m. EDT Sunday with no suspicious activity being detected after that time, Adam Singolda, Taboola's CEO, said in a blog post.

"While we use 2-step authentication, our initial investigation shows the attack was enabled through a phishing mechanism," Singolda said. "We immediately changed all access passwords, and will continue to investigate this over the next 24 hours."

SEA's preferred method of attack is spear phishing -- a targeted form of phishing. When the group doesn't succeed at compromising an employee from its targeted organization it goes after that organization's partners and various service providers.

In August 2013 SEA used spear phishing to compromise a reseller account at Melbourne IT, an Australian domain registrar and IT services company. The attack allowed the hacker group to alter the DNS (Domain Name System) records for several domain names including nytimes.com, sharethis.com, huffingtonpost.co.uk, twitter.co.uk and twimg.com and temporarily redirect those websites to a server under its control.

In February the group gained access to the administration panel of a San Francisco-based company called MarkMonitor that manages domain names on behalf of large enterprises. This allowed them to change the WHOIS information for facebook.com, changing the domain's contact address to Damascus, Syria.

In April, SEA managed to redirect users trying to access the RSA Conference website to a defacement page. The attack was carried out through Lucky Orange, a real-time Web analytics provider used by the RSA Conference website.

"If you're using 3rd party analytics or advertising networks, your website's security relies on the weakest of those since any of them is able to take over your website (and potentially steal your user's data or trick them into installing malware)," Jacobs said. "Websites like Reuters use more than 30 of these services and thus expose a considerable attack surface."

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags intrusiononline safetyThomson ReuterssecurityMarkMonitorAccess control and authenticationMelbourne IT

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?