CSIDB logo
Incident

Vice Media

Incident posture

Attack window
Jul 2014
Location
Russia
Status
Historical
CIA posture
Available to members
Updated
2026-01-18 15:15

Linked entities

Victim
Vice Media
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A popular news website was compromised by a hacker or group using the alias W0rm, later identified as a single individual called Rev0lver, who exploited a security vulnerability to access its content management system. The breach exposed user email addresses and hashed passwords, though the credentials remained unusable without decryption; the vulnerability was subsequently patched and affected passwords reset. The attackers also claimed to have infiltrated other major media outlets, offering stolen databases for sale in Bitcoin, but asserted their primary intent was to expose security weaknesses rather than profit from the data. Investigations revealed connections to prior incidents targeting prominent technology news platforms.

Motives

Detailed motive labels are available to members.

5 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 21, 2014, a hacker or group identifying as W0rm claimed via Twitter to have compromised Vice.com and The Wall Street Journal's websites, accompanied by screenshots as evidence. The threat actor announced intentions to sell each stolen database for one Bitcoin. Vice.com confirmed the following day that an exploit had allowed unauthorized access to its content management system (CMS) user list, which contained email addresses and cryptographically hashed passwords. The company emphasized that the hashed passwords remained unusable without decryption and stated no website defacement or user account compromises occurred beyond the CMS access. Vice.com patched the vulnerability, reset all affected passwords as a precaution, and characterized the incident as limited to the CMS user credentials. The Wall Street Journal's publisher, Dow Jones & Company, did not publicly confirm or deny the alleged breach at the time of reporting, though the article noted a separate recent compromise of the newspaper’s Facebook account involving a false post about Air Force One.

W0rm had previously targeted technology news site CNET on July 12, 2014, using identical tactics: tweeting screenshots of breached data and offering the database for one Bitcoin. CNET acknowledged the attack two days later, confirming theft of usernames, email addresses, and encrypted passwords for over one million users. During a Twitter exchange with CNET, W0rm claimed its primary objective was highlighting security vulnerabilities rather than profiting from data decryption or sales. Subsequent investigation by IntelCrawler CEO Andrew Komarov, reported in an update to the original article, identified W0rm as a lone individual using the alias Rev0lver, contradicting initial characterizations of the actor as a group. The Vice.com breach represented part of a pattern targeting media organizations, with W0rm leveraging public disclosures via social media to amplify attention to the intrusions.

Sources

Sources available to members: 1 source.

CSIDB