Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Sophos takes down partner portal after signs of hacking

Sophos believes that hackers might have stolen sensitive user information from its partner portal

Security firm Sophos has taken its partner portal offline and will reset every user's password after it found signs of a potential security breach on the server hosting it.

"Two unauthorized programs were found on the server, and our preliminary investigations indicate that these were designed to allow unauthorized remote access to information," Sophos said in a security alert posted on its website.

The company's staff found the unauthorized applications during a routine security check on April 3, and the potentially compromised server was immediately taken offline for further investigation, the company said.

Sophos could not establish if the data stored in the website's database, which includes partners' names and business addresses, email addresses, contact details, and hashed passwords, had been stolen. However, it decided to proceed under the assumption that it had.

The website will be restored after the security audit is completed and the problem is remediated. However, all user passwords will be forcibly reset as an additional precaution.

The company advised its partners to also change their passwords on other websites where they might have used them, and to be on alert for potential phishing emails that claim to originate from Sophos.

It's relatively common for attackers responsible for breaches that result in stolen email addresses to exploit the known business relationship between the affected users and the victim organization through phishing, in an attempt to extract more information.

In situations where the affected organizations are security firms like Sophos, such phishing attacks can have a high rate of success, because of the inherent trust that exists between users and their security vendors.

"We realize that the site's downtime and the forced password resets may be an overreaction and are sorry for the disruption this will cause, but we would rather cause some inconvenience at this stage than delay as we wait for further information," the company said.

Only the older partner portal, located at https://gpp.partners.sophos.com, has been affected by this security incident, Sophos said. Partners that have already moved to its new Salesforce.com-based portal don't have to worry about the password resets or downtime.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Salesforce.com, Sophos
References show all

Comments

visit them now

1

You made some really good points there. I
checked on the web for additional information about the issue and found most people will go
along with your views on this website.

Comments are now closed.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • Getting Real About Security Management and Big Data – A Roadmap for Big Data in Security Analytics
    It’s an exciting yet daunting time to be a security professional. Security threats are becoming more aggressive and voracious. This whitepaper examines the escalating complexity for the security management environment; how to get more meaning from data already collected and the combination of infrastructure, analytic tools and threat intelligence need to drive business value from Big Data. Download now.
    Learn more »
  • The Power of Cloud
    Although cloud is widely recognized as a technology game changer, its potential for driving business innovation remains virtually untapped. To take advantage of cloud’s potential to transform internal operations, customer relationships and industry value chains, organisations need to determine how best to employ cloud-enabled business models that promote sustainable competitive advantage. Learn more about driving business model innovation.
    Learn more »
  • How Web Security Improves Productivity and Compliance
    In this white paper, we will look at how secure web gateways, one type of information security technology, can provide benefits to many departments within any business or government agency. Download now.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments

Computerworld
ARN
CFO World
CMO