CSIDB logo
Incident

Endurance International Group

Incident posture

Attack window
Mar 2015
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-02-02 20:04

Linked entities

Victim
Endurance International Group
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Mar 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Syrian Electronic Army compromised control systems of multiple hosting services under Endurance Group, including Justhost, alleging support for terrorist websites such as Islam-Army.com. Attackers accessed administrative infrastructure and briefly hijacked Bluehost's Twitter account, threatening future disruptions by altering DNS settings. The parent company regained social media control within hours, characterizing the incident as cybervandalism while implementing security enhancements, though operational impacts beyond the Twitter breach remained unspecified.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 31, 2015, the Syrian Electronic Army (SEA), a pro-Assad hacker group, publicly claimed responsibility for compromising the control systems of five web hosting services under the Endurance International Group: Bluehost, Justhost, HostGator, Fastdomain, and Hostmonster. The attackers alleged these companies supported terrorist websites, specifically citing Islam-Army.com—a site registered through Fastdomain and hosted on Bluehost servers—as an example of prohibited content. The SEA breached administrative control panels, enabling potential widespread disruption, though the full extent of operational damage remained unconfirmed. Concurrently, the group hijacked Bluehost’s official Twitter account, posting messages aligned with their claims before Endurance Group regained control hours later. The hackers published screenshots of compromised hosting dashboards as proof of access and threatened future attacks involving DNS manipulation to take all hosted websites offline.

Endurance Group acknowledged the Twitter compromise in a statement, classifying it as “cybervandalism” and confirming account recovery within hours. The company emphasized ongoing investigations and implementation of “appropriate security measures” to safeguard its platforms but did not disclose technical details about the control system breaches or confirm data or service impacts. None of the affected hosting brands commented publicly via their Twitter channels following the incident. The SEA reiterated its intent to target infrastructure supporting perceived terrorist entities while denying financial ties to the Assad regime. Islam-Army.com became inaccessible post-attack, though archived copies reflected the SEA’s defacement message. No further disruptions to Endurance Group’s services or additional DNS changes were verified at the time of reporting.

Sources

Sources available to members: 1 source.

CSIDB