Those who tried to view the Washington Post on a mobile device on Thursday were greeted with pop-up messages from the well-known hacktivist group Syrian Electronic Army (SEA).
One of the texts bluntly told visitors that the page had been hacked, while others were of a propaganda nature, about military actions in Syria and Yemen.
In fact, the company's web server and website were not compromised. The hackers were able to display their messages through the Instart Logic service, a content delivery network (CDN) used by the company.
So users who tried to access the Washington Post website from their mobile phones were automatically redirected to a different website controlled by the hackers. All the while, the browser address bar showed that they were on the correct website.
According to the newspaper, the website was under the control of hackers for about 30 minutes and no damage was caused.
Shailesh Prakash, head of security at the Washington Post, said the attack affected “the mobile website” but that it did not affect any of the published articles.
Kenn White, a computer scientist in North Carolina, managed to obtain the JavaScript code used by the hackers to display the following notifications:
“You've been hacked by the Syrian Electronic Army!”
"US govt is training the terrorists to kill more Syrians."
"Saudi Arabia and its allies are killing hundreds of Yemenis people everyday!"
"The media is always lying."
The breach had no other consequences; the Syrian Electronic Army could easily (if they wanted to) direct the company's visitors to a website that distributes malware.
However, this particular group of hackers is not accustomed to such actions, since their motivations are not financial.
