Thursday, April 22, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Security

GoDaddy staff fall prey to social engineering scam in cryptocurrency exchange attack wave

November 23, 2020
in Internet Security
GoDaddy staff fall prey to social engineering scam in cryptocurrency exchange attack wave
586
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

GoDaddy employees were exploited to facilitate attacks on multiple cryptocurrency exchanges through social engineering and phishing. 

Staff at the domain name registrar were subject to a social engineering scam that duped them into changing email and registration records, used to conduct attacks on other organizations. 

You might also like

Instagram debuts new tool to stop abusive message salvos made through new accounts

Facebook cracks down on posts urging violence, mockery ahead of Chauvin verdict in George Floyd case

New Australian cyber package includes AU$37.5m Indo-Pacific investment

As reported by security expert Brian Krebs last week, GoDaddy confirmed that the scam led to a “small number” of customer domain names being ‘modified” earlier this month.

Starting in mid-November, fraudsters ensured that email and web traffic intended for cryptocurrency exchanges was redirected. Liquid.com and the NiceHash cryptocurrency trading posts were impacted, and it is suspected that other exchanges may also have been affected. 

See also: Cryptocurrency platform dangles ‘bug bounty’ carrot to hacker who stole $2 million

According to Liquid CEO Mike Kayamori, a security incident on November 13 was caused by GoDaddy incorrectly transferring control of an account related to the firm’s core domain names. 

“This gave the actor the ability to change DNS records and in turn, take control of a number of internal email accounts,” Kayamori said in a blog post. “In due course, the malicious actor was able to partially compromise our infrastructure, and gain access to document storage.”

Liquid.com contained the attack after discovery, and while the attacker may have accessed user emails, names, addresses, and encrypted passwords, client funds were accounted for. 

In NiceHash’s case, the company blamed “technical issues” at GoDaddy resulting in “unauthorized access” to domain settings, leading to the DNS records for nicehash.com being changed. 

This attack occurred on November 18. NiceHash responded quickly, freezing all wallet activity to prevent any loss of user cryptocurrency. Withdrawals were suspended for 24 hours while an internal audit took place and normal service has since resumed. 

NiceHash says that it does not look like user information was exposed or compromised, but urges caution if users receive links or suspicious emails claiming to be from the cryptocurrency exchange. 

The company also recommended that users change their passwords and enable two-factor authentication (2FA) to be on the safe side.

CNET: What’s the best cheap VPN? We found 3 good options

Speaking to Krebs, NiceHash founder Matjaz Skorjanc added that the attackers attempted to force password resets on third-party services, including Slack, but NiceHash was able to fend off these attempts. 

A GoDaddy spokesperson said the domain registrar “immediately locked down the accounts involved in this incident, reverted any changes that took place to accounts, and assisted affected customers with regaining access to their accounts.”

TechRepublic: It’s time for banks to rethink how they secure customer information

The spokesperson added that as “threat actors become increasingly sophisticated and aggressive in their attacks, we are constantly educating employees about new tactics that might be used against them.”

In May, GoDaddy reported a security breach in which an individual was able to access SSH accounts within the firm’s hosting infrastructure without permission. GoDaddy said there was no evidence of tampering that would impact customers, but security bolt-ons would be provided for a year, for free, to anyone affected. 

Previous and related coverage


Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0


Credit: Zdnet

Previous Post

IBM takes the next step with Cloud Pak for Data

Next Post

Detect Generator Functions with JavaScript

Related Posts

Instagram debuts new tool to stop abusive message salvos made through new accounts
Internet Security

Instagram debuts new tool to stop abusive message salvos made through new accounts

April 21, 2021
Facebook cracks down on posts urging violence, mockery ahead of Chauvin verdict in George Floyd case
Internet Security

Facebook cracks down on posts urging violence, mockery ahead of Chauvin verdict in George Floyd case

April 21, 2021
New Australian cyber package includes AU$37.5m Indo-Pacific investment
Internet Security

New Australian cyber package includes AU$37.5m Indo-Pacific investment

April 21, 2021
Google issues Chrome update patching seven security vulnerabilities
Internet Security

Google issues Chrome update patching seven security vulnerabilities

April 21, 2021
Multi-factor authentication: Use it for all the people that access your network, all the time
Internet Security

Multi-factor authentication: Use it for all the people that access your network, all the time

April 21, 2021
Next Post
How to Change the WordPress Admin Login Logo

Detect Generator Functions with JavaScript

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Machine Learning Tacks Evolution of COVID-19 Misinformation
Machine Learning

Machine Learning Tacks Evolution of COVID-19 Misinformation

April 22, 2021
How AI Is Disruptive Innovation For OCR | by Infrrd | Apr, 2021
Neural Networks

How AI Is Disruptive Innovation For OCR | by Infrrd | Apr, 2021

April 22, 2021
Instagram debuts new tool to stop abusive message salvos made through new accounts
Internet Security

Instagram debuts new tool to stop abusive message salvos made through new accounts

April 21, 2021
Improve Your Cyber Security Posture by Combining State of the Art Security Tools
Internet Privacy

Improve Your Cyber Security Posture by Combining State of the Art Security Tools

April 21, 2021
6 Ways AI is Changing The Learning And Development Landscape
Data Science

6 Ways AI is Changing The Learning And Development Landscape

April 21, 2021
Weekly NFT roundup April 14-20: Real-world applications grow through postage and insurance
Blockchain

Weekly NFT roundup April 14-20: Real-world applications grow through postage and insurance

April 21, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Machine Learning Tacks Evolution of COVID-19 Misinformation April 22, 2021
  • How AI Is Disruptive Innovation For OCR | by Infrrd | Apr, 2021 April 22, 2021
  • Instagram debuts new tool to stop abusive message salvos made through new accounts April 21, 2021
  • Improve Your Cyber Security Posture by Combining State of the Art Security Tools April 21, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates