HomeInvestigations Hacker attack on Cosco management company! Website changed!

[EXCLUSIVE] Hacker attack on Cosco management company! Website changed!

PCT.Hack

A hacker attack appears to have taken place a few hours ago on the website of COSCO , specifically SEPS.A.

As is known, the state-owned Chinese company Cosco, through its subsidiary SEP S.A., purchased Pier 2 and began operations on October 1, 2009, with the aim of transforming it into the first large-scale terminal in Greece. The company is fully controlled by COSCO and ranks 5th worldwide in freight terminal management companies, while it has been featured in the Greek media from time to time regarding its use as a transit center for multinational IT companies [see here and here].

Despite all the investments made by Cosco's Chinese investors, it seems that the protection of the company's IT systems, especially those available to the public, was almost non-existent. The Indonesian hacker, a member of the Gantengers Crew with the nickname "d3b~x" (who a few days ago had also carried out a website defacement attack on a banking application company) seems to be behind the attack on the website of SETS.A.

“ d3b~x”, according to information from foreign websites, proceeded to alter an internal link of the website, using a weakness that he probably identified in the website’s management system. The Indonesian hacker also has a website [here]. The weakness allowed him, as we see from the result, to post his own content on the link [here]

You can see a screenshot of the attack below, while at the time of writing these lines, the management team of SET S.A. has not been aware of the attack.

SEP.Defaced

It is worth noting that the Gantengers Crew  are low-level hackers , lacking the necessary expertise for high-level attacks, while using common tools available to everyone to carry out the website alterations. This makes the impact of the attack even more significant , since it seems that minimal measures were taken to protect the website from external alteration attacks, while hackers of the lowest cognitive level achieve alteration and unauthorized access!

The website, although informative for the public, is located within the company's infrastructure. It is not clear whether there is an interface with internal company systems or whether it is located in a demilitarized zone (DMZ). In any case, administrators and IT managers must IMMEDIATELY take the website out of operation and investigate what kind of access the malicious hackers gained and whether they managed to gain access to the organization's internal systems.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS