“Dear Customer,
At around 4am EST, our system administration team identified a website defacement attack affecting a large number of customers. We are still investigating, but it appears that files named index.php have been defaced.
If you have a backup of your site, you may upload your index.php files to correct this. You may need to do this for each directory. If your site uses an index.html or index.htm, you will need to upload those files, then delete the index.php.” – InMotion
If you received this message on Sunday, rest assured that you were not alone! InMotion Hosting’s customers’ websites were attacked early Sunday morning by one Bangladeshi hacker going by the alias “TiGER-M@TE”. It wasn’t just a server hack, but their whole data center was infiltrated. The perpetrator replaced every index file in every major directory of every account including the provider’s official sites. This could have affected as many as 70,000 websites.
In an alleged interview with TiGER-M@TE by The Hacker News, he claims, “ ”I hack 700,000 websites in one shot, this may be a new world record. After submitting 200,000 domains, zone-h was going down again and again and became almost unresponsive in the end. So i was unable to submit all websites. so I’ve listed all domains in this attachment. It was not just a server hack, actually whole data center got hacked.”
This appears to be the same hacker who was previously successful with his attack on Google. He claimed to be hacking since 2007, working alone, and only using private exploits and zero-day attacks.
If one of the largest web hosting companies can be hacked, then just about anyone can be a target. In fact, this story hit close to home here at SEO Expert Marketing, as one of our clients had their website go down. Thankfully, we were able to swiftly alleviate the situation an hour after noticing it was hacked.