Menu
Browse

Cyber Incident Victim: Vice Media

Date:

Jul 2014

Location:

Russia

Summary

A popular news website was compromised by a hacker or group using the alias W0rm, later identified as a single individual called Rev0lver, who exploited a security vulnerability to access its content management system. The breach exposed user email addresses and hashed passwords, though the credentials remained unusable without decryption; the vulnerability was subsequently patched and affected passwords reset. The attackers also claimed to have infiltrated other major media outlets, offering stolen databases for sale in Bitcoin, but asserted their primary intent was to expose security weaknesses rather than profit from the data. Investigations revealed connections to prior incidents targeting prominent technology news platforms.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 5 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On July 21, 2014, a hacker or group identifying as W0rm claimed via Twitter to have compromised Vice.com and The Wall Street Journal's websites, accompanied by screenshots as evidence. The threat actor announced intentions to sell each stolen database for one Bitcoin. Vice.com confirmed the following day that an exploit had allowed unauthorized access to its content management system (CMS) user list, which contained email addresses and cryptographically hashed passwords. The company emphasized that the hashed passwords remained unusable without decryption and stated no website defacement or user account compromises occurred beyond the CMS access. Vice.com patched the vulnerability, reset all affected passwords as a precaution, and characterized the incident as limited to the CMS user credentials. The Wall Street Journal's publisher, Dow Jones & Company, did not publicly confirm or deny the alleged breach at the time of reporting, though the article noted a separate recent compromise of the newspaper’s Facebook account involving a false post about Air Force One.

Cyber Incident Image

W0rm had previously targeted technology news site CNET on July 12, 2014, using identical tactics: tweeting screenshots of breached data and offering the database for one Bitcoin. CNET acknowledged the attack two days later, confirming theft of usernames, email addresses, and encrypted passwords for over one million users. During a Twitter exchange with CNET, W0rm claimed its primary objective was highlighting security vulnerabilities rather than profiting from data decryption or sales. Subsequent investigation by IntelCrawler CEO Andrew Komarov, reported in an update to the original article, identified W0rm as a lone individual using the alias Rev0lver, contradicting initial characterizations of the actor as a group. The Vice.com breach represented part of a pattern targeting media organizations, with W0rm leveraging public disclosures via social media to amplify attention to the intrusions.

Sources
Sources available to members
1 source