Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Security-wise, It’s a Tough Time to be an Online News Site

The influential journalist H.L. Mencken famously waxed poetic about news reporting, describing it as being “the life of kings.” However, Mr. Mencken’s comment was made in a pre-Internet era, and a more accurate regally-themed quote for the news business may be Shakespeare’s “Uneasy lies the head that wears a crown.” News organizations today face a variety of challenges. Falling print circulations are forcing newspapers to look to their online properties to generate more revenue.

The influential journalist H.L. Mencken famously waxed poetic about news reporting, describing it as being “the life of kings.” However, Mr. Mencken’s comment was made in a pre-Internet era, and a more accurate regally-themed quote for the news business may be Shakespeare’s “Uneasy lies the head that wears a crown.” News organizations today face a variety of challenges. Falling print circulations are forcing newspapers to look to their online properties to generate more revenue. Social media has disrupted the traditional reporting process, increasing news organizations’ exposure to hackers and factual errors in the race to break news first. Several high-profile news organizations have recently become the targets of advanced attacks both by hacktivists aiming to embarrass and cybercriminals looking to steal privileged information, tarnishing their reputations and exposing their investigative journalists.

Just last week, The Washington Post reported that its website was compromised by the Syrian Electronic Army (SEA), a hacktivist group sympathetic to Syrian President Bashar al-Asad. For a short time on Thursday, the SEA was able to redirect viewers of washingtonpost.com to their own web site. Incidents like this bring into startling relief the vulnerabilities that online news organizations must start addressing when it comes to hacking.

HacktivismHacktivism is becoming the tool of choice for many online groups seeking to draw attention to their causes, and online news sites make tempting targets. Many hacktivists view attacks on news sites they perceive to have biases against their causes to be a particularly effective ways to stick their thumbs in the eyes of their political enemies. High-profile new sites draw millions of readers from all corners of the globe every day. Even the short-term hijacking of a news website can get a hacktivist’s message in front of a portion of those readers, many of whom would otherwise be oblivious to the hacktivist’s cause.

Promoting a political message is only one reason to hack a news site. Financial gain and cyber espionage are others. News organizations live and die by the value of the information they provide. In the process of building a story, journalists often interact with highly influential people in government and business, and those journalists can gain access to information that could be highly damaging (or profitable in the case of financial news) if leaked in advance of a story’s publication or made public in any way at all. This could make new sites a popular target of cybercriminals looking to gain access to sensitive information on a news organizations’ internal network via their external web site. Foreign governments are also targeting news organizations for cyberattack. In January, The New York Times said that Chinese hackers had accessed the company’s network to steal reporters’ user names and passwords. The attack was reportedly motivated by The New York Times’ reporting on members of the Chinese prime minister’s family earning billions of dollars in sweet heart business deals.

Lastly, news sites are targeted by cybercriminals because they are businesses and their owners expect them to make a profit. With print circulations declining, the best revenue stream available to many newspapers is selling ad space on their online properties, and online ad networks are becoming an increasingly popular vehicle for cybercriminals to use to deliver malware. Ad networks are highly automated and often lack security controls to recognize new or sophisticated attacks, opening the door for a cybercriminal to upload malware disguised as an advertisement. With news web sites regularly topping lists of popular online destinations for consumers, what better place for a cybercriminal to post their bogus ad to gain the most exposure for their malware than a news site?

The motivations behind cyberattacks against news organizations are many, but the way the attacks are carried out seams to follow one of two approaches. As discussed above, cybercriminals are using ad networks to disseminate malware, and hacktivists seem to be following suit. The SEA claims it gained access to the washingtonpost.com servers via the Outbrain ad network. Social media has also made news web sites uniquely vulnerable to phishing attacks. Twitter and YouTube have made it possible for anyone in world to break a news story as it’s happening. Knowing this, and in light of today’s 24-hour news cycle and the intense competition from other news organizations, its understandable why a journalist would be quick to click on a link from an unknown source in order to get the scoop. That kind of behavior is phisher’s dream.

Obviously, now that news sites know that hacktivists and cybercriminals have them in their sights, the lesson to be learned here is that cybersecurity needs to be a key part of any news organizations’ online strategy. It’s a lesson that other online businesses and organizations should pay heed to; otherwise some day they just may see their own cybersecurity mishaps make the front page.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.