Citaat:
21st May 2012 - Further Update
Following an initial investigation I can report that what occurred today was the result of a social engineering attack.
The person was able to impersonate myself with our web hosting company, and provide correct answers to their verification questions. And thereby gain access to our client account with the host, and ultimately change the email and then request a mailing of the access details.
This means that there was no actual hacking of our server. They were ultimately given the access details.
This is obviously a terrible situation, and very unfortunate, but rest assured that this was no issue or vulnerability with the WHMCS software itself.
We are immediately reviewing all of our hosting arrangements, and will be migrating to a new setup at the earliest opportunity.
I would like to take this opportunity to thank all of you who have sent in messages of support, and offers of help. It has clearly been a very stressful time, and I thank everyone both personally and on behalf of WHMCS for their loyalty and support.
The matter is now in the hands of the FBI.
Citaat:
Latest Status Update
Just another quick update as I know there's a lot of rumours and speculation going around.
Right now to compound matters, we are experiencing a large scale DDOS attack, which started at around 1am last night, and continues to this moment, so accessing the site may be intermittent for the time being due to the protection hardware that has been put in place for that.
We know we've let you down. Although the attack yesterday was not directly due to any lapses in the security in place on either our server or WHMCS itself, we realise that we could, and should, have had a more robust hosting infrastructure in place. Plans have already been put in motion for a new multi-server hosting infrastructure to be setup and migrated to.
As soon as we get things sorted, we'll be back online and give you another update.
In the meantime, thank you for bearing with us.
Matt
En een mogelijk motief voor de hack: