Lenovo website hacked, Lizard Squad claims responsibility


  • TECH
  • Thursday, 26 Feb 2015

REVENGE FOR SUPERFISH?: Hacking group Lizard Squad claim to be behind the Lenovo website attacks.

China's Lenovo Group Ltd website was hacked, the company said, days after the US government advised Lenovo customers to remove a pre-installed virus-like software, Superfish, on laptops that makes the devices more vulnerable to attacks.

Hacking group Lizard Squad claimed to be behind the attacks, according to its Twitter page.

Lizard Squad has taken credit for several high-profile outages, including attacks that took down Sony Corp's PlayStation Network and Microsoft Corp's Xbox Live network last month. Members of the group have not been identified.

"The domain name service server hosting Lenovo's website was hacked. We do not have any further information at this time to share. We'll update as soon as possible," Lenovo said in a statement to Reuters.

San Francisco-based security firm CloudFlare said hackers transferred the domain to CloudFlare in order to point it to a defacement site.

"As soon as we at CloudFlare noticed, we seized the account and worked with Lenovo to restore service while they worked to recover their domain," Marc Rogers, principal security researcher at CloudFlare, said in an e-mail to Reuters.

Starting 4pm ET (2100 GMT) on Wednesday, visitors to the Lenovo website saw a slideshow of young people looking into webcams and the song Breaking Free playing in the background, according to The Verge, which first reported the breach.

"We're breaking free! Soarin', flyin', there's not a star in heaven that we can't reach!," Lizard Squad posted on its Twitter page, quoting the song from the movie High School Musical.

The hackers also posted a couple of screenshots of an e-mail between Lenovo employees regarding the Superfish software.

The Department of Homeland Security said in an alert that the Superfish program makes users vulnerable to a type of cyber attack known as SSL spoofing, in which remote attackers can read encrypted web traffic, redirect traffic from official websites to spoofs, and perform other attacks.

Rogers also said CloudFlare was able to restore service before Lenovo recovered the domain, suggesting that the outage was probably "quite small".

However, when we tried to access the Malaysian site at 11am, we saw the following message."The Lenovo site you are attempting to access is currently unavailable due to system maintenance. Please try the site again in a few minutes. We apologise for any inconvenience this may create. — Reuters

Limited time offer:
Just RM5 per month.

Monthly Plan

RM13.90/month
RM5/month

Billed as RM5/month for the 1st 6 months then RM13.90 thereafters.

Annual Plan

RM12.33/month

Billed as RM148.00/year

1 month

Free Trial

For new subscribers only


Cancel anytime. No ads. Auto-renewal. Unlimited access to the web and app. Personalised features. Members rewards.
Follow us on our official WhatsApp channel for breaking news alerts and key updates!
   

Next In Tech News

Televisa to merge Sky, cable 'as soon as possible'
EU's Vestager meets French tech firm Mistral AI amid competition concerns
Shein falls under tough EU online content rules as user numbers jump
Google parent Alphabet reclaims spot in $2 trillion valuation club
India's HCLTech misses Q4 revenue estimates
Chipmaker Intel falls as AI competition hurts forecast
Russia's Yandex reports Q1 revenue rise as market awaits spin-off news
Japan to levy big fines with new app rules
Inside Big Tech’s underground race to buy AI training data
Facebook scams demand stricter online rules, Japan lawmaker says

Others Also Read