Western Digital to provide recovery services for hacked NAS drives

Users affected by the cyber attack will be able to upgrade to a new My Cloud device

Western Digital has announced a new trade-in programme to help customers mitigate the effects of a mass malware attack that saw terabytes of data wiped from users’ NAS drives overnight.

Those who lost data as a result of the hack will be able to benefit from Western Digital’s data recovery services, as well as a trade-in programme for My Book Live network-attached storage devices that were targeted in the attack. Customers partaking in the programme will be able to upgrade to a new supported My Cloud device.

Both programmes will become available starting July, the company stated.

The announcement comes after it was found that cyber criminals used not one but two vulnerabilities in order to remotely wipe terabytes of data from Western Digital My Book Live devices.

This is according to an investigation conducted by Ars Technica and Censys CTO Derek Abdine, which found that hackers exploited an undocumented vulnerability in a file named system_factory_restore.

The Discovery of the flaw comes after Western Digital identified a zero-day flaw that was attributed as the source of the attacks. Labelled as CVE-2021-35941, the unauthenticated factory reset vulnerability had been introduced to the My Book Live over a decade earlier, in April 2011.

Meanwhile, the Ars Technica and Censys investigation found that a Western Digital developer had edited out an authentication check which originally asked users to type in their password prior to remote access being enabled. 

Related Resource

Owning your own access security

The key to building strong cloud security and avoiding the risk of vendor lock-in

Whitepaper front coverDownload now

Security expert HD Moore told Ars Technica that it seems as if someone at Western Digital “intentionally enabled the bypass”.

In a statement, Western Digital said that an internal “investigation of this incident has not uncovered any evidence that Western Digital cloud services, firmware update servers, or customer credentials were compromised”. 

“As the My Book Live devices can be directly exposed to the internet through port forwarding, the attackers may be able to discover vulnerable devices through port scanning. The vulnerabilities being exploited in this attack are limited to the My Book Live series, which was introduced to the market in 2010 and received a final firmware update in 2015,” it stated, adding that the vulnerabilities “do not affect” the company’s “current My Cloud product family”, which will be offered as an upgrade to the impacted customers.

Featured Resources

B2B under quarantine

Key B2C e-commerce features B2B need to adopt to survive

Download now

The top three IT pains of the new reality and how to solve them

Driving more resiliency with unified operations and service management

Download now

The five essentials from your endpoint security partner

Empower your MSP business to operate efficiently

Download now

How fashion retailers are redesigning their digital future

Fashion retail guide

Download now

Recommended

How to use machine learning and AI in cyber security
Security

How to use machine learning and AI in cyber security

30 Jul 2021
Chipotle’s marketing email hacked to send phishing emails
phishing

Chipotle’s marketing email hacked to send phishing emails

29 Jul 2021
The top 12 password-cracking techniques used by hackers
Security

The top 12 password-cracking techniques used by hackers

29 Jul 2021
Colonial Pipeline hack spurred copycat attacks on other oil and gas companies
hacking

Colonial Pipeline hack spurred copycat attacks on other oil and gas companies

29 Jul 2021

Most Popular

RMIT to be first Australian university to implement AWS supercomputing facility
high-performance computing (HPC)

RMIT to be first Australian university to implement AWS supercomputing facility

28 Jul 2021
Samsung Galaxy S21 5G review: A rose-tinted experience
Mobile Phones

Samsung Galaxy S21 5G review: A rose-tinted experience

14 Jul 2021
Zyxel USG Flex 200 review: A timely and effective solution
Security

Zyxel USG Flex 200 review: A timely and effective solution

28 Jul 2021