Lizard Squad Hacks Malaysia Airlines (Updated)

MAS’s misery continues.

150126112829-malaysia-airlines-site-hack-super-169

You’ve probably heard by now that the Malaysia airlines website was hacked by a group of people. The hack took place this morning and has now changed into a security nightmare for MAS with private e-mails stolen from their website/servers. For those of you who are slighly confused, here’s a rundown of what transpired and who are the group behind this hack.

 

The Hack

LizardSquad1

Early this morning, the MAS website was brought down by a group that dubs themselves as the Cyber Caliphate. Initially, many though that the “hack” itself is a pretty standard page defacing as seen here. Indeed, if this were all it is, we wouldn’t be covering it since website defacing is relatively harmless; a nuisance yes, but harmless nonetheless. A few hours ago, MAS clarified that this incident is nothing more than a DNS redirect and stated that no personal info was stolen.

Except, according to the hackers, this wasn’t the case.

lizarddefiance

 

As you can see on the Lizard Squad’s own tweets, they claimed that they have acquired some really sensitive data from the hack. The imgur link you see on the page itself is full of e-mails confirming ticket bookings from MAS and Fireflyz. Furthermore, all the e-mails have names of people and reportedly things like IC numbers and credit card information as well. The link itself is now dead, but I’ve managed to take a look at it, and it seems to be authentic e-mails from MAS’s side.

Claiming credit for the hack is Lizard Squad, an infamous bunch of hackers that were responsible for the Christmas Day attacks on PSN and Xbox Live. Also credited were @umgrobert and @umg_chris. While there is no denying that Lizard Squad is responsible for the hack, @umgrobert has come out and state that they were not involved with the hacking period.

twitter conversation

So not only have the hackers stolen sensitive data from MAS, they have also attempted to frame 2 people for this incident.

 

The Hackers

The main hack group responsible for the MAS hack is a group called Lizard Squad. If you don’t know who these guys are, you might remember them from other the other hacks that they did late last year. As mentioned earlier, this group claimed responsibility for taking out PSN and Xbox Live on Christmas Day last year, but the group has also claimed other hacking incidents such as the Sybil attack on the Tor networks as well as the taking out North Korea’s internet.

The most interesting part however, is Lizard Squad’s claim to be the official Cyber Caliphate. While I am unsure if Lizard Squad is a member of Cyber Caliphate hack group, or they are merely piggybagging on the Cyber Caliphate name for kicks, the fact remains that the Cyber Caliphate itself is a legit hacking group. Allegedly formed by members/supporters of ISIS, the Cyber Caliphate is the Cyber arm of the Islamic State, and they have done some absurdly high profile hacks like the time they hacked U.S. Central Command’s Twitter account and proceeded to post some highly classified data .

1104034

Other targets of the Cyber Caliphate include the Pentagon and the FBI.

wboc-hack

 

screen-shot-2015-01-12-at-10-22-39-am (1)

 

After taking a quick look at Lizard Squad’s Twitter account, they have not taken responsibility for these hacks, so it is unsure if they were even a part of these ballsy acts. Going by what I’ve seen, it seems that either the Cyber Caliphate or Lizard Squad is working together to take down MAS’s website, or the Lizard Squad is using the Cyber Caliphate name for pure notoriety.

So what happens now? Nobody knows. It remains to be seen what MAS would do seeing as they have their e-mail database stolen, and it looks like Lizard Squad is about to drop a bombshell on them as well. We will update this article as new updates regarding this hack is made available.

 

Update #1 : It seems that the MAS website hack was done via a DNS Hijacking method, Senior Security Adviser at Sophos, Chester Wisniewski has this to say : ” It appears that Malaysia Airlines’ TTL (Time To Live), was set to 24 hours. This meant that any changes can take up to 24 hours to propagate, and this could prolong the outage. DNS hijacking has happened frequently over the last few years, such as high profile attacks by the Syrian Electronic Army on big name companies, prompting them to protect their DNS assets. The best way for companies to avoid this is to ensure there is domain locking enabled on their accounts and to use a DNS name provider who offers two-factor authentication to prevent unauthorised access to domain settings.”

Comment what you think!