CSIDB logo
Incident

Hover

Incident posture

Attack window
Aug 2015
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-02-01 05:09

Linked entities

Victim
Hover
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A domain registrar experienced potential unauthorized access to a system, prompting a precautionary password reset for all users. The company confirmed no evidence of account compromise but mandated resets via password recovery to mitigate risks, citing extreme caution despite limited public disclosure of incident details.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On August 5, 2015, domain registrar Hover, a subsidiary of Tucows, notified users via email of a security incident involving potential unauthorized access to one of its internal systems. The company stated this access "could have occurred" during a brief, unspecified timeframe but emphasized no evidence indicated actual compromise of user accounts. As a precautionary measure, Hover proactively reset all customer passwords, locking users out of their accounts until they completed a password reset process. Affected customers were instructed to use the "I forgot my password" feature on Hover's login page to regain access. The company characterized its response as erring on the side of "extreme caution" given the theoretical risk, though it provided no technical details regarding the nature of the system exposure, potential attack vectors, or forensic findings.

The password reset action impacted all Hover account holders, requiring immediate credential changes regardless of individual risk indicators. Hover's website displayed a prominent password recovery link but offered no additional public statements or incident details beyond the initial email, creating what external observers described as an information vacuum. While the company maintained there was no proof of account breaches, security analysts noted the theoretical risk extended beyond Hover if customers reused compromised credentials across multiple services. The incident drew criticism for lacking transparency regarding the affected system's function, exposure duration, or remediation steps beyond password resets. No data categories beyond account access credentials were referenced as potentially exposed, and Hover did not disclose whether multi-factor authentication adoption rates influenced their response strategy.

Sources

Sources available to members: 1 source.

CSIDB