Results 1 to 8 of 8

Thread: Anime News Network Hacked?

  1. #1

  2. #2
    Vampiric Minion Kraco's Avatar
    Join Date
    Oct 2005
    Location
    :noitacoL
    Age
    46
    Posts
    17,964
    Nasty business.

  3. #3
    They're calling it "technical problems" on Facebook:
    https://www.facebook.com/animenewsne...00549403299533


    Kinda disappointed on their response and lack of information. This is a situation that could potentially damage their user-base, the least they could do is be honest so that their members can take their precautionary actions if they deem it necessary.

  4. #4
    Working domain right now:

    http://www.animenewsnetwork.cc/


    Edit:

    Last night, Anime News Network suffered a pretty major hack, one that took down our original domain (www.animenewsnetwork.com) and compromised our email domain — meaning you can't reach us through any animenewsnetwork.com email accounts for the time being. Right now, you can't contact any of our staff using an animenewsnetwork.com email; it won't reach us at this moment.

    Through this process, the hacker also compromised some of our Twitter accounts, like @anime and @animenewsnet as well as a handful of personal staff accounts like @ANN_Ed and @ANNZac. We're still working on cleaning all this up – it's a pretty involved process that may take some time, but for now we're live at AnimeNewsNetwork.cc. Please spread the word on social media, as this is our new (temporary) home for the time being! We'll be back with more updates as things progress – we apologize for the inconvenience, and shall rise again soon.


    http://www.animenewsnetwork.cc/site-...etwork/.119882
    Last edited by Munsu; Tue, 08-08-2017 at 12:15 PM.

  5. #5
    On August 7th, a hacker contacted my cell phone company to initiate the transfer of my number to a new sim-card. The hacker called 3 times, and each time they failed the security authentication. After three failures, they tried my cell phone company's online chat feature where they were able to convince a customer service representative (CSR) to make the transfer. At this time, it isn't clear to me if the CSR was negligent, or if the hackers did manage to exploit a weakness in my cellphone company's system, or my account, however the evidence currently suggests that it was a bad decision on the CSR's part that contributed to the successful hack.

    Finding my phone number isn't particularly hard. It's on my business cards, it's on every e-mail I send, and it was in ANN's whois information.

    With control over my cellphone number, the hackers were able to exploit “account recovery” features to gain access to one of my e-mail accounts. Of course, the e-mail account they targeted was the one used for ANN's domain registrar. Once they had my e-mail account, they were able to use it to retrieve the password for ANN's registrar account and then transfer the ANN domain to a registrar in Hong Kong.

    They also used my phone number to recover the password for ANN's @Anime twitter account, delete the account, and then rename their own account to @Anime.

    With control of the AnimeNewsNetwork.com domain, the hackers are now theoretically able to read any e-mail sent to e-mail addresses @ AnimeNewsNetwork.com, and we have reason to believe that they are doing this. So don't send e-mail to our old addresses.

    Aside from this, the hackers never compromised our servers. They never gained access to anything on our server, no passwords, user info, or anything was compromised.


    http://www.animenewsnetwork.cc/site-...hacked/.120038

  6. #6
    Vampiric Minion Kraco's Avatar
    Join Date
    Oct 2005
    Location
    :noitacoL
    Age
    46
    Posts
    17,964
    I wonder if somebody at the phone company will find themselves without a job very soon. Not that those would be all too desirable job titles anyway, so I imagine most there aren't planning to stick for life anyway. Aside from that, the phone company will most likely be made to pay all the expenses this case has and will produce.

  7. #7
    Quote Originally Posted by Kraco View Post
    I wonder if somebody at the phone company will find themselves without a job very soon. Not that those would be all too desirable job titles anyway, so I imagine most there aren't planning to stick for life anyway. Aside from that, the phone company will most likely be made to pay all the expenses this case has and will produce.
    It's an interesting case study. All the protection in the world won't prevent human error.

  8. #8
    Family Friendly Mascot Buffalobiian's Avatar
    Join Date
    Sep 2006
    Location
    Amaburi
    Age
    34
    Posts
    18,809
    It was "human error" in that they decided to trust the caller as being legit and give them access to their account again.

    One needs to consider the situation where the caller is the legitimate victim of losing their phone and trying to regain access. In such a case, personal details verification should obviously be asked for. How much would be the question.

    I suspect the company did not have such a policy put in place previous to this.

    If it's not Isuzu-chan Mii~

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •