Suspicious event hijacks Amazon traffic for 2 hours, steals cryptocurrency

(credit: Amazon)

Amazon lost control of a small number of its cloud services IP addresses for two hours on Tuesday morning when hackers exploited a known Internet-protocol weakness that let them to redirect traffic to rogue destinations. By subverting Amazon’s domain-resolution service, the attackers masqueraded as cryptocurrency website MyEtherWallet.com and stole about $ 150,000 in digital coins from unwitting end users. They may have targeted other Amazon customers as well.

The incident, which started around 6 AM California time, hijacked roughly 1,300 IP addresses, Oracle-owned Internet Intelligence said on Twitter. The malicious redirection was caused by fraudulent routes that were announced by Columbus, Ohio-based eNet, a large Internet service provider that is referred to as autonomous system 10297. Once in place, the eNet announcement caused Hurricane Electric and possibly Hurricane Electric customers and other eNet peers to send traffic over the same unauthorized routes. The 1,300 addresses belonged to Route 53, Amazon’s domain name system service

In a statement, Amazon officials wrote: “Neither AWS nor Amazon Route 53 were hacked or compromised. An upstream Internet Service Provider (ISP) was compromised by a malicious actor who then used that provider to announce a subset of Route 53 IP addresses to other networks with whom this ISP was peered. These peered networks, unaware of this issue, accepted these announcements and incorrectly directed a small percentage of traffic for a single customer’s domain to the malicious copy of that domain.”

Read 10 remaining paragraphs | Comments

Biz & IT – Ars Technica

China-Made Huawei Phones Sold at US Bases Could Be Spying on American Soldiers

  1. China-Made Huawei Phones Sold at US Bases Could Be Spying on American Soldiers  The Epoch Times
  2. Huawei & US Government Timeline: A Standoff Years In The Making  Android Headlines
  3. Full coverage

china espionage – read more

The battlefield of information warfare has been leveled

  1. The battlefield of information warfare has been leveled  The Hill
  2. Kremlin: US, Russia aiming ‘cyber’ pistols at each other  Washington Examiner
  3. Full coverage

cyber warfare news – read more

Ride-hailing app Careem reveals data breach affecting 14 million people

  1. Ride-hailing app Careem reveals data breach affecting 14 million people  TechCrunch
  2. Careem Data Breach Exposes Data Of 14 Million Users  Tom’s Hardware
  3. Dubai’s Careem admits to data breach, affects 14 million customers  ArabianBusiness.com
  4. Careem | Crunchbase  Crunchbase
  5. Who Needs Judgment When You’ve Got Data? You Do.  ValueWalk
  6. Full coverage

data breach – read more