Fox-IT reveals hackers hijacked its DNS records, spied on clients' files

  • 14 December 2017
  • 0 replies
  • 175 views

Userlevel 7
Badge +54
Dutch security firm was not protecting its DNS entries with two-factor authentication.
 
14th December 2017  By Graham Cluley

 


 
Kudos to Dutch security firm Fox-IT which has gone public about a cyber attack it suffered in September:
 
"In the early morning of September 19 2017, an attacker accessed the DNS records for the Fox-IT.com domain at our third party domain registrar. The attacker initially modified a DNS record for one particular server to point to a server in their possession and to intercept and forward the traffic to the original server that belongs to Fox-IT. This type of attack is called a Man-in-the-Middle (MitM) attack. The attack was specifically aimed at ClientPortal, Fox-IT’s document exchange web application, which we use for secure exchange of files with customers, suppliers and other organizations. We believe that the attacker’s goal was to carry out a sustained MitM attack."
 
Full Article.

0 replies

Be the first to reply!

Reply