Cyber Incident Victim: keepyourlinks.com
Date:
Dec 2015
Location:
United States of America
Summary
C0d3c1t4d3l hacks keepyourlinks.com and dumps 4,586 usernames and clear text passwords.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Description of the incident: On 16th December 2015, a cyber attack occurred on KeepYourLinks.com, a website that provides link management and analytics services to businesses. The attacker, identified as Cod3c1t4d3l, used an exfiltration technique from the application server to steal sensitive data from the company's database. According to the article published on Pastebin, the attacker was able to gain unauthorized access to the system by exploiting a vulnerability in the website's security measures. Once inside, they were able to move laterally within the network and extract sensitive information such as login credentials for other systems, database passwords, and even source code from the application server. The attack was discovered when an employee noticed unusual activity on the system and alerted management immediately. An investigation was launched, and it was found that the attacker had been present in the system for several days before being detected. KeepYourLinks.com took immediate action to contain the incident and prevent further damage by isolating the affected systems and notifying relevant authorities. The company also worked with security experts to conduct a thorough analysis of the attack and implement additional security measures to prevent similar incidents in the future.
