SKIP TO MAIN CONTENT

NYT attack result of Indian spear phishers

The cyberattack which crashed The New York Times website on Wednesday morning resulted from a "spear phishing" attack from Indian hackers.

2 min read

Published

Updated

Source: AAP


Skip to article content

The cyberattack which brought down The New York Times website was the result of "spear phishing" by attackers in India, according to Melbourne IT, the Australian web hosting firm whose defences were breached.

Hackers claiming to be from the Syrian Electronic Army targeted the Times on Wednesday morning Australian time, bringing it down for several hours.

They also targeted twimg.com, a domain used by Twitter for image serving.

Using a valid username and password, hackers accessed the account of one of Melbourne IT's US clients, who resell web domains to companies including The New York Times.

Once inside, the hackers altered the domain coding to direct users away from the site.

News that makes sense

Your trusted source for staying up-to-date with the world around you. Get free daily news updates and analysis, straight to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Theo Hnarakis, Melbourne IT's chief executive, said the attackers got access to its US client's username and password through a "spear phishing" campaign.

Phishing is any attempt to acquire sensitive information via email by masquerading as a trustworthy source.

Spear phishing is when the attempts are directed at specific people or companies - in this case, Melbourne IT's US client, whom Mr Hnarakis would not name.

"The attack has been sent to a variety of staff of our reseller," he told AAP.

"A few of those staff have responded inadvertently."

He said the attack came from an internet service provider based in India.

Melbourne IT's investigation so far pointed to an attack from the Syrian Electronic Army, who support president Bashar al-Assad.

Mr Hnarakis said he was confident the threat had been neutralised and that other web sites served by Melbourne IT were safe.

The company has shut down all email addresses thought to have been breached during the attack.

"All passwords have been changed, the right blocks have been established, so we're fairly confident this won't occur again."

He said all companies were susceptible to phishing attacks.

On its website, Melbourne IT claims it has "a client list of over 500,000 Australian and international businesses".


Get SBS News straight to your inbox

Sign up now for daily news from Australia and around the world. You can also subscribe to Insight's weekly newsletter for in-depth features and first-person stories.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Follow SBS News

Download our apps

Listen to our podcasts

Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS

SBS World News

Take a global view with Australia's most comprehensive world news service

Stream now

Watch the latest news videos from Australia and across the world