Wikileaks 'hacked' by OurMine

The whistleblowing site was supposedly breached, but the attack was found to be a simple DNS spoof

Notorious whistleblowing site Wikileaks drew the attention of the cyber security community this week, as the organisation fell victim to an apparent hack.

Visitors to the Wikileaks homepage were greeted with a message from security company OurMine, proclaiming that it had hacked WikiLeaks in response to a challenge supposedly issued by the organisation.

"Hi, it's OurMine," the message read. "Don't worry we are just testing your... blablablab [sic], Oh wait, this is not a security test! Wikileaks, remember when you challenged us to hack you?"

The same statement also taunted cyber vigilante group Anonymous, indicating that this hack was partly in revenge for an incident in which Anonymous allegedly attempted to dox the group for attacking Wikileaks, which has been accused of being a front for Russian intelligence. "There we go" the message read. "One group beat you all!"

However, it quickly emerged that OurMine had not actually broken into Wikileaks' servers at all. Instead, the group used a tactic known as 'DNS poisoning', whereby an attacker gains control of the DNS server that controls how traffic is routed to an IP address, and redirects it to a location of their choosing, in this case, a page hosted on OurMine's own server.

The attack has now apparently been thwarted, and the Wikileaks site appears to be fully operational once again.

The statement left by the group echoed the message it commonly left on the social media accounts of its other victims, which usually state that the group is "just testing [the victim's] security". These victims include various high-profile companies and individuals, including Facebook founder Mark Zuckerberg, Google CEO Sundar Pichai and, most recently, Game Of Thrones creators HBO.

These hacks are apparently operated as promotional stunts for the group's cyber security consultancy and penetration testing business, with victims advised to contact the group if they wish to improve their security.

Featured Resources

How virtual desktop infrastructure enables digital transformation

Challenges and benefits of VDI

Free download

The Okta digital trust index

Exploring the human edge of trust

Free download

Optimising workload placement in your hybrid cloud

Deliver increased IT agility with the cloud

Free Download

Modernise endpoint protection and leave your legacy challenges behind

The risk of keeping your legacy endpoint security tools

Download now

Recommended

Nigerian cyber criminals target Texas unemployment system
cyber security

Nigerian cyber criminals target Texas unemployment system

27 May 2021
Hackers use open source Microsoft dev platform to deliver trojans
Security

Hackers use open source Microsoft dev platform to deliver trojans

14 May 2021

Most Popular

How to move Microsoft's Windows 11 from a hard drive to an SSD
Microsoft Windows

How to move Microsoft's Windows 11 from a hard drive to an SSD

4 Jan 2022
Microsoft Exchange servers break thanks to 'Y2K22' bug
email delivery

Microsoft Exchange servers break thanks to 'Y2K22' bug

4 Jan 2022
Solving cyber security's diversity problem
Careers & training

Solving cyber security's diversity problem

5 Jan 2022