Viber admits to swallowing 'Syrian Electronic Army' phishing bait

Filed Under: Data loss, Denial of Service, Featured, Phishing, Security threats

The Syrian Electronic Army (SEA) claimed on Tuesday that it had taken over the support page for instant messaging/VoIP service Viber.

SEA post

The Syrian Electronic Army hacked today the website and the database of the Israeli-based "Viber" app. The SEA downloaded some of the app databases and after we gain access to some systems of that app, it was clear for us that the purpose of this app is spying and tracking of its users. The SEA hacked the support page of the Viber app and uploaded screenshots of one of the app systems in addition to the app administrators names/phone numbers Viber itself announced that the claims are overblown and that only two minor systems were breached - a customer support panel and a support administration system.

TechCrunch published a statement from Viber, which said that no sensitive user data was breached.

Viber didn't confirm that the SEA was responsible for the breach.

The company blamed the takeover on a phishing attack that succeeded against an employee.

Viber's statement:

Today the Viber Support site was defaced after a Viber employee unfortunately fell victim to an email phishing attack. The phishing attack allowed access to two minor systems: a customer support panel and a support administration system. Information from one of these systems was posted on the defaced page.

It is very important to emphasize that no sensitive user data was exposed and that Viber’s databases were not “hacked”. Sensitive, private user information is kept in a secure system that cannot be accessed through this type of attack and is not part of our support system.

We take this incident very seriously and we are working right now to return the support site to full service for our users. Additionally, we want to assure all of our users that we are reviewing all of our policies to make sure that no such incident is repeated in the future.

Initially, the defaced online helpdesk page bore a blue banner that read "Hacked by the Syrian Electronic Army."

According to E Hacking News, the defaced support page advised visitors that the app is "designed for spying and tracking."

The defaced page read:

Dear All Viber Users,

The Israeli-based 'Viber' is spying and tracking you

We weren't able to hack all Viber systems, but most of it is designed for spying and tracking

The SEA also put up a screenshot of what looked like an internal database showing phone numbers, device UDID, country, IP address, operating system and version, first registration to Viber, and what version of Viber they use.

As Graham Cluley noted, the phone numbers shown in the screenshot all had the international dialing code of 963, which is Syria's code.

The SEA also Tweeted that Viber users had best delete the app:

Warning: If you have "Viber" app installed we advise you to delete it

In recent months, the SEA has hacked a host of sites, including Financial Times blogs, satirical news site The Onion, Guardian Twitter accounts, National Public Radio in the US, and the BBC Weather's Twitter account, among other Twitter accounts.

Viber logoAs of Wednesday morning, Viber's support page was showing a 403 Forbidden error message, which is an HTTP status code shown by a web server when a visitor isn't permitted to access a given URL.

The hackers have told E Hacking News that they still have access to the company’s systems.

Viber launched in 2010 as a direct competitor for Skype.

Founded by an American-Israeli, the company has centers in Belarus and Israel. In 2011, online news pub Israel21c declared it one of the top 10 iPhone apps in Israel.

Is it a surveillance tool? I can't imagine any mobile app that isn't, frankly. They collect quite a bit of data on users.

What's done with that data is another matter, as the PRISM stories about widespread surveillance by the US National Security Agency have illustrated.

What we do know is that the SEA, like many other rogue and criminal online outfits, uses phishing to great advantage.

That's how it took over The Onion, for example, using three separate methods that breached employees' Google Apps accounts.

Viber's policy review in the wake of the breach will surely include phishing defense training, I would assume.

Any other organisation that doesn't want the SEA, or other wrongdoers, taking it over, would be wise to review their own policies before it suffers a similar fate to Viber.

, ,

You might like

3 Responses to Viber admits to swallowing 'Syrian Electronic Army' phishing bait

  1. Guest616 · 274 days ago

    Even with proper training there will always be someone that opens attachments. A lot of times you cannot even blame them since the phishing email will be spoofed from an internal email address. Not to mention all the software on the users PC would have to be up to date to avoid the malware being executed if its not 0day. It is easy picking out there with the amount of uninformed employees.

  2. viberteam · 273 days ago

    Hi,
    I'm an official representative from Viber.

    As explained in the article, no sensitive user data was exposed and Viber's databases were not "hacked". Sensitive, private user information is kept in a secure system that cannot be accessed through this type of attack and is not part of our support system.

    We are reviewing all of our policies to make sure that no such incident is repeated in the future.

    Note to our users: there is no need to uninstall and reinstall Viber, as no security threat is posed.

    If you have any more questions/doubts, please feel free to let us know :)

    Thanks,
    The Viber Team.

  3. guest · 212 days ago

    the problem with hacking is that we cannot tell if you are a ..."Team Member" or a "Hacker" you do not even provide a name...

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

About the author

I've been writing about technology, careers, science and health since 1995. I rose to the lofty heights of Executive Editor for eWEEK, popped out with the 2008 crash, joined the freelancer economy, and am still writing for my beloved peeps at places like Sophos's Naked Security, CIO Mag, ComputerWorld, PC Mag, IT Expert Voice, Software Quality Connection, Time, and the US and British editions of HP's Input/Output. I respond to cash and spicy sites, so don't be shy.