Menu
Browse

Cyber Incident Victim: Fast Company

Date:

Sep 2022

Location:

United States of America

Summary

Fast Company experienced multiple website breaches involving unauthorized content modifications and push notifications. Attackers initially defaced the homepage with offensive messages, then compromised the content management system using a default password on a WordPress instance to create administrator accounts. This access enabled distribution of racist alerts through Apple News, prompting the service to disable the organization's channel. The hacker, claiming affiliation with a known forum group, publicly shared details of the intrusion method after the incidents.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On September 25, 2022, Fast Company’s website was initially breached when its homepage was defaced with stories containing obscene and racist language. The defacement included references to "Hacked by Vinny Troia" and the alias "Thrax," indicating involvement from members of the Breached hacking community. Fast Company temporarily took its website offline to address the incident but restored it after remediation. Two days later, on September 27 at approximately 8:00 PM EST, attackers breached the site again, exploiting access to the company’s content management system (CMS) to push two racist and obscene notifications through Apple News. These notifications were sent to Fast Company’s Apple News subscribers within one minute of each other, prompting immediate user reports on social media platforms like Twitter. Apple News disabled Fast Company’s channel shortly afterward to prevent further malicious notifications. Fast Company again took its website offline and replaced it with a statement confirming both breaches.

Cyber Incident Image

The attacker, using the alias 'Thrax,' later claimed responsibility on the Breached hacking forum, alleging they gained access via a WordPress instance with a default password. After compromising the CMS, the threat actor created administrator accounts and leveraged stored tokens to distribute unauthorized Apple News alerts. The breaches caused operational disruptions, requiring repeated website takedowns, and reputational damage due to the distribution of offensive content. Fast Company’s public statement acknowledged both the Sunday website defacement and the Tuesday Apple News compromise but did not disclose additional technical details about the vulnerabilities exploited. The incident highlighted risks associated with third-party integrations like Apple News and CMS security practices, though no data theft or lateral network movement was confirmed in the available reports.

Sources
Sources available to members
2 sources